Identify your compliance gaps in under 20 minutes. Answer each question honestly based on your current state — not aspirational. Results generate a prioritized action list and show where JHarris Advisory can help. Updated for the 2026 HIPAA Security Rule Final Rule — includes new mandatory controls for asset inventory, MFA, encryption, and vulnerability management.
Estimated time: 15-20 minutes
Organization Information
How to score:
0No — not in place
1Partially — in progress or informal
2Yes — fully documented and implemented
Domain 1 — Risk Analysis & Management
45 CFR §164.308(a)(1) | Max 12 points
0
/ 12
1.1Formal written HIPAA Security Risk Analysis completed within past 12 months
1.2Risk analysis is built from a current technology asset inventory and network map documenting all systems that create, receive, maintain, or transmit ePHI (including cloud, mobile, and third-party) — required under 2026 Security Rule
1.3Written risk management plan exists that prioritizes and tracks remediation of identified risks
1.4Risk analysis is reviewed and updated when operations, technology, or regulations change
1.5Risk analysis results have been presented to and acknowledged by leadership or the board
1.6Risk analysis covers third-party vendors (Business Associates) as part of the overall risk picture
Domain 2 — Access Controls & Audit Controls
45 CFR §§164.312(a)(1), 164.312(b) | Max 12 points
0
/ 12
2.1Documented role-based access controls for all ePHI systems
2.2Access to ePHI provisioned and de-provisioned through formal documented process (not ad hoc)
2.3Unique user IDs for all workforce members — no shared credentials for PHI system access
2.4Automatic logoff implemented on workstations and systems with ePHI access
2.5Audit logs for ePHI access maintained and reviewed on a documented schedule
2.6Physical safeguards documented for workstations, servers, and facilities with ePHI
Domain 3 — Business Associate Agreements
45 CFR §164.504(e) | Max 12 points
0
/ 12
3.1Current written inventory of all Business Associates (vendors who handle PHI on your behalf)
3.2Signed, current BAA on file for every Business Associate
3.3BAAs reviewed and updated when vendor relationships or HIPAA requirements change
3.4Security posture of Business Associates is assessed before signing a BAA
3.5Subcontractor relationships tracked — you know which BAs use subcontractors to handle your PHI
3.6Process in place to receive and act on breach notifications from Business Associates
45 CFR §§164.312(a)(2)(iv), 164.312(e)(2)(ii), 164.312(a)(1) | Max 12 points | NEW — Final Rule effective 2026
0
/ 12
6.1Written technology asset inventory maintained listing all hardware, software, and cloud systems that create, receive, maintain, or transmit ePHI — with ownership and data classification noted
6.2Current network map documenting ePHI data flows, network segmentation boundaries, and system interconnections — updated when architecture changes
6.3Multi-factor authentication (MFA) implemented on all systems and applications used to access ePHI — MFA is now a required standard under the 2026 final rule, not addressable
6.4ePHI encrypted at rest on all applicable systems using current NIST-approved cryptographic standards — encryption at rest is now required, not addressable
6.5ePHI encrypted in transit across all networks and communication channels — encryption in transit is now required, not addressable; exceptions must be documented
6.6Vulnerability scanning conducted on all ePHI systems on a documented schedule; penetration testing performed at least annually; patch management process in place with remediation tracked and documented
—
out of 72
—
—
Domain Breakdown
Your Top 3 Priority Areas
What JHarris Advisory Can Help With
Based on your assessment results, here are the specific services most relevant to your situation.
Build this into your HIPAA compliance program
This assessment shows you where the gaps are. The HIPAA Compliance Toolkit gives you the policy templates, BAA tracker, breach response plan, training materials, and 2026 Security Rule technical safeguard checklists to close them.