HIPAA Security Rule Assessment

Evaluates compliance with the HIPAA Security Rule across Administrative, Physical, Technical, Organizational, and Breach Notification safeguards.

Your Information

Your information is kept private and used only to send your results.
0 of 43 answered 0%

Administrative Safeguards - Security Management

Has a written risk analysis been completed in the last 12 months?
High impact
Is there a documented risk management plan addressing identified risks?
High impact
Are sanctions defined and applied for workforce violations of security policies?
High impact
Are audit logs and system activity reviewed on a regular schedule?
High impact

Administrative Safeguards - Workforce Security

Is there a formal process for authorizing and supervising workforce member access to ePHI?
High impact
Is termination access revocation performed same-day for departing staff?
High impact
Are background checks conducted on workforce members with ePHI access?

Administrative Safeguards - Information Access

Are access privileges granted based on role and need-to-know?
High impact
Is ePHI access periodically reviewed and recertified?
High impact

Administrative Safeguards - Security Awareness

Is security awareness training provided at hire and at least annually?
High impact
Are staff trained on phishing and social engineering recognition?
High impact
Are password management practices covered in training?

Administrative Safeguards - Incident Response

Is there a documented incident response procedure?
High impact
Are security incidents logged and reviewed?
High impact

Administrative Safeguards - Contingency Plan

Is there a documented data backup plan?
High impact
Is there a documented disaster recovery plan?
High impact
Is there an emergency mode operation plan (operating during an emergency)?
High impact
Are recovery procedures tested at least annually?
High impact

Administrative Safeguards - Business Associates

Are signed Business Associate Agreements on file for every vendor that handles ePHI?
High impact
Are subcontractor BAAs required and tracked for your BAs?
High impact

Physical Safeguards - Facility Access

Are physical access controls in place at facilities housing ePHI systems?
High impact
Are visitors logged and escorted in areas containing ePHI?

Physical Safeguards - Workstation Use

Are workstation use policies in place (screen locking

Physical Safeguards - Workstation Security

Are workstations physically secured (cable locks or restricted areas)?

Physical Safeguards - Device and Media

Is there a documented procedure for device disposal and media destruction?
High impact
Is media reuse sanitized (wiped) before reassignment?
High impact
Are inventory records maintained of hardware and media that contain ePHI?
High impact

Technical Safeguards - Access Control

Does every user have a unique user ID (no shared accounts)?
High impact
Is there an automatic logoff mechanism after a period of inactivity?
High impact
Is ePHI encrypted at rest on servers and endpoints?
High impact
Is there an emergency access procedure for ePHI during an outage?

Technical Safeguards - Audit Controls

Are audit logs enabled on systems that store or process ePHI?
High impact
Are audit logs retained for at least six years?
High impact

Technical Safeguards - Integrity

Are mechanisms in place to detect unauthorized alteration of ePHI?
High impact

Technical Safeguards - Authentication

Is multi-factor authentication required for all remote and admin access?
High impact
Is MFA required for email (Google Workspace or Microsoft 365)?
High impact

Technical Safeguards - Transmission

Is ePHI encrypted in transit (TLS 1.2 or higher)?
High impact
Is email containing ePHI encrypted or sent via secure messaging?
High impact

Organizational Requirements

Are HIPAA policies and procedures maintained in writing and reviewed annually?
High impact
Is documentation retained for at least six years from creation or last effective date?
High impact

Breach Notification

Is there a documented breach notification procedure?
High impact
Are individuals notified within 60 days of breach discovery?
High impact
Is HHS notified for breaches affecting 500 or more individuals?
High impact
Please answer all questions. remaining.
Results will be emailed to you immediately after submission.
Powered by Blackhawk MSP