Free HIPAA security readiness self-assessment · No signup required
HIPAA security risk assessment tool
Answer 16 plain-language questions and get a Wolferdawg readiness score, category breakdown, and prioritized security checklist. No login required.
Free HIPAA security readiness self-assessment
Use this quick check to review selected administrative, technical, physical, and data safeguards. Answer based on what your practice can verify today. If evidence is missing, choose Not sure.
- 16 questions
- About 5 minutes
- No signup
- Answers scored in your browser
Do not enter patient information. This tool asks only for yes, no, or not sure answers. It is a readiness check, not the formal risk analysis required by the HIPAA Security Rule.
Your score by category
Your prioritized security readiness checklist
Email your score, grade, verdict, and identified gaps. The submitted contact information and results are also copied to Wolferdawg IT Consulting. By clicking Email me my checklist, you agree that Wolferdawg IT Consulting may retain your contact information and assessment results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list. Do not enter patient information.
Need help completing a documented risk analysis?
Wolferdawg IT Consulting helps practices identify systems and electronic patient information, document risks, and build a practical remediation plan. This technical service is not legal advice or a compliance certification.
Or call (580) 956-8424 or email hello@wolferdawg.io.
This is a self-reported educational readiness check based on 16 selected safeguards. It is not the formal HIPAA Security Rule risk analysis, an audit, certification, legal advice, or a determination of compliance. For a documented risk analysis or legal guidance, work with qualified security and legal professionals.
How the HIPAA security readiness score works
The percentage and letter grade are a Wolferdawg diagnostic, not a government score or HIPAA certification. Each yes answer earns the points assigned to that question. No and not sure earn zero and create a finding.
| Category | Available points | Share of score |
|---|---|---|
| Administrative safeguards | 12 of 34 | About 35% |
| Technical safeguards | 18 of 34 | About 53% |
| Physical and data safeguards | 4 of 34 | About 12% |
| Percentage | Base grade | Critical-finding rule |
|---|---|---|
| 90 to 100% | A | One critical finding caps the final grade at C. Two or more critical findings cap it at F. |
| 80 to 89% | B | |
| 70 to 79% | C | |
| 60 to 69% | D | |
| Below 60% | F |
Why the grade cap? A high total can otherwise hide an unverified safeguard that this tool treats as critical. Your formal risk analysis must evaluate the actual likelihood and impact of each risk.
What a formal HIPAA security risk analysis includes
The U.S. Department of Health and Human Services describes risk analysis as an ongoing, documented process. A complete analysis should:
- define the scope and identify all electronic protected health information the organization creates, receives, maintains, or transmits;
- identify and document reasonably anticipated threats and vulnerabilities;
- assess existing security measures;
- evaluate the likelihood and potential impact of threats;
- assign risk levels and document risk-management decisions; and
- review and update the analysis when material changes, incidents, or new risks affect the environment.
Use the official HHS risk analysis guidance, HIPAA Security Rule resources, and the federal Security Risk Assessment Tool when building the formal analysis.
Privacy, data use, and limitations
Your yes, no, and not sure answers are scored in your browser. When results appear, the usage record includes the request time, IP address and approximate location, grade, score, and total gap count. It does not include individual answers or identified gaps.
If you request an emailed checklist, the name, email address, practice name, score, grade, verdict, and identified gaps are submitted to the mail service and copied to Wolferdawg IT Consulting. By requesting the checklist, you agree that Wolferdawg IT Consulting may retain your contact information and assessment results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list.
Do not submit protected health information. Do not enter patient names, medical details, record numbers, or any other patient information into this page or the optional email form.
HHS explains that properly encrypted electronic patient information can be rendered unreadable to unauthorized people, but breach-notification duties depend on the specific facts and applicable law. See the HHS guidance on encryption and breach notification.
Founder, Wolferdawg IT Consulting. 27+ years of IT and cybersecurity experience. Content reviewed August 25, 2026.
What to do after your assessment
- Verify every no and not sure answer against current documentation and system evidence.
- Start with critical findings, then evaluate likelihood and impact in the formal risk-analysis process.
- Assign an owner, target date, and documented action for each accepted or reduced risk.
- Retest safeguards after changes and update the analysis when the environment changes.
Need a technical partner? Schedule a 30-minute call or contact Wolferdawg IT Consulting at (580) 956-8424.
Related free cybersecurity tools
Common questions about this HIPAA risk assessment
What the tool does, what it does not do, and how to use your results.
Turn the findings into a documented plan
Wolferdawg IT Consulting can help your practice verify technical safeguards, map electronic patient information, and prioritize remediation.