Where does your program actually stand against the Security Rule?
36 questions6 sections15 to 20 minutesScored against the current Security Rule
Organization: —
—
of 60 · compliance
—
of 12 · prep
NOT SCORED
HIPAA Compliance Self-Assessment
What you get, and what it costs. Your compliance score, readiness level, and highest-priority gap appear immediately, free. Enter your email at the end for the complete domain-by-domain report, priority actions, and engagement plan.
Identify your compliance gaps in under 20 minutes. Answer each question based on your current state, not aspirational. Domains 1 through 5 score you against the Security Rule as it stands today and produce your compliance score out of 60. Domain 6 is a separate, advisory section covering the proposed 2026 Security Rule changes. Those changes are not final; the Fall 2026 Unified Agenda moved it to long-term actions with July 2027 as the target. Domain 6 is reported separately and does not affect your compliance score or readiness tier.
Estimated time: 15-20 minutes
Organization Information
How to score:
0No, not in place
1Partially, in progress or informal
2Yes, fully documented and implemented
Domain 1 — Risk Analysis & Management
45 C.F.R. § 164.308(a)(1) | Max 12 points
0
/ 12
1.1Formal written HIPAA Security Risk Analysis completed within past 12 months
1.2Risk analysis is built from a current technology asset inventory and network map documenting all systems that create, receive, maintain, or transmit ePHI, including cloud, mobile, and third-party
1.3Written risk management plan exists that prioritizes and tracks remediation of identified risks
1.4Risk analysis is reviewed and updated when operations, technology, or regulations change
1.5Risk analysis results have been presented to and acknowledged by leadership or the board
1.6Risk analysis covers third-party vendors (Business Associates) as part of the overall risk picture
Domain 2 — Access Controls & Audit Controls
45 C.F.R. §§ 164.312(a)(1), 164.312(b) | Max 12 points
0
/ 12
2.1Documented role-based access controls for all ePHI systems
2.2Access to ePHI provisioned and de-provisioned through formal documented process, not ad hoc
2.3Unique user IDs for all workforce members, no shared credentials for PHI system access
2.4Automatic logoff implemented on workstations and systems with ePHI access
2.5Audit logs for ePHI access maintained and reviewed on a documented schedule
2.6Physical safeguards documented for workstations, servers, and facilities with ePHI
Domain 3 — Business Associate Agreements
45 C.F.R. § 164.504(e) | Max 12 points
0
/ 12
3.1Current written inventory of all Business Associates (vendors who handle PHI on your behalf)
3.2Signed, current BAA on file for every Business Associate
3.3BAAs reviewed and updated when vendor relationships or HIPAA requirements change
3.4Security posture of Business Associates is assessed before signing a BAA
3.5Subcontractor relationships tracked, you know which BAs use subcontractors to handle your PHI
3.6Process in place to receive and act on breach notifications from Business Associates
Advisory only · not scored toward compliance · Max 12 points
0
/ 12
This section is not law. These items come from the proposed Security Rule changes published January 6, 2025 at 90 Fed. Reg. 898. That rulemaking is not final and the Fall 2026 Unified Agenda moved it to long-term actions with July 2027 as the target. Nothing here is required today, and your score in this section does not affect your compliance score or readiness tier. It is here because most of this work is reachable under the current rule's existing requirements, so it counts either way.
6.1Written technology asset inventory maintained listing all hardware, software, and cloud systems that create, receive, maintain, or transmit ePHI, with ownership and data classification noted
6.2Current network map documenting ePHI data flows, segmentation boundaries, and system interconnections, updated when architecture changes
6.3Multi-factor authentication implemented on all systems and applications used to access ePHI. Currently addressable under 45 C.F.R. § 164.312(a)(2)(i); the proposal would make it required.
6.4ePHI encrypted at rest using current NIST-approved cryptographic standards. Currently addressable under 45 C.F.R. § 164.312(a)(2)(iv); the proposal would make it required.
6.5ePHI encrypted in transit across all networks and communication channels. Currently addressable under 45 C.F.R. § 164.312(e)(2)(ii); the proposal would make it required.
6.6Vulnerability scanning on a documented schedule, annual penetration testing, and a patch management process with remediation tracked
—
out of 60 · current Security Rule
—
—
Reported separately · advisory
Preparatory readiness: — of 12
—
Get your full report
You have your compliance score and your biggest gap. The full report shows every domain, the specific action behind each one, your top three priorities, and a service-matched engagement plan.
All five compliance domains scored, plus the preparatory section
Your top three priority areas with specific remediation actions
Effort estimates and a recommended engagement path
Printable report for your compliance file
JHarris Advisory LLC provides consulting services, not legal services. It is not a law firm, and submitting this form does not create an attorney-client relationship. Your assessment answers stay in your browser; only what you type above is sent. Do not enter PHI anywhere on this page.
Build this into your HIPAA compliance program
This assessment shows you where the gaps are. The HIPAA Compliance Toolkit gives you the policy templates, BAA tracker, breach response plan, and training materials to close them.