risk-compliance · assessments · privacy-healthcare

HIPAA Security Self Assessment

Scores readiness against the HIPAA Security Rule safeguard areas from a weighted questionnaire. Use it for a self-assessment of security controls; the questions are original and a score is not evidence of compliance.

Last updated
Assessment Journey

Calculator overview

Inputs and outputs

This summary comes from the calculator's published input and output contract.

Inputs

Assessment Questions
About this input

One row per self-assessment question grouped under the administrative, physical and technical safeguard areas: enter a score for how far the safeguard is in place and a scope flag, and edit the weight if needed. The questions are written for this tool and are not the text of the HIPAA Security Rule, so a score is not evidence of compliance. A question marked not applicable is removed from both the numerator and the denominator, so it does not penalise the score. Every question needs a score and an applicability flag from the dropdowns; an entry that is blank or not on the list makes the tool refuse to score rather than guess.

Default 21 rows
ColumnRange or allowed values
Category Not declared
Question Not declared
Weight At least 0
Score 0 - Not in place, 1 - Ad hoc, 2 - Partially in place, 3 - Largely in place, 4 - Fully in place, 5 - Fully in place and verified
Applicability Applicable, Not applicable

Outputs

Share Not Applicable
About this output

The questions marked not applicable as a percent of all questions, a check on how much of the set was excluded.

Unit %
Second Priority
About this output

The in-scope question with the second largest weighted gap to a full score.

Unit question
Questions Not Applicable
About this output

The number of questions marked not applicable. These are removed from both the numerator and the denominator, so they neither help nor penalise the score.

Unit count
Share Of The Total Gap In The Top Three
About this output

The combined weighted gap of the top three priorities as a percent of the whole gap to a full score, showing how concentrated the improvement is.

Unit %
Total Weight In Scope
About this output

The sum of the weights of the questions in scope, as a weight total. It is the denominator the readiness score is measured against.

Unit weight
Top Priority
About this output

The in-scope question contributing the largest weighted gap to a full score, the single item worth the most improvement.

Unit question
Third Priority
About this output

The in-scope question with the third largest weighted gap to a full score.

Unit question
Questions In Scope
About this output

The number of questions marked applicable and therefore included in the readiness score.

Unit count
Lowest Scoring Category
About this output

The safeguard area with the weakest weighted score, the natural place to focus first.

Unit category
Highest Scoring Category
About this output

The safeguard area, administrative, physical or technical, with the strongest weighted score.

Unit category
Category Scores
About this output

One row per safeguard area: its weighted score in percent and its share of the total weight, so you can see where the overall figure comes from.

No unit declared
Model Status
About this output

The overall check on your entries, shown above the results. It reads OK when the inputs are usable, NOT VALID with a reason when an entry makes the model meaningless, or CHECK with a reason when a result is valid but worth a second look. Read it before you trust the numbers below.

No unit declared
Points Available To Gain
About this output

The total weighted gap to a full score: the sum over the questions in scope of weight times score shortfall. It is measured in raw weight-times-score points on your own weight scale, not in percentage points, so re-weighting changes it even when the answers do not.

Unit points
Overall Score
About this output

The weighted readiness score across the questions in scope, in percent, combining each answer with its weight. It reflects self-reported readiness, not an audit or a compliance determination.

Unit %
Overall Band
About this output

The maturity band, from Not established to Optimised, read from the overall score. The band is a summary of your answers, not a certification.

Unit band

What it is

This is a HIPAA Security Rule readiness self-assessment. You score 21 questions about your organisation's security safeguards, each on a scale from zero to five, and it returns a weighted readiness score as a percentage, a band, a score for each of four safeguard areas, and a ranked list of the gaps worth closing first.

What it is not, and this matters more here than on most pages. The 21 questions were written for this workbook. They are not the Security Rule's own text, they do not cover its implementation specifications exhaustively, and completing this assessment is not evidence of compliance with anything. It is not a risk analysis under the Security Rule; that is a specific, documented obligation with its own requirements, and a questionnaire is not it. It is not an audit, not a certification, and would not satisfy a regulator, an enforcement inquiry, or a customer's due diligence. The four areas are named after the Security Rule's own safeguard groupings because that grouping is publicly documented and widely understood; the names are referenced as a factual matter only. The weights, scale and band boundaries are editable and carry no official standing.

What it is good for is an internal first picture of where you stand and a defensible order of work.

