HIPAA Compliance Consulting

Let Automation Find the HIPAA Compliance Gaps
Costing Your Organization Thousands

One Guy Consulting builds a full HIPAA program for small practices and business associates: security risk assessments, automatic gap analyses, self-generating remediation plans, and AI-tailored policies your staff will actually read. Software speed, human guidance, zero clients ever fined.

Zeroclients fined by OCR
Zerofailed HIPAA audits
3,500+organizations guided
Since 2015HIPAA is all we do
The process

A compliance plan in weeks, not months.

The same repeatable path auditors expect, run start to finish. Each step builds on the one before it. Automation handles the repeat work, so a small team can keep up.

01

Initial Settings

One page, three fields important enough that you’re locked out of every other step until this one is completed to start. This step is crucial since it allows you to check a requirement under HIPAA off your list, pre-sign agreements digitally, and designate your org a C.E., or B.A.

02

Security Risk Assessment

The Risk Analysis that informs each step of your HIPAA compliance plan that follows. Thanks to this one audit, which is more-or-less a questionnaire, we are able to infer everything we have to regarding gaps, remediation plans, and policies. Then, POOF, these items are simply in your account waiting for you.

03

Automated Gap Analysis

A gap is a part of the law you're not following. The gap analysis generates the moment you finalize your security risk assessment. This reduces hours of repetitive work, where usually someone needs to match every last gap to each HIPAA regulation specification.

04

Auto-generating remediation plans

In a fashion similar to the automated gap analysis, the plans to fix your gaps will be waiting for you rather than you needing to brainstorm 50 ideas just to write down a plan to satisfy your gaps. Dive right in to fixing problems rather than just listing problems.

05

Invite Users and Training

Inviting users to the platform to complete their training is fast and simple. After a quick verification and password setup, the employee will provide some network and device info, saving you the effort later.

06

Review and Approve AI-Tailored Policies and Procedures

Compliance Officers are encouraged to understand each policy in full. However, nothing says employees need to slog through hours of reading policies when a paragraph or two achieves the same thing.

07

Publish Finalized Policies

After you have reviewed the policies enough to feel comfortable rolling them out to your organization, your next step is to disseminate the material for the immediate purpose of having staff train on them.

08

Vendor Management

From the powerful vendor profile, organizations can track business relationships, BAA's, CA's, score vendors on risk, and fully execute important agreements that are stored in the tool.

09

Site and Network Audit

18 questions comprise the Site and Network audit, so you’ll be in and out regarding that one in no time! Facility Access Controls, Workstation Use, Workstation Security, Device and Media Controls, Network & Infrastructure, and ePHI Data Flow are the over-arching categories addressed in this questionnaire.

10

Data and Device Audit

One Guy Consulting steps a bit outside of the box to ensure accuracy on this next requirement. All of this is done while minimizing compliance officer effort. When employees onboard to the solution they answer some questions about their device and network which funnel right into the tool.

11

Test Incident Management System

There are an infinite number of ways and methods in which reporting incidents can occur. The One Guy Consulting portal opts to build the feature right in. You have everything at your fingertips to handle incidents, but be sure to occasionally test it to make sure it works!

12

Perform Annual Requirements

There are things that the federal government expects you to do on an ongoing basis. To ensure ongoing doesn’t become sometimes, most organizations operate on an annual cadence for HIPAA compliance plan renewals. Not only will we remind you when items are due again, but we’ll be right there to help you still, because that’s what One Guy Consulting does.

See the full process
Why us

One Guy Consulting blends software and expert guidance to get you compliant fast

Most compliance platforms sell you the software and leave the interpretation to you. One Guy Consulting gives you software and guidance on industry best practices at the same time, every time. The software tailors your policies, maps your gaps, and builds your data inventory in a fraction of the time it would take any other way. You get compliant fast, but better yet - you can prove it.

/ SRA informs following steps / Gaps detected immediately / Remediation Plans that auto-generate / AI-Tailored Policies and procedures / Fully digital vendor management (No wasted paper!) / Complete Incident Management System Built-In
Compliance Glossary

1,300 HIPAA terms, in plain English.

Every HIPAA or compliance term related to, standing for, meaning ‘x,’ known as ‘y,’ or allegorical for ‘z’ that we could possibly think of - Sorted for your convenience and stretching across a meager 91 pages, these 1,300 terms should get you out of most hairy situations … Hairy HIPAA situations at least. We still don’t know how Mom used to get those stains out with only Club Soda.

1,300Terms defined
A–ZFully searchable
91 pagesFree PDF
FAQ

HIPAA compliance, answered.

How do I know if I have to be HIPAA compliant?+

You have to follow HIPAA if you create, receive, store, or share protected health information (PHI). PHI is any health information that can identify a person, like medical records, bills, or insurance details.

That covers healthcare providers, health plans, and clearinghouses (called covered entities), plus any vendor that handles PHI for them (called a business associate). The legal definitions are in 45 CFR 160.103.

What happens if we are not HIPAA compliant?+

Civil penalties run from $145 to $73,011 per violation, capped at $2,190,294 per calendar year for identical violations. The tiers are set in 45 CFR 160.404 and the current inflation-adjusted amounts are in 45 CFR 102.3. The HHS Office for Civil Rights enforces them.

