Free tool for therapy bloggers & private-practice sites

BAA Coverage Gap Quiz — embed it on any page.

A five-question check based on the framework in What a BAA actually is, and what it does not cover. It walks a clinician through the five risk categories a BAA leaves uncovered — subprocessor breaches, subpoenas, policy changes, model training, and their own Security Rule duties — and gives a score with actionable gaps. No account, no tracking beyond a standard backlink, free to embed on any clinician or therapy-practice blog.

What it does

Five short questions. Each maps to one of the five risk categories from the cornerstone post. The clinician answers in about 60 seconds, gets a 0–10 coverage-gap score with a short diagnostic for every category where there is a gap, and can read the full framework or see the architectural alternative.

Who it's for

  • Therapy-practice bloggers writing about HIPAA, AI scribes, or private-practice compliance.
  • Clinician consultants who help solo practices evaluate tools.
  • Training programs and supervisor sites that want a simple self-check tool for their cohorts.
  • Anyone who writes about the difference between "we signed the BAA" and "the data is safe."

Embed it

Paste these two lines anywhere on your page. No build step, no dependency, no cross-domain cookie. The widget renders inline at ~540 px wide and adapts to light or dark backgrounds automatically.

<div id="therapydraft-baa-quiz"></div>
<script async src="https://therapydraft.com/embed.js"></script>

What you get as the embedder

  • A useful, on-topic interactive tool for your readers.
  • A standard rel="noopener" backlink from a ranking privacy-focused clinical tool.
  • Zero maintenance — updates ship live from the CDN.
  • Full MIT license on the script itself; inspect, fork, or self-host if you prefer.

Privacy

The widget runs entirely in the visitor's browser. Answers are held in memory for the life of the page session and then discarded — nothing is POSTed to our servers, no cookies set, no analytics beaconed. The only network fetch is the script file itself.

Source: /embed.js · License: MIT · Built from the framework in the BAA coverage-gap post.

Live preview