Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Get your Patient Protect Score.

A five-minute Patient Protect Score Snapshot of your current risk exposure — what an OCR investigator would find in your practice, categorized, defensibility-scored, and benchmarked against practices your size.

This is a live scoring engine that reads across entity classification, practice profile, ePHI data flow, and operational safeguards, then produces a full Exposure Report and estimated Patient Protect Score Snapshot you can act on the same day. Learn how the Patient Protect Score works.

Free·No login required·~5 minutes·Data stays in your browser·Anonymous by design

What your Exposure Report will show.

A preview of what renders at the end of the diagnostic. The report combines self-attested compliance signals with practice-profile data and ePHI-flow analysis to produce a categorized, actionable exposure view — not a percentage.

Sample report

Overall exposure

HIGH

A practice in the HIGH tier carries multiple actively exploitable exposures and would struggle to defend against an OCR review today.

Critical exposures

4

Actively exploitable. Fix in the next 30 days.

Significant exposures

11

Meaningful risk. Address within the quarter.

Documentation gaps

18

Evidence missing. Producible on request.

If a ransomware event hit today

You could immediately produce

  • Workforce access records
  • Written policies

You could not produce

  • Current vendor documentation (BAAs, review dates)
  • Risk-management history
  • Documented security decisions

Confidence in defensibility

41%

Modeled likelihood that the practice could produce required evidence during an OCR review today.

Estimated remediation time

6.5hrs

To close all Critical and Significant exposures using the report's remediation queue.

Peer benchmark

Practices your size · average

38

Your practice

64

Bottom 30% of peers

Compares your exposure profile against the aggregate distribution of independent practices in Patient Protect's diagnostic corpus, segmented by practice size and specialty.

Sample data. Your report will populate with your own diagnostic answers.

Diagnostic starts here

Get your Score Snapshot.

The report format you just previewed, populated with your own answers. About five minutes. Data stays in your browser; no login required at any step.

How exposed is your practice?

Answer four short sections and get a complete risk profile — unified score, breach cost estimate, and a prioritized action plan.

Under 5 minutes

Unified risk score

Across compliance, entity exposure, practice profile, and data flow

Breach cost estimate

Year 1 exposure, 10-year projection, and industry benchmarks

Action plan

Prioritized recommendations specific to your practice

Free. No account required. Your data stays in your browser.

How the diagnostic actually scores you.

Every finding maps to a specific HIPAA Security Rule requirement or an OCR enforcement pattern. The Exposure Report is a composite of six independent signal categories, each scored on its own axis, then combined into an overall exposure tier.

01

Signal · Entity classification

Do you know what HIPAA actually requires of you?

Covered entity, business associate, hybrid entity, and downstream-vendor obligations differ materially. The diagnostic starts here because misclassification cascades into every downstream requirement.

45 CFR §160.103

02

Signal · Practice profile

What is the shape of your operating environment?

Practice size, patient record count, data storage location, security baseline, and vendor exposure. These inputs establish the risk surface OCR would consider proportional for your practice under Security Rule flexibility provisions.

45 CFR §164.306(b)

03

Signal · ePHI data flow

Where does patient data actually move?

The diagnostic maps every operational surface where ePHI is created, received, maintained, or transmitted — EHR, billing, messaging, referrals, cloud storage, and vendor endpoints. Data-flow gaps are the leading cause of accidental disclosure findings in OCR enforcement.

HIPAA Security Rule §164.308(a)(1)(ii)(A)

04

Signal · Administrative safeguards

Do you have the policies, and do you follow them?

Risk analysis, workforce training, sanction policy, information system activity review. Missing or inadequate risk analysis is the second-most-cited violation in OCR Corrective Action Plans.

45 CFR §164.308

05

Signal · Technical safeguards

Are the systems technically secure?

Access controls, audit logging, integrity controls, transmission security. Scored against the Security Rule technical safeguard requirements with weighting for practice-size proportionality.

45 CFR §164.312

06

Signal · Evidence & defensibility

Could you prove it, right now, on paper?

