One Guy Consulting  /  HIPAA compliance program Contents of your account

Exactly what you walk away with

Not a promise of compliance. The actual documents, records and reports your practice ends up with, built inside the tool, shown here screen by screen.

Privacy Officer signature drawn once in the portal and applied to every generated policy and BAA
Signed once, inside the tool Your Privacy Officer

Exhibit 01

Initial Settings

You start by naming who is in charge.

Assign your Privacy Officer, save your signature once, and enter your organization details. That signature then applies itself to every policy and BAA the tool generates, and your logo lands on every document your staff reads.

More on HIPAA consulting
You keep Privacy Officer on record Named owner, signature on file,
organization details saved
Privacy Officer Assignment screen in the portal showing a green Assigned badge after the officer is saved

PLATE 1.1 Assigned, and the step flips green on your checklist.

Exhibit 02

Security Risk Assessment

The foundation everything else is built on.

63 questions covering everywhere PHI lives. Each one cites the exact HIPAA rule behind it. Only answer yes if you can back it with evidence. No is a fine answer, because anything missing is what we build next.

More on Security Risk Assessment
You keep Completed Security Risk Assessment 63 answers, submitted and locked
Export Markdown  /  Export CSV
Security Risk Assessment marked complete in the portal with Export Markdown and Export CSV buttons

PLATE 2.1 Submitted and locked, with one-click export.

Exhibit 03

Gap Analysis

Done the moment you submit, automatically.

The tool reads your answers against the regulation and hands back the report: total gaps, which ones put you out of compliance, sorted into categories. Nothing further for your Privacy Officer to do.

More on Gap Analysis
You keep Gap Analysis report Every gap, sorted by category
Export Gap Report
Gap Analysis Report in the portal showing 45 total gaps, 43 non-compliant, 2 needing review across 11 categories

PLATE 3.1 Real numbers from a real assessment, not a sample. Yours will look different.

Exhibit 04

Remediation Plan

Your gaps become a tracked to-do list.

Every gap turns into a task with a priority, an owner and a due date, and each one explains the fix in plain English. Attach your proof to the task as you close it, so the plan doubles as your evidence trail.

More on Remediation Plans
You keep Remediation plan Every gap becomes a task, prioritized,
assigned and due-dated on its own
Remediation Plans summary band in the portal showing 59 total tasks, 59 open, 0 completed and 0 percent completion
Remediation Plans task table listing open tasks with High priority, Privacy Officer as assignee and November 2026 due dates

PLATE 4.1 The band across the top is the whole plan at a glance. PLATE 4.2 Every task carries a priority, an owner and a due date.

Exhibit 05

Staff Invited and Trained

Your whole team, from one screen.

Add a name and a work email. The tool invites them and assigns their training. You watch progress live, and one click sends a reminder listing exactly what that person still owes. Everything completed lands in a timestamped record you can hand to an auditor.

More on HIPAA Staff Training
Employee Management table in the portal tracking each employee's status and training progress out of two modules

PLATE 5.1 Live completion tracking, per employee.

You keep Trained, tracked workforce Date and time of every completion
Download CSV
Training Records table in the portal showing each completed training module and policy attestation with its exact date and time

PLATE 5.2 And the record it produces: every module and attestation, timestamped, downloadable as a CSV.

Exhibits 06 and 07 Your policy library
06  /  Review Policies

Reviewed, customized policy set

The written policies and procedures your practice runs on, reviewed against how you actually work before anything is published.

07  /  Publish Policies

Published policies and attestations

Policies released to your staff, with the record of who acknowledged what and when.

Exhibit 08

Vendors and BAAs

Every vendor tracked, every agreement executed.

Build the vendor profile, then send the Business Associate Agreement for signature. The vendor signs electronically, and the countersigned agreement is stored on their profile as a PDF. Already have signed BAAs? Upload them.

More on Vendor Management
You keep Vendor register and executed BAAs Signed both ways, stored as a PDF
on the vendor's profile
BAA Ready panel in the portal listing the covered entity, business associate and effective date with an e-sign link to send to the vendor

PLATE 8.1 Generated, signed by you, and ready to send.

Exhibits 09 and 10 Your physical and technical audit
09  /  Site & Network Audit

Site and network audit record

A written record of your physical premises and your network, captured once and kept where the rest of the program lives.

10  /  Data & Device Audit

Device inventory and assessment

Every device that touches PHI, listed and assessed, so you can answer the question without walking the building.

Exhibit 11  /  last

Incident Reporting and Response Log

One form, and the clock starts properly.

Staff report an incident with the dates, systems and people affected. Your Privacy Officer is alerted on submit. From the log you review each one, add comments and close it out.

More on Incident Management
You keep Incident response log Every report, every review,
every close-out, in one place
Incident report form in the portal capturing location, affected systems and the number of individuals affected

PLATE 11.1 The report form your staff actually see.

Get in touch

Want this running on your practice?

Tell us where you are today. We will tell you what the first ninety days look like.