Free tool

Where does your HIPAA program actually stand?

24 questions. About eight minutes. You get a scored report with your gaps ranked by risk and the rule citation for each one. No call required.

0 of 24 answered

01 Which describes you?
02 Do you have a written inventory of every system that creates, receives, maintains, or transmits ePHI? §164.308(a)(1)
03 Do you have documented data flow diagrams showing where ePHI moves?
04 Have you completed a risk analysis in the last 12 months? §164.308(a)(1)(ii)(A)
05 Is your risk analysis asset-based (threats paired to specific systems), not a questionnaire score?
06 Do you maintain a risk register with owners, treatment decisions, and target dates? §164.308(a)(1)(ii)(B)
07 For each accepted risk, is there a written rationale with a named approver and a review date?
08 Have you formally designated a Security Officer? §164.308(a)(2)
09 Have you formally designated a Privacy Officer? §164.530(a)
10 Do you have a written sanction policy that has actually been applied? §164.308(a)(1)(ii)(C)
11 Do you have a current, complete policy set covering the Security, Privacy, and Breach Notification Rules?
12 Can you show who acknowledged which *version* of each policy, with a timestamp?
13 Has every workforce member — including contractors — completed HIPAA training in the last 12 months? §164.308(a)(5)
14 Is training role-based (clinical, engineering, billing, front desk) rather than one generic course?
15 Does every user have a unique login, with no shared accounts on ePHI systems? §164.312(a)(2)(i)
16 Is MFA enforced on every system holding or reaching ePHI?
17 Do you run documented access reviews at least annually, with attestation records?
18 Are accounts deprovisioned within one business day of termination? §164.308(a)(3)(ii)(C)
19 Is ePHI encrypted at rest and in transit everywhere, including backups and endpoints? §164.312(a)(2)(iv)
20 Do you record AND periodically review audit logs on ePHI systems? §164.312(b)
21 Have you tested a restore from backup in the last 12 months? §164.308(a)(7)
22 Do you have a signed, current BAA for every vendor that touches ePHI? §164.308(b)(1)
23 Do you assess vendor risk at least annually for ePHI-handling vendors?
24 Do you have a documented breach risk assessment procedure using the four-factor test? §164.402