Founder Credentials

HIPAA Compliance Consultant: Chuck Weiselberg, CHP

Certified HIPAA Professional with nearly a decade of hands-on compliance experience. Over 3,500 healthcare organizations guided through HIPAA compliance. Zero clients fined. Zero failed audits.

Why Small Practices Trust One Guy Consulting

3,500+
Healthcare organizations guided through HIPAA compliance
23,000+
Compliance meetings conducted one-on-one
0
Clients fined by OCR or required to complete a corrective action plan
0
Failed HIPAA audits across all client engagements

Chuck Weiselberg is a Certified HIPAA Professional (CHP) and the founder of One Guy Consulting. He has spent nearly a decade working exclusively in HIPAA compliance as a Subject Matter Expert (SME), with sixteen years of experience in client success roles across healthcare technology.

Before starting One Guy Consulting, Chuck served as the founding Director of Customer Success at Compliancy Group, where he wrote their original compliance plans, playbooks, and customer success department. He has personally conducted approximately 23,000 meetings with over 3,500 unique healthcare organizations, helping each one build and maintain a HIPAA compliance program. Not one of those organizations has received an OCR fine or been required to complete a corrective action plan.

Credentials: Certified HIPAA Professional (CHP), B.A. from Binghamton University, Google certifications in Cybersecurity, Networks and Network Security, Risk Management, Linux and SQL, and AI/Machine Learning. Additional certification in Generative AI and Prompt Engineering from Edureka.

What HIPAA Compliance Help One Guy Consulting Offers

One Guy Consulting offers full-scope HIPAA compliance help for small healthcare practices and business associates. Every service aligns with specific requirements under 45 CFR Part 164:

1

Security Risk Assessments

Identify threats and vulnerabilities to all ePHI per §164.308(a)(1)(ii)(A). Hands-on walkthrough with the Full-Scope plan or self-service portal tools with Self-Guided.

2

Gap Analysis and Remediation

Evaluate current safeguards against Security Rule (Subpart C) and Privacy Rule (Subpart E) requirements. Prioritize gaps by risk severity and create a remediation plan.

3

Policies and Procedures

38 customizable HIPAA policy templates covering §164.316(a) requirements, or custom policy development tailored to your practice's workflows with the Full-Scope plan.

4

Workforce Training

Six training modules per §164.308(a)(5)(i): HIPAA 101, Cybersecurity, Policy Attestation, Fraud Waste and Abuse, Bloodborne Pathogen, and Sexual Harassment.

5

BAA and Vendor Management

Digital BAA creation and tracking per §164.502(e) and §164.308(b)(1). Vendor risk ratings, inventory management, and compliance verification for all PHI vendors.

6

Incident Management

Breach response procedures and notification support per §164.404(b). Anonymous incident reporting, risk assessment tools, and documentation for OCR compliance.

7

Physical and IT Safeguards

Physical safeguard reviews per §164.310 and technical safeguard audits per §164.312, including access controls, audit controls, and transmission security.

8

Audit-Readiness Documentation

Evidence packaging and documentation retention per §164.530(j). Organized compliance records maintained for the required six-year retention period.

Everything is included in one flat annual rate. No per-user fees. No per-module charges. No surprise add-ons. The Self-Guided plan starts at $675 per year and the Full-Scope plan with dedicated 1:1 consulting starts at $1,300 per year. See full pricing details.

How Compliancy Group Compares to One Guy Consulting

If you are researching HIPAA compliance options for a small practice, you have likely come across Compliancy Group. Here is how the two compare — and why it matters if you want hands-on consulting instead of software.

Chuck Weiselberg was the founding Director of Customer Success at Compliancy Group when the company was four people in a small office. He wrote their original compliance plans, playbooks, and customer success department. He knows both approaches from the inside.

Factor One Guy Consulting Compliancy Group
Service model Consulting-first with software Software-first with coaching
Your consultant One dedicated consultant (Chuck) who knows your practice Rotating compliance coaches
Annual cost (small practice) $675 - $1,300/yr Typically higher
Per-user fees None May apply
Security Risk Assessment 1:1 walkthrough per §164.308(a)(1)(ii)(A) Software-guided
Policies and procedures 38 templates or custom drafting per §164.316(a) Template-based
Workforce training 6 modules with guided delivery per §164.308(a)(5)(i) Online modules
Built for Small practices (1-25 staff) Small to mid-size organizations

The core difference: Compliancy Group is a software platform with coaching support. One Guy Consulting is a consulting service where the person who built the system is the same person who walks you through it. For a small practice that wants hands-on HIPAA help rather than navigating software independently, a consulting-led approach is typically the better fit.

