Tools

HIPAA Readiness Scorecard

The HIPAA readiness scorecard is a 12-question self-assessment that rates how prepared a healthcare organization or business associate is for a HIPAA audit, investigation...

Arinder Singh SuriArinder Singh Suri|September 30, 2026·17 min read

The HIPAA readiness scorecard is a 12-question self-assessment that rates how prepared a healthcare organization or business associate is for a HIPAA audit, investigation or customer security review. Each question scores zero, one or two points, producing a total out of 24 that places you in a readiness band with clear next steps.

Most organizations think they are more HIPAA-ready than they are, until an investigator or hospital customer asks for evidence. This scorecard gives you an honest answer in about ten minutes, using the same questions our consultants ask first. Taction Software has built HIPAA-compliant healthcare software and compliance programs since 2013 across 200+ healthcare projects, and this scorecard complements our free HIPAA compliance checklist with a scored view of where you stand.

How the Scorecard Works

The scorecard focuses on evidence, not intentions. For each of the 12 questions, give yourself two points if the control exists, works in practice and is documented, one point if it exists but is incomplete, outdated or undocumented, and zero points if it does not exist. Be honest, because the value comes from finding gaps before anyone else does. Add your points for a total out of 24, then check your readiness band. The six principles below explain how to score accurately, and what the scorecard can and cannot tell you about your compliance position.

Two Points: Working and Documented

Award two points only when the control exists, operates as described and you can produce evidence within a day, such as a dated report, signed agreement or completed review record. If you would need to search for evidence or recreate it, score one point instead.

One Point: Partial or Outdated

Award one point when the control exists but is incomplete, inconsistent or outdated, such as a risk analysis from several years ago or training records missing for some staff. Partial controls still create findings, but they are usually faster and cheaper to fix.

Zero Points: Missing

Award zero points when the control does not exist or nobody can confirm it does. Zero scores are not failures, they are priorities. Identifying them now gives you time to fix them before an auditor, investigator or major customer discovers them first.

Score With Evidence in Hand

Answer each question while looking at the actual evidence, not from memory. Teams scoring from memory consistently overrate themselves. If evidence is held by another department or vendor, ask for it, because auditors will ask the same question and expect the same answer.

Include Every Location and System

Score for the whole organization, including every clinic, cloud service, remote worker and vendor that handles PHI. Controls that exist at headquarters but not at smaller sites still count as partial, because investigators look at the organization as a whole.

It Is Not a Legal Opinion

The scorecard is a practical readiness tool, not a legal determination of compliance. It highlights where you are likely exposed. For formal assessment, our HIPAA risk assessment services provide a documented analysis that satisfies Security Rule requirements. Counsel handles legal questions.

Questions 1 to 6: Program and Administrative Safeguards

The first six questions cover the foundations of a HIPAA program: risk analysis, risk management, policies, training, vendor agreements and leadership accountability. These administrative safeguards are where investigators usually begin, and gaps here are among the most frequently cited problems in federal enforcement actions. Strong scores in this section suggest a program that exists beyond paperwork. Weak scores usually mean the organization would struggle to demonstrate compliance quickly. Score each question from zero to two using the evidence standard above, and note any question where you scored less than two for follow-up.

Question 1: Is Your Risk Analysis Current?

Score two if you have a documented risk analysis updated within the last year that covers every system, location and vendor handling electronic PHI. Score one if it exists but is older or incomplete. Our free HIPAA risk assessment template helps you start.

Question 2: Do You Act on Identified Risks?

Score two if every significant risk in your analysis has an owner, a remediation plan and documented progress. Score one if some risks are tracked but many sit unaddressed. Identifying risks without acting on them is itself a common finding in investigations.

Question 3: Do Policies Match Actual Practice?

Score two if your privacy and security policies are current, approved and reflect how staff really work. Score one if policies exist but are templates, outdated or inconsistent with practice. Auditors compare written policies to reality, and mismatches become findings quickly.

Question 4: Can You Prove Workforce Training?

Score two if you can produce dated training completion records for every workforce member, including new hires and contractors, covering HIPAA requirements relevant to their roles. Score one if training happens but records are incomplete or scattered across systems and managers.

Question 5: Are All Vendor BAAs Signed and Current?

Score two if you maintain a complete inventory of vendors handling PHI, each with a signed, current Business Associate Agreement. Score one if agreements exist for major vendors but the inventory is incomplete. Our guide to Business Associate Agreements explains required terms.

