Guide

The HIPAA compliance quote: what the Security Rule obligates

Summary

Paying a HIPAA compliance company is optional for a solo practice: the Security Rule names outcomes rather than products, letting a covered entity use any security measures that reasonably and appropriately implement its standards, with cost as one factor to weigh. The work underneath is not optional. A documented risk analysis, written policies kept six years, and training on those policies are owed whether a vendor performs them or the practice does.

By Gale Editorial · Updated 2026-09-02. Every figure cited to a dated source. How we write.

Does the Security Rule require you to buy anything?

No. The rule states what a practice's security has to achieve and leaves the means to the practice: a covered entity may use any security measures that allow it to reasonably and appropriately implement the standards 1. Cost is one of four factors the rule names for that choice, beside the practice's size and complexity, its technical infrastructure, and how likely and how serious each risk is 1.

A HIPAA compliance company sells labor and software against those standards. That is a real service, and for a clinician who has never written a policy it can be a good buy. It is not a precondition. The rule names cost as a factor to weigh, never a figure to spend, and the sentence that permits any reasonable measure permits a practice to perform the work itself 1.

But the duties underneath do not move, whoever performs them.

Quotes for this work commonly arrive as a monthly or annual subscription with a renewal date attached, which makes the purchase look like a licence being maintained. Read the deliverables instead, and ask which section of the rule each one answers.

Required and Addressable: the two words that sort a quote

Every implementation specification in the Security Rule carries one of two tags, and the tag decides how much freedom a practice has. Addressable means a practice that finds the listed measure unreasonable for its own circumstances may document why and put an equivalent measure in its place 1. Required means no substitute is offered. A quote that presents every line as equally mandatory has flattened a distinction the regulation draws in its own text.

The risk analysis is Required, with no addressable path beside it 2. The four workforce training methods the rule lists are each Addressable 2. Sorting a quote starts there.

Line on the quoteWhere it sits in the ruleWho can perform it
Security risk analysisRequired, no substitute offered 2The practice, using the free federal tool 3
Written policies and proceduresDocumentation standard: in writing, retained, reviewed 4The practice, in any form it can retain
Security awareness and training methodsAddressable list: reminders, malware procedures, log-in monitoring, password management 2The practice, or an equivalent it documents
Privacy Rule workforce trainingTimed to the compliance date, new members, and material policy changes 5The practice, on the rule's clock

Addressable does not mean optional. It opens a second path: document why the listed measure is not reasonable and appropriate here, then implement an equivalent alternative where one is reasonable and appropriate 1. Both paths end in a written record, and the record is what an investigator can read years later.

The risk analysis, and the federal tool built for it

The risk analysis is the one line on the quote that is not negotiable. The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information a practice holds, and that specification carries no addressable substitute 2. What is negotiable is who performs it. ONC and OCR publish a free downloadable Security Risk Assessment Tool built for that assessment 3.

The tool is at version 3.6.1, last updated May 28, 2026, its stated target audience is medium and small providers, and the answers stay on the machine that entered them rather than travelling to HHS 3. Its page does not claim a practice needs no vendor, and it should not be read that way. What it does is put the required instrument within reach of anyone willing to spend an evening on it.

Working through it is how a solo practice finds out what it holds. The laptop with the schedule on it, the phone the answering service forwards to, the cloud drive still holding intake forms from a year ago: each is an asset with a risk beside it. Write down what happens to that schedule when the laptop dies. That is the contingency plan, and it is yours to write.

But the tool stops at the finding. Nothing in it encrypts a drive, replaces a vendor or trains a receptionist, and consulting hours are worth most on the remediation an analysis exposes rather than on the analysis itself.

The documentation standard asks for a record you keep

A written record, retained and reviewed. The rule requires the policies and procedures a practice adopts to be kept in writing, held 6 years from the date of its creation or the date when it last was in effect, whichever is later, made available to the people who carry them out, and reviewed and updated periodically 4. That is the form the regulation asks for, and a practice can produce it in a vendor portal or in a dated folder on an encrypted drive.

The retention clock belongs to the practice either way, which turns one question into the most useful thing to put to a salesperson: if the subscription lapses in year three, does the practice keep an exportable copy of everything written in the portal, or does the record leave with the vendor?

Periodic review is the clause a one-time purchase cannot satisfy. A policy set generated in one afternoon and never opened again satisfies the writing duty and fails the review one 4. Calendar the review the day the policies are adopted. If your practice keeps psychotherapy notes, the decisions you make about who may see them belong in that same record.

