Who Should Run Your HIPAA Privacy Evaluation: Law Firm, Consulting Firm, or Privacy Specialist?
A HIPAA privacy evaluation is an intensive review of how an organization handles protected health information (PHI). It requires assessing how PHI is used and disclosed, testing whether patients can exercise their right of access, reviewing the Notice of Privacy Practices against current guidance, confirming the minimum necessary standard is applied in practice, and verifying that workforce training matches what staff is doing day to day. Many organizations hire someone to complete the evaluation, but fewer decide in advance who will carry out the fixes it identifies.
In our experience, many healthcare organizations facing this decision default to whoever already has a relationship, such as outside counsel or a consulting firm. Neither is built for this specific job. This often only becomes clear after the evaluation is delivered, when someone still has to act on what it found. That’s what this piece answers: who should conduct a HIPAA privacy evaluation, and who should act on what it finds.
What the HIPAA Privacy Rule Asks For
The HIPAA Privacy Rule governs how protected health information is used, disclosed, and protected as a patient right. That is different from the Security Rule, which governs the technical, physical, and administrative safeguards protecting electronic PHI. A HIPAA Privacy Program Evaluation tests the Privacy Rule side specifically: right of access, disclosures, the Notice of Privacy Practices, minimum necessary, and workforce training. An evaluator who folds both rules into one generic ‘HIPAA compliance’ review has not evaluated the Privacy Rule on its own terms.
The Three Options Organizations Consider for Program Evaluations
Law firms interpret the regulation. That is useful when an organization needs a legal opinion on a specific disclosure question or a defensible position ahead of litigation. It is a different skill than running an evaluation, staffing an interim privacy officer, or monitoring a corrective action plan over time. Most law firms offering HIPAA advisory work stop at the opinion.
Consulting firms bring broad healthcare advisory experience. National firms have added HIPAA advisory practices to their healthcare consulting lines, and many can produce a competent program evaluation as a standalone deliverable. Where they fall short is staffing: interim compliance officer and interim privacy officer roles require someone embedded in the organization’s operations, not a team that rotates off after the audit is finished. Across most of the national accounting and consulting firms competing for this work, this staffing capability is limited.
Healthcare Privacy specialists run the program, evaluating through a detailed, HIPAA-specific lens. Not all of them finish the job. Strategic Management Services runs an evaluation that identifies gaps, assists with remediating every area it flags, and staffs an interim privacy officer for organizations that need one while they build internal capacity.
Comparing Your Options for a HIPAA Privacy Program Evaluation
| HIPAA Advