Free HIPAA Risk Assessment

Walk through a HIPAA security risk assessment for your practice and get a scored report of where the gaps are. Free, no signup, built for small practices.

Frequently asked questions

Is a HIPAA risk assessment required?

A security risk analysis is a requirement of the HIPAA Security Rule for covered entities and business associates, and it is expected to be conducted and documented periodically rather than once. This tool helps you work through the areas it covers; it does not replace a formal assessment or legal advice.

How often should a HIPAA risk assessment be done?

Periodically, and again whenever something material changes — new systems, a new location, a new vendor handling protected health information, or an incident. Many practices run one annually and document it.

What does a HIPAA risk assessment cover?

Administrative, physical and technical safeguards: who can access protected health information and how that access is controlled and logged, how data is encrypted at rest and in transit, how devices and facilities are secured, how workforce members are trained, and how incidents would be detected and reported.