1/9 Does your practice have a documented HIPAA Policies and Procedures manual that is current and accessible to all staff?
*
No — we do not have a formal HIPAA policies and procedures manual
We have something in place but it has not been reviewed or updated recently
Yes — we have a current manual customised to how we operate and all staff can access it
We have generic or basic documentation but it is not customised to our practice
2/9 Does your practice provide regular HIPAA training to all staff, and do you keep documented training logs?
*
Yes — all staff are trained regularly and we maintain training logs with dates and subject matter
No — we have not done formal HIPAA training for our team
Training only happens when a new person joins, not on an ongoing basis
We do some training but do not formally document it
3/9 Has your practice completed a formal Security Risk Assessment within the last 12 months?
No — we have never completed a formal Security Risk Assessment
We completed one but it was more than a year ago
We completed one more than 2 years ago or after a major change in our practice
Yes — completed within the last 12 months and properly documented
4/9 Does your practice have a written Remediation Plan based on your last risk assessment, and is it reviewed annually?
*
We have an old remediation plan that has not been updated
We identified gaps in our last assessment but never formally documented a fix plan
Yes — we have a documented remediation plan that is reviewed and updated annually
No — we do not have a remediation plan and have not done a risk assessment
5/9 Does your practice have signed and current Business Associate Agreements (BAAs) with all vendors who handle patient data, and have you validated their HIPAA compliance?
*
Yes — all vendors have current signed BAAs and we have verified their compliance
No — we do not have Business Associate Agreements in place
We have BAAs with some vendors but not all, and have not validated their compliance
We have old agreements that have not been updated since 2013 or recently
6/9 Has your practice conducted a formal HIPAA compliance program audit within the last year?
*
We did an audit more than two years ago but not since then
Yes — we conduct annual compliance audits and have a signed audit report on file
We have done some internal review but not a formal documented audit
No — we have never conducted a formal HIPAA compliance program audit
7/9 If your practice accepts government reimbursements (Medicare or Medicaid), do you conduct OIG Exclusion Screening for your workforce?
*
Yes — we run OIG screening regularly and keep screening reports on file
We accept government reimbursements but have not done OIG screening
We are not sure what OIG Exclusion Screening is
We do not accept government reimbursements so this does not apply to us
8/9 Does your practice have cybersecurity safeguards in place — such as network vulnerability scans, software patch logs, and system authentication monitoring?
*
No — we do not have formal cybersecurity safeguards or documentation in place
We rely on our IT vendor but have never verified what they actually cover
We have some basic measures but they are not formally documented
Yes — we have all of these in place and documented
9/9 Has your practice ever scanned your website for tracking pixels that may be sharing patient data with third parties like Google or Meta?
*
We have not scanned our website but we do use tools like Google Analytics
Yes — we have scanned our website and confirmed no unauthorised tracking pixels are present
No — we have never heard of tracking pixel compliance issues
We are aware of this issue and are in the process of addressing it
Your Free HIPAA Compliance Report is Ready
Please complete this short form to customize your report
Name:
*
Email
*