Free compliance & forms tool
HIPAA Security Risk Assessment Questionnaire
A HIPAA risk assessment is an accurate and thorough look at the risks to the confidentiality, integrity and availability of electronic patient information, and the Security Rule requires it. This free HIPAA security risk assessment tool asks 37 questions across administrative, physical and technical safeguards, then prints a prioritized list of gaps. It is a screening aid; the official free SRA Tool is the next step.
Prepared by Prospyr · Reviewed October 3, 2026 · Free, no sign-up, runs in your browser
HIPAA security gap summary
Practice: ____________________
0 of 37 questions answered. 0 in place (0%). 0 gaps: 0 high, 0 medium, 0 low priority.
Screening aid based on 45 CFR Part 164 Subpart C. It does not replace the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A).
Where does electronic PHI live?
Tick every place patient information is stored or sent. This is your starting asset list; a full risk analysis covers each one.
Administrative safeguards
0/14 answeredWho is responsible, how people get access, and how you respond when something goes wrong.
Is a specific person named as your security official?
45 CFR 164.308(a)(2) · Required
Have you completed a documented risk analysis that covers all the places electronic PHI lives?
Using this questionnaire alone does not meet the requirement.
45 CFR 164.308(a)(1)(ii)(A) · Required
Is there a written risk management plan that assigns an owner and a date to each risk you found?
45 CFR 164.308(a)(1)(ii)(B) · Required
Do you have a written sanction policy for staff who violate security policies?
45 CFR 164.308(a)(1)(ii)(C) · Required
Does someone regularly review audit logs, access reports or security incident reports?
45 CFR 164.308(a)(1)(ii)(D) · Required
Is access to PHI systems limited by job role, with a documented approval for each new user?
45 CFR 164.308(a)(3)–(4) · Addressable
Do you remove system access the same day someone leaves or changes roles?
45 CFR 164.308(a)(3)(ii)(C) · Addressable
Does every workforce member get security awareness training, including phishing and password habits, at hire and periodically?
45 CFR 164.308(a)(5) · Required
Do you have procedures to detect and report malicious software, and is anti-malware running on every computer?
45 CFR 164.308(a)(5)(ii)(B) · Addressable
Is there a written security incident procedure that tells staff how to report and respond?
45 CFR 164.308(a)(6) · Required
Are electronic PHI backups made on a schedule and stored somewhere separate from the originals?
45 CFR 164.308(a)(7)(ii)(A) · Required
Have you tested restoring from a backup in the past year?
45 CFR 164.308(a)(7)(ii)(D) · Addressable
Do you have a disaster recovery plan and an emergency-mode plan for keeping care going without your systems?
45 CFR 164.308(a)(7)(ii)(B)–(C) · Required
Do you re-evaluate your safeguards periodically and after changes such as new software or a new location?
45 CFR 164.308(a)(8) · Required
Physical safeguards
0/7 answeredYour building, front desk, workstations and devices.
Is access to areas with servers, network equipment or records limited, with visitors controlled?
45 CFR 164.310(a)(2)(ii)–(iii) · Addressable
Do you have locks, alarms or similar protection for the facility and equipment?
45 CFR 164.310(a)(2)(ii) · Addressable
Is there a written policy for how workstations may be used and where?
45 CFR 164.310(b) · Required
Are screens positioned or protected so patients and visitors cannot see PHI, and are workstations locked when unattended?
45 CFR 164.310(c) · Required
Do you have a procedure for disposing of devices, drives and paper that held PHI?
45 CFR 164.310(d)(2)(i) · Required
Is PHI wiped from a device or drive before it is reused or handed to someone else?
45 CFR 164.310(d)(2)(ii) · Required
Do you keep an inventory of devices and media that hold PHI and track when they move?
45 CFR 164.310(d)(2)(iii) · Addressable
Technical safeguards
0/8 answeredLogins, encryption and how your systems record activity.
Does every person have their own login, with no shared accounts?
45 CFR 164.312(a)(2)(i) · Required
Is there a way to reach electronic PHI in an emergency, such as when the usual system or person is unavailable?
45 CFR 164.312(a)(2)(ii) · Required
Do workstations and mobile devices log off or lock automatically after a short idle time?
