Free Self-Assessment
HIPAA Security Readiness Check
How This Check Helps
The HIPAA Security Rule requires every practice and business associate to protect electronic patient information with administrative, physical and technical safeguards, and to prove it with documentation. This check walks through those safeguards in plain language, starting with the ones OCR enforcement actions cite most.
You answer 24 questions, see your score instantly and get a prioritized list of what to fix. Use it before an audit, before signing a new vendor, or to see how well your current IT provider is really protecting your patients’ data.
Answer 24 Questions
Choose Yes, No, Unknown or Not applicable for each question. It takes about 6 minutes, and you see your score as soon as you finish.
This self-assessment is educational. It is not an audit, a certification, legal advice or an insurance underwriting decision. Your answers stay in your browser and are not sent to Triton unless you contact us.
How Your Score Works
Each Yes earns points, weighted by how much the safeguard matters. No and Unknown earn none, because an auditor treats an undocumented safeguard as missing. Not applicable removes a question from your total.
A score of 85 percent or higher, with every high-priority safeguard in place, is a strong result. Below that, your results list the gaps in priority order, starting with the safeguards HIPAA treats as required.
HHS proposed an update to the Security Rule in January 2025. It is not final, so the current rule still applies; where the proposal would change a safeguard, the question says so.
What Happens After You Finish
A strong score: congratulations. Your HIPAA security controls are where reviewers expect them to be. If you are happy with your current IT provider, they are doing their job. If you are not, Triton would be a good fit: we can take over without losing what you have built.
Gaps or a failing score: set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.
HIPAA Readiness Check: Common Questions
Is this an official HIPAA risk analysis?
No. It is a quick self-check. A HIPAA risk analysis must be documented and cover every system that holds electronic patient information. HHS offers a free Security Risk Assessment Tool, and Triton can complete a full risk analysis with you.
Do you store my answers?
No. Your answers stay in your browser, and nothing is sent to Triton unless you choose to contact us.
Who should answer the questions?
The practice manager, the designated security official or the owner. If you are not sure of an answer, choose Unknown: an auditor would treat it the same way.
When should I choose Not applicable?
Only when a safeguard truly does not apply to you, for example a question about portable devices when no device that accesses patient information ever leaves the building. Not applicable removes the question from your score.
Is multi-factor authentication required by HIPAA?
Today it is an addressable safeguard. The January 2025 proposed update would make it mandatory, but that rule is not final. It remains one of the strongest protections against stolen passwords.
What happens if my score is low?
Set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.
How Triton Delivers
The Sophos XDR Mandate
We deploy Sophos Firewalls as the non-negotiable perimeter standard. Any firm operating without synchronized endpoint protection is an insurance liability. Sophos Endpoint (EDR/XDR) is the mandatory internal security layer.
AWS Scalability
We deploy on AWS because downtime is not an option. When a critical system goes down, AWS support responds with enterprise urgency, not a ticket queue. Every dollar of downtime is a dollar your IT provider owes you an answer for.
The AI Autonomous Advantage
Axiom, Triton’s proprietary AI monitoring system, gives our engineers real-time visibility that off-the-shelf tools cannot replicate. It is not for sale, it is how we deliver.
Founded in 2001
25 Years of IT Expertise
Serving New England
5 Regional Offices + Dublin & BVI
Under 10 Minute Response
84th Percentile · MSPbots Verified
Sophos Silver · Microsoft Solutions Partner
Security & Cloud Partners
HIPAA · CMMC · SOC 2 · PCI
Multi-Framework Compliance
Let's Discuss Your IT Needs
Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.