A HIPAA compliance consultant does six concrete things: runs a gap assessment against the Privacy and Security Rules, performs the security risk analysis regulators expect to see on paper, writes your policies and procedures, builds a business associate agreement (BAA) program, trains your workforce, and hands you a remediation roadmap ranked by risk. The money sorts into three shapes: hourly advice at $250 to $350 an hour, project work from $2,000 for a basic gap review up to $40,000 for a full readiness assessment, and ongoing retainers. That’s the whole market, minus the parts that are theater.
We’re gmware, a custom software development firm headquartered in Austin, TX with engineering centers in Bangalore and Mohali, India. Healthcare builds are part of our delivery history, and we’ve written before about what a HIPAA-compliant application actually requires in the code. This post is the other half of that conversation: what happens when you hire outside help for the compliance program itself, what each engagement shape costs with sources, and the one claim that should make you close the tab on any vendor (“get HIPAA certified!”) because no such certification exists.
What does a HIPAA compliance consultant actually do?
Strip the proposals down and nearly every engagement is some bundle of the same six deliverables.
Gap assessment. A structured walk through the Privacy Rule, Security Rule, and Breach Notification Rule against what your organization actually does. Not what the binder says. What the front desk does at 4:55pm on a Friday when a records request comes in.
Security risk analysis. This is the load-bearing deliverable. The Security Rule requires covered entities and business associates to conduct a risk assessment identifying where electronic PHI lives and what threatens it. It’s also the thing OCR keeps fining people for skipping, which we’ll get to.
Policies and procedures. The written rules your staff can be held to: access authorization, sanctions, incident response, contingency plans. A consultant’s real value here isn’t the documents, it’s tailoring them so they describe your actual workflows instead of a fictional hospital’s.
BAA program. An inventory of every vendor that creates, receives, maintains, or transmits PHI on your behalf, and a signed agreement with each. The vendor list is always longer than the client expects. The email tool. The answering service. The IT guy’s monitoring software.
Workforce training. Required, recurring, and cheap to do properly: e-learning runs $20 to $80 per employee per year.
Remediation roadmap. The ranked to-do list that comes out of the first two items. Good consultants rank by risk and cost. Weak ones hand you 90 undifferentiated findings and an invoice.
Ongoing retainers repeat the cycle: annual risk analysis updates, policy reviews, training refreshes, and support if an audit letter or breach shows up.
What HIPAA compliance consulting costs in 2026
Here’s the engagement-cost table, every range sourced. The spread inside each line is scope: how many locations and systems you run, and how much PHI your operation actually touches.
| Engagement shape | What you get | Sourced 2026 range |
|---|---|---|
| Hourly advisory | Questions answered, contracts reviewed, incident triage | $250 to $350/hour |
| Gap analysis + risk assessment + risk management plan | Where you stand, what’s exposed, what to fix first | $2,000 to $25,000 |
| Third-party risk assessment, small org | The documented SRA, done by an outside firm | $5,000 to $20,000 |
| Full external readiness assessment | Audit-style review across all three rules | $15,000 to $40,000 |
| Full program stand-up, small practice | Assessment through policies, BAAs, and training | $6,000 to $35,000 initial |
| Full program stand-up, mid-size org | Same, at 50 to 500 staff scale | $80,000 to $450,000 initial |
| Ongoing program, small practice | Annual SRA refresh, training, policy upkeep | $3,500 to $18,000/year |
| Ongoing advisory retainer | Standing access to a consultant | $2,000 to $5,000/year at the light end |
What each engagement shape costs
Notice what’s missing from the table: remediation. The assessment tells you the server closet has no access log and the billing vendor never signed a BAA. Fixing those is engineering and legal work priced separately, and it’s routinely the biggest number in the whole project. Any consultant who quotes “compliance” as one flat fee without asking what your stack looks like is guessing, the same way a flat-fee pen test quote is a guess.
If you’re budgeting an engagement right now, tell us what systems touch PHI and we’ll give you a straight read on which shape fits and what the remediation half is likely to run.
Why the risk analysis is the deliverable that matters
Because it’s the one OCR checks first. In the first five months of 2025, OCR announced ten HIPAA resolution agreements with fines from $25,000 to $3 million, and the recurring defect across that enforcement run was the same: no accurate and thorough risk analysis. Not exotic attacks. Paperwork nobody did.
The penalty math behind those settlements is unfriendly. The 2026 civil tiers run from $145 per violation at the lowest tier to $73,011 per violation for uncorrected willful neglect, with an annual cap of $2,190,294 per provision. And the exposure is not hypothetical: 772 large healthcare breaches were reported in 2025, affecting roughly 138.5 million people, a new annual record for breach count.
Why the risk analysis is not optional paperwork
So when you evaluate a consultant, put weight on how they do the SRA. Ask to see a sanitized sample. If it reads like a generic questionnaire with your logo on it, that’s what OCR will think too.
There is no official HIPAA certification
Here’s the honest-verdict section, and it cuts against a chunk of the industry. HHS answers the certification question directly: there is no standard or implementation specification that requires a covered entity to certify compliance. No federal body issues a HIPAA certificate, and no private seal binds a regulator. Even vendors who sell certification programs concede the point: certification is not a requirement of HIPAA, and it’s a voluntary process that at best demonstrates good-faith effort.
