Calculator overview
Inputs and outputs
This summary comes from the calculator's published input and output contract.
Inputs
- Assessment Questions
-
Default 21 rows
About this input
One row per self-assessment question grouped under the administrative, physical and technical safeguard areas: enter a score for how far the safeguard is in place and a scope flag, and edit the weight if needed. The questions are written for this tool and are not the text of the HIPAA Security Rule, so a score is not evidence of compliance. A question marked not applicable is removed from both the numerator and the denominator, so it does not penalise the score. Every question needs a score and an applicability flag from the dropdowns; an entry that is blank or not on the list makes the tool refuse to score rather than guess.
Column Range or allowed values Category Not declared Question Not declared Weight At least 0 Score 0 - Not in place, 1 - Ad hoc, 2 - Partially in place, 3 - Largely in place, 4 - Fully in place, 5 - Fully in place and verified Applicability Applicable, Not applicable
Outputs
- Share Not Applicable
-
Unit %
About this output
The questions marked not applicable as a percent of all questions, a check on how much of the set was excluded.
- Second Priority
-
Unit question
About this output
The in-scope question with the second largest weighted gap to a full score.
- Questions Not Applicable
-
Unit count
About this output
The number of questions marked not applicable. These are removed from both the numerator and the denominator, so they neither help nor penalise the score.
- Share Of The Total Gap In The Top Three
-
Unit %
About this output
The combined weighted gap of the top three priorities as a percent of the whole gap to a full score, showing how concentrated the improvement is.
- Total Weight In Scope
-
Unit weight
About this output
The sum of the weights of the questions in scope, as a weight total. It is the denominator the readiness score is measured against.
- Top Priority
-
Unit question
About this output
The in-scope question contributing the largest weighted gap to a full score, the single item worth the most improvement.
- Third Priority
-
Unit question
About this output
The in-scope question with the third largest weighted gap to a full score.
- Questions In Scope
-
Unit count
About this output
The number of questions marked applicable and therefore included in the readiness score.
- Lowest Scoring Category
-
Unit category
About this output
The safeguard area with the weakest weighted score, the natural place to focus first.
- Highest Scoring Category
-
Unit category
About this output
The safeguard area, administrative, physical or technical, with the strongest weighted score.
- Category Scores
-
No unit declared
About this output
One row per safeguard area: its weighted score in percent and its share of the total weight, so you can see where the overall figure comes from.
- Model Status
-
No unit declared
About this output
The overall check on your entries, shown above the results. It reads OK when the inputs are usable, NOT VALID with a reason when an entry makes the model meaningless, or CHECK with a reason when a result is valid but worth a second look. Read it before you trust the numbers below.
- Points Available To Gain
-
Unit points
About this output
The total weighted gap to a full score: the sum over the questions in scope of weight times score shortfall. It is measured in raw weight-times-score points on your own weight scale, not in percentage points, so re-weighting changes it even when the answers do not.
- Overall Score
-
Unit %
About this output
The weighted readiness score across the questions in scope, in percent, combining each answer with its weight. It reflects self-reported readiness, not an audit or a compliance determination.
- Overall Band
-
Unit band
About this output
The maturity band, from Not established to Optimised, read from the overall score. The band is a summary of your answers, not a certification.
What it is
This is a HIPAA Security Rule readiness self-assessment. You score 21 questions about your organisation's security safeguards, each on a scale from zero to five, and it returns a weighted readiness score as a percentage, a band, a score for each of four safeguard areas, and a ranked list of the gaps worth closing first.
What it is not, and this matters more here than on most pages. The 21 questions were written for this workbook. They are not the Security Rule's own text, they do not cover its implementation specifications exhaustively, and completing this assessment is not evidence of compliance with anything. It is not a risk analysis under the Security Rule; that is a specific, documented obligation with its own requirements, and a questionnaire is not it. It is not an audit, not a certification, and would not satisfy a regulator, an enforcement inquiry, or a customer's due diligence. The four areas are named after the Security Rule's own safeguard groupings because that grouping is publicly documented and widely understood; the names are referenced as a factual matter only. The weights, scale and band boundaries are editable and carry no official standing.
