HIPAA risk assessment checklist
All 46 Security Rule standards and implementation specifications, grouped as the regulation groups them: R = required, A = addressable. The free tool asks these questions and scores the gaps.
Administrative safeguards (45 CFR 164.308)
| Standard / specification | Citation | R/A | Question to ask |
|---|---|---|---|
| Risk analysis Security management process | 164.308(a)(1)(ii)(A) | R | Have you done an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of all the ePHI you create, receive, maintain or transmit, covering every system and location where it lives? |
| AI tools in scope Security management process | 164.308(a)(1)(ii)(A); 164.308(b)(1) | Scope | Does your risk analysis include AI tools (chatbots, AI scribes, writing or coding assistants) that can read or process ePHI, and do those vendors have business associate agreements? |
| Risk management Security management process | 164.308(a)(1)(ii)(B) | R | Have you put security measures in place to reduce the risks you found to a reasonable and appropriate level, with a written plan, owners and dates? |
| Sanction policy Security management process | 164.308(a)(1)(ii)(C) | R | Do you have, and apply, a written sanctions policy for workforce members who don't follow your security policies? |
| Information system activity review Security management process | 164.308(a)(1)(ii)(D) | R | Do you regularly review records of system activity, such as audit logs, access reports and security incident tracking reports? |
| Assigned security responsibility | 164.308(a)(2) | R | Have you named one security official who is responsible for developing and implementing your security policies and procedures? |
| Authorization and/or supervision Workforce security | 164.308(a)(3)(ii)(A) | A | Do you authorize or supervise workforce members who work with ePHI or in places where it can be accessed? |
| Workforce clearance procedure Workforce security | 164.308(a)(3)(ii)(B) | A | Do you have a procedure to decide that a person's access to ePHI is appropriate before you grant it? |
| Termination procedures Workforce security | 164.308(a)(3)(ii)(C) | A | When someone leaves or changes role, do you remove their access (accounts, keys, badges, remote access) promptly, under a written procedure? |
| Isolating health care clearinghouse functions Information access management | 164.308(a)(4)(ii)(A) | R | If your organization includes a health care clearinghouse, are its ePHI and systems protected from unauthorized access by the rest of the organization? (Choose Not applicable if you have no clearinghouse function.) |
| Access authorization Information access management | 164.308(a)(4)(ii)(B) | A | Do you have written policies for granting access to ePHI, for example through a workstation, program or process? |
| Access establishment and modification Information access management | 164.308(a)(4)(ii)(C) | A | Do you set up, document, review and change each user's access rights according to those policies? |
| Security reminders Security awareness and training | 164.308(a)(5)(ii)(A) | A | Does your whole workforce, including management, get security awareness training and periodic security reminders? |
| Protection from malicious software Security awareness and training | 164.308(a)(5)(ii)(B) | A | Do you have procedures to guard against, detect and report malicious software (anti-malware, timely patching, email filtering)? |
| Log-in monitoring Security awareness and training | 164.308(a)(5)(ii)(C) | A | Do you monitor log-in attempts and report discrepancies, such as repeated failed sign-ins or sign-ins from unusual places? |
| Password management Security awareness and training | 164.308(a)(5)(ii)(D) | A | Do you have procedures for creating, changing and safeguarding passwords, and use multi-factor authentication where it's available? |
| Response and reporting Security incident procedures | 164.308(a)(6)(ii) | R | Can you identify and respond to suspected or known security incidents, reduce their harmful effects, and document each incident and its outcome? |
| Data backup plan Contingency plan | 164.308(a)(7)(ii)(A) | R | Do you create and keep retrievable exact copies of ePHI (backups), with at least one copy that ransomware can't reach, and have you tested restoring them? |
| Disaster recovery plan Contingency plan | 164.308(a)(7)(ii)(B) | R | Do you have procedures to restore any loss of data after an emergency such as fire, flood, ransomware or system failure? |
| Emergency mode operation plan Contingency plan | 164.308(a)(7)(ii)(C) | R | Can you keep critical business processes running, while still protecting ePHI, during an emergency? |
| Testing and revision procedures Contingency plan | 164.308(a)(7)(ii)(D) | A | Do you periodically test your contingency plans and revise them based on what you learn? |
| Applications and data criticality analysis Contingency plan | 164.308(a)(7)(ii)(E) | A | Have you assessed which applications and data are most critical, to set restore priorities? |
| Evaluation | 164.308(a)(8) | R | Do you periodically evaluate, technically and non-technically, how well your security policies and procedures meet the Security Rule, including after changes in your environment or operations? |
| Written contract or other arrangement Business associate contracts and other arrangements | 164.308(b)(3) | R | Do you have a signed business associate agreement with every vendor that creates, receives, maintains or transmits ePHI for you (EHR, billing, IT support, cloud backup, email, answering service)? |
