HIPAA Risk Assessment Tool
Review HIPAA safeguard questions, then plan the follow-up.
Answer a short set of questions drawn straight from the HIPAA Security Rule safeguards. Get a self-check percentage across administrative, physical, technical, and documentation prompts, with a Not applicable choice and a follow-up list tied to cited regulations. The tool is educational and does not replace a formal risk analysis. Free, private, and no account required.
The assessment
Answer honestly and the self-check updates as you go
This self-assessment is an educational starting point built from the HIPAA Security Rule safeguard standards and core Privacy Rule duties. It does not replace the formal, written risk analysis the rule requires at 45 CFR 164.308(a)(1), and it is not legal advice. Use it to organize questions for follow-up, then document a complete risk analysis and risk management process.
What it covers
Six things this HIPAA risk assessment does for you
Administrative
Risk analysis, people, and process
Review risk analysis, risk management, workforce training, named officials, access control, business associate agreements, and contingency planning.
Physical
Facilities, workstations, and devices
Who can physically reach systems and records, how workstations are used, and how devices and media are tracked and wiped before disposal.
Technical
Access, encryption, and audit controls
Unique logins, risk-based authentication, audit controls, and documented decisions for addressable encryption and automatic-logoff specifications.
Documentation
Policies, breach readiness, and evidence
Written policies, breach-response procedures, applicable covered-entity privacy duties, and dated records for authorized review.
Prioritized output
A follow-up list you can act on
Answers marked partly, no, or not sure become a numbered follow-up list. Not-applicable answers are excluded from scoring and follow-up.
Training follow-up
Document the training work
When a training answer needs follow-up, identify the people and duties involved, assign role-relevant instruction, and retain completion records.
The full picture
How a HIPAA risk assessment works, and how to act on yours
What a HIPAA risk assessment actually is
A HIPAA risk assessment, often called a security risk analysis, is the structured process of finding where electronic protected health information could be exposed and deciding what to do about it. It is not optional and it is not paperwork for its own sake. The Security Rule requires it directly at 45 CFR 164.308(a)(1)(ii)(A), which requires covered entities and business associates subject to the Security Rule to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI they hold. That analysis informs the organization's safeguard and risk-management decisions.
The tool above is a fast way to take that idea and turn it into a concrete baseline. It asks about cited safeguards, summarizes your self-reported answers, and shows which items need follow-up. It cannot identify all assets, threats, vulnerabilities, likelihoods, or impacts in your environment, so it does not replace the written, organization-wide risk analysis the rule requires. Treat the output as a triage list for the formal analysis, not as a compliance or risk determination.
Why a documented analysis matters
The Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities to ePHI. A written analysis helps the organization connect its asset inventory and threat review to specific risk-management decisions. It also creates a dated record of the scope, assumptions, findings, owners, and remediation work that authorized reviewers can examine later.
There is a practical reason too. You cannot prioritize risks you have not identified. Examples may include an unencrypted laptop, a former worker's active account, a business associate relationship without the required agreement, or an untested backup. A formal analysis evaluates those facts in context. The checklist percentage above simply helps organize the first questions.
The administrative safeguards
Administrative safeguards are the policies, processes, and people side of HIPAA security. They begin with the risk analysis and risk management process at 164.308(a)(1), which require the organization to assess and reduce risks. They include a security awareness and training program at 164.308(a)(5), assignment of a security official at 164.308(a)(2), workforce access management at 164.308(a)(3) and (a)(4), business associate arrangements at 164.308(b), and contingency planning at 164.308(a)(7).
A weak answer in this category can point to different work. Naming a security official, reviewing access, documenting business associate arrangements, training the workforce, and testing contingency procedures each address a different requirement. Assign owners and evidence to each applicable item instead of treating one completed task as a substitute for the rest.
The physical safeguards
Physical safeguards govern the tangible world: who can physically reach the systems and records that hold ePHI, how workstations are used, and how devices and media are handled over their lifecycle. Facility access controls at 164.310(a) cover locks, badges, and visitor logs for server rooms, network closets, and records storage. Workstation use and security at 164.310(b) and (c) cover positioning screens away from public view and locking them when staff step away. Device and media controls at 164.310(d) cover tracking hardware and securely wiping or destroying it before reuse or disposal.
Physical controls address risks that software controls alone cannot resolve. Examples include media disposed of without proper handling, devices that retain ePHI, or unattended workstations visible to unauthorized people. Use answers in this category to investigate facility controls, workstation policies, and device or media procedures in the context of your environment.