Methodology

Purpose and model boundary

This model scores self-reported security-control maturity across twenty-one original questions grouped under administrative, physical, technical, and organisational/documentation safeguard headings. It produces category scores, an overall maturity score and band, and a weighted improvement-priority list.

It is a readiness aid only. It does not determine whether HIPAA applies, identify protected health information, distinguish every required and addressable implementation specification, perform a risk analysis, test evidence, provide legal advice, or establish compliance with the HIPAA Security Rule.

Inputs and units

Each fixed question row contains:

Field Meaning and restriction
Category and question Locked workbook text. The questions are original and do not reproduce regulatory wording.
Weight, w_i Nonnegative integer expressing the question's importance within its safeguard category.
Score, s_i Required choice mapped to 0 through 5, from Not in place through Fully in place and verified.
Applicability, a_i Required choice mapped to 1 for Applicable or 0 for Not applicable.

The page uses fixed category weights: Administrative safeguards 40, Physical safeguards 20, Technical safeguards 30, and Organisational and documentation 10. Maturity bands begin at 0% Not established, 25% Initial, 45% Developing, 65% Managed, and 85% Optimised. These are workbook-authored scoring choices, not regulatory thresholds.

Governing relationships

For category c, maximum score s_max = 5, and applicable flag a_i:

CategoryScore_c = sum over i in c (w_i × s_i × a_i) / (s_max × sum over i in c (w_i × a_i))

Not-applicable questions are removed from numerator and denominator. A category with no applicable question is labelled not assessed and excluded from the overall category-weight denominator.

With fixed category weight W_c:

OverallScore = sum over assessed c (W_c × CategoryScore_c) / sum over assessed c W_c

The band is the highest threshold reached by 100 × OverallScore.

Question gaps and priorities use:

Gap_i = w_i × (s_max - s_i) × a_i

Points_Available_To_Gain = sum(Gap_i)

Positive gaps are ranked descending with a small row-index tiebreaker. Top_Priority, Second_Priority, and Third_Priority are the first three ranked questions. Their share is the sum of those three gaps divided by total gap, with zero returned when no gap exists.

Calculation sequence

  1. Confirm all score, applicability and weight cells are valid.
  2. Map score labels to 0 through 5 and applicability labels to 1 or 0.
  3. Calculate applicable weighted scores and weighted shortfalls by question.
  4. Calculate each assessed safeguard-category score and maturity band.
  5. Combine assessed categories using the fixed category weights.
  6. Rank positive gaps and return the top three question priorities.
  7. Calculate scope counts, assessed-category extrema, total gap and top-three share.
  8. Evaluate Model_Status using the ordered rules below.

Outputs and interpretation

Overall_Score and Overall_Band summarize the answers under this workbook's weights. They are not a regulatory score or compliance opinion. The category grid and chart show within-category scores; they do not show regulatory severity or the evidence quality behind an answer.

Points_Available_To_Gain is the raw sum of weight × score shortfall, not a percentage-point deficit. Priorities rank weighted shortfalls, so a higher-weight partial control can rank ahead of a lower-weight missing control. Highest and lowest category outputs ignore categories with no applicable questions.

Validation and status logic

The workbook evaluates status in this order:

Condition Returned status
Fewer than all 21 score entries match the six-item score list NOT VALID: a score entry is blank or not one of the listed options
Fewer than all 21 applicability entries match the scope list NOT VALID: an applicability entry is blank or not one of the listed options
Any weight is not numeric NOT VALID: a weight is not a number
Any weight is blank NOT VALID: a weight is blank
Any weight is negative NOT VALID: a weight is negative
No question is Applicable NOT VALID: every question is marked not applicable, so there is nothing to score
Total weight across Applicable questions is zero NOT VALID: the total weight in scope is zero, so there is nothing to score
At least one question is Not applicable CHECK: a question is excluded as not applicable; the Security Rule's required implementation specifications cannot be waived, so confirm each exclusion is genuinely outside this organisation's scope
Overall score is below 45% CHECK: the overall score is below the Developing band; treat the priority list as a work plan
None of the preceding conditions applies OK

The exclusion warning is deliberately stricter than the other assessment models and takes precedence over the low-score warning. It does not decide that an exclusion is lawful; it tells the reader to confirm scope outside the model.