Physical safeguards (45 CFR 164.310)
| Standard / specification | Citation | R/A | Question to ask |
|---|---|---|---|
| Contingency operations Facility access controls | 164.310(a)(2)(i) | A | Do you have procedures that allow access to the facility to restore lost data under your disaster recovery and emergency mode plans? |
| Facility security plan Facility access controls | 164.310(a)(2)(ii) | A | Do you have a plan to protect your facility and the equipment in it from unauthorized physical access, tampering and theft? |
| Access control and validation procedures Facility access controls | 164.310(a)(2)(iii) | A | Do you control and validate people's access to the facility based on their role, including visitor control? |
| Maintenance records Facility access controls | 164.310(a)(2)(iv) | A | Do you document repairs and changes to the physical security parts of your facility, such as locks, doors and walls? |
| Workstation use | 164.310(b) | R | Do you have policies on how workstations that can access ePHI are used, and in what physical surroundings (including home and remote work)? |
| Workstation security | 164.310(c) | R | Are workstations that access ePHI physically protected so that only authorized users can use them? |
| Disposal Device and media controls | 164.310(d)(2)(i) | R | Do you have procedures for the final disposal of ePHI and of the hardware or media it was stored on (wiping, shredding, certificates of destruction)? |
| Media re-use Device and media controls | 164.310(d)(2)(ii) | R | Do you remove ePHI from electronic media before the media is re-used? |
| Accountability Device and media controls | 164.310(d)(2)(iii) | A | Do you keep a record of the movements of hardware and electronic media that hold ePHI, and who is responsible for them? |
| Data backup and storage Device and media controls | 164.310(d)(2)(iv) | A | Do you make a retrievable exact copy of ePHI before moving equipment? |
Technical safeguards (45 CFR 164.312)
| Standard / specification | Citation | R/A | Question to ask |
|---|---|---|---|
| Unique user identification Access control | 164.312(a)(2)(i) | R | Does every person who uses a system with ePHI have their own unique user name, with no shared log-ins? |
| Emergency access procedure Access control | 164.312(a)(2)(ii) | R | Do you have a procedure for getting necessary ePHI during an emergency, for example when the usual administrator is unavailable? |
| Automatic logoff Access control | 164.312(a)(2)(iii) | A | Do sessions end or lock automatically after a set period of inactivity? |
| Encryption and decryption Access control | 164.312(a)(2)(iv) | A | Is ePHI encrypted where it is stored: laptops, phones, servers, backups and removable media? |
| Audit controls | 164.312(b) | R | Do your systems record, and let you examine, activity in systems that contain or use ePHI (audit logs)? |
| Mechanism to authenticate electronic protected health information Integrity | 164.312(c)(2) | A | Do you have ways to confirm that ePHI hasn't been altered or destroyed in an unauthorized way? |
| Person or entity authentication | 164.312(d) | R | Do you verify that a person or system asking for access to ePHI is who they claim to be, for example with strong passwords plus multi-factor authentication? |
| Integrity controls Transmission security | 164.312(e)(2)(i) | A | Do you have measures to make sure ePHI sent over a network isn't changed without detection? |
| Encryption Transmission security | 164.312(e)(2)(ii) | A | Is ePHI encrypted when it's sent over networks (secure email, TLS, VPN, patient portals)? |
Policies, procedures and documentation (45 CFR 164.316)
| Standard / specification | Citation | R/A | Question to ask |
|---|---|---|---|
| Policies and procedures | 164.316(a) | R | Have you written and put in place reasonable and appropriate policies and procedures for each Security Rule standard? |
| Time limit Documentation | 164.316(b)(2)(i) | R | Do you keep your security policies, procedures and required records (such as risk analyses and assessments) for six years from when they were created or last in effect, whichever is later? |
| Availability Documentation | 164.316(b)(2)(ii) | R | Are those documents available to the people responsible for carrying out the procedures they describe? |
| Updates Documentation | 164.316(b)(2)(iii) | R | Do you review your documentation periodically, and update it after changes in your environment or operations that affect ePHI security? |
Addressable doesn't mean optional: see required vs addressable safeguards.
Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment
Questions
How many implementation specifications does the HIPAA Security Rule have?
Counting the standards that have no separate specifications, this checklist has 46 items across 164.308, 164.310, 164.312 and 164.316: 24 required and 22 addressable, following Appendix A to Subpart C of Part 164 and section 164.316.
Is a checklist enough for a HIPAA risk assessment?
No. A checklist shows whether a safeguard exists; a risk analysis also has to identify threats and vulnerabilities to all your ePHI and rate how likely and how harmful each risk is.
Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.
Sources
- Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR)
- 45 CFR 164.308: administrative safeguards
- 45 CFR 164.310: physical safeguards
- 45 CFR 164.312: technical safeguards
- 45 CFR 164.316: policies, procedures and documentation
- 45 CFR 164.306: general rules, including addressable specifications
- Checked 1 October 2026.