
Founder & CEO
Alexander Perrin
Product strategy · Research authorship
Primary author of the Secure Care Research Institute research program, including The Economics of ePHI Exposure.
Full bioA five-minute Patient Protect Score Snapshot of your current risk exposure — what an OCR investigator would find in your practice, categorized, defensibility-scored, and benchmarked against practices your size.
This is a live scoring engine that reads across entity classification, practice profile, ePHI data flow, and operational safeguards, then produces a full Exposure Report and estimated Patient Protect Score Snapshot you can act on the same day. Learn how the Patient Protect Score works.
Free·No login required·~5 minutes·Data stays in your browser·Anonymous by design
A preview of what renders at the end of the diagnostic. The report combines self-attested compliance signals with practice-profile data and ePHI-flow analysis to produce a categorized, actionable exposure view — not a percentage.
Overall exposure
HIGH
A practice in the HIGH tier carries multiple actively exploitable exposures and would struggle to defend against an OCR review today.
Critical exposures
4
Actively exploitable. Fix in the next 30 days.
Significant exposures
11
Meaningful risk. Address within the quarter.
Documentation gaps
18
Evidence missing. Producible on request.
If a ransomware event hit today
You could immediately produce
You could not produce
Confidence in defensibility
41%
Modeled likelihood that the practice could produce required evidence during an OCR review today.
Estimated remediation time
6.5hrs
To close all Critical and Significant exposures using the report's remediation queue.
Peer benchmark
Practices your size · average
38
Your practice
64
Bottom 30% of peers
Compares your exposure profile against the aggregate distribution of independent practices in Patient Protect's diagnostic corpus, segmented by practice size and specialty.
Sample data. Your report will populate with your own diagnostic answers.
Diagnostic starts here
The report format you just previewed, populated with your own answers. About five minutes. Data stays in your browser; no login required at any step.
Answer four short sections and get a complete risk profile — unified score, breach cost estimate, and a prioritized action plan.
Unified risk score
Across compliance, entity exposure, practice profile, and data flow
Breach cost estimate
Year 1 exposure, 10-year projection, and industry benchmarks
Action plan
Prioritized recommendations specific to your practice
Free. No account required. Your data stays in your browser.
Every finding maps to a specific HIPAA Security Rule requirement or an OCR enforcement pattern. The Exposure Report is a composite of six independent signal categories, each scored on its own axis, then combined into an overall exposure tier.
01
Signal · Entity classification
Covered entity, business associate, hybrid entity, and downstream-vendor obligations differ materially. The diagnostic starts here because misclassification cascades into every downstream requirement.
45 CFR §160.10302
Signal · Practice profile
Practice size, patient record count, data storage location, security baseline, and vendor exposure. These inputs establish the risk surface OCR would consider proportional for your practice under Security Rule flexibility provisions.
45 CFR §164.306(b)03
Signal · ePHI data flow
The diagnostic maps every operational surface where ePHI is created, received, maintained, or transmitted — EHR, billing, messaging, referrals, cloud storage, and vendor endpoints. Data-flow gaps are the leading cause of accidental disclosure findings in OCR enforcement.
HIPAA Security Rule §164.308(a)(1)(ii)(A)04
Signal · Administrative safeguards
Risk analysis, workforce training, sanction policy, information system activity review. Missing or inadequate risk analysis is the second-most-cited violation in OCR Corrective Action Plans.
45 CFR §164.30805
Signal · Technical safeguards
Access controls, audit logging, integrity controls, transmission security. Scored against the Security Rule technical safeguard requirements with weighting for practice-size proportionality.
45 CFR §164.31206
Signal · Evidence & defensibility
Most OCR findings are not about missing safeguards. They are about missing evidence. The diagnostic models what your practice could produce in a same-day audit — vendor documentation, workforce training records, risk-analysis history, security decisions. That composite becomes the defensibility percentage on the report.
45 CFR §164.316Methodology attribution
The Exposure Diagnostic scoring model draws on Patient Protect's published research through the Secure Care Research Institute, including The Economics of ePHI Exposure and the State of Compliance quarterly series. It is calibrated against OCR public enforcement data and Corrective Action Plan patterns.
Full reasoning is in the Quiet Failure of HIPAA in Independent Practices founder essay, which explains the specific failure modes the diagnostic is designed to detect.
Most free HIPAA assessments produce either a downloadable Excel file or a percentage score. Neither produces an answer a practice can act on. The Exposure Diagnostic sits in a distinct category.
HHS SRA Tool refers to the free downloadable Excel-based tool published jointly by HHS OCR and ONC. Attributes for other vendor assessments describe the general category and do not make claims about specific vendors' current products.
The Exposure Diagnostic scoring engine is a collaboration between our founder, our security architect, and our clinical compliance lead. Each of the six signal categories reflects the discipline of the person who owns it.

Founder & CEO
Product strategy · Research authorship
Primary author of the Secure Care Research Institute research program, including The Economics of ePHI Exposure.
Full bio
Chief Technology Officer
Federal & clinical infrastructure security
Architected Patient Protect's zero-trust security stack. Designed the technical-safeguard scoring signals in the diagnostic.
Full bio
Chief Security Officer
Certified HIPAA Consultant · 10+ years clinical
Shaped the administrative-safeguard and workforce-training signal categories from direct clinical experience.
