Free HIPAA Security Scorecard
One HIPAA Audit Could Cost You Six Figures.
Those fines often trace back to gaps a practice couldn’t see on its own. This free Scorecard checks ten core Security Rule controls that line up with the issues OCR raises most for an independent practice.
In about three minutes you get a score out of 100, and a written review of your biggest gaps follows by email.
This is an educational self-assessment based only on your answers, not an audit or legal advice, and a high score doesn’t mean your practice is compliant.
We use your answers to prepare your review. The Scorecard asks only about your practice’s security setup, so there’s no need to enter patient names, records, or any other patient information.
Prefer not to use the form, or having trouble with it? Email hello@hipsana.com and we’ll send it another way.
What’s in the Scorecard
The 10 questions, and how they’re scored.
Each scoring question is a yes/no about how your practice handles patient data. Here are all ten, so nothing is a surprise.
Two controls carry the most weight in the score: signed vendor agreements and the risk analysis.
Score: 59/100 - some gaps to close.
Your biggest gap: no risk analysis in the last 12 months. A HIPAA Security Risk Analysis is among the failures OCR cites most often, and it is one of the first documents an investigator asks for. A current one maps where patient data lives and what could expose it. If you have never run one, that is the highest-value place to start.
Next: no two-factor login (2FA). A second sign-in step for email and your practice software is one of the fastest gaps to close, and it protects every account that touches patient data.
What is working: signed vendor agreements and a tested backup plan already put you ahead of many small practices.
This is a starting point for understanding your risk, not legal advice or a finding that you are or are not compliant.
A sample of the kind of written review a practice gets back after the Scorecard. This example is illustrative, not a real practice.