Sample HIPAA AI Readiness Report
This is a representative report from a fictional dental practice. Your assessment produces the same sections with scores and recommendations tailored to your answers.
HIPAA AI Readiness Report
Sample Dental Practice
Executive Summary
Sample Dental Practice completed the HIPAA AI Readiness Assessment with an overall score of 62% and a High risk level. The practice shows partial maturity in traditional HIPAA safeguards but meaningful gaps in access control, vendor management, and AI governance. Leadership should treat the High posture as the baseline until remediation evidence is documented and verified.
Priority themes: refresh the Security Risk Analysis, tighten MFA and encryption on endpoints, and establish written AI-use policy before expanding clinical or operational AI tools.
Overall Score
62% — Risk Level: High (93 of 150 possible points across 75 questions).
This score reflects the maturity of controls that protect ePHI and govern AI use — not a certification. Treat High as the posture leadership should manage against until remediation evidence is on file.
HIPAA Score
68% — Administrative Safeguards, Audit Logging, and Cloud & Third-Party Risk (including BAAs).
HIPAA posture is directionally sound but still has remediable gaps. Prioritize Security Risk Analysis, named officers, BAAs, training, and incident response before polish items.
Cybersecurity Score
58% — Access Control, Encryption, Endpoint Security, Network Security, Backup & Disaster Recovery, and API & Integration Security.
Cyber posture is weak enough that a single credential theft, lost laptop, or ransomware event could become a reportable incident. Identity, encryption, and tested backups usually buy the most risk reduction per week of work.
AI Governance Score
55% — policies, vendor due diligence, human oversight, and inventory of AI tools in clinical or operational workflows.
AI governance is not yet a managed program; AI tools may already touch PHI without policy, BAAs, or oversight. If AI is in use or planned within 12 months, treat policy + vendor terms as 30-day work.
Top 10 Risks
- No current HIPAA Security Risk Analysis on file within the past 12 months.
- Multi-factor authentication is not enforced for all workforce members with ePHI access.
- Endpoint encryption and mobile device management gaps increase breach exposure.
- Business Associate Agreements are missing or outdated for key vendors.
- Incident response plan lacks tested tabletop exercises and contact trees.
- Workforce HIPAA training is not documented annually for all staff.
- AI tools in use without inventory, policy, or vendor risk review.
- Backup restoration has not been tested in the past 12 months.
- Audit logging does not cover all systems that store or transmit ePHI.
- Physical access controls for areas with ePHI are undocumented.
Top 10 Recommendations
- Commission or refresh a documented HIPAA Security Risk Analysis within 30 days.
- Enforce MFA on all accounts with ePHI access, including EHR and cloud apps.
- Deploy full-disk encryption and MDM on all laptops and mobile devices.
- Audit BAAs for EHR, cloud storage, billing, and any AI vendors — renew gaps.
- Run a tabletop incident response exercise and update the contact roster.
- Schedule annual HIPAA training with signed attestations for all workforce.
- Inventory AI tools touching PHI; add human review and vendor due diligence.
- Test backup restore quarterly and document results.
- Enable centralized audit logging with 6+ month retention on ePHI systems.
- Document physical access policies and badge controls for clinical areas.
30-Day Action Plan
- Commission or refresh a documented HIPAA Security Risk Analysis.
- Enforce MFA on all workforce accounts with ePHI access.
- Inventory AI tools and draft an interim AI-use policy with human-review rules.
- Audit BAAs for top 5 vendors and request updates where missing.
- Schedule annual HIPAA training for all staff with signed attestations.
60-Day Action Plan
- Deploy endpoint encryption and MDM on all laptops and mobile devices.
- Enable centralized audit logging with retention on ePHI systems.
- Test backup restoration and document results.
- Update incident response plan with contact tree and escalation paths.
- Document physical access controls for areas storing ePHI.
- Review cloud storage configurations for encryption and access logging.
90-Day Action Plan
- Continue monitoring; schedule the next readiness reassessment in 90 days to confirm improvements held.
- Expand AI vendor due diligence to any new tools before clinical rollout.
- Review workforce access quarterly and remove stale accounts.
Owner Letter
Dear Practice Owner,
Your team completed the HIPAA AI Readiness Assessment with an overall score of 62% (High risk). This letter summarizes what leadership should prioritize before your next audit or major technology change.
The assessment is not a certification — it is a structured self-evaluation of how well your practice protects ePHI and governs AI use. A High score means several foundational controls need attention before you can confidently expand AI tools or onboard new vendors.
Focus the next 30 days on refreshing your Security Risk Analysis, enforcing MFA, and inventorying AI tools. The 60- and 90-day plans in your full report sequence the remaining work without overwhelming your team.
Share this report with your compliance lead, IT partner, and anyone evaluating AI vendors. Questions about remediation? Contact assessments@hipaa-assessment.com.
Sincerely,
HIPAA AI Readiness Assessment