Home About Products Pricing Blog Contact Login
HIPAA Compliance Consulting

Find the HIPAA Compliance Gaps Costing Your Organization Thousands

Chuck Weiselberg, Certified HIPAA Professional

You'll always work with One Guy Consulting owner, Chuck Weiselberg, Certified HIPAA Professional. Chuck is an expert in compliance.

In one 30-minute review, we will evaluate your HIPAA compliance standing, identify your largest risks, and give you practical steps that you can implement immediately. No obligation, no pressure.

  • Identify your highest-risk HIPAA compliance gaps
  • Ask any HIPAA question and get practical, honest answers
  • Leave with a prioritized action plan you can begin immediately
Certified HIPAA Professional 10+ Years Experience No client has ever failed an audit No Sales Pressure

What Is HIPAA Compliance?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a healthcare focused privacy law. It applies nationwide in the United States. It sets rules for protecting individually identifiable health information known as P.H.I. (Protected Health Information).

HIPAA contains three main rules: the Privacy Rule, the Security Rule, and the Breach Notification Rule. They require covered entities and their business associates to implement safeguards in the categories of technical, physical, and administrative. This protects PHI from unauthorized access, use, or disclosure.

HIPAA compliance is a dynamic and fluid process. There’s a lot of moving parts and even the most seasoned compliance professional occasionally confuses a BAA vs. NDA, the HIPAA identifiers list, or the HIPAA breach definition.

Whether you need HIPAA compliance in Chicago, are researching HIPAA regulations In Arlington Heights, building a compliance plan for Elk Grove Village, or are located right here in Queens New York and need to brush up on the HIPAA breach notification timeline, One Guy Consulting has your back!

You have enough to do in your day to day work. Stop worrying about your HIPAA compliance and let One Guy Consulting help you in the way they know best.

Who Needs to Be HIPAA Compliant?

Covered Entities

Health plans, healthcare clearinghouses, and healthcare providers who submit claims or check eligibility electronically, which covers nearly every practice today. Once you qualify, HIPAA protects PHI in every form: paper charts, spoken conversations, and electronic records.

Business Associates

Any person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity - billing companies, MSPs, cloud vendors, EHR platforms. They need a signed BAA in place before any PHI changes hands, and they answer to OCR directly.

BAs to Other BAs

The 2013 Omnibus Rule made subcontractors business associates in their own right. Handle PHI for a business associate instead of a covered entity, and you carry the same obligations and direct liability, with a BAA signed with the business associate that hired you.

The Process

How It Works

Every engagement follows a repeatable process. It starts with a Security Risk Assessment (SRA), required under 45 CFR Section 164.308(a)(1)(ii)(A), to establish your compliance baseline.

Assess and Analyze Automatically

Select a Compliance Officer. Complete your Security Risk Assessment. Then receive and review both the automated Gap Analysis and automated Remediation Plans.

Adopt and Attest

Review, tailor, and publish your HIPAA policies. Have staff attest to their reading and understanding. Complete HIPAA 101 training and cybersecurity awareness training.

Agreements and Auditing

Manage BAs, sign Business Associate Agreements (BAAs), review vendor risk, and finish your physical, device, and IT audits.

Anonymous Incident Reporting

Every account includes a way that staff can report unauthorized disclosures of PHI (protected health information). Issues can be submitted anonymously and your Compliance Officer gets clear next steps.

From there, gaps are identified, fixes are prioritized, and policies are written. Staff training and administrative controls are then addressed in accordance with HIPAA's Security Rule, Privacy Rule, and Breach Notification Rule.

Chuck Weiselberg, Founder of One Guy Consulting
NYC-Based • Nationally Available

Meet Chuck Weiselberg

Founder & CEO | Certified HIPAA Professional (CHP)

Since 2015, Chuck has helped organizations build practical HIPAA programs that hold up in the real world. He is based in Queens, N.Y. and helps small practices and their business associates nationwide. In ten years of consulting on HIPAA no client of his has ever been fined, or failed an audit. Looking for HIPAA compliance services near you? Remote engagements cover every state.

