Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Free readiness check

Fifteen questions. Real citations. No email.

This is not a lead-generation quiz with a score attached. Every question maps to a specific requirement in the HIPAA Security Rule, and the result names the §164 citation behind each gap so you can look it up yourself. It runs entirely in your browser. Nothing is transmitted anywhere.

Progress 0 / 15
Question 1
01
Risk analysis

Can you produce a written, enterprise-wide risk analysis dated within the last 12 months?

Enterprise-wide means every location, every system, and every place ePHI lives. A vulnerability scan is not a risk analysis, and a completed HHS SRA Tool questionnaire has repeatedly failed to satisfy investigators.

45 CFR §164.308(a)(1)(ii)(A)
Question 2
02
Risk management

Do you have a dated remediation plan with named owners and evidence that items were completed?

A list of findings is not a risk management plan. The plan needs priorities, an owner per item, target dates, and proof of completion.

45 CFR §164.308(a)(1)(ii)(B)
Question 3
03
Business associates

Do you have a current, executed Business Associate Agreement with your IT provider?

A clause inside a master services agreement often does not meet the requirement. Check the date, and check that it names the right legal entity.

45 CFR §164.504(e)
Question 4
04
Business associates

Can you list every vendor that holds or touches your ePHI, with executed agreements and renewal dates?

Include the clearinghouse, the billing company, the transcription service, the answering service, the shredding company, and the IT provider’s own subcontractors.

45 CFR §164.308(b)(1)
Question 5
05
Access control

Is multi-factor authentication enforced on every path into ePHI, including the VPN, remote desktop, the practice management system, the imaging portal, and the clearinghouse?

MFA on Microsoft 365 alone does not count. The question is whether any path exists that a valid password alone can open.

45 CFR §164.312(d)
Question 6
06
Access control

Does every workforce member have a unique login, with no shared front-desk or shared local administrator accounts?

Shared logins are usually defended as clinical workflow. Badge or proximity authentication with fast user switching solves the workflow without destroying attribution.

45 CFR §164.312(a)(2)(i)
Question 7
07
Audit controls

Are audit logs retained for at least 12 months and can you actually produce them on request?

Retention and retrievability are different problems. Logs that exist in a system nobody can query are not producible.

45 CFR §164.312(b)
Question 8
08
Encryption

Can you produce an encryption status report covering every laptop, desktop, server, and mobile device?

Encryption is addressable, which means implemented or documented as an equivalent alternative. Assumed is neither.

45 CFR §164.312(a)(2)(iv)
Question 9
09
Contingency plan

Has a full restore from backup been tested and timed in the last 90 days, with the result written down?

A backup job reporting success is not a restore test. The timing is the artifact, because it is what tells you how long a real recovery takes.

45 CFR §164.308(a)(7)(ii)(D)
Question 10
10
Contingency plan

Are your backups immutable and stored where an attacker with domain administrator rights cannot delete them?

If your backup destination is a network share reachable from a compromised server, it is part of the blast radius rather than the recovery plan.

45 CFR §164.308(a)(7)(ii)(A)
Question 11
11
Incident response

Have you run an incident response tabletop in the last 12 months, with minutes and after-action items?

A plan that exists only as a Word document nobody has walked through is a plan in name only.

45 CFR §164.308(a)(6)(ii)
Question 12
12
Workforce

Can you produce role-based security training completion records, retained six years?

Retained six years is the actual requirement, and it is longer than most learning platforms keep records by default.

45 CFR §164.308(a)(5)
Question 13
13
Workforce

Is there a documented record showing access was removed the same day for every departed workforce member in the last year?

Include the practice management system, the clearinghouse, the imaging portal, and any shared vendor accounts, not only email.

45 CFR §164.308(a)(3)(ii)(C)
Question 14
14
Device and media

Do you have a current inventory of every device that touches ePHI, including clinical and imaging equipment?

Include the imaging modalities, the anesthesia and monitoring equipment, and anything else the vendor installed and nobody has looked at since.

45 CFR §164.310(d)(2)(iii)
Question 15
15
Penalty mitigation

Could you demonstrate 12 rolling months of Recognized Security Practices in place enterprise-wide?

Qualifying practices include NIST CSF, SP 800-53, SP 800-171, and HICP / §405(d). The requirement is documentation of continuous implementation, not a one-time statement.

HITECH §13412

Answer all 15 questions to see the result. “I do not know” is a legitimate answer and scores the same as no, because an artifact you cannot locate is an artifact you cannot produce.

What this is and is not

A readiness check is not a risk analysis.

A real risk analysis under §164.308(a)(1)(ii)(A) is enterprise-wide fieldwork. It enumerates every system and every ePHI repository at every location, identifies threats and vulnerabilities against each, assesses likelihood and impact, and documents the whole thing against a recognized methodology. Ours are conducted against NIST SP 800-66 Rev. 2 and mapped to Security Rule citations. They take weeks, not minutes.

This page is a readiness check: fifteen questions that predict, fairly reliably, what a real analysis will find. We use the same fifteen to open an assessment, because if a practice cannot answer them the rest of the engagement is already scoped.

It is worth being blunt about one thing. A completed HHS Security Risk Assessment Tool questionnaire is also not a risk analysis, and OCR settlements have said so repeatedly. The tool is genuinely useful for structuring your thinking. It is not the deliverable.

Why “I do not know” scores as no

Because in an investigation it does. A data request gives you a deadline, and an artifact nobody can locate inside that deadline is functionally an artifact that does not exist. If the honest answer is that somebody probably has it somewhere, the honest score is zero.

After the result

A 30-minute review, if you want one.

We walk your result with you, tell you which gaps we would actually work first, and give you the order. If we are not the right provider for you, we will say so on that call rather than after a proposal.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.