Twenty-one of the HIPAA Security Rule’s implementation specifications are “addressable”, and addressable does not mean optional. It means you implement it, implement something equivalent, or document why neither is reasonable for your organisation — and the missing documentation is the single most common finding in OCR enforcement.

This assessment covers the Security Rule at implementation-specification level, the Privacy Rule and the Breach Notification Rule, and records the addressable decisions as you go. It is free, it saves as you go, and you can stop and come back to it.

What is a HIPAA gap assessment?

A gap assessment compares what your organisation does today against 45 CFR Parts 160 and 164, and records the distance. It is not the same thing as the risk analysis required by § 164.308(a)(1)(ii)(A) — that one looks at threats and vulnerabilities to your ePHI — but the two feed each other, and you need both.

The usual surprise is scope. Organisations that think of themselves as vendors rather than health care providers are frequently business associates, and business associates and their subcontractors have been directly liable since 2013. The assessment opens by establishing which you are.

What this assessment covers

96 assessable items across the three rules.

DomainItemsWhat it asks about
Scope and applicability5Covered entity or business associate, hybrid designation, ePHI inventory, designated record sets, officials
Security Rule general rules3§ 164.306 — general standards, flexibility of approach, and the addressable decision log
Administrative safeguards23§ 164.308 — risk analysis and management, sanctions, activity review, workforce security, access management, training, incidents, contingency planning, evaluation, business associates
Physical safeguards10§ 164.310 — facility access, workstation use and security, device and media controls
Technical safeguards9§ 164.312 — access control, audit controls, integrity, authentication, transmission security
Organizational requirements8§ 164.314 and § 164.316 — business associate contracts, group health plans, policies and six-year documentation
Privacy Rule: uses and disclosures11Minimum necessary, authorizations, permitted disclosures, de-identification, limited data sets, verification
Privacy Rule: individual rights6Notice of privacy practices, restrictions, confidential communications, access, amendment, accounting
Privacy Rule: administrative requirements11§ 164.530 — privacy official, training, safeguards, complaints, sanctions, mitigation, documentation
Breach notification10The four-factor assessment, discovery, 60-day notification, content, media and Secretary notice, burden of proof

Required, addressable, and the decision you have to record

The Security Rule distinguishes required specifications from addressable ones, and this assessment labels every one. For an addressable specification you have three lawful options:

  • Implement it as written.
  • Implement an alternative measure that achieves the same purpose, and document why.
  • Document why neither is reasonable and appropriate for your size, complexity and risk — and then do nothing further.

All three are defensible. What is not defensible is the fourth option most organisations take by accident: doing nothing and writing nothing down. Encryption at rest is the clearest example — addressable, but it is also the safe harbour that keeps a lost laptop from becoming a reportable breach.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records an investigator could sample
Not applicableA justified exclusion, removed from the score

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every standard and specification with your status and notes, the score broken down by rule and safeguard, a prioritised gap list, and the Governance Docs documents that close each gap — PDF and working Excel.

How long does it take?

About 45 minutes. It is the longest of our assessments because the Security Rule is scored at specification level rather than standard level, which is the only way the addressable decisions get captured.

A note on the 2025 proposed Security Rule

In January 2025 HHS published a notice of proposed rulemaking that would overhaul the Security Rule — removing the addressable distinction, and mandating multi-factor authentication, encryption, asset inventories and network segmentation. It has not been finalised, and the Unified Agenda now targets 2027.

This assessment scores you against the rule as it stands, because that is what you are liable under today. Where a proposal is likely to matter — encryption, MFA — the guidance says so, so that the decisions you make now age well.

What to do with your score

Below 40% — start with the risk analysis and the ePHI inventory. Every other safeguard decision depends on knowing where the data is.

40–70% — usually a documentation gap rather than a control gap. The addressable decision log and the six-year retention obligation are the cheapest wins.

Above 70% — focus on evidence an investigator would sample: activity reviews actually performed, training records by name, leaver revocation timings, and the breach file for incidents you decided not to report.

Frequently asked questions

Is this assessment really free?

Yes. Every standard, your section breakdown and your overall score cost nothing. The $39 full report is optional.

Does it work for business associates?

Yes. The assessment establishes your status first, and the business associate and subcontractor obligations are scored alongside the covered entity ones.

Is this the risk analysis required by the Security Rule?

No. This measures your safeguards against the rule. The § 164.308(a)(1)(ii)(A) risk analysis assesses threats and vulnerabilities to your ePHI and is a separate, mandatory exercise — though your results here will tell you where to focus it.

Does it include the reproductive health privacy provisions?

No. That 2024 rule was vacated nationwide in 2025, so scoring against it would be misleading. It is deliberately excluded.

Is a high score the same as being HIPAA compliant?

No. There is no such thing as HIPAA certification, and no assessment substitutes for the required risk analysis. This tells you where your documented gaps are.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. Do not enter actual PHI — the notes fields are for describing controls, not patients. You can delete your answers at any time.