HIPAA Compliance Self-Assessment Checklist Form
Evaluate your organization's readiness across administrative, physical, and technical HIPAA safeguards. This form is for internal self-assessment purposes only and does not collect sensitive information.
Administrative Safeguards: Does your organization have documented HIPAA policies and procedures?
*
Yes, fully documented and regularly reviewed
Partially documented
Not documented
Administrative Safeguards: How confident are you in your HIPAA staff training program?
*
Not confident
1
2
3
4
Very confident
5
1 is Not confident, 5 is Very confident
Physical Safeguards: Are workstation and device security controls in place?
*
Workstations are physically secured
Mobile devices are managed and encrypted
Visitor access is controlled
Physical Safeguards: How would you rate your facility's access controls?
*
Weak
1
2
3
4
Strong
5
1 is Weak, 5 is Strong
Technical Safeguards: Which of the following security measures are implemented?
*
User access controls (unique IDs, role-based access)
Regular system activity audits/logs
Data encryption in transit and at rest
Technical Safeguards: Rate your confidence in your incident response procedures.
*
Not confident
1
2
3
4
Very confident
5
1 is Not confident, 5 is Very confident
Administrative Safeguards: How often are risk assessments conducted?
*
Annually or more frequently
Every 2-3 years
Rarely or never
Physical Safeguards: Are backup and disaster recovery plans in place and tested?
*
Yes, plans are documented and tested regularly
Plans exist but are not regularly tested
No formal plans in place
Technical Safeguards: How would you prioritize improvements to your security controls?
*
Immediate priority
High priority
Routine/ongoing
Overall: Please share any additional comments or areas of concern regarding your HIPAA safeguard readiness.
Submit Assessment
Should be Empty: