Skip to main content
FrameworkMapper
Healthcare Compliance Assessment

HIPAA Security Rule Assessment

Assess your organization's compliance with the HIPAA Security Rule safeguards protecting electronic Protected Health Information (ePHI).

HIPAA

Why This Matters

The Penalties Are Real — and Growing

HHS OCR enforces HIPAA with fines that reach into the millions. The question isn't whether you'll be audited — it's whether you'll be ready.

💊
Multi-Million

Maximum civil penalties per violation category per year reach into the millions under the tiered penalty structure. Willful neglect with no correction can hit the ceiling for each standard violated.

Source: 45 CFR § 160.404; HHS OCR

📋
Risk Analysis

The most-cited HIPAA Security Rule violation in OCR enforcement actions is the failure to conduct an accurate and thorough risk analysis — a required administrative safeguard.

Source: HHS OCR Enforcement Highlights1

🔍
Audit Program

HHS OCR's HIPAA Audit Program reviews covered entities and business associates for compliance. Organizations without documented assessments face immediate findings of non-compliance.

Source: HHS OCR HIPAA Audit Program2

🏥
725M+

healthcare records have been exposed in breaches reported to HHS since 2009. Healthcare data breaches carry the highest average cost of any industry for 13 consecutive years.

Source: HHS Breach Portal; IBM Cost of a Data Breach 20233

Sources

  1. U.S. Department of Health & Human Services, Office for Civil Rights. HIPAA Enforcement Highlights. hhs.gov/hipaa
  2. HHS OCR HIPAA Audit Program. hhs.gov/hipaa/audit
  3. IBM Security. Cost of a Data Breach Report 2023. IBM Corporation.

What is the HIPAA Security Rule?

The HIPAA Security Rule (45 CFR Part 164) establishes national standards for protecting electronic Protected Health Information (ePHI). Any covered entity or business associate that creates, receives, maintains, or transmits ePHI must comply.

3 Safeguard Categories

Administrative, Physical, and Technical safeguards covering 18 standards and 36 implementation specifications.

Ongoing Compliance

HIPAA requires continuous risk analysis and management — not a one-time certification. Regular assessments document your ongoing compliance posture.

ePHI Protection

Designed to ensure confidentiality, integrity, and availability of all electronic Protected Health Information your organization handles.

3 Safeguard Categories

The HIPAA Security Rule organizes its requirements into three safeguard categories, each addressing a distinct dimension of ePHI protection.

Admin

Administrative Safeguards

Policies, procedures, and training governing how ePHI is managed. The largest category, covering risk analysis, workforce management, and contingency planning.

9 Standards • 22 Specs
Physical

Physical Safeguards

Physical measures protecting electronic systems, buildings, and equipment from unauthorized access, tampering, and theft.

4 Standards • 9 Specs
Technical

Technical Safeguards

Technology controls protecting ePHI and controlling access — including access controls, audit controls, integrity, and transmission security.

5 Standards • 9 Specs

Key Standards Covered in the Assessment

§164.308

Risk Analysis & Management

Identify and reduce risks to ePHI to a reasonable and appropriate level

§164.308

Workforce Training & Management

Ensure all workforce members understand HIPAA policies and procedures

§164.308

Contingency Planning

Data backup, disaster recovery, and emergency mode operation plans

§164.310

Facility Access Controls

Limit physical access to systems storing ePHI to authorized personnel

§164.310

Device & Media Controls

Govern receipt, removal, and disposal of hardware and electronic media

§164.312

Access Controls

Unique user IDs, emergency access procedures, automatic logoff, and encryption

§164.312

Audit Controls

Hardware and software activity that records access to ePHI

§164.312

Transmission Security

Encryption and integrity controls protecting ePHI in transit

Who Needs HIPAA Compliance?

Healthcare Providers

Hospitals, clinics, physician practices, dentists, pharmacies, and any provider transmitting health information electronically.

Health Plans

Health insurance companies, HMOs, company health plans, Medicare and Medicaid programs.

Business Associates

IT vendors, billing companies, EHR providers, cloud storage services, and any third party handling ePHI on behalf of a covered entity.

Healthcare Clearinghouses

Organizations that process nonstandard health information into standard formats or vice versa.