Most OCR findings are not about missing safeguards. They are about missing evidence. The diagnostic models what your practice could produce in a same-day audit — vendor documentation, workforce training records, risk-analysis history, security decisions. That composite becomes the defensibility percentage on the report.

45 CFR §164.316

Methodology attribution

The Exposure Diagnostic scoring model draws on Patient Protect's published research through the Secure Care Research Institute, including The Economics of ePHI Exposure and the State of Compliance quarterly series. It is calibrated against OCR public enforcement data and Corrective Action Plan patterns.

Full reasoning is in the Quiet Failure of HIPAA in Independent Practices founder essay, which explains the specific failure modes the diagnostic is designed to detect.

Why this diagnostic is different.

Most free HIPAA assessments produce either a downloadable Excel file or a percentage score. Neither produces an answer a practice can act on. The Exposure Diagnostic sits in a distinct category.

Attribute
HHS SRA Tool
Generic vendor assessments
Patient Protect Exposure Diagnostic
Output
Static Excel file
Percentage score
Categorized Exposure Report with defensibility rating
Categorization
None
Single score
Critical, Significant, Documentation with remediation priority
OCR-review simulation
Not included
Not included
Models what you could produce in a same-day audit
Peer benchmark
Not included
Rarely included
Compares against practices your size
ePHI data-flow analysis
Not included
Not typically included
Included — maps every operational ePHI surface
Setup time
Hours; requires download
5-30 minutes
~5 minutes in your browser
Regulatory mapping
Referenced by section
Varies
Every finding cites the specific 45 CFR requirement

HHS SRA Tool refers to the free downloadable Excel-based tool published jointly by HHS OCR and ONC. Attributes for other vendor assessments describe the general category and do not make claims about specific vendors' current products.

Built by the team behind Patient Protect.

The Exposure Diagnostic scoring engine is a collaboration between our founder, our security architect, and our clinical compliance lead. Each of the six signal categories reflects the discipline of the person who owns it.

Alexander Perrin

Founder & CEO

Alexander Perrin

Product strategy · Research authorship

Primary author of the Secure Care Research Institute research program, including The Economics of ePHI Exposure.

Full bio
Joseph A. Perrin

Chief Technology Officer

Joseph A. Perrin

Federal & clinical infrastructure security

Architected Patient Protect's zero-trust security stack. Designed the technical-safeguard scoring signals in the diagnostic.

Full bio
Angie Perrin, RDH

Chief Security Officer

Angie Perrin, RDH

Certified HIPAA Consultant · 10+ years clinical

Shaped the administrative-safeguard and workforce-training signal categories from direct clinical experience.

Full bio

Frequently asked questions.

How exposed is my practice under HIPAA right now?

The only way to know is to test each of the operational categories OCR investigators actually cite in enforcement — risk analysis, workforce access, vendor management, evidence retention, and breach response. Patient Protect's free Exposure Diagnostic runs each of those categories against your practice profile and returns a full Exposure Report in about five minutes. Independent practices consistently discover between 3 and 8 critical exposures they were not tracking.

What would an OCR investigator find in my practice?

OCR investigations focus on documented evidence — proof that safeguards existed, were operating, and were reviewed. The Exposure Report simulates that review across the same categories OCR uses in Corrective Action Plans: risk analysis, access management, business associate oversight, workforce training, audit controls, and breach notification readiness. It lists what you could produce in an audit and what you could not.

How is this different from the HHS SRA tool?

The HHS Security Risk Assessment tool is a downloadable Excel file that captures your answers in a static document. It does not score your responses, compare them against peer practices, produce a defensibility rating, or update as your practice changes. Patient Protect's Exposure Diagnostic is a live scoring engine that combines answer-based signals with ePHI data-flow analysis and produces a categorized Exposure Report with remediation prioritization.

How long does the diagnostic take?

About five minutes for the full flow. Six steps: quick check, entity classification, practice profile, ePHI data flow, unified scoring, and the Exposure Report. All assessment data stays in your browser and is never transmitted to Patient Protect servers unless you explicitly request an emailed report.

