HIPAA Security Rule update

    Free audit-readiness score · About ten minutes

    Eight questions an auditor asks first. Answer them before one does.

    Every OCR investigation, cyber-liability renewal, and hospital questionnaire starts in the same eight areas. Answer honestly and you leave with a score, a dollar estimate of exposure, and the areas to fix.

    Start here

    Choose where you honestly are today.

    There is no right answer, only yours. No name, no email, nothing to sign up for. You do not even have to tell us who you are, and the results stay on your screen.

    Prefer to talk it through first?Talk to a Specialist

    Has your organization designated a HIPAA Privacy Officer and Security Officer?

    Choose the one that is true today. The next question opens beside this page.

    Choose where you are today

    What you leave with

    A score, a dollar figure, and the areas to fix first.

    The results appear on your screen the moment the last question is answered. Each of the eight areas is graded pass, warning, or fail from your own answers, so the areas marked fail are the list to start on.

    • A score out of 100
    • A dollar estimate of exposure
    • Eight areas graded pass, warning, or fail

    The report by email is optional

    Add an address and the full report follows: the gap analysis by area, the exposure breakdown, and a remediation roadmap. A specialist may follow up. Add nothing and the results stay on your screen.

    The results screen of the audit-readiness score: an estimated exposure figure, eight HIPAA areas graded pass, warning, or fail, and an optional email field for the full report

    Each area, graded

    The eight areas

    The eight areas, and why each one is asked.

    An OCR investigator’s first document request, a cyber-liability application, and a hospital’s vendor questionnaire ask about the same eight areas. Each area opens with the question they ask first.

    1. 01

      Privacy Officer & Compliance Program

      Someone accountable by name for privacy and for security, a written program behind them, and workforce and vendors screened against the exclusion lists.

      45 CFR 164.530(a), 164.308(a)(2)

    2. 02

      Risk Assessment

      A risk analysis in the last twelve months that covers every system that creates, receives, maintains, or transmits ePHI, with findings and a remediation plan.

      45 CFR 164.308(a)(1)(ii)(A)

    3. 03

      Policies & Procedures

      Written policies for your organization, reviewed each year, and distributed to every workforce member with a recorded acknowledgment.

      45 CFR 164.316, 164.530(i)

    4. 04

      Employee Training

      Every workforce member trained, new hires trained on arrival, completion recorded, and phishing tested rather than assumed.

      45 CFR 164.530(b), 164.308(a)(5)

    5. 05

      Business Associate Agreements

      Every vendor that touches PHI on an inventory with a signed agreement, monitored after the signature, with satisfactory assurance collected.

      45 CFR 164.502(e), 164.504(e)

    6. 06

      Technical Safeguards

      ePHI encrypted at rest and in transit, unique logins with role-based access and multi-factor authentication, email carrying PHI encrypted, and the network watched.

      45 CFR 164.312

    7. 07

      Incident & Breach Response

      A written response plan, and a team that knows the four-factor assessment and the notification deadlines before the day it is needed.

      45 CFR 164.308(a)(6), 164.400 to 164.414

    8. 08

      Physical Safeguards

      Controlled access to the places PHI is stored or viewed, workstation rules, and disposal of the devices that held it.

      45 CFR 164.310

    How the score works

    One gateway question per area. Follow-ups only where the basics are in place.

    Each area starts with its gateway question. Answer yes and the follow-ups open, so a strong area is graded on its detail. Answer no and the area is graded on that answer alone. An area passes at 75, warns at 50, and fails below. The dollar figure is a band read from your total against published OCR settlement and breach-cost figures, scaled for smaller organizations. It is a planning number, not a prediction.

    This is a self-assessment, not the risk analysis HIPAA requires under 45 CFR 164.308(a)(1)(ii)(A). That analysis is the work of the program, with a compliance team guiding it.

    Straight answers

    What the score is, and what it is not.

    The Live Compliance audit-readiness score is a free ten-minute HIPAA self-assessment across the eight areas an auditor asks about first: officers and the program, risk analysis, policies, training, business associates, technical safeguards, incident response, and physical safeguards.

    It grades each area pass, warning, or fail from your own answers, estimates dollar exposure from published enforcement figures, and keeps the results on your screen. It is not the risk analysis HIPAA requires. That is the work of the program.

    • Eight areas
    • About ten minutes
    • No signup
    • Since 2010
    • 100% audit success rate
    Talk to a specialist

    Yes. The questions and the results run in your browser. Nothing is sent to Live Compliance unless you add an email address to receive the report. There is no account, no card, and no call required.

    No. HIPAA requires a documented risk analysis of every system that handles ePHI under 45 CFR 164.308(a)(1)(ii)(A). This is a ten-minute self-assessment across eight areas, built to show where that work stands. The full risk analysis is part of every Live Compliance plan, with a compliance team guiding it.

    You do. The results appear on your screen and stay there. If you add an email, your answers and results are sent to Live Compliance to build the report, and a specialist may follow up. If you do not, nothing leaves your browser.

    It is a band read from your total score against published OCR settlement and breach-cost figures, scaled for smaller organizations. A score in the nineties reads in the tens of thousands, and a score below fifty reads above a million. It is a planning number for prioritizing, not a prediction of a fine.

    The full report in writing: the gap analysis by area, the exposure breakdown, and a remediation roadmap, so you can share it with a partner, an administrator, or your IT provider. It is optional. The on-screen results are complete without it.

    Start with the areas marked fail, in the order the eight areas run: officers and the program, then the risk analysis, then policies and training. Those four are what an investigator's first document request asks for. A specialist can read your results with you in a free 30-minute review, and the guarantee stands behind the program: audit-ready in 60 days, or we keep working at no additional cost until you are.

    Ten minutes now, or a finding later.

    Start with question one at the top of this page, or ask a specialist to read what you already have. Either way, the guarantee stands behind the program: audit-ready in 60 days, or we keep working at no additional cost until you are.

    Or talk to a specialist

    About ten minutes · No signup · No call required

    500+
    healthcare organizations
    100%
    audit success rate
    2010
    protecting healthcare since