HIPAA Security Rule Gap Assessment Template
A structured self-assessment covering all 18 required standards under the HIPAA Security Rule: Administrative Safeguards (45 CFR 164.308), Physical Safeguards (164.310), and Technical Safeguards (164.312), plus 164.316 documentation requirements.
Each standard includes the regulatory citation, a plain-language explanation of what it requires, and an interview question you can use directly with staff or leadership to determine compliance status.
What's included:
- Assessment tabs for Administrative, Physical, and Technical Safeguards
- A Summary dashboard that automatically tallies Pass, Fail, Partial, and N/A results as you complete the assessment
- A completed example based on a fictional 22-person healthcare practice, showing exactly what a finished assessment looks like
- A Read Me guide explaining how to use the template
This template is built for practice owners, office managers, and IT staff at small healthcare organizations who need to understand where they stand against HIPAA Security Rule requirements before an audit, before a state health department visit, or as part of routine risk management.
This is a self-assessment tool. It shows you where your gaps are. It does not validate your answers against evidence, write your remediation plan, or produce your policies. If you want a professional to verify your findings, prioritize what to fix first, and build a remediation roadmap, NAXS Labs conducts independent HIPAA Security Rule gap assessments for small healthcare practices.
Licensed for use on a single engagement or within a single purchasing organization. Not licensed for resale or reuse across multiple clients without written permission from NAXS Labs LLC.