Blog Post

Who Should Run Your HIPAA Privacy Evaluation: Law Firm, Consulting Firm, or Privacy Specialist?

Richard P. Kusserow | August 2026

A HIPAA privacy evaluation is an intensive review of how an organization handles protected health information (PHI). It requires assessing how PHI is used and disclosed, testing whether patients can exercise their right of access, reviewing the Notice of Privacy Practices against current guidance, confirming the minimum necessary standard is applied in practice, and verifying that workforce training matches what staff is doing day to day. Many organizations hire someone to complete the evaluation, but fewer decide in advance who will carry out the fixes it identifies.

In our experience, many healthcare organizations facing this decision default to whoever already has a relationship, such as outside counsel or a consulting firm. Neither is built for this specific job. This often only becomes clear after the evaluation is delivered, when someone still has to act on what it found. That’s what this piece answers: who should conduct a HIPAA privacy evaluation, and who should act on what it finds.

What the HIPAA Privacy Rule Asks For

The HIPAA Privacy Rule governs how protected health information is used, disclosed, and protected as a patient right. That is different from the Security Rule, which governs the technical, physical, and administrative safeguards protecting electronic PHI. A HIPAA Privacy Program Evaluation tests the Privacy Rule side specifically: right of access, disclosures, the Notice of Privacy Practices, minimum necessary, and workforce training. An evaluator who folds both rules into one generic ‘HIPAA compliance’ review has not evaluated the Privacy Rule on its own terms.

The Three Options Organizations Consider for Program Evaluations

Law firms interpret the regulation. That is useful when an organization needs a legal opinion on a specific disclosure question or a defensible position ahead of litigation. It is a different skill than running an evaluation, staffing an interim privacy officer, or monitoring a corrective action plan over time. Most law firms offering HIPAA advisory work stop at the opinion.

Consulting firms bring broad healthcare advisory experience. National firms have added HIPAA advisory practices to their healthcare consulting lines, and many can produce a competent program evaluation as a standalone deliverable. Where they fall short is staffing: interim compliance officer and interim privacy officer roles require someone embedded in the organization’s operations, not a team that rotates off after the audit is finished. Across most of the national accounting and consulting firms competing for this work, this staffing capability is limited.

Healthcare Privacy specialists run the program, evaluating through a detailed, HIPAA-specific lens. Not all of them finish the job. Strategic Management Services runs an evaluation that identifies gaps, assists with remediating every area it flags, and staffs an interim privacy officer for organizations that need one while they build internal capacity.

Comparing Your Options for a HIPAA Privacy Program Evaluation

HIPAA Advisory ServicesInterim Compliance OfficerInterim Privacy OfficerHIPAA Privacy Program  EvaluationsPrimary Focus
Law FirmsYesNoNoLimitedLegal interpretation and regulatory risk
General Consulting FirmsYesLimitedLimitedYesBroad audit, tax, and advisory portfolio, with compliance as one service line among many
Large National Healthcare Consulting FirmsYesYesYesYesBroad healthcare consulting portfolio, with HIPAA as one line of business among many
Strategic Management ServicesYesYesYesYes100% healthcare compliance focus, since 1992

Law firms interpret the regulation. Consulting firms bring broad advisory experience. Strategic Management Services runs the program.

Why These Differences Matter

An organization that hires a law firm for a privacy opinion still needs someone to implement the change. An organization that hires a consulting an accounting firm for an evaluation still needs someone to staff the response when the evaluation finds gaps in access request handling or workforce training. Both paths end at the same questions: who is going to do the work? And how will you know if it’s done effectively?

These questions have gotten more expensive to leave unanswered, as demonstrated by the OCR’s enforcement record:

This pattern spans both rules.

An organization operating under the Security Rule readiness framework already has one half of this covered. A Privacy Program Evaluation closes the other half, and it is worth doing with a firm whose primary focus is healthcare compliance, not a firm that added HIPAA to a broader audit or consulting practice.

Founded in 1992 by Richard P. Kusserow, Former Inspector General of the U.S. Department of Health and Human Services, Strategic Management Services has served more than 3,000 healthcare organizations with 100 percent of its practice focused on healthcare compliance. That focus is what separates a firm that can staff an interim privacy officer, complete a program evaluation, and monitor the result from a firm that can only produce the opinion or audit.

Organizations that want to see how their current program compares, whether through outside counsel, an accounting firm, or no dedicated privacy oversight at all, can review Strategic Management Services’ approach to interim privacy staffing alongside the evaluation itself.

The OCR doesn’t wait for you to find the gaps in your Privacy Rule program. Find out where you stand before they do.

Book a Consultation

About the Author

Richard P. Kusserow established Strategic Management Services, LLC, after retiring from being the DHHS Inspector General, and has assisted over 3,000 health care organizations and entities in developing, implementing and assessing compliance programs.

Subscribe to blog