What a HIPAA Compliance Consultant Does
A HIPAA consultant runs the Security Rule risk analysis, maps where PHI actually lives, closes gaps across the three safeguard categories, and produces the documentation you would need to show a regulator. The risk analysis is not one deliverable among many — it is the specific item OCR asks for first, and its absence appears in enforcement action after enforcement action.
The work splits across the safeguards the Security Rule defines:
| Safeguard | What it covers | Where organizations fail |
|---|---|---|
| Administrative | Risk analysis, workforce training, sanctions, contingency planning | Risk analysis missing, outdated, or never repeated |
| Physical | Facility access, workstation use, device and media controls | Device disposal with no record |
| Technical | Access control, audit controls, integrity, transmission security | Encryption gaps and unlogged access to ePHI |
Read the detail in HIPAA safeguards explained.
There Is No HIPAA Certificate
Worth stating plainly because much of this market implies otherwise. HHS does not certify anyone. There is no register, no accreditation body, and no certificate that makes you HIPAA compliant.
What exists is an independent assessment against the HIPAA Rules and your own documented evidence that you performed the required activities. That is what you show a customer, an auditor, or OCR. If a vendor offers a "HIPAA certificate", you are buying their attestation — which can still be useful for a sales conversation, provided everyone understands what it is and is not.
Avantcert produces the assessment and the evidence package. We do not issue a certificate, because there is no such thing to issue.
Covered Entities and Business Associates
Covered entities are health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically.
Business associates are any vendor that creates, receives, maintains or transmits PHI on a covered entity's behalf — hosting providers, analytics vendors, billing companies, and most software companies selling into healthcare. Since the HITECH Act, business associates are directly liable, not merely contractually obliged. A great many SaaS companies discover this the first time a health system sends them a BAA.
Subcontractors of business associates are also captured. The obligation flows down the chain the same way the data does.
Our HIPAA Engagement
1. PHI mapping and scoping. Where PHI enters, where it rests, where it leaves, and which systems and vendors touch it.
2. Security Rule risk analysis. The required assessment, documented so it stands up to scrutiny rather than sitting in a spreadsheet nobody signed.
3. Gap remediation. Administrative, physical and technical safeguards, prioritized by risk rather than by how easy they are to close.
4. Policies and procedures. The full policy set, plus breach notification procedures you could actually follow under pressure.
5. BAA review. Agreements with every vendor that touches PHI, and with your own customers where you are the business associate.
6. Workforce training. Delivered and evidenced, because the Security Rule requires it and untrained staff are the most common breach vector.
Cost and Timeline
Avantcert engagement ranges, already discounted 30–50% below typical market rates. No certification body fee, because there is no certificate.
| Tier | Employees | Avantcert engagement | Max duration |
|---|---|---|---|
| Startup | 5–50 | from $3,000 | 60 days |
| Mid-Market | 51–200 | around $7,500 | 60 days |
| Large Enterprise | 201–500 | up to $12,000 | 60 days |
See the full HIPAA compliance cost breakdown or how long HIPAA compliance takes.
Get a Scoped HIPAA Quote
Tell us whether you are a covered entity or a business associate, and roughly where PHI sits. Scoped estimate within 24 hours.
Our form could not load. Email your role and PHI scope and you'll get the same estimate within 24 hours.
Email your requirements Open the full quote formWhen You Actually Need HITRUST
HIPAA is a legal obligation. HITRUST is a certifiable framework, and it is what many health systems ask for when they want something verifiable rather than an assurance.
| HIPAA | HITRUST | |
|---|---|---|
| Nature | Legal obligation | Voluntary certification |
| Certificate | None exists | Yes, issued by HITRUST |
| Typical trigger | You handle PHI | A health system requires it in procurement |
| Avantcert engagement | $3,000–$12,000 | $25,000–$90,000 |
You cannot substitute HITRUST for HIPAA obligations — but HITRUST is frequently what unlocks the contract. See HIPAA vs HITRUST or HITRUST certification services.
HIPAA Consultant FAQs
What does a HIPAA compliance consultant do?
A HIPAA consultant runs the Security Rule risk analysis, maps where PHI lives, closes gaps across the administrative, physical and technical safeguards, writes the policy set, reviews your Business Associate Agreements, and puts workforce training and breach procedures in place. The risk analysis is the specific item regulators ask for first.
Is there such a thing as HIPAA certification?
No. HHS does not certify anyone, and no certificate confers compliance. What exists is an independent assessment against the HIPAA Rules, plus your own documented evidence. If a vendor sells you a "HIPAA certificate", what you are buying is their attestation, not a government recognition.
Who has to comply with HIPAA?
Covered entities — health plans, healthcare clearinghouses and most healthcare providers — and their business associates, meaning any vendor that creates, receives, maintains or transmits PHI on their behalf. Software companies serving healthcare customers are almost always business associates, and the obligation reaches them directly.
How much does HIPAA compliance cost?
Avantcert HIPAA engagements run from $3,000 for a 5–50 employee organization, around $7,500 at 51–200, and up to $12,000 at 201–500 or complex scope, within a 60-day maximum. There is no certification body fee because there is no HIPAA certificate.
What is a HIPAA risk analysis?
A documented assessment of the risks to the confidentiality, integrity and availability of the electronic PHI you hold. It is explicitly required by the Security Rule, it is the first document requested in an OCR investigation, and its absence is one of the most commonly cited failures in enforcement actions.
Do I need HIPAA or HITRUST?
HIPAA compliance is a legal obligation if you handle PHI. HITRUST is a certifiable framework some healthcare buyers require as proof. You cannot substitute HITRUST for HIPAA obligations, but a HITRUST certification is often what unlocks a health-system contract, because it gives their procurement team something to verify.
Free HIPAA Checklist
Download our free HIPAA pre-audit checklist, 43 audit-ready items covering all three safeguard categories, as a print-friendly PDF and an editable CSV tracker. No cost.
Official reference: HHS, HIPAA Security Rule.
Start with the risk analysis
The document regulators ask for first, done properly. See our HIPAA risk assessment for the document OCR asks for first. Comparing providers? See our roundup of HIPAA compliance consultants and the seven criteria worth judging us all against.