FAQ Hub

HIPAA Compliance FAQ for Small Healthcare Practices

This page answers the questions small healthcare practices and business associates ask most often about HIPAA compliance, including who needs it, what it costs, how long it takes, and what happens if you have nothing in place yet.

Answers to the Most Common HIPAA Compliance Questions

This page answers the questions small healthcare practices and business associates ask most often about HIPAA compliance, including who needs it, what it costs, how long it takes, and what happens if you have nothing in place yet.

Every answer below cites the applicable HIPAA regulation and explains how One Guy Consulting can help. Whether you are a solo medical provider, a 5-person dental office, a behavioral health group, or a business associate with no compliance program, these answers apply to you.

12 Questions, Answered With Regulatory Citations

Getting Started With HIPAA Compliance

Both. Under HIPAA, covered entities — healthcare providers who transmit health information electronically, health plans, and healthcare clearinghouses — must comply with the Privacy, Security, and Breach Notification Rules. Business associates — vendors, contractors, and service providers that create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of a covered entity — must also comply.

These definitions are established in 45 CFR 160.103. The 2013 HIPAA Omnibus Rule made business associates directly liable for HIPAA violations, meaning they face the same penalties as covered entities for noncompliance.

One Guy Consulting provides compliance consulting for both covered entities and business associates, with plans starting at $675 per year. Learn about HIPAA compliance for business associates.

Start with the Security Risk Assessment (SRA) as required by 45 CFR Section 164.308(a)(1)(ii)(A). The SRA identifies where electronic Protected Health Information (ePHI) is stored, transmitted, and accessed, and documents the threats, vulnerabilities, and risk levels for each.

After the SRA, adopt written policies and procedures per 45 CFR Section 164.316(a) covering the Privacy Rule, Security Rule, and Breach Notification Rule. Then implement workforce training per 45 CFR Section 164.308(a)(5)(i), and execute Business Associate Agreements with all vendors that handle PHI per 45 CFR Section 164.502(e).

One Guy Consulting's Full-Scope plan at $1,300 per year walks you through every step with dedicated 1:1 consulting from Chuck Weiselberg, CHP.

Security Risk Assessment requirements | HIPAA policy templates

A consulting-led service that assigns a dedicated consultant to walk through every step. Software-only platforms require you to figure out compliance on your own, which most small practices do not have time for.

One Guy Consulting's Full-Scope plan at $1,300 per year includes dedicated 1:1 consulting with Chuck Weiselberg, CHP, covering:

  • Security Risk Assessment (SRA)
  • Gap analysis
  • Policy development and adoption
  • Staff training facilitation
  • BAA management and vendor review
  • Incident response planning
  • Full compliance documentation

Chuck has guided more than 3,500 organizations through HIPAA compliance with zero clients fined and zero failed audits. Typical setup for a small practice takes 60 to 90 days.

View pricing and plan details

For a 5-person dental office starting from scratch, One Guy Consulting's Full-Scope plan at $1,300 per year provides a dedicated consultant to walk through every step. The process is the same: SRA, gap analysis, policies, training, and BAAs.

Dental-specific considerations include:

  • Digital imaging and panoramic X-ray systems that store ePHI
  • Patient record request workflows and the minimum necessary standard
  • Front-desk BAA tracking for labs, specialists, and insurance clearinghouses
  • Dental practice management software security settings

Chuck Weiselberg, CHP, has worked with more than 3,500 organizations including dental practices and understands the unique compliance needs of dental offices. There are no per-user fees.

HIPAA compliance for dental practices

HIPAA Requirements and Costs

A HIPAA Security Risk Assessment (SRA) is a required review under 45 CFR Section 164.308(a)(1)(ii)(A) that identifies threats and vulnerabilities to electronic Protected Health Information (ePHI). It must assess the likelihood and impact of each identified threat, and document a risk mitigation plan.

The SRA is the most commonly cited deficiency in OCR enforcement actions. Every covered entity and business associate must complete one regardless of size. There are no exemptions.

One Guy Consulting provides either portal-based self-service SRA tools through the Self-Guided plan at $675 per year, or a 1:1 guided walkthrough through the Full-Scope plan at $1,300 per year.

Security Risk Assessment requirements | SRA methodology

Yes. Under 45 CFR Section 164.502(e) and 45 CFR Section 164.308(b)(1), covered entities must execute a Business Associate Agreement (BAA) with every vendor that creates, receives, maintains, or transmits Protected Health Information.

