A HIPAA compliance consultant built for small practices.
Written Risk Analysis under 45 CFR 164.308. Policies built for your practice, not a template library. Flat fees from $750, three-week delivery, CIPP/US certified. Serving dental offices, med spas, therapy practices, and clinics in all 50 states.
Book a Free Call with SamWhat does a HIPAA compliance consultant actually do?
A HIPAA compliance consultant performs the compliance work your software tracks. The center of that work is the Security Risk Analysis required under 45 CFR 164.308(a)(1)(ii)(A): an accurate, thorough, organization-wide assessment of where your patient data lives, how it moves, and what could compromise it. It is the first document OCR requests in every investigation, and inadequate risk analysis appears in roughly 90 percent of OCR's Security Rule enforcement actions.
Around that center sit the pieces a small practice actually needs: practice-specific policies and a current Notice of Privacy Practices, a complete inventory of vendors and Business Associate Agreements under 45 CFR 164.502(e), a workforce training program with documentation that survives an audit, and a breach response plan written before anything goes wrong.
What a consultant is not: a $39-a-month dashboard, and a $600-an-hour law firm. Software provides templates and tracking; it cannot see your practice, and even the government's free SRA Tool carries a disclaimer that using it does not guarantee compliance. Attorneys are essential for litigation and OCR responses, and expensive overkill for building routine documentation. The consultant sits in the middle: hands-on, flat-fee, and focused on the work itself.
Why small practices, specifically?
Because that is where enforcement moved. OCR's Risk Analysis Initiative, launched in October 2024 with a $90,000 settlement against a county ambulance service, has run through 2026 and across a change in administration, reaching 14 enforcement actions. Recent settlements include a $250,000-range case load of small providers and, in June 2026, a $450,000 settlement with an employer health plan covering just 10,023 people. A Dallas dental practice paid $10,000 over replies to Yelp reviews. Civil penalties in 2026 run from $145 to $2,190,294 per violation under the current federal schedule.
Small practices carry the same obligations as hospital systems with none of the staff. That mismatch is the entire design brief for this practice: enterprise-grade documentation, sized and priced for an office of four to one hundred people.
Services and flat-fee pricing
Privacy Exposure Review
Your top three privacy risks, in writing, in 48 hours. The lowest-commitment way to find out where you stand.
$750 flatHIPAA Risk Analysis
The full written Security Rule Risk Analysis: NIST SP 800-30 methodology, risk register, ranked remediation roadmap. OCR-ready.
$3,500–$4,500 flat · 3 weeksPolicies & Notice of Privacy Practices
Practice-specific policies and a current NPP, written for your workflows and 2026 rules.
Scoped flat feeVendor & BAA Review
Every vendor touching PHI, inventoried, with the missing Business Associate Agreements identified and closed.
Scoped flat feeFractional Privacy Officer
Ongoing privacy officer coverage without the full-time hire: monitoring, training, incident response, annual refresh.
$2,500–$5,000/monthState Privacy Law Programs
CCPA, CPRA, TDPSA and other state law compliance for the data HIPAA does not cover.
From $3,500How the engagement works
| Week | What happens | What you get |
|---|---|---|
| 1 | Asset and data-flow inventory: every system, device, and vendor that touches patient data, mapped through structured remote interviews. | A complete picture of where your ePHI actually lives. |
| 2 | Risk scoring against the NIST SP 800-30 framework, the methodology OCR recognizes, built against the HHS Audit Protocol criteria and the nine elements of HHS Final Guidance. | A risk register with likelihood and impact scores. |
| 3 | Written report and walkthrough: findings ranked by enforcement risk, not alphabetically, with a remediation roadmap your office can execute. | The document OCR asks for first, plus the plan. |
Everything runs remotely with secure document exchange; no PHI needs to leave your systems for the assessment. Practices in the greater Houston area can add an in-person walkthrough.
How do you choose a HIPAA consultant?
HIPAA consulting is an unregulated field, which means anyone can claim the title. Five screens that separate the real ones:
- A recognized privacy credential. The CIPP/US from the IAPP is the standard for US privacy law. Ask for it by name.
- A named methodology. If the answer to "how do you score risk?" is not a framework like NIST SP 800-30, you are buying a questionnaire.
- A sample deliverable. A real consultant can show you a redacted findings report. Judge the writing: could your office manager act on it?
- Current enforcement fluency. Ask what OCR settled most recently. A consultant who tracks enforcement can tell you; one who sells templates cannot.
- Flat fees in writing. Hourly compliance billing punishes you for asking questions. Fixed scope, fixed price.
