Free Self-Assessment

HIPAA Security Readiness Check

How This Check Helps

The HIPAA Security Rule requires every practice and business associate to protect electronic patient information with administrative, physical and technical safeguards, and to prove it with documentation. This check walks through those safeguards in plain language, starting with the ones OCR enforcement actions cite most.

You answer 24 questions, see your score instantly and get a prioritized list of what to fix. Use it before an audit, before signing a new vendor, or to see how well your current IT provider is really protecting your patients’ data.

Medical receptionist locking a computer screen with a privacy filter at the front desk

Answer 24 Questions

Choose Yes, No, Unknown or Not applicable for each question. It takes about 6 minutes, and you see your score as soon as you finish.

Risk Analysis & Security Management

Have you completed a written risk analysis covering every system that creates, stores, or transmits patient information, updated in the past year?

Required implementation specification. Missing or outdated risk analyses are the focus of OCR's Risk Analysis Initiative enforcement actions.

Do you have a written risk management plan that addresses the specific risks your risk analysis identified?

Required. A risk analysis without a documented plan to reduce the risks it found does not satisfy the Security Rule.

Has one person been formally designated as your organization's HIPAA Security Official?

Required. One named individual must be responsible for developing and enforcing your security policies.

Is there a written sanction policy for staff who violate your security policies?

Required. Documents the consequences for policy violations so enforcement is consistent and defensible.

Workforce Training & Access Control

Do all staff complete HIPAA security awareness training before accessing patient records, with refreshers at least annually?

Required. Training must cover password practices, malicious software, and login monitoring, not just a one-time hire packet.

Does every staff member log into every system with their own unique username, never a shared or generic login?

Required. Unique user IDs are how you trace exactly who accessed a record; shared logins make that impossible.

Is each employee's access to patient information limited to only what their specific job requires?

Required. Minimum-necessary access limits the damage a single compromised account or careless employee can cause.

Is a departing or transferred employee's system access removed the same day, not days or weeks later?

Addressable but expected. Delayed offboarding is a common OCR audit finding and a common breach source.

Do computers and devices that access patient information automatically log off or lock after a period of inactivity?

Addressable safeguard against an unattended, unlocked screen exposing records to anyone walking by.

Do staff receive periodic phishing-awareness testing in addition to general security training?

HHS 405(d) HICP names email phishing as the top threat to the health sector; training must specifically address it.

Technical Safeguards

Is multi-factor authentication (MFA) required to remotely access email, EHR, or other systems holding patient information?

Currently an addressable access control, not yet mandatory under the 2013 rule. HHS's January 2025 proposed rule (not yet final) would make MFA required; treat it as good practice now.

Are laptops, phones, and other portable devices that access patient information encrypted?

Currently addressable, not mandatory. The pending 2025 proposed rule would make device encryption required; a stolen unencrypted device is a reportable breach today.

Is email containing patient information encrypted whenever it is sent outside your organization?

Currently addressable, not mandatory. Unencrypted PHI sent by email over open networks is a frequent OCR finding.

Do your systems keep audit logs of who accessed, changed, or deleted patient records, and does someone review them?

Required. Audit controls are how a breach is actually detected and investigated; a log nobody reviews doesn't count.

Is anti-malware or endpoint detection software installed and kept current on all computers and servers?

Addressable safeguard and an HHS 405(d) HICP top practice; malicious software is a leading path into patient data.

Are security patches and software updates applied to computers, servers, and network devices on a regular schedule?

Part of ongoing risk management; unpatched systems are the vulnerability most often exploited in ransomware cases OCR has settled.

Physical Safeguards

Are the rooms or areas where servers, computers, or paper records are kept physically secured from public access?

Required. Physical access controls stop walk-in theft or tampering with the systems holding patient data.

Do you have a written procedure to wipe or destroy data before disposing of or reusing old computers, phones, or copiers?

Addressable but expected. Improperly disposed devices and copiers with hard drives are a documented breach source.