The technical safeguards
Technical safeguards are controls built into systems. Access control at 164.312(a) includes the required unique-user-identification specification. Automatic logoff at 164.312(a)(2)(iii) is addressable, so the organization follows the documented process in 164.306(d) to implement it or select an equivalent measure when reasonable and appropriate. Authentication at 164.312(d) requires procedures to verify identity. Multi-factor authentication can be an appropriate risk-based control, but HIPAA does not name it as a universal requirement. Audit controls at 164.312(b) require mechanisms that record and examine activity in systems containing or using ePHI.
Encryption at rest under 164.312(a)(2)(iv) and transmission encryption under 164.312(e)(2)(ii) are addressable specifications. The organization must evaluate each one under 164.306(d), document the decision, and implement an equivalent measure when reasonable and appropriate if it does not implement the specification. For breach purposes, ePHI is treated as unreadable only when the HHS-specified method applies and the key or process needed to decrypt it has not been compromised. Review unique IDs, authentication, encryption, logoff, and audit controls against the documented risks.
Documentation and breach readiness
The Security Rule requires written policies and procedures and retention of required documentation for six years under 164.316. Breach procedures should support notice without unreasonable delay and within the applicable federal outer limit. The Notice of Privacy Practices and access prompts concern covered-entity Privacy Rule duties and can be marked Not applicable when they do not fit the organization's role or circumstances.
HIPAA contains specific documentation duties, and dated records help an organization explain what it did and when. That is why the tool counts documentation as its own safeguard area rather than folding it into the others. If answers need follow-up, identify which actions require written policies, decisions, or completion records and store that evidence where authorized reviewers can retrieve it.
How to read your score
The overall percentage is based only on applicable prompts you answered yes, partly, no, or not sure. Not-applicable answers are excluded. A score at or above eighty percent means your answers identify fewer unresolved prompts, while a score between fifty-five and seventy-nine percent leaves several partial or missing items. A score below fifty-five percent leaves many answers missing or uncertain. None of these bands measures likelihood, impact, overall risk, or compliance. Use the percentage to organize follow-up, then verify scope, evidence, threats, vulnerabilities, and risk in the formal analysis.
The category bars show how your answers are distributed, not where an incident will occur. Read them to find groups with more missing or uncertain answers, then investigate the listed items and document what the formal analysis finds. Because the self-check recalculates instantly, you can revisit it as an organizational aid after remediation.
Turning the assessment into a real risk analysis
The self-check is a starting point, not the finished product the rule requires. To build a documented risk analysis, begin with an inventory of where ePHI is created, received, stored, and transmitted, including systems, devices, vendors, and workflows. A risk analysis that starts from a real inventory is far stronger than one that starts from a form. Then investigate applicable follow-up items by documenting the threat, current control, likelihood, impact, and any resulting risk-management decision.
Next, convert confirmed findings into a tracked remediation plan with an owner and a due date for each item, which is the risk management step at 164.308(a)(1)(ii)(B). Without owners and dates, a list of risks is just awareness, and awareness alone reduces no exposure. Finally, set a documented review cadence based on your environment and revisit the analysis when material changes affect systems, vendors, staffing, or work location. Keep every version dated so reviewers can follow the analysis and remediation history.
Covered entities and business associates both need this
The Security Rule risk-analysis duty applies to covered entities and business associates. Business-associate status depends on the function or service performed, the handling of PHI on behalf of a covered entity or business associate, and the exceptions in 45 CFR 160.103. Organizations that meet the definition have direct Security Rule duties, including the risk-analysis requirement, in addition to applicable contractual obligations.
Organization size, complexity, capabilities, costs, and risks inform reasonable and appropriate safeguard decisions under 164.306(b). The duty to perform the analysis remains, while its scope and supporting inventory reflect the organization's systems and ePHI. Use Not applicable for role-specific Privacy Rule prompts that do not fit, not as a substitute for evaluating Security Rule safeguards.
Common mistakes that weaken an assessment
A few predictable errors make a risk assessment look complete while leaving the organization exposed. The first is scoping too narrowly, assessing the electronic health record but ignoring email, messaging, spreadsheets, personal devices, and the vendors that quietly hold copies of the same data. Risk lives in the places people forget. The second is treating the assessment as a one-time event, filing it, and never revisiting it after new systems, vendors, or remote-work changes reshape the risk picture. A two-year-old analysis often describes an organization that no longer exists.
