HIPAA Status Tune-Up
A HIPAA compliance self-assessment evaluates whether your practice meets the administrative, physical, and technical safeguard requirements of the HIPAA Security Rule (45 CFR 164.308) and the Privacy Rule (45 CFR Part 164). This assessment evaluates your practice's alignment with federal HIPAA requirements across 10 key compliance areas. Results are confidential and delivered by email.
Start Your Status Tune-UpWhat This Assessment Covers
Each question in this assessment maps to a specific federal HIPAA requirement. The five primary compliance areas evaluated are:
- Risk Analysis - 45 CFR 164.308(a)(1)
- Workforce Training - 45 CFR 164.308(a)(5)
- Business Associate Agreements - 45 CFR 164.308(b)
- Access Controls - 45 CFR 164.312(a)
- Incident Response - 45 CFR 164.308(a)(6)
How It Works
Answer 10 questions about your current compliance practices.
No prior research is needed. Select "Not Sure" for any area you cannot confirm.
Results are confidential and delivered by email. The assessment takes approximately 2 minutes.
The 10 Questions at a Glance
The assessment asks whether your organization has the following safeguards in place:
- Annual Security Risk Assessment - 164.308(a)(1)(ii)(A)
- Gap Report derived from risk assessment findings - 164.308(a)(1)(ii)(B)
- Remediation Plans built from gap report findings - 164.308(a)(1)(ii)(B)
- Documentation reflecting 2025 Privacy Rule amendments - 45 CFR Part 164, Subpart E
- Inventory of all devices that can access PHI - 164.310(d)
- Annual workforce training including policy attestation and cybersecurity awareness - 164.308(a)(5)
- Unique login credentials for each staff member accessing PHI systems - 164.312(a)(2)(i)
- Business Associate Agreements with all required third parties - 164.308(b)(1)
- Security vetting of prospective business associates - 164.314(a)
- Anonymous reporting mechanism for unauthorized PHI disclosures - 164.308(a)(6)
Why Self-Assessment Matters
The HIPAA Security Rule requires covered entities to conduct periodic evaluations of their security measures (45 CFR 164.308(a)(8)). A self-assessment provides an initial benchmark of compliance readiness before a formal Security Risk Assessment. Organizations that identify gaps early can prioritize remediation and reduce the risk of enforcement action.
This content is for educational and informational purposes only and should not be construed as legal advice.
Evaluate your HIPAA compliance readiness
This assessment covers risk analysis (45 CFR 164.308(a)(1)), workforce training (164.308(a)(5)), business associate agreements (164.308(b)), access controls (164.312(a)), and incident response (164.308(a)(6)). Answer 10 questions. No prior research is needed. Results are confidential and delivered by email.
See your status tune-up results in mere moments.
Just enter your email and we will send your confidential results.
Check your inbox!
Your confidential HIPAA status tune-up results are on the way. Keep an eye out for an email from One Guy Consulting.
Book Your Free 30 Minute HIPAA Compliance ReviewWant to talk through your results? Schedule a free 15-minute call.
HIPAA Status Tune-Up FAQ
Everything you need to know about this assessment.
The questions in this assessment map directly to the administrative safeguard requirements of the HIPAA Security Rule (45 CFR §164.306), the physical and technical safeguard standards, and the Privacy Rule's workforce training and accountability provisions. The answers you provide help identify which regulatory areas may require attention before your next compliance review or HHS audit.