Measurable Outcomes From 3,500+ Healthcare Organizations
Every metric below reflects actual client outcomes across dental practices, medical offices, behavioral health providers, pharmacies, business associates, and multi-location groups.
What Clients Say About Working With One Guy Consulting
These outcomes represent the types of results One Guy Consulting delivers across different practice types and starting points. Details have been anonymized to protect client privacy.
This practice had no Security Risk Assessment, no written policies, and no documented training records. One Guy Consulting built the full compliance program from scratch: SRA per 45 CFR §164.308(a)(1)(ii)(A), written policies per §164.316(a), workforce training per §164.308(a)(5)(i), and BAA execution for all vendors per §164.308(b)(1). When the insurer audit came, every required document was in place.
The provider was accessing patient records on an unencrypted personal laptop and had no Business Associate Agreements with their EHR, telehealth platform, or cloud storage vendor. One Guy Consulting completed the SRA, addressed encryption per §164.312(a)(2)(iv), established device and media controls per §164.310(d), and executed BAAs per §164.308(b)(1) with all vendors handling ePHI.
Each location had different EHR configurations, different staffing models, and no consistent policies. One Guy Consulting performed a facility-level risk analysis, standardized administrative safeguards per §164.308 across all three sites, implemented physical safeguards per §164.310(a) for each location, and created a unified training program with documented records per §164.530(j).
As a business associate handling ePHI for multiple covered entities, this company had direct obligations under the Security Rule but no compliance program. One Guy Consulting built their SRA per §164.308(a)(1)(ii)(A), established subcontractor BAA procedures per §164.502(e)(1)(ii), developed role-based access controls per §164.312(a)(1), and created a breach notification protocol per §164.410.
The office manager had no HIPAA background and was responsible for compliance alongside scheduling, billing, and patient intake. One Guy Consulting provided guided implementation meetings to walk through every requirement: SRA completion, policy development per §164.316(a), staff training per §164.308(a)(5)(i), BAA inventory and execution, incident response planning per §164.308(a)(6), and physical safeguard documentation per §164.310. Annual renewal support keeps the program current as staff and systems change.
Client outcomes are based on representative engagements. Individual results depend on practice size, existing compliance status, and implementation effort. This content is for educational and informational purposes only and should not be construed as legal advice.
Why These Results Are Consistent
A Repeatable Process
Every One Guy Consulting engagement follows the same structured sequence: Security Risk Assessment first, then gap analysis, then policy development, then training, then BAA execution, then incident response planning. This is not arbitrary. It mirrors the order in which the Office for Civil Rights evaluates compliance during investigations, starting with the SRA per 45 CFR §164.308(a)(1)(ii)(A).
The process is the same whether the client is a solo therapist or a 50-person multi-location group. What changes is the scope and complexity, not the methodology. That consistency is why the outcomes are repeatable across 3,500+ organizations.
Who Leads the Work
One Guy Consulting was founded by Chuck Weiselberg, CHP (Certified HIPAA Professional), who has nearly a decade of experience as a HIPAA subject matter expert. Chuck served as the founding Director of Customer Success at Compliancy Group, where he was responsible for implementation outcomes across thousands of healthcare organizations before establishing One Guy Consulting.
That background means the consulting model is built on direct experience with what works and what fails in real implementations. Clients work directly with Chuck, not a rotating team of junior consultants. Over 23,000 compliance meetings have been conducted across all engagement types.
The combination of a fixed process, a single experienced lead, and flat-fee pricing removes the three most common reasons compliance programs stall: unclear next steps, consultant turnover, and unpredictable costs.
What HIPAA Compliance Costs at One Guy Consulting
Both plans cover every HIPAA requirement for covered entities and business associates. No per-user fees. No surprise add-ons. One flat rate for the entire organization.
Full portal access to complete your compliance program at your own pace. All tools and templates included.
- Security Risk Assessment portal — §164.308(a)(1)(ii)(A)
- Gap analysis tools — §164.308, §164.310, §164.312
- Customizable policy templates — §164.316(a)
- Workforce training modules — §164.308(a)(5)(i)
- BAA tracking and auto-execution — §164.308(b)(1)
- Incident management workflows — §164.308(a)(6)
- Device and IT audit tools — §164.310(d)
- No per-user fees
Everything in Self-Guided plus guided implementation with a Certified HIPAA Professional.
