Free · no signup · no PHI
Where does your practice actually stand on the HIPAA Security Rule?
Twelve questions drawn from the same safeguard catalog our paid analysis scores. You get a readiness score, the gaps in priority order, and the citation behind each one. Nothing is emailed, stored, or sent anywhere — the whole check runs in your browser.
This is a self-check, not a security risk analysis. The Security Rule requires an accurate and thorough documented assessment of risks to all ePHI. Twelve questions cannot satisfy that, and this page is not legal advice, an audit opinion, or a compliance certification.
0 of 12 answered
- 1Security management process
Has the practice documented a risk analysis covering the confidentiality, integrity, and availability of every form and location of ePHI it creates, receives, maintains, or transmits?
45 CFR 164.308(a)(1)(ii)(A); HHS Guidance on Risk Analysis
- 2Assigned security responsibility
Has one accountable security official been identified with documented authority and responsibility for Security Rule policies and safeguards?
45 CFR 164.308(a)(2)
- 3Risk management
Does the practice maintain a documented risk-management plan that prioritizes risks, assigns owners and dates, and tracks treatment or accepted residual risk?
45 CFR 164.308(a)(1)(ii)(B)
- 4Workforce authorization
Is workforce access to ePHI authorized according to role, minimum necessary job duties, and current employment status?
45 CFR 164.308(a)(3); 164.308(a)(4)
- 5Termination and transfer
Does a tested process promptly remove or modify physical and electronic access when workforce members terminate or change roles?
45 CFR 164.308(a)(3)(ii)(C); 164.310(a)(2)(iii)
- 6Security awareness and training
Do all workforce members receive security training at onboarding and periodically, with attendance and content retained?
45 CFR 164.308(a)(5)(i)
- 7Data backup plan
Are retrievable exact copies of ePHI created on a defined schedule, protected from alteration, and monitored for success?
45 CFR 164.308(a)(7)(ii)(A)
- 8Business associate management
Are all vendors that create, receive, maintain, or transmit ePHI identified, covered by appropriate agreements, and periodically reviewed?
45 CFR 164.308(b); 164.314(a)
- 9Device and media accountability
Are devices and electronic media containing ePHI inventoried and tracked through receipt, movement, reassignment, repair, and disposal?
45 CFR 164.310(d)(1); 164.310(d)(2)(iii)
- 10Encryption and decryption
Is ePHI encrypted at rest on servers, endpoints, removable media, backups, and supported mobile devices, with keys appropriately managed?
45 CFR 164.312(a)(2)(iv); 164.306(d)
- 11Audit controls
Do information systems record access and activity involving ePHI with enough detail for review and investigation?
45 CFR 164.312(b)
- 12Transmission security
Is ePHI protected against unauthorized access and improper modification whenever transmitted over electronic networks?
45 CFR 164.312(e)
Common questions
- Does the free federal SRA Tool not already do this?
- The ONC/HHS Security Risk Assessment Tool is free, thorough, and worth using. Most small practices stall on it for the same reason they stall on any long questionnaire: it produces a completed questionnaire, and the work that follows — prioritising, assigning, evidencing, and keeping it current — is still theirs to organise. That follow-through is what our paid workspace is for.
- How often does the analysis have to be done?
- The Security Rule requires the analysis to be accurate and current, and requires review when operations, technology, or the environment materially change (45 CFR 164.308(a)(8), 164.306(e)). For clinicians in MIPS, the Promoting Interoperability category also requires conducting or reviewing a security risk analysis during the performance year. Confirm your own obligations — this page is not legal advice.
- Do you see my answers?
- No. The check runs entirely in your browser. Nothing is submitted, emailed, or stored, and no patient information is requested at any point — here or in the paid workspace.