What does the Exposure Report actually contain?

An overall exposure rating (Controlled, Moderate, High, or Critical), a categorized list of findings (Critical exposures, Significant exposures, Documentation gaps), an estimate of the hours required to remediate, a defensibility percentage that models what you could produce in an OCR review today, and a peer-benchmark comparison against practices of similar size. Each finding links to the specific HIPAA regulation or safeguard it maps to.

Is this diagnostic HIPAA compliant?

Yes. The tool collects no Protected Health Information at any point. All assessment data stays in your browser via local storage and is never transmitted to external servers. The questions evaluate operational safeguards — policies, controls, workflows, and vendor relationships — without touching patient data. Anonymous by design.

How often should we run this?

The Security Rule (45 CFR §164.308(a)(1)(ii)(A)) does not prescribe a frequency. HHS guidance says risk analysis should be conducted and updated as needed based on the covered entity's environment; some organizations run it annually, some more or less often. What triggers a re-run is a material change: new vendor, EHR migration, new location, staff turnover in an access-holding role, adoption of new AI or communication tools, or any suspected incident. Patient Protect's platform maintains a continuously-updated diagnostic score for practices that want a live signal between assessments. For the full requirements the Security Rule imposes on risk analysis, see the HIPAA Security Risk Assessment guide.

How accurate is the peer benchmark?

The benchmark compares your exposure profile against the aggregate distribution of independent practices in Patient Protect's diagnostic corpus, segmented by practice size and specialty type. It is directional, not diagnostic — a practice in the elevated tier faces measurably more exposure than the median peer of its size, but individual outcomes depend on many factors the diagnostic cannot see. The comparison is intended to contextualize the finding, not replace the formal Security Risk Assessment the Security Rule requires.

What do I do after I see my Exposure Report?

The report ranks findings by remediation priority — Critical exposures first, then Significant, then Documentation gaps. Most Critical exposures are actionable in hours and cost nothing to fix (they are usually access management, policy publication, or vendor documentation issues). The Patient Protect platform closes these categories automatically and keeps them closed as your practice changes; the report can also be used as a work plan for internal remediation or for scoping a HIPAA consultant engagement.

Who built this diagnostic?

Patient Protect's Exposure Diagnostic was designed by our team — Alexander Perrin (founder and CEO, primary author of the Secure Care Research Institute research program), Joseph A. Perrin (CTO, federal-grade infrastructure security architect), and Angie Perrin, RDH (CSO, Certified HIPAA Consultant with 10+ years of clinical practice). The scoring methodology draws on published OCR enforcement patterns, the HIPAA Security Rule technical safeguard requirements, and Patient Protect's own research on the operational reality of independent-practice compliance.

Do I have to give you my email?

No. The Exposure Report renders in your browser without any account or email. Email capture is offered only if you want the report emailed to you or your compliance officer. Everything stays local by default.

Looking for the formal HIPAA risk-analysis requirements? Read the HIPAA Security Risk Assessment guide for what §164.308(a)(1)(ii)(A) requires, how often, what a defensible analysis contains, and how it relates to ongoing risk management.

From free tools to a running program

Ready to start the real work?

Your Snapshot shows where the practice stands today. The Patient Protect platform is the operational layer that closes the exposures the Snapshot surfaces — real-time monitoring, BAA tracking, workforce training, breach simulation, and continuous compliance scoring built for independent practices.

Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.

This tool is a self-evaluation aid for educational purposes only. Results do not constitute legal, regulatory, or professional HIPAA compliance advice. No attorney-client or consultant-client relationship is created. Consider having findings reviewed by qualified HIPAA compliance counsel before taking action. See our Terms of Use.

Part of the HIPAA Foundation · 15+ free tools

See the full collection
AssessFree · proprietary

Assess risk

Your Patient Protect Score is a snapshot. The platform re-scores continuously, tracks remediation on every finding, and captures the evidence for audit.

Next in the sequence

ePHI Data Flow Mapper

Assessments, classification tools, and an AI assistant that reveal your actual compliance standing and starting point.