What it is good for is an internal first picture of where you stand and a defensible order of work.
Methodology
Purpose and model boundary
This model scores self-reported security-control maturity across twenty-one original questions grouped under administrative, physical, technical, and organisational/documentation safeguard headings. It produces category scores, an overall maturity score and band, and a weighted improvement-priority list.
It is a readiness aid only. It does not determine whether HIPAA applies, identify protected health information, distinguish every required and addressable implementation specification, perform a risk analysis, test evidence, provide legal advice, or establish compliance with the HIPAA Security Rule.
Inputs and units
Each fixed question row contains:
| Field | Meaning and restriction |
|---|---|
| Category and question | Locked workbook text. The questions are original and do not reproduce regulatory wording. |
Weight, w_i |
Nonnegative integer expressing the question's importance within its safeguard category. |
Score, s_i |
Required choice mapped to 0 through 5, from Not in place through Fully in place and verified. |
Applicability, a_i |
Required choice mapped to 1 for Applicable or 0 for Not applicable. |
The page uses fixed category weights: Administrative safeguards 40, Physical safeguards 20, Technical safeguards 30, and Organisational and documentation 10. Maturity bands begin at 0% Not established, 25% Initial, 45% Developing, 65% Managed, and 85% Optimised. These are workbook-authored scoring choices, not regulatory thresholds.
Governing relationships
For category c, maximum score s_max = 5, and applicable flag a_i:
CategoryScore_c = sum over i in c (w_i × s_i × a_i) / (s_max × sum over i in c (w_i × a_i))
Not-applicable questions are removed from numerator and denominator. A category with no applicable question is labelled not assessed and excluded from the overall category-weight denominator.
With fixed category weight W_c:
OverallScore = sum over assessed c (W_c × CategoryScore_c) / sum over assessed c W_c
The band is the highest threshold reached by 100 × OverallScore.
Question gaps and priorities use:
Gap_i = w_i × (s_max - s_i) × a_i
Points_Available_To_Gain = sum(Gap_i)
Positive gaps are ranked descending with a small row-index tiebreaker. Top_Priority, Second_Priority, and Third_Priority are the first three ranked questions. Their share is the sum of those three gaps divided by total gap, with zero returned when no gap exists.
Calculation sequence
- Confirm all score, applicability and weight cells are valid.
- Map score labels to 0 through 5 and applicability labels to 1 or 0.
- Calculate applicable weighted scores and weighted shortfalls by question.
- Calculate each assessed safeguard-category score and maturity band.
- Combine assessed categories using the fixed category weights.
- Rank positive gaps and return the top three question priorities.
- Calculate scope counts, assessed-category extrema, total gap and top-three share.
- Evaluate
Model_Statususing the ordered rules below.
Outputs and interpretation
Overall_Score and Overall_Band summarize the answers under this workbook's weights. They are not a regulatory score or compliance opinion. The category grid and chart show within-category scores; they do not show regulatory severity or the evidence quality behind an answer.
Points_Available_To_Gain is the raw sum of weight × score shortfall, not a percentage-point deficit. Priorities rank weighted shortfalls, so a higher-weight partial control can rank ahead of a lower-weight missing control. Highest and lowest category outputs ignore categories with no applicable questions.
