HIPAA Risk Assessment Tool

Review HIPAA safeguard questions, then plan the follow-up.

Answer a short set of questions drawn straight from the HIPAA Security Rule safeguards. Get a self-check percentage across administrative, physical, technical, and documentation prompts, with a Not applicable choice and a follow-up list tied to cited regulations. The tool is educational and does not replace a formal risk analysis. Free, private, and no account required.

18cited safeguard checks
4safeguard categories
0data leaves your browser

The assessment

Answer honestly and the self-check updates as you go

Each question names the HIPAA standard it maps to. Mark yes, partly, no, not sure, or not applicable, and review the resulting category breakdown and follow-up list.
0 of 18 answered
Administrative safeguards

Have you completed a written risk analysis covering every system that creates, receives, stores, or transmits ePHI?

45 CFR 164.308(a)(1)(ii)(A)

Is there a risk management process that tracks and addresses the risks the analysis identified, with owners and due dates?

45 CFR 164.308(a)(1)(ii)(B)

For the duties that apply to your organization, do you provide Privacy Rule training and a security awareness and training program?

45 CFR 164.530(b) and 164.308(a)(5)

Have you named a security official and, if you are a covered entity, a privacy official?

45 CFR 164.308(a)(2) and 164.530(a)

Are access rights granted by job role and revoked promptly when someone leaves or changes positions?

45 CFR 164.308(a)(3) and (a)(4)

Have you determined which vendor relationships meet the business-associate definition and put required agreements in place?

45 CFR 160.103, 164.308(b)(1), and 164.502(e)

Is there a contingency plan with required data backup and disaster recovery procedures, plus a documented decision for addressable testing and revision?

45 CFR 164.306(d) and 164.308(a)(7)
Physical safeguards

Are areas and systems that hold ePHI protected by physical access controls such as locks, badges, or visitor logs?

45 CFR 164.310(a)

Are workstations positioned and configured so unauthorized people cannot view PHI on screen?

45 CFR 164.310(b) and (c)

Do you track devices and media that hold ePHI and securely wipe or destroy them before reuse or disposal?

45 CFR 164.310(d)
Technical safeguards

Does every user have a unique ID, and have you selected authentication controls based on your risk analysis?

45 CFR 164.312(a)(2)(i) and (d)

Have you implemented encryption at rest and in transit, or documented why each addressable specification is not reasonable and appropriate and selected an equivalent measure when appropriate?

45 CFR 164.306(d), 164.312(a)(2)(iv), and (e)(2)(ii)

Do your systems log access to ePHI, and does someone actually review those audit logs?

45 CFR 164.312(b)

Have you implemented automatic logoff where reasonable and appropriate, or documented the addressable-specification decision and an equivalent measure when appropriate?

45 CFR 164.306(d) and 164.312(a)(2)(iii)
Policies and breach readiness

Do you maintain current written HIPAA policies and procedures, retained for at least six years?

45 CFR 164.316 and 164.530(j)

Is there a written breach notification process that supports notice without unreasonable delay and within the applicable federal outer limits?

45 CFR 164.404

If these covered-entity duties apply, do individuals receive the required Notice of Privacy Practices and have a process for access requests?

45 CFR 164.520 and 164.524

Do you keep dated records of training, risk analyses, and reviews that an authorized reviewer could inspect?

45 CFR 164.316(b) and 164.530(j)

This self-assessment is an educational starting point built from the HIPAA Security Rule safeguard standards and core Privacy Rule duties. It does not replace the formal, written risk analysis the rule requires at 45 CFR 164.308(a)(1), and it is not legal advice. Use it to organize questions for follow-up, then document a complete risk analysis and risk management process.

What it covers

Six things this HIPAA risk assessment does for you

The tool organizes cited prompts across the three Security Rule safeguard groups and related documentation, then identifies answers that need follow-up.

Administrative

Risk analysis, people, and process

Review risk analysis, risk management, workforce training, named officials, access control, business associate agreements, and contingency planning.

Physical

Facilities, workstations, and devices

Who can physically reach systems and records, how workstations are used, and how devices and media are tracked and wiped before disposal.

Technical

Access, encryption, and audit controls

Unique logins, risk-based authentication, audit controls, and documented decisions for addressable encryption and automatic-logoff specifications.

Documentation

Policies, breach readiness, and evidence

Written policies, breach-response procedures, applicable covered-entity privacy duties, and dated records for authorized review.

Prioritized output

A follow-up list you can act on

Answers marked partly, no, or not sure become a numbered follow-up list. Not-applicable answers are excluded from scoring and follow-up.

Training follow-up

Document the training work

When a training answer needs follow-up, identify the people and duties involved, assign role-relevant instruction, and retain completion records.

The full picture

How a HIPAA risk assessment works, and how to act on yours

A plain-English guide to the risk analysis the Security Rule requires, what each safeguard area means, and how to turn self-check answers into documented follow-up.

