Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

HIPAA Readiness Checklist

Work through the HIPAA Security Rule safeguards across administrative, physical, and technical controls. Check off what you have in place, watch your completion score update, and export a summary to share with your team. For the broader picture, see our guide to HIPAA for digital health.

0%
0 of 0 complete
Important: this is a readiness aid, not a compliance determination. The items below are drawn from the HIPAA Security Rule safeguards and common practice. Checking every box does not make you HIPAA compliant. Real compliance depends on a documented risk analysis, implemented and maintained safeguards, signed Business Associate Agreements, and evidence you can produce on request. Some safeguards are required and others are addressable, meaning you must implement them or document why an alternative is reasonable. Use this to prioritize and to brief your team, then validate the details with qualified counsel or an assessor.

Questions

Does this checklist make me HIPAA compliant?

No. HIPAA compliance is determined by your actual implemented safeguards, documentation, and risk analysis, not by a self-checklist. This tool helps you see where you stand against the Security Rule safeguards so you can prioritize the work.

What does the HIPAA Security Rule cover?

It requires administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). That includes a risk analysis, access controls, workforce training, encryption where reasonable, audit controls, and a contingency plan, among others.

Who has to comply with HIPAA?

Covered entities such as healthcare providers and health plans, and business associates that handle ePHI on their behalf. If you build software that touches health data for a covered entity, you are likely a business associate and need a Business Associate Agreement.

Is a risk analysis really required?

Yes. A documented, periodic risk analysis is an explicit Security Rule requirement and one of the most commonly cited gaps in enforcement actions. It is the foundation everything else builds on.

Is this checklist free?

Yes, it is free with no signup, and nothing you check is sent anywhere. If you need help reaching and documenting HIPAA compliance, our team can guide the program.

Not ready for a call yet?

Get the compliance playbook

A few short notes from Jacob on getting audit-ready without months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

HIPAA Readiness

We get you aligned to the HIPAA Security Rule safeguards.

Explore HIPAA Readiness →

Handling health data? Get it right.

We help teams in the healthcare & healthtech industry run the risk analysis, implement the safeguards, and produce the documentation HIPAA actually requires. Turn this checklist into a real program.

See our compliance services Book a call

Want the full picture on HIPAA?

This gives you the shape of the problem. The full picture is all 84 HIPAA safeguards, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

Start your free HIPAA assessment See what is in the platform

No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the workspace.