45 CFR 164.312(a)(2)(iii) · Addressable
Is electronic PHI encrypted at rest, on laptops, phones, servers and backups, or have you documented an equivalent measure?
45 CFR 164.312(a)(2)(iv) · Addressable
Do your systems record who accessed or changed PHI, and can you read those records?
45 CFR 164.312(b) · Required
Do you have measures that detect improper alteration or destruction of electronic PHI?
45 CFR 164.312(c)(2) · Addressable
Do you verify that people accessing electronic PHI are who they say they are, for example with strong passwords or multi-factor sign-in?
45 CFR 164.312(d) · Required
Is electronic PHI protected when it travels over networks, including email, text messages and patient portals?
Encryption in transit is addressable under (e)(2)(ii); the protection itself is required.
45 CFR 164.312(e)(1) · Required
Business associates and vendors
0/4 answeredEvery outside company that creates, receives, stores or sends PHI for you.
Do you keep a current list of every vendor that touches PHI?
EHR, billing, texting, cloud storage, IT support, shredding, answering service.
Good practice; see 45 CFR 164.308(b) · Good practice
Is there a signed business associate agreement with each of them?
45 CFR 164.308(b)(1), (b)(3) · Required
Do the agreements require the vendor to protect PHI, report incidents and breaches to you, and hold subcontractors to the same standard?
45 CFR 164.314(a)(2)(i) · Required
Have you reviewed how each vendor protects your data, such as its security documentation, in the past year?
Good practice; supports 45 CFR 164.308(a)(1) · Good practice
Policies and documentation
0/4 answeredWritten down, findable and current.
Are your security policies and procedures written (paper or electronic)?
45 CFR 164.316(a) · Required
Do you keep policies, risk analyses and related records for at least six years?
45 CFR 164.316(b)(2)(i) · Required
Can the people who carry out each procedure actually find the current version?
45 CFR 164.316(b)(2)(ii) · Required
Do you review and update your documentation when operations or systems change?
45 CFR 164.316(b)(2)(iii) · Required
Your gap list
Answer the questions above and gaps will appear here, highest priority first.
All answers
| Question | Answer | Citation |
|---|---|---|
| Is a specific person named as your security official? | Not answered | 45 CFR 164.308(a)(2) |
| Have you completed a documented risk analysis that covers all the places electronic PHI lives? | Not answered | 45 CFR 164.308(a)(1)(ii)(A) |
| Is there a written risk management plan that assigns an owner and a date to each risk you found? | Not answered | 45 CFR 164.308(a)(1)(ii)(B) |
| Do you have a written sanction policy for staff who violate security policies? | Not answered | 45 CFR 164.308(a)(1)(ii)(C) |
| Does someone regularly review audit logs, access reports or security incident reports? | Not answered | 45 CFR 164.308(a)(1)(ii)(D) |
| Is access to PHI systems limited by job role, with a documented approval for each new user? | Not answered | 45 CFR 164.308(a)(3)–(4) |
| Do you remove system access the same day someone leaves or changes roles? | Not answered | 45 CFR 164.308(a)(3)(ii)(C) |
| Does every workforce member get security awareness training, including phishing and password habits, at hire and periodically? | Not answered | 45 CFR 164.308(a)(5) |
| Do you have procedures to detect and report malicious software, and is anti-malware running on every computer? | Not answered | 45 CFR 164.308(a)(5)(ii)(B) |
| Is there a written security incident procedure that tells staff how to report and respond? | Not answered | 45 CFR 164.308(a)(6) |
| Are electronic PHI backups made on a schedule and stored somewhere separate from the originals? | Not answered | 45 CFR 164.308(a)(7)(ii)(A) |
| Have you tested restoring from a backup in the past year? | Not answered | 45 CFR 164.308(a)(7)(ii)(D) |
| Do you have a disaster recovery plan and an emergency-mode plan for keeping care going without your systems? | Not answered | 45 CFR 164.308(a)(7)(ii)(B)–(C) |
| Do you re-evaluate your safeguards periodically and after changes such as new software or a new location? | Not answered | 45 CFR 164.308(a)(8) |
| Is access to areas with servers, network equipment or records limited, with visitors controlled? | Not answered | 45 CFR 164.310(a)(2)(ii)–(iii) |
| Do you have locks, alarms or similar protection for the facility and equipment? | Not answered | 45 CFR 164.310(a)(2)(ii) |
