Starter
Free
Best for: getting started
- ✔️ Access to 50% of the full assessment
- ✔️ Guided HIPAA questions
- ✔️ Recommended next steps
Review key HIPAA requirements, identify potential privacy and security gaps, and get clear recommended actions with our private HIPAA compliance assessment tool — no email or login required.
Start free — no credit card, no email, no account.
Prefer a printable version? HIPAA Compliance Checklist PDF →
Not sure where your HIPAA compliance gaps are? Start with a quick assessment and identify areas that may need attention.
⚠️ Privacy Notice: Do not enter any real patient Protected Health Information (PHI).
Consider reviewing your HIPAA safeguards periodically and after major changes involving vendors, EHR systems, telehealth tools, devices, staff, or workflows.
A HIPAA risk assessment helps healthcare practices evaluate potential risks and vulnerabilities involving electronic protected health information and determine where safeguards may need attention.
GetHIPAAcheck helps solo providers, private practices, and small healthcare organizations review key HIPAA compliance areas, identify potential gaps, and document practical next steps.
GetHIPAAcheck is designed to help solo providers and small healthcare practices review key HIPAA requirements, document potential gaps, and organize practical next steps.
In simple terms: “Use the assessment to review key HIPAA requirements, identify areas that may need attention, and document your next steps.”
See how GetHIPAAcheck guides you through key HIPAA requirements, helps identify potential compliance gaps, and organizes your next steps.
Start free. Upgrade when you need the full assessment, PDF reports, history, or reminders.
Free
Best for: getting started
$18/month
Best for: full assessment + PDF report
$28/month
Best for: ongoing compliance tracking
Practical HIPAA guidance for therapists, telehealth providers, solo providers, and small healthcare practices.
What to prepare, document, and review before starting your assessment.
Examples of protected health information and common handling considerations.
Review common policies, records, and compliance documentation your practice may need.
HIPAA applies to covered entities and, in many situations, their business associates. Whether HIPAA applies to your practice depends on your role, activities, and how protected health information is handled.
HIPAA violations can lead to corrective action, investigations, and civil or criminal penalties depending on the circumstances.
GetHIPAAcheck guides you through key HIPAA requirements, helps you identify potential compliance gaps, and provides recommended next steps. Paid plans also include downloadable reports for your records.
No. GetHIPAAcheck is an educational and compliance-support tool. It does not provide legal advice or guarantee HIPAA compliance.
A HIPAA authorization may be required for certain uses or disclosures of protected health information that are not otherwise permitted by the HIPAA Privacy Rule. View the HIPAA authorization form resource .
GetHIPAAcheck uses a structured question-based approach to help healthcare providers review key HIPAA compliance areas. Assessment content references applicable provisions of the HIPAA Administrative Simplification Regulations, including relevant requirements within 45 CFR Parts 160 and 164.
Regulatory references can be reviewed through the Electronic Code of Federal Regulations (eCFR) .
GetHIPAAcheck is designed to support your compliance review process. It is not an official HHS or OCR product and does not replace legal or professional advice.
Start a guided HIPAA compliance assessment, identify potential gaps, and get practical recommended next steps.
Start Free HIPAA AssessmentHIPAA does not require one universal audit schedule. Reviews should be performed periodically and when changes may affect the privacy or security of protected health information.
| When to Review | What to Consider |
|---|---|
| 🗓️ Periodic Compliance Review | Reassess whether your current privacy and security safeguards remain appropriate for your practice. |
|
💻 New Technology or Vendor
EHR, telehealth, cloud, billing, IT |
Review how the change affects ePHI, access controls, vendor relationships, security risks, and documentation. |
| 👥 Staffing or Role Changes | Review workforce access, permissions, training, and whether access is still appropriate. |
| 📋 Policy or Workflow Changes | Confirm that policies, procedures, and safeguards still reflect how your practice actually operates. |
|
🚨 Security or Privacy Incident
Lost device, unauthorized access, ransomware, suspected breach |
Investigate the event, assess its impact, review affected safeguards, and document appropriate follow-up actions. |
| 🔄 Newly Identified Risk | Reassess relevant safeguards and determine whether additional corrective actions are appropriate. |
GetHIPAAcheck is a guided HIPAA compliance assessment designed for solo providers and small healthcare practices. Review key HIPAA Privacy and Security requirements, identify potential gaps, and organize practical next steps.
Start with the free assessment and upgrade when you need the full assessment, reports, history, or reminders.
⚖️ Legal & Compliance Disclaimer
GetHIPAAcheck is a privately developed compliance-support tool provided
for educational and informational purposes.
It does not provide legal advice and does not create an attorney-client
or other professional relationship.
GetHIPAAcheck is independent of and is not affiliated with, endorsed by,
or approved by the U.S. Department of Health and Human Services (HHS)
or the Office for Civil Rights (OCR).
Assessments, reports, checklists, recommendations, and templates are intended
to support internal compliance review and documentation. They do not constitute
HIPAA certification, legal certification, or government approval.
Users remain responsible for evaluating and meeting the HIPAA requirements
and other laws applicable to their organizations.