Fifteen questions. Real citations. No email.
This is not a lead-generation quiz with a score attached. Every question maps to a specific requirement in the HIPAA Security Rule, and the result names the §164 citation behind each gap so you can look it up yourself. It runs entirely in your browser. Nothing is transmitted anywhere.
A readiness check is not a risk analysis.
A real risk analysis under §164.308(a)(1)(ii)(A) is enterprise-wide fieldwork. It enumerates every system and every ePHI repository at every location, identifies threats and vulnerabilities against each, assesses likelihood and impact, and documents the whole thing against a recognized methodology. Ours are conducted against NIST SP 800-66 Rev. 2 and mapped to Security Rule citations. They take weeks, not minutes.
This page is a readiness check: fifteen questions that predict, fairly reliably, what a real analysis will find. We use the same fifteen to open an assessment, because if a practice cannot answer them the rest of the engagement is already scoped.
It is worth being blunt about one thing. A completed HHS Security Risk Assessment Tool questionnaire is also not a risk analysis, and OCR settlements have said so repeatedly. The tool is genuinely useful for structuring your thinking. It is not the deliverable.
Why “I do not know” scores as no
Because in an investigation it does. A data request gives you a deadline, and an artifact nobody can locate inside that deadline is functionally an artifact that does not exist. If the honest answer is that somebody probably has it somewhere, the honest score is zero.