Is your product actually HIPAA-aware?

Fifteen questions across the seven areas a hospital security review, a covered entity or an investor’s technical diligence will actually check for. Answer honestly, get a score and see exactly which category is weakest. Not legal advice, not a certification — nobody can sell you one of those honestly.

15 questions, 7 categoriesShows your weakest areasUS-relevant only
Data inventory
Vendor agreements & tracking SDKs
Encryption
Access control & identity
Audit logging
Breach response
Segregation of the regulated core

Check the boxes that are true

Leave a box unchecked if you’re not sure — an unverified safeguard behaves like a missing one in a real review.

This checklist is not

  • A legal opinion, a certification, or a substitute for counsel
  • A full reading of the HIPAA Security Rule’s implementation specifications
  • Aware of your state’s additional health-privacy laws
  • Relevant if you never create, receive, maintain or transmit PHI

US-relevant only: HIPAA is US federal law. If you operate in the UK, EU or Canada, different rules apply — GDPR, UK GDPR and PIPEDA among them — and this checklist does not score against any of those.

Four safeguard areas that show up in every real review

The checklist covers seven categories; these four are where we see the most expensive gaps in practice.

Data inventory & vendor map

Knowing exactly where PHI enters, lives and leaves your system — and which third parties ever touch it — is the precondition for every other safeguard. You cannot secure what you haven't mapped.

Encryption & access control

At rest, in transit, and behind roles that can be revoked individually without breaking anyone else's access. The mechanics are well understood; the gap is usually in coverage, not technique.

Audit logging

Who read or wrote a PHI record, and when, retained for years and hard to tamper with. This is the difference between answering a security review's questions and guessing at them.

Breach response

A written plan is table stakes. A plan your team has actually rehearsed once is the part almost nobody has, and the part that matters most in the first hour of a real incident.

What this checklist is, and what it deliberately isn’t

Each of the fifteen questions maps to one of seven categories, and each category mirrors a section of how we build HIPAA-aware systems: data inventory, vendor agreements and tracking SDKs, encryption, access control and identity, audit logging, breach response, and segregation of the regulated core. The score is simply the share of checked boxes, and the weakest-categories panel is sorted by the same arithmetic — there is no hidden weighting toward any one answer.

It is deliberately not a reading of the HIPAA Security Rule’s implementation specifications, which run to dozens of addressable and required items with their own legal interpretation. It is a practical proxy for what a security questionnaire, a hospital’s vendor-risk team or a technical due-diligence pass actually asks about first, because that is the review your product will really face.

We build HIPAA-aware, compliance-conscious systems. We do not issue certifications or legal sign-off, and neither should anyone else claiming to sell you one — the law does not define a HIPAA certification to hold.

The unprofitable advice: if your score is low and you have not yet shipped to real patients, that is the cheapest moment this problem will ever be to fix. Retrofitting audit logging and access control onto a live system with real PHI is a materially harder and more expensive project than designing them in before the schema exists.

What founders ask about HIPAA compliance

Is a 100% score the same as being HIPAA compliant?

No. This checklist scores the safeguards a real buyer, hospital security team or investor's technical diligence checks for in practice — it does not read the full text of the HIPAA Security Rule's implementation specifications, and it cannot give you a legal opinion or a certification. Nobody can sell you HIPAA certification honestly; the law doesn't define one. A perfect score means you're covering what we check for on every HIPAA-aware build, which is a genuinely strong starting point, not a finish line.

Why does this only apply in the US?

Because HIPAA is US federal law. If you operate in the UK, EU or Canada, the safeguards that matter are broadly similar in spirit — encryption, access control, audit logging, breach response — but the legal framework is different: GDPR and the UK GDPR outside the US, PIPEDA in Canada. This checklist scores against HIPAA specifically and shouldn't be read as coverage for those regimes.

What's the single most common gap you see?

Analytics and crash-reporting SDKs receiving PHI in event payloads without anyone noticing. A field name like `patient_name` or a raw error message containing a diagnosis gets logged straight into Firebase, Sentry or Mixpanel, none of which have signed a BAA, and nobody catches it because the SDK is doing exactly what it was told to do. It's in the vendor-agreements category on this checklist for that reason.

We're pre-revenue and don't have PHI yet. Should we still care?

If your product will eventually create, receive, maintain or transmit PHI, the cheapest time to build in these safeguards is before the schema exists, not after a hospital security questionnaire lands on your desk. Retrofitting audit logging and access control onto a live system with real patient data is materially harder and riskier than designing them in from day one.

What happens after I see my score?

The weakest-categories panel points at exactly which of the seven areas need work, and each one maps to a section of how we build HIPAA-aware systems. If you want a second opinion or a plan to close the gaps, that's a conversation, not a form to fill out.

Close the gaps properly

Send us your score and we'll tell you what closes the gaps

Paste in your weakest categories. We'll come back with what a HIPAA-aware version one should actually contain, a fixed price and a date — usually within one business day.