| Is there a written policy for how workstations may be used and where? | Not answered | 45 CFR 164.310(b) |
| Are screens positioned or protected so patients and visitors cannot see PHI, and are workstations locked when unattended? | Not answered | 45 CFR 164.310(c) |
| Do you have a procedure for disposing of devices, drives and paper that held PHI? | Not answered | 45 CFR 164.310(d)(2)(i) |
| Is PHI wiped from a device or drive before it is reused or handed to someone else? | Not answered | 45 CFR 164.310(d)(2)(ii) |
| Do you keep an inventory of devices and media that hold PHI and track when they move? | Not answered | 45 CFR 164.310(d)(2)(iii) |
| Does every person have their own login, with no shared accounts? | Not answered | 45 CFR 164.312(a)(2)(i) |
| Is there a way to reach electronic PHI in an emergency, such as when the usual system or person is unavailable? | Not answered | 45 CFR 164.312(a)(2)(ii) |
| Do workstations and mobile devices log off or lock automatically after a short idle time? | Not answered | 45 CFR 164.312(a)(2)(iii) |
| Is electronic PHI encrypted at rest, on laptops, phones, servers and backups, or have you documented an equivalent measure? | Not answered | 45 CFR 164.312(a)(2)(iv) |
| Do your systems record who accessed or changed PHI, and can you read those records? | Not answered | 45 CFR 164.312(b) |
| Do you have measures that detect improper alteration or destruction of electronic PHI? | Not answered | 45 CFR 164.312(c)(2) |
| Do you verify that people accessing electronic PHI are who they say they are, for example with strong passwords or multi-factor sign-in? | Not answered | 45 CFR 164.312(d) |
| Is electronic PHI protected when it travels over networks, including email, text messages and patient portals? | Not answered | 45 CFR 164.312(e)(1) |
| Do you keep a current list of every vendor that touches PHI? | Not answered | Good practice; see 45 CFR 164.308(b) |
| Is there a signed business associate agreement with each of them? | Not answered | 45 CFR 164.308(b)(1), (b)(3) |
| Do the agreements require the vendor to protect PHI, report incidents and breaches to you, and hold subcontractors to the same standard? | Not answered | 45 CFR 164.314(a)(2)(i) |
| Have you reviewed how each vendor protects your data, such as its security documentation, in the past year? | Not answered | Good practice; supports 45 CFR 164.308(a)(1) |
| Are your security policies and procedures written (paper or electronic)? | Not answered | 45 CFR 164.316(a) |
| Do you keep policies, risk analyses and related records for at least six years? | Not answered | 45 CFR 164.316(b)(2)(i) |
| Can the people who carry out each procedure actually find the current version? | Not answered | 45 CFR 164.316(b)(2)(ii) |
| Do you review and update your documentation when operations or systems change? | Not answered | 45 CFR 164.316(b)(2)(iii) |
Safeguards in place
0%
0 of 37 questions answered "in place". 0 answered so far.
0 gaps: 0 high, 0 medium, 0 low priority.
- Administrative safeguards0/14
- Physical safeguards0/7
- Technical safeguards0/8
- Business associates and vendors0/4
- Policies and documentation0/4
A screening aid, not the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A), and not legal advice. Answers stay in your browser and in the page address.
How the HIPAA security risk assessment works
A risk analysis has four jobs. Use them as the frame when you move from this questionnaire to your full assessment.
- Inventory. List where electronic PHI lives: EHR, email, phones, backups, vendors. The checkboxes at the top of the tool start that list.
- Find weaknesses. Compare each place to the Security Rule safeguards. The questions below do this at a screening level.
- Rate the risk. For each gap, judge how likely a problem is and how much harm it would cause.
- Act and document. Assign an owner and a date, then keep the paperwork for six years.
The tool covers step two and gives you a head start on steps one and four. Steps three and four are yours, which is why the printed summary has room for follow-up.
HIPAA risk assessment questions: the five areas this tool covers
- Administrative safeguards (14 questions). Security official, risk analysis and management, access, training, incident response and backup plans.
- Physical safeguards (7). Facility access, workstations, device disposal and reuse.
- Technical safeguards (8). Unique logins, automatic logoff, encryption, audit controls, authentication and transmission security.