Knowingly obtaining or disclosing PHI in violation of HIPAA is also a federal crime, with fines up to $250,000 and up to 10 years in prison in the worst cases (42 U.S.C. 1320d-6).

How long does your HIPAA compliance process take?+

Weeks, not months. Automation does the repetitive work, so most of the timeline comes down to your size, your number of locations, and how fast your staff finish training.

What is the difference between Self-Guided and Full-Scope?+

Self-Guided is $675/year and is designed for experienced compliance professionals who need a reliable, cloud-based platform to centralize their work.

Full-Scope is $1,300/year and is designed for small and scaling teams tackling HIPAA compliance for the first time, or transitioning from another platform, who need guided assistance getting their program up and running.

How much does HIPAA compliance consulting cost for a 5-person healthcare office?+

$1,300 a year, flat.

We do not charge by seat and we do not charge by usage.

A five-person office pays the same as a fifteen-person one, and adding staff or running more assessments never changes the invoice.

Pay two years up front and there is a discount. Full breakdown on our Pricing page.

Is One Guy Consulting an attorney?+

No.

Chuck Weiselberg is not an attorney and One Guy Consulting is not a law firm. Nothing on this site is legal advice.

Chuck is a Certified HIPAA Professional who gives you his recommendations.

Consult an attorney before making important business or legal decisions.

What is a HIPAA security risk assessment?+

A Security Risk Assessment (SRA) is a federally mandated evaluation required to be completed on a regular basis.

It identifies potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) and forms the foundation of any HIPAA compliance program.

What is a HIPAA gap analysis?+

A HIPAA gap analysis compares your current administrative, physical, and technical safeguards against the requirements of the HIPAA Security Rule and the Privacy Rule.

It identifies partial controls, missing documentation, and procedures not consistently followed.

What is a HIPAA remediation plan?+

A HIPAA remediation plan converts identified compliance gaps into assigned and specific corrective actions, with owners and deadlines affixed to them for the sake of accountability.

It demonstrates to auditors that an organization has a structured, documented approach to addressing gaps that results in written policies.

Do I need to write my own HIPAA policies from scratch?+

Not at all!

Unless you want to.....

Otherwise, our software will enable you to review and adopt AI-tailored template policies and procedures which will be waiting in your account for you by the time you are ready to address them.

What do I do if my small clinic still does not have a HIPAA risk assessment or written policies?+

Do the HIPAA Security Risk Assessment first.

Then, use the findings to write your policies and procedures. This fixes the highest-risk gaps while providing written proof of your actions.

These are all things One Guy Consulting is very familiar with and will be happy to assist you on.

Do you offer ongoing HIPAA compliance support?+

That depends on your plan.

Self-Guided ($675/year) is the platform on its own: your SRA, gap analysis, remediation plans, policies, training and records stay live and current year round, but no consulting time is included.

Full-Scope ($1,300/year) adds four hours a month with Chuck, hands-on implementation, incident response guidance, and audit-readiness help.

Coming soon

Managed cybersecurity is on the way.

A broader security offering for the same small practices, run and monitored for you. Launching in the near future.

Vulnerability scanningRecurring scans that surface known weaknesses before someone else finds them.
Penetration testingReal-world testing of your defenses, with prioritized findings you can act on.
Chuck Weiselberg, Certified HIPAA Professional
Chuck WeiselbergCertified HIPAA Professional
The one guy

You get the person who built it, not a ticket queue.

Chuck Weiselberg helped write the compliance playbooks at two of the biggest names in this space before starting One Guy Consulting. Roughly 23,000 meetings and 3,500 organizations later, not one of them has been fined or failed an audit.

Chuck Weiselberg, C.H.P. · Queens, NY · HIPAA since 2015

Pricing

Two plans, six convenient ways to pay

Choose the level of expert guidance your organization requires, when you would like to meet, and how often you’d like to pay. We’ll handle the rest.

For Advanced Users
Self-Guided
$675 / year
or $60 / month
  • SRA, gap analysis, remediation plans
  • Policy templates and staff training
  • Vendor and BAA management
  • Incident management and dashboard
Compare plans
Most popular
Full-Scope
$1,300 / year
or $120 / month
  • Everything in Self-Guided
  • Four hours a month, one on one with Chuck
  • Hands-on SRA walkthrough and custom policies
  • Audit-readiness prep and OCR response support
Compare plans
24-month
Prepay and save
Self-Guided
$1,175 / 2 years
save $175
Full-Scope
$2,300 / 2 years
save $300

One payment, two full years of coverage.

See 24-month pricing

The clock is ticking.

Enforcement actions, threat actors, government fines, and system vulnerabilities are already out there. Are you actually still waiting to become HIPAA compliant?

Work With Us

Find the gaps before OCR does.

Thirty minutes, no pressure, no obligation. We look at where you stand and tell you the truth about it.

  • Where you standA straight read on your risk assessment, policies, and training.
  • Your top 3 gapsThe problems most likely to hurt you, in plain English.
  • What fixing it costsWhich plan fits and what you would actually pay.
Get in touch

Tell us where you stand.

Send a note and Chuck gets back to you himself. No pressure, no obligation.

OGC-BotHi! What can I help you with?