9 Questions to Ask Before You Hire a HIPAA Remediation Company
Aug 25, 2026, 4:49:47 PM Emily Zaczynski 13 min read
If you are vetting a HIPAA remediation partner right now, there is a good chance you are doing it under pressure. Maybe an audit notice landed with a thirty-day deadline. Maybe a breach exposed gaps you did not know you had, or a payer contract suddenly asks for proof of compliance you cannot produce. Whatever brought you here, the feeling tends to be the same. The rules are dense, the stakes are high, and the provider you have been paying for years cannot tell you where patient data lives, who can access it, or what to fix first.
- Why an Urgent Timeline Changes Everything
- The 9 Questions
- What Sets the Right Consultant Apart
- Match the Consultant's Experience to Your Environment
- The Cost of Getting This Wrong
- Why Continuous Monitoring Matters
- How CompassMSP Answers These Nine Questions
That uncertainty is completely normal. HIPAA compliance is genuinely confusing, even for experienced healthcare leaders, and the consequences of getting it wrong are serious enough to keep anyone up at night. The reassuring part is that the right partner can make sense of it with you. A good consultant turns a wall of requirements into a clear sequence of fixes and helps you walk into an audit with evidence in hand instead of anxiety.
This guide is built to help you find that partner. Below are nine questions that separate consultants who understand urgent healthcare compliance from those running generic IT audits with HIPAA language attached. Whether you run a single clinic or a growing multi-site system, the questions are the same. The answers will tell you very quickly who has done this work before.
A good consultant turns a wall of requirements into a clear sequence of fixes and helps you walk into an audit with evidence in hand instead of anxiety.
Why an Urgent Timeline Changes Everything
Most HIPAA compliance conversations assume you have time. Time to assess, time to document, time to phase in controls. A short remediation window strips that assumption away. You need a partner who knows where to look first, what auditors actually review, and how to sequence fixes so the critical gaps close before the deadline arrives.
The difference between a consultant who can deliver under a tight timeline and one who cannot usually shows up in the first conversation. Consultants who have done this work before ask specific questions about your environment. Consultants who have not tend to open with a slide deck.
That’s why I put together 9 questions to help you find a HIPAA Remediation company you can trust to do the job right the first time.
The 9 Questions
1. What is your methodology for completing a HIPAA risk assessment quickly?
A risk assessment is a legal requirement, not a nice-to-have. Under 45 CFR Section 164.308(a)(1), covered entities must conduct a thorough assessment of potential risks to electronic protected health information (ePHI). In practice, that means mapping ePHI flows across every site, every connected device, and every third-party integration that touches patient data.
Ask how the consultant prioritizes when time is short. A strong answer describes a structured approach that tackles the highest-risk systems first rather than a promise to audit everything at once. Ask to see a sample deliverable from a comparable healthcare client so you can judge the quality of the work before you commit.
2. How do you handle medical device security?
Healthcare organizations of every size run legacy imaging equipment, infusion pumps, and patient monitoring devices that manufacturers will never patch. A consultant who only discusses endpoint protection is describing a different network than yours.
Look for answers that address network segmentation, passive traffic monitoring for devices that cannot be managed directly, and coordination with your biomedical engineering team. The HIPAA Security Rule update that HHS proposed in December 2024 would require network segmentation for systems that contain ePHI. That rule is still proposed rather than final, but it signals where federal expectations are clearly heading. A consultant who cannot speak to isolating medical devices has not spent enough time in clinical environments.
3. What does your remediation roadmap look like, and how do you sequence fixes?
A tight timeline forces prioritization. Ask how the consultant ranks findings and what criteria decide which gaps close first. The answer should weigh regulatory severity, exploitability, and business impact.
A strong consultant delivers a prioritized remediation roadmap rather than a flat list of findings. They can explain which controls need to be in place before an audit and which can follow as ongoing improvements. If clinical operations cannot pause while gaps close, the roadmap should account for that too.
