Clinical IT Health Analyzer

Select the option that best represents your current clinic operations. Your results are generated locally and kept private.

Question 1 of 5

How is Protected Health Information (PHI) stored in your facility?

Unencrypted Local Hardware

Files are saved directly on office laptops, USB keys, local workstations, or physical folder cabinets.

Basic Local Server

We run a local medical server requiring user passwords, but lack active access logging or AES-256 hardware encryption.

Secure Audited Host Vaults

Patient records sit in secure data centers using hardware-level AES-256 encryption, strict user query logs, and signed BAAs.

Question 2 of 5

How are user accounts and clinical credentials configured?

Shared Logins & Weak Passwords

Staff share general computer logins or write down basic passwords on sticky notes; no MFA is active.

Individual Accounts Only

Every assistant, physician, and receptionist has a unique login, but Multi-Factor Authentication (MFA) is not enforced.

Mandated MFA & Role Containment

Unique accounts, role-based access policies (RBAC), and strict biometric or hardware-enforced MFA locks all terminals.

Question 3 of 5

What is your disaster recovery and database backup protocol?

Sporadic Manual Backups

Staff copy folders to localized external USB drives once in a while. Recovery has never been tested.

Automated Local Copying

Our servers sync database files nightly to a local backup NAS, but we lack off-site copies or regular restore drills.

Immutable, Tested Cloud Mirrors

Encrypted hourly snapshots route to air-gapped cloud centers. We run automated restoration drills monthly.

Question 4 of 5

How does your clinic protect against malware and phishing scripts?

Free Workplace Antivirus

Basic antivirus software runs on workstations. No central network firewall or network monitors are in place.

Standard Paid Antivirus Shielding

We pay for business antivirus and run a standard hardware firewall, but lack active endpoint logging (EDR).

Managed Threat Response (SOC/EDR)

Active 24/7/365 Endpoint Detection, intrusion logs, and isolated phishing security barriers protect email nodes.

Question 5 of 5

How is cybersecurity and compliance training handled for clinic employees?

No Formal Instruction

Administrative or receptionist staff do not undergo cybersecurity training or patient data privacy instruction.

Annual Checklist Reviews

Staff review and sign a compliance document annually, but we do not execute phishing simulation tests.

Automated Phishing Simulations

Monthly simulated attacks, interactive HIPAA/PHIPA micro-learning modules, and instant retraining sessions for staff.

Analyzing Your Data...

Review your compliance and cyber risk metrics below.

0%
Security Index
Calculating...
Regulatory Compliance 0%
Cybersecurity Strength 0%
Disaster Recovery SLA 0%

Action Checklist Recommendations