CompyMax

Risk assessment

HIPAA risk assessment software that remembers what you answered last year.

A guided assessment mapped to the Security Rule safeguards, in plain language, producing a readiness score and a gap list you can actually work through. Built for organizations with no compliance officer.

Last reviewed .

Start with the free government tool. Come here when it stops being enough.

HHS publishes the SRA Tool at no cost, and for a solo practitioner doing this once it is a genuinely reasonable starting point — we would rather say so than pretend otherwise. What it does not do is the part that makes the assessment useful the second time.

  • It is a desktop download, so two people cannot work on it at once
  • There is no remediation tracking — you get findings, not owners and due dates
  • Nothing carries forward, so next year starts from a blank form
  • There is nowhere to attach the evidence that a gap was actually closed
  • The output is a file on one machine, not something you can hand to a client
  • It does not know what your systems are actually configured to do

Plain language, not statute

Questions are written for an office manager, not a lawyer. Each one says what it is asking for and why, with the underlying citation available if you want it — never instead of the explanation.

A score, in one sitting

Ten minutes of answering gives you a provisional score and a sense of where you stand before committing to anything. The assessment saves as you go, so the considered pass across all 68 controls — realistically an afternoon — can happen whenever you are ready.

Gaps become tasks automatically

Every answer short of satisfied creates a remediation task with an owner, a due date and a place to upload evidence. The assessment stops being a document and becomes a work queue.

Year-over-year carry forward

Next year's assessment starts pre-filled with last year's answers, showing what changed. Re-confirming twenty controls and revisiting four is an afternoon, not a fortnight.

Verified where we can verify

Connect Microsoft 365 read-only and some answers stop being self-attested. Multi-factor registration, dormant accounts, external mail forwarding, admin sprawl and baseline identity protection are checked against the real configuration. Google Workspace checks are built and awaiting Google's verification review.

Multi-user, with a record of who said what

Your IT provider answers the technical questions, your office manager answers the administrative ones, and every response is attributed and dated in an append-only log.

The 68 controls, by safeguard

The assessment walks every standard and implementation specification in the Security Rule, grouped the way the rule itself groups them. Nothing is sampled and nothing is skipped: an unanswered control counts as unsatisfied and stays in the denominator, because a score that improves when you stop answering is not a score.

Verified against the Security Rule text at 45 CFR 164.308, 164.310, 164.312 and 164.316.
Safeguard groupCitationWhat it covers
Administrative164.308Risk analysis and management, sanctions, workforce authorization and clearance, termination, training, incident procedures, contingency planning, periodic evaluation, business associate contracts.
Physical164.310Facility access controls, workstation use and security, device and media disposal, re-use and accountability.
Technical164.312Access control and unique user identification, emergency access, automatic logoff, encryption and decryption, audit controls, integrity, person or entity authentication, transmission security.
Organizational and documentation164.314 / 164.316Business associate contract requirements, policy documentation, and the six-year retention obligation.

Controls are marked required or addressable exactly as the rule marks them. Addressable does not mean optional — it means you must implement it, or document why it is not reasonable and appropriate and what you did instead. The assessment asks for that reasoning rather than letting the control disappear.

The free HHS SRA Tool, feature by feature

We would rather set this out plainly than imply the government tool is bad. It is not. It is a genuinely reasonable choice for a solo practitioner doing this once, and if that describes you, use it.

HHS SRA ToolThis platform
CostFreeFrom $79/month, 14-day trial
Runs onA Windows or iOS download, on one machineThe browser, any device
Multiple peopleOne file, one person at a timeConcurrent, with each answer attributed and dated
RemediationProduces findingsProduces tasks with owners, due dates and evidence uploads
Next yearStart from a blank formAnswers carry forward as pending drafts, with a year-over-year comparison
EvidenceNowhere to attach itFiles attach to the control or task, hashed and dated
Configuration checksAsks you what is configuredReads Microsoft 365 settings directly and records the result
OutputA file on one computerA branded, dated pack you can send, plus a live trust page

The honest summary: the SRA Tool is a questionnaire, and this is a programme. If you will do the assessment once and file it, the free tool is enough. If somebody is going to ask you for evidence — a hospital client, an insurer, a payer — the difference is the part after the questionnaire.

How often you have to redo it

The Security Rule requires the risk analysis to be reviewed periodically and updated as needed. It deliberately does not name an interval, which is why the question keeps being asked and why the answer is a judgement rather than a date.

Annually, as the defensible default
This is the practice almost everyone follows and the cadence an investigator will expect to see. It is also what the carry-forward is designed around: confirm what is unchanged, work what moved.
Whenever something material changes
A new system holding patient data, an office move, an acquisition, a significant staffing change, or a new category of service. Each of these changes the risk picture, and a review triggered by the change is stronger evidence than one triggered by the calendar.
After a security incident
Whether or not it turned out to be a reportable breach. The incident is evidence about your actual risk, and re-running the affected controls is the visible response.

A point worth being precise about: the risk analysis is not the same thing as a vulnerability scan or a penetration test. Scans examine technical weaknesses in systems; the risk analysis is an organization-wide assessment covering administrative and physical safeguards too. Reviews frequently find a scan report submitted in place of a risk analysis, and it does not satisfy the requirement.

What an investigator actually asks to see

Failure to conduct an accurate and thorough risk analysis is the most frequently cited issue in HIPAA enforcement. What resolves the question is rarely the sophistication of the analysis — it is whether the documentation exists and whether it shows sustained attention.

  1. The current risk analysis, dated

    Covering the whole organization, not one system. If it has no date, it cannot be shown to be current, which for these purposes is much the same as not existing.

  2. Prior versions, showing a history

    One assessment proves a moment. A series proves a programme — which is precisely what the year-over-year comparison is for.

  3. The risk management plan that followed

    Identified risks with owners, dates and what was actually done. An analysis with no remediation record reads as an exercise nobody acted on.

  4. Evidence that the remediation happened

    The configuration screenshot, the signed policy, the completed training record, the executed agreement. This is the difference between a task marked done and a task shown done.

  5. Documented risk acceptances

    Where you decided not to remediate, the reasoning and who accepted it. Recorded acceptance is a defensible position; a silent gap is not.

All of this is retained for six years under 45 CFR 164.316(b)(2) — from creation or last effective date, whichever is later. That includes superseded versions, which is why nothing here is edited in place.

Common questions

Is a risk assessment required by HIPAA?
Yes. Conducting and documenting a risk analysis is a Security Rule requirement (45 CFR 164.308(a)(1)(ii)(A)) for covered entities and business associates, and it is the single most commonly cited failure in enforcement actions. The rule does not mandate any particular tool.
How do you do a HIPAA risk assessment?
Establish where electronic patient information is created, stored and transmitted; identify the threats and vulnerabilities to it; note the safeguards already in place; rate the likelihood and impact of each risk; then document the results and a remediation plan with owners. For a small organization that is roughly an afternoon of focused work — this tool walks it in plain language, and the free HHS SRA Tool covers similar ground on the desktop.
How often should a HIPAA risk assessment be done?
The rule says periodically rather than naming an interval. Annually is the common, defensible practice, plus whenever something material changes — a new system, an office move, an acquisition, or an incident. The carry-forward is designed for exactly that cadence.
What are the 5 things a risk assessment should include?
An inventory of where patient information lives, the threats and vulnerabilities to it, the safeguards currently in place, a likelihood-and-impact rating for each risk, and a documented remediation plan with owners and dates. The documentation is not optional — an undocumented assessment does not exist as far as an investigator is concerned.

Software and researched information, not legal advice. No product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules, and using this service does not establish that you comply with them.