Need IT help now? Call (321) 221-7117 — We respond within 2 hours.

Need IT help? Help Desk Request Assistance Get in Touch

Free self-check · 3 minutes · No sign-up

Free HIPAA Readiness Check for Small Practices, Plus FTC Safeguards for Tax Firms

This free HIPAA readiness check is twelve yes-or-no questions, each tied to what the rules actually say. You get a score and your biggest gaps on screen straight away. Pick your practice type to start.

What does this HIPAA readiness check cover?

The twelve controls regulators and insurers ask about first: a written risk assessment, a named person responsible, multi-factor authentication, encryption, backups, vendor agreements, staff training, removing former staff, an incident response plan, logging, supported systems and email protection. For medical and dental practices each question maps to a section of the HIPAA Security Rule; for tax and accounting firms, to the FTC Safeguards Rule, which applies to tax preparers as financial institutions.

It is a self-check, not an audit or legal advice. A “yes” means you believe the control is in place; the real test is whether you could show evidence of it if asked.

Who has to follow the FTC Safeguards Rule?

Any “financial institution” under the Gramm-Leach-Bliley Act, which includes tax preparers, CPA firms that prepare returns, bookkeepers handling client financial data and many other small firms. Since June 2023 the amended rule requires a named Qualified Individual, a written risk assessment, multi-factor authentication, encryption, staff training, vendor oversight and a written incident response plan. Since May 2024, a breach involving 500 or more people must be reported to the FTC within 30 days. The IRS also expects every preparer to keep a written information security plan, and its free template, Publication 5708, is the usual starting point. For more on PTIN renewal and Line 11, see our FTC Safeguards guide for tax and CPA firms.

What does HIPAA require of a small practice’s IT?

The HIPAA Security Rule requires a documented risk analysis, a designated security official, workforce training, access controls, audit controls, a contingency plan with backups, and a Business Associate Agreement with every vendor that handles patient information. Some safeguards, such as encryption, are “addressable”, which means you must implement them or document why an equivalent measure is reasonable. HHS has proposed making most of them mandatory. Our guide to what a HIPAA risk assessment involves includes a free worksheet.

What should I do with a low score?

Start with the risk assessment, because every other control flows from it and it is the first document regulators ask for. Then multi-factor authentication and backups, which stop the most common incidents. Most practices can close the majority of gaps in a few weeks without new hardware. If you want help, we offer a free IT assessment with a written report, and we provide HIPAA-compliant IT services and cybersecurity for practices and firms across Polk County, including Lakeland and Winter Haven. Call (321) 221-7117.

Digital Business Card