top of page

HIPAA Compliance Consultant or DIY? Take the Security Rule Quiz First

Nav
5 hours ago
6 min read

Take the HIPAA Security Readiness Quiz


Twenty-one questions, each tied to a specific section of the HIPAA Security Rule, marked Required, Addressable or Recommended. Answer honestly. The result is a readiness score and a gap list with the required items first.



The most expensive HIPAA consultant is the one you hire to find out things a five-minute quiz could have told you. The second most expensive is the one you didn't hire the year the Office for Civil Rights sent a letter. (There's a third, but that one comes with a lawyer.)


Here's the short answer. A HIPAA compliance consultant checks how your practice measures up against the HIPAA rules, runs or reviews your security risk analysis, writes the policies you're missing, and helps you close the gaps. Whether you need one depends on how much of the Security Rule you already have in place and documented. So find that out first.


hipaa compliance consultant

TL;DR: Take the 21-question quiz below. If it finds a missing risk analysis or several required safeguards you can't document, get outside help. If it mostly finds small gaps, you can probably close them yourself, and your IT provider can do most of the technical work.

I've spent 20+ years in IT, and healthcare clients usually ask the same thing first: "Are we compliant?" The honest answer is usually "partly, and you can't prove the rest." Here's a way to see which parts.


Medical office computer used to take a HIPAA security readiness quiz

What a HIPAA Compliance Consultant Actually Does


A good HIPAA compliance consultant usually covers five things:


  1. A gap assessment against the Privacy, Security and Breach Notification Rules

  2. The security risk analysis, or a review of the one you already have

  3. Policies and procedures, written for your practice, not downloaded from a template site

  4. Training, usually annual, with records you can show an auditor

  5. Vendor and business associate agreement review, so every vendor with patient data has a BAA


Here's what often gets missed: most consultants document. They don't implement. They'll tell you that laptops need encryption and audit logs need reviewing. Someone still has to turn on BitLocker, set up the logging and actually look at it every week. That someone is usually your IT provider.


So the real question isn't "consultant or not." It's which part of the work you need help with: figuring out what's required, or doing it.


Filing cabinet folders representing the HIPAA security risk analysis

The Risk Analysis Is Where Most Practices Fall Short


If you only fix one thing, fix this one. The very first implementation specification in the Security Rule, 45 CFR 164.308(a)(1)(ii)(A), requires you to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information."


OCR takes it seriously enough to run a whole enforcement program around it. In June 2026, a $450,000 settlement with a health plan became OCR's 14th Risk Analysis Initiative enforcement action and its 20th ransomware action, according to Nixon Peabody. OCR's director summed it up: "effective cybersecurity starts with Security Rule compliance."


A real risk analysis isn't a checklist you tick once. It's an inventory of everywhere patient data lives (the EHR, email, backups, laptops, phones, the scanner that saves to a shared folder nobody remembers setting up), what could go wrong with each, and how likely and how bad that would be. Then it gets updated whenever something changes.


Locked laptop representing addressable HIPAA safeguards like encryption

Addressable Doesn't Mean Optional


This is the single most misunderstood word in HIPAA. Many of the Security Rule's implementation specifications are marked "Addressable," and a lot of practices read that as "optional." It isn't.


Under 45 CFR 164.306(d), for each addressable item you have to assess whether it's reasonable for your practice, then either implement it or "document why it would not be reasonable and appropriate to implement" it and put an equivalent alternative in place.


Encryption on laptops is addressable. So is automatic logoff. Try explaining to an auditor why encrypting the laptop that went missing from the car wasn't reasonable. It's a short conversation.


Calendar on a desk tracking the HIPAA Security Rule update timeline

The HIPAA Security Rule Update Is Still Coming


In January 2025, HHS proposed the biggest update to the Security Rule since it was written. As of now it's still a proposal. The target for a final rule has moved to July 2027, according to Clark Hill.


If it goes through as proposed, The HIPAA Journal summarizes the big changes:


  • The required versus addressable distinction goes away

  • Multi-factor authentication "for access to ePHI, with limited exceptions"

  • Encryption "of all ePHI at rest and in transit, with limited exceptions"

  • A technology asset inventory and network map, updated at least every 12 months

  • Written procedures for restoring data within 72 hours

  • Security Rule compliance audits at least every 12 months


My advice: don't wait for the final rule. Almost everything on that list is something insurers already ask about, and it's good security anyway. That's why the quiz includes MFA as a recommended item even though today's rule doesn't name it.