Required vs. Addressable

HIPAA implementation specifications are classified as either Required or Addressable. Addressable doesn't mean optional — it means you must assess whether the specification is reasonable and appropriate for your organization, and document your decision.

REQ

Must be implemented exactly as stated. No flexibility.

ADDR

Implement, implement an equivalent alternative, or document why it doesn't apply.

How the Assessment Works

Our assessment tool guides you through all Security Rule standards with clear explanations and helps you document your compliance decisions and evidence.

1

Select a Safeguard Category

Work through Administrative, Physical, and Technical safeguards at your own pace.

2

Evaluate Each Standard

For each standard and implementation specification, document your current compliance status: Met, Partially Met, or Not Met.

3

Document Evidence & Rationale

Add notes on how you implement each standard, including your rationale for addressable specifications.

4

Generate Reports

Download your compliance report to support internal review, audits, and breach response documentation.

Time Estimate

A complete HIPAA Security Rule assessment typically takes 2–4 hours for organizations with existing policies and documentation.

What to Have Ready

  • Existing HIPAA policies and procedures
  • Most recent risk analysis (if any)
  • Workforce training records
  • Business Associate Agreements list

Required Documentation

The Security Rule requires covered entities to retain documentation for at least 6 years from creation or last effective date. Our assessment generates the documentation you need to satisfy this requirement.

  • Written risk analysis findings
  • Risk management plan
  • Addressable specification rationale
  • Sanctions and incident policies

What You'll Receive

Generate comprehensive reports to document your HIPAA Security Rule compliance and support audits, breach investigations, and Business Associate due diligence.

Compliance Report

Complete assessment results showing compliance status for each standard and specification, organized by safeguard category with summary statistics.

  • All 18 standards covered
  • Category-by-category breakdown
  • Your implementation notes
Sample PDF Coming Soon

Gap Optimization & Remediation Plan

Identifies standards and specifications not yet fully implemented, with a prioritized plan for bringing your organization into compliance.

  • Gaps by safeguard category
  • Risk-prioritized action items
  • Assessment date tracking
Sample PDF Coming Soon

Encrypted Backup

A password-protected JSON file containing all your assessment data. Use it to restore your assessment or transfer between devices.

  • AES-256 encryption
  • Complete data export
  • Easy restore process
Generated from your data

Beyond Compliance

See Your Results Through an Attacker's Eyes

Completing your assessment unlocks FrameworkMapper's threat-informed views — the same control scores, re-read against real adversary behavior from MITRE ATT&CK® and curated threat intelligence.

🎯

Threat Lens & Adversary Likelihood

Advanced reports that map your control scores to attacker techniques and rank which adversaries are most likely to succeed against you.

📄

Threat-Informed Executive Report

A board-ready PDF with your Attack Surface Coverage Score (ASCS) and kill-chain exposure, computed from your actual answers.

🚨

Incident Response Packet

Your assessment answers and evidence pre-fill a Responder Brief and evidence bundle, so responders can act on day one. Learn more

Included With Your Subscription

Runs on the FrameworkMapper Bundle

This assessment is part of the FrameworkMapper Bundle — one per-framework subscription that also includes Gap Optimization, the Threat-Gap Visualizer, the Incident Response Packet, and progress check-ins with phone photo evidence capture, across a 12-month term.

How Pricing Works

The Full HIPAA Landscape

This assessment focuses on the Security Rule. Understanding where it fits within the broader HIPAA framework helps you achieve comprehensive compliance.

Security Rule This Assessment

Electronic PHI (ePHI)

  • 18 standards, 36 implementation specs
  • Administrative, Physical & Technical safeguards
  • Applies to covered entities and business associates
  • 45 CFR Part 164 Subpart C
Privacy Rule

All Forms of PHI

  • Governs use and disclosure of PHI
  • Patient rights (access, amendment, accounting)
  • Notice of Privacy Practices requirement
  • 45 CFR Part 164 Subpart E
Breach Notification

Breach Response

  • 60-day notification window for affected individuals
  • HHS notification required for all breaches
  • Media notification for 500+ affected in one state
  • 45 CFR Part 164 Subpart D

Ready to Assess Your HIPAA Security Rule Compliance?

Try our HIPAA Security Rule assessment tool with a free trial. Document your compliance posture across all three safeguard categories.

Contact sales at sales@frameworkmapper.com