For practices already using AI
Find out what you're exposed to. In three minutes.
Ten questions about how your practice already uses AI. You get a readiness score and your three sharpest gaps, free.
No patient information. Ever.
Never enter protected health information.
Ask your agent
agent tools not detected in this browserThis works with your AI agent in ChatGPT's desktop browser and Chrome with WebMCP enabled. Here's what that looks like.
Run the HIPAA AI readiness check on this page for me. I'm a 4-clinician therapy practice in California using an ambient scribe and ChatGPT, no vendor BAA yet, and we've never done a written risk analysis. Ask me anything you can't infer, then give me my score and my three sharpest gaps.
Walkthrough video coming shortly. The ten-question click-through below is identical to what the agent runs.
01 / 03 — THE CHECK
The check
Ten questions about the AI already in the building. Selects only — nothing to type, nothing to upload.
02 / 03 — YOUR SCORE
Your score
A weighted readiness score and the three exposures that matter most, with the state rules layered on top.
03 / 03 — YOUR ROADMAP
Your roadmap
The fixes in order, drawn from a thirty-safeguard library and tuned to your answers.
Where the line sits
AI may
- Inspect the ten questions and the safeguard library
- Ask the practice each question in its own words
- Record answers and advance the check
- Score the answers and explain every exposure
- Stage the roadmap offer and open the dialog
Human must
- Type their own email address and tick consent
- Book the 20-minute review themselves
- Make any determination about their own practice
- Decide what the practice does about a gap
- Keep patient information out of the conversation entirely
Your data
Your answers stay in your browser. We keep your email and your score — not a list of your gaps.
This is general education, not legal, compliance, security, or clinical advice. It does not determine HIPAA compliance and does not satisfy the security risk analysis required under 45 CFR 164.308(a)(1)(ii)(A). No HIPAA certification is offered or implied — HHS does not recognise any HIPAA certification.