Assess
Set up your organization, answer the security risk assessment, and the gap analysis is generated the moment you finalize it.
One Guy Consulting helps small practices and business associates build a full HIPAA program. Software speed, human guidance, zero clients ever fined.
Free 30-minute review. No credit card, nothing to install, and we never ask for patient information.


You work with Chuck Weiselberg, C.H.P., not a ticket queue. The software does the busywork, and Chuck walks you through the rest. Meet Chuck
The same repeatable path auditors expect, run start to finish. Each step builds on the one before it. Automation handles the repeat work, so a small team can keep up.
Set up your organization, answer the security risk assessment, and the gap analysis is generated the moment you finalize it.
Remediation plans are generated from your gaps. Review and approve your AI-tailored policies and procedures, then publish them.
Invite your staff to complete their training, and track vendors and execute BAAs in one place.
Finish the site, network, data and device audits, test your incident management system, and keep up with the annual requirements.
One page, three fields important enough that you’re locked out of every other step until this one is completed to start. This step is crucial since it allows you to check a requirement under HIPAA off your list, pre-sign agreements digitally, and designate your org a C.E., or B.A.
The Risk Analysis that informs each step of your HIPAA compliance plan that follows. Thanks to this one audit, which is more-or-less a questionnaire, we are able to infer everything we have to regarding gaps, remediation plans, and policies. Then, POOF, these items are simply in your account waiting for you.
A gap is a part of the law you're not following. The gap analysis generates the moment you finalize your security risk assessment. This reduces hours of repetitive work, where usually someone needs to match every last gap to each HIPAA regulation specification.
In a fashion similar to the automated gap analysis, the plans to fix your gaps will be waiting for you rather than you needing to brainstorm 50 ideas just to write down a plan to satisfy your gaps. Dive right in to fixing problems rather than just listing problems.
Inviting users to the platform to complete their training is fast and simple. After a quick verification and password setup, the employee will provide some network and device info, saving you the effort later.
Compliance Officers are encouraged to understand each policy in full. However, nothing says employees need to slog through hours of reading policies when a paragraph or two achieves the same thing.
After you have reviewed the policies enough to feel comfortable rolling them out to your organization, your next step is to disseminate the material for the immediate purpose of having staff train on them.
From the powerful vendor profile, organizations can track business relationships, BAA's, CA's, score vendors on risk, and fully execute important agreements that are stored in the tool.
18 questions comprise the Site and Network audit, so you’ll be in and out regarding that one in no time! Facility Access Controls, Workstation Use, Workstation Security, Device and Media Controls, Network & Infrastructure, and ePHI Data Flow are the over-arching categories addressed in this questionnaire.
One Guy Consulting steps a bit outside of the box to ensure accuracy on this next requirement. All of this is done while minimizing compliance officer effort. When employees onboard to the solution they answer some questions about their device and network which funnel right into the tool.
There are an infinite number of ways and methods in which reporting incidents can occur. The One Guy Consulting portal opts to build the feature right in. You have everything at your fingertips to handle incidents, but be sure to occasionally test it to make sure it works!
There are things that the federal government expects you to do on an ongoing basis. To ensure ongoing doesn’t become sometimes, most organizations operate on an annual cadence for HIPAA compliance plan renewals. Not only will we remind you when items are due again, but we’ll be right there to help you still, because that’s what One Guy Consulting does.
When an auditor, a business partner, or your own staff asks whether HIPAA is handled, this is what you pull up.




Most compliance platforms sell you the software and leave the interpretation to you. One Guy Consulting gives you HIPAA compliance software and guidance on industry best practices at the same time, every time. The software tailors your policies, maps your gaps, and builds your data inventory in a fraction of the time it would take any other way. You get compliant fast, but better yet - you can prove it.
One Guy Consulting’s HIPAA compliance blog is your go-to resource for articles on anything from cybersecurity events, emerging technologies, to realistically navigating the complicated nuances that comprise the HIPAA regulation. Take your pick and happy reading!
Every HIPAA or compliance term related to, standing for, meaning ‘x,’ known as ‘y,’ or allegorical for ‘z’ that we could possibly think of - Sorted for your convenience and stretching across a meager 91 pages, these 1,300 terms should get you out of most hairy situations … Hairy HIPAA situations at least. We still don’t know how Mom used to get those stains out with only Club Soda.
You have to follow HIPAA if you create, receive, store, or share protected health information (PHI). PHI is any health information that can identify a person, like medical records, bills, or insurance details.
That covers healthcare providers, health plans, and clearinghouses (called covered entities), plus any vendor that handles PHI for them (called a business associate). The legal definitions are in 45 CFR 160.103.
Civil penalties run from $145 to $73,011 per violation, capped at $2,190,294 per calendar year for identical violations. The tiers are set in 45 CFR 160.404 and the current inflation-adjusted amounts are in 45 CFR 102.3. The HHS Office for Civil Rights enforces them.
Knowingly obtaining or disclosing PHI in violation of HIPAA is also a federal crime, with fines up to $250,000 and up to 10 years in prison in the worst cases (42 U.S.C. 1320d-6).
Weeks, not months. Automation does the repetitive work, so most of the timeline comes down to your size, your number of locations, and how fast your staff finish training.
