Sunlit Florida waterfront workspace overlooking the bay

Free Tool · Medical & Dental Practices

HIPAA Risk Assessment.
Check your security
in about 5 minutes.

A free HIPAA risk assessment self-check for medical, dental and therapy practices in Naples, Fort Myers and Miami. 23 plain-language questions on the HIPAA Security Rule and everyday cybersecurity, with a score and your top 3 fixes.

HIPAA Self-Check

Check your HIPAA security.
Start with the biggest gaps.

Answer Yes, Partly, No or Not sure. “Not sure” counts as a gap, because in an audit or a breach an unknown is a risk. This is a quick self-check, not a HIPAA compliance determination or legal advice. Please don’t enter any patient information.

Free HIPAA self-check · about 5 minutes

How ready is your practice’s security?

23 quick questions: the HIPAA Security Rule basics plus the everyday protections that stop phishing and ransomware. Answer Yes, Partly, No or Not sure, and get a score and your top 3 fixes.

  • HIPAA safeguards
  • Identity & access
  • Devices
  • Data & backups
  • Email & people
  • Network & response

This is a quick self-check, not a HIPAA compliance determination or legal advice. Runs entirely in your browser. FLTECHS doesn’t see or store your answers unless you choose to send them.

What the HIPAA Security Rule requires

The HIPAA Security Rule requires covered entities and their business associates to protect electronic protected health information (ePHI) with administrative, physical and technical safeguards. The starting point is a risk analysis: an “accurate and thorough assessment” of the risks to the confidentiality, integrity and availability of ePHI (45 CFR 164.308(a)(1)(ii)(A)). HHS describes risk analysis as an ongoing process. The rule doesn’t set a fixed schedule, but reviewing it at least once a year and after major changes is common practice.

The rule also calls for unique user IDs, audit controls, a security awareness and training program, a contingency plan with data backup and disaster recovery, and written policies kept for six years. Encryption is currently an “addressable” safeguard: you implement it where it is reasonable and appropriate, or document why not and what you do instead. For laptops and email, encryption is usually the practical answer. HHS proposed updates to the Security Rule in January 2025 that would make more of these safeguards explicit; they are not final as of this writing.

Business Associate Agreements (BAAs)

Any vendor that creates, receives, maintains or transmits ePHI for your practice is a business associate, and HIPAA requires a signed Business Associate Agreement before it handles that data. HHS guidance names IT contractors and managed service providers, EHR vendors and cloud services as examples. Don’t forget your phones: voicemails, call recordings and texts often contain PHI. FlowPBX, our cloud phone system, is a HIPAA-ready phone system with a signed BAA for medical and dental clients.

What attackers do to medical and dental offices

Practices are attacked the same way as other small businesses: phishing emails that steal Microsoft 365 passwords, shared or weak logins on the EHR, unpatched computers and remote access left open to the internet. Ransomware hits healthcare especially hard because it can stop scheduling, charting and billing at once, and a breach of unsecured PHI can trigger notification duties under the HIPAA Breach Notification Rule. HHS lists breaches affecting 500 or more people on its public breach portal.

What a professional assessment from FLTECHS adds

A self-check tells you where to look. Our team helps you document a Security Risk Analysis, inventories the systems that hold ePHI, checks MFA, encryption, backups and audit logging, and gives you a prioritized plan to close the gaps. We handle the IT safeguards and help with the documentation; we don’t claim to make you “HIPAA certified”. The first consult is free: on-site in Naples, remote first for Fort Myers and Miami-Dade, with on-site visits when needed. Learn more about our healthcare and dental IT services.

Is this a HIPAA compliance certification?

No. HHS does not certify HIPAA compliance, and this self-check is not a compliance determination or legal advice. It is a quick way to spot likely gaps before a full Security Risk Analysis. Your compliance officer or attorney makes the final compliance decisions; we provide the IT safeguards and the documentation support.

How often should we update our Security Risk Analysis?

HHS calls risk analysis an ongoing process, and the Security Rule expects you to review and update your security measures as needed. Many practices review it every year and whenever something big changes: a new EHR, a new office, a move to the cloud or a security incident.

Do we need a BAA with our IT provider and phone company?

If they create, receive, maintain or transmit ePHI for you, yes. That usually includes your managed IT provider, cloud backup, email and a hosted phone system that stores voicemail, call recordings or texts. FlowPBX, our cloud phone system, comes with a signed BAA for medical and dental clients; ask us about the rest of your vendors.

Is this self-check private?

Yes. It runs in your browser and nothing is stored, and it never asks for patient information. If you press “Send my results to FLTECHS”, only your score and gap list are placed in our contact form, and you review the message before sending it.

Protect your patients and your practice

Get a Free HIPAA Security Consult.

Send us your results or call 239-986-8647. We’ll review your gaps with you and help you plan your Security Risk Analysis. On-site in Naples, remote for Fort Myers and Miami-Dade.