Answer 10 questions and get a scored HIPAA Security Rule readiness result with specific fixes for risk analysis, BAAs, encryption, audit logs and training.
This HIPAA quick assessment asks ten questions about the controls that HHS Office for Civil Rights investigators look at first, scores your answers out of 30, and tells you which of your safeguards are weakest and what to do about each one. It takes about three minutes, requires no signup, and runs entirely in your browser. Your answers are encoded into the page URL, so you can bookmark or share a result without any data being stored on a server.
It is designed for the people who carry HIPAA responsibility without a compliance department behind them: practice managers, dental and behavioural health office administrators, small hospital IT leads, and the business associates — billing companies, transcription services, health-tech startups, MSPs — who inherit the same obligations by contract. If you want a full framework walkthrough afterwards, this is the fast triage that tells you whether you need one.
Each question targets a specific area of the HIPAA Security Rule, and the four answer options describe increasing levels of maturity scored 0 to 3.
| Question area | Security Rule anchor |
|---|---|
| Date of last security risk assessment | Risk analysis, 164.308(a)(1)(ii)(A) — Required |
| How access to PHI is controlled | Information access management, 164.308(a)(4); access control, 164.312(a) |
| Encryption of PHI at rest and in transit | 164.312(a)(2)(iv) and 164.312(e)(2)(ii) — both Addressable |
| Security awareness training for the workforce | 164.308(a)(5) |
| Business Associate Agreements with vendors touching PHI | 164.308(b)(1) and 164.502(e) |
| Documented breach and incident response plan | Security incident procedures, 164.308(a)(6) — Required |
| Audit logging of PHI access | Audit controls, 164.312(b); activity review, 164.308(a)(1)(ii)(D) |
| Device security for endpoints reaching PHI | Workstation and device controls, 164.310(b)–(d) |
| Physical access control to areas holding PHI | Facility access controls, 164.310(a) |
| Written HIPAA policies and procedures | 164.316 — policies, documentation and six-year retention |
Three findings account for most of what goes wrong in OCR enforcement against smaller covered entities and business associates.
No current risk analysis. This is the single most cited failing. The risk analysis at 164.308(a)(1)(ii)(A) is a Required implementation specification — not addressable — and it must be an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic PHI you hold. A vendor’s security questionnaire is not a risk analysis. Neither is a penetration test. The rule does not name a fixed frequency, but it must be kept current, which in practice means reviewing it annually and after any material change to systems or operations.
Missing Business Associate Agreements. Any vendor that creates, receives, maintains or transmits PHI on your behalf needs a signed BAA: the EHR vendor, the cloud host, the billing company, the answering service, the IT support firm, the shredding company, the backup provider. The list is usually longer than the one in someone’s head, which is why the assessment scores “BAAs tracked with annual vendor reviews” higher than “BAAs with all known vendors”.
Encryption treated as optional. Encryption is genuinely addressable under the current Security Rule, which means you may implement an equivalent alternative — but you must document the assessment and the reasoning, and “we did not get round to it” is not an alternative measure. Encryption also has a decisive practical effect on breach exposure: PHI rendered unusable, unreadable or indecipherable to unauthorised persons through encryption meeting HHS guidance falls within the safe harbour, so its loss is not a breach requiring notification. A stolen encrypted laptop is an incident; a stolen unencrypted one is potentially a reportable breach.
Worth knowing: HHS proposed a substantial overhaul of the Security Rule in January 2025 that would remove the addressable/required distinction and make encryption and multi-factor authentication mandatory. As of mid-2026 that rule has not been finalised, and the current requirements still stand. Build toward encryption anyway — the direction of travel is not ambiguous.
The clock starts at discovery, and a breach is treated as discovered on the first day it is known or reasonably should have been known to the organisation. That is why the audit logging question in this assessment matters more than it looks: without log review, discovery happens whenever someone happens to notice.
No, and it is important not to confuse the two. The risk analysis required at 164.308(a)(1)(ii)(A) is a documented, system-by-system evaluation of threats, vulnerabilities, likelihood and impact across everywhere ePHI lives. This is a ten-question maturity check that tells you whether you are likely to survive one. HHS and ONC publish a free Security Risk Assessment Tool for the full exercise.
No. It is an informational aid. HIPAA obligations turn on facts specific to your organisation — whether you are a covered entity or business associate, what systems hold ePHI, what your contracts say — and nothing here creates a compliant artefact by itself. Confirm anything consequential with qualified counsel or a compliance professional.
It means the ten controls sampled look healthy. HIPAA has considerably more than ten requirements, including the entire Privacy Rule, which this assessment does not touch. Treat a strong score as permission to move from firefighting to evidence-gathering, not as a conclusion.
Yes. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for compliance with the Security Rule and for breach notification, not merely contractually liable to the covered entity. If you are an MSP, a billing service or a health-tech vendor, every question here applies to you.
