Is your practice HIPAA compliant?
A 9-question gap check for small healthcare practices. Check every box your practice has in place — gaps are highlighted automatically.
Check each item your practice has in place
Check each item your practice has in place — your recommended plan and gap summary update automatically as you go.
Want a personalized review of your results? Email Cynthia directly at cynthia@lookoutprivacy.com — she'll take a look and help you figure out your next step.
This self-assessment is for general informational purposes only and does not constitute legal advice or a formal HIPAA risk analysis. Results are intended to help identify potential gaps — not to certify compliance. Consult qualified legal counsel for guidance specific to your practice.
Why this matters for small practices
OCR enforcement is increasing
Small practices are no longer overlooked. The Office for Civil Rights has significantly expanded audit activity targeting practices with fewer than 10 providers.
Missing documentation is the most cited violation
Failure to maintain written policies, training records, and vendor agreements is consistently among the most common reasons OCR issues financial penalties — across practices of every size.
Flat fees, no hourly billing
Lookout Privacy offers flat annual plans starting at $2,500 — so you know exactly what you're paying and can budget for compliance like any other practice expense.
Built for practices without a compliance team
You're the provider and the compliance officer. Lookout Privacy is designed for practices where one person wears all the hats — including privacy officer.
Our service plans
All plans are flat annual fees. No hourly billing. Ever.
- Core HIPAA policy library
- Annual staff training (up to 10)
- BAA templates & checklist
- Vendor inventory guidance
- Incident log & decision tree
- Everything in Essentials
- Quarterly policy reviews
- Active vendor oversight (10 vendors)
- BAA reviews (up to 6/yr)
- Incident response guidance
- New hire training (up to 25 staff)
- 2 advisory hours/yr
- Everything in Active
- Vendor oversight & BAAs (up to 20/yr)
- AI governance framework
- Annual compliance risk report
- Incident guidance within 2 business days
- 4 advisory sessions/yr
- Two semi-annual check-in calls
- Staff training (up to 3 sessions/yr, unlimited users)