For healthcare providers, health plans and the business associates that serve them, HIPAA compliance is no longer a paperwork exercise. Regulators are focused on whether you have actually analyzed and managed your security risks, and ransomware has made the consequences of getting it wrong far more visible. A good HIPAA consultant helps you meet the requirements and genuinely reduce risk. A poor one leaves you with binders of templates.
This guide explains what a HIPAA compliance consultant does, seven criteria for choosing one, typical engagement scope and timeline, and how AI changes the picture.
What a HIPAA compliance consultant does, and doesn't do
A HIPAA consultant helps covered entities and business associates meet the HIPAA Privacy, Security and Breach Notification Rules. Typical work includes:
- Security Rule risk analysis and a risk management plan.
- Policies and procedures for privacy, security and breach response.
- Technical safeguard reviews: access control, audit logging, encryption, backup and multi-factor authentication.
- Business associate agreement (BAA) review and vendor oversight.
- Workforce training and incident response planning.
- Preparation for audits, payer reviews and Office for Civil Rights (OCR) investigations.
What a consultant doesn't do is certify you. There is no official government HIPAA certification. Be wary of anyone selling one.
Security Rule risk analysis: the non-negotiable deliverable
The HIPAA Security Rule requires an accurate and thorough assessment of the risks to electronic protected health information (ePHI) at 45 CFR 164.308(a)(1)(ii)(A). It is also the requirement most often cited in enforcement. HHS's Office for Civil Rights has run a dedicated risk analysis enforcement focus, and many recent settlements involve organizations that never completed an adequate one. Any consultant you hire should put a real, enterprise-wide risk analysis at the center of the engagement.
7 criteria for choosing a HIPAA consultant
- Healthcare experience: have they worked with organizations like yours, such as a physician group, hospital, health plan, health-tech vendor or business associate?
- Security depth: can they assess technical controls, not just policies? Ransomware and access failures are security problems first.
- Risk analysis method: do they follow recognized guidance such as NIST SP 800-66 Revision 2 and cover all systems that hold ePHI, including cloud and vendors?
- Remediation support: will they help fix what they find, or only report it?
- Vendor and BAA oversight: can they help you assess business associates and manage the risk they bring?
- Evidence and documentation: will you end up with documentation that stands up to an OCR inquiry?
- Ongoing support: HIPAA risk analysis must be kept current. Ask how they support annual reviews and changes.
No CISO, growing risk? Senior practitioners assess your posture, prioritise the fixes that matter, and give you a roadmap you can defend to the board and your auditors. Book a security posture review →
Typical engagement scope and timeline
- Weeks 1–4: discovery and risk analysis. Inventory the systems, data flows and vendors that handle ePHI, then assess threats, vulnerabilities and existing safeguards.
- Weeks 4–8: risk management plan and policies. Prioritize risks, assign owners and update policies and procedures.
- Weeks 8–16 and beyond: remediation. Implement technical and administrative safeguards, train staff and test incident response.
- Ongoing: periodic risk analysis updates, vendor reviews and evidence maintenance.
Cost depends on the number of locations, systems and vendors, and on how much remediation help you need. A scoped risk analysis is the best first step, because it defines the remediation work.
The Security Rule update: where it stands
HHS proposed significant changes to the HIPAA Security Rule in January 2025, including more prescriptive requirements for asset inventories, multi-factor authentication, encryption and testing. As of 2026, the proposal has been moved to HHS's long-term agenda, with final action anticipated around July 2027. The existing rule still applies in full, and many of the proposed controls, such as multi-factor authentication and tested backups, are already expected as good practice.
HIPAA and AI: governing clinical and administrative AI tools
AI scribes, coding assistants, chatbots and analytics tools increasingly process ePHI. A HIPAA consultant should help you check whether AI vendors sign BAAs, where data is processed and retained, whether data is used to train models, and how outputs are logged and reviewed. For a wider view, see our guides to AI governance in healthcare and MFA and healthcare data breaches.
Frequently asked questions
What does a HIPAA compliance consultant do?
A HIPAA consultant helps healthcare organizations and business associates complete a Security Rule risk analysis, manage the risks it finds, update policies, oversee vendors, train staff and prepare documentation for audits or investigations.
Is there an official HIPAA certification?
No. HHS does not certify organizations as HIPAA compliant. Consultants and auditors can assess your compliance, but no official government certification exists.
How often should a HIPAA risk analysis be done?
HIPAA requires it to be accurate and current. Most organizations review it at least annually and whenever there are significant changes to systems, vendors or operations.
Has the HIPAA Security Rule been updated?
HHS proposed updates in January 2025. As of 2026 they have not been finalized, and HHS's agenda anticipates final action around July 2027. The existing Security Rule remains in force.
Key takeaways
- A HIPAA consultant should center the engagement on a thorough Security Rule risk analysis, the most commonly cited enforcement failure.
- Choose on healthcare experience, security depth, risk analysis method, remediation support, vendor oversight, documentation and ongoing support.
- There's no official HIPAA certification; avoid anyone selling one.
- The proposed Security Rule update is delayed, but the current rule still applies and many proposed controls are already best practice.
- Include AI tools that process ePHI in your risk analysis and vendor reviews.