That doesn’t make every badge worthless. Documented third-party review is real evidence of effort, and effort matters at penalty-tier time. But it reframes what you’re buying. You’re buying the work, not the sticker. Which suggests a short red-flag list for shopping:
- “Become HIPAA certified in 48 hours.” There’s nothing official to become, and a two-day turnaround means templates that weren’t tailored to how your PHI actually moves.
- A price quoted before any scoping questions. If they never asked what touches PHI, the number is fiction.
- A “compliance guarantee.” Nobody can guarantee an OCR outcome. A consultant who promises one is writing a check your organization cashes.
- No sample SRA. The core deliverable should survive inspection before you sign.
- Silence on remediation. If the proposal ends at “findings report,” ask who fixes the findings, because that’s where the money and the risk both live.
One more thing, since HIPAA is law and we are not lawyers: for the legal questions an engagement surfaces (breach notification decisions, state-law overlays, BAA negotiation with a stubborn vendor), have your counsel in the loop. A good consultant will say that themselves.
Consultant, compliance software, or DIY: match the tool to the problem
The three paths aren’t really competitors. They solve different halves of the problem, and the right answer for most small organizations is a blend. Here’s the decision matrix we’d use.
| DIY + free HHS tools | Compliance software | Consultant | |
|---|---|---|---|
| Cash cost | Free SRA Tool + $20 to $80/employee training | $1,200 to $6,000/year, small org | $2,000 to $40,000 per project |
| Real cost | Your time, and the risk of blind spots | Setup effort plus someone to own it | The fee, plus remediation |
| SRA quality | As good as the person driving the tool | Structured, but self-reported | Independent and defensible |
| Policies | Generic unless you rewrite them | Templated, lightly tailored | Written to your actual workflows |
| Fixes the gaps | No | No | Sometimes, if they have engineers |
| Best for | Tiny practice, simple stack, a diligent owner | Teams that need continuous evidence and reminders | First-time programs, audits, breach recovery, complex vendor chains |
Three paths, three different jobs
The pattern that works in practice: a consultant (or a capable internal owner) for the first risk analysis and policy set, software to keep evidence and reminders alive afterward, and engineering help scoped separately for whatever the SRA turns up. It’s the same division of labor we described for SOC 2, where Vanta-style platforms watch and engineers change things. The platform never closes its own findings. Someone has to.
How to scope the engagement so you don’t overpay
Five questions before you sign anything.
- What’s in scope? Sites, systems, vendors, and which rules (Security only, or Privacy and Breach Notification too). Scope creep in compliance runs downhill into your invoice.
- What are the named deliverables? You want the SRA document, the risk management plan, the policy set, the BAA inventory, and the ranked roadmap listed in the SOW by name.
- Who does the remediation, and at what rate? Some firms assess and disappear. Some assess and upsell. Know which one you’re hiring before the findings arrive.
- How do they handle the technical safeguards? Encryption, access controls, and audit logging are engineering, not paperwork. If the consultant has no engineers, plan for a second vendor. Our walkthrough of the five technical safeguards shows what that half of the work involves.
- What happens next year? A risk analysis is a snapshot. Ask what the annual refresh costs before the first engagement ends, not after.
A worked example, since abstractions hide the math. A three-provider dermatology practice with one EHR, a billing vendor, and a patient-texting app should expect the low end: a $5,000 to $20,000 third-party SRA or a package inside the $6,000 to $35,000 small-practice stand-up range, not a $100K enterprise review. A 40-person healthtech startup with PHI in three cloud services and a hospital customer demanding proof sits higher, and honestly gets more value from pairing a lean assessment with real remediation engineering than from a thicker report. Already holding a quote and unsure if it’s sane? Send it over and we’ll tell you what we see.
When you don’t need a consultant
Three situations where we’d tell you to keep your money, and we build compliance-adjacent software for a living.
You’re small, simple, and diligent. HHS built its free Security Risk Assessment Tool specifically for small and medium providers. A solo practice with one EHR and a short vendor list, plus an owner willing to spend a few evenings on it, can produce a legitimate SRA with it. Add cheap training and you have a defensible baseline program.
You haven’t done the basics. If laptops aren’t encrypted and there’s no MFA on the EHR, a $25,000 assessment will mostly tell you that. Close the obvious gaps first, then pay someone to find the non-obvious ones. We made the same argument about cybersecurity consulting generally: hygiene first, advice second.
You might not be covered by HIPAA at all. A wellness app that never touches a covered entity usually falls outside HIPAA entirely, under FTC rules instead. Don’t buy a HIPAA program to feel safe; check whether the law even applies. When it does apply and you’re moving infrastructure, note that the bar is rising: the updated Security Rule proposal puts a January 1, 2027 compliance date on mandatory MFA and encryption, which changes what any assessment this year should measure against.
Where gmware fits
We’re not a compliance-certification shop, and after the section above you know why we’re fine with that. What we do is the technical-safeguards half of HIPAA work: the architecture that segments PHI and logs every access, the encryption and access-control engineering, and the remediation backlog a risk analysis produces, delivered through our cybersecurity and healthcare software development practices. Austin leads scope the work on US hours; Bangalore and Mohali engineers clear the backlog. We run production data systems ourselves (Shield Suite tracks retail intelligence across 60,000+ beverage-alcohol storefronts), so audit trails and access control are how we operate, not a slide.
If a consultant’s findings report is sitting on your desk, or a hospital customer just asked for proof you can’t produce yet, tell us what your stack looks like. We’ll come back within 48 hours with a straight answer on what the technical fixes cost and what order to do them in.