4. How do you document compliance controls for OCR?
When the Office for Civil Rights evaluates an organization, it looks at documentation. Written policies, audit logs, training records, risk assessment history, and evidence that remediation actually happened all carry far more weight than good intentions.
Ask what artifacts the consultant produces, how they organize evidence, and whether they have supported a client through an actual OCR investigation. A consultant who deflects toward a monitoring sales pitch has not faced the documentation rigor an audit demands.
5. Who specifically owns HIPAA compliance on our account?
Senior consultants close contracts. Junior staff often service them. Ask who will lead your compliance program, what their credentials are, and what happens when that person changes roles.
For healthcare organizations without a dedicated compliance officer, the consultant's internal ownership structure effectively becomes your compliance function, so it deserves real scrutiny. A named lead with healthcare credentials is very different from a rotating support queue.
6. How do you verify subcontractor HIPAA compliance?
A consultant can maintain strong internal controls while quietly routing your PHI through a third-party data center, network operations center, or cloud platform that does not. Under 45 CFR Section 164.314(a), business associates must ensure their subcontractors protect ePHI with equivalent safeguards.
Ask to see the full subcontractor list and the complete business associate agreement chain. The gap here is well documented. In OCR's most recent completed HIPAA audit program, which covered 2016 and 2017 and was reported in 2020, only 17 percent of audited business associates and 14 percent of covered entities were substantially fulfilling their responsibility to safeguard ePHI through risk analysis. Consultants who understand that risk raise it before you have to.
7. What does ongoing compliance monitoring look like after remediation?
Passing one audit and staying compliant are two different accomplishments. Ask how the consultant supports continuous monitoring, quarterly access reviews, and policy updates as regulations change.
The proposed 2025 HIPAA Security Rule update would require covered entities to restore critical systems within 72 hours of an incident and to maintain exact backup copies of ePHI. Business associates would also need to notify covered entities within 24 hours of activating a contingency plan. Even though the rule is not yet final, those expectations point toward controls that require ongoing verification, testing, and documentation. A consultant who only offers project-based engagements leaves you exposed the day after the audit closes.
8. What is your ransomware response capability, and can you show me the runbook?
A JAMA Health Forum study found that ransomware attacks on healthcare delivery organizations more than doubled between 2016 and 2021, and that 44 percent of those attacks disrupted care delivery, including ambulance diversions and electronic health record downtime.
Ask to see the incident response runbook rather than simply hear that one exists. A strong answer includes documented procedures for network isolation, forensic evidence preservation, clinical downtime activation, and regulatory notification timelines. A consultant who pivots to prevention messaging when you ask about response has not been tested.
9. How do you coordinate HIPAA compliance with broader IT strategy?
Compliance does not live in a silo. Your HIPAA program intersects with network architecture, cloud migration plans, vendor management, and daily IT operations. A consultant who treats compliance as separate from IT strategy creates friction your teams cannot afford.
The best partners align remediation with your technology roadmap so the two reinforce each other instead of competing. That coordination is often what makes an aggressive timeline achievable without disrupting patient care.
What Sets the Right Consultant Apart
The consultants who deliver under pressure share a few habits. They ask detailed questions about your environment before proposing solutions. They produce documentation that auditors can actually follow. They name specific systems, timelines, and accountability structures rather than describing capabilities in the abstract.
The warning signs are just as consistent. A consultant who generalizes, who redirects to a product demo when your questions get specific, or who cannot produce a sample deliverable from a comparable client has already shown you what kind of partner they will be.
Match the Consultant's Experience to Your Environment
A single clinic and a twenty-site health system face different compliance realities, and the right partner scales to either. Multi-location environments add complexity through multiple EHR instances, multiple network configurations, multiple physical access control systems, and policies that may not align from site to site. Smaller and single-site organizations face their own version of the challenge, often carrying the same regulatory obligations with a fraction of the internal staff to meet them.
