HIPAA Quick Assessment

Answer 10 questions and get a scored HIPAA Security Rule readiness result with specific fixes for risk analysis, BAAs, encryption, audit logs and training.

Advertisement

Free HIPAA Quick Assessment — 10 Questions, 3 Minutes

This HIPAA quick assessment asks ten questions about the controls that HHS Office for Civil Rights investigators look at first, scores your answers out of 30, and tells you which of your safeguards are weakest and what to do about each one. It takes about three minutes, requires no signup, and runs entirely in your browser. Your answers are encoded into the page URL, so you can bookmark or share a result without any data being stored on a server.

It is designed for the people who carry HIPAA responsibility without a compliance department behind them: practice managers, dental and behavioural health office administrators, small hospital IT leads, and the business associates — billing companies, transcription services, health-tech startups, MSPs — who inherit the same obligations by contract. If you want a full framework walkthrough afterwards, this is the fast triage that tells you whether you need one.

What the Assessment Covers

Each question targets a specific area of the HIPAA Security Rule, and the four answer options describe increasing levels of maturity scored 0 to 3.

Question areaSecurity Rule anchor
Date of last security risk assessmentRisk analysis, 164.308(a)(1)(ii)(A) — Required
How access to PHI is controlledInformation access management, 164.308(a)(4); access control, 164.312(a)
Encryption of PHI at rest and in transit164.312(a)(2)(iv) and 164.312(e)(2)(ii) — both Addressable
Security awareness training for the workforce164.308(a)(5)
Business Associate Agreements with vendors touching PHI164.308(b)(1) and 164.502(e)
Documented breach and incident response planSecurity incident procedures, 164.308(a)(6) — Required
Audit logging of PHI accessAudit controls, 164.312(b); activity review, 164.308(a)(1)(ii)(D)
Device security for endpoints reaching PHIWorkstation and device controls, 164.310(b)–(d)
Physical access control to areas holding PHIFacility access controls, 164.310(a)
Written HIPAA policies and procedures164.316 — policies, documentation and six-year retention

How to Use It

  1. Answer honestly, not aspirationally. The value of the result depends entirely on picking the option that describes what is actually in place today, not what is written in a plan. “Documented plan, never tested” is a different score from “documented plan, tested annually” for a reason.
  2. Answer all ten. Questions advance one at a time with a progress indicator; it takes about three minutes.
  3. Read the tier. Scores of 80% or more return Strong, 50–79% returns Needs Improvement, and below 50% returns At Risk.
  4. Work the recommendations. Every question you did not max out returns a specific recommendation explaining what the control is, why HIPAA expects it, and the practical step to close it.
  5. Share or revisit the result. The URL carries your answers, so you can send the result to your practice owner or MSP, or re-open it in six months to compare.

What Actually Trips Up Small Practices

Three findings account for most of what goes wrong in OCR enforcement against smaller covered entities and business associates.

No current risk analysis. This is the single most cited failing. The risk analysis at 164.308(a)(1)(ii)(A) is a Required implementation specification — not addressable — and it must be an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic PHI you hold. A vendor’s security questionnaire is not a risk analysis. Neither is a penetration test. The rule does not name a fixed frequency, but it must be kept current, which in practice means reviewing it annually and after any material change to systems or operations.

Missing Business Associate Agreements. Any vendor that creates, receives, maintains or transmits PHI on your behalf needs a signed BAA: the EHR vendor, the cloud host, the billing company, the answering service, the IT support firm, the shredding company, the backup provider. The list is usually longer than the one in someone’s head, which is why the assessment scores “BAAs tracked with annual vendor reviews” higher than “BAAs with all known vendors”.

Encryption treated as optional. Encryption is genuinely addressable under the current Security Rule, which means you may implement an equivalent alternative — but you must document the assessment and the reasoning, and “we did not get round to it” is not an alternative measure. Encryption also has a decisive practical effect on breach exposure: PHI rendered unusable, unreadable or indecipherable to unauthorised persons through encryption meeting HHS guidance falls within the safe harbour, so its loss is not a breach requiring notification. A stolen encrypted laptop is an incident; a stolen unencrypted one is potentially a reportable breach.

Worth knowing: HHS proposed a substantial overhaul of the Security Rule in January 2025 that would remove the addressable/required distinction and make encryption and multi-factor authentication mandatory. As of mid-2026 that rule has not been finalised, and the current requirements still stand. Build toward encryption anyway — the direction of travel is not ambiguous.

