HIPAA Security Rule Readiness Checklist
Evaluate your organization's compliance posture across Administrative, Physical, and Technical Safeguards — plus proposed NPRM items. Takes approximately 10–15 minutes.
This self-assessment evaluates your organization's readiness against the HIPAA Security Rule requirements for protecting electronic protected health information (ePHI). It covers current requirements (Part A) and proposed NPRM modifications (Part B).
This is a readiness checklist — not a substitute for the documented risk analysis required by the Security Rule.
Frequently Asked Questions
No. This is a readiness checklist that helps you identify potential gaps in your HIPAA Security Rule compliance posture. OCR requires covered entities and business associates to conduct an accurate and thorough risk analysis — a documented assessment that identifies threats and vulnerabilities to ePHI and feeds into a risk management plan. A full risk analysis is more comprehensive than a self-assessment checklist and typically involves interviews, system inventories, and detailed threat modeling. This tool helps you understand where to focus that deeper analysis.
Part A covers requirements under the current HIPAA Security Rule, which is the law that governs today. Part B covers items from the proposed Security Rule modifications (NPRM published January 2025), which have not been finalized. We separate them so you can clearly see your compliance posture under current law while also understanding what may be required if the proposed changes take effect.
A Part A score below 70% suggests significant gaps in current Security Rule compliance. The most critical step is ensuring you have a documented risk analysis and a designated security official, as these are OCR's most common enforcement targets. From there, prioritize the specific gaps identified in your results — the recommendations section maps each gap to an action. Many organizations at this stage benefit from external expertise to structure their remediation roadmap.
The HIPAA Security Rule requires ongoing risk management, not just a one-time assessment. Best practice is to reassess at least annually, after any significant change to your systems or operations, and after any security incident. If the proposed NPRM is finalized, it would explicitly require annual compliance audits. Regular reassessment also helps demonstrate the ongoing compliance effort OCR looks for during investigations.
This self-assessment is an educational tool to help healthcare organizations evaluate their HIPAA Security Rule readiness. It is not a substitute for the documented risk analysis required by the Security Rule, nor does it constitute legal or compliance advice. Results reflect your self-reported responses and should be validated by qualified professionals. Proposed NPRM items (Part B) have not been finalized and may change. Information reflects regulatory status as of April 2026. Consult legal counsel for compliance guidance specific to your organization.