Most IT compliance resources fall into one of two categories: a PDF you download and never open, or a $500-per-seat SaaS platform built for enterprise security teams.

Neither is useful if you run a 10-person dental office or a small law firm in San Jose.

So we built something in between. Four free browser-based tools โ€” no account, no email gate, nothing stored on our end. Just open them and use them.

What’s Available

HIPAA IT Readiness Checklist

Covers the technical safeguard requirements under HIPAA across six categories: access controls, audit logging, encryption and transmission security, backup and data integrity, device and endpoint security, and staff training.

36 items total. Each one is marked as Required or Addressable under the actual HIPAA Security Rule, with plain-English notes explaining what it means in practice for a medical or dental office.

When you’re done, you can print the results or save as PDF. Useful for a quick self-assessment before talking to an IT provider, or before your next compliance review.

โ†’ Open the HIPAA IT Checklist


PCI DSS 4.0 Compliance Tracker

If your business accepts credit cards, PCI DSS applies to you โ€” regardless of size or transaction volume. The penalties for non-compliance after a breach are significant: card brands can fine you $5,000 to $100,000 per month, and in serious cases you can lose the ability to accept card payments altogether.

The tracker covers all 12 PCI DSS 4.0 requirement domains. Mark each requirement as compliant, a gap, or not applicable. Filter to show only gaps. Export a plain-text status report you can share with a QSA or use as an internal action list.

This isn’t a substitute for a formal PCI audit โ€” but it’s a useful way to understand where you stand before that conversation.

โ†’ Open the PCI DSS Tracker


MSP Evaluation Worksheet

This one is the most directly useful if you’re currently evaluating IT providers โ€” or wondering whether your current one is actually doing what you’re paying for.

24 questions across 6 categories: response time and SLA, backup and recovery practices, documentation and transparency, pricing and contract terms, security posture, and communication.

Each question has three scored responses and a note explaining what to look for and why it matters. At the end you get a score out of 48 and a verdict.

A few questions worth paying attention to regardless of which provider you use:

  • Does your IT provider perform actual test restores, or just confirm that the backup job ran green? A backup job that shows green does not mean your data is recoverable.
  • If your primary IT contact left their company tomorrow, could their replacement support your environment from day one? If the answer is no, you have key-person risk baked into your IT setup.
  • Do you have direct access to your Microsoft 365 admin credentials, domain registrar login, and key vendor accounts โ€” or does your IT provider hold all of them?

Bring the worksheet to any vendor meeting. Including ours.

โ†’ Open the MSP Evaluation Worksheet


Network Diagram Builder

Drag-and-drop your routers, switches, servers, firewalls, access points, and endpoints onto a canvas. Draw connections between them. Label everything with device names and IP addresses. Export as PNG.

It’s useful before an IT assessment โ€” having a diagram of your current setup saves time and helps an IT provider understand your environment faster. It’s also useful when onboarding a new provider, since handing over a documented network diagram instead of starting from scratch is exactly the kind of thing that reduces transition risk.

The builder runs entirely in your browser. Nothing is uploaded.

โ†’ Open the Network Diagram Builder


Why Free?

The short answer: the people who need these tools most are the ones least likely to pay for them upfront.

A dental office manager who wants to understand their HIPAA exposure isn’t going to buy a compliance platform. A business owner who’s been burned by a previous IT provider isn’t going to hand over their email address before they can look at an evaluation worksheet.

These tools are free because they’re more useful that way. If you find gaps and want help addressing them, that’s what a free IT assessment is for.


Who These Are Built For

All four tools are designed for Bay Area small businesses โ€” specifically the kinds of businesses where the person responsible for IT is also responsible for a dozen other things.

The HIPAA checklist and PCI DSS tracker are most relevant for medical offices, dental practices, law firms, and accounting firms. The MSP worksheet is useful for any business that uses an IT provider or is considering switching. The network diagram builder is useful for anyone who doesn’t currently have documentation of their office network โ€” which is most small businesses.

View all free IT tools โ†’