North Privacy Advisors is built to pass its own screens: founded by Sam Cherkaoui, CIPP/US, publishing weekly on OCR enforcement, NIST-based methodology, redacted samples on request, and every engagement flat-fee. Recent work includes a multi-location Texas med spa where five documented risk findings, three at maximum severity, were closed within 90 days of the report, documentation that later carried the practice through private-equity due diligence. Read the case studies or the complete 2026 guide to the HIPAA Risk Analysis for the full methodology.
Consultant, software, or lawyer: which job is which?
| Compliance software | HIPAA consultant | Healthcare attorney | |
|---|---|---|---|
| Typical cost | $39 to $500/month | $750 to $4,500 flat per engagement | $300 to $1,000+ per hour |
| What it does | Templates, training modules, attestation tracking, reminders | Performs the Risk Analysis, writes practice-specific policies, builds the BAA inventory and breach plan | Litigation, OCR investigation response, complex contracts |
| What it cannot do | See your practice; perform the 164.308 analysis; talk to OCR | Represent you in court or negotiate with OCR after a letter arrives | Affordably build routine documentation |
| Right time to buy | After the analysis exists, to maintain it | First, because the analysis tells you what everything else must contain | The day a breach, lawsuit, or OCR letter lands |
The combination that works for most small practices: consultant first for the Risk Analysis and program build, the cheapest software tier that fits for year-over-year maintenance, and an attorney's number saved for the day it is genuinely legal work. We compared the three paths in dollar terms in the 2026 cost guide.
Specialty-specific compliance, because the gaps differ
Dental and orthodontic practices. The enforcement record is unambiguous: OCR has settled with dental practices over social media replies, and imaging-heavy workflows scatter ePHI across operatory tablets, panoramic systems, and aligner-lab transfers. Multi-location groups carry the added burden of one organization-wide analysis across every site. Start with the dental Risk Analysis guide.
Med spas and aesthetic practices. Before-and-after photos are protected health information, full-face images are one of HIPAA's 18 identifiers, and marketing them requires a signed authorization that is not your treatment consent form. Our most recent published engagement closed five documented findings at a multi-location Texas med spa in 90 days. The photo and testimonial trap covers the specifics.
Therapy and behavioral health. Session notes carry heightened sensitivity, the 42 CFR Part 2 substance-use rules layer on top of HIPAA, and tracking pixels on appointment pages have become the specialty's signature violation. Small group practices are squarely in OCR's small-entity enforcement pattern.
Telehealth providers. Every platform in the stack, video, messaging, scheduling, transcription, is a business associate that needs a BAA before PHI flows, and state rules stack on the federal floor. The telehealth compliance page goes deeper.
Frequently asked questions
What does a HIPAA compliance consultant do that software does not?
A consultant performs the accurate, thorough, organization-wide Risk Analysis required under 45 CFR 164.308(a)(1)(ii)(A), the first document OCR requests in an investigation. Software provides templates, training, and tracking, but a questionnaire score is not a risk analysis, and inadequate risk analysis appears in roughly 90 percent of OCR's Security Rule enforcement actions.
How much does a HIPAA compliance consultant cost for a small practice?
Here, the entry point is a $750 Privacy Exposure Review delivered in 48 hours. A full written HIPAA Risk Analysis is a flat $3,500 to $4,500, delivered in three weeks. Ongoing fractional privacy officer coverage runs $2,500 to $5,000 per month. All flat fees.
Do I need a HIPAA consultant or a healthcare lawyer?
For routine compliance work, a consultant. The Risk Analysis, policies, training program, and BAA inventory are practical work done for flat fees. A healthcare attorney is the right choice for breach litigation, OCR investigation responses, and complex contracts.
Does the work require on-site visits?
Usually not. Assessments run remotely with secure document exchange and structured interviews, which is how we serve practices in all 50 states. In-person walkthroughs are available in the greater Houston area.
How long does a HIPAA Risk Analysis take?
Three weeks: inventory in week one, NIST SP 800-30 risk scoring in week two, written report with a ranked remediation roadmap in week three.
What credentials should a HIPAA consultant have?
The field is unregulated, so credentials and published work are the screen. Look for the CIPP/US from the IAPP, a named methodology, sample deliverables, and evidence the consultant tracks OCR enforcement actively.
Who this is for
Dental and orthodontic offices, med spas and aesthetic practices, therapy and behavioral health groups, telehealth providers, and independent medical clinics, generally under 100 employees. If your compliance program is a binder from 2019 and a software subscription nobody logs into, you are exactly who this page was written for. Start with the $750 review and know where you stand this week, or go straight to the full Risk Analysis if you already know the gap.
Find out where you actually stand, before OCR does.
A free 30-minute consultation. No pitch, no pressure: your situation, the real gaps, and whether we are a fit.
Book a Free Call with Sam