FAQ Hub

HIPAA Compliance FAQ for Small Healthcare Practices

This page answers the questions small healthcare practices and business associates ask most often about HIPAA compliance, including who needs it, what it costs, how long it takes, and what happens if you have nothing in place yet.

Answers to the Most Common HIPAA Compliance Questions

This page answers the questions small healthcare practices and business associates ask most often about HIPAA compliance, including who needs it, what it costs, how long it takes, and what happens if you have nothing in place yet.

Every answer below cites the applicable HIPAA regulation and explains how One Guy Consulting can help. Whether you are a solo medical provider, a 5-person dental office, a behavioral health group, or a business associate with no compliance program, these answers apply to you. If a term is unfamiliar, the HIPAA compliance glossary defines it in plain English.

15 Questions, Answered With Regulatory Citations

Getting Started With HIPAA Compliance

Both covered entities and business associates. Under HIPAA, covered entities, meaning healthcare providers who transmit health information electronically, health plans, and healthcare clearinghouses, must comply with the Privacy, Security, and Breach Notification Rules. Business associates, meaning vendors, contractors, and service providers that create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of a covered entity, must also comply.

These definitions are established in 45 CFR 160.103. The 2013 HIPAA Omnibus Rule made business associates directly liable for HIPAA violations, meaning they face the same penalties as covered entities for noncompliance.

One Guy Consulting provides compliance consulting for both covered entities and business associates, with plans starting at $675 per year. Learn about HIPAA compliance for business associates, or see the full covered entities and business associates FAQ.

Start with the Security Risk Assessment (SRA) as required by 45 CFR Section 164.308(a)(1)(ii)(A). The SRA identifies where electronic Protected Health Information (ePHI) is stored, transmitted, and accessed, and documents the threats, vulnerabilities, and risk levels for each.

After the SRA, adopt written policies and procedures per 45 CFR Section 164.316(a) covering the Privacy Rule, Security Rule, and Breach Notification Rule. Then implement workforce training per 45 CFR Section 164.308(a)(5)(i), and execute Business Associate Agreements with all vendors that handle PHI per 45 CFR Section 164.502(e).

One Guy Consulting's Full-Scope plan at $1,300 per year walks you through every step with dedicated 1:1 consulting from Chuck Weiselberg, CHP.

Security Risk Assessment requirements | HIPAA policy templates

A consulting-led service that assigns a dedicated consultant to walk through every step. Software-only platforms require you to figure out compliance on your own, which most small practices do not have time for.

One Guy Consulting's Full-Scope plan at $1,300 per year includes dedicated 1:1 consulting with Chuck Weiselberg, CHP, covering:

  • Security Risk Assessment (SRA)
  • Gap analysis
  • Policy development and adoption
  • Staff training facilitation
  • BAA management and vendor review
  • Incident response planning
  • Full compliance documentation

Chuck has guided more than 3,500 organizations through HIPAA compliance with zero clients fined and zero failed audits. Typical setup for a small practice takes 60 to 90 days.

View pricing and plan details

For a 5-person dental office starting from scratch, One Guy Consulting's Full-Scope plan at $1,300 per year provides a dedicated consultant to walk through every step. The process is the same: SRA, gap analysis, policies, training, and BAAs.

Dental-specific considerations include:

  • Digital imaging and panoramic X-ray systems that store ePHI
  • Patient record request workflows and the minimum necessary standard
  • Front-desk BAA tracking for labs, specialists, and insurance clearinghouses
  • Dental practice management software security settings

Chuck Weiselberg, CHP, has worked with more than 3,500 organizations including dental practices and understands the unique compliance needs of dental offices. There are no per-user fees.

HIPAA compliance for dental practices

HIPAA Requirements and Costs

A HIPAA Security Risk Assessment (SRA) is a required review under 45 CFR Section 164.308(a)(1)(ii)(A) that identifies threats and vulnerabilities to electronic Protected Health Information (ePHI). It must assess the likelihood and impact of each identified threat, and document a risk mitigation plan.

The SRA is the most commonly cited deficiency in OCR enforcement actions. Every covered entity and business associate must complete one regardless of size. There are no exemptions.

