This tool provides an automated, indicative self-assessment for informational purposes only. It does not constitute a security audit, penetration test, or legal or regulatory advice, and does not guarantee compliance with HIPAA, OWASP, or any other standard. Consult qualified security and compliance professionals.
FHIR API security checklist
A free, indicative security self-assessment for healthcare APIs. Check your FHIR deployment against OAuth 2.0, SMART on FHIR, the OWASP API Security Top 10 and HIPAA technical safeguards, and get a scored report with prioritised fixes in about ten minutes.
What you get
Instant security score
Weighted questions across ten control areas, from authentication and TLS to PHI protection, scored the moment you finish.
Free, no email needed
Severity-ranked gaps
The findings most likely to expose patient data, ranked so your team knows what to fix first.
Free, no email needed
Standards mapping
Every finding mapped to OAuth 2.0, SMART on FHIR, the OWASP API Security Top 10 and HIPAA technical safeguards.
Free, no email needed
Prioritised remediation report
A scored report with prioritised recommendations you can hand to engineering, delivered by email when you ask for it.
Emailed on request
How it works
Answer the checklist and see your score as you go.
About 10 minutes
Ten control areas: authentication, authorization, TLS, hardening, validation, audit, PHI protection, OWASP API, FHIR specifics and HIPAA.
Private by design
Answers are scored in your browser as you go. They are processed only to build the report you request, never sold or shared.
Indicative, not an audit
A planning tool for engineering and compliance teams. Not a security audit, penetration test or legal advice.
Find your FHIR API gaps before an attacker does
Free, indicative, about ten minutes.
FAQ
Want a second pair of eyes on the results?
Book a scoping call with CodeGeeks to walk through the findings and plan the fixes. A conversation, not a penetration test.