Question 6: Is Someone Accountable for HIPAA?

Score two if you have designated privacy and security officers with clear authority, time and resources, who report regularly to leadership. Score one if roles are assigned on paper but lack time or authority. Programs without real accountability tend to decay quickly between audits.

Questions 7 to 12: Technical Safeguards and Response

The second six questions cover technical safeguards and incident readiness: access control, audit logging, encryption, backups, incident response and security testing. These controls determine whether a breach happens and how bad it becomes if it does. Investigators increasingly test technical controls directly rather than relying on policy documents alone. Strong scores here indicate a program that protects patient data in practice. Score each question from zero to two using the same evidence standard, and note weak areas, because technical gaps often take longer to fix than documentation gaps and need planning.

Question 7: Do You Review User Access Regularly?

Score two if user access to systems with PHI is reviewed on a schedule, former staff are removed promptly and reviews are documented. Score one if access is managed but reviews are irregular. Our healthcare identity and access management work fixes this systematically.

Question 8: Are Audit Logs Enabled and Reviewed?

Score two if systems handling PHI record user activity and someone reviews logs or alerts for inappropriate access on a defined schedule. Score one if logging is enabled but nobody reviews it. Unreviewed logs rarely satisfy investigators asking how inappropriate access would be detected.

Question 9: Is PHI Encrypted Everywhere?

Score two if PHI is encrypted on laptops, mobile devices, servers, backups and in transit, with verification records. Score one if encryption covers some but not all locations. Lost unencrypted devices remain a leading cause of reportable breaches in healthcare organizations.

Question 10: Are Backups Tested for Recovery?

Score two if critical systems have offline or immutable backups and restoration is tested at least annually with documented results. Score one if backups exist but restoration is untested. Our healthcare data backup services help close this common gap. Untested backups often fail.

Question 11: Is Your Incident Response Plan Practiced?

Score two if you have a documented incident and breach response plan, an incident log and at least one recent tabletop exercise. Score one if a plan exists but has never been practiced. Our healthcare data breach response plan shows the expected structure.

Question 12: Do You Test Security Regularly?

Score two if you run vulnerability scanning and periodic penetration testing, and track findings to closure. Score one if testing happens occasionally without follow-through. Our healthcare penetration testing services include retesting, so fixes are confirmed rather than assumed. Closure is what counts.

What Your Score Means

Your total score places you in one of four readiness bands. The bands indicate how an audit, investigation or demanding customer review would likely go today and how much work is needed to reach a defensible position. They are guides rather than guarantees, because a single critical gap, such as no risk analysis, can outweigh strong scores elsewhere. Read your band and then check your individual zero scores, since those deserve attention first regardless of total. The six points below explain each band and how to use the results with leadership, boards and compliance teams.

20 to 24: Audit Ready

A score of 20 or more suggests a mature program with working, documented controls. Focus on keeping evidence current, testing controls and preparing for new requirements. A mock audit can confirm readiness before a real review or major customer security assessment.

14 to 19: Mostly Ready

A score of 14 to 19 suggests a solid foundation with specific gaps. Most organizations in this band can reach audit readiness within weeks by fixing partial controls and organizing evidence. Prioritize any zero scores first, then upgrade one-point answers.

8 to 13: Significant Gaps

A score of 8 to 13 suggests an organization that would likely receive findings in an audit or investigation today. A structured remediation plan, usually starting with the risk analysis, vendor agreements and access reviews, should begin now rather than waiting for a trigger event.

0 to 7: High Risk

A score below 8 suggests major exposure. If an investigation, breach or customer review is approaching, act immediately. Our HIPAA audit preparation services help organizations close the most critical gaps quickly under deadline pressure. Waiting only makes the eventual fix more expensive and stressful.

Zero Scores Come First

Regardless of total, any question scored zero is a priority, especially risk analysis, vendor agreements, encryption and incident response. A missing risk analysis alone is among the most frequently cited problems in enforcement actions, so it should be fixed before anything else.

Rescore Every Quarter

Readiness changes as systems, vendors and staff change. Rescore quarterly and after major changes, such as new EHR modules, cloud services or acquisitions. Tracking your score over time shows leadership and boards whether the compliance program is improving or quietly slipping backward.

