HR Data Security Checklist

Quarterly review the HR team runs to confirm employee data — HRIS records, I-9s, medical files, ER investigations, payroll and benefits data — is access-controlled, vendor-vetted, and breach-ready. Designed for an HR Operations or HR Compliance lead at a 50–1,000 employee comp...

5 sections 19 steps Collects data
1

Access Governance & Identity

  1. Pull the HRIS admin access roster
    • Export the current list of admin and elevated-permission users from Workday, BambooHR, Rippling, or whichever HRIS the team uses. Include payroll admins, ATS admins (Greenhouse, Lever, Ashby), and benefits-portal admins. Stale admin accounts from former HR coordinators are the most common finding here.

  2. Review role-based permissions in the HRIS
    • Confirm HRBPs only see their assigned business units, recruiters only see open reqs they support, and managers see only direct and indirect reports. Watch for overly broad "HR Read All" roles that drift onto coordinators during high-hiring quarters.

    Collects file
  3. Verify MFA enforcement on HR systems
    • Check MFA is required on the HRIS, ATS, payroll (Gusto, ADP, Paychex), benefits admin portal, and the background-check vendor (Checkr, Sterling). SAML/SSO tenants should confirm conditional access policies cover all HR apps, not just the HRIS.

  4. Confirm offboarding deprovisioning within 24 hours
    • Spot-check the last 10 separations against HRIS, ATS, payroll, and benefits portal access logs. Terminated employees retaining HR system access past the last day is both a security and a discrimination-litigation risk if they pull files from prior cases.

2

Vendor & System Security

  1. Collect SOC 2 reports from HR vendors
    • Request current SOC 2 Type II reports from the HRIS, ATS, payroll, benefits admin, background-check, and LMS vendors. Reports older than 12 months don't satisfy most enterprise security reviews — flag any vendor whose report is expired, in-progress, or refused.

    Collects list
  2. Confirm BAAs with PHI-handling vendors
    • HIPAA Business Associate Agreements must be on file with the benefits broker, EAP provider, COBRA administrator, and any wellness or telehealth vendor receiving member-level data. Brokers rotate carriers — a BAA signed three years ago may not cover the current carrier.

  3. Verify encryption on HRIS data exports
    • Scheduled exports (payroll feeds, 401(k) contributions, ACA reporting feeds for 1094-C/1095-C) should travel over SFTP or vendor-native API — never plain email. Audit the last quarter of scheduled jobs and recipient inboxes.

  4. Escalate vendor security gaps to legal and IT
    • Open a vendor remediation ticket with IT security and employment counsel. Document the gap, the vendor's response timeline, and whether a compensating control (data minimization, restricted access, alternate vendor) is needed before the next contract renewal.

3

Sensitive Records Handling

  1. Audit I-9 file segregation
    • I-9s and supporting documents must be stored separately from the personnel file — both for ICE inspection prep and to limit exposure of national-origin data. Confirm retention is 3 years from hire date or 1 year from termination, whichever is later.

  2. Verify ADA and FMLA medical file separation
    • ADA accommodation records, FMLA certifications, workers' comp documentation, and STD/LTD paperwork must live in a separate confidential medical file with restricted access. Managers should never see medical certifications — only the accommodation outcome.

  3. Restrict ER investigation file access
    • HR Acuity, AllVoices, or NAVEX case files should be visible only to the assigned investigator and ER lead. Pull the access log for the past quarter and confirm no HRBPs viewed cases outside their assigned scope.

  4. Apply records retention schedules
    • Purge records past their retention window: applicant records (1 year minimum, longer for federal contractors under OFCCP), payroll records (3 years FLSA, 4 years IRS), benefits records (6 years ERISA), OSHA 300 logs (5 years). Document each purge for audit trail.

4

Workforce Training & Acknowledgment

  1. Assign annual HR data privacy training
    • Push the annual privacy module via the LMS (TalentLMS, Litmos, LinkedIn Learning) to everyone with HRIS, ATS, or payroll access. Benefits team members get a separate HIPAA module. Track completion against a 30-day deadline.

    Collects number
  2. Collect signed confidentiality acknowledgments
    • Anyone with elevated HR data access re-signs the confidentiality and acceptable-use acknowledgment annually. Store signed copies in the personnel file. Missing acknowledgments are a frequent finding in pre-litigation discovery.

    Collects file
  3. Brief managers on handling employee PII
    • Cover the named situations: salary discussions in Slack DMs, performance docs emailed to personal accounts, accommodation details shared with skip-level managers, photos of badges or licenses in messaging tools. Include a reminder that NLRA still protects employees discussing their own pay.

5

Incident Response & Quarterly Sign-Off

  1. Run an HR data breach tabletop
    • Walk through a realistic scenario with HR, IT security, and legal: a phished payroll admin, a misdirected 1095-C batch, an ATS export sent to the wrong hiring manager. Time the response against state breach-notification windows (most states: 30–60 days from discovery).

  2. Log incidents detected this quarter
    • Capture every confirmed or suspected exposure of employee data — even minor ones like a benefits enrollment email cc'd to the wrong person. Patterns matter as much as severity for the audit narrative.

    Collects list
  3. Notify legal and privacy of suspected breach
    • Engage employment counsel and the privacy officer the same day the incident is logged. State breach-notification clocks (CCPA/CPRA in California, SHIELD Act in New York, and 45+ other state laws) typically start at discovery, not at confirmation. Don't wait for forensic certainty before opening the file.

  4. Sign off on the quarterly HR data security audit
    • HR Director or VP HR signs off on the quarter's review. Include any open items being carried into next quarter and the target close date. The signed record is what auditors and acquirer due-diligence teams ask for first.

    Collects signature Collects paragraph

Use this template

Copy it to your account, customize the steps, and run it with your team in minutes.


Sections 5
Steps 19
Category Human Resources
Price Free to start
Need a different process

Browse hundreds of free templates across every team and industry.

Back to template library

Run HR Data Security Checklist with your team

Customize the steps, assign roles, set a schedule, and keep a complete record for every run.