Ungated self-check

How ready is your billing security program?

Ten questions to prepare for a useful security conversation. Keep your answers locally; this page does not collect them.

Score each question: 2 = documented and reviewed evidence; 1 = partly implemented or unverified; 0 = absent or unknown. This is an informal planning tool, not a security assessment or compliance score.

  1. Have you mapped where electronic patient information moves and is stored?
  2. Does your risk register have owners and open remediation actions?
  3. Do individual accounts and available MFA cover critical billing access?
  4. Can you show which work devices are managed and protected?
  5. Have encryption and secure-transfer decisions been reviewed and documented?
  6. Does offboarding include provider and payer accounts?
  7. Are vendor responsibilities and applicable BAAs recorded?
  8. Are critical-data recovery and external platform outages addressed?
  9. Does someone review relevant logs and follow up on incidents?
  10. Can management find current policies, evidence and review dates?

0–7 · Establish visibility

Prioritize an inventory and a scoped assessment. Unknowns require investigation; they do not prove a breach.

8–14 · Close the gaps

Focus on inconsistent coverage, unclear owners and evidence that needs verification.

15–20 · Verify the evidence

Validate the claimed controls and look for exceptions. A high self-score does not establish HIPAA compliance.

Override: a suspected active incident, known unauthorized access or an unprotected critical system needs prompt investigation regardless of the total. Follow your incident process; this website is not an emergency response channel.

Discuss my readiness priorities →

Bring the three lowest-scoring areas to the conversation. Do not send PHI, passwords or incident evidence through the public form. See the medical billing security program.