One Guy Consulting provides either portal-based self-service SRA tools through the Self-Guided plan at $675 per year, or a 1:1 guided walkthrough through the Full-Scope plan at $1,300 per year.

Security Risk Assessment requirements | SRA methodology

Yes. Under 45 CFR Section 164.502(e) and 45 CFR Section 164.308(b)(1), covered entities must execute a Business Associate Agreement (BAA) with every vendor that creates, receives, maintains, or transmits Protected Health Information.

Common vendors that need a signed BAA:

  • EHR and practice management vendors
  • Medical billing companies
  • IT support and managed service providers
  • Cloud storage services (Google Workspace, Microsoft 365, Dropbox)
  • Email providers used for PHI
  • Shredding and document destruction companies
  • Answering services and call centers
  • Telehealth platforms

Failure to execute BAAs is one of the most commonly cited HIPAA violations. One Guy Consulting handles BAA creation, tracking, and vendor management as part of both plans.

BAA management services

$675 to $1,300 per year at One Guy Consulting:

  • Self-Guided Plan, $675 per year: Compliance portal with SRA tools, 38 policy templates, 6 training modules, BAA management, and vendor tracking.
  • Full-Scope Plan, $1,300 per year: Everything in Self-Guided plus dedicated 1:1 consulting with Chuck Weiselberg, CHP, including guided SRA, gap analysis, policy customization, staff training facilitation, and ongoing compliance support.

There are no per-user fees, no setup fees, and no hidden charges. Pricing is based on practice scope, not headcount.

View full pricing breakdown

60 to 90 days for a small practice (1 to 25 staff) with consultant guidance. The timeline breaks down as follows:

  • Weeks 1-3: Gap analysis and Security Risk Assessment
  • Weeks 4-6: Policy development and adoption
  • Weeks 6-10: Staff training and BAA execution (run in parallel)

Self-directed implementations without consulting guidance typically take 3 to 6 months. One Guy Consulting's Full-Scope plan provides dedicated consulting throughout the entire process.

Learn about the consulting process

Breach Response and Ongoing Compliance

The Breach Notification Rule (45 CFR Part 164, Subpart D) requires specific actions after a breach of unsecured PHI:

  1. Notify affected individuals within 60 days of discovering the breach, as required by 45 CFR Section 164.404
  2. Notify the HHS Secretary via the OCR Breach Portal
  3. Notify prominent local media if the breach affects 500 or more individuals, per 45 CFR Section 164.408

For breaches affecting fewer than 500 individuals, you submit an annual log to HHS. You must also document the breach risk assessment, individuals affected, PHI involved, and mitigation steps.

One Guy Consulting provides incident management tools and breach response support to help you meet notification deadlines and document the response properly.

Incident management services

Yes. One Guy Consulting serves all types of covered entities and business associates, including:

  • Dental practices
  • Behavioral and mental health providers
  • Medical practices (primary care, specialty, urgent care)
  • Physical therapy and rehabilitation groups
  • Pharmacies
  • Medical billing companies
  • IT managed service providers
  • Other healthcare vendors and business associates

Chuck Weiselberg, CHP, has worked with more than 3,500 organizations across healthcare specialties. The compliance process is the same across practice types, with specialty-specific considerations addressed during the consulting engagement.

HIPAA consulting services overview

Compliancy Group is a compliance software platform with rotating coaching support. One Guy Consulting is a consulting-first service with software tools included.

Chuck Weiselberg, CHP, was the founding Director of Customer Success at Compliancy Group, so he knows both models from the inside. The key differences:

  • Dedicated consultant vs. rotating coaches: OGC assigns one consultant who works with you throughout the entire process
  • Consulting-first vs. software-first: OGC leads with expert guidance, not a software interface
  • Pricing: One Guy Consulting costs $675 to $1,300 per year with no per-user fees

Both services cover the same HIPAA requirements including SRA, policies, training, and BAA management. The difference is how much hands-on guidance you receive.