Breach Notification Deadlines Worth Memorising

  • Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery of the breach (45 CFR 164.404).
  • HHS must be notified contemporaneously with individual notice when a breach affects 500 or more individuals; for breaches affecting fewer than 500, you keep a log and submit it no later than 60 days after the end of the calendar year (45 CFR 164.408).
  • Media notice is required for breaches affecting more than 500 residents of a state or jurisdiction (45 CFR 164.406).
  • Business associates must notify the covered entity without unreasonable delay and within 60 days of discovery (45 CFR 164.410).
  • Documentation required by the Security Rule must be retained for six years from the date of creation or the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)(i)).

The clock starts at discovery, and a breach is treated as discovered on the first day it is known or reasonably should have been known to the organisation. That is why the audit logging question in this assessment matters more than it looks: without log review, discovery happens whenever someone happens to notice.

Frequently Asked Questions

Does this replace a HIPAA Security Risk Assessment?

No, and it is important not to confuse the two. The risk analysis required at 164.308(a)(1)(ii)(A) is a documented, system-by-system evaluation of threats, vulnerabilities, likelihood and impact across everywhere ePHI lives. This is a ten-question maturity check that tells you whether you are likely to survive one. HHS and ONC publish a free Security Risk Assessment Tool for the full exercise.

Is this legal advice?

No. It is an informational aid. HIPAA obligations turn on facts specific to your organisation — whether you are a covered entity or business associate, what systems hold ePHI, what your contracts say — and nothing here creates a compliant artefact by itself. Confirm anything consequential with qualified counsel or a compliance professional.

My score came back “Strong”. Am I compliant?

It means the ten controls sampled look healthy. HIPAA has considerably more than ten requirements, including the entire Privacy Rule, which this assessment does not touch. Treat a strong score as permission to move from firefighting to evidence-gathering, not as a conclusion.

Do business associates have to do all of this?

Yes. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for compliance with the Security Rule and for breach notification, not merely contractually liable to the covered entity. If you are an MSP, a billing service or a health-tech vendor, every question here applies to you.

What are the penalties for non-compliance?

Civil money penalties are tiered by culpability under 45 CFR 160.404 — from no knowledge despite reasonable diligence, through reasonable cause, to willful neglect corrected within 30 days, to willful neglect not corrected. Each tier has a per-violation range and an annual cap for identical violations, and the amounts are adjusted for inflation each year, so check the current figures published by HHS rather than relying on a number quoted in an article. Correcting willful neglect within 30 days materially reduces exposure, which is the practical reason to act on findings quickly.

How often should staff be trained?

The Security Rule requires a security awareness and training programme for all workforce members, including management, with periodic security updates. It does not fix a frequency, but annual training with documented sign-off is the accepted norm, and adding phishing simulation is what separates a strong programme from a compliant-on-paper one.

How long do I have to keep audit logs?

The six-year retention requirement at 164.316(b)(2)(i) applies to the documentation the Security Rule requires you to maintain — policies, procedures, actions, activities and assessments. Log retention itself is set by your own documented policy informed by your risk analysis; many organisations align it to six years for simplicity, and doing so removes an argument during an investigation.

Is my data sent anywhere?

No. The assessment runs in your browser and your answers are encoded into the page URL. Nothing is submitted for storage and there is no account.

What should I do after this?

Close whichever recommendation scored lowest, then broaden out. The compliance readiness checklist covers HIPAA in depth alongside SOC 2 and CMMC, the security policy generator produces the written policies 164.316 expects, and the data classification policy architect builds the handling rules that make “minimum necessary” enforceable rather than aspirational. If you need to put a number on the exposure for a budget conversation, the data breach cost calculator is the one to use.

What Is a HIPAA Quick Assessment

The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting sensitive patient health information (Protected Health Information, or PHI). A HIPAA assessment evaluates an organization's compliance with the Privacy Rule, Security Rule, and Breach Notification Rule — identifying gaps in administrative, physical, and technical safeguards that protect PHI.

HIPAA compliance is mandatory for Covered Entities (healthcare providers, health plans, healthcare clearinghouses) and their Business Associates (vendors who handle PHI). Violations can result in penalties ranging from $100 to $50,000 per violation, up to $1.5 million annually per violation category, plus potential criminal charges.