Contingency Planning & Backups

Do you have a written data backup and disaster recovery plan for all patient information?

Required. OCR ransomware settlements repeatedly cite the absence of a documented backup and recovery plan.

Have you actually tested restoring data from backup within the past year, not just confirmed backups run?

Addressable but critical in practice. Untested backups are a top finding in OCR's ransomware enforcement cases.

Vendors, Breach Response & Documentation

Do you have a signed Business Associate Agreement with every vendor, cloud service, or IT provider that can access patient information?

Required. A vendor touching PHI without a signed BAA is itself a compliance violation, regardless of the vendor's own security.

Do you have a written incident response plan describing how you would detect, contain, and report a security incident?

Required. Security incident procedures must be documented in advance, not improvised during an actual event.

Could you notify every affected patient within 60 days, and HHS on the required schedule, if a breach occurred today?

Individuals must be notified within 60 days of discovery; HHS notification timing depends on breach size (500+ triggers immediate notice).

Do you retain your HIPAA policies, risk analyses, and training records for at least 6 years?

Required. Documentation must be kept 6 years from its creation date or the date it was last in effect, whichever is later.

This self-assessment is educational. It is not an audit, a certification, legal advice or an insurance underwriting decision. Your answers stay in your browser and are not sent to Triton unless you contact us.

How Your Score Works

Each Yes earns points, weighted by how much the safeguard matters. No and Unknown earn none, because an auditor treats an undocumented safeguard as missing. Not applicable removes a question from your total.

A score of 85 percent or higher, with every high-priority safeguard in place, is a strong result. Below that, your results list the gaps in priority order, starting with the safeguards HIPAA treats as required.

HHS proposed an update to the Security Rule in January 2025. It is not final, so the current rule still applies; where the proposal would change a safeguard, the question says so.

What Happens After You Finish

A strong score: congratulations. Your HIPAA security controls are where reviewers expect them to be. If you are happy with your current IT provider, they are doing their job. If you are not, Triton would be a good fit: we can take over without losing what you have built.

Gaps or a failing score: set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.

HIPAA Readiness Check: Common Questions

No. It is a quick self-check. A HIPAA risk analysis must be documented and cover every system that holds electronic patient information. HHS offers a free Security Risk Assessment Tool, and Triton can complete a full risk analysis with you.

No. Your answers stay in your browser, and nothing is sent to Triton unless you choose to contact us.

The practice manager, the designated security official or the owner. If you are not sure of an answer, choose Unknown: an auditor would treat it the same way.

Only when a safeguard truly does not apply to you, for example a question about portable devices when no device that accesses patient information ever leaves the building. Not applicable removes the question from your score.

Today it is an addressable safeguard. The January 2025 proposed update would make it mandatory, but that rule is not final. It remains one of the strongest protections against stolen passwords.

Set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.

How Triton Delivers

The Sophos XDR Mandate

We deploy Sophos Firewalls as the non-negotiable perimeter standard. Any firm operating without synchronized endpoint protection is an insurance liability. Sophos Endpoint (EDR/XDR) is the mandatory internal security layer.

AWS Scalability

We deploy on AWS because downtime is not an option. When a critical system goes down, AWS support responds with enterprise urgency, not a ticket queue. Every dollar of downtime is a dollar your IT provider owes you an answer for.

The AI Autonomous Advantage

Axiom, Triton’s proprietary AI monitoring system, gives our engineers real-time visibility that off-the-shelf tools cannot replicate. It is not for sale, it is how we deliver.

Founded in 2001

25 Years of IT Expertise

Serving New England

5 Regional Offices + Dublin & BVI

Under 10 Minute Response

84th Percentile · MSPbots Verified

Sophos Silver · Microsoft Solutions Partner

Security & Cloud Partners

HIPAA · CMMC · SOC 2 · PCI

Multi-Framework Compliance

Let's Discuss Your IT Needs

Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.

Triton Technologies support engineer at workstation