CompyMax

What is your HIPAA readiness score?

12questions you can answer from memory, about the requirements that decide whether a client’s security review stalls and how bad an incident gets. Your score and a written gap list appear as you answer — no email, no signup, and the scoring runs in your browser rather than on our servers.

Last reviewed .

Every question here cites the section of 45 CFR it comes from.

That is the test we hold this tool to: if a question cannot be tied to a citation, it is a sales prompt rather than a requirement, and it does not belong on the form. Answer honestly — a score you flattered is worth nothing to you, and nobody else ever sees it.

  1. 1.Have you completed a written security risk analysis in the last 12 months?

    45 CFR 164.308(a)(1)(ii)(A)

  2. 2.Do you track the gaps that assessment found, with an owner and a date for each?

    45 CFR 164.308(a)(1)(ii)(B)

  3. 3.Do you have written HIPAA policies that your staff have actually read and acknowledged?

    45 CFR 164.316(a)-(b)

  4. 4.Has everyone who touches patient information completed security training in the last year, with a record of it?

    45 CFR 164.308(a)(5)(i)

  5. 5.Do you have a signed business associate agreement with every vendor that touches patient information?

    45 CFR 164.308(b)(1), 164.502(e)

  6. 6.Could you produce a list of every vendor that holds your patient information today?

    45 CFR 164.308(a)(1)(ii)(A)

  7. 7.Is multi-factor authentication turned on for email and every system holding patient information?

    45 CFR 164.312(d)

  8. 8.Is patient information encrypted on laptops, backups and anywhere else it is stored?

    45 CFR 164.312(a)(2)(iv), 164.402

  9. 9.When someone leaves, is their access removed the same day — including from vendor systems?

    45 CFR 164.308(a)(3)(ii)(C)

  10. 10.Do you have a written incident log, and does anyone know the 60-day notification deadline?

    45 CFR 164.308(a)(6), 164.404, 164.410

  11. 11.Have you tested restoring from backup in the last year?

    45 CFR 164.308(a)(7)(ii)(A)-(B)

  12. 12.If a client asked today for evidence of your HIPAA programme, how long would it take to send?

    45 CFR 164.316(b)(2)

Answer the questions above and your score appears here. Nothing is sent anywhere — the scoring runs in your browser.

The same twelve questions, answered from your records instead of your memory.

Inside the product the assessment runs across all 68 Security Rule controls, each gap becomes a task with an owner and a date, and the evidence behind every answer is filed where you can hand it to a client in one link. 14 days free, no credit card, no sales call.

Common questions

Do I have to give an email address to see my score?
No. The score and the full gap list appear as soon as you answer, and the scoring runs entirely in your browser — nothing is sent anywhere unless you separately ask us to email you a copy. Gating a result somebody just produced is the pattern that makes these tools worthless, and this one is aimed at people who assess vendors for a living.
Does a high score mean my organization is compliant?
No, and no tool can tell you that. This scores twelve requirements; the Security Rule has considerably more, and compliance also depends on how well each safeguard is actually implemented in your environment. Treat a high score as a sign the foundations are there and a low one as a reliable signal that they are not.
Which requirements does it cover?
Risk analysis and risk management, written policies and workforce acknowledgement, security training records, business associate agreements and the vendor list behind them, multi-factor authentication, encryption at rest, access removal at offboarding, incident logging and the breach notification deadline, backup restore testing, and how quickly you could hand a client evidence. Each carries its CFR citation on the question.
What should I do with the result?
Work the gap list from the top — it is ordered by weight, not by the order of the questions. The heaviest items are the risk analysis, business associate agreements, multi-factor authentication and encryption, because those are the ones that change either your legal position or how bad an incident becomes, rather than only how it is documented.

Want the long version? Every requirement, in order, with the evidence that proves it →

A self-assessment tool covering twelve of the Security Rule’s requirements, offered as general information. It is not an assessment of your organization and we do not provide legal advice. Your answers stay in your browser unless you ask us to email you a copy of the results.