What to Fix First

After scoring, most organizations face more gaps than they can fix at once. Prioritizing by risk and effort keeps progress visible and reduces exposure fastest. Some fixes take days, such as signing missing Business Associate Agreements, while others take months, such as encrypting every endpoint or implementing log review. Starting with high-impact, low-effort fixes builds momentum and credibility with leadership. The six priorities below reflect the order we typically recommend when helping organizations raise their readiness score quickly, although your specific findings may change the sequence slightly. Early wins build trust.

Update the Risk Analysis

The risk analysis anchors everything else and is often the first document investigators request. Updating it also reveals which other gaps matter most. Organizations scoring low on Question 1 should start here, because every later fix becomes easier to prioritize and justify.

Close Vendor Agreement Gaps

Missing Business Associate Agreements are usually quick to fix and carry significant risk if a vendor is breached. Build a complete vendor inventory, send agreements where missing and document oversight for high-risk vendors within a few weeks. Start with high-risk vendors.

Clean Up User Access

Remove former staff, shared accounts and excessive permissions, then set a recurring review schedule. Access cleanup reduces breach risk immediately and closes a visible gap that auditors test early in almost every review of healthcare organizations. Document every single review.

Verify Encryption

Confirm encryption on every laptop, phone, server and backup, and fix exceptions. Encrypted devices that are lost may not count as reportable breaches under federal rules, so encryption dramatically reduces the consequences of the most common security incidents. Record the results.

Turn On Log Review

Where logging exists but nobody reviews it, set up alerts for high-risk activity and a simple documented review routine. This converts an existing but unused control into evidence that inappropriate access would actually be detected and investigated. Start small. Expand coverage gradually.

Practice Incident Response

Run a tabletop exercise using a realistic scenario, such as ransomware or a lost laptop, and update the plan based on findings. Practiced response reduces breach impact and demonstrates to regulators that the organization takes incident readiness seriously. Record the lessons.

Cost of Closing HIPAA Readiness Gaps

Our HIPAA readiness work is billed at a blended rate of $50 per hour, covering compliance consultants, security engineers and project management. Cost depends on your score, organization size, systems, vendors and how close any audit or customer deadline is. The ranges below reflect typical effort and are planning figures, not quotes. Bring your completed scorecard to a call, and we can estimate remediation far more accurately. The six options below describe common engagements, and our HIPAA compliance consulting page explains our full compliance services. Every estimate lists its assumptions.

Readiness Review: $2,000 to $6,000

A readiness review typically takes 40 to 120 hours. We validate your scorecard with evidence, identify gaps you may have missed and produce a prioritized remediation plan with effort estimates that leadership can approve and track to completion. Scope is fixed upfront.

Risk Analysis Update: $4,000 to $12,000

Updating or rebuilding your risk analysis with a risk management plan typically takes 80 to 240 hours. Smaller organizations sit at the lower end, while multi-site providers and complex technology environments need more interviews and system reviews. Discovery confirms the range.

Remediation Program: $8,000 to $30,000

A remediation program covering policies, vendor agreements, access reviews, logging, encryption verification and training typically takes 160 to 600 hours. Technical fixes are handled directly by our engineers rather than listed in reports for your team to implement alone. Phases are common.

Mock Audit: $2,000 to $5,000

A mock audit typically takes 40 to 100 hours, testing evidence production, staff interviews and technical controls against realistic auditor requests. It confirms readiness for organizations scoring in the upper bands before a real audit or customer review. Findings get fixed.

Ongoing Compliance Support: $1,000 to $4,000 per Month

Retainers typically cover 20 to 80 hours per month for quarterly rescoring, access reviews, policy updates, vendor reviews and incident support, keeping your score from slipping as systems, vendors and staff change over time. Scope is reviewed every quarter with your compliance lead.

What Changes the Cost

Cost rises with more locations, systems, vendors, outdated documentation and short deadlines. It falls when evidence already exists and an internal owner coordinates work. Legal counsel, security tools and external audit fees are separate from our consulting and engineering cost.

Why Choose Taction for HIPAA Readiness

Two questions matter when choosing a partner to raise your HIPAA readiness: can they find the gaps an auditor would find, and can they actually fix them, including the technical ones. Many consultants deliver reports and leave remediation to internal teams that are already stretched. Our consultants work alongside engineers who build HIPAA-compliant healthcare software every day, drawing on 200+ healthcare projects since 2013 and ISO 27001 certified processes. We sign Business Associate Agreements before accessing PHI and work alongside your legal counsel. The six points below explain what working with us on HIPAA readiness looks like in practice.