Full bioFounder essay
The Quiet Failure of HIPAA in Independent Practices
Research paper · SSRN
The Economics of ePHI Exposure: A Long-Term Impact Model
Research library
Secure Care Research Institute — full publication list
Vendor comparison
Ten questions to ask any HIPAA compliance vendor
Diagnostic — external
HIPAA Readiness Scan — what an OCR investigator sees on your public website
The only way to know is to test each of the operational categories OCR investigators actually cite in enforcement — risk analysis, workforce access, vendor management, evidence retention, and breach response. Patient Protect's free Exposure Diagnostic runs each of those categories against your practice profile and returns a full Exposure Report in about five minutes. Independent practices consistently discover between 3 and 8 critical exposures they were not tracking.
OCR investigations focus on documented evidence — proof that safeguards existed, were operating, and were reviewed. The Exposure Report simulates that review across the same categories OCR uses in Corrective Action Plans: risk analysis, access management, business associate oversight, workforce training, audit controls, and breach notification readiness. It lists what you could produce in an audit and what you could not.
The HHS Security Risk Assessment tool is a downloadable Excel file that captures your answers in a static document. It does not score your responses, compare them against peer practices, produce a defensibility rating, or update as your practice changes. Patient Protect's Exposure Diagnostic is a live scoring engine that combines answer-based signals with ePHI data-flow analysis and produces a categorized Exposure Report with remediation prioritization.
About five minutes for the full flow. Six steps: quick check, entity classification, practice profile, ePHI data flow, unified scoring, and the Exposure Report. All assessment data stays in your browser and is never transmitted to Patient Protect servers unless you explicitly request an emailed report.
An overall exposure rating (Controlled, Moderate, High, or Critical), a categorized list of findings (Critical exposures, Significant exposures, Documentation gaps), an estimate of the hours required to remediate, a defensibility percentage that models what you could produce in an OCR review today, and a peer-benchmark comparison against practices of similar size. Each finding links to the specific HIPAA regulation or safeguard it maps to.
Yes. The tool collects no Protected Health Information at any point. All assessment data stays in your browser via local storage and is never transmitted to external servers. The questions evaluate operational safeguards — policies, controls, workflows, and vendor relationships — without touching patient data. Anonymous by design.
The Security Rule (45 CFR §164.308(a)(1)(ii)(A)) does not prescribe a frequency. HHS guidance says risk analysis should be conducted and updated as needed based on the covered entity's environment; some organizations run it annually, some more or less often. What triggers a re-run is a material change: new vendor, EHR migration, new location, staff turnover in an access-holding role, adoption of new AI or communication tools, or any suspected incident. Patient Protect's platform maintains a continuously-updated diagnostic score for practices that want a live signal between assessments. For the full requirements the Security Rule imposes on risk analysis, see the HIPAA Security Risk Assessment guide.
The benchmark compares your exposure profile against the aggregate distribution of independent practices in Patient Protect's diagnostic corpus, segmented by practice size and specialty type. It is directional, not diagnostic — a practice in the elevated tier faces measurably more exposure than the median peer of its size, but individual outcomes depend on many factors the diagnostic cannot see. The comparison is intended to contextualize the finding, not replace the formal Security Risk Assessment the Security Rule requires.
The report ranks findings by remediation priority — Critical exposures first, then Significant, then Documentation gaps. Most Critical exposures are actionable in hours and cost nothing to fix (they are usually access management, policy publication, or vendor documentation issues). The Patient Protect platform closes these categories automatically and keeps them closed as your practice changes; the report can also be used as a work plan for internal remediation or for scoping a HIPAA consultant engagement.
Patient Protect's Exposure Diagnostic was designed by our team — Alexander Perrin (founder and CEO, primary author of the Secure Care Research Institute research program), Joseph A. Perrin (CTO, federal-grade infrastructure security architect), and Angie Perrin, RDH (CSO, Certified HIPAA Consultant with 10+ years of clinical practice). The scoring methodology draws on published OCR enforcement patterns, the HIPAA Security Rule technical safeguard requirements, and Patient Protect's own research on the operational reality of independent-practice compliance.
No. The Exposure Report renders in your browser without any account or email. Email capture is offered only if you want the report emailed to you or your compliance officer. Everything stays local by default.
Looking for the formal HIPAA risk-analysis requirements? Read the HIPAA Security Risk Assessment guide for what §164.308(a)(1)(ii)(A) requires, how often, what a defensible analysis contains, and how it relates to ongoing risk management.
From free tools to a running program
Your Snapshot shows where the practice stands today. The Patient Protect platform is the operational layer that closes the exposures the Snapshot surfaces — real-time monitoring, BAA tracking, workforce training, breach simulation, and continuous compliance scoring built for independent practices.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.
This tool is a self-evaluation aid for educational purposes only. Results do not constitute legal, regulatory, or professional HIPAA compliance advice. No attorney-client or consultant-client relationship is created. Consider having findings reviewed by qualified HIPAA compliance counsel before taking action. See our Terms of Use.
Part of the HIPAA Foundation · 15+ free tools
See the full collectionYour Patient Protect Score is a snapshot. The platform re-scores continuously, tracks remediation on every finding, and captures the evidence for audit.
Next in the sequence
ePHI Data Flow MapperAssessments, classification tools, and an AI assistant that reveal your actual compliance standing and starting point.