IT technician working on servers alongside a HIPAA compliance consultant

Consultant, MSP, or Both?


Here's my one strong opinion on this. A binder of HIPAA policies is a lot like a compliance badge. It satisfies the auditor. It doesn't stop a breach. A practice can have beautiful policies and still have a front desk PC that auto-logs into the EHR as the doctor.


The flip side is true too. I've taken the 3am call about a virus spreading across a client's network and had it contained before the first employee logged in. That's the technical half of an incident. The other half is deciding who has to be notified and whether it's a reportable breach, and that half depends on paperwork someone wrote before the night it happened.


So here's a rule of thumb:


  • Hire a consultant if you've never done a risk analysis, you've had a breach, or OCR has contacted you

  • Lean on your MSP if you have the policies but the technical safeguards (encryption, logging, backups, MFA, patching) aren't really running

  • Use both if the quiz came back red across the board


Many MSPs, including us, can run the technical side of the risk analysis and fix what it finds, then work alongside a consultant for the legal and privacy pieces.


Calculator on a desk for estimating HIPAA consulting costs

What HIPAA Consulting Costs


Honest numbers are hard here, because scope varies so much. The HIPAA Journal puts consulting fees anywhere "from a few hundred dollars into the tens of thousands," depending on the size and complexity of the organization and the work involved.


What moves the price:


  • How many locations, systems and vendors touch patient data

  • Whether you need a full risk analysis or a review of an existing one

  • Whether they're writing policies from scratch

  • Whether you want ongoing help or a one-time project


Ask any consultant exactly what you'll get at the end. A risk analysis document, a policy set and a remediation plan with owners and dates is a real deliverable. A 60-page PDF that says "consider encryption" is not.


Small dental practice exam room that may not need a HIPAA consultant

When You Don't Need Us for This


If you're a solo practitioner using a cloud EHR, everything else in Microsoft 365 with MFA on, encrypted laptops and a current risk analysis, you probably don't need a consultant or an MSP. Keep the risk analysis updated, keep your BAAs on file, and retake the quiz every year.


Where it gets harder is a practice with 10 to 100 staff, a couple of locations, imaging or lab systems, and a practice manager who's also the security official, the HR department and the person who fixes the printer. That's where a managed IT provider for healthcare with a flat monthly rate earns its keep.


Man thinking through common HIPAA compliance consultant questions

Straight Answers


What does a HIPAA compliance consultant do?


They assess your practice against the HIPAA Privacy, Security and Breach Notification Rules, run or review your security risk analysis, write missing policies, train staff and review vendor agreements. Most document what's needed. Your IT provider usually implements the technical fixes.


Do small practices need a HIPAA consultant?


Not always. If you have a current risk analysis, documented policies, BAAs and the basic technical safeguards in place, you may not. If you've never done a risk analysis, it's worth getting help.


How much does a HIPAA consultant cost?


The HIPAA Journal puts fees from a few hundred dollars into the tens of thousands, depending on the size of the organization and the scope of work. A full risk analysis with policies costs more than a review.


Is a HIPAA risk assessment required every year?


Today's rule requires an accurate and thorough risk analysis and updates when your environment changes, but doesn't set an annual schedule. The proposed update would add yearly requirements, and once a year is a sensible habit either way.


What is the difference between required and addressable in HIPAA?


Required specifications must be implemented. Addressable ones must be assessed, then either implemented or documented as not reasonable, with an equivalent alternative in place. Neither one is optional.


Can my IT company do our HIPAA risk analysis?


Yes, many managed IT providers can run the technical risk analysis and fix what it finds. For the Privacy Rule and legal questions, pair them with a consultant or healthcare attorney.


Man on a phone call getting help with HIPAA compliance

Still Stuck? Give Us a Call


If the quiz turned up more red than green, you're not alone, and you're not in trouble yet. A gap list is the first step of a real risk management plan.


We're a flat-rate MSP in Baltimore covering Maryland, Virginia and Washington D.C., and we work with healthcare practices on exactly this. Give us a call on 410-703-3857 or book a free review, and we'll go through your quiz results with you, fix the technical gaps and tell you honestly whether you need a consultant for the rest.


And while you're at it, run your team through our phishing IQ test. Plenty of breaches don't start with a hacker in a hoodie. They start with a very convincing email.


Comments


bottom of page