HIPAA Readiness Screening

How ready is your organization?

Answer nine questions to get a quick snapshot of your organization's HIPAA security readiness, including areas of strength and areas that may require additional attention.

9 Questions About 3 Minutes Immediate Results

Before You Begin

Answer based on what you can demonstrate.

This screening is designed to provide a quick picture of your organization's HIPAA security readiness. As you answer each question, consider all systems and devices that store, process, transmit, or access electronic protected health information (ePHI) — including workstations and laptops used to access cloud-hosted EHRs and other systems.

Could you provide evidence for your answer?

Answer based on what your organization can demonstrate, not simply what you believe is being done.

Evidence might include policies and procedures, training records, access-control documentation, system configurations, security-monitoring reports, audit logs, risk-analysis documentation, backup and recovery test results, Business Associate Agreements, or other records showing that a safeguard is actually implemented.

Training

Saying employees receive annual training is different from being able to show who completed the training, what they received, and when they completed it.

Monitoring

Saying systems are monitored is different from being able to produce recent logs, alerts, reports, or review records showing that monitoring actually occurs.

When in doubt, score yourself based on what you could demonstrate today.

Important

This is a preliminary readiness screening. It is not a HIPAA Security Risk Analysis, compliance audit, legal opinion, or determination that your organization is or is not HIPAA compliant.

About You

Tell us about your organization.

01

Security Risk Analysis

Has your organization completed a documented HIPAA Security Risk Analysis that evaluates risks and vulnerabilities to ePHI across your environment?

A HIPAA Security Risk Analysis evaluates potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI throughout the organization. A vulnerability scan or general IT security assessment alone is not a HIPAA Security Risk Analysis.
Security Risk Analysis
02

Security Policies & Procedures

Does your organization maintain documented HIPAA security policies and procedures that reflect how your organization actually protects ePHI?

HIPAA security policies and procedures should document how your organization implements and maintains its administrative, physical, and technical safeguards—not simply restate HIPAA requirements. Consider whether current documentation could be produced to demonstrate how these safeguards are actually implemented.
Security Policies and Procedures
03

Access & Authentication

Are systems and devices that store, process, transmit, or access ePHI protected by individual user accounts, appropriate access permissions, and strong authentication controls?

Include workstations, laptops, remote-access systems, cloud applications, EHR platforms, and other systems used to access ePHI—even when ePHI is not stored directly on the device. Consider whether account, permission, and authentication configurations could be demonstrated if requested.
Access and Authentication
04

Audit Controls & Security Monitoring

Does your organization log and review activity on systems and devices that store, process, transmit, or access ePHI to identify suspicious activity, security events, and unauthorized access?

Consider servers, workstations, laptops, EHR systems, cloud services, firewalls, remote-access systems, and other technology used to access ePHI. A workstation used to access a cloud-hosted EHR can still be relevant even if patient records are not stored locally.
Audit Controls and Security Monitoring
05

Encryption & Protection of ePHI

Is ePHI encrypted when stored and transmitted, including on systems and devices where ePHI may be stored locally?

Consider servers, databases, laptops, workstations, removable media, backups, email, file transfers, and network communications that may contain or transmit ePHI. Base your answer on encryption controls that can be verified rather than assumed.
Encryption and Protection of ePHI
06

Backup, Recovery & Availability

Does your organization maintain reliable backups and recovery procedures for systems and data necessary to maintain access to ePHI, and are those recovery procedures tested?

Consider ePHI and the systems necessary to make it available following hardware failure, ransomware, data loss, or another disruption. This may include servers, databases, cloud services, configuration data, and other critical systems.
Backup Recovery and Availability
07

Workforce Security & Training

Does your organization provide recurring HIPAA and security awareness training and maintain processes for managing workforce access to ePHI?

Consider security and HIPAA awareness training as well as how user access is granted, changed when responsibilities change, and promptly removed when workforce members leave. Training completion and access-management activity should be demonstrable rather than informal.
Workforce Security and Training
08

Physical Safeguards

Does your organization have physical safeguards in place to prevent unauthorized access to systems and devices that store, process, transmit, or access ePHI?

Consider facility access, server and network equipment, employee workstations, laptops, mobile devices, screen visibility, device placement, and the physical disposal or reuse of equipment that may contain or provide access to ePHI.
Physical Safeguards
09

Business Associates & Third-Party Risk

Does your organization identify and appropriately manage vendors and other third parties that create, receive, maintain, transmit, or otherwise have access to ePHI?

Consider EHR providers, IT and cybersecurity providers, cloud and hosting services, backup providers, billing companies, consultants, support vendors, and other organizations that may handle or have access to ePHI. A vendor does not necessarily need to store patient information to potentially qualify as a Business Associate.
Business Associates and Third-Party Risk

Get Your Results

See your HIPAA readiness score.

Your results will include an overall readiness score, individual scores for each area, identified strengths, and areas that may require additional attention.