This is because he makes complex rules easier to follow and leads with empathy, clarity, and steady guidance.

Book Your Free 30 Minute HIPAA Compliance Review
What We Offer

Products

Get the HIPAA help you need in one place. Click any square below to learn more about how our product(s) work.

HIPAA Security Risk Assessment

A regular review of risk to ePHI, required under 45 CFR Section 164.308(a)(1)(ii)(A). It is the starting point for a strong HIPAA program.

Explore HIPAA Security Risk Assessment services →

HIPAA Gap Analysis

A gap analysis measures your current safeguards against the requirements of 45 CFR Part 164, Subparts C and E, and identifies where your organization falls short.

Review HIPAA Gap Analysis Resources →

HIPAA Remediation Plans

Remediation Plans document how you will fix identified gaps, consistent with the risk management requirement at 45 CFR Section 164.308(a)(1)(ii)(B). They also demonstrate to auditors that your organization has a structured corrective action process.

See HIPAA remediation planning services →

HIPAA Policy Templates

Ready-made templates addressing the policies and procedures standard at 45 CFR Section 164.316. You approve, then your staff reviews. No starting from scratch.

Access HIPAA Policy Template Services →

Staff HIPAA Training

Meet the workforce training requirement under 45 CFR Section 164.308(a)(5)(i) with HIPAA 101 and cybersecurity awareness training.

HIPAA Training for Staff →

Physical Site Audit

A yearly on-site review of your physical safeguards under 45 CFR Section 164.310, covering facility access controls, workstation use, and workstation security.

Review Physical Safeguard Requirements →

Device & IT Audits

A yearly check of your devices and IT setup against the technical safeguard requirements at 45 CFR Section 164.312, covering encryption, access controls, and audit logging.

Complete Device and IT Audits →

Unauthorized Disclosure of PHI (Incidents)

Give staff a clear way to report incidents as required under the Breach Notification Rule (45 CFR Sections 164.400 through 164.414). Reports can be anonymous, and your compliance officer gets clear response steps.

Get Help with HIPAA Incident Response →

Ready to Protect Your Practice?

Plans starting at $60/month. No long-term commitment required.

View Pricing Plans
Client Reviews

Client Feedback

★★★★★
"One Guy Consulting is super easy to work with. I actually look forward to my implementation meetings for HIPAA."
Samantha M.
★★★★★
"We've been working with One Guy Consulting for years and always been very pleased with the results."
Katie M. — Local Guide
★★★★★
"One Guy Consulting is great at what they do! I was intimidated to start work on this project, but nothing was further from the truth! Chuck was so professional and welcoming. He was always happy to clarify questions I had. They really knew how to put me at ease. Thanks so much, One Guy Consulting! Special shout-out to Chuck for getting me across the finish line."
Jennifer M.
Professional Endorsements

What Colleagues Say

Recommendations from professionals who have worked alongside Chuck.

"Charles is a master of automation, allowing him to operate with the output of a much larger team while working as a department of one."
Omar Barazanji - Machine Learning / MLOps / Agentic AI Engineer
Reference

Key HIPAA Terms

OCR

The Office for Civil Rights is the federal agency within HHS responsible for enforcing HIPAA compliance and investigating breaches.

HIPAA

The Health Insurance Portability and Accountability Act of 1996 establishes national standards for protecting patient health information. Its implementing regulations are codified at 45 CFR Parts 160 and 164.

Security Risk Analysis

A federally mandated assessment required on a regular basis under 45 CFR §164.308(a)(1)(ii)(A) to evaluate whether current safeguards adequately protect ePHI. Methodology is informed by the NIST SP 800-39 risk management framework.

Security Rule

The HIPAA Security Rule (45 CFR Part 164, Subpart C) establishes national standards for protecting ePHI through administrative safeguards (§164.308), physical safeguards (§164.310), and technical safeguards (§164.312).

