Assessment areas
What the free HIPAA compliance assessment reviews
The initial assessment focuses on high-impact HIPAA and cybersecurity areas that often create audit risk, breach exposure, workflow problems, or documentation gaps.
Administrative Safeguards
Review policy ownership, HIPAA responsibilities, workforce training, security procedures, incident response documentation, sanction policies, risk management activity, and leadership oversight.
Read about HIPAA leadership responsibility
Technical Safeguards
Discuss user access, MFA, administrator privileges, audit logs, email security, encryption, patching, endpoints, firewalls, remote access, Microsoft 365, cloud systems, and backup protection.
Review the Security Rule safeguards matrix
Physical Safeguards
Evaluate workstation security, device protection, office access, server or network equipment access, screen locking, media disposal, paper record protection, and backup media handling.
Explore HIPAA compliance consulting
HIPAA Risk Assessment Readiness
Determine whether your organization has completed a meaningful risk assessment, tracked findings, prioritized gaps, assigned owners, and maintained evidence of remediation.
Vendor and BAA Exposure
Review whether vendors that handle PHI are inventoried, contracts are organized, Business Associate Agreements are tracked, and third-party access is limited and monitored.
Incident and Breach Readiness
Discuss whether your team knows how to respond to ransomware, lost devices, unauthorized access, misdirected email, vendor incidents, suspicious logins, and exposed PHI.