Telehealth Compliance Score Calculator
HIPAA compliance assessment for telehealth setup.
About this calculator
This calculator rolls up seven self-rated compliance domains -- encryption, BAA coverage, access controls, audit logging, staff training, incident response, and risk assessment -- into a single weighted score out of 100, plus an eighth derived domain (physical safeguards, set to 80% of the access-controls score as a correlated proxy rather than its own input). Domains are weighted by how central they are to the HIPAA Security Rule and to actual breach risk: encryption carries the heaviest weight at 25%, since unencrypted PHI in transit or at rest is the single most common root cause cited in HHS OCR breach settlements, followed by BAA coverage, access controls, and audit logging at 15% each. The composite score also drives two practical estimates: an annual compliance cost that scales with provider count and with how far each domain sits below a perfect 100, and a tiered potential OCR penalty exposure figure based on where the composite score lands relative to 50/70/85 breakpoints.
Provider count changes only the cost estimates -- it plays no role in the compliance score itself, since the score measures how well safeguards are implemented, not how many people use them. This is a self-assessment tool, not a substitute for a formal HIPAA Security Risk Assessment (SRA) conducted under HHS guidance, and the weights, cost formula, and OCR penalty tiers are illustrative estimates rather than figures published in a specific regulatory schedule -- actual OCR settlements vary widely by breach scope, prior history, and cooperation, and are not a simple function of a compliance score like this one.
Medical Disclaimer
This calculator is for informational and educational purposes only. It is not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider before making decisions about your health. Never disregard professional medical advice or delay seeking it because of results from this tool.
Inputs
Results
Compliance Score (0-100)
67.8
Risk Level (0=High, 1=Mod, 2=Low)
1
How to Use This Calculator
- Score your Encryption, BAA Coverage, Access Controls, Audit Logging, Staff Training, Incident Response, and Risk Assessment each from 0-100 based on current implementation.
- Enter the number of providers using the telehealth platform to scale cost estimates.
- Review the weighted Compliance Score out of 100 and the resulting Risk Level (0=High, 1=Moderate, 2=Low).
- Check the Weakest Area Score to see which compliance domain needs attention first.
- Use the Annual Compliance Cost, Gap Remediation Cost, and Potential Penalty Exposure to budget for closing gaps and managing regulatory risk.
How the result changes with Encryption Score (0-100)
| Encryption Score (0-100) | Compliance Score (0-100) | Risk Level (0=High, 1=Mod, 2=Low) |
|---|---|---|
| 40 | 57.8 | 0 |
| 60 | 62.8 | 1 |
| 100 | 72.8 | 1 |
What each input means
- Encryption Score (0-100)
- End-to-end encryption, data-at-rest encryption, TLS for data in transit. 100 = fully encrypted.
- BAA Coverage (0-100)
- Business Associate Agreements with all vendors handling PHI. 100 = all BAAs signed.
- Access Controls (0-100)
- MFA, role-based access, automatic session timeout, unique user IDs. 100 = fully implemented.
- Audit Logging (0-100)
- System activity logs, access tracking, log review process. 100 = comprehensive audit trail.
- Staff Training (0-100)
- Annual HIPAA training completion, telehealth-specific protocols. 100 = all staff current.
- Incident Response (0-100)
- Documented breach response plan, notification procedures, tested annually. 100 = fully prepared.
- Risk Assessment (0-100)
- Security Risk Assessment (SRA) completion — required annually for Promoting Interoperability.
- Number of Providers
- Number of clinicians/providers using the telehealth platform.
What each result means
- Compliance Score (0-100)
- Weighted HIPAA compliance score. >80 = Low risk, 60-80 = Moderate, <60 = High risk.
- Risk Level (0=High, 1=Mod, 2=Low)
- Overall risk classification based on compliance score.
- Annual Compliance Cost ($)
- Estimated annual cost to maintain current compliance level.
- Gap Remediation Cost ($)
- Estimated one-time cost to close identified compliance gaps.
- Weakest Area Score
- Score of the lowest-performing compliance domain — prioritize this first.
- Potential Penalty Exposure ($)
- Estimated OCR fine exposure range based on current compliance posture.
How this is calculated
Worked example, using the default values
- Identify Input Parameters8 parametersEncryption Score (0-100) = 80, BAA Coverage (0-100) = 90, Access Controls (0-100) = 70, Audit Logging (0-100) = 60, Staff Training (0-100) = 50, Incident Response (0-100) = 40, Risk Assessment (0-100) = 60, Number of Providers = 10 = 8 input(s) provided
- Calculate Compliance ScoreCompliance Score = encryption * weights.encryption +67.8 = 67.8
- Calculate Risk Level1 = 1
- Calculate Annual Compliance CostAnnual Compliance Cost = baseCost + gapCost * sqrt(providerCount)25060 = $25,060
- Calculate Gap Remediation CostGap Remediation Cost = (5060 = $5,060
Engine last updated . Checked against 2 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Which compliance domain has the biggest effect on the overall score?
Encryption, weighted at 25% -- the heaviest of the seven scored domains -- so a change in the encryption score moves the overall compliance score more than an equal-sized change in any other single domain. That weighting reflects how often unencrypted PHI shows up as a root cause in real HHS OCR breach settlements, not an arbitrary ranking.
Does the number of providers on the platform affect the compliance score itself?
No -- provider count has no effect on the compliance score, since the score measures how well safeguards are implemented across the seven domains, not how many people are using the platform. Provider count only scales the two cost estimates: it directly raises the annual compliance cost and the estimated gap-remediation cost as the base cost and gap-remediation formulas both multiply by it.
Why does increasing the number of providers raise the estimated annual compliance cost?
The annual compliance cost formula adds $1,500 per provider on top of a $5,000 base, then layers a remediation-gap cost that also scales with provider count -- so every additional provider using the telehealth platform directly increases the estimated dollar cost of maintaining the current compliance posture, independent of how compliant that posture actually is.
Does a higher BAA coverage score meaningfully improve the overall compliance score?
Yes -- BAA coverage carries a 15% weight, tied for the second-highest of the seven scored domains alongside access controls and audit logging, so raising it moves the overall weighted score by a proportional amount. Business Associate Agreements are a HIPAA requirement for any vendor that handles PHI, which is why incomplete BAA coverage is weighted heavily rather than treated as a minor administrative gap.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
More in Medical & Clinical.