The third mistake is stopping at awareness. Finding risks and never assigning owners or due dates leaves the risk-management work incomplete. The fourth is confusing a vendor's compliance with your own. A platform being HIPAA-capable does not make your configuration of it compliant, and a signed business associate agreement does not absolve you of your own safeguards. The fifth is keeping no dated evidence, so even genuine diligence cannot be documented later. The tool supports a safeguard-by-safeguard review and turns partial, negative, or uncertain answers into an ordered follow-up list.
Where workforce training fits
The Security Rule requires a security awareness and training program for all workforce members of covered entities and business associates subject to the rule. The Privacy Rule separately requires covered entities to train workforce members on applicable policies and procedures. This tool flags an applicable training answer for follow-up so the organization can assign relevant instruction and retain required records.
Keep going
Guides and tools that build on your self-check
Free tool
HIPAA software compliance checklist
Building or operating software that touches PHI? Generate a cited Security Rule checklist tailored to your reported stack and controls.
Build your checklistRisk
HIPAA risk assessment guide
A walkthrough of how to scope and document the formal risk analysis required by the Security Rule.
Read the guideSecurity
HIPAA security rule
The administrative, physical, and technical safeguards behind every question in this tool, explained in plain English.
Study the ruleAudit
HIPAA self-audit checklist
A printable checklist to confirm each safeguard is documented, not just assumed, before an audit.
Open the checklistVendors
HIPAA vendor risk assessment
How to evaluate the business associates and third parties that touch PHI on your behalf.
Assess vendorsFree tool
Free HIPAA practice test
Check your team's knowledge of the rules with a scored practice exam and answer explanations.
Take the testFree tool
HIPAA certification cost calculator
Estimate individual or team course costs if your review identifies applicable workforce instruction.
Estimate costFree tool
HIPAA violation penalty calculator
See possible penalty exposure and why risk-analysis records may matter without guaranteeing a culpability tier.
Estimate penaltiesFree tool
Free HIPAA BAA generator
If a relationship meets the business-associate definition, build a draft agreement from the HHS sample provisions.
Generate a BAAFree tool
HIPAA breach notification deadline calculator
Enter a discovery date to calculate federal outer-limit dates and review which individual, HHS, or media rules may apply.
Review notice timingRisk assessment FAQ
Common questions about HIPAA risk assessments
Is this HIPAA risk assessment tool free?
Yes. The assessment is completely free, runs entirely in your browser, and requires no account or email. Answer the questions and you get a self-check percentage, a safeguard-by-safeguard breakdown, and a prioritized follow-up list. Nothing you enter leaves your device.
Does this replace a formal HIPAA risk analysis?
No, and it does not claim to. The HIPAA Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities at 45 CFR 164.308(a)(1)(ii)(A). This tool organizes self-reported answers to selected prompts. Use it for follow-up, then document a complete analysis and risk-management process.
What does the score actually measure?
Each prompt cites a HIPAA standard and assigns points to applicable yes, partly, no, or not sure answers. Not-applicable answers are excluded. The percentage summarizes only those self-reported answers. It does not measure threats, likelihood, impact, overall risk, or compliance.
Who should run this assessment?
Covered entities and business associates subject to the Security Rule can use the safeguard prompts. Covered-entity-only Privacy Rule prompts can be marked Not applicable by a business associate or when the cited duty does not fit the user's role or circumstances.
Why does workforce training keep coming up?
Because the Security Rule requires a security awareness and training program for all workforce members at 45 CFR 164.308(a)(5). If the training answer needs follow-up, identify the applicable duty, assign relevant instruction, and keep required records.
How often should we reassess our HIPAA risk?
HIPAA does not prescribe a universal annual schedule. Review risk on a documented cadence appropriate to your environment and when material changes occur, such as new systems, vendors, work locations, or a security incident. Re-running this educational tool can help track remediation, but it does not replace the formal analysis.
Review the cited requirements and document the resulting decisions. If workforce instruction is applicable, compare individual courses or plan an organization rollout.
Primary sources: 45 CFR 164.306 explains required and addressable specifications, 45 CFR 164.308 covers administrative safeguards, and 45 CFR 164.312 covers technical safeguards. HHS also publishes breach-notification encryption guidance.
From self-check to follow-up