Twelve questions across administrative, technical, physical and contingency safeguards — the same ones an auditor opens with, and the same ones our guided self-audit is built around.
HIPAA's Security Rule organizes requirements into a handful of safeguard categories. None of this replaces a formal risk analysis, and answering "yes" to everything below isn't a certification — but if you can't say yes to most of it, that's exactly what an investigation finds first.
Policies, training and accountability — the paperwork an auditor asks for first.
Has a written security risk analysis been completed in the last 12 months?
Required under the Security Rule, and the most cited deficiency in audits.
Have you designated a Privacy and Security Official?
A named person accountable for policies and incident response.
Has every workforce member completed HIPAA training in the last 12 months?
Track this on your team dashboard.
Do you have signed Business Associate Agreements with every vendor handling PHI?
Billing services, cloud storage, IT support, transcription.
Is there a written breach response plan with notification deadlines?
Include the 60-day individual notification requirement.
Access controls, encryption and authentication on the systems that touch PHI.
Are all laptops, phones and tablets that touch patient data fully encrypted?
Full-disk encryption (FileVault, BitLocker, or mobile device encryption).
Does every staff member have unique login credentials?
No shared accounts, no generic 'frontdesk' logins.
Is multi-factor authentication enabled on systems holding patient data?
Email, EHR, cloud storage and remote access.
Do workstations lock automatically after a period of inactivity?
Recommended: 10 minutes or less in shared spaces.
Locks, storage and disposal for the devices and paper that hold PHI.
Are paper records and servers stored in locked, access-controlled areas?
Include visitor logs where applicable.
Is there a secure disposal process for paper and retired devices?
Shredding and certified media sanitisation.
What happens when something goes wrong — backups, restores, and recovery.
Are patient records backed up and has a restore been tested?
An untested backup is not a backup.
That's normal — most businesses have gaps. What matters is documenting how you're closing them.
Run this same checklist inside HIPAA TrustGuard and AI drafts the policy or procedure for every gap, from your actual answers.
Pass an independent AI validation pass and publish a trust badge clients can verify themselves at a public URL.
$499/year, unlimited staff — the guided self-audit, AI-drafted documentation, and a verifiable trust badge.