Score HIPAA Security Rule posture across the administrative, physical and technical safeguards plus required and addressable specifications.
The Security Rule splits into administrative (§164.308), physical (§164.310) and technical (§164.312) safeguards, and beneath each standard sit implementation specifications marked required or addressable. Addressable does not mean optional — it means you either implement it or record a reasoned decision not to, which is why documented alternatives earn full credit here while silence earns none. Two things dominate real HIPAA enforcement: an out-of-date risk analysis and a missing business associate agreement, and both are flagged separately so a good average cannot bury them. This is a management estimate, not an audit finding or an OCR determination.
HIPAA Compliance
Score = 0.35 × safeguard standards met ÷ 18 + 0.30 × required specifications + 0.15 × addressable specifications + 0.20 × documentation and agreements.
Score = 0.35 × safeguard standards met ÷ 18 + 0.30 × required specifications + 0.15 × addressable specifications + 0.20 × documentation and agreements. The Security Rule splits into administrative (§164.308), physical (§164.310) and technical (§164.312) safeguards, and beneath each standard sit implementation specifications marked required or addressable. Addressable does not mean optional — it means you either implement it or record a reasoned decision not to, which is why documented alternatives earn full credit here while silence earns none.
Two things dominate real HIPAA enforcement: an out-of-date risk analysis and a missing business associate agreement, and both are flagged separately so a good average cannot bury them. This is a management estimate, not an audit finding or an OCR determination.
This calculator takes 10 inputs: Administrative safeguards met (§164.308, of 9), Physical safeguards met (§164.310, of 4), Technical safeguards met (§164.312, of 5), Required implementation specifications in place, Required implementation specifications in scope, Addressable specifications implemented or documented as not reasonable, Addressable specifications in scope, Current risk analysis on file (§164.308(a)(1)(ii)(A)), Business associate agreement signed with every business associate, Breach notification process tested against the 60-day rule. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. HHS does not certify or accredit anyone against HIPAA, so any vendor claiming to be HIPAA certified is describing a third-party attestation against someone's checklist. Compliance is a state you have to be able to evidence at any moment, which is why the documentation weighting matters as much as the technical controls.
A documented decision. Assess whether the specification is reasonable and appropriate for your environment; if it is, implement it, and if it is not, implement an equivalent alternative and write down the analysis. An addressable specification with no record either way is treated as a gap.