HIPAA Risk Assessment Toolby Agent Trust Cloud

HIPAA risk assessment tool

A free HIPAA security risk assessment: answer one question for each Security Rule safeguard and get a likelihood × impact risk register, a heat map and a downloadable report. No sign-up.

Runs in your browser. Nothing is sent or stored. Do not enter patient information.

Rule status, checked 1 October 2026: a risk analysis is required today under 45 CFR 164.308(a)(1)(ii)(A). HHS's proposed Security Rule update (January 2025) is not final; the current rule applies. Details and dates.

Organization name only. Never enter patient names, record numbers or dates of birth.

0 of 47 answered

Administrative safeguards 45 CFR 164.308

Security management process 164.308(a)(1)

Have you done an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of all the ePHI you create, receive, maintain or transmit, covering every system and location where it lives?

Required Risk analysis · 45 CFR 164.308(a)(1)(ii)(A)

Does your risk analysis include AI tools (chatbots, AI scribes, writing or coding assistants) that can read or process ePHI, and do those vendors have business associate agreements?

Scope check AI tools in scope · 45 CFR 164.308(a)(1)(ii)(A); 164.308(b)(1)

Have you put security measures in place to reduce the risks you found to a reasonable and appropriate level, with a written plan, owners and dates?

Required Risk management · 45 CFR 164.308(a)(1)(ii)(B)

Do you have, and apply, a written sanctions policy for workforce members who don't follow your security policies?

Required Sanction policy · 45 CFR 164.308(a)(1)(ii)(C)

Do you regularly review records of system activity, such as audit logs, access reports and security incident tracking reports?

Required Information system activity review · 45 CFR 164.308(a)(1)(ii)(D)

Assigned security responsibility 164.308(a)(2)

Have you named one security official who is responsible for developing and implementing your security policies and procedures?

Required Assigned security responsibility · 45 CFR 164.308(a)(2)

Workforce security 164.308(a)(3)

Do you authorize or supervise workforce members who work with ePHI or in places where it can be accessed?

Addressable Authorization and/or supervision · 45 CFR 164.308(a)(3)(ii)(A)

Do you have a procedure to decide that a person's access to ePHI is appropriate before you grant it?

Addressable Workforce clearance procedure · 45 CFR 164.308(a)(3)(ii)(B)

When someone leaves or changes role, do you remove their access (accounts, keys, badges, remote access) promptly, under a written procedure?

Addressable Termination procedures · 45 CFR 164.308(a)(3)(ii)(C)

Information access management 164.308(a)(4)

If your organization includes a health care clearinghouse, are its ePHI and systems protected from unauthorized access by the rest of the organization? (Choose Not applicable if you have no clearinghouse function.)

Required Isolating health care clearinghouse functions · 45 CFR 164.308(a)(4)(ii)(A)

Do you have written policies for granting access to ePHI, for example through a workstation, program or process?

Addressable Access authorization · 45 CFR 164.308(a)(4)(ii)(B)

Do you set up, document, review and change each user's access rights according to those policies?

Addressable Access establishment and modification · 45 CFR 164.308(a)(4)(ii)(C)

Security awareness and training 164.308(a)(5)

Does your whole workforce, including management, get security awareness training and periodic security reminders?

Addressable Security reminders · 45 CFR 164.308(a)(5)(ii)(A)

Do you have procedures to guard against, detect and report malicious software (anti-malware, timely patching, email filtering)?

Addressable Protection from malicious software · 45 CFR 164.308(a)(5)(ii)(B)

Do you monitor log-in attempts and report discrepancies, such as repeated failed sign-ins or sign-ins from unusual places?

Addressable Log-in monitoring · 45 CFR 164.308(a)(5)(ii)(C)

Do you have procedures for creating, changing and safeguarding passwords, and use multi-factor authentication where it's available?

Addressable Password management · 45 CFR 164.308(a)(5)(ii)(D)

Security incident procedures 164.308(a)(6)

Can you identify and respond to suspected or known security incidents, reduce their harmful effects, and document each incident and its outcome?

