Would your handling of patient data stand up to scrutiny?
The five areas HIPAA itself is organized around — administrative, technical and physical safeguards, privacy and patient rights, vendors and breach readiness. Plain language, scored on screen, with a branded PDF report to keep.
Your level, five-dimension profile and recommendations appear on screen the moment you finish — no email, and the branded PDF report is yours to keep.
01Administrative Safeguards
02Technical Safeguards
03Physical Safeguards
04Privacy & Patient Rights
05Vendors & Breach Readiness
Scored in this browser — nothing is sent unless you choose to.
Written by DigiWagon’s delivery practiceScored with the published DigiWagon HIPAA Readiness FrameworkISO/IEC 27001 and ISO 9001 certifiedWork we’ve delivered
This checklist is an educational self-assessment built from the HIPAA Security and Privacy Rules’ published safeguards. It is not legal advice, an audit, or a certification — engage qualified counsel for compliance determinations.
Who this is for
Digital health founders building or commissioning software that touches PHI
Practice and clinic operators responsible for patient data
Compliance and operations leads preparing for scrutiny
The flow
How it works
01Answer quick multiple-choice questions about how patient data is actually handled today — options, not essays.
02Get your readiness level and a five-area profile, scored against the published rubric.
03Keep the branded PDF report — and send your results through if software that touches PHI is on your roadmap.
Every result is one level and five area scores — an example profile.
The framework
Five areas, scored in the open
Every answer carries zero to three points by the maturity it describes. Three questions per area give an area score out of nine; the five dimensions together map to one of four readiness levels. The rubric is published because a score you can't inspect isn't worth acting on.
0–3 per answer→3 questions per dimension→dimension score out of 9→5 dimensions→your result out of 45
No gate. Full results on screen — email is never required to see them.
Nothing stored. Answers are scored in your browser and never leave this page unless you choose to send them.
No invented benchmarks. Every number derives from the published rubric and your own answers.
All five dimensions weigh equally in v1 — deliberately, until real-world results earn differentiated weights. Framework v1 · September 2026.
The management layer HIPAA checks first: a current risk analysis, named security and privacy officers, and a trained workforce.
Why this matters
Enforcement actions cite a missing or stale risk analysis more than any technical failure — the fines follow the paperwork. Administrative safeguards are also where every other control gets its authority and budget.
When did your organization last complete a HIPAA risk analysis?
Who is responsible for HIPAA security and privacy?
How is your workforce trained on handling patient information?
02
Technical Safeguards
The controls inside your systems: who can access patient data, whether it's encrypted in transit and at rest, and whether access leaves an audit trail.
Why this matters
Technical safeguards decide the blast radius of every mistake: stolen laptops and phished passwords become reportable breaches or non-events depending on the encryption and access design underneath.
How is access to patient data controlled?
Is patient data encrypted?
Could you tell who accessed a specific patient record, and when?
03
Physical Safeguards
The tangible layer: who can walk up to systems and records, how laptops and phones that touch patient data are managed, and how hardware and paper leave the building.
Why this matters
Breach reports are full of physical stories — the unencrypted laptop from a car, the un-wiped copier sold on. Physical safeguards are the cheapest ones to get right and the most embarrassing to explain when missed.
How is physical access to systems and records controlled?
How are laptops and phones that touch patient data managed?
What happens to old hardware and paper records?
04
Privacy & Patient Rights
The Privacy Rule in daily practice: minimum-necessary access, an honest Notice of Privacy Practices, and what actually happens when a patient asks for their records.
Why this matters
Patient-rights failures generate complaints, and complaints are how small organizations end up under investigation — the right-of-access rules have their own enforcement program with a steady record of penalties.
How does "minimum necessary" work in your organization?
Where does your Notice of Privacy Practices stand?
A patient asks for their records — what happens?
05
Vendors & Breach Readiness
The perimeter you don't control: Business Associate Agreements with every vendor touching PHI, a tested incident plan, and the 60-day breach-notification clock.
Why this matters
Your compliance is only as strong as the vendors holding your data — and when something goes wrong, the clock starts at discovery, not at readiness. Improvised breach response is how bad days become penalties.
Do Business Associate Agreements cover the vendors that touch patient data?
If patient data leaked tonight, what would happen?
How prepared are you for breach-notification obligations?
What your score means
Exposed0–13 of 45
Gaps at this level aren't paperwork problems — they're the conditions breaches and penalties come from, and most carry personal stress for whoever owns the fallout. The sequence that works: risk analysis, named owner, encryption, BAAs. Weeks of focused work changes your position materially; start with the lowest area below.
Patchwork14–24 of 45
Real safeguards exist — what's missing is the system holding them together, and patchwork fails exactly where the pieces meet: the unmanaged laptop, the vendor without a BAA, the log nobody reads. Pick each area's recommendation and finish it; completion, not sophistication, is this level's work.
Structured25–35 of 45
Your program is genuinely organized — the remaining distance is between 'we have it' and 'we can prove it': reviews on calendars, plans actually tested, documentation that would satisfy an auditor on a bad day. If you're building software that touches PHI, this is a strong position to build from.
Audit-Ready36–45 of 45
This posture would stand up to scrutiny, and it compounds: partners sign faster, enterprise deals clear security review, and new products inherit controls instead of retrofitting them. The work now is keeping it true through change — every new vendor, system and hire arrives inside the discipline.
FAQ
About this checklist
Short answers to what people ask before they take it — including what a self-assessment can and cannot tell you.
01What is a HIPAA compliance checklist?
A HIPAA compliance checklist is a structured way to assess how an organization handles protected health information against the safeguards the law requires — administrative, technical and physical controls, privacy practices, and vendor management. It turns a dense regulation into concrete questions you can answer, showing which obligations are covered and which need work.
02Who should use this checklist?
Anyone responsible for an organization that creates, stores or transmits protected health information: healthcare providers, digital health startups, and the operations or product leaders building software that touches patient data. The questions are written in plain language — you need working knowledge of your organization, not a compliance background.
03Is this checklist legal advice or a certification?
No. This is an educational self-assessment built from the HIPAA Security and Privacy Rules' published safeguards. It shows where your posture likely stands and what typically closes each gap, but it is not legal advice, an audit, or any form of certification — engage qualified counsel for compliance determinations.
04What does the checklist cover?
Five areas mirroring how HIPAA itself is organized: administrative safeguards like risk analysis and training, technical safeguards like access control and encryption, physical safeguards for facilities and devices, privacy practices and patient rights, and vendor management with breach readiness. Three questions each show exactly where attention is needed first.
05Do I need to share my email address to see the results?
No. Your score, the five-area breakdown and every recommendation appear on screen the moment you finish, and the branded PDF report generates locally in your browser. Contact details only come into it if you choose to send your results to our team for a build-readiness conversation.
06What should we do after a low score?
Start with whichever area scored lowest — its recommendation names the first concrete step, and the highest-risk gaps are usually a current risk analysis, encryption coverage and Business Associate Agreements. If you're building or commissioning software that touches patient data, send your results through and we'll walk the technical gaps with you.
Building software that touches patient data?
Send your results through and we'll walk the technical gaps with you — access design, encryption, audit trails and the architecture choices that make compliance a property of the system rather than a promise. A working conversation, not a pitch.
One click opens the assistant you already use with a question that points it at this page, so the answer comes from what we publish, not a guess.
The question it opens withRead https://digiwagon.com/tools/hipaa-compliance-checklist and tell me what "HIPAA Compliance Checklist" helps me decide, what inputs I should gather before using it, and how DigiWagon suggests acting on the result. Stick to what the page says and mark anything you are not sure about.