Security & Compliance

HIPAA Compliance Consulting: What You Get and What It Costs

11 min read

A HIPAA compliance consultant does six concrete things: runs a gap assessment against the Privacy and Security Rules, performs the security risk analysis regulators expect to see on paper, writes your policies and procedures, builds a business associate agreement (BAA) program, trains your workforce, and hands you a remediation roadmap ranked by risk. The money sorts into three shapes: hourly advice at $250 to $350 an hour, project work from $2,000 for a basic gap review up to $40,000 for a full readiness assessment, and ongoing retainers. That’s the whole market, minus the parts that are theater.

We’re gmware, a custom software development firm headquartered in Austin, TX with engineering centers in Bangalore and Mohali, India. Healthcare builds are part of our delivery history, and we’ve written before about what a HIPAA-compliant application actually requires in the code. This post is the other half of that conversation: what happens when you hire outside help for the compliance program itself, what each engagement shape costs with sources, and the one claim that should make you close the tab on any vendor (“get HIPAA certified!”) because no such certification exists.

What does a HIPAA compliance consultant actually do?

Strip the proposals down and nearly every engagement is some bundle of the same six deliverables.

Gap assessment. A structured walk through the Privacy Rule, Security Rule, and Breach Notification Rule against what your organization actually does. Not what the binder says. What the front desk does at 4:55pm on a Friday when a records request comes in.

Security risk analysis. This is the load-bearing deliverable. The Security Rule requires covered entities and business associates to conduct a risk assessment identifying where electronic PHI lives and what threatens it. It’s also the thing OCR keeps fining people for skipping, which we’ll get to.

Policies and procedures. The written rules your staff can be held to: access authorization, sanctions, incident response, contingency plans. A consultant’s real value here isn’t the documents, it’s tailoring them so they describe your actual workflows instead of a fictional hospital’s.

BAA program. An inventory of every vendor that creates, receives, maintains, or transmits PHI on your behalf, and a signed agreement with each. The vendor list is always longer than the client expects. The email tool. The answering service. The IT guy’s monitoring software.

Workforce training. Required, recurring, and cheap to do properly: e-learning runs $20 to $80 per employee per year.

Remediation roadmap. The ranked to-do list that comes out of the first two items. Good consultants rank by risk and cost. Weak ones hand you 90 undifferentiated findings and an invoice.

Ongoing retainers repeat the cycle: annual risk analysis updates, policy reviews, training refreshes, and support if an audit letter or breach shows up.

What HIPAA compliance consulting costs in 2026

Here’s the engagement-cost table, every range sourced. The spread inside each line is scope: how many locations and systems you run, and how much PHI your operation actually touches.

Engagement shapeWhat you getSourced 2026 range
Hourly advisoryQuestions answered, contracts reviewed, incident triage$250 to $350/hour
Gap analysis + risk assessment + risk management planWhere you stand, what’s exposed, what to fix first$2,000 to $25,000
Third-party risk assessment, small orgThe documented SRA, done by an outside firm$5,000 to $20,000
Full external readiness assessmentAudit-style review across all three rules$15,000 to $40,000
Full program stand-up, small practiceAssessment through policies, BAAs, and training$6,000 to $35,000 initial
Full program stand-up, mid-size orgSame, at 50 to 500 staff scale$80,000 to $450,000 initial
Ongoing program, small practiceAnnual SRA refresh, training, policy upkeep$3,500 to $18,000/year
Ongoing advisory retainerStanding access to a consultant$2,000 to $5,000/year at the light end

Notice what’s missing from the table: remediation. The assessment tells you the server closet has no access log and the billing vendor never signed a BAA. Fixing those is engineering and legal work priced separately, and it’s routinely the biggest number in the whole project. Any consultant who quotes “compliance” as one flat fee without asking what your stack looks like is guessing, the same way a flat-fee pen test quote is a guess.

If you’re budgeting an engagement right now, tell us what systems touch PHI and we’ll give you a straight read on which shape fits and what the remediation half is likely to run.

Why the risk analysis is the deliverable that matters

Because it’s the one OCR checks first. In the first five months of 2025, OCR announced ten HIPAA resolution agreements with fines from $25,000 to $3 million, and the recurring defect across that enforcement run was the same: no accurate and thorough risk analysis. Not exotic attacks. Paperwork nobody did.