We Fix, Not Just Report

When we find disabled logging, missing encryption or stale access, our engineers fix it directly. Findings turn into closed gaps within days, which matters when an auditor or customer deadline leaves no time to engage another vendor or wait for internal capacity.

Evidence-Based Scoring

We validate every scorecard answer against real evidence, so your score reflects what an auditor would see rather than what teams remember. Validated scores give leadership an honest baseline and make progress reports credible to boards and customers. Honesty drives real progress.

Built Around Real Audit Requests

Our remediation mirrors what investigators and customer auditors actually ask for, so effort goes into evidence that will be reviewed. You avoid polishing documents nobody requests while leaving the controls auditors test first unaddressed. Priorities stay clear and budgets stay focused.

Compliance Proven in Real Platforms

For Procentive, we built a behavioral health platform with encryption, role-based access and audit logging aligned to HIPAA safeguards. Read the Procentive case study to see compliance built into a production system. The same discipline shapes every readiness program we deliver.

Leadership When You Need It

If your organization lacks a dedicated security leader, our healthcare CISO as a service can own the readiness program, report to leadership and serve as an accountable contact for auditors, investigators and demanding customer security reviews. Engagements scale with your needs.

Evidence You Keep

The evidence library, policies, risk analysis and remediation records we build belong to you and keep working after the project ends. Future audits, customer reviews and quarterly rescoring become faster because everything is already organized in one place. Nothing is lost at handover.

Frequently Asked Questions

These are the questions privacy officers, practice managers, IT leaders and health technology founders ask most often after completing the HIPAA readiness scorecard, whether their score surprised them or confirmed what they suspected. The answers are short on purpose and are not legal advice, so involve counsel for legal interpretation. If your score raises urgent questions, a short call with our team will help you decide what to do first. For regulatory context on upcoming changes, see our overview of the HIPAA Security Rule update before the call. Answers reflect our practice.

What Is a Good HIPAA Readiness Score?

A score of 20 to 24 suggests audit readiness, while 14 to 19 indicates a solid base with specific gaps. Regardless of total, any zero score on risk analysis, vendor agreements, encryption or incident response should be treated as a priority.

How Often Should We Complete the Scorecard?

Complete it quarterly and after major changes, such as new systems, cloud services, acquisitions or leadership changes. Tracking scores over time shows whether your program is improving and gives boards a simple, consistent measure of compliance progress. Trends matter most.

Does a High Score Mean We Are HIPAA Compliant?

Not by itself. The scorecard highlights readiness and likely gaps, but compliance depends on a documented risk analysis, implemented safeguards and ongoing management. A formal assessment and legal review provide stronger assurance than any self-assessment tool alone. Treat it as a starting point.

Can Business Associates Use the Scorecard?

Yes. Business associates, including software vendors, billing companies and IT providers, have direct HIPAA obligations and face the same questions from customers and regulators. The scorecard applies equally to them and is especially useful before customer security reviews. Customers expect it.

How Much Does It Cost to Close Readiness Gaps?

At our $50 blended hourly rate, a readiness review typically costs $2,000 to $6,000, a risk analysis update $4,000 to $12,000, and a full remediation program $8,000 to $30,000, depending on scope. Legal and audit fees are separate. Estimates list assumptions.

What Should We Do If We Scored Below 8?

Start immediately with the risk analysis, vendor agreements, access cleanup and encryption verification. If an audit, investigation or breach is already underway, involve legal counsel and experienced support right away, because early action improves outcomes significantly. Speed matters most here.

Tell Us Your Score

Share your total score, your zero-score questions and any upcoming audits, investigations or customer reviews. In a 30-minute call we will confirm your biggest risks and outline a realistic plan to raise your score quickly. Book a free consultation. No commitment needed.

Ready to Discuss Your Project With Us?

Your email address will not be published. Required fields are marked *

What's Next?

Our expert reaches out shortly after receiving your request and analyzing your requirements.

If needed, we sign an NDA to protect your privacy.

We request additional information to better understand and analyze your project.

We schedule a call to discuss your project, goals. and priorities, and provide preliminary feedback.

If you're satisfied, we finalize the agreement and start your project.