HIPAA Security Rule Assessment
Assess your organization's compliance with the HIPAA Security Rule safeguards protecting electronic Protected Health Information (ePHI).
Why This Matters
The Penalties Are Real — and Growing
HHS OCR enforces HIPAA with fines that reach into the millions. The question isn't whether you'll be audited — it's whether you'll be ready.
Maximum civil penalties per violation category per year reach into the millions under the tiered penalty structure. Willful neglect with no correction can hit the ceiling for each standard violated.
Source: 45 CFR § 160.404; HHS OCR
The most-cited HIPAA Security Rule violation in OCR enforcement actions is the failure to conduct an accurate and thorough risk analysis — a required administrative safeguard.
Source: HHS OCR Enforcement Highlights1
HHS OCR's HIPAA Audit Program reviews covered entities and business associates for compliance. Organizations without documented assessments face immediate findings of non-compliance.
Source: HHS OCR HIPAA Audit Program2
healthcare records have been exposed in breaches reported to HHS since 2009. Healthcare data breaches carry the highest average cost of any industry for 13 consecutive years.
Source: HHS Breach Portal; IBM Cost of a Data Breach 20233
Sources
- U.S. Department of Health & Human Services, Office for Civil Rights. HIPAA Enforcement Highlights. hhs.gov/hipaa
- HHS OCR HIPAA Audit Program. hhs.gov/hipaa/audit
- IBM Security. Cost of a Data Breach Report 2023. IBM Corporation.
What is the HIPAA Security Rule?
The HIPAA Security Rule (45 CFR Part 164) establishes national standards for protecting electronic Protected Health Information (ePHI). Any covered entity or business associate that creates, receives, maintains, or transmits ePHI must comply.
3 Safeguard Categories
Administrative, Physical, and Technical safeguards covering 18 standards and 36 implementation specifications.
Ongoing Compliance
HIPAA requires continuous risk analysis and management — not a one-time certification. Regular assessments document your ongoing compliance posture.
ePHI Protection
Designed to ensure confidentiality, integrity, and availability of all electronic Protected Health Information your organization handles.
3 Safeguard Categories
The HIPAA Security Rule organizes its requirements into three safeguard categories, each addressing a distinct dimension of ePHI protection.
Administrative Safeguards
Policies, procedures, and training governing how ePHI is managed. The largest category, covering risk analysis, workforce management, and contingency planning.
Physical Safeguards
Physical measures protecting electronic systems, buildings, and equipment from unauthorized access, tampering, and theft.
Technical Safeguards
Technology controls protecting ePHI and controlling access — including access controls, audit controls, integrity, and transmission security.
Key Standards Covered in the Assessment
Risk Analysis & Management
Identify and reduce risks to ePHI to a reasonable and appropriate level
Workforce Training & Management
Ensure all workforce members understand HIPAA policies and procedures
Contingency Planning
Data backup, disaster recovery, and emergency mode operation plans
Facility Access Controls
Limit physical access to systems storing ePHI to authorized personnel
Device & Media Controls
Govern receipt, removal, and disposal of hardware and electronic media
Access Controls
Unique user IDs, emergency access procedures, automatic logoff, and encryption
Audit Controls
Hardware and software activity that records access to ePHI
Transmission Security
Encryption and integrity controls protecting ePHI in transit
Who Needs HIPAA Compliance?
Healthcare Providers
Hospitals, clinics, physician practices, dentists, pharmacies, and any provider transmitting health information electronically.
Health Plans
Health insurance companies, HMOs, company health plans, Medicare and Medicaid programs.
Business Associates
IT vendors, billing companies, EHR providers, cloud storage services, and any third party handling ePHI on behalf of a covered entity.
Healthcare Clearinghouses
Organizations that process nonstandard health information into standard formats or vice versa.
Required vs. Addressable
HIPAA implementation specifications are classified as either Required or Addressable. Addressable doesn't mean optional — it means you must assess whether the specification is reasonable and appropriate for your organization, and document your decision.