- Business associates (4). Vendor list, signed agreements and what they must report to you.
- Policies and documentation (4). Written policies, six-year retention and review.
Each question shows its 45 CFR citation and whether the specification is required or addressable, so the printout can go straight into your compliance binder.
Worked example: reading your gap list
A practice answers all 37 questions and marks 3 not applicable, leaving 34. It answers "in place" on 26, so 26 ÷ 34 = 76% in place. The 8 gaps sort like this:
- High (3): no documented risk analysis, no risk management plan, and unsure whether anyone reviews audit logs. All three are required.
- Medium (4): the sanction policy and business associate agreements are only partly done (required), and nobody has tested a backup restore or turned on encryption for laptops (addressable).
- Low (1): automatic logoff covers desktops but not tablets.
The first two high items are the same requirement, so the practice starts there: run the SRA Tool, record the results, and write the plan. The percentage is a progress marker, not a compliance score.
HIPAA risk assessment tool vs. the official SRA Tool
The HHS and ONC Security Risk Assessment Tool is free and built for small and medium providers. It walks through multiple-choice questions, threats and vulnerabilities, and asset and vendor management. It takes longer than this questionnaire and produces the detailed record an auditor expects. Use this page when you want a ten-minute read on where the gaps are, or a one-page printout for your team. Use the SRA Tool for the analysis itself.
Pair this with the HIPAA compliance checklistfor the Privacy and Breach rules, and see how Prospyr's aesthetic EMR handles access and records for your practice.
Frequently asked questions
What is a HIPAA security risk assessment?
It is the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A): an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic PHI your practice holds. You list where electronic PHI lives, identify threats and weaknesses, rate the risk, and write down what you will do about it. The Security Rule marks this specification as required.
Is there a free HIPAA risk assessment tool?
Yes. HHS and the Office of the National Coordinator for Health IT publish a free Security Risk Assessment (SRA) Tool for small and medium providers, as a Windows application or an Excel workbook. This page's questionnaire is a faster first pass that follows the same safeguard groupings. Use it to see where you stand, then do the full analysis in the SRA Tool.
How often should a HIPAA risk assessment be done?
The Security Rule does not set a fixed interval. It requires an ongoing process and says to evaluate your safeguards periodically and when operations change. Many practices repeat the analysis every year and after changes such as a new EHR, a new location, a new vendor or a security incident. Put the date on each printed summary and keep it.
What does a HIPAA risk assessment cover?
It covers every place electronic PHI is created, received, stored or sent, and the administrative, physical and technical safeguards around each one. That includes your EHR, email, text messages, laptops, phones, backups, cloud storage and the vendors that touch the data. The questionnaire above walks through those safeguard groups, using the sections of 45 CFR 164.308, 164.310 and 164.312.
Does completing this questionnaire make me HIPAA compliant?
No. It is a screening aid and does not satisfy the risk analysis requirement on its own. The SRA Tool itself states that it is neither required by nor a guarantee of compliance. Compliance means you can show you identified your risks, acted on them and documented both.
What do the priority labels mean?
They are this tool's triage rule, not an OCR scoring method. A required safeguard that is missing, or that you are not sure about, is high. A required safeguard that is only partly in place, or an addressable safeguard that is missing, is medium. An addressable safeguard that is partly in place is low. Fix high items first, then use your own judgment about likelihood and impact.
What is the difference between required and addressable?
Required specifications must be implemented. Addressable ones must be implemented if reasonable and appropriate, or you document why an equivalent alternative is. Addressable does not mean optional. The labels on each question follow the Security Rule text.
Sources and scope
- HHS and ONC Security Risk Assessment (SRA) Tool
Free for small and medium providers. States it is neither required by nor a guarantee of compliance with federal, state or local laws.
- 45 CFR 164.308: Administrative safeguards
Risk analysis and risk management (required), workforce, training, incident, contingency plan and evaluation standards, business associate contracts.
- 45 CFR 164.310: Physical safeguards
- 45 CFR 164.312: Technical safeguards
Required vs. addressable labels used on each question.
- 45 CFR 164.316: Policies and procedures and documentation
Written policies, six-year retention, availability and periodic review.
A screening aid, not the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A) and not legal advice. It does not certify HIPAA compliance. State law may add requirements; confirm with your attorney or compliance officer.