JHA-HC-BD-02 | HIPAA Compliance Self-Assessment

HIPAA Compliance Self-Assessment

Identify your compliance gaps in under 20 minutes. Answer each question honestly based on your current state — not aspirational. Results generate a prioritized action list and show where JHarris Advisory can help. Updated for the 2026 HIPAA Security Rule Final Rule — includes new mandatory controls for asset inventory, MFA, encryption, and vulnerability management.

Estimated time: 15-20 minutes

Organization Information

How to score:
0 No — not in place
1 Partially — in progress or informal
2 Yes — fully documented and implemented

Domain 1 — Risk Analysis & Management

45 CFR §164.308(a)(1) | Max 12 points
0
/ 12
1.1 Formal written HIPAA Security Risk Analysis completed within past 12 months
1.2 Risk analysis is built from a current technology asset inventory and network map documenting all systems that create, receive, maintain, or transmit ePHI (including cloud, mobile, and third-party) — required under 2026 Security Rule
1.3 Written risk management plan exists that prioritizes and tracks remediation of identified risks
1.4 Risk analysis is reviewed and updated when operations, technology, or regulations change
1.5 Risk analysis results have been presented to and acknowledged by leadership or the board
1.6 Risk analysis covers third-party vendors (Business Associates) as part of the overall risk picture

Domain 2 — Access Controls & Audit Controls

45 CFR §§164.312(a)(1), 164.312(b) | Max 12 points
0
/ 12
2.1 Documented role-based access controls for all ePHI systems
2.2 Access to ePHI provisioned and de-provisioned through formal documented process (not ad hoc)
2.3 Unique user IDs for all workforce members — no shared credentials for PHI system access
2.4 Automatic logoff implemented on workstations and systems with ePHI access
2.5 Audit logs for ePHI access maintained and reviewed on a documented schedule
2.6 Physical safeguards documented for workstations, servers, and facilities with ePHI

Domain 3 — Business Associate Agreements

45 CFR §164.504(e) | Max 12 points
0
/ 12
3.1 Current written inventory of all Business Associates (vendors who handle PHI on your behalf)
3.2 Signed, current BAA on file for every Business Associate
3.3 BAAs reviewed and updated when vendor relationships or HIPAA requirements change
3.4 Security posture of Business Associates is assessed before signing a BAA
3.5 Subcontractor relationships tracked — you know which BAs use subcontractors to handle your PHI
3.6 Process in place to receive and act on breach notifications from Business Associates

Domain 4 — Breach Response Procedures

45 CFR §164.400 et seq. | Max 12 points
0
/ 12
4.1 Written breach response policy covering four-factor risk assessment, notification requirements, and timelines
4.2 Breach response team designated with roles and current contact information documented
4.3 Breach response procedures tested through a tabletop exercise within the past 24 months
4.4 All prior reportable breaches were reported to HHS OCR and affected individuals on time
4.5 Breach log maintained for incidents affecting fewer than 500 individuals
4.6 After-action reviews conducted following any breach or near-miss, with findings incorporated into the program

Domain 5 — Workforce Training & Sanction Policy

45 CFR §§164.308(a)(5), 164.530(b), (e) | Max 12 points
0
/ 12
5.1 All workforce members with PHI access receive HIPAA training at hire and at least annually
5.2 Training content is current and addresses breach notification, minimum necessary, and HIPAA Security Rule
5.3 Role-specific training provided for high-risk roles (clinical staff, billing, IT, reception)
5.4 Written sanction policy exists describing consequences for workforce HIPAA violations
5.5 Sanctions documented and applied consistently when violations occur
5.6 New employees complete HIPAA training before accessing PHI

Domain 6 — 2026 Security Rule: Mandatory Technical Safeguards

45 CFR §§164.312(a)(2)(iv), 164.312(e)(2)(ii), 164.312(a)(1) | Max 12 points | NEW — Final Rule effective 2026
0
/ 12
6.1 Written technology asset inventory maintained listing all hardware, software, and cloud systems that create, receive, maintain, or transmit ePHI — with ownership and data classification noted
6.2 Current network map documenting ePHI data flows, network segmentation boundaries, and system interconnections — updated when architecture changes
6.3 Multi-factor authentication (MFA) implemented on all systems and applications used to access ePHI — MFA is now a required standard under the 2026 final rule, not addressable
6.4 ePHI encrypted at rest on all applicable systems using current NIST-approved cryptographic standards — encryption at rest is now required, not addressable
6.5 ePHI encrypted in transit across all networks and communication channels — encryption in transit is now required, not addressable; exceptions must be documented
6.6 Vulnerability scanning conducted on all ePHI systems on a documented schedule; penetration testing performed at least annually; patch management process in place with remediation tracked and documented
out of 72

Domain Breakdown

Your Top 3 Priority Areas

What JHarris Advisory Can Help With

Based on your assessment results, here are the specific services most relevant to your situation.

Build this into your HIPAA compliance program

This assessment shows you where the gaps are. The HIPAA Compliance Toolkit gives you the policy templates, BAA tracker, breach response plan, training materials, and 2026 Security Rule technical safeguard checklists to close them.

FEATURED GUIDE

HIPAA Security Rule NPRM: What's Proposed, What It Means, and What to Do Now

The complete readiness guide — proposed changes, 30/60/90-day plan, evidence checklist, and free assessment. Updated June 2026.
Read the Guide →

Read the complete hipaa readiness guide