Beta launch coming soon!Join the waitlist
Latest OCR Settles $552K Ransomware Case with OSF Healthcare: Risk Analysis Failure Again at the Center Latest HIPAA Security Rule Overhaul Pushed to 2027: What a Small Practice Should Do Right Now Latest Four Ransomware Settlements, One Repeated Finding: No Thorough Risk Analysis
HIPAA Security Rule · built for practices of 1–20

Find your HIPAA gaps.
Know exactly what to fix.

HIPAAWorks turns the HIPAA Security Rule into plain-language questions, then gives you remediation steps written for the software your practice already owns, and keeps a dated record of every gap you found and every fix you made.

Seven questions, about five minutes, no card required.

Multi-factor sign-in required
Each practice's data isolated
Start free, no card
app.hipaaworks.com/dashboard
Example risk analysis workspace
Illustrative data
Next: review 3 critical gaps
Identified gaps
Critical3identified
High5identified
Medium4identified
Low2identified
Risk analysis checklist
18 of 42 reviewed
Remediation activity
Open5
In progress4
Remediated4
Risk accepted1
Gaps by safeguard area
Technical safeguards
6
Administrative safeguards
5
Physical safeguards
3
Evidence trail
Files and activity recorded
View trail ›
Multi-factor login not enforced on email and the patient record system
Microsoft 365
Workstation drives are not encrypted
BitLocker
86%
of OCR's 566 compliance reviews in 2020 resulted in corrective action or a civil monetary penalty.
94%
of covered entities in OCR's 2016–2017 audits failed to implement appropriate risk-management activities.
12 months
is the prior period for which an organization must adequately demonstrate recognized security practices for HHS to consider them in certain enforcement and audit decisions.
Practice manager reviewing a laptop in a bright independent clinic office
For the people who keep a small practice moving.

Security work that fits the person already doing the job.

There is no separate compliance department in most practices. HIPAAWorks gives the practice manager, owner, or clinical lead a clear place to start—and a record to keep current.

Useful between patients, meetings, and everything else.

Five steps. No IT department required.

Written for a practice manager, not a compliance officer. Every question is answerable without technical expertise: HIPAAWorks does the translation.

Laptop and organized notes on a small practice manager's desk
A manageable workflow starts with the work already in front of you.
Made for the in-between moments

Keep the next security task clear, even on a busy clinic day.

HIPAAWorks turns a broad rule into a short list of decisions your team can actually make, document, and revisit.

Plain EnglishQuestions about what happens in your office.
Your toolsGuidance tied to the software you already use.
Your recordNotes and evidence kept with the work.
1
Tell us your technology
About 5 minutes
Your patient record system, email, billing vendor, devices, and remote access. This drives every recommendation that follows.
2
Answer plain-language questions
About an hour, save and return
The full Security Rule assessment. No regulatory jargon: we ask what actually happens in your office.
3
Review your identified gaps
As soon as you finish
Critical, High, Medium, Low, plus a breakdown by safeguard area, so the priority order is obvious. No scores, ever.
4
Work through the fixes
At your own pace
Step-by-step guidance for the software you use, plus the policies and processes to put in writing. Move each gap through Open, In progress, Remediated, or Risk accepted, with notes.
5
Keep the record current
Ongoing, and once a year
Attach evidence, generate your organization-attested risk analysis, and reassess each year with a timestamp trail.

Everything here is a screen you actually use.

Not a binder, not a promise. Each item below is a working part of your account from day one.

A severity-tiered gap report
Every identified gap explained in plain language and tiered Critical, High, Medium, or Low, with a breakdown by safeguard area. No score, no grade, no pass/fail. Regulators don't recognize one, and it would only create false comfort.
Remediation guidance for your software
Fixes reference the EHR, email platform, and billing vendor you recorded in your technology profile. A practice on Microsoft 365 gets different instructions than one on Google Workspace.
Remediation tracking with an activity trail
Move each gap from Open to In progress to Remediated or Risk accepted, add notes, and every change is timestamped automatically. That trail is the record of what you found and what you did about it.
An evidence library
Upload photos and documents (the locked server closet, a screenshot of a setting, a signed policy) and attach each one to the gap it supports. A claim with evidence behind it is far stronger than a claim alone.
Pro
Documents you can hand to someone
Core exports a formatted PDF of your gap report and its remediation guidance. Pro generates the full organization-attested risk analysis: the document to give an auditor, an insurer, or your attorney.
Built for a team
Invite the people who actually do the work, with Owner, Admin, Editor, and Viewer roles. Multi-factor authentication is required on every account, and each organization's data is isolated at the database level.

A breach creates more than one bill.

The impact can include ransom demands, investigation and recovery work, legal response, notification, and operational disruption.

Cost category Possible impact
Ransom demand Extortion payment request
IT forensics & remediation Investigation and recovery work
Federal penalty Civil monetary penalty or settlement
Legal fees Counsel and response work
Breach notification costs Required notices and support

These are cost categories, not an estimate. Actual exposure varies by the incident, systems involved, affected individuals, and response requirements.

A risk analysis is not paperwork you file once.

Under the 2021 HITECH amendment, HHS is directed to consider whether an organization had recognized security practices in place for the prior 12 months when determining fines, audit outcomes, and other remedies. That is a continuous record: what you found, what you did about it, and when. HIPAAWorks builds it as you work.

Start your assessment

Two plans. No per-seat fees.

Core finds your gaps and helps you close them. Pro adds the record that proves you did. Annual billing saves 10%.

Core
$89.99 /mo
or $972/year, save 10%
Find your gaps and close them.
Full HIPAA Security Rule assessment
Severity-tiered gap report with safeguard-area breakdown
Remediation guidance written for your technology
Remediation tracking with a timestamped activity trail
Gap report PDF export
Team members with roles
Get started

Start free: your practice profile, your technology profile, and a seven-question Quick Check that names your first flagged gaps: about five minutes, no card required. The full assessment, the step-by-step fixes, and your documented record begin when you subscribe.

Practices of 1–20 people with no compliance department.

Independent practices carrying the same legal obligations as a health system, without the staff to match.

Three members of a small outpatient care team reviewing their work together
One small team, making security work part of the routine.
Physician practices
Solo and small-group practices operating outside health system ownership: compliance-aware, resource-constrained.
Dental practices
A wide technology surface (records, imaging, billing, patient messaging), and all of it in scope.
PT & OT clinics
Fragmented, multi-site, and among the most compliance-under-resourced practices in the country.
Behavioral health
Solo therapists to group practices, the fastest-growing segment, with the same obligations as everyone else.

Latest HIPAA Security News for Small Practices

Plain-English operational breakdowns of recent HHS & OCR updates: what changed, and what to check in your practice.