What a HIPAA risk assessment actually is

A HIPAA risk assessment, often called a security risk analysis, is the structured process of finding where electronic protected health information could be exposed and deciding what to do about it. It is not optional and it is not paperwork for its own sake. The Security Rule requires it directly at 45 CFR 164.308(a)(1)(ii)(A), which requires covered entities and business associates subject to the Security Rule to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI they hold. That analysis informs the organization's safeguard and risk-management decisions.

The tool above is a fast way to take that idea and turn it into a concrete baseline. It asks about cited safeguards, summarizes your self-reported answers, and shows which items need follow-up. It cannot identify all assets, threats, vulnerabilities, likelihoods, or impacts in your environment, so it does not replace the written, organization-wide risk analysis the rule requires. Treat the output as a triage list for the formal analysis, not as a compliance or risk determination.

Why a documented analysis matters

The Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities to ePHI. A written analysis helps the organization connect its asset inventory and threat review to specific risk-management decisions. It also creates a dated record of the scope, assumptions, findings, owners, and remediation work that authorized reviewers can examine later.

There is a practical reason too. You cannot prioritize risks you have not identified. Examples may include an unencrypted laptop, a former worker's active account, a business associate relationship without the required agreement, or an untested backup. A formal analysis evaluates those facts in context. The checklist percentage above simply helps organize the first questions.

The administrative safeguards

Administrative safeguards are the policies, processes, and people side of HIPAA security. They begin with the risk analysis and risk management process at 164.308(a)(1), which require the organization to assess and reduce risks. They include a security awareness and training program at 164.308(a)(5), assignment of a security official at 164.308(a)(2), workforce access management at 164.308(a)(3) and (a)(4), business associate arrangements at 164.308(b), and contingency planning at 164.308(a)(7).

A weak answer in this category can point to different work. Naming a security official, reviewing access, documenting business associate arrangements, training the workforce, and testing contingency procedures each address a different requirement. Assign owners and evidence to each applicable item instead of treating one completed task as a substitute for the rest.

The physical safeguards

Physical safeguards govern the tangible world: who can physically reach the systems and records that hold ePHI, how workstations are used, and how devices and media are handled over their lifecycle. Facility access controls at 164.310(a) cover locks, badges, and visitor logs for server rooms, network closets, and records storage. Workstation use and security at 164.310(b) and (c) cover positioning screens away from public view and locking them when staff step away. Device and media controls at 164.310(d) cover tracking hardware and securely wiping or destroying it before reuse or disposal.

Physical controls address risks that software controls alone cannot resolve. Examples include media disposed of without proper handling, devices that retain ePHI, or unattended workstations visible to unauthorized people. Use answers in this category to investigate facility controls, workstation policies, and device or media procedures in the context of your environment.

The technical safeguards

Technical safeguards are controls built into systems. Access control at 164.312(a) includes the required unique-user-identification specification. Automatic logoff at 164.312(a)(2)(iii) is addressable, so the organization follows the documented process in 164.306(d) to implement it or select an equivalent measure when reasonable and appropriate. Authentication at 164.312(d) requires procedures to verify identity. Multi-factor authentication can be an appropriate risk-based control, but HIPAA does not name it as a universal requirement. Audit controls at 164.312(b) require mechanisms that record and examine activity in systems containing or using ePHI.

Encryption at rest under 164.312(a)(2)(iv) and transmission encryption under 164.312(e)(2)(ii) are addressable specifications. The organization must evaluate each one under 164.306(d), document the decision, and implement an equivalent measure when reasonable and appropriate if it does not implement the specification. For breach purposes, ePHI is treated as unreadable only when the HHS-specified method applies and the key or process needed to decrypt it has not been compromised. Review unique IDs, authentication, encryption, logoff, and audit controls against the documented risks.

Documentation and breach readiness

The Security Rule requires written policies and procedures and retention of required documentation for six years under 164.316. Breach procedures should support notice without unreasonable delay and within the applicable federal outer limit. The Notice of Privacy Practices and access prompts concern covered-entity Privacy Rule duties and can be marked Not applicable when they do not fit the organization's role or circumstances.

HIPAA contains specific documentation duties, and dated records help an organization explain what it did and when. That is why the tool counts documentation as its own safeguard area rather than folding it into the others. If answers need follow-up, identify which actions require written policies, decisions, or completion records and store that evidence where authorized reviewers can retrieve it.

How to read your score

The overall percentage is based only on applicable prompts you answered yes, partly, no, or not sure. Not-applicable answers are excluded. A score at or above eighty percent means your answers identify fewer unresolved prompts, while a score between fifty-five and seventy-nine percent leaves several partial or missing items. A score below fifty-five percent leaves many answers missing or uncertain. None of these bands measures likelihood, impact, overall risk, or compliance. Use the percentage to organize follow-up, then verify scope, evidence, threats, vulnerabilities, and risk in the formal analysis.

The category bars show how your answers are distributed, not where an incident will occur. Read them to find groups with more missing or uncertain answers, then investigate the listed items and document what the formal analysis finds. Because the self-check recalculates instantly, you can revisit it as an organizational aid after remediation.