Validation and status logic
The workbook evaluates status in this order:
| Condition | Returned status |
|---|---|
| Fewer than all 21 score entries match the six-item score list | NOT VALID: a score entry is blank or not one of the listed options |
| Fewer than all 21 applicability entries match the scope list | NOT VALID: an applicability entry is blank or not one of the listed options |
| Any weight is not numeric | NOT VALID: a weight is not a number |
| Any weight is blank | NOT VALID: a weight is blank |
| Any weight is negative | NOT VALID: a weight is negative |
| No question is Applicable | NOT VALID: every question is marked not applicable, so there is nothing to score |
| Total weight across Applicable questions is zero | NOT VALID: the total weight in scope is zero, so there is nothing to score |
| At least one question is Not applicable | CHECK: a question is excluded as not applicable; the Security Rule's required implementation specifications cannot be waived, so confirm each exclusion is genuinely outside this organisation's scope |
| Overall score is below 45% | CHECK: the overall score is below the Developing band; treat the priority list as a work plan |
| None of the preceding conditions applies | OK |
The exclusion warning is deliberately stricter than the other assessment models and takes precedence over the low-score warning. It does not decide that an exclusion is lawful; it tells the reader to confirm scope outside the model.
Assumptions and limitations
- Answers are self-reported and are not supported by evidence testing, interviews, sampling, technical validation or an independent audit.
- The model does not decide whether an organisation is a covered entity or business associate, what information is in scope, or which implementation specifications are required or addressable in a particular case.
- The twenty-one custom questions are not regulatory text and are not exhaustive. A high score can coexist with a material legal or security deficiency.
- Weights, the 0-to-5 scale and maturity bands are illustrative and have no official HIPAA standing.
- Marking a question Not applicable excludes it mathematically, but the model cannot determine whether that exclusion is legally or operationally supportable.
- The calculator does not perform the accurate-and-thorough risk analysis required for a real security program, estimate likelihood or impact, or create a remediation plan.
- Category averages can hide a critical individual weakness. Review question-level answers, evidence and risk context rather than relying on the headline score.
Restrictions and non-computing states
The grid has exactly twenty-one rows. Category and question columns are locked display data. All weights, score choices and applicability choices are required; even an excluded question must retain a valid score label because the workbook validates the complete score column first. The page refuses negative weights, unlisted choices, blank required cells and wrong grid shape. The workbook also requires at least one Applicable question and positive in-scope weight.
Errors and warnings
A rejected entry means no workbook assessment was made. Workbook NOT VALID identifies an unusable scoring denominator or malformed workbook entry. Workbook CHECK retains results but requires review of every exclusion or a below-Developing score. A connection or calculation-service failure is an availability issue, not a HIPAA conclusion.
References
The workbook derives its scoring rather than reproducing any table, chart, figure or control text from a regulation, standard or guidance document. The 21 questions are original to this workbook, and the weights, rating scale and band boundaries are choices made in it.
The following are the authoritative sources this tool sits beside and does not implement:
- U.S. Department of Health and Human Services. HIPAA Security Rule, 45 CFR Part 164 Subpart C. https://www.hhs.gov/hipaa/for-professionals/security/index.html
- HHS Office for Civil Rights and ONC. Security Risk Assessment Tool, the government's own risk-analysis instrument. https://www.healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-tool
- National Institute of Standards and Technology. Implementing the HIPAA Security Rule, SP 800-66. https://csrc.nist.gov/pubs/sp/800/66/r2/final
A risk analysis under the Security Rule is a specific documented obligation with its own requirements. If that is what you need, the HHS tool above is built for it and this page is not. Nothing here is legal advice, and no trademark or agency name appearing in this tool implies endorsement by its owner.
Additional source notes migrated from Methodology
The workbook uses the public safeguard-area structure only and reproduces no regulatory question set. Scope and interpretation should be checked against official HHS material, including the Security Rule summary, required versus addressable implementation specifications, and risk-analysis guidance.
Frequently asked questions
Does a good score here mean we are HIPAA compliant?
Is this the risk analysis the Security Rule requires?
Why does the tool warn me every time I exclude a question?
Why is the Administrative area weighted most heavily?
My score is below the Developing band and the status is flagging it. What should I do?
Can I change the weights and the bands?
Found a problem, or have an idea?
Tell us if a result looks wrong, a label is unclear, or something is missing. We read every message.
LogicCommons is in beta. If a result, label, or reference looks wrong, tell us here; we read every message.