4 questions
Administrative safeguards
Ownership, risk analysis, remediation, and workforce preparation.
HIPAA Security & Breach Readiness Self-Check
Answer 12 plain-language questions to identify readiness indicators across administrative, technical, physical, incident-response, business-associate, and continuity practices. No PHI or patient information is required.
Free 12-question self-check
Answer practical questions covering selected HIPAA Security and Breach Notification topics. You will see an immediate readiness band, then can unlock a category-by-category breakdown.
Usually takes 4–6 minutes. No patient information is needed.
What the self-check covers
Administrative safeguards carry the most questions in this version. Results are reported as self-assessment points—not a percentage of HIPAA compliance.
4 questions
Ownership, risk analysis, remediation, and workforce preparation.
3 questions
Identity, access, encryption, and activity visibility.
2 questions
Facilities, workstations, devices, and electronic media.
3 questions
Response procedures, business associates, backup, and recovery.
Important boundaries
This educational self-check is based solely on the answers provided and covers selected HIPAA Security and Breach Notification topics. It is not legal advice, an official HHS or OCR determination, a certification, an audit, or a complete HIPAA risk analysis.
The score does not establish HIPAA compliance or determine whether a reportable breach occurred. Obligations depend on the organization’s role, circumstances, risks, and documented implementation. Consult qualified legal or compliance professionals and perform an organization-wide risk analysis.
Related next steps
Explore technical safeguards, recovery readiness, and managed security support for healthcare organizations.
Learn moreKeep users, devices, networks, cloud platforms, and critical workflows protected and productive.
Learn moreBuild a broader technology foundation for security frameworks, client requirements, and risk management.
Learn moreFrequently asked questions
No. It is an educational self-check covering selected HIPAA Security and Breach Notification topics. It is not an official HHS or OCR determination, legal advice, an audit, certification, or complete organization-wide risk analysis.
No. The quiz asks only about organization-level safeguards. Do not enter patient names, records, diagnoses, identifiers, medical information, passwords, authentication codes, or other sensitive information.
After you request the detailed breakdown, Meta IT Pro receives your business contact information, overall result, category scores, and the titles of reported priority gaps. The lead notification does not include raw answer details or a free-text field.
The rubric is versioned against the regulatory basis date shown on this page. Proposed safeguards such as broader MFA requirements may be useful readiness indicators, but the quiz does not present a proposed rule as a current mandate.
The detailed category breakdown appears immediately in your browser. Meta IT Pro receives the request through its Microsoft 365 business mailbox and may contact you to discuss questions or technical next steps.
Free IT & cybersecurity assessment
Start with a no-obligation conversation about your IT, Microsoft 365, backups, and cybersecurity risks.