Ask whether a consultant has led remediation for organizations similar to yours in size and structure. Ask how they standardize controls without disrupting the workflows your clinical staff depend on. The answer reveals whether they have done this work or only read about it.
The Cost of Getting This Wrong
HIPAA penalties scale with culpability. Under the 2025 inflation-adjusted amounts, a single violation can run from $145 to $73,011, and repeated violations of the same requirement can reach an annual cap of roughly $2.19 million per category. Willful neglect that goes uncorrected sits at the top of that range.
The operational cost often runs higher than the fines. Healthcare has been the most expensive industry for data breaches for fourteen consecutive years, with the average incident reaching $7.42 million in IBM's 2025 Cost of a Data Breach Report and taking 279 days to identify and contain. Behind those numbers sit diverted ambulances, delayed procedures, extended EHR downtime, and the patient trust that erodes when care delivery fails. This is exactly why a reactive posture has become the most expensive line item in healthcare. A tight remediation timeline leaves no room for trial and error, and the consultant you select either knows how to deliver under pressure or they do not. The questions above will tell you which one you are talking to.
Why Continuous Monitoring Matters
Ongoing compliance monitoring earns its keep by giving you visibility into the risks that auditors and threat actors both look for. Done well, continuous monitoring surfaces access control gaps before they become breaches, catches policy drift before it becomes audit exposure, and keeps documentation current so your team is never scrambling before a deadline. It is the difference between treating HIPAA as a recurring crisis and treating it as a stable, defensible program.
How CompassMSP Answers These Nine Questions
If the nine questions above describe what a strong partner looks like, here is how CompassMSP answers each one.
- Rapid risk assessment (Question 1): We run a structured HIPAA Security and Privacy Risk Analysis that maps ePHI across your systems, workflows, and devices, and we tackle the highest-risk exposures first so a tight timeline stays realistic.
- Medical device security (Question 2): We address clinical devices that cannot be patched or managed directly through network segmentation and traffic monitoring, coordinating with your biomedical engineering teams rather than relying on endpoint tools alone.
- Prioritized remediation roadmap (Question 3): We deliver a remediation roadmap that sequences fixes by audit risk and operational disruption, so critical gaps close before the deadline while clinical staff keep working.
- OCR-ready documentation (Question 4): We translate findings into a risk register, a prioritized remediation plan, and audit-ready evidence, including policies, logs, and training records that stand up to an OCR review.
- Named accountability (Question 5): Every engagement gets a named compliance lead with healthcare credentials, backed by vCISO advisory, giving you a single point of accountability from assessment through audit.
- Subcontractor and vendor oversight (Question 6): We review your business associate agreements and third-party data pathways so a subcontractor's gap does not quietly become your breach.
- Continuous monitoring (Question 7): We validate controls year-round through recurring assessments and technical validation, keeping you audit-ready after the deadline passes rather than only in the weeks before it.
- Ransomware response (Question 8): We back remediation with documented incident response and 24/7 SOC monitoring covering network isolation, recovery, and regulatory notification timelines.
- Integrated IT strategy (Question 9): We bring managed IT, cybersecurity, cloud, and compliance together under one provider, so remediation aligns with your technology roadmap instead of competing with it.
We do this for small and mid-sized healthcare organizations across the full range of complexity, whether you run a single practice or a multi-location system, right-sizing controls to the resources and workflows you actually have. If you want to see how the pieces fit together before you talk to anyone, our HIPAA and HITRUST guide for healthcare breaks down where the two frameworks overlap and how to build a program that holds up under scrutiny.
Turn Compliance Pressure into a Plan
When the process works, the outcome is straightforward. Leaders gain audit readiness instead of a scramble. Teams get clear priorities instead of competing demands. And your organization ends up with compliance that holds up under scrutiny.
