Wolferdawg IT Consulting favicon

Free HIPAA security readiness self-assessment

Use this quick check to review selected administrative, technical, physical, and data safeguards. Answer based on what your practice can verify today. If evidence is missing, choose Not sure.

  • 16 questions
  • About 5 minutes
  • No signup
  • Answers scored in your browser

Do not enter patient information. This tool asks only for yes, no, or not sure answers. It is a readiness check, not the formal risk analysis required by the HIPAA Security Rule.

Administrative safeguards

The policies, people, and paperwork behind your security.

Technical safeguards

How your systems control access and protect data.

Physical and data safeguards

Protecting the devices and copies that hold patient data.

A
100% readiness score

Your score by category

Your prioritized security readiness checklist

Email this checklist

Email your score, grade, verdict, and identified gaps. The submitted contact information and results are also copied to Wolferdawg IT Consulting. By clicking Email me my checklist, you agree that Wolferdawg IT Consulting may retain your contact information and assessment results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list. Do not enter patient information.

Need help completing a documented risk analysis?

Wolferdawg IT Consulting helps practices identify systems and electronic patient information, document risks, and build a practical remediation plan. This technical service is not legal advice or a compliance certification.

Or call (580) 956-8424 or email hello@wolferdawg.io.

This is a self-reported educational readiness check based on 16 selected safeguards. It is not the formal HIPAA Security Rule risk analysis, an audit, certification, legal advice, or a determination of compliance. For a documented risk analysis or legal guidance, work with qualified security and legal professionals.

How the HIPAA security readiness score works

The percentage and letter grade are a Wolferdawg diagnostic, not a government score or HIPAA certification. Each yes answer earns the points assigned to that question. No and not sure earn zero and create a finding.

CategoryAvailable pointsShare of score
Administrative safeguards12 of 34About 35%
Technical safeguards18 of 34About 53%
Physical and data safeguards4 of 34About 12%
PercentageBase gradeCritical-finding rule
90 to 100%AOne critical finding caps the final grade at C. Two or more critical findings cap it at F.
80 to 89%B
70 to 79%C
60 to 69%D
Below 60%F

Why the grade cap? A high total can otherwise hide an unverified safeguard that this tool treats as critical. Your formal risk analysis must evaluate the actual likelihood and impact of each risk.

What a formal HIPAA security risk analysis includes

The U.S. Department of Health and Human Services describes risk analysis as an ongoing, documented process. A complete analysis should:

  • define the scope and identify all electronic protected health information the organization creates, receives, maintains, or transmits;
  • identify and document reasonably anticipated threats and vulnerabilities;
  • assess existing security measures;
  • evaluate the likelihood and potential impact of threats;
  • assign risk levels and document risk-management decisions; and
  • review and update the analysis when material changes, incidents, or new risks affect the environment.

Use the official HHS risk analysis guidance, HIPAA Security Rule resources, and the federal Security Risk Assessment Tool when building the formal analysis.

Privacy, data use, and limitations

Your yes, no, and not sure answers are scored in your browser. When results appear, the usage record includes the request time, IP address and approximate location, grade, score, and total gap count. It does not include individual answers or identified gaps.

If you request an emailed checklist, the name, email address, practice name, score, grade, verdict, and identified gaps are submitted to the mail service and copied to Wolferdawg IT Consulting. By requesting the checklist, you agree that Wolferdawg IT Consulting may retain your contact information and assessment results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list.

Do not submit protected health information. Do not enter patient names, medical details, record numbers, or any other patient information into this page or the optional email form.

HHS explains that properly encrypted electronic patient information can be rendered unreadable to unauthorized people, but breach-notification duties depend on the specific facts and applicable law. See the HHS guidance on encryption and breach notification.

Reviewed by Dieter Wolf
Founder, Wolferdawg IT Consulting. 27+ years of IT and cybersecurity experience. Content reviewed August 25, 2026.

What to do after your assessment

  1. Verify every no and not sure answer against current documentation and system evidence.
  2. Start with critical findings, then evaluate likelihood and impact in the formal risk-analysis process.
  3. Assign an owner, target date, and documented action for each accepted or reduced risk.
  4. Retest safeguards after changes and update the analysis when the environment changes.

Need a technical partner? Schedule a 30-minute call or contact Wolferdawg IT Consulting at (580) 956-8424.

Common questions about this HIPAA risk assessment

What the tool does, what it does not do, and how to use your results.

The HIPAA Security Rule requires regulated entities to perform an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic protected health information they create, receive, maintain, or transmit. The analysis must be documented. This 16-question self-assessment does not replace that formal process.

No. A score from this tool is not a HIPAA certification, formal security risk analysis, compliance audit, or legal determination. HIPAA compliance depends on the regulated entity's documented analysis, risk management, policies, agreements, safeguards, training, and ongoing operations.

The current HIPAA Security Rule does not specify one fixed schedule. HHS describes risk analysis as an ongoing process. It should be reviewed and updated when changes in technology, operations, ownership, staffing, incidents, or threats could affect electronic protected health information. Some organizations also choose a regular annual review.

This tool scores 16 yes, no, or not sure answers. A formal risk analysis identifies all electronic protected health information, documents relevant threats and vulnerabilities, assesses existing safeguards, evaluates likelihood and impact, assigns risk levels, and documents risk-management actions. An audit may also verify policies, configurations, agreements, training records, and other evidence.

The 16 questions carry one, two, or three points based on this tool's assigned priority. Yes earns the available points. No and not sure earn zero and create a finding. The maximum is 34 points. Administrative safeguards contribute 12 points, technical safeguards contribute 18, and physical and data safeguards contribute 4. One critical finding caps the grade at C, and two or more critical findings cap it at F.

The answers are scored in your browser. When results appear, the usage record includes the request time, IP address and approximate location, grade, score, and total gap count. It does not include individual answers or identified gaps. If you request an emailed checklist, the name, email address, practice name, score, grade, verdict, and identified gaps are submitted to the mail service and copied to Wolferdawg IT Consulting. By requesting the emailed checklist, you agree that Wolferdawg IT Consulting may retain your contact information and assessment results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list.

No. Do not enter patient names, medical details, record numbers, or other protected health information. The assessment questions require only yes, no, or not sure answers. The optional email form asks only for your name, practice name, and email address.

Start with findings marked critical. Verify each answer, identify the electronic protected health information and systems affected, assign an owner, and document the planned action. The correct order depends on the likelihood and potential impact of each risk, which must be evaluated during the formal risk-analysis and risk-management process.

Turn the findings into a documented plan

Wolferdawg IT Consulting can help your practice verify technical safeguards, map electronic patient information, and prioritize remediation.