HIPAA risk assessment tool
A free HIPAA security risk assessment: answer one question for each Security Rule safeguard and get a likelihood × impact risk register, a heat map and a downloadable report. No sign-up.
Runs in your browser. Nothing is sent or stored. Do not enter patient information.
Rule status, checked 1 October 2026: a risk analysis is required today under 45 CFR 164.308(a)(1)(ii)(A). HHS's proposed Security Rule update (January 2025) is not final; the current rule applies. Details and dates.
Your HIPAA risk assessment
0 questions are unanswered and are left out of the score. Answer them for a complete register.
By safeguard group
| Group | Applicable | In place | Gaps |
|---|
Heat map: likelihood × impact
Each cell counts the gaps at that likelihood (rows) and impact (columns).
| I1 | I2 | I3 | I4 | I5 |
|---|
Risk register
Highest risk first. Change likelihood or impact where you know better and the score updates; add an owner and a due date for each action, then download.
No gaps in your answers. Keep evidence that each safeguard is really in place.
| # | Safeguard | Likelihood | Impact | Risk | Recommended action | Owner | Due |
|---|
Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.
What this HIPAA risk assessment covers
The questions follow the Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR) and 45 CFR 164.316: policies, procedures and documentation: 20 standards and 46 items in all, 24 required and 22 addressable, across administrative (45 CFR 164.308: administrative safeguards), physical (45 CFR 164.310: physical safeguards) and technical (45 CFR 164.312: technical safeguards) safeguards and documentation. One extra scope check asks whether AI tools that can see ePHI are in your analysis and covered by business associate agreements.
How the risk register is scored
- Likelihood (1-5) comes from your answer: Partly = 3, Not in place or Not sure = 4. A safeguard nobody can confirm can't be relied on, so "Not sure" counts as missing.
- Impact (1-5) is a default for each safeguard: how much harm its absence typically allows to the confidentiality, integrity or availability of ePHI in a small practice. Change it where you know your situation is different.
- Risk = likelihood × impact, the qualitative method described in NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments: 1-4 low, 5-9 medium, 10-16 high, 20-25 critical.
- Addressable items accept "Alternative documented", which counts as in place, because 45 CFR 164.306: general rules, including addressable specifications (d) allows an equivalent alternative measure when the specification itself isn't reasonable and appropriate.
What to do with the result
- Download the report and the CSV risk register; keep the report with your risk analysis documentation for six years.
- Give each gap an owner and a due date: that is your risk management plan, required by 164.308(a)(1)(ii)(B).
- Complete the parts a checklist can't: an inventory of every system and vendor that holds ePHI, and the threats to each. The security risk assessment guide and template show how.
Questions
Is this HIPAA risk assessment tool free?
Yes. The whole assessment, the risk register and the downloadable report are free, with no sign-up.
Is my information sent or stored anywhere?
No. The tool runs entirely in your browser; answers are not sent to us or anyone else and are gone when you close the tab. The site's content security policy blocks the page from making any outgoing request. Never enter patient information: the free-text fields refuse values that look like Social Security numbers, medical record numbers or dates of birth.
What does the tool cover?
One question for each of the 46 standards and implementation specifications of the HIPAA Security Rule's administrative, physical and technical safeguards and documentation requirements (45 CFR 164.308, 164.310, 164.312 and 164.316), marked required or addressable, plus a scope check for AI tools that can see ePHI.
How is risk scored?
Each gap gets a likelihood from your answer (Partly = 3, Not in place or Not sure = 4) and a default impact for that safeguard, both on a 1-5 scale and both editable in the register. Risk = likelihood × impact, from 1 to 25: 1-4 low, 5-9 medium, 10-16 high, 20-25 critical.
Is this a complete HIPAA risk analysis?
No. It shows which Security Rule safeguards look missing and how serious each gap is, and gives you a register to work from. HHS expects an accurate and thorough analysis of risks to all your ePHI, including an inventory of systems and the threats to each. It is not legal advice.
Is the tool endorsed by HHS?
No. It is made by Agent Trust Cloud and is not affiliated with or endorsed by HHS. HHS does not certify risk assessment tools; its own free SRA Tool is compared fairly on our SRA Tool comparison page.