The penalty math behind those settlements is unfriendly. The 2026 civil tiers run from $145 per violation at the lowest tier to $73,011 per violation for uncorrected willful neglect, with an annual cap of $2,190,294 per provision. And the exposure is not hypothetical: 772 large healthcare breaches were reported in 2025, affecting roughly 138.5 million people, a new annual record for breach count.

So when you evaluate a consultant, put weight on how they do the SRA. Ask to see a sanitized sample. If it reads like a generic questionnaire with your logo on it, that’s what OCR will think too.

There is no official HIPAA certification

Here’s the honest-verdict section, and it cuts against a chunk of the industry. HHS answers the certification question directly: there is no standard or implementation specification that requires a covered entity to certify compliance. No federal body issues a HIPAA certificate, and no private seal binds a regulator. Even vendors who sell certification programs concede the point: certification is not a requirement of HIPAA, and it’s a voluntary process that at best demonstrates good-faith effort.

That doesn’t make every badge worthless. Documented third-party review is real evidence of effort, and effort matters at penalty-tier time. But it reframes what you’re buying. You’re buying the work, not the sticker. Which suggests a short red-flag list for shopping:

  • “Become HIPAA certified in 48 hours.” There’s nothing official to become, and a two-day turnaround means templates that weren’t tailored to how your PHI actually moves.
  • A price quoted before any scoping questions. If they never asked what touches PHI, the number is fiction.
  • A “compliance guarantee.” Nobody can guarantee an OCR outcome. A consultant who promises one is writing a check your organization cashes.
  • No sample SRA. The core deliverable should survive inspection before you sign.
  • Silence on remediation. If the proposal ends at “findings report,” ask who fixes the findings, because that’s where the money and the risk both live.

One more thing, since HIPAA is law and we are not lawyers: for the legal questions an engagement surfaces (breach notification decisions, state-law overlays, BAA negotiation with a stubborn vendor), have your counsel in the loop. A good consultant will say that themselves.

Consultant, compliance software, or DIY: match the tool to the problem

The three paths aren’t really competitors. They solve different halves of the problem, and the right answer for most small organizations is a blend. Here’s the decision matrix we’d use.

DIY + free HHS toolsCompliance softwareConsultant
Cash costFree SRA Tool + $20 to $80/employee training$1,200 to $6,000/year, small org$2,000 to $40,000 per project
Real costYour time, and the risk of blind spotsSetup effort plus someone to own itThe fee, plus remediation
SRA qualityAs good as the person driving the toolStructured, but self-reportedIndependent and defensible
PoliciesGeneric unless you rewrite themTemplated, lightly tailoredWritten to your actual workflows
Fixes the gapsNoNoSometimes, if they have engineers
Best forTiny practice, simple stack, a diligent ownerTeams that need continuous evidence and remindersFirst-time programs, audits, breach recovery, complex vendor chains

The pattern that works in practice: a consultant (or a capable internal owner) for the first risk analysis and policy set, software to keep evidence and reminders alive afterward, and engineering help scoped separately for whatever the SRA turns up. It’s the same division of labor we described for SOC 2, where Vanta-style platforms watch and engineers change things. The platform never closes its own findings. Someone has to.

How to scope the engagement so you don’t overpay

Five questions before you sign anything.

  1. What’s in scope? Sites, systems, vendors, and which rules (Security only, or Privacy and Breach Notification too). Scope creep in compliance runs downhill into your invoice.
  2. What are the named deliverables? You want the SRA document, the risk management plan, the policy set, the BAA inventory, and the ranked roadmap listed in the SOW by name.
  3. Who does the remediation, and at what rate? Some firms assess and disappear. Some assess and upsell. Know which one you’re hiring before the findings arrive.
  4. How do they handle the technical safeguards? Encryption, access controls, and audit logging are engineering, not paperwork. If the consultant has no engineers, plan for a second vendor. Our walkthrough of the five technical safeguards shows what that half of the work involves.
  5. What happens next year? A risk analysis is a snapshot. Ask what the annual refresh costs before the first engagement ends, not after.

A worked example, since abstractions hide the math. A three-provider dermatology practice with one EHR, a billing vendor, and a patient-texting app should expect the low end: a $5,000 to $20,000 third-party SRA or a package inside the $6,000 to $35,000 small-practice stand-up range, not a $100K enterprise review. A 40-person healthtech startup with PHI in three cloud services and a hospital customer demanding proof sits higher, and honestly gets more value from pairing a lean assessment with real remediation engineering than from a thicker report. Already holding a quote and unsure if it’s sane? Send it over and we’ll tell you what we see.

