HIPAA Compliance Scanner

Is your healthcare site HIPAA compliant?
Get a free scan in 30 seconds.

WatchSuit audits your website for BAA gaps, PHI handling disclosures, Notice of Privacy Practices, breach notification procedures, and minimum necessary standards. Identifies violations before OCR does.

Enforcement Data

OCR Fines in 2023–2024

The Office for Civil Rights has never fined less than six figures. And the breach that triggers the fine is usually discovered months after it starts. Run a scan before OCR runs one.

Entity Amount What Happened Source
Montefiore Medical Center
New York City · 2024
$4.75M Employee stole and sold PHI of 12,517 patients over 6 months. Multiple Security Rule failures. OCR couldn't detect the breach for years. HHS Press Release
Heritage Valley Health System
Pennsylvania · 2024
$950K Ransomware attack. Failed to conduct accurate security risk analysis. HHS Press Release
Plastic Surgery Associates of South Dakota
2024
$500K Ransomware. 10,000+ patients. Multiple Security Rule violations. HHS Press Release
Lafourche Medical Group
Louisiana · 2023
$480K Phishing attack exposed 34,862 patients. Failed risk analysis, no system activity monitoring. First phishing settlement ever. HHS Press Release
Doctors' Management Services
Massachusetts · 2023
$100K Ransomware (GandCrab). 206,695 patients. Breach began April 2017, not detected until December 2018. 3-year CAP. HHS Press Release
Bryan County Ambulance Authority
Oklahoma · 2024
$90K Ransomware. 14,000+ patients. Failed risk analysis. First OCR risk analysis initiative settlement. HHS Press Release
5 Checks · HIPAA

What we check

01
BAA Detection
Scans for mentions of Business Associate Agreements in your privacy policy and marketing materials. Required for any vendor handling PHI on behalf of a covered entity.
45 CFR §164.504(e)
02
PHI Handling Disclosure
Detects language around how Protected Health Information is collected, used, and shared — and whether scope limits are in place.
45 CFR §164.502(b)
03
Notice of Privacy Practices (NPP)
Checks for NPP references and whether they include required elements: individual rights, covered entity's duties, and contact information.
45 CFR §164.520
04
Breach Notification Procedures
Detects whether procedures for reporting PHI breaches to HHS are documented — must include the "without unreasonable delay" / ≤60-day discovery rule.
45 CFR §§164.400–414
05
Minimum Necessary Standard Signals
Scans for scope-limiting language around data use — uses and disclosures must be limited to the minimum necessary to accomplish the intended purpose.
45 CFR §164.502(b), §164.514(d)
Live Demo — No Login Required
Scan your healthcare site now
BAA · PHI handling · NPP · Breach notification · Minimum necessary standards
Open HIPAA Scanner →
Premium Report: Full HIPAA Audit + 4 Other Frameworks
Deep multi-page crawl, PDF remediation roadmap, 48-hr turnaround. Covers HIPAA alongside GDPR, EU AI Act, CCPA, and SOC 2 — one report, five frameworks, zero blind spots.

Frequently Asked Questions

No. Our scanner identifies publicly visible compliance gaps in your website's privacy disclosures, terms of service, and publicly-facing policies. A HIPAA risk assessment under 45 CFR §164.308(a)(1)(ii)(A) requires a comprehensive, organization-wide evaluation of all ePHI systems — something that requires access to your internal infrastructure, not just your public website. Use our scanner as a first line of defense; follow with a full risk analysis for complete compliance.
A covered entity (45 CFR §160.103) includes health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically. A business associate is any person or organization that performs functions involving the use or disclosure of PHI on behalf of a covered entity (e.g., billing companies, cloud providers, IT vendors). BAAs are required under 45 CFR §164.504(e). Healthcare websites often use dozens of third-party vendors (analytics, chat, payment processors) who may qualify as business associates — our scanner flags vendors that appear to handle patient data without contractual HIPAA protections.
OCR enforcement data shows that organizations are penalized for gaps that existed at the time of a breach — not just at the time of audit. Scan quarterly at minimum, and always after: (1) adding new third-party vendors or scripts, (2) updating your privacy policy, (3) launching new patient-facing features. The Montefiore breach occurred undetected for 6 months; Lafourche's breach began in March 2021. A recurring scan catches drift before it becomes an OCR fine.
Under 45 CFR §164.402, any impermissible use or disclosure of unsecured PHI that compromises its security or privacy is presumed a breach. Exceptions exist only if a documented risk assessment shows low probability of compromise — which OCR requires organizations to prove, not just assert.
Yes. Substance use disorder (SUD) patient records are governed by 42 CFR Part 2, which provides stricter confidentiality protections than HIPAA. OCR launched its Part 2 Civil Enforcement Program in February 2024 (CARES Act §3221) and is actively investigating Part 2 violations. If you treat SUD patients, your Notice of Privacy Practices must specifically address Part 2 restrictions.

About this page: WatchSuit is not a law firm and this page does not constitute legal advice. HIPAA compliance requirements are fact-specific. Consult a qualified HIPAA compliance attorney or privacy counsel for advice applicable to your organization. Last updated: May 2026.