In the downloads section, CMS has provided some pretty great PDFs outlining all aspects of the Security Rule and how to comply. You could build some checklists and policies from there.
You can also check out the Doctors Company, a malpractice firm, and look for the “E-Risk Guidelines for Online Communications” they helped develop.