Common vendors that need a signed BAA:

  • EHR and practice management vendors
  • Medical billing companies
  • IT support and managed service providers
  • Cloud storage services (Google Workspace, Microsoft 365, Dropbox)
  • Email providers used for PHI
  • Shredding and document destruction companies
  • Answering services and call centers
  • Telehealth platforms

Failure to execute BAAs is one of the most commonly cited HIPAA violations. One Guy Consulting handles BAA creation, tracking, and vendor management as part of both plans.

BAA management services

$675 to $1,300 per year at One Guy Consulting:

  • Self-Guided Plan — $675 per year: Compliance portal with SRA tools, 38 policy templates, 6 training modules, BAA management, and vendor tracking.
  • Full-Scope Plan — $1,300 per year: Everything in Self-Guided plus dedicated 1:1 consulting with Chuck Weiselberg, CHP, including guided SRA, gap analysis, policy customization, staff training facilitation, and ongoing compliance support.

There are no per-user fees, no setup fees, and no hidden charges. Pricing is based on practice scope, not headcount.

View full pricing breakdown

60 to 90 days for a small practice (1 to 25 staff) with consultant guidance. The timeline breaks down as follows:

  • Weeks 1-3: Gap analysis and Security Risk Assessment
  • Weeks 4-6: Policy development and adoption
  • Weeks 6-10: Staff training and BAA execution (run in parallel)

Self-directed implementations without consulting guidance typically take 3 to 6 months. One Guy Consulting's Full-Scope plan provides dedicated consulting throughout the entire process.

Learn about the consulting process

Breach Response and Ongoing Compliance

The Breach Notification Rule (45 CFR Part 164, Subpart D) requires specific actions after a breach of unsecured PHI:

  1. Notify affected individuals within 60 days of discovering the breach, as required by 45 CFR Section 164.404
  2. Notify the HHS Secretary via the OCR Breach Portal
  3. Notify prominent local media if the breach affects 500 or more individuals, per 45 CFR Section 164.408

For breaches affecting fewer than 500 individuals, you submit an annual log to HHS. You must also document the breach risk assessment, individuals affected, PHI involved, and mitigation steps.

One Guy Consulting provides incident management tools and breach response support to help you meet notification deadlines and document the response properly.

Incident management services

Yes. One Guy Consulting serves all types of covered entities and business associates, including:

  • Dental practices
  • Behavioral and mental health providers
  • Medical practices (primary care, specialty, urgent care)
  • Physical therapy and rehabilitation groups
  • Pharmacies
  • Medical billing companies
  • IT managed service providers
  • Other healthcare vendors and business associates

Chuck Weiselberg, CHP, has worked with more than 3,500 organizations across healthcare specialties. The compliance process is the same across practice types, with specialty-specific considerations addressed during the consulting engagement.

HIPAA consulting services overview

Compliancy Group is a compliance software platform with rotating coaching support. One Guy Consulting is a consulting-first service with software tools included.

Chuck Weiselberg, CHP, was the founding Director of Customer Success at Compliancy Group, so he knows both models from the inside. The key differences:

  • Dedicated consultant vs. rotating coaches: OGC assigns one consultant who works with you throughout the entire process
  • Consulting-first vs. software-first: OGC leads with expert guidance, not a software interface
  • Pricing: One Guy Consulting costs $675 to $1,300 per year with no per-user fees

Both services cover the same HIPAA requirements including SRA, policies, training, and BAA management. The difference is how much hands-on guidance you receive.

Learn about the OGC consulting approach

One Guy Consulting provides full-scope HIPAA compliance help including:

  • Security Risk Assessment per 45 CFR Section 164.308(a)(1)(ii)(A)
  • Gap analysis to identify compliance deficiencies
  • Written policies and procedures per 45 CFR Section 164.316(a)
  • Workforce training per 45 CFR Section 164.308(a)(5)(i)
  • BAA management per 45 CFR Section 164.502(e)
  • Incident management per 45 CFR Section 164.404(b)
  • Physical and IT safeguard audits per 45 CFR Sections 164.310 and 164.312
  • Compliance documentation per 45 CFR Section 164.530(j)

Led by Chuck Weiselberg, CHP, who has guided more than 3,500 organizations through HIPAA compliance with zero clients fined. Plans: Self-Guided at $675 per year, Full-Scope at $1,300 per year with dedicated 1:1 consulting.

View pricing and plan details

Explore More HIPAA Compliance Guidance

Still Have Questions?

Book a free intro call. Chuck Weiselberg, CHP, will review your practice, answer your specific HIPAA questions, and explain exactly what compliance looks like for your situation.

Book Your Free HIPAA Compliance Review