HIPAA Readiness Screening
How ready is your organization?
Answer nine questions to get a quick snapshot of your organization's HIPAA security readiness, including areas of strength and areas that may require additional attention.
Before You Begin
Answer based on what you can demonstrate.
This screening is designed to provide a quick picture of your organization's HIPAA security readiness. As you answer each question, consider all systems and devices that store, process, transmit, or access electronic protected health information (ePHI) — including workstations and laptops used to access cloud-hosted EHRs and other systems.
Could you provide evidence for your answer?
Answer based on what your organization can demonstrate, not simply what you believe is being done.
Evidence might include policies and procedures, training records, access-control documentation, system configurations, security-monitoring reports, audit logs, risk-analysis documentation, backup and recovery test results, Business Associate Agreements, or other records showing that a safeguard is actually implemented.
Saying employees receive annual training is different from being able to show who completed the training, what they received, and when they completed it.
Saying systems are monitored is different from being able to produce recent logs, alerts, reports, or review records showing that monitoring actually occurs.
When in doubt, score yourself based on what you could demonstrate today.
This is a preliminary readiness screening. It is not a HIPAA Security Risk Analysis, compliance audit, legal opinion, or determination that your organization is or is not HIPAA compliant.