Assumptions and limitations

  • Answers are self-reported and are not supported by evidence testing, interviews, sampling, technical validation or an independent audit.
  • The model does not decide whether an organisation is a covered entity or business associate, what information is in scope, or which implementation specifications are required or addressable in a particular case.
  • The twenty-one custom questions are not regulatory text and are not exhaustive. A high score can coexist with a material legal or security deficiency.
  • Weights, the 0-to-5 scale and maturity bands are illustrative and have no official HIPAA standing.
  • Marking a question Not applicable excludes it mathematically, but the model cannot determine whether that exclusion is legally or operationally supportable.
  • The calculator does not perform the accurate-and-thorough risk analysis required for a real security program, estimate likelihood or impact, or create a remediation plan.
  • Category averages can hide a critical individual weakness. Review question-level answers, evidence and risk context rather than relying on the headline score.

Restrictions and non-computing states

The grid has exactly twenty-one rows. Category and question columns are locked display data. All weights, score choices and applicability choices are required; even an excluded question must retain a valid score label because the workbook validates the complete score column first. The page refuses negative weights, unlisted choices, blank required cells and wrong grid shape. The workbook also requires at least one Applicable question and positive in-scope weight.

Errors and warnings

A rejected entry means no workbook assessment was made. Workbook NOT VALID identifies an unusable scoring denominator or malformed workbook entry. Workbook CHECK retains results but requires review of every exclusion or a below-Developing score. A connection or calculation-service failure is an availability issue, not a HIPAA conclusion.

References

The workbook derives its scoring rather than reproducing any table, chart, figure or control text from a regulation, standard or guidance document. The 21 questions are original to this workbook, and the weights, rating scale and band boundaries are choices made in it.

The following are the authoritative sources this tool sits beside and does not implement:

A risk analysis under the Security Rule is a specific documented obligation with its own requirements. If that is what you need, the HHS tool above is built for it and this page is not. Nothing here is legal advice, and no trademark or agency name appearing in this tool implies endorsement by its owner.

Additional source notes migrated from Methodology

The workbook uses the public safeguard-area structure only and reproduces no regulatory question set. Scope and interpretation should be checked against official HHS material, including the Security Rule summary, required versus addressable implementation specifications, and risk-analysis guidance.

Frequently asked questions

Does a good score here mean we are HIPAA compliant?
No. This is a self-assessment against 21 questions written for this workbook, not against the Security Rule's text, and it covers neither its implementation specifications exhaustively nor the Privacy and Breach Notification Rules at all. A score is not evidence of compliance and would not satisfy a regulator, an enforcement inquiry or a customer's due diligence. It tells you where to look, not where you stand legally.
Is this the risk analysis the Security Rule requires?
No, and the distinction is important. The required risk analysis is a specific documented obligation: identify where protected health information lives, assess threats and vulnerabilities to it, evaluate likelihood and impact, and record the whole thing. A weighted questionnaire is not that, however carefully it is answered. HHS and ONC publish a Security Risk Assessment Tool built for the purpose, linked in the references.
Why does the tool warn me every time I exclude a question?
Because the Security Rule separates required implementation specifications from addressable ones, and required specifications cannot be waived. Addressable ones can be met by an equivalent measure or documented as not reasonable and appropriate. But that is a recorded decision, not a removal. The check asks you to confirm the exclusion is genuinely outside your scope, because exclusions move the score substantially: dropping one safeguard area from the shipped example lifts it a whole band.
Why is the Administrative area weighted most heavily?
Because most of what the Security Rule asks for is administrative rather than technical: risk analysis, workforce training, sanction policies, incident response procedures, contingency planning, business associate agreements. Organisations often invest in technical controls first because they are purchasable, then score poorly here, which is exactly the pattern the shipped example shows: physical and technical safeguards around 50 percent while administrative sits at 37.
My score is below the Developing band and the status is flagging it. What should I do?
Read the priority list as a work plan, which is what the status suggests. The list ranks by weight times shortfall, so the items at the top are the ones where effort recovers the most. In the shipped example that is contingency planning, business associate agreements and an encryption decision. The top three together are only about a fifth of the total gap, which means the work is broad rather than concentrated.
Can I change the weights and the bands?
Yes, they are editable, and that is deliberate: the weighting reflects a judgement about what matters most for your organisation. Be aware that doing so makes your score incomparable with anyone else's, and that neither the defaults nor your version has any official standing. Nothing about the scale, weights or bands comes from the Security Rule.
This page is provided by LogicCommons for informational purposes only. Results are analysis outputs computed from the inputs you supply and are not engineering advice, a design, or a substitute for review by a licensed professional under the codes adopted where the work is built. Verify all inputs and results independently.

LogicCommons is in beta. If a result, label, or reference looks wrong, tell us here; we read every message.