Protected Health Information Breach Risk Assessment Questionnaire Form
Complete this questionnaire to assess your organization's risk factors and preparedness for potential breaches involving protected health information. This form is for general risk evaluation only and does not collect any sensitive or confidential data.
Organization Name
*
Which of the following best describes your organization's current policies for handling protected health information?
*
Comprehensive written policies and procedures
Basic written guidelines
Informal or unwritten practices
No established policies
Other
How frequently does your organization provide training on breach prevention and response?
*
Annually
Every 2-3 years
Only during onboarding
No formal training provided
What methods does your organization use to detect unauthorized access or breaches?
*
Automated monitoring systems
Manual audits
Incident reporting by staff
No detection methods in place
Other
Does your organization have a documented incident response plan for breaches?
*
Yes, fully documented and tested
Yes, but not regularly tested
Plan is informal or incomplete
No incident response plan
Which physical safeguards are currently implemented to protect information?
*
Restricted access to facilities
Visitor sign-in procedures
Locked file storage
None of the above
Which technical safeguards are in place for digital information?
*
Data encryption
Multi-factor authentication
Regular software updates
Access controls
None of the above
Has your organization experienced any information breaches in the past 24 months?
*
Yes, more than once
Yes, once
No known breaches
Unsure
How often are access rights reviewed for staff and contractors?
*
Quarterly
Annually
Less than once a year
Never
Please describe any recent improvements or planned actions to reduce breach risk.
Contact Email (for follow-up on this assessment)
*
example@example.com
Submit Assessment
Should be Empty: