Ungated self-check
How ready is your billing security program?
Ten questions to prepare for a useful security conversation. Keep your answers locally; this page does not collect them.
Score each question: 2 = documented and reviewed evidence; 1 = partly implemented or unverified; 0 = absent or unknown. This is an informal planning tool, not a security assessment or compliance score.
- Have you mapped where electronic patient information moves and is stored?
- Does your risk register have owners and open remediation actions?
- Do individual accounts and available MFA cover critical billing access?
- Can you show which work devices are managed and protected?
- Have encryption and secure-transfer decisions been reviewed and documented?
- Does offboarding include provider and payer accounts?
- Are vendor responsibilities and applicable BAAs recorded?
- Are critical-data recovery and external platform outages addressed?
- Does someone review relevant logs and follow up on incidents?
- Can management find current policies, evidence and review dates?
0–7 · Establish visibility
Prioritize an inventory and a scoped assessment. Unknowns require investigation; they do not prove a breach.
8–14 · Close the gaps
Focus on inconsistent coverage, unclear owners and evidence that needs verification.
15–20 · Verify the evidence
Validate the claimed controls and look for exceptions. A high self-score does not establish HIPAA compliance.
Override: a suspected active incident, known unauthorized access or an unprotected critical system needs prompt investigation regardless of the total. Follow your incident process; this website is not an emergency response channel.
Discuss my readiness priorities →
Bring the three lowest-scoring areas to the conversation. Do not send PHI, passwords or incident evidence through the public form. See the medical billing security program.