What is your HIPAA readiness score?
12questions you can answer from memory, about the requirements that decide whether a client’s security review stalls and how bad an incident gets. Your score and a written gap list appear as you answer — no email, no signup, and the scoring runs in your browser rather than on our servers.
Last reviewed .
Every question here cites the section of 45 CFR it comes from.
That is the test we hold this tool to: if a question cannot be tied to a citation, it is a sales prompt rather than a requirement, and it does not belong on the form. Answer honestly — a score you flattered is worth nothing to you, and nobody else ever sees it.
Answer the questions above and your score appears here. Nothing is sent anywhere — the scoring runs in your browser.
The same twelve questions, answered from your records instead of your memory.
Inside the product the assessment runs across all 68 Security Rule controls, each gap becomes a task with an owner and a date, and the evidence behind every answer is filed where you can hand it to a client in one link. 14 days free, no credit card, no sales call.
Common questions
- Do I have to give an email address to see my score?
- No. The score and the full gap list appear as soon as you answer, and the scoring runs entirely in your browser — nothing is sent anywhere unless you separately ask us to email you a copy. Gating a result somebody just produced is the pattern that makes these tools worthless, and this one is aimed at people who assess vendors for a living.
- Does a high score mean my organization is compliant?
- No, and no tool can tell you that. This scores twelve requirements; the Security Rule has considerably more, and compliance also depends on how well each safeguard is actually implemented in your environment. Treat a high score as a sign the foundations are there and a low one as a reliable signal that they are not.
- Which requirements does it cover?
- Risk analysis and risk management, written policies and workforce acknowledgement, security training records, business associate agreements and the vendor list behind them, multi-factor authentication, encryption at rest, access removal at offboarding, incident logging and the breach notification deadline, backup restore testing, and how quickly you could hand a client evidence. Each carries its CFR citation on the question.
- What should I do with the result?
- Work the gap list from the top — it is ordered by weight, not by the order of the questions. The heaviest items are the risk analysis, business associate agreements, multi-factor authentication and encryption, because those are the ones that change either your legal position or how bad an incident becomes, rather than only how it is documented.
Keep reading
- Vendor compliance checkerVerdicts on the tools small healthcare organizations actually run.
- HIPAA glossaryPlain-language definitions, each with its citation.
- HIPAA compliance checklistEvery requirement, in order, with the evidence that proves it.
- HIPAA to SOC 2 crosswalkAll 68 controls mapped to SOC 2 and NIST CSF, and the eight gaps.
- HIPAA training requirementsWho must be trained, how often, and what proof to keep.
- HIPAA compliance auditsThe three different things called an audit, and what each asks for.
- Practice management softwareHow to evaluate what a vendor is actually offering you.
- How we researchSourcing, review cadence and corrections policy.
- About the teamThe compliance officers, clinicians and security people behind the research.
Looking for the software rather than the explanation? HIPAA risk assessment software.
Want the long version? Every requirement, in order, with the evidence that proves it →
A self-assessment tool covering twelve of the Security Rule’s requirements, offered as general information. It is not an assessment of your organization and we do not provide legal advice. Your answers stay in your browser unless you ask us to email you a copy of the results.