Learn about the OGC consulting approach

One Guy Consulting provides full-scope HIPAA compliance help including:

  • Security Risk Assessment per 45 CFR Section 164.308(a)(1)(ii)(A)
  • Gap analysis to identify compliance deficiencies
  • Written policies and procedures per 45 CFR Section 164.316(a)
  • Workforce training per 45 CFR Section 164.308(a)(5)(i)
  • BAA management per 45 CFR Section 164.502(e)
  • Incident management per 45 CFR Section 164.404(b)
  • Physical and IT safeguard audits per 45 CFR Sections 164.310 and 164.312
  • Compliance documentation per 45 CFR Section 164.530(j)

Led by Chuck Weiselberg, CHP, who has guided more than 3,500 organizations through HIPAA compliance with zero clients fined. Plans: Self-Guided at $675 per year, Full-Scope at $1,300 per year with dedicated 1:1 consulting.

View pricing and plan details

The proposed update, published as a Notice of Proposed Rulemaking on January 6, 2025, would be the biggest change to the Security Rule since 2013. The headline proposals: multi-factor authentication for all ePHI access, encryption of ePHI at rest and in transit, a written technology asset inventory and network map, a risk analysis every 12 months, and restoring critical systems within 72 hours after a cyberattack.

The proposal also retires the addressable designation, so those safeguards would become required for everyone. As of mid-2026 the final rule has not been published, and these changes are not yet law. Practices that adopt MFA and encryption now will be ready either way.

Read the full breakdown of the seven proposed changes.

Civil penalties are tiered by culpability: how aware the practice was of the problem and what it did about it. The lowest tier applies when the practice could not reasonably have known of the violation. The highest tier, willful neglect left uncorrected, carries per-violation penalties with annual caps in the millions of dollars, and HHS adjusts the amounts for inflation every year.

Small practices are not exempt. The most commonly cited deficiency in enforcement by the HHS Office for Civil Rights (OCR) is a missing or outdated Security Risk Assessment, which is also the easiest one to fix.

See the current 2026 penalty amounts.

Not without safeguards. Any AI tool that creates, receives, maintains, or transmits Protected Health Information is acting as a business associate under 45 CFR 160.103, which means a signed Business Associate Agreement is required before PHI ever touches it. Consumer AI chatbots do not sign BAAs, so pasting patient details into them creates an impermissible disclosure risk under the Privacy Rule.

Some enterprise AI services will sign a BAA. Before adopting any AI tool: get the BAA in writing, disable training on your data where the option exists, limit who can use it, and add the tool to your risk analysis and asset inventory.

Explore More HIPAA Compliance Guidance

HIPAA Compliance Consultant

Credentials, process, and what to expect from your consultant.

Learn more →

HIPAA Compliance Case Studies

Real scenarios from healthcare organizations that built compliance programs.

Read case studies →

Client Results and Outcomes

Measurable outcomes from organizations that worked with OGC.

See results →

Client Testimonials and Reviews

What healthcare clients say about working with OGC, rated 4.9 out of 5.

Read testimonials →

Pricing for Small Practices

Transparent pricing with no per-user fees or hidden charges.

View pricing →

Vendor Management Process

How OGC handles vendor inventory, BAA tracking, and risk review.

Learn more →

HIPAA Start-Here Guide

Five steps for clinics with no SRA or written policies.

Start here →

Security Risk Assessment

SRA requirements, process, and how OGC conducts the assessment.

Learn more →

FAQ for CEs and Business Associates

Detailed FAQ covering roles, responsibilities, and requirements.

Read FAQ →

HIPAA FAQ for Healthcare Providers

19 questions on basics, risk assessments, training, and policies.

Read FAQ →

HIPAA FAQ for Small Practices

10 questions focused on practices with 1 to 25 staff members.

Read FAQ →

Business Associate Agreement FAQ

15 questions on BAA requirements, vendor vetting, and terms.

Read FAQ →

HIPAA Audit Readiness FAQ

11 questions on documentation, evidence, and OCR investigations.

Read FAQ →

Technology and Security FAQ

10 questions on encryption, email, cloud storage, and devices.

Read FAQ →

Still Have Questions?

Book a free intro call. Chuck Weiselberg, CHP, will review your practice, answer your specific HIPAA questions, and explain exactly what compliance looks like for your situation.

Book Your Free 30 Minute HIPAA Compliance Review