Quick Check

2-Minute HIPAA Readiness Quick Check

Answer ten practical questions. Your score is an initial planning signal only; it does not certify compliance or replace a risk analysis, legal review, penetration test, or professional audit.

Do not enter PHI. Assessment answers are not submitted or retained by this tool and clear after five minutes.

HIPAA security readiness assessment graphic with healthcare professionals, a checklist, and a readiness score
Initial self-check

Answer all ten questions

Choose Yes only when the activity is current and supported by evidence. The score updates immediately, shows how much of the checklist applies, and will not turn green when a critical control is reported missing or uncertain.

Do not enter PHI, patient names, credentials, or incident details. Assessment answers are processed in your browser and are not submitted to or retained by this tool. The website may use consent-controlled analytics, but the complete assessment form and results are explicitly masked from Microsoft Clarity session recording. This assessment session clears after five minutes.

Live score starts with your first answer0 of 10 answered · coverage pending
1Have you identified every place electronic patient information is stored, used, or sent?
What to verify

Confirm covered-entity or business-associate status and map ePHI across systems, devices, cloud services, locations, workflows, and vendors.

2Are Privacy and Security Officials formally assigned?
What to verify

Verify written assignments, decision authority, reporting lines, and responsibility for policies, safeguards, complaints, investigations, and corrective action.

3Have you completed a documented HIPAA risk analysis for all ePHI?
What to verify

Look for an accurate and thorough analysis of threats, vulnerabilities, safeguards, likelihood, and impact to ePHI confidentiality, integrity, and availability.

4Are security risks assigned, tracked, and corrected?
What to verify

Verify priorities, owners, deadlines, decisions, remediation status, accepted-risk approvals, and evidence that completed work was validated.

5Are required HIPAA procedures current, approved, and retained?
What to verify

Check privacy, security, incident, sanction, complaint, contingency, documentation, review, and retention procedures against actual operations.

6Are access, logging, authentication, transmission, endpoint, and encryption controls working?
What to verify

Verify unique accounts, appropriate authorization, audit logs, authentication, transmission security, endpoint protection, and documented encryption decisions.

7Are workforce access, training, termination, and sanctions documented?
What to verify

Check role-based approvals, supervision, training records, prompt access removal, investigation steps, and consistent sanctions.

8Are vendors with patient-data access identified and governed?
What to verify

Verify a current vendor inventory, due diligence, appropriate Business Associate Agreements, access paths, subprocessors, and incident responsibilities.

9Are incident response and recovery procedures documented and tested?
What to verify

Check breach assessment, escalation, backups, restoration tests, disaster recovery, emergency operations, notifications, and lessons learned.

10Do you reevaluate safeguards and track improvements when things change?
What to verify

Verify periodic technical and nontechnical evaluations, vulnerability review, corrective-action tracking, and reassessment after operational or technology changes.

Use the result correctly

A green score is the beginning of verification

Strong answers should be tested against policies, screenshots, access lists, risk records, backup results, audit logs, vendor agreements, incident exercises, and technical configuration. A scan can identify technical vulnerabilities, but a scan alone cannot establish HIPAA compliance.

For a comprehensive questionnaire, use the full HIPAA Security Readiness Assessment. For a concise evidence list, use the HIPAA Security Checklist. When you need independent evidence review, request a HIPAA readiness conversation.