Civil money penalties are tiered by culpability under 45 CFR 160.404 — from no knowledge despite reasonable diligence, through reasonable cause, to willful neglect corrected within 30 days, to willful neglect not corrected. Each tier has a per-violation range and an annual cap for identical violations, and the amounts are adjusted for inflation each year, so check the current figures published by HHS rather than relying on a number quoted in an article. Correcting willful neglect within 30 days materially reduces exposure, which is the practical reason to act on findings quickly.
The Security Rule requires a security awareness and training programme for all workforce members, including management, with periodic security updates. It does not fix a frequency, but annual training with documented sign-off is the accepted norm, and adding phishing simulation is what separates a strong programme from a compliant-on-paper one.
The six-year retention requirement at 164.316(b)(2)(i) applies to the documentation the Security Rule requires you to maintain — policies, procedures, actions, activities and assessments. Log retention itself is set by your own documented policy informed by your risk analysis; many organisations align it to six years for simplicity, and doing so removes an argument during an investigation.
No. The assessment runs in your browser and your answers are encoded into the page URL. Nothing is submitted for storage and there is no account.
Close whichever recommendation scored lowest, then broaden out. The compliance readiness checklist covers HIPAA in depth alongside SOC 2 and CMMC, the security policy generator produces the written policies 164.316 expects, and the data classification policy architect builds the handling rules that make “minimum necessary” enforceable rather than aspirational. If you need to put a number on the exposure for a budget conversation, the data breach cost calculator is the one to use.
The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting sensitive patient health information (Protected Health Information, or PHI). A HIPAA assessment evaluates an organization's compliance with the Privacy Rule, Security Rule, and Breach Notification Rule — identifying gaps in administrative, physical, and technical safeguards that protect PHI.
HIPAA compliance is mandatory for Covered Entities (healthcare providers, health plans, healthcare clearinghouses) and their Business Associates (vendors who handle PHI). Violations can result in penalties ranging from $100 to $50,000 per violation, up to $1.5 million annually per violation category, plus potential criminal charges.
| Safeguard Type | Requirements | Examples |
|---|---|---|
| Administrative | Policies, procedures, workforce training | Risk analysis, security officer designation, workforce training, incident response plan |
| Physical | Facility and workstation protections | Facility access controls, workstation use policies, device disposal procedures |
| Technical | Technology-based protections | Access controls, audit controls, integrity controls, transmission security |
| Requirement | Rule | Description |
|---|---|---|
| Risk Analysis | Security Rule §164.308(a)(1) | Conduct accurate and thorough assessment of risks to PHI |
| Access Control | Security Rule §164.312(a)(1) | Implement policies to allow only authorized access to ePHI |
| Audit Controls | Security Rule §164.312(b) | Record and examine access and activity in systems containing ePHI |
| Encryption | Security Rule §164.312(a)(2)(iv) | Encrypt ePHI at rest and in transit (addressable) |
| Breach Notification | Breach Rule §164.404 | Notify affected individuals within 60 days of breach discovery |
| BAA Requirement | Privacy Rule §164.502(e) | Execute Business Associate Agreements with all vendors handling PHI |
| Minimum Necessary | Privacy Rule §164.502(b) | Limit PHI access and disclosure to the minimum necessary for the purpose |
The HIPAA Quick Assessment is a free 10-question self-evaluation tool that helps healthcare practices quickly gauge their HIPAA compliance readiness. It covers key requirements including risk assessments, access controls, encryption, employee training, Business Associate Agreements, incident response, audit logs, device security, physical safeguards, and documentation.
The assessment takes approximately 3 minutes to complete. It consists of 10 multiple-choice questions covering the most critical HIPAA security requirements, with each question offering four answer options ranging from no compliance to full compliance.
No, all data is processed entirely in your browser and never transmitted to any server. Your assessment answers remain completely private. You can share your results via a URL link if you choose, but this only encodes your scores in the URL parameters without storing anything on our servers.
Your score is rated on a 30-point scale across three levels. A score of 24 or higher (80%+) indicates a Strong program with well-established controls. A score between 15-23 (50-79%) means your program Needs Improvement with significant gaps. A score below 15 indicates you are At Risk and need immediate action to avoid potential penalties.
No, this is a self-assessment tool designed for educational purposes and initial gap analysis only. It does not constitute a formal HIPAA audit or provide certification. For official compliance verification, you should work with a qualified HIPAA compliance consultant or undergo a formal Security Risk Assessment as required by HIPAA regulations.
HIPAA penalties range from $100 to $50,000 per violation depending on the level of negligence, with an annual maximum of $1.5 million per violation category. Willful neglect that remains uncorrected carries the highest penalties. Beyond financial penalties, organizations may face corrective action plans, reputational damage, and loss of patient trust.