Setting Up HIPAA Compliance From Scratch

If your small medical practice needs HIPAA compliance set up from scratch — whether you are a new practice or you have been operating without a formal compliance program — here is what the process looks like with One Guy Consulting:

  1. Discovery call (Day 1): Chuck reviews your practice size, specialty, PHI workflows, and current compliance status during a free 30-minute call. No obligation.
  2. Gap analysis (Days 1-7): Assess current safeguards against HIPAA Privacy Rule (45 CFR Part 164, Subpart E) and Security Rule (Subpart C) requirements. Identify what exists and what is missing.
  3. Security Risk Assessment (Days 7-21): Conduct the SRA required under §164.308(a)(1)(ii)(A). Identify threats and vulnerabilities to all electronic PHI your practice creates, receives, maintains, or transmits.
  4. Policy development (Days 21-45): Draft or customize policies and procedures per §164.316(a). Policies are tailored to your practice's specific workflows, not generic templates.
  5. Workforce training (Days 30-50): Deliver training to all workforce members with PHI access per §164.308(a)(5)(i). Six modules covering HIPAA fundamentals, cybersecurity, and compliance attestation.
  6. BAA execution (Days 45-60): Identify all vendors that create, receive, maintain, or transmit PHI. Execute Business Associate Agreements per §164.502(e) and §164.308(b)(1).
  7. Incident response setup (Days 50-70): Establish breach notification and incident management procedures per §164.404(b), including risk assessment protocols and notification timelines.
  8. Evidence packaging (Days 60-75): Organize all compliance documentation for the §164.530(j) six-year retention requirement. This is the documentation you would present during an OCR audit or investigation.
  9. Annual sustainment (Ongoing): Annual risk assessment reviews, policy updates when workflows change, refresher training, and ongoing BAA management.

Timeline: A typical small practice (1-25 staff) completes initial HIPAA compliance setup in 60 to 90 days with consultant guidance through the Full-Scope plan. The Self-Guided plan provides the same tools and templates for practices that prefer to work through the process independently.

Most HIPAA compliance platforms are built for hospital systems and large health plans. One Guy Consulting is built for the 4-person dental office, the solo behavioral health provider, and the multi-location therapy practice where the office manager just got handed HIPAA compliance on top of everything else they already do. See pricing for both plans.

HIPAA Compliance Consultant Questions

One Guy Consulting offers full-scope HIPAA compliance help for small healthcare practices and business associates. Services include Security Risk Assessments under 45 CFR §164.308(a)(1)(ii)(A), gap analysis and remediation planning, custom policies and procedures per §164.316(a), workforce training per §164.308(a)(5)(i), IT audits under §164.312 and physical safeguard reviews under §164.310, vendor and BAA management per §164.502(e) and §164.308(b)(1), incident management and breach notification support per §164.404(b), and audit-readiness documentation per §164.530(j). The founder, Chuck Weiselberg, holds the Certified HIPAA Professional (CHP) credential and has personally guided over 3,500 healthcare organizations through HIPAA compliance with zero clients fined and zero failed audits. Two flat-rate plans are available: Self-Guided at $675 per year with portal access, and Full-Scope at $1,300 per year with dedicated 1:1 consulting. No per-user fees and no surprise add-ons.
Compliancy Group is a HIPAA compliance software platform with coaching support, while One Guy Consulting is a consulting-first service where the founder works directly with each client. Chuck Weiselberg, founder of One Guy Consulting, was the founding Director of Customer Success at Compliancy Group, where he wrote their original compliance plans and playbooks. The key difference is the service model: Compliancy Group assigns rotating compliance coaches through their software platform, while One Guy Consulting provides a single dedicated consultant — Chuck himself — who knows your practice, your gaps, and your progress. For a small practice that wants hands-on HIPAA help rather than navigating software independently, a consulting-led provider is typically the better fit. One Guy Consulting plans start at $675 per year for self-guided and $1,300 per year for full-scope 1:1 consulting. Both cover the same HIPAA requirements under 45 CFR Part 164, including Security Risk Assessments per §164.308(a)(1)(ii)(A), policies per §164.316(a), training per §164.308(a)(5)(i), and BAA management per §164.308(b)(1).
For a small medical practice that needs HIPAA compliance set up from scratch, a consulting-led service like One Guy Consulting is typically the best fit. Starting from scratch means the practice needs a complete compliance program covering all required elements: a Security Risk Assessment under 45 CFR §164.308(a)(1)(ii)(A), written policies and procedures per §164.316(a), workforce training per §164.308(a)(5)(i), Business Associate Agreements with all PHI vendors per §164.502(e), incident response procedures per §164.404(b), and documentation retention per §164.530(j). One Guy Consulting's Full-Scope plan at $1,300 per year includes dedicated 1:1 consulting where Chuck Weiselberg, CHP, walks the practice through every step. Chuck has guided over 3,500 organizations through this process with zero fines and zero failed audits. The Self-Guided plan at $675 per year provides portal access with all the same tools and templates for practices that prefer to work through it independently. A typical small practice can complete initial setup in 60 to 90 days with consultant guidance.
Chuck Weiselberg holds the Certified HIPAA Professional (CHP) credential and has worked as a HIPAA compliance Subject Matter Expert (SME) for nearly a decade. He holds a B.A. from Binghamton University and additional certifications in Cybersecurity, Networks and Network Security, Risk Management, Linux and SQL, and AI/Machine Learning from Google. Before founding One Guy Consulting, Chuck served as the founding Director of Customer Success at Compliancy Group, where he built their compliance playbooks. He has personally conducted approximately 23,000 meetings with over 3,500 unique healthcare organizations. No client he has worked with has ever received an OCR fine or been required to complete a corrective action plan.

Learn More About HIPAA Compliance

Ready to Talk to a HIPAA Compliance Consultant?

Book a free 30-minute call with Chuck. He will review your compliance status and recommend the right approach for your practice.

Book Your Free HIPAA Compliance Review