HIPAA Compliance Self-Assessment | JHarris Advisory

HIPAA Compliance Self-Assessment

What you get, and what it costs. Your compliance score, readiness level, and highest-priority gap appear immediately, free. Enter your email at the end for the complete domain-by-domain report, priority actions, and engagement plan.

Identify your compliance gaps in under 20 minutes. Answer each question based on your current state, not aspirational. Domains 1 through 5 score you against the Security Rule as it stands today and produce your compliance score out of 60. Domain 6 is a separate, advisory section covering the proposed 2026 Security Rule changes. Those changes are not final; the Fall 2026 Unified Agenda moved it to long-term actions with July 2027 as the target. Domain 6 is reported separately and does not affect your compliance score or readiness tier.

Estimated time: 15-20 minutes

Organization Information

How to score:
0 No, not in place
1 Partially, in progress or informal
2 Yes, fully documented and implemented

Domain 1 — Risk Analysis & Management

45 C.F.R. § 164.308(a)(1) | Max 12 points
0
/ 12
1.1Formal written HIPAA Security Risk Analysis completed within past 12 months
1.2Risk analysis is built from a current technology asset inventory and network map documenting all systems that create, receive, maintain, or transmit ePHI, including cloud, mobile, and third-party
1.3Written risk management plan exists that prioritizes and tracks remediation of identified risks
1.4Risk analysis is reviewed and updated when operations, technology, or regulations change
1.5Risk analysis results have been presented to and acknowledged by leadership or the board
1.6Risk analysis covers third-party vendors (Business Associates) as part of the overall risk picture

Domain 2 — Access Controls & Audit Controls

45 C.F.R. §§ 164.312(a)(1), 164.312(b) | Max 12 points
0
/ 12
2.1Documented role-based access controls for all ePHI systems
2.2Access to ePHI provisioned and de-provisioned through formal documented process, not ad hoc
2.3Unique user IDs for all workforce members, no shared credentials for PHI system access
2.4Automatic logoff implemented on workstations and systems with ePHI access
2.5Audit logs for ePHI access maintained and reviewed on a documented schedule
2.6Physical safeguards documented for workstations, servers, and facilities with ePHI

Domain 3 — Business Associate Agreements

45 C.F.R. § 164.504(e) | Max 12 points
0
/ 12
3.1Current written inventory of all Business Associates (vendors who handle PHI on your behalf)
3.2Signed, current BAA on file for every Business Associate
3.3BAAs reviewed and updated when vendor relationships or HIPAA requirements change
3.4Security posture of Business Associates is assessed before signing a BAA
3.5Subcontractor relationships tracked, you know which BAs use subcontractors to handle your PHI
3.6Process in place to receive and act on breach notifications from Business Associates

Domain 4 — Breach Response Procedures

45 C.F.R. § 164.400 et seq. | Max 12 points
0
/ 12
4.1Written breach response policy covering four-factor risk assessment, notification requirements, and timelines
4.2Breach response team designated with roles and current contact information documented
4.3Breach response procedures tested through a tabletop exercise within the past 24 months
4.4All prior reportable breaches were reported to HHS OCR and affected individuals on time
4.5Breach log maintained for incidents affecting fewer than 500 individuals
4.6After-action reviews conducted following any breach or near-miss, with findings incorporated into the program

Domain 5 — Workforce Training & Sanction Policy

45 C.F.R. §§ 164.308(a)(5), 164.530(b), (e) | Max 12 points
0
/ 12
5.1All workforce members with PHI access receive HIPAA training at hire and at least annually
5.2Training content is current and addresses breach notification, minimum necessary, and the Security Rule
5.3Role-specific training provided for high-risk roles (clinical staff, billing, IT, reception)
5.4Written sanction policy exists describing consequences for workforce HIPAA violations
5.5Sanctions documented and applied consistently when violations occur
5.6New employees complete HIPAA training before accessing PHI

Domain 6 — Preparatory: Proposed Security Rule Changes

Advisory only · not scored toward compliance · Max 12 points
0
/ 12
This section is not law. These items come from the proposed Security Rule changes published January 6, 2025 at 90 Fed. Reg. 898. That rulemaking is not final and the Fall 2026 Unified Agenda moved it to long-term actions with July 2027 as the target. Nothing here is required today, and your score in this section does not affect your compliance score or readiness tier. It is here because most of this work is reachable under the current rule's existing requirements, so it counts either way.
6.1Written technology asset inventory maintained listing all hardware, software, and cloud systems that create, receive, maintain, or transmit ePHI, with ownership and data classification noted
6.2Current network map documenting ePHI data flows, segmentation boundaries, and system interconnections, updated when architecture changes
6.3Multi-factor authentication implemented on all systems and applications used to access ePHI. Currently addressable under 45 C.F.R. § 164.312(a)(2)(i); the proposal would make it required.
6.4ePHI encrypted at rest using current NIST-approved cryptographic standards. Currently addressable under 45 C.F.R. § 164.312(a)(2)(iv); the proposal would make it required.
6.5ePHI encrypted in transit across all networks and communication channels. Currently addressable under 45 C.F.R. § 164.312(e)(2)(ii); the proposal would make it required.
6.6Vulnerability scanning on a documented schedule, annual penetration testing, and a patch management process with remediation tracked
out of 60 · current Security Rule
Reported separately · advisory
Preparatory readiness: — of 12

Get your full report

You have your compliance score and your biggest gap. The full report shows every domain, the specific action behind each one, your top three priorities, and a service-matched engagement plan.

  • All five compliance domains scored, plus the preparatory section
  • Your top three priority areas with specific remediation actions
  • Effort estimates and a recommended engagement path
  • Printable report for your compliance file
JHarris Advisory LLC provides consulting services, not legal services. It is not a law firm, and submitting this form does not create an attorney-client relationship. Your assessment answers stay in your browser; only what you type above is sent. Do not enter PHI anywhere on this page.
Build this into your HIPAA compliance program

This assessment shows you where the gaps are. The HIPAA Compliance Toolkit gives you the policy templates, BAA tracker, breach response plan, and training materials to close them.

FEATURED GUIDE

HIPAA Security Rule NPRM: What's Proposed, What It Means, and What to Do Now

The complete readiness guide — proposed changes, 30/60/90-day plan, evidence checklist, and free assessment. Updated June 2026.
Read the Guide →

Read the complete hipaa readiness guide