HIPAA SRA Readiness Checker
Answer 12 quick questions and get an instant readiness score against the HIPAA Security Rule safeguards — plus a plain-English list of the gaps most likely to surface in a Security Risk Assessment.
Free, no signup, and nothing leaves your browser. This is a self-check, not a substitute for a written HIPAA Security Risk Assessment — but it will show you where you stand in about two minutes.
Do you have a written HIPAA Security Risk Assessment completed within the last 12 months?
Does your assessment inventory every system and vendor that stores or transmits ePHI?
Do you have a signed BAA with every vendor that touches PHI — including any AI or automation tools?
Is access to ePHI restricted by role, with a unique login for each staff member (no shared accounts)?
Do you disable system access promptly when an employee leaves or changes roles?
Is ePHI encrypted both in transit and at rest across all systems?
Do your systems log who accesses ePHI, and does someone actually review those logs?
Is multi-factor authentication (MFA) required for systems that access ePHI?
Do you have tested data backups and a documented recovery plan for a ransomware event or outage?
Has your workforce completed HIPAA security awareness training in the last 12 months?
Do you have a written breach notification and incident response procedure?
For any AI tool touching PHI, do you know exactly where its data is stored and that it is never used to train models?
Your HIPAA SRA Readiness
–
Gaps to address
These are the safeguards you flagged as missing or uncertain, and why each one matters.
Turn this into a defensible, written SRA
This checker shows where you stand. A full HIPAA Security Risk Assessment inventories your actual systems, reviews your BAAs, scores the threats, and delivers a written document formatted for an OCR examiner — CISSP-informed, fixed from-price.
Disclaimer: This readiness checker is an educational self-assessment, not legal advice or a HIPAA risk analysis. Your result does not determine compliance and should not replace a written Security Risk Assessment performed for your specific environment.