Turning the assessment into a real risk analysis

The self-check is a starting point, not the finished product the rule requires. To build a documented risk analysis, begin with an inventory of where ePHI is created, received, stored, and transmitted, including systems, devices, vendors, and workflows. A risk analysis that starts from a real inventory is far stronger than one that starts from a form. Then investigate applicable follow-up items by documenting the threat, current control, likelihood, impact, and any resulting risk-management decision.

Next, convert confirmed findings into a tracked remediation plan with an owner and a due date for each item, which is the risk management step at 164.308(a)(1)(ii)(B). Without owners and dates, a list of risks is just awareness, and awareness alone reduces no exposure. Finally, set a documented review cadence based on your environment and revisit the analysis when material changes affect systems, vendors, staffing, or work location. Keep every version dated so reviewers can follow the analysis and remediation history.

Covered entities and business associates both need this

The Security Rule risk-analysis duty applies to covered entities and business associates. Business-associate status depends on the function or service performed, the handling of PHI on behalf of a covered entity or business associate, and the exceptions in 45 CFR 160.103. Organizations that meet the definition have direct Security Rule duties, including the risk-analysis requirement, in addition to applicable contractual obligations.

Organization size, complexity, capabilities, costs, and risks inform reasonable and appropriate safeguard decisions under 164.306(b). The duty to perform the analysis remains, while its scope and supporting inventory reflect the organization's systems and ePHI. Use Not applicable for role-specific Privacy Rule prompts that do not fit, not as a substitute for evaluating Security Rule safeguards.

Common mistakes that weaken an assessment

A few predictable errors make a risk assessment look complete while leaving the organization exposed. The first is scoping too narrowly, assessing the electronic health record but ignoring email, messaging, spreadsheets, personal devices, and the vendors that quietly hold copies of the same data. Risk lives in the places people forget. The second is treating the assessment as a one-time event, filing it, and never revisiting it after new systems, vendors, or remote-work changes reshape the risk picture. A two-year-old analysis often describes an organization that no longer exists.

The third mistake is stopping at awareness. Finding risks and never assigning owners or due dates leaves the risk-management work incomplete. The fourth is confusing a vendor's compliance with your own. A platform being HIPAA-capable does not make your configuration of it compliant, and a signed business associate agreement does not absolve you of your own safeguards. The fifth is keeping no dated evidence, so even genuine diligence cannot be documented later. The tool supports a safeguard-by-safeguard review and turns partial, negative, or uncertain answers into an ordered follow-up list.

Where workforce training fits

The Security Rule requires a security awareness and training program for all workforce members of covered entities and business associates subject to the rule. The Privacy Rule separately requires covered entities to train workforce members on applicable policies and procedures. This tool flags an applicable training answer for follow-up so the organization can assign relevant instruction and retain required records.

Keep going

Guides and tools that build on your self-check

Use these pages to study the underlying rules, document a formal risk analysis, and address any applicable training work.

Risk assessment FAQ

Common questions about HIPAA risk assessments

Is this HIPAA risk assessment tool free?

Yes. The assessment is completely free, runs entirely in your browser, and requires no account or email. Answer the questions and you get a self-check percentage, a safeguard-by-safeguard breakdown, and a prioritized follow-up list. Nothing you enter leaves your device.

Does this replace a formal HIPAA risk analysis?

No, and it does not claim to. The HIPAA Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities at 45 CFR 164.308(a)(1)(ii)(A). This tool organizes self-reported answers to selected prompts. Use it for follow-up, then document a complete analysis and risk-management process.

What does the score actually measure?

Each prompt cites a HIPAA standard and assigns points to applicable yes, partly, no, or not sure answers. Not-applicable answers are excluded. The percentage summarizes only those self-reported answers. It does not measure threats, likelihood, impact, overall risk, or compliance.

Who should run this assessment?

Covered entities and business associates subject to the Security Rule can use the safeguard prompts. Covered-entity-only Privacy Rule prompts can be marked Not applicable by a business associate or when the cited duty does not fit the user's role or circumstances.

Why does workforce training keep coming up?

Because the Security Rule requires a security awareness and training program for all workforce members at 45 CFR 164.308(a)(5). If the training answer needs follow-up, identify the applicable duty, assign relevant instruction, and keep required records.

How often should we reassess our HIPAA risk?

HIPAA does not prescribe a universal annual schedule. Review risk on a documented cadence appropriate to your environment and when material changes occur, such as new systems, vendors, work locations, or a security incident. Re-running this educational tool can help track remediation, but it does not replace the formal analysis.

Review the cited requirements and document the resulting decisions. If workforce instruction is applicable, compare individual courses or plan an organization rollout.

Primary sources: 45 CFR 164.306 explains required and addressable specifications, 45 CFR 164.308 covers administrative safeguards, and 45 CFR 164.312 covers technical safeguards. HHS also publishes breach-notification encryption guidance.

From self-check to follow-up

Act on applicable workforce instruction.

If the training prompt needs follow-up, confirm which Privacy or Security Rule duty applies, assign relevant instruction, and keep the required records. USA HIPAA courses include a graded assessment and dated certificates for individual and team records.