Independent guidance on the services practices actually buy. The full provider directory sits behind every topic.
Paneling, payer enrollment, CAQH, timelines, vendor selection.
In-house vs outsource, pricing models, coding, payer contracts.
EHR selection by specialty, migration, practice-management software.
Starting a practice, consultants, MSOs, vetting and costs.
HIPAA rules, malpractice coverage, healthcare counsel, verified vendors.
Five regulatory domains an independent practice actually has to manage. One of them -- HIPAA privacy and security -- has a real self-check tool today. The other four don't yet; this table says so plainly instead of dressing up a guide as an instrument.
| Domain | The question | Self-check now | When to bring in help |
|---|---|---|---|
| HIPAA Privacy & Security | Are our safeguards where an audit would expect them? | Yes HIPAA Quick-Check, ~2 min → |
A risk analysis finds a real gap, or you're building or buying new systems. HHS has proposed stricter Security Rule safeguards (90 FR 898, proposed rule, 2025-01-06); if it finalizes, the bar moves. |
| HIPAA Breach & Incident | Do we have a response plan before we need one? | Partial Breach playbook → (a checklist, not a tool) |
Any suspected breach, immediately -- this is a clock, not a maybe: 60 calendar days from discovery for individual notice under 45 CFR 164.404, and the breach playbook is written to that clock. |
| Malpractice & Liability Coverage | Is our coverage the right type and limit? | Partial Comparison worksheet → |
A coverage change, a claim, or a new procedure or location. |
| OSHA & Workplace Safety | Are we exposed on the standards that actually get cited? | Partial OSHA guide → |
After any citation-triggering incident, or new equipment. The bloodborne pathogens standard also requires the exposure control plan to be reviewed and updated at least annually (OSHA, 29 CFR 1910.1030(c)(1)(iv), last amended 84 FR 21598, 2019-05-14). |
| Legal Counsel & OIG Exclusion | Do we need an attorney, and are we screening vendors and staff? | Partial Attorney guide → / OIG screening → |
Before a contract, or when setting up an exclusion-screening program. OIG publishes the List of Excluded Individuals/Entities with monthly supplements (OIG, LEIE database and supplement downloads, last update 2026-09-10); hiring anyone on it can trigger civil monetary penalties. |
malpractice-quote-triangulator) but has not been built. That gap is named here, not filled with
a placeholder.
HIPAA, malpractice, legal and regulatory obligations, and self-assessment are different questions with different answers. Each group below links the strongest existing guide for that question; genuine gaps are called out, not papered over with a placeholder link.
The deepest set of guides here, covering both prevention and response.
The first 72 hours after discovering a HIPAA breach determine the quality of the audit trail OCR will review, whether notifications meet the Breach Notification Rule, and how the incident resolves. The hour-by-hour sequence.
Verified items across the Privacy Rule, Security Rule, breach notification, and BAA requirements.
Covered platforms, BAAs, patient consent, state licensure, audio-only rules, and documentation.
What a risk analysis must document under 45 CFR 164.308, how often to update it, and why its absence is OCR's most-cited finding.
Most small-practice HIPAA exposure is a CRM or texting tool with no signed BAA. What triggers PHI, and how to choose a compliant platform.
The thinnest group here -- and where the real tool gap sits (see the triage matrix above).
Occurrence vs. claims-made, typical premium ranges by specialty, and what to ask before you sign.
Claims-made vs. occurrence, coverage limits by specialty, carrier scorecard, and tail costs -- a structured worksheet, not an interactive tool.
Obligations outside HIPAA that aren't malpractice either -- grouped here as a practical bucket, not a legal category.
Eight situations that call for legal counsel, the Stark Law and Anti-Kickback framework, fee structures, and how to evaluate candidates.
Screening is monthly and covers contractors and vendors, not just employees. How to build a defensible, dated evidence trail.
The penalties, the four standards that drive most citations, and a five-step compliance program.
Check yourself before you pay someone. The one group where a real instrument, not just an article, already exists.
12 questions across 6 HIPAA domains. About 2 minutes. No email required until the end -- see where you're actually exposed.
Start the checkYour MSP is a HIPAA business associate. What to check on BAA terms, breach-notification timing, subcontractor flow-down, and system access scope.
A 50-point paper worksheet covering similar ground to the Quick-Check above, if you want a scored document for your files.
malpractice-quote-triangulator),
an OSHA-specific self-check, and a legal-counsel or OIG-exclusion decision tool. None of the three exist
today -- the triage matrix above shows exactly where each gap sits.
Every firm in the directory below passed our tier-1 data-quality and identity-verification review before it was admitted. That review confirms the business is real, correctly categorized, and reachable. It is not a quality assessment of any firm's compliance work, and it is not a ranking. HIPAA-specific evaluation criteria for this category don't exist yet; when they do, they'll be published at /methodology/ before they're used, the same way every other category's criteria are.
76 businesses hold tier-1 membership in this category (a handful list more than one office; each is one grading event, not one per address). Listed alphabetically below -- this is a verified directory, not a ranking, and no company can pay to appear here.
The first 12 of the 76 tier-1 members in alphabetical order. Not a curated pick, and not the full roster. Selection basis is verification status only.
Tier-1 verified · Phoenix, Seattle, Tustin (3 locations)
76 businesses, 12 shown above. Browse every tier-1 Compliance & HIPAA services member, filterable by state and city.
These two directories are not reviewed by this hub. They are plain, browsable listings -- what you find there may carry its own directory-level score, which is a separate thing from an editorial verdict.