Training: two duties on two clocks

Two separate rules ask for training, and one annual module answers neither by itself. The Privacy Rule sets its timing directly: train the workforce on the practice's own privacy policies and procedures by the compliance date, each new member within a reasonable period of time after joining, and again after a material change to those policies 5. That clock runs on hires and on policy changes.

The Security Rule's side is looser. Its four listed methods, periodic security reminders, procedures for guarding against and reporting malicious software, log-in monitoring and password management, are each Addressable, so a practice may adopt an equivalent approach of its own and document the reasoning 2.

That matters for the line item priced as a per-seat annual training licence. What the Privacy Rule asks for is training on the practice's own policies 5, which a module written before those policies existed cannot contain. A generic course can carry the general material; the practice still has to cover its own document and record who sat through it.

Bundled quotes often carry other training beside the HIPAA lines. The rules for OSHA and the solo office come from a different agency and carry duties of their own, and a HIPAA subscription satisfies none of them. Price those lines separately, or you cannot tell which rule you are paying for.

What to send back before you sign

Ask the vendor to map every line to the rule and to say who performs it. A quote written that way answers itself in a page, and a quote that cannot be written that way has told you something worth knowing before the first payment. Six questions do most of the work here, and all six fit in one email sent the day the proposal arrives.

  • Which standard does each deliverable answer? A line that names no section is software, priced as compliance.
  • Do you perform the risk analysis, or supply a questionnaire? Performing it is hours of work; supplying one duplicates a free federal instrument 3.
  • Which deliverables are Addressable, and what documentation of the substitution does the practice receive 1?
  • If the contract ends, what leaves with you? The six-year retention duty stays with the practice 4.
  • What recurs, and why? Name the event that triggers retraining, rather than the anniversary date 5.
  • Which lines are not HIPAA at all? Price the OSHA, billing and marketing items on their own.

The same exercise works on the rest of a new practice's mail. The PLLC formation quote splits into a state fee and drafting hours the way this one splits into required work, addressable work and software. None of this is legal advice, and an unusual arrangement is a real reason to put a quote in front of counsel. Start the risk analysis either way, because it is the one line that has to exist whether or not anyone is paid to produce it 2.

Common questions

No rule names one. The Security Rule lets a covered entity use any security measures that reasonably and appropriately implement its standards, and it lists cost among the factors a practice weighs when choosing them. A vendor sells labor and software against that standard, and the risk analysis, the written policies and the training are owed with or without the vendor. Whether to buy the labor is a business decision for the practice.

ONC and OCR publish a downloadable Security Risk Assessment Tool built for the assessment the Security Rule requires, currently version 3.6.1, last updated May 28, 2026. Its stated audience is medium and small providers, and entered data stays on the local machine rather than going to HHS. It walks a practice through its assets and risks and leaves a record. It remediates nothing it finds.

It marks an implementation specification a practice can meet by an equivalent route. Where the listed measure is not reasonable and appropriate for that practice, the rule allows documenting why and putting an equivalent alternative in its place where one is reasonable. It is a second path rather than an exemption, and it ends in writing either way. The risk analysis carries no such path: it is Required, with no substitute offered.

Six years from the date a policy was created or the date it was last in effect, whichever is later. The rule also asks that policies be available to the people who implement them, and that they be reviewed and updated periodically. That retention duty sits with the practice, which is why an exportable copy matters before a compliance subscription lapses or a portal closes.

Not on its own. The Privacy Rule requires training on the practice's own privacy policies, by the compliance date, for each new workforce member within a reasonable period after joining, and again after a material policy change. A generic module predates your policies and runs on a renewal date rather than on those events. Keep the record of who was trained, on what, and when.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Security standards: General rules. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). linkThe Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification.
  2. 2.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Administrative safeguards. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). linkThat the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents.
  3. 3.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC and OCR publish a free downloadable Security Risk Assessment Tool for the risk analysis the Security Rule requires, at version 3.6.1 last updated May 28, 2026, with medium and small providers as its stated target audience and entered data kept local rather than transmitted to HHS.
  4. 4.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Policies and procedures and documentation requirements. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). linkThe documentation duty: policies and procedures kept in writing, retained 6 years from creation or the date last in effect whichever is later, made available to the people who implement them, and reviewed and updated periodically.
  5. 5.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Administrative requirements. Code of Federal Regulations, Title 45, Part 164, Subpart E (govinfo.gov, U.S. Government Publishing Office). linkThe Privacy Rule's training timing: workforce training on the practice's own privacy policies by the compliance date, each new member within a reasonable period of time after joining, and again after a material change in those policies.

https://www.gale.care/for-providers/se-hipaa-vendor-quote-check · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)