Free tool

The 12-Point Privacy & Security Self-Assessment

Score your organization’s posture in one board meeting. Twelve questions, an honest number, and a plain-language reading of what it means — built for pregnancy help organizations.

Completely private. This runs entirely in your browser. Nothing you select is stored, sent, or seen by us — there is no form here to submit.

Prefer paper for the board meeting? Print the PDF edition — same twelve questions, formatted for the table.

The twelve questions

Score each question: 2 points for “yes, and we could prove it with a document,” 1 for “mostly,” 0 for “no” or “not sure.”

1 Do we know, in writing, whether we are a HIPAA covered entity — and does our website language match that answer?
2 Has a security risk assessment been performed in the last twelve months, and did the board see the results?
3 Is multi-factor authentication required on email, our client-management system, and remote access — for staff and volunteers?
4 Are our backups automatic, kept separate from our network, and actually tested by restoring a file in the last six months?
5 Does every staff member and data-touching volunteer complete security awareness training at least annually?
6 Do we maintain a list of every vendor that stores or processes client data, with a written agreement for each?
7 When someone leaves — including volunteers — are their accounts disabled within one business day?
8 Do we have written privacy and security policies, reviewed within the last year, that match what we actually do?
9 Do we have a one-page incident response plan — who to call, in what order, within the first hour — and have we tested it, not just written it, in the past twelve months?
10 Is client-identifying information barred, in writing, from unapproved AI tools and personal accounts?
11 Could we produce, within one week, the security documentation our insurer’s renewal application asks for?
12 Does a named person own these questions — with the time and authority to act on them?