HIPAA Compliance Essentials for 2026
Use this as a practical roadmap for building a complete compliance program.
You'll always work with One Guy Consulting owner, Chuck Weiselberg, Certified HIPAA Professional. Chuck is an expert in compliance.
In one 30-minute review, we will evaluate your HIPAA compliance standing, identify your largest risks, and give you practical steps that you can implement immediately. No obligation, no pressure.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a healthcare focused privacy law. It applies nationwide in the United States. It sets rules for protecting individually identifiable health information known as P.H.I. (Protected Health Information).
HIPAA contains three main rules: the Privacy Rule, the Security Rule, and the Breach Notification Rule. They require covered entities and their business associates to implement safeguards in the categories of technical, physical, and administrative. This protects PHI from unauthorized access, use, or disclosure.
HIPAA compliance is a dynamic and fluid process. There’s a lot of moving parts and even the most seasoned compliance professional occasionally confuses a BAA vs. NDA, the HIPAA identifiers list, or the HIPAA breach definition.
Whether you need HIPAA compliance in Chicago, are researching HIPAA regulations In Arlington Heights, building a compliance plan for Elk Grove Village, or are located right here in Queens New York and need to brush up on the HIPAA breach notification timeline, One Guy Consulting has your back!
You have enough to do in your day to day work. Stop worrying about your HIPAA compliance and let One Guy Consulting help you in the way they know best.
Health plans, healthcare clearinghouses, and healthcare providers who submit claims or check eligibility electronically, which covers nearly every practice today. Once you qualify, HIPAA protects PHI in every form: paper charts, spoken conversations, and electronic records.
Any person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity - billing companies, MSPs, cloud vendors, EHR platforms. They need a signed BAA in place before any PHI changes hands, and they answer to OCR directly.
The 2013 Omnibus Rule made subcontractors business associates in their own right. Handle PHI for a business associate instead of a covered entity, and you carry the same obligations and direct liability, with a BAA signed with the business associate that hired you.
Every engagement follows a repeatable process. It starts with a Security Risk Assessment (SRA), required under 45 CFR Section 164.308(a)(1)(ii)(A), to establish your compliance baseline.
Select a Compliance Officer. Complete your Security Risk Assessment. Then receive and review both the automated Gap Analysis and automated Remediation Plans.
Review, tailor, and publish your HIPAA policies. Have staff attest to their reading and understanding. Complete HIPAA 101 training and cybersecurity awareness training.
Manage BAs, sign Business Associate Agreements (BAAs), review vendor risk, and finish your physical, device, and IT audits.
Every account includes a way that staff can report unauthorized disclosures of PHI (protected health information). Issues can be submitted anonymously and your Compliance Officer gets clear next steps.
From there, gaps are identified, fixes are prioritized, and policies are written. Staff training and administrative controls are then addressed in accordance with HIPAA's Security Rule, Privacy Rule, and Breach Notification Rule.
Founder & CEO | Certified HIPAA Professional (CHP)
Since 2015, Chuck has helped organizations build practical HIPAA programs that hold up in the real world. He is based in Queens, N.Y. and helps small practices and their business associates nationwide. In ten years of consulting on HIPAA no client of his has ever been fined, or failed an audit. Looking for HIPAA compliance services near you? Remote engagements cover every state.
This is because he makes complex rules easier to follow and leads with empathy, clarity, and steady guidance.
More about Chuck and One Guy Consulting →
Book Your Free 30 Minute HIPAA Compliance ReviewGet the HIPAA help you need in one place. Click any square below to learn more about how our product(s) work.
A regular review of risk to ePHI, required under 45 CFR Section 164.308(a)(1)(ii)(A). It is the starting point for a strong HIPAA program.
Explore HIPAA Security Risk Assessment services →A gap analysis measures your current safeguards against the requirements of 45 CFR Part 164, Subparts C and E, and identifies where your organization falls short.
Review HIPAA Gap Analysis Resources →Remediation Plans document how you will fix identified gaps, consistent with the risk management requirement at 45 CFR Section 164.308(a)(1)(ii)(B). They also demonstrate to auditors that your organization has a structured corrective action process.
See HIPAA remediation planning services →Ready-made templates addressing the policies and procedures standard at 45 CFR Section 164.316. You approve, then your staff reviews. No starting from scratch.
Access HIPAA Policy Template Services →Meet the workforce training requirement under 45 CFR Section 164.308(a)(5)(i) with HIPAA 101 and cybersecurity awareness training.
HIPAA Training for Staff →A yearly on-site review of your physical safeguards under 45 CFR Section 164.310, covering facility access controls, workstation use, and workstation security.
Review Physical Safeguard Requirements →A yearly check of your devices and IT setup against the technical safeguard requirements at 45 CFR Section 164.312, covering encryption, access controls, and audit logging.
Complete Device and IT Audits →Give staff a clear way to report incidents as required under the Breach Notification Rule (45 CFR Sections 164.400 through 164.414). Reports can be anonymous, and your compliance officer gets clear response steps.
Get Help with HIPAA Incident Response →Plans starting at $60/month. No long-term commitment required.
View Pricing Plans"One Guy Consulting is super easy to work with. I actually look forward to my implementation meetings for HIPAA."Samantha M.
"We've been working with One Guy Consulting for years and always been very pleased with the results."Katie M. — Local Guide
"One Guy Consulting is great at what they do! I was intimidated to start work on this project, but nothing was further from the truth! Chuck was so professional and welcoming. He was always happy to clarify questions I had. They really knew how to put me at ease. Thanks so much, One Guy Consulting! Special shout-out to Chuck for getting me across the finish line."Jennifer M.
Recommendations from professionals who have worked alongside Chuck.
"Charles is a master of automation, allowing him to operate with the output of a much larger team while working as a department of one."Omar Barazanji - Machine Learning / MLOps / Agentic AI Engineer
The Office for Civil Rights is the federal agency within HHS responsible for enforcing HIPAA compliance and investigating breaches.
The Health Insurance Portability and Accountability Act of 1996 establishes national standards for protecting patient health information. Its implementing regulations are codified at 45 CFR Parts 160 and 164.
A federally mandated assessment required on a regular basis under 45 CFR §164.308(a)(1)(ii)(A) to evaluate whether current safeguards adequately protect ePHI. Methodology is informed by the NIST SP 800-39 risk management framework.
The HIPAA Security Rule (45 CFR Part 164, Subpart C) establishes national standards for protecting ePHI through administrative safeguards (§164.308), physical safeguards (§164.310), and technical safeguards (§164.312).
The HIPAA Privacy Rule (45 CFR Part 164, Subpart E) governs the use and disclosure of Protected Health Information (PHI), establishing patient rights, authorization requirements, and the minimum necessary standard for disclosures.
The Breach Notification Rule (45 CFR Sections 164.400 through 164.414) requires covered entities and business associates to provide notification following a breach of unsecured protected health information.
Use this as a practical roadmap for building a complete compliance program.
Understand what HIPAA requires, who it applies to, and why it matters for your organization.
Learn what qualifies as PHI, the 18 HIPAA identifiers, and how to handle it properly.
Know your obligations when a breach occurs—timelines, reporting steps, and penalty risks.
Understand role boundaries so contracts, obligations, and audits stay clean.
Understand the access, amendment, and disclosure rights your patients are entitled to.
If you are not sure what to tackle first, reach out and we will help you map the next step.