Required Response and reporting · 45 CFR 164.308(a)(6)(ii)

Contingency plan 164.308(a)(7)

Do you create and keep retrievable exact copies of ePHI (backups), with at least one copy that ransomware can't reach, and have you tested restoring them?

Required Data backup plan · 45 CFR 164.308(a)(7)(ii)(A)

Do you have procedures to restore any loss of data after an emergency such as fire, flood, ransomware or system failure?

Required Disaster recovery plan · 45 CFR 164.308(a)(7)(ii)(B)

Can you keep critical business processes running, while still protecting ePHI, during an emergency?

Required Emergency mode operation plan · 45 CFR 164.308(a)(7)(ii)(C)

Do you periodically test your contingency plans and revise them based on what you learn?

Addressable Testing and revision procedures · 45 CFR 164.308(a)(7)(ii)(D)

Have you assessed which applications and data are most critical, to set restore priorities?

Addressable Applications and data criticality analysis · 45 CFR 164.308(a)(7)(ii)(E)

Evaluation 164.308(a)(8)

Do you periodically evaluate, technically and non-technically, how well your security policies and procedures meet the Security Rule, including after changes in your environment or operations?

Required Evaluation · 45 CFR 164.308(a)(8)

Business associate contracts and other arrangements 164.308(b)(1)

Do you have a signed business associate agreement with every vendor that creates, receives, maintains or transmits ePHI for you (EHR, billing, IT support, cloud backup, email, answering service)?

Required Written contract or other arrangement · 45 CFR 164.308(b)(3)

Physical safeguards 45 CFR 164.310

Facility access controls 164.310(a)(1)

Do you have procedures that allow access to the facility to restore lost data under your disaster recovery and emergency mode plans?

Addressable Contingency operations · 45 CFR 164.310(a)(2)(i)

Do you have a plan to protect your facility and the equipment in it from unauthorized physical access, tampering and theft?

Addressable Facility security plan · 45 CFR 164.310(a)(2)(ii)

Do you control and validate people's access to the facility based on their role, including visitor control?

Addressable Access control and validation procedures · 45 CFR 164.310(a)(2)(iii)

Do you document repairs and changes to the physical security parts of your facility, such as locks, doors and walls?

Addressable Maintenance records · 45 CFR 164.310(a)(2)(iv)

Workstation use 164.310(b)

Do you have policies on how workstations that can access ePHI are used, and in what physical surroundings (including home and remote work)?

Required Workstation use · 45 CFR 164.310(b)

Workstation security 164.310(c)

Are workstations that access ePHI physically protected so that only authorized users can use them?

Required Workstation security · 45 CFR 164.310(c)

Device and media controls 164.310(d)(1)

Do you have procedures for the final disposal of ePHI and of the hardware or media it was stored on (wiping, shredding, certificates of destruction)?

Required Disposal · 45 CFR 164.310(d)(2)(i)

Do you remove ePHI from electronic media before the media is re-used?

Required Media re-use · 45 CFR 164.310(d)(2)(ii)

Do you keep a record of the movements of hardware and electronic media that hold ePHI, and who is responsible for them?

Addressable Accountability · 45 CFR 164.310(d)(2)(iii)

Do you make a retrievable exact copy of ePHI before moving equipment?

Addressable Data backup and storage · 45 CFR 164.310(d)(2)(iv)

Technical safeguards 45 CFR 164.312

Access control 164.312(a)(1)

Does every person who uses a system with ePHI have their own unique user name, with no shared log-ins?

Required Unique user identification · 45 CFR 164.312(a)(2)(i)

Do you have a procedure for getting necessary ePHI during an emergency, for example when the usual administrator is unavailable?

Required Emergency access procedure · 45 CFR 164.312(a)(2)(ii)

Do sessions end or lock automatically after a set period of inactivity?

Addressable Automatic logoff · 45 CFR 164.312(a)(2)(iii)

Is ePHI encrypted where it is stored: laptops, phones, servers, backups and removable media?

Addressable Encryption and decryption · 45 CFR 164.312(a)(2)(iv)

Audit controls 164.312(b)

Do your systems record, and let you examine, activity in systems that contain or use ePHI (audit logs)?

