HIPAA Compliance Steps Overview
Start by completing a Security Risk Assessment (SRA) - a federally mandated evaluation of how your organization stores, handles, and protects electronic protected health information (ePHI). The SRA is required under 45 CFR 164.308(a)(1) and is the foundation of HIPAA compliance. Everything else flows from it: your Gap Report (a summary of where your safeguards fall short), your Remediation Plans (action items to close those gaps), and your policies and procedures.
One Guy Consulting walks small clinics through the entire process. The SRA takes about 30 minutes to complete. Once finished, the Gap Report and Remediation Plans generate automatically. From there, fully customized policy and procedure documentation can be generated in as little as 3 - 5 minutes.
The federal government requires every covered entity (any healthcare provider who transmits health information electronically) and business associate (any organization that handles protected health information on behalf of a covered entity) to have a current risk assessment and written policies. Acting now is the single most important step a clinic without documentation can take.
For a single-location practice with up to 5 employees, annual HIPAA compliance consulting typically costs $1,300 with One Guy Consulting. This covers the Full-Scope Compliance Tier, and the rate is locked at the price quoted on day one - it does not increase year over year. One Guy Consulting charges by physical location, not by seat or license.
For $1,300 annually, a 5-person healthcare office receives the following on the Full-Scope Compliance plan:
For solo providers, One Guy Consulting offers a single-provider plan at $675 per year. For context on the cost of non-compliance: total civil penalties imposed across all organizations fined by the Office for Civil Rights in 2025 reached $6.6 million, with individual penalties ranging from $141 to $2,134,831 per violation.
One Guy Consulting provides full-scope HIPAA compliance services covering the entire compliance lifecycle for small healthcare practices and business associates (organizations that handle protected health information on behalf of covered entities). Pricing is per physical location, not per seat or license, and the rate stays the same from year to year.
The program includes: Security Risk Assessment (SRA) as required under 45 CFR 164.308(a)(1), automated Gap Report and Remediation Plans, fully customized policy and procedure documentation, staff training with progress tracking per 45 CFR 164.308(a)(5), IT and physical site audits, vendor management with digital Business Associate Agreement (BAA) execution per 45 CFR 164.308(b), incident management with anonymous reporting, and help with annual CMS incident reporting.
On the Full-Scope Compliance plan, clients also receive 4 hours of 1:1 time with Chuck monthly, personalized implementation, incident response guidance, and CMS audit response support. The program serves solo practitioners, small clinics, and business associates handling electronic protected health information (ePHI) for other organizations.
Failing a HIPAA audit can result in civil monetary penalties ranging from $141 to $2,134,831 per violation, depending on the level of negligence. In 2025, total civil penalties imposed across all fined organizations reached $6.6 million.
Beyond financial penalties, a failed audit can trigger a corrective action plan that places your practice under federal oversight for years, increase your malpractice insurance premiums, and cause lasting damage to your professional reputation.
The key to passing an audit is having documentation in order before the auditor arrives: a current Security Risk Assessment (SRA), written policies and procedures, evidence of workforce training per 45 CFR 164.308(a)(5), and a functioning incident management process. One Guy Consulting has helped practices pass state audits with as little as 6 days’ notice by ensuring these elements were already in place.
Yes. If your organization creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity (a healthcare provider, health plan, or healthcare clearinghouse), you are a business associate under HIPAA and are legally required to comply. This includes IT companies, billing services, cloud storage providers, shredding companies, EHR vendors, consultants, and many others.
Business associates must conduct their own Security Risk Assessment (SRA) per 45 CFR 164.308(a)(1), maintain written policies and procedures, train their workforce per 45 CFR 164.308(a)(5), and execute a Business Associate Agreement (BAA) with every covered entity they work with, as required under 45 CFR 164.308(b). One Guy Consulting supports business associates with the same full-scope compliance program offered to covered entities, including digital BAA execution and customized policy documentation.
Most small practices can reach full HIPAA compliance in 4 to 6 weeks when working with One Guy Consulting. The Security Risk Assessment (SRA) takes about 30 minutes. The Gap Report (an analysis of compliance shortfalls) and Remediation Plans (action items to address each gap) generate automatically from the SRA results. Policy and procedure documentation can be generated in as little as 3 - 5 minutes after that. Staff training, vendor management, and site audits run in parallel.