The right direction starts with a partner you trust. Connect with CompassMSP to talk through your HIPAA compliance needs.
YOU MAY NEED TO KNOW
Frequently Asked Questions
How long does HIPAA remediation typically take?
Timelines depend on the scope of your gaps, the number of locations, and the documentation already in place. Organizations with mature baseline controls may close critical gaps in about 30 days. Those starting from significant non-compliance usually need 60 to 90 days for full remediation. A qualified consultant assesses your environment before committing to a timeline.
What credentials should a HIPAA compliance consultant have?
Look for healthcare privacy credentials such as CHC, CHPC, or HCISPP combined with security certifications such as CISSP, CISM, or CISA. Beyond credentials, ask for references from healthcare organizations similar to yours in size and complexity. A consultant who has worked through an OCR investigation brings experience that certifications alone cannot capture.
Can managed IT services replace a dedicated HIPAA consultant?
It depends on the provider. Some managed IT companies treat compliance as an afterthought. Others, including CompassMSP, integrate compliance advisory with managed IT, cybersecurity, and cloud services so remediation and daily operations reinforce each other. The deciding factor is whether the provider can produce the documentation OCR requires and support you through an actual audit.
What is the biggest mistake healthcare organizations make when selecting a HIPAA consultant?
Treating all consultants as interchangeable and selecting on price alone. The questions that matter are specific: methodology, deliverables, subcontractor accountability, and incident response readiness. Organizations that skip those questions often discover the gap during an audit, when it is too late to course correct.
What is the difference between a HIPAA risk assessment and a gap assessment?
A risk assessment identifies where ePHI lives, what could threaten it, and how likely and damaging each threat would be. A gap assessment compares your current safeguards against HIPAA requirements to show where controls are missing or insufficient. Both feed the remediation roadmap, and a thorough engagement includes each of them.
Do I need HITRUST certification, or is HIPAA compliance enough?
HIPAA is a federal legal requirement with no formal certification. HITRUST is a certifiable framework that maps to HIPAA and lets you prove your safeguards to auditors, payers, and enterprise partners. Many organizations pursue HITRUST because contracts increasingly demand third-party validation. Our HIPAA and HITRUST guide for healthcare breaks down where the two overlap and how to decide.
What happens during an OCR audit?
The Office for Civil Rights requests documentation that demonstrates compliance, including your risk analysis, policies and procedures, training records, and evidence of remediation. Auditors evaluate whether your written safeguards match what you actually do. Organized, defensible documentation aligned with a recognized methodology such as NIST SP 800-30 is the difference between a manageable review and a scramble.
What are the penalties for a HIPAA violation?
Under the 2025 inflation-adjusted amounts, civil penalties range from $145 per violation to a maximum of $73,011 per violation, with an annual cap of roughly $2.19 million for repeated violations of the same requirement. Organizations are also frequently placed under multi-year corrective action plans and ongoing HHS monitoring. Reputational damage and breach notification costs often exceed the fines themselves.
Do small or single-location practices need the same level of remediation as large systems?
The regulatory obligations are the same regardless of size, but the approach should be right-sized. A small practice does not need enterprise-grade complexity, and it does need documented safeguards, a current risk analysis, and evidence it can produce on demand. CompassMSP works with small and mid-sized healthcare organizations, whether single-site or multi-location, and tailors remediation to the resources and workflows each one has.
How does CompassMSP support urgent HIPAA remediation?
CompassMSP delivers prioritized remediation roadmaps, documentation that meets OCR standards, and ongoing monitoring that keeps you audit-ready after the deadline passes. Our cybersecurity services and compliance advisory work together so remediation does not compete with daily operations.
Emily Zaczynski
Emily is a vCISO for Compass MSP. She is an experienced compliance professional with 12 years of expertise, including 9 years specializing in insurance compliance. She has a proven track record of ensuring regulatory adherence, mitigating risks, and implementing best practices within dynamic environments.