Privacy Rule

The HIPAA Privacy Rule (45 CFR Part 164, Subpart E) governs the use and disclosure of Protected Health Information (PHI), establishing patient rights, authorization requirements, and the minimum necessary standard for disclosures.

Breach Notification Rule

The Breach Notification Rule (45 CFR Sections 164.400 through 164.414) requires covered entities and business associates to provide notification following a breach of unsecured protected health information.

FAQ

Frequently Asked Questions

You need to be HIPAA compliant if creating, receiving, storing, or sharing Protected Health Information (PHI) — any individually identifiable health information such as medical records, billing data, or insurance details, as defined in 45 CFR §160.103. That includes covered entities like healthcare providers and health plans, plus vendors that handle PHI for them as business associates.
A typical HIPAA compliance process takes about 1–2 months. The timeline depends on organization size, number of locations, and how many staff need training.
A Security Risk Assessment (SRA) is a federally mandated evaluation required on a regular basis under 45 CFR §164.308(a)(1)(ii)(A). It identifies potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) and forms the foundation of any HIPAA compliance program.
HIPAA violations can result in civil monetary penalties ranging from $145 to $73,011 per violation (adjusted for inflation), up to $2,190,294 annually per violation category, as established by the HHS Office for Civil Rights enforcement framework. Willful neglect violations that are not corrected can result in criminal penalties for violating HIPAA including fines up to $250,000 and imprisonment.
Yes. HIPAA compliance is ongoing. We help with yearly SRA updates, policy reviews, staff refreshers, and day-to-day questions.
A HIPAA gap analysis compares your current administrative, physical, and technical safeguards against the requirements of the HIPAA Security Rule (45 CFR Part 164, Subpart C) and the Privacy Rule (Subpart E). It identifies partial controls, missing documentation, and procedures not consistently followed.
A HIPAA remediation plan documents identified compliance gaps and assigns specific corrective actions, owners, and deadlines to resolve them. It demonstrates to auditors that an organization has a structured, documented approach to addressing risks identified during a Security Risk Assessment, consistent with the risk management requirement at §164.308(a)(1)(ii)(B).
No, we provide policy templates tuned to HIPAA requirements and help tailor them to your organization.
Each staff member should complete policy attestation, HIPAA 101 training, and cybersecurity awareness training each year.
No. One Guy Consulting is not a law firm and does not give legal advice. You should talk to an attorney before making major legal or business decisions.
Self-Guided — $675/year. Designed for experienced compliance professionals who need a reliable, cloud-based platform to centralize their work.

Full-Scope — $1,300/year. Designed for small and scaling teams tackling HIPAA compliance for the first time, or transitioning from another platform, who need guided assistance getting their program up and running.
One Guy Consulting does not handle PHI as part of our service, but we are happy to sign a BAA with your organization if you would like one in place.
Step 1: Select a Compliance Officer, complete the Security Risk Assessment, and review the automated gap analysis and remediation plans.

Step 2: Review, tailor, and publish your HIPAA policies. Have staff attest to their understanding, then complete HIPAA 101 and cybersecurity awareness training.

Step 3: Manage vendor relationships, execute Business Associate Agreements, conduct vendor risk analysis, and complete your physical site, device inventory, and IT networking audits.

Step 4: Verify your Incident Management System works by running a test reporting scenario.
Do the HIPAA Security Risk Assessment first, then use the findings to write your policies and procedures, fix the highest-risk gaps, and keep documentation. These are all things One Guy Consulting is very familiar with and will be happy to assist you on.
$1,300 / Year / Flat rate. If you choose, there is an option to purchase two years in advance at a discounted rate. More info on this is found on our Pricing page.
Industries Served

Specialties We Serve

Dental Practices Mental Health Providers Medical Clinics Pharmacies IT Vendors & MSPs Healthcare Startups EHR Companies Hospitals Billing Companies Skilled Nursing

Discuss your HIPAA requirements

If you are not sure what to tackle first, reach out and we will help you map the next step.

Book Your Free 30 Minute HIPAA Compliance Review