How do I know if I have to be HIPAA compliant?+
You need to be HIPAA compliant if creating, receiving, storing, or sharing Protected Health Information (PHI), any individually identifiable health information such as medical records, billing data, or insurance details, as defined in 45 CFR 160.103. That includes covered entities like healthcare providers and health plans, plus vendors that handle PHI for them as business associates.
What happens if we are not HIPAA compliant?+
HIPAA violations can result in civil monetary penalties ranging from $145 to $73,011 per violation, up to $2,190,294 annually per violation category, as established by the HHS Office for Civil Rights enforcement framework. Willful neglect violations that are not corrected can result in criminal penalties for violating HIPAA including fines up to $250,000 and imprisonment.
How long does your HIPAA compliance process take?+
Days, not weeks. Automation does the repetitive work, so most of the timeline comes down to your size, your number of locations, and how fast your staff finish training.
What is the difference between Self-Guided and Full-Scope?+
Self-Guided is $675/year and is designed for experienced compliance professionals who need a reliable, cloud-based platform to centralize their work. Full-Scope is $1,300/year and is designed for small and scaling teams tackling HIPAA compliance for the first time, or transitioning from another platform, who need guided assistance getting their program up and running.
How much does HIPAA compliance consulting cost for a 5-person healthcare office?+
$1,300 / Year / Flat rate. If you choose, there is an option to purchase two years in advance at a discounted rate. More info on this is found on our Pricing page.
Is One Guy Consulting an attorney?+
No. One Guy Consulting is not a law firm and does not provide legal advice. Consult an attorney before making important business or legal decisions.
What is a HIPAA security risk assessment?+
A Security Risk Assessment (SRA) is a federally mandated evaluation required on a regular basis under 45 CFR 164.308(a)(1)(ii)(A). It identifies potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) and forms the foundation of any HIPAA compliance program.
What is a HIPAA gap analysis?+
A HIPAA gap analysis compares your current administrative, physical, and technical safeguards against the requirements of the HIPAA Security Rule (45 CFR Part 164, Subpart C) and the Privacy Rule (Subpart E). It identifies partial controls, missing documentation, and procedures not consistently followed.
What is a HIPAA remediation plan?+
A HIPAA remediation plan documents identified compliance gaps and assigns specific corrective actions, owners, and deadlines to resolve them. It demonstrates to auditors that an organization has a structured, documented approach to addressing risks, consistent with the risk management requirement at 164.308(a)(1)(ii)(B).
Do I need to write my own HIPAA policies from scratch?+
No, One Guy Consulting provides policy templates tuned to HIPAA requirements and helps tailor them to your organization.
What do I do if my small clinic still does not have a HIPAA risk assessment or written policies?+
Do the HIPAA Security Risk Assessment first, then use the findings to write your policies and procedures, fix the highest-risk gaps, and keep documentation. These are all things One Guy Consulting is very familiar with and will be happy to assist you on.
Do you offer ongoing HIPAA compliance support?+
Yes. HIPAA compliance is not a one-time event. We offer ongoing support including regularly scheduled SRA updates, policy reviews, staff training refreshers, and assistance with any compliance questions that arise.
Does One Guy Consulting sign a Business Associate Agreement (BAA)?+
One Guy Consulting, as of today, 9-11-2026, offers no service which would warrant a BAA. However, as we are always working to expand our service offering to meet customer (and regulatory) demand this will change. BAA’s will only be necessary for three features yet to roll out; Mobile Device Management (MDM), Vulnerability Scanning, and Penetration Testing. Stay Tuned!