Quick answer
Choosing a HIPAA consultant comes down to eight questions that test for the things enforcement actually punishes. There is no government-issued HIPAA certification, so ignore badges and interrogate deliverables: the written risk analysis required by 45 CFR 164.308(a)(1)(ii)(A), cited in roughly 90% of OCR’s Security Rule enforcement actions and failed by 86% of covered entities in OCR’s own audits. A Houston practice should also test for Texas HB 300 fluency, a vendor and BAA process, flat pricing, and a sample of the written record you will actually receive. The eight questions below come with the enforcement facts behind each one.
Hiring a HIPAA consultant is a strange purchase. You cannot easily judge the work until the day OCR, a cyber insurer, or a patient complaint tests it, and by then it is too late to switch vendors. After years of doing this work and reading every enforcement action OCR publishes, here are the eight questions I would ask anyone selling HIPAA help to a Houston practice, including me.
1. Who will actually perform my risk analysis?
Start here because OCR starts here. The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A) is the first document requested in an investigation, the gap cited in roughly 90 percent of OCR’s Security Rule enforcement actions, and the subject of a dedicated federal enforcement campaign: the Risk Analysis Initiative, which opened in October 2024 with a $90,000 settlement against a county ambulance service and reached its twelfth action in 2026.
Ask who performs the analysis, what methodology they follow, and whether the result is specific to your practice. If the answer involves software generating a score from a questionnaire, keep reading: in OCR’s own audit program, 86 percent of covered entities failed the risk analysis requirement, and 94 percent failed risk management, overwhelmingly because generic checklists stood in for real analysis.
2. Can I see a sample deliverable?
Compliance is a written record. Ask to see a redacted sample of the actual documents you will receive: the risk analysis, the risk management plan, the policies. A consultant who cannot produce a sample is selling a process, not a record, and the record is the only thing OCR reads.
While you are looking at the sample, check whether it could only describe one specific practice. A deliverable that would fit any office in Houston equally well will protect none of them.
3. What do your credentials actually mean?
Here is something the compliance industry prefers not to say plainly: there is no official HIPAA certification. HHS has never created, endorsed, or recognized one, for consultants or for practices. Anyone promising to make your practice “HIPAA certified” is describing a product of their own invention.
Real credentials exist: CIPP/US from the IAPP is the recognized U.S. privacy professional certification, and legal or security credentials signal depth. But the question to ask is not “are you certified?” It is “what does that credential require, and who stands behind it?“
4. Do you know Texas law, not just federal?
A Houston practice answers to two regulators. Federal HIPAA is the floor. The Texas Medical Records Privacy Act (HB 300) sits on top of it: it defines covered entity more broadly than federal law, cuts the deadline for providing electronic records to 15 business days against the federal 30 days, and authorizes the Texas Attorney General to seek penalties up to $1.5 million per violation category per year, on a separate track from OCR.
Ask a prospective consultant what HB 300 changes for your practice. If the answer is a blank look, they are selling you a 49-state product in the one state where that is not enough.
5. How will you handle my vendors?
Vendor risk is where small practices get hurt without doing anything themselves. A clinic paid $750,000 for handing X-ray films to a vendor without a business associate agreement. And in March 2026, OCR settled with MMG Fusion, a dental software vendor whose breach exposed roughly 15 million records; the company had failed to notify the practices it served, whose duty to notify their own patients never went away.
A typical practice has a dozen vendors touching patient data. Ask the consultant how they inventory those vendors, verify signed BAAs under 45 CFR 164.502(e), and what happens when a vendor refuses to sign.
6. Will your documentation survive an insurance claim?
Cyber insurance applications now ask the same questions OCR does: risk assessment, MFA, incident response, training. Carriers verify answers during claims investigations, and in the Travelers v. International Control Services case, a policy was rescinded entirely over an MFA attestation that turned out to be only partially true.
Ask whether the consultant’s deliverables are written to support your insurance attestations, not just your HIPAA file. One document should serve both masters, because the renewal questionnaire and the OCR data request are converging on the same list.
7. Am I buying software or judgment?
Compliance software has its place, and for some practices a $3,000-per-year platform is better than nothing. But software cannot interview your front desk, notice the tablet syncing intraoral photos to a personal cloud account, or tell you which of its 400 checklist items actually matter for a three-operatory practice in Katy. The enforcement record shows where checklists end: practices fined despite years of paid subscriptions, because a training portal is not a risk analysis and a template is not a policy.
The fair question for any consultant, me included: “what will you find that software would not?” The answer should be specific and a little uncomfortable.
8. What does it cost, and what exactly do I get?
HIPAA consulting for a small practice should be flat-fee, scoped, and finite. Open-ended hourly engagements transfer all the risk to you. As a reference point for the Houston market: North Privacy Advisors performs the complete written HIPAA Risk Analysis at a flat $3,500 to $4,500 delivered in about three weeks, and a $750 Privacy Exposure Review that identifies your top three gaps in 48 hours. Whoever you talk to, get the number and the deliverable list in writing before work starts.
The stakes behind the price: 2026 federal penalties run from $145 to a cap of $2,190,294 per violation category under Federal Register 2026-01688, with willful neglect starting at $73,011 per violation, and nearly every settlement adds a corrective action plan monitored by OCR for two to three years. Against that, the cost of a real consultant is a rounding error.
What to do next
If you are comparing consultants this month, use the eight questions above as your screen and disqualify anyone who stumbles on the first three. If you want a fast, low-commitment read on where your practice stands before talking to anyone, run our free 60-second privacy check, or start with the $750 Privacy Exposure Review and get your top gaps in writing this week. And if you want the full picture of what the flagship engagement covers, the HIPAA Risk Analysis service page spells out every deliverable, because that is the standard this article just told you to demand.
Last Updated: July 17, 2026