When to hire one, what to ask before you sign, and the four answers that should end the conversation.
What a consultant actually does
A HIPAA compliance consultant builds or repairs the parts of a programme that require judgement: scoping which systems and entities are covered, running the risk analysis, writing policies that describe your real operations, designing the remediation plan, and preparing you for whatever audience is coming — OCR, an enterprise customer’s security team, or a cyber insurer. The good ones leave you with a programme your own people can run. The bad ones leave you with a PDF and a renewal quote.
It is worth being clear about what no consultant can do: certify you. HHS operates no certification programme, and “HIPAA certified” is a marketing phrase, not a regulatory status. What a credible consultant delivers instead is a documented, defensible programme — which is the thing certification pretends to be.
When a consultant is the right call
First-time program build, post-incident remediation, an enterprise deal blocked in security review, or an internal team without healthcare-specific experience.
Each of those has a distinct urgency profile. A first-time build benefits from a consultant because sequencing errors are expensive — remediating before assessing, or writing policies before the risk analysis, means doing work twice. Post-incident, the calculus changes: OCR expects to see corrective action, and outside expertise both accelerates it and signals seriousness (loop in counsel here too — a consultant is not a lawyer). A blocked enterprise deal is the most common trigger we see in health tech: the questionnaire arrives, the gaps are real, and the deal clock is running. And a generalist security team without healthcare experience tends to over-build the technical safeguards while missing the administrative ones — which is where most findings live.
When is a consultant the wrong call? When the gap is maintenance rather than expertise. If you know what needs doing and simply lack hands or reminders, you have a tooling and ownership problem, and paying consulting rates for it is the most expensive possible fix.
Questions to ask
Who specifically does the work? What is the fixed fee and what expands it? What do we own at the end? Will you validate remediation afterwards? Have you handled our entity type and our vertical?
Why each question matters:
- Who does the work? Firms sell partners and staff juniors. Ask for the named individuals, their healthcare background, and how much of the engagement is templated versus bespoke.
- What is fixed and what expands? A scoped assessment should be fixed fee. Ask specifically what discoveries change the price — additional entities, additional systems — so surprises are contractual rather than emotional.
- What do we own? You want the risk register in an editable format, policies in DOCX, and the working files — not just the report. Deliverables you cannot edit are deliverables you will pay to update.
- Will you validate remediation? An assessment without a follow-up re-test leaves you holding a list of findings and no proof you closed them.
- Our entity type, our vertical? A consultant who has only done hospital work will misjudge a 30-person digital health startup, and vice versa. Covered entity and business associate obligations differ in ways that matter.
Answers that should end the conversation
‘We’ll make you HIPAA certified.’ ‘The risk analysis is a questionnaire.’ ‘Pricing depends on your budget.’ ‘You keep the report but not the working files.’
The first is disqualifying because it is false — see above. The second is disqualifying because §164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of risks to ePHI, and a questionnaire score is neither asset-based nor threat-paired; it would be the first thing a real reviewer rejected. The third means pricing is anchored to your willingness to pay rather than the work. The fourth means you are renting your own compliance programme.
What engagements cost
Ranges vary with entity count, system count, and how much remediation the consultant executes versus recommends — the cost guide breaks down typical figures for gap assessments, risk analyses, and implementation engagements. The general shape: assessments are the cheap end, implementation is the expensive end, and retainers for fractional compliance-officer arrangements sit in between. Whatever the number, insist on seeing the deliverables list before the price makes sense.
Consultant versus platform
A consultant gets you to a point in time. A platform keeps you there. Programs that buy only the first re-buy it every two years.
The failure mode is predictable: the engagement ends, the binder is current for one proud quarter, then training lapses, a vendor is added without a BAA, two employees leave with their access intact, and by the next customer audit the binder describes an organisation that no longer exists. The durable arrangement is consultant for judgement, platform for persistence — the assessment and design bought once, the acknowledgement tracking, renewal reminders, and evidence collection running continuously. That is the model behind our services and platform pairing, and it is worth demanding from whoever you hire.
Getting value once you have hired
The engagements that disappoint rarely fail on consultant quality; they fail on client preparation and handover. Three practices change the outcome. First, do the cheap discovery yourself before the clock starts: run the free readiness assessment, gather your existing documents however embarrassing, and draft the systems list — every hour a consultant spends extracting basics from your team is billed judgement spent on inventory work. Second, assign an internal counterpart with real hours, not a distracted executive sponsor; the counterpart is who the knowledge transfers to, and without one the engagement’s understanding leaves in the consultant’s laptop. Third, insist the final session be a handover, not a presentation — your team walking through the risk register and the maintenance calendar, with the consultant correcting, is worth more than any slide deck.
And schedule the ending deliberately. A good engagement finishes with three artefacts in your hands: the working files, a remediation plan with owners and dates that survive the consultant’s departure, and a defined re-engagement trigger — the annual review, a material change, an incident — so the relationship becomes periodic and cheap rather than continuous and expensive. Consultants worth hiring will propose this structure themselves; it is a reliable final filter. One last calibration: the goal of the engagement is not a perfect programme but a programme your organisation can sustain at its real staffing level — a consultant who designs for the team you have, rather than the team a hospital has, is delivering the version that will still be running in two years.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.