Must be implemented exactly as stated. No flexibility.
Implement, implement an equivalent alternative, or document why it doesn't apply.
How the Assessment Works
Our assessment tool guides you through all Security Rule standards with clear explanations and helps you document your compliance decisions and evidence.
Select a Safeguard Category
Work through Administrative, Physical, and Technical safeguards at your own pace.
Evaluate Each Standard
For each standard and implementation specification, document your current compliance status: Met, Partially Met, or Not Met.
Document Evidence & Rationale
Add notes on how you implement each standard, including your rationale for addressable specifications.
Generate Reports
Download your compliance report to support internal review, audits, and breach response documentation.
Time Estimate
A complete HIPAA Security Rule assessment typically takes 2–4 hours for organizations with existing policies and documentation.
What to Have Ready
- Existing HIPAA policies and procedures
- Most recent risk analysis (if any)
- Workforce training records
- Business Associate Agreements list
Required Documentation
The Security Rule requires covered entities to retain documentation for at least 6 years from creation or last effective date. Our assessment generates the documentation you need to satisfy this requirement.
- Written risk analysis findings
- Risk management plan
- Addressable specification rationale
- Sanctions and incident policies
What You'll Receive
Generate comprehensive reports to document your HIPAA Security Rule compliance and support audits, breach investigations, and Business Associate due diligence.
Compliance Report
Complete assessment results showing compliance status for each standard and specification, organized by safeguard category with summary statistics.
- All 18 standards covered
- Category-by-category breakdown
- Your implementation notes
Gap Optimization & Remediation Plan
Identifies standards and specifications not yet fully implemented, with a prioritized plan for bringing your organization into compliance.
- Gaps by safeguard category
- Risk-prioritized action items
- Assessment date tracking
Encrypted Backup
A password-protected JSON file containing all your assessment data. Use it to restore your assessment or transfer between devices.
- AES-256 encryption
- Complete data export
- Easy restore process
Beyond Compliance
See Your Results Through an Attacker's Eyes
Completing your assessment unlocks FrameworkMapper's threat-informed views — the same control scores, re-read against real adversary behavior from MITRE ATT&CK® and curated threat intelligence.
Threat Lens & Adversary Likelihood
Advanced reports that map your control scores to attacker techniques and rank which adversaries are most likely to succeed against you.
Threat-Informed Executive Report
A board-ready PDF with your Attack Surface Coverage Score (ASCS) and kill-chain exposure, computed from your actual answers.
Incident Response Packet
Your assessment answers and evidence pre-fill a Responder Brief and evidence bundle, so responders can act on day one. Learn more
Included With Your Subscription
Runs on the FrameworkMapper Bundle
This assessment is part of the FrameworkMapper Bundle — one per-framework subscription that also includes Gap Optimization, the Threat-Gap Visualizer, the Incident Response Packet, and progress check-ins with phone photo evidence capture, across a 12-month term.
How Pricing WorksThe Full HIPAA Landscape
This assessment focuses on the Security Rule. Understanding where it fits within the broader HIPAA framework helps you achieve comprehensive compliance.
Electronic PHI (ePHI)
- 18 standards, 36 implementation specs
- Administrative, Physical & Technical safeguards
- Applies to covered entities and business associates
- 45 CFR Part 164 Subpart C
All Forms of PHI
- Governs use and disclosure of PHI
- Patient rights (access, amendment, accounting)
- Notice of Privacy Practices requirement
- 45 CFR Part 164 Subpart E
Breach Response
- 60-day notification window for affected individuals
- HHS notification required for all breaches
- Media notification for 500+ affected in one state
- 45 CFR Part 164 Subpart D
Ready to Assess Your HIPAA Security Rule Compliance?
Try our HIPAA Security Rule assessment tool with a free trial. Document your compliance posture across all three safeguard categories.
Contact sales at sales@frameworkmapper.com