Self-Guided is $675/year and is designed for experienced compliance professionals who need a reliable, cloud-based platform to centralize their work.
Full-Scope is $1,300/year and is designed for small and scaling teams tackling HIPAA compliance for the first time, or transitioning from another platform, who need guided assistance getting their program up and running.
$1,300 a year, flat.
We do not charge by seat and we do not charge by usage.
A five-person office pays the same as a fifteen-person one, and adding staff or running more assessments never changes the invoice.
Pay two years up front and there is a discount. Full breakdown on our Pricing page.
No.
Chuck Weiselberg is not an attorney and One Guy Consulting is not a law firm. Nothing on this site is legal advice.
Chuck is a Certified HIPAA Professional who walks you through the software and his process.
Consult an attorney before making important business or legal decisions.
A Security Risk Assessment (SRA) is a federally mandated evaluation required to be completed on a regular basis.
It identifies potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) and forms the foundation of any HIPAA compliance program.
A HIPAA gap analysis compares your current administrative, physical, and technical safeguards against the requirements of the HIPAA Security Rule and the Privacy Rule.
It identifies partial controls, missing documentation, and procedures not consistently followed.
A HIPAA remediation plan converts identified compliance gaps into assigned and specific corrective actions, with owners and deadlines affixed to them for the sake of accountability.
It demonstrates to auditors that an organization has a structured, documented approach to addressing gaps that results in written policies.
Not at all!
Unless you want to.....
Otherwise, our software will enable you to review and adopt AI-tailored template policies and procedures which will be waiting in your account for you by the time you are ready to address them.
Do the HIPAA Security Risk Assessment first.
Then, use the findings to write your policies and procedures. This fixes the highest-risk gaps while providing written proof of your actions.
These are all things One Guy Consulting is very familiar with and will be happy to assist you on.
That depends on your plan.
Self-Guided ($675/year) is the platform on its own: your SRA, gap analysis, remediation plans, policies, training and records stay live and current year round, but no consulting time is included.
Full-Scope ($1,300/year) adds four hours a month with Chuck, personalized implementation, incident response guidance, and audit-readiness help.
From people at healthcare organizations Chuck has guided through HIPAA compliance.
Thank goodness for One Guy Consulting and their expertise in consulting on HIPAA compliance. We were totally lost before Chuck walked us through what we needed to do.
Staff training is always a mess; people don't know what to complete, or when. What shouldn't have taken terribly long, became a nightmare year after year. Then, I joined One Guy Consulting and it has been smooth sailing.
I was intimidated to start work on this project, but nothing was further from the truth! Chuck was so professional and welcoming. He was always happy to clarify questions I had.
A broader security offering for the same small practices, run and monitored for you. Launching in the near future.
Chuck Weiselberg helped write the compliance playbooks at two of the biggest names in this space before starting One Guy Consulting. Roughly 23,000 meetings and 3,500 organizations later, not one of them has been fined or failed an audit.
Chuck Weiselberg, C.H.P. · Queens, NY · HIPAA since 2015
healthcare organizations guided through HIPAA since 2015
Choose the level of expert guidance your organization requires, when you would like to meet, and how often you’d like to pay. We’ll handle the rest.
Small practices typically budget $5,000 to $15,000 for HIPAA compliance consulting (source: Medcurity, 2026). Full-Scope is $1,300 a year, flat.
One payment, two full years of coverage.
See 24-month pricingFlat rate per location. Monthly plans have no long-term commitment. We never ask for patient information.
Enforcement actions, threat actors, government fines, and system vulnerabilities are already out there. Are you actually still waiting to become HIPAA compliant?
Thirty minutes, no pressure, no obligation. We look at where you stand and tell you the truth about it.
Free 30-minute review. No credit card, nothing to install, and we never ask for patient information.
Each service area maps to a specific HIPAA duty. The platform automates the repeatable work. Chuck walks you through the software and his process.
Identify every system, device, and workflow that stores, transmits, or accesses ePHI, then rate the risk. Your gap analysis and remediation plan are built from it.
Compare your current safeguards, records, and workflows against the regulation, automatically, so you can see exactly where you fall short before an auditor does.
Findings become a prioritized plan with assigned tasks, timelines, progress tracking, and completion records. AI drafts it; you approve it.
Customized, plain-language policies that reflect how your practice actually operates, with adoption records kept for audit. Roughly 38 templates.
Six training modules covering the Privacy Rule, Security Rule, breach reporting, and phishing awareness, with completion records and signed attestations.
A living inventory of every vendor that touches PHI, with digital Business Associate Agreements executed in-app and reviewed annually.
Report, assess, and document incidents with a breach workflow ready before you need it, including the four-factor risk assessment and notification steps.
One view of where you stand: what is complete, what needs attention, and your evidence organized and retained for the required six years.
A broader security offering for the same small practices, run and monitored for you. Launching in the near future.
A free 30-minute review, no obligation. We find the gaps and tell you the truth about them.
Free 30-minute review. No credit card, nothing to install, and we never ask for patient information.
Send a note and Chuck gets back to you himself. No pressure, no obligation.
Managed cybersecurity for healthcare is on the way. Leave your name and email and we will tell you the day it opens. No other mail, and you can leave the list any time.