When you don’t need a consultant

Three situations where we’d tell you to keep your money, and we build compliance-adjacent software for a living.

You’re small, simple, and diligent. HHS built its free Security Risk Assessment Tool specifically for small and medium providers. A solo practice with one EHR and a short vendor list, plus an owner willing to spend a few evenings on it, can produce a legitimate SRA with it. Add cheap training and you have a defensible baseline program.

You haven’t done the basics. If laptops aren’t encrypted and there’s no MFA on the EHR, a $25,000 assessment will mostly tell you that. Close the obvious gaps first, then pay someone to find the non-obvious ones. We made the same argument about cybersecurity consulting generally: hygiene first, advice second.

You might not be covered by HIPAA at all. A wellness app that never touches a covered entity usually falls outside HIPAA entirely, under FTC rules instead. Don’t buy a HIPAA program to feel safe; check whether the law even applies. When it does apply and you’re moving infrastructure, note that the bar is rising: the updated Security Rule proposal puts a January 1, 2027 compliance date on mandatory MFA and encryption, which changes what any assessment this year should measure against.

Where gmware fits

We’re not a compliance-certification shop, and after the section above you know why we’re fine with that. What we do is the technical-safeguards half of HIPAA work: the architecture that segments PHI and logs every access, the encryption and access-control engineering, and the remediation backlog a risk analysis produces, delivered through our cybersecurity and healthcare software development practices. Austin leads scope the work on US hours; Bangalore and Mohali engineers clear the backlog. We run production data systems ourselves (Shield Suite tracks retail intelligence across 60,000+ beverage-alcohol storefronts), so audit trails and access control are how we operate, not a slide.

If a consultant’s findings report is sitting on your desk, or a hospital customer just asked for proof you can’t produce yet, tell us what your stack looks like. We’ll come back within 48 hours with a straight answer on what the technical fixes cost and what order to do them in.

  • hipaa compliance
  • compliance consulting
  • healthcare security
FAQ

Common questions, answered

What does a HIPAA compliance consultant actually do?
Six things, typically in one engagement: a gap assessment against the Privacy and Security Rules, the security risk analysis OCR expects to see documented, written policies and procedures, a business associate agreement program covering every vendor that touches PHI, workforce training, and a prioritized remediation roadmap. Ongoing retainers add annual risk analysis updates, training refreshes, and audit support.
How much does HIPAA compliance consulting cost?
Consultants bill roughly $250 to $350 an hour. Packaged another way: gap analysis, risk assessment, and risk management planning run $2,000 to $25,000, a full external readiness assessment runs $15,000 to $40,000, and a small practice typically spends $6,000 to $35,000 to stand up a program, then $3,500 to $18,000 a year to keep it running. Mid-size organizations spend far more.
Is there an official HIPAA certification?
No. HHS states there is no standard or implementation specification that requires a covered entity to certify compliance, and no government body issues or recognizes a HIPAA certificate. Vendors selling 'HIPAA certified' status are selling their own private badge. It can be useful as evidence of effort, but it does not bind OCR, and treating it as proof of compliance is how organizations get surprised.
Can compliance software like Vanta or Drata replace a HIPAA consultant?
It replaces the tracking, not the judgment or the engineering. A platform will template your policies, monitor controls, and store evidence for $1,200 to $6,000 a year at small-org scale. It won't decide what's in scope, tailor policies to how your office actually works, negotiate BAAs, or fix the technical gaps it finds. Most teams that succeed pair software for upkeep with targeted expert help for setup.
Does a small medical practice need a HIPAA consultant?
Not always. HHS publishes a free Security Risk Assessment Tool built specifically for small and medium providers, and a disciplined office manager can get a basic program standing with it plus low-cost training at $20 to $80 per employee per year. Bring in a consultant when you've had a breach scare, an audit letter, a complex vendor chain, or nobody internally who will actually own the work.
What happens if we skip the security risk analysis?
It's the single failure OCR keeps penalizing. In the first five months of 2025 alone, OCR announced ten resolution agreements with fines from $25,000 to $3 million, and the missing or inadequate risk analysis sat at the center of that enforcement push. Penalty tiers for uncorrected willful neglect start at $73,011 per violation, with an annual cap of $2,190,294 per provision.

See it on your own data.

Book a 30-minute discovery call and we'll walk through your use case.