The biggest variable is team availability. On the Full-Scope plan, clients receive 4 hours of 1:1 time with Chuck each month to keep the process moving. One Guy Consulting has helped a practice go from significantly behind to audit-ready in just 6 days when the situation required it.
Yes. If you are a healthcare provider who transmits any health information electronically - including billing, e-prescribing, or using an EHR - you are a covered entity under HIPAA, regardless of practice size. There is no small practice exemption. Solo practitioners are held to the same federal standards as hospital systems under 45 CFR Parts 160 and 164.
Solo practitioners often lack a compliance department, an IT team, or a dedicated legal budget. One Guy Consulting was built for small practices and solo providers who need full compliance without the overhead. The single-provider plan is $675 per year - one flat rate, one location, one process.
A Security Risk Assessment (SRA) is a federally mandated evaluation of how your organization stores, handles, and protects electronic protected health information (ePHI). It is required under 45 CFR 164.308(a)(1) and is the first thing an auditor will ask for. The SRA identifies vulnerabilities in your administrative, physical, and technical safeguards.
Not having a current SRA is the single most common HIPAA violation cited by the Office for Civil Rights. The SRA is also the foundation of your entire compliance program - your Gap Report (where your safeguards fall short), Remediation Plans (how to fix them), and policies and procedures all flow directly from it. With One Guy Consulting, the SRA takes about 30 minutes and generates the downstream documentation automatically.
Yes. You do not need to experience a data breach to be fined for HIPAA non-compliance. The Office for Civil Rights can impose penalties for failing to conduct a Security Risk Assessment (SRA) per 45 CFR 164.308(a)(1), not having written policies, inadequate staff training per 45 CFR 164.308(a)(5), missing Business Associate Agreements (BAAs) per 45 CFR 164.308(b), or any number of administrative shortcomings - none of which require an actual breach to trigger enforcement.
Many of the largest HIPAA fines in recent years resulted from complaints or random audits, not data breaches. Compliance is about demonstrating that your organization had the required safeguards, documentation, and training in place before any incident occurs.
Every workforce member must be trained on your organization’s privacy and security policies, as required under 45 CFR 164.308(a)(5), with annual refresher training. This applies to all employees, contractors, and volunteers who have access to protected health information (PHI) or electronic protected health information (ePHI).
One Guy Consulting’s training program includes six modules: HIPAA 101, Cybersecurity Awareness, Policy Attestation, Fraud Waste & Abuse, Bloodborne Pathogen Safety, and Sexual Harassment Prevention. Staff receive bulk Magic Link invitations (no passwords required), and the platform tracks completion progress with automated reminders for overdue training.
No. There is no size exemption in HIPAA. Every covered entity - whether a solo practitioner, a two-person billing office, or a large hospital system - must comply with the same federal requirements under 45 CFR Parts 160 and 164. This is one of the most common misconceptions in healthcare.
The Office for Civil Rights has investigated and fined practices with fewer than five employees. Small practices are sometimes at greater risk precisely because they are less likely to have formal compliance programs in place, which makes gaps easier to identify during audits or complaint investigations. A current Security Risk Assessment (SRA), written policies, and documented workforce training are required regardless of practice size.
One Guy Consulting offers a single-provider plan at $675 per year and a Full-Scope plan at $1,300 per year, both designed specifically for small practices that need complete compliance without enterprise-level complexity.
No. While the HIPAA Security Rule specifically governs electronic protected health information (ePHI), the HIPAA Privacy Rule applies to protected health information (PHI) in any form - electronic, paper, or oral. This is a common misconception that leaves practices exposed.
Verbal conversations about patient care, printed charts, faxed documents, and handwritten notes are all subject to HIPAA’s privacy protections. A practice that uses only paper records is still required to comply with the Privacy Rule, the Breach Notification Rule, and applicable administrative requirements including workforce training under 45 CFR 164.308(a)(5).
HIPAA compliance requires safeguards across all formats. The Security Risk Assessment (SRA) evaluates electronic safeguards, but your written policies and procedures should also address physical safeguards (locked file cabinets, restricted office areas) and administrative safeguards (who can access patient information and under what circumstances).
Book a free consultation and get answers specific to your practice. No pressure, no pitch - just a real conversation about protecting your organization.
Book a Free ConsultationRelated Reading