Required Audit controls · 45 CFR 164.312(b)

Integrity 164.312(c)(1)

Do you have ways to confirm that ePHI hasn't been altered or destroyed in an unauthorized way?

Addressable Mechanism to authenticate electronic protected health information · 45 CFR 164.312(c)(2)

Person or entity authentication 164.312(d)

Do you verify that a person or system asking for access to ePHI is who they claim to be, for example with strong passwords plus multi-factor authentication?

Required Person or entity authentication · 45 CFR 164.312(d)

Transmission security 164.312(e)(1)

Do you have measures to make sure ePHI sent over a network isn't changed without detection?

Addressable Integrity controls · 45 CFR 164.312(e)(2)(i)

Is ePHI encrypted when it's sent over networks (secure email, TLS, VPN, patient portals)?

Addressable Encryption · 45 CFR 164.312(e)(2)(ii)

Policies, procedures and documentation 45 CFR 164.316

Policies and procedures 164.316(a)

Have you written and put in place reasonable and appropriate policies and procedures for each Security Rule standard?

Required Policies and procedures · 45 CFR 164.316(a)

Documentation 164.316(b)(1)

Do you keep your security policies, procedures and required records (such as risk analyses and assessments) for six years from when they were created or last in effect, whichever is later?

Required Time limit · 45 CFR 164.316(b)(2)(i)

Are those documents available to the people responsible for carrying out the procedures they describe?

Required Availability · 45 CFR 164.316(b)(2)(ii)

Do you review your documentation periodically, and update it after changes in your environment or operations that affect ePHI security?

Required Updates · 45 CFR 164.316(b)(2)(iii)

What this HIPAA risk assessment covers

The questions follow the Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR) and 45 CFR 164.316: policies, procedures and documentation: 20 standards and 46 items in all, 24 required and 22 addressable, across administrative (45 CFR 164.308: administrative safeguards), physical (45 CFR 164.310: physical safeguards) and technical (45 CFR 164.312: technical safeguards) safeguards and documentation. One extra scope check asks whether AI tools that can see ePHI are in your analysis and covered by business associate agreements.

How the risk register is scored

What to do with the result

  1. Download the report and the CSV risk register; keep the report with your risk analysis documentation for six years.
  2. Give each gap an owner and a due date: that is your risk management plan, required by 164.308(a)(1)(ii)(B).
  3. Complete the parts a checklist can't: an inventory of every system and vendor that holds ePHI, and the threats to each. The security risk assessment guide and template show how.

Questions

Is this HIPAA risk assessment tool free?

Yes. The whole assessment, the risk register and the downloadable report are free, with no sign-up.

Is my information sent or stored anywhere?

No. The tool runs entirely in your browser; answers are not sent to us or anyone else and are gone when you close the tab. The site's content security policy blocks the page from making any outgoing request. Never enter patient information: the free-text fields refuse values that look like Social Security numbers, medical record numbers or dates of birth.

What does the tool cover?

One question for each of the 46 standards and implementation specifications of the HIPAA Security Rule's administrative, physical and technical safeguards and documentation requirements (45 CFR 164.308, 164.310, 164.312 and 164.316), marked required or addressable, plus a scope check for AI tools that can see ePHI.

How is risk scored?

Each gap gets a likelihood from your answer (Partly = 3, Not in place or Not sure = 4) and a default impact for that safeguard, both on a 1-5 scale and both editable in the register. Risk = likelihood × impact, from 1 to 25: 1-4 low, 5-9 medium, 10-16 high, 20-25 critical.

Is this a complete HIPAA risk analysis?

No. It shows which Security Rule safeguards look missing and how serious each gap is, and gives you a register to work from. HHS expects an accurate and thorough analysis of risks to all your ePHI, including an inventory of systems and the threats to each. It is not legal advice.

Is the tool endorsed by HHS?

No. It is made by Agent Trust Cloud and is not affiliated with or endorsed by HHS. HHS does not certify risk assessment tools; its own free SRA Tool is compared fairly on our SRA Tool comparison page.