HIPAA Security Rule Safeguards

Safeguard TypeRequirementsExamples
AdministrativePolicies, procedures, workforce trainingRisk analysis, security officer designation, workforce training, incident response plan
PhysicalFacility and workstation protectionsFacility access controls, workstation use policies, device disposal procedures
TechnicalTechnology-based protectionsAccess controls, audit controls, integrity controls, transmission security

Key HIPAA Requirements

RequirementRuleDescription
Risk AnalysisSecurity Rule §164.308(a)(1)Conduct accurate and thorough assessment of risks to PHI
Access ControlSecurity Rule §164.312(a)(1)Implement policies to allow only authorized access to ePHI
Audit ControlsSecurity Rule §164.312(b)Record and examine access and activity in systems containing ePHI
EncryptionSecurity Rule §164.312(a)(2)(iv)Encrypt ePHI at rest and in transit (addressable)
Breach NotificationBreach Rule §164.404Notify affected individuals within 60 days of breach discovery
BAA RequirementPrivacy Rule §164.502(e)Execute Business Associate Agreements with all vendors handling PHI
Minimum NecessaryPrivacy Rule §164.502(b)Limit PHI access and disclosure to the minimum necessary for the purpose

Common Use Cases

  • Initial compliance assessment: Evaluate your organization's current HIPAA compliance posture and identify gaps before a formal audit
  • Business Associate evaluation: Assess whether a vendor or partner meets HIPAA requirements before sharing PHI through a Business Associate Agreement
  • Annual risk analysis: Conduct the required annual risk analysis to identify new threats, vulnerabilities, and changes to your PHI environment
  • Merger/acquisition due diligence: Evaluate the HIPAA compliance of an acquisition target to identify potential liabilities and remediation costs
  • Incident response readiness: Verify that breach notification procedures, investigation processes, and documentation meet HIPAA requirements

Best Practices

  1. Conduct risk analysis annually — The Security Rule requires regular risk analysis. Annual assessment (at minimum) ensures new systems, vendors, and threats are evaluated.
  2. Document everything — HIPAA enforcement relies heavily on documentation. Policies, training records, risk analyses, incident logs, and BAAs must be documented and retained for six years.
  3. Train all workforce members — Everyone with access to PHI must receive HIPAA training upon hire and at least annually. Include phishing awareness since email is a top breach vector in healthcare.
  4. Encrypt PHI at rest and in transit — While technically "addressable" (not "required"), encryption is considered the standard of care. Unencrypted PHI breaches have no safe harbor protection.
  5. Implement the minimum necessary standard — Role-based access controls should ensure that staff only access the PHI required for their specific job functions. Audit access logs regularly.

Frequently Asked Questions

What is the HIPAA Quick Assessment tool?+

The HIPAA Quick Assessment is a free 10-question self-evaluation tool that helps healthcare practices quickly gauge their HIPAA compliance readiness. It covers key requirements including risk assessments, access controls, encryption, employee training, Business Associate Agreements, incident response, audit logs, device security, physical safeguards, and documentation.

How long does the HIPAA Quick Assessment take to complete?+

The assessment takes approximately 3 minutes to complete. It consists of 10 multiple-choice questions covering the most critical HIPAA security requirements, with each question offering four answer options ranging from no compliance to full compliance.

Is my data stored when I use this HIPAA assessment tool?+

No, all data is processed entirely in your browser and never transmitted to any server. Your assessment answers remain completely private. You can share your results via a URL link if you choose, but this only encodes your scores in the URL parameters without storing anything on our servers.

What does my HIPAA readiness score mean?+

Your score is rated on a 30-point scale across three levels. A score of 24 or higher (80%+) indicates a Strong program with well-established controls. A score between 15-23 (50-79%) means your program Needs Improvement with significant gaps. A score below 15 indicates you are At Risk and need immediate action to avoid potential penalties.

Does this tool provide official HIPAA certification?+

No, this is a self-assessment tool designed for educational purposes and initial gap analysis only. It does not constitute a formal HIPAA audit or provide certification. For official compliance verification, you should work with a qualified HIPAA compliance consultant or undergo a formal Security Risk Assessment as required by HIPAA regulations.

What are the penalties for HIPAA non-compliance?+

HIPAA penalties range from $100 to $50,000 per violation depending on the level of negligence, with an annual maximum of $1.5 million per violation category. Willful neglect that remains uncorrected carries the highest penalties. Beyond financial penalties, organizations may face corrective action plans, reputational damage, and loss of patient trust.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.