The HIPAA compliance quote: what the Security Rule obligates
Summary
Paying a HIPAA compliance company is optional for a solo practice: the Security Rule names outcomes rather than products, letting a covered entity use any security measures that reasonably and appropriately implement its standards, with cost as one factor to weigh. The work underneath is not optional. A documented risk analysis, written policies kept six years, and training on those policies are owed whether a vendor performs them or the practice does.
By Gale Editorial · Updated 2026-09-02. Every figure cited to a dated source. How we write.
Does the Security Rule require you to buy anything?
No. The rule states what a practice's security has to achieve and leaves the means to the practice: a covered entity may use any security measures that allow it to reasonably and appropriately implement the standards 1Ref 1U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Security standards: General rules.The Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification.. Cost is one of four factors the rule names for that choice, beside the practice's size and complexity, its technical infrastructure, and how likely and how serious each risk is 1Ref 1U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Security standards: General rules.The Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification..
A HIPAA compliance company sells labor and software against those standards. That is a real service, and for a clinician who has never written a policy it can be a good buy. It is not a precondition. The rule names cost as a factor to weigh, never a figure to spend, and the sentence that permits any reasonable measure permits a practice to perform the work itself 1Ref 1U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Security standards: General rules.The Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification..
But the duties underneath do not move, whoever performs them.
Quotes for this work commonly arrive as a monthly or annual subscription with a renewal date attached, which makes the purchase look like a licence being maintained. Read the deliverables instead, and ask which section of the rule each one answers.
Required and Addressable: the two words that sort a quote
Every implementation specification in the Security Rule carries one of two tags, and the tag decides how much freedom a practice has. Addressable means a practice that finds the listed measure unreasonable for its own circumstances may document why and put an equivalent measure in its place 1Ref 1U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Security standards: General rules.The Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification.. Required means no substitute is offered. A quote that presents every line as equally mandatory has flattened a distinction the regulation draws in its own text.
The risk analysis is Required, with no addressable path beside it 2Ref 2U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative safeguards.That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents.. The four workforce training methods the rule lists are each Addressable 2Ref 2U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative safeguards.That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents.. Sorting a quote starts there.
| Line on the quote | Where it sits in the rule | Who can perform it |
|---|---|---|
| Security risk analysis | Required, no substitute offered 2Ref 2U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative safeguards.That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents. | The practice, using the free federal tool 3Ref 3Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC and OCR publish a free downloadable Security Risk Assessment Tool for the risk analysis the Security Rule requires, at version 3.6.1 last updated May 28, 2026, with medium and small providers as its stated target audience and entered data kept local rather than transmitted to HHS. |
| Written policies and procedures | Documentation standard: in writing, retained, reviewed 4Ref 4U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Policies and procedures and documentation requirements.The documentation duty: policies and procedures kept in writing, retained 6 years from creation or the date last in effect whichever is later, made available to the people who implement them, and reviewed and updated periodically. | The practice, in any form it can retain |
| Security awareness and training methods | Addressable list: reminders, malware procedures, log-in monitoring, password management 2Ref 2U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative safeguards.That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents. | The practice, or an equivalent it documents |
| Privacy Rule workforce training | Timed to the compliance date, new members, and material policy changes 5Ref 5U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative requirements.The Privacy Rule's training timing: workforce training on the practice's own privacy policies by the compliance date, each new member within a reasonable period of time after joining, and again after a material change in those policies. | The practice, on the rule's clock |
Addressable does not mean optional. It opens a second path: document why the listed measure is not reasonable and appropriate here, then implement an equivalent alternative where one is reasonable and appropriate 1Ref 1U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Security standards: General rules.The Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification.. Both paths end in a written record, and the record is what an investigator can read years later.
The risk analysis, and the federal tool built for it
The risk analysis is the one line on the quote that is not negotiable. The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information a practice holds, and that specification carries no addressable substitute 2Ref 2U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative safeguards.That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents.. What is negotiable is who performs it. ONC and OCR publish a free downloadable Security Risk Assessment Tool built for that assessment 3Ref 3Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC and OCR publish a free downloadable Security Risk Assessment Tool for the risk analysis the Security Rule requires, at version 3.6.1 last updated May 28, 2026, with medium and small providers as its stated target audience and entered data kept local rather than transmitted to HHS..
The tool is at version 3.6.1, last updated May 28, 2026, its stated target audience is medium and small providers, and the answers stay on the machine that entered them rather than travelling to HHS 3Ref 3Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC and OCR publish a free downloadable Security Risk Assessment Tool for the risk analysis the Security Rule requires, at version 3.6.1 last updated May 28, 2026, with medium and small providers as its stated target audience and entered data kept local rather than transmitted to HHS.. Its page does not claim a practice needs no vendor, and it should not be read that way. What it does is put the required instrument within reach of anyone willing to spend an evening on it.
Working through it is how a solo practice finds out what it holds. The laptop with the schedule on it, the phone the answering service forwards to, the cloud drive still holding intake forms from a year ago: each is an asset with a risk beside it. Write down what happens to that schedule when the laptop dies. That is the contingency plan, and it is yours to write.
But the tool stops at the finding. Nothing in it encrypts a drive, replaces a vendor or trains a receptionist, and consulting hours are worth most on the remediation an analysis exposes rather than on the analysis itself.
The documentation standard asks for a record you keep
A written record, retained and reviewed. The rule requires the policies and procedures a practice adopts to be kept in writing, held 6 years from the date of its creation or the date when it last was in effect, whichever is later, made available to the people who carry them out, and reviewed and updated periodically 4Ref 4U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Policies and procedures and documentation requirements.The documentation duty: policies and procedures kept in writing, retained 6 years from creation or the date last in effect whichever is later, made available to the people who implement them, and reviewed and updated periodically.. That is the form the regulation asks for, and a practice can produce it in a vendor portal or in a dated folder on an encrypted drive.
The retention clock belongs to the practice either way, which turns one question into the most useful thing to put to a salesperson: if the subscription lapses in year three, does the practice keep an exportable copy of everything written in the portal, or does the record leave with the vendor?
Periodic review is the clause a one-time purchase cannot satisfy. A policy set generated in one afternoon and never opened again satisfies the writing duty and fails the review one 4Ref 4U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Policies and procedures and documentation requirements.The documentation duty: policies and procedures kept in writing, retained 6 years from creation or the date last in effect whichever is later, made available to the people who implement them, and reviewed and updated periodically.. Calendar the review the day the policies are adopted. If your practice keeps psychotherapy notes, the decisions you make about who may see them belong in that same record.
Training: two duties on two clocks
Two separate rules ask for training, and one annual module answers neither by itself. The Privacy Rule sets its timing directly: train the workforce on the practice's own privacy policies and procedures by the compliance date, each new member within a reasonable period of time after joining, and again after a material change to those policies 5Ref 5U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative requirements.The Privacy Rule's training timing: workforce training on the practice's own privacy policies by the compliance date, each new member within a reasonable period of time after joining, and again after a material change in those policies.. That clock runs on hires and on policy changes.
The Security Rule's side is looser. Its four listed methods, periodic security reminders, procedures for guarding against and reporting malicious software, log-in monitoring and password management, are each Addressable, so a practice may adopt an equivalent approach of its own and document the reasoning 2Ref 2U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative safeguards.That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents..
That matters for the line item priced as a per-seat annual training licence. What the Privacy Rule asks for is training on the practice's own policies 5Ref 5U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative requirements.The Privacy Rule's training timing: workforce training on the practice's own privacy policies by the compliance date, each new member within a reasonable period of time after joining, and again after a material change in those policies., which a module written before those policies existed cannot contain. A generic course can carry the general material; the practice still has to cover its own document and record who sat through it.
Bundled quotes often carry other training beside the HIPAA lines. The rules for OSHA and the solo office come from a different agency and carry duties of their own, and a HIPAA subscription satisfies none of them. Price those lines separately, or you cannot tell which rule you are paying for.
What to send back before you sign
Ask the vendor to map every line to the rule and to say who performs it. A quote written that way answers itself in a page, and a quote that cannot be written that way has told you something worth knowing before the first payment. Six questions do most of the work here, and all six fit in one email sent the day the proposal arrives.
- Which standard does each deliverable answer? A line that names no section is software, priced as compliance.
- Do you perform the risk analysis, or supply a questionnaire? Performing it is hours of work; supplying one duplicates a free federal instrument 3Ref 3Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC and OCR publish a free downloadable Security Risk Assessment Tool for the risk analysis the Security Rule requires, at version 3.6.1 last updated May 28, 2026, with medium and small providers as its stated target audience and entered data kept local rather than transmitted to HHS..
- Which deliverables are Addressable, and what documentation of the substitution does the practice receive 1Ref 1U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Security standards: General rules.The Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification.?
- If the contract ends, what leaves with you? The six-year retention duty stays with the practice 4Ref 4U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Policies and procedures and documentation requirements.The documentation duty: policies and procedures kept in writing, retained 6 years from creation or the date last in effect whichever is later, made available to the people who implement them, and reviewed and updated periodically..
- What recurs, and why? Name the event that triggers retraining, rather than the anniversary date 5Ref 5U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative requirements.The Privacy Rule's training timing: workforce training on the practice's own privacy policies by the compliance date, each new member within a reasonable period of time after joining, and again after a material change in those policies..
- Which lines are not HIPAA at all? Price the OSHA, billing and marketing items on their own.
The same exercise works on the rest of a new practice's mail. The PLLC formation quote splits into a state fee and drafting hours the way this one splits into required work, addressable work and software. None of this is legal advice, and an unusual arrangement is a real reason to put a quote in front of counsel. Start the risk analysis either way, because it is the one line that has to exist whether or not anyone is paid to produce it 2Ref 2U.S. Department of Health and Human Services (Office for Civil Rights) (2024).Administrative safeguards.That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents..
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Security standards: General rules. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). link ✓The Security Rule's 'any security measures' standard, the four factors a practice weighs when choosing them (size and complexity, technical infrastructure, cost, and the probability and criticality of risks), and the Required-versus-Addressable framework including the document-and-substitute path for an Addressable specification.
- 2.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Administrative safeguards. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). link ✓That the risk analysis under the security management process is Required with no addressable substitute, and that the four listed security awareness and training methods are each Addressable, so a practice may implement an equivalent measure it documents.
- 3.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC and OCR publish a free downloadable Security Risk Assessment Tool for the risk analysis the Security Rule requires, at version 3.6.1 last updated May 28, 2026, with medium and small providers as its stated target audience and entered data kept local rather than transmitted to HHS.
- 4.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Policies and procedures and documentation requirements. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). link ✓The documentation duty: policies and procedures kept in writing, retained 6 years from creation or the date last in effect whichever is later, made available to the people who implement them, and reviewed and updated periodically.
- 5.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Administrative requirements. Code of Federal Regulations, Title 45, Part 164, Subpart E (govinfo.gov, U.S. Government Publishing Office). link ✓The Privacy Rule's training timing: workforce training on the practice's own privacy policies by the compliance date, each new member within a reasonable period of time after joining, and again after a material change in those policies.
https://www.gale.care/for-providers/se-hipaa-vendor-quote-check · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.