Skip to content

For medical, dental & legal practices · Private to your browser

Are your IT safeguards ready for a HIPAA question?

Check the IT safeguards the HIPAA Security Rule expects — administrative, physical, and technical — for your practice. This is an awareness self-check, not a compliance assessment. Nothing is sent anywhere.

Check every safeguard that is in place and verified today. Honest answers give you a useful picture of where your practice stands.

Administrative

Policies, people, and paperwork

Physical

Devices, screens, and disposal

Technical

Access, logging, and recovery

Reading this without JavaScript?

The list above is a plain-English map of the IT safeguards HIPAA expects. Anything you cannot check is worth a conversation before it becomes a finding. See the HIPAA-aware IT page for how each safeguard gets implemented and documented.

Want these implemented and documented?

Book the free IT Health Check

An honest word on what this is

This is an awareness self-check of the IT safeguards HIPAA expects — not a compliance assessment, not an audit, and not legal advice. HIPAA is an ongoing obligation your practice carries; a checklist cannot certify it, and no one honest will tell you otherwise. What we can do is implement, verify, and document the technical safeguards, and sign a BAA as your IT provider. For the legal and policy side, work with a HIPAA attorney or compliance consultant.

Straight answers

Does passing this mean we are HIPAA compliant?

No — and anyone who tells you a checklist makes you "HIPAA certified" is wrong. HIPAA is not a certification; it is an ongoing obligation your practice carries. This tool checks the IT safeguards side and raises your awareness of gaps. Real compliance also includes a formal risk analysis, documentation, workforce policies, and legal considerations this cannot judge. Treat it as a starting point, not a verdict.

Is this legal advice?

No. We are an IT company, not attorneys, and nothing here is legal or compliance advice. What we can do is implement, verify, and document the technical safeguards — MFA, encryption, logging, tested backups — and sign a BAA as your IT provider. For the legal and policy side, work with a HIPAA attorney or compliance consultant.

We are a small practice. Does HIPAA really apply to us?

Yes. HIPAA applies regardless of size, and small practices are frequently investigated after a breach — usually a phished email or ransomware, not a targeted hacker. The safeguards here are mostly configuration on tools you already have, which makes them some of the cheapest risk reduction available to a clinic.

Do you store what I enter?

No. There is no signup and nothing leaves your browser — the whole self-check runs on this device.

HIPAA-aware IT, built and documented.

We implement the technical safeguards, sign a BAA, and keep the documentation current — so the IT side of your HIPAA obligation is handled and provable.