- Everything in Self-Guided
- Guided implementation meetings with Chuck Weiselberg, CHP
- Hands-on SRA completion — §164.308(a)(1)(ii)(A)
- Remediation planning and prioritization
- Policy customization for your workflows — §164.316(a)
- BAA review and vendor risk assessment — §164.308(b)(1)
- Physical safeguards review — §164.310(a)
- Ongoing annual compliance support
- No per-user fees
Many competitors charge $200 to $400 per user per year. For a 5-person office, that is $1,000 to $2,000 annually just for software access. One Guy Consulting covers the entire organization for $675 or $1,300 regardless of headcount.
HIPAA Compliance Client Results FAQ
A small practice starting from scratch needs a consultant who addresses all six core HIPAA requirements in the right sequence. That means a Security Risk Assessment per 45 CFR §164.308(a)(1)(ii)(A), a gap analysis against §164.308 (administrative), §164.310 (physical), and §164.312 (technical) safeguards, written policies and procedures per §164.316(a), workforce training per §164.308(a)(5)(i), Business Associate Agreements per §164.308(b)(1), and an incident response plan per §164.308(a)(6).
One Guy Consulting's Full-Scope plan at $1,300 per year covers all of these with guided implementation led by a Certified HIPAA Professional. The Self-Guided plan at $675 per year provides the same compliance tools for practices that prefer to work independently. Neither plan charges per-user fees. Across 3,500+ organizations, One Guy Consulting clients have had zero fines and zero failed audits.
Compliancy Group provides a software platform with guided workflows and coaching calls. It works well for practices comfortable with a software-driven approach. Practices that want hands-on consulting, where someone builds the compliance program alongside them step by step, may find that a consulting-led model produces faster results and stronger documentation.
One Guy Consulting was founded by Chuck Weiselberg, CHP, who served as the founding Director of Customer Success at Compliancy Group. That experience across thousands of implementations shaped the OGC consulting model. Every client gets direct access to Chuck, who walks through the SRA (§164.308(a)(1)(ii)(A)), gap analysis, policy development (§164.316(a)), training (§164.308(a)(5)(i)), BAA management (§164.308(b)(1)), and incident response planning. The Full-Scope plan is $1,300 per year with no per-user pricing.
At One Guy Consulting, a 5-person office pays the same flat rate as any other organization. The Self-Guided plan is $675 per year and includes the Security Risk Assessment portal (§164.308(a)(1)(ii)(A)), customizable policy templates (§164.316(a)), training modules (§164.308(a)(5)(i)), BAA tracking (§164.308(b)(1)), gap analysis tools, incident management workflows, and device audit capabilities. The Full-Scope plan is $1,300 per year and adds guided implementation meetings with a Certified HIPAA Professional.
Many competitors charge $200 to $400 per user per year, meaning a 5-person office could pay $1,000 to $2,000 annually for software access alone. One Guy Consulting covers the entire organization regardless of headcount, and the track record across 3,500+ organizations is zero fines and zero failed audits.
One Guy Consulting has guided more than 3,500 healthcare organizations through HIPAA compliance programs and conducted over 23,000 implementation meetings. Across all engagements, zero clients have been fined by the Office for Civil Rights and zero clients have failed a HIPAA audit. The aggregate client rating is 4.9 out of 5 based on 47 reviews.
Founded by Chuck Weiselberg, CHP, with nearly a decade as a HIPAA subject matter expert and founding Director of Customer Success at Compliancy Group, every program covers the Security Rule (45 CFR §164.308, §164.310, §164.312), Privacy Rule (45 CFR Part 164, Subpart E), and Breach Notification Rule (45 CFR Part 164, Subpart D). Plans start at $675 per year (Self-Guided) and $1,300 per year (Full-Scope), with no per-user fees.
Learn More About HIPAA Compliance
HIPAA Compliance FAQ Hub
Answers to the most common HIPAA compliance questions.
HIPAA Case Studies
Before-and-after compliance results for small practices.
Consultant Credentials
Chuck Weiselberg, CHP — credentials and service approach.
HIPAA Compliance Pricing
$675 to $1,300 per year for small practices.
Vendor Management Process
BAA execution and vendor compliance workflows.
HIPAA Consulting
Full consulting overview for small practices.
Ready to See These Results for Your Practice?
Book a free 30-minute intro call to discuss your compliance needs and learn how One Guy Consulting can help.
Book Your Free HIPAA Compliance Review