HIPAA Risk Assessment Toolby Agent Trust Cloud

HIPAA risk assessment checklist

All 46 Security Rule standards and implementation specifications, grouped as the regulation groups them: R = required, A = addressable. The free tool asks these questions and scores the gaps.

Administrative safeguards (45 CFR 164.308)

Standard / specificationCitationR/AQuestion to ask
Risk analysis
Security management process
164.308(a)(1)(ii)(A)RHave you done an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of all the ePHI you create, receive, maintain or transmit, covering every system and location where it lives?
AI tools in scope
Security management process
164.308(a)(1)(ii)(A); 164.308(b)(1)ScopeDoes your risk analysis include AI tools (chatbots, AI scribes, writing or coding assistants) that can read or process ePHI, and do those vendors have business associate agreements?
Risk management
Security management process
164.308(a)(1)(ii)(B)RHave you put security measures in place to reduce the risks you found to a reasonable and appropriate level, with a written plan, owners and dates?
Sanction policy
Security management process
164.308(a)(1)(ii)(C)RDo you have, and apply, a written sanctions policy for workforce members who don't follow your security policies?
Information system activity review
Security management process
164.308(a)(1)(ii)(D)RDo you regularly review records of system activity, such as audit logs, access reports and security incident tracking reports?
Assigned security responsibility164.308(a)(2)RHave you named one security official who is responsible for developing and implementing your security policies and procedures?
Authorization and/or supervision
Workforce security
164.308(a)(3)(ii)(A)ADo you authorize or supervise workforce members who work with ePHI or in places where it can be accessed?
Workforce clearance procedure
Workforce security
164.308(a)(3)(ii)(B)ADo you have a procedure to decide that a person's access to ePHI is appropriate before you grant it?
Termination procedures
Workforce security
164.308(a)(3)(ii)(C)AWhen someone leaves or changes role, do you remove their access (accounts, keys, badges, remote access) promptly, under a written procedure?
Isolating health care clearinghouse functions
Information access management
164.308(a)(4)(ii)(A)RIf your organization includes a health care clearinghouse, are its ePHI and systems protected from unauthorized access by the rest of the organization? (Choose Not applicable if you have no clearinghouse function.)
Access authorization
Information access management
164.308(a)(4)(ii)(B)ADo you have written policies for granting access to ePHI, for example through a workstation, program or process?
Access establishment and modification
Information access management
164.308(a)(4)(ii)(C)ADo you set up, document, review and change each user's access rights according to those policies?
Security reminders
Security awareness and training
164.308(a)(5)(ii)(A)ADoes your whole workforce, including management, get security awareness training and periodic security reminders?
Protection from malicious software
Security awareness and training
164.308(a)(5)(ii)(B)ADo you have procedures to guard against, detect and report malicious software (anti-malware, timely patching, email filtering)?
Log-in monitoring
Security awareness and training
164.308(a)(5)(ii)(C)ADo you monitor log-in attempts and report discrepancies, such as repeated failed sign-ins or sign-ins from unusual places?
Password management
Security awareness and training
164.308(a)(5)(ii)(D)ADo you have procedures for creating, changing and safeguarding passwords, and use multi-factor authentication where it's available?
Response and reporting
Security incident procedures
164.308(a)(6)(ii)RCan you identify and respond to suspected or known security incidents, reduce their harmful effects, and document each incident and its outcome?
Data backup plan
Contingency plan
164.308(a)(7)(ii)(A)RDo you create and keep retrievable exact copies of ePHI (backups), with at least one copy that ransomware can't reach, and have you tested restoring them?
Disaster recovery plan
Contingency plan
164.308(a)(7)(ii)(B)RDo you have procedures to restore any loss of data after an emergency such as fire, flood, ransomware or system failure?
Emergency mode operation plan
Contingency plan
164.308(a)(7)(ii)(C)RCan you keep critical business processes running, while still protecting ePHI, during an emergency?
Testing and revision procedures
Contingency plan
164.308(a)(7)(ii)(D)ADo you periodically test your contingency plans and revise them based on what you learn?
Applications and data criticality analysis
Contingency plan
164.308(a)(7)(ii)(E)AHave you assessed which applications and data are most critical, to set restore priorities?
Evaluation164.308(a)(8)RDo you periodically evaluate, technically and non-technically, how well your security policies and procedures meet the Security Rule, including after changes in your environment or operations?
Written contract or other arrangement
Business associate contracts and other arrangements
164.308(b)(3)RDo you have a signed business associate agreement with every vendor that creates, receives, maintains or transmits ePHI for you (EHR, billing, IT support, cloud backup, email, answering service)?

Physical safeguards (45 CFR 164.310)

Standard / specificationCitationR/AQuestion to ask
Contingency operations
Facility access controls
164.310(a)(2)(i)ADo you have procedures that allow access to the facility to restore lost data under your disaster recovery and emergency mode plans?
Facility security plan
Facility access controls
164.310(a)(2)(ii)ADo you have a plan to protect your facility and the equipment in it from unauthorized physical access, tampering and theft?
Access control and validation procedures
Facility access controls
164.310(a)(2)(iii)ADo you control and validate people's access to the facility based on their role, including visitor control?
Maintenance records
Facility access controls
164.310(a)(2)(iv)ADo you document repairs and changes to the physical security parts of your facility, such as locks, doors and walls?
Workstation use164.310(b)RDo you have policies on how workstations that can access ePHI are used, and in what physical surroundings (including home and remote work)?
Workstation security164.310(c)RAre workstations that access ePHI physically protected so that only authorized users can use them?
Disposal
Device and media controls
164.310(d)(2)(i)RDo you have procedures for the final disposal of ePHI and of the hardware or media it was stored on (wiping, shredding, certificates of destruction)?
Media re-use
Device and media controls
164.310(d)(2)(ii)RDo you remove ePHI from electronic media before the media is re-used?
Accountability
Device and media controls
164.310(d)(2)(iii)ADo you keep a record of the movements of hardware and electronic media that hold ePHI, and who is responsible for them?
Data backup and storage
Device and media controls
164.310(d)(2)(iv)ADo you make a retrievable exact copy of ePHI before moving equipment?

Technical safeguards (45 CFR 164.312)

Standard / specificationCitationR/AQuestion to ask
Unique user identification
Access control
164.312(a)(2)(i)RDoes every person who uses a system with ePHI have their own unique user name, with no shared log-ins?
Emergency access procedure
Access control
164.312(a)(2)(ii)RDo you have a procedure for getting necessary ePHI during an emergency, for example when the usual administrator is unavailable?
Automatic logoff
Access control
164.312(a)(2)(iii)ADo sessions end or lock automatically after a set period of inactivity?
Encryption and decryption
Access control
164.312(a)(2)(iv)AIs ePHI encrypted where it is stored: laptops, phones, servers, backups and removable media?
Audit controls164.312(b)RDo your systems record, and let you examine, activity in systems that contain or use ePHI (audit logs)?
Mechanism to authenticate electronic protected health information
Integrity
164.312(c)(2)ADo you have ways to confirm that ePHI hasn't been altered or destroyed in an unauthorized way?
Person or entity authentication164.312(d)RDo you verify that a person or system asking for access to ePHI is who they claim to be, for example with strong passwords plus multi-factor authentication?
Integrity controls
Transmission security
164.312(e)(2)(i)ADo you have measures to make sure ePHI sent over a network isn't changed without detection?
Encryption
Transmission security
164.312(e)(2)(ii)AIs ePHI encrypted when it's sent over networks (secure email, TLS, VPN, patient portals)?

Policies, procedures and documentation (45 CFR 164.316)

Standard / specificationCitationR/AQuestion to ask
Policies and procedures164.316(a)RHave you written and put in place reasonable and appropriate policies and procedures for each Security Rule standard?
Time limit
Documentation
164.316(b)(2)(i)RDo you keep your security policies, procedures and required records (such as risk analyses and assessments) for six years from when they were created or last in effect, whichever is later?
Availability
Documentation
164.316(b)(2)(ii)RAre those documents available to the people responsible for carrying out the procedures they describe?
Updates
Documentation
164.316(b)(2)(iii)RDo you review your documentation periodically, and update it after changes in your environment or operations that affect ePHI security?

Addressable doesn't mean optional: see required vs addressable safeguards.

Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment

Questions

How many implementation specifications does the HIPAA Security Rule have?

Counting the standards that have no separate specifications, this checklist has 46 items across 164.308, 164.310, 164.312 and 164.316: 24 required and 22 addressable, following Appendix A to Subpart C of Part 164 and section 164.316.

Is a checklist enough for a HIPAA risk assessment?

No. A checklist shows whether a safeguard exists; a risk analysis also has to identify threats and vulnerabilities to all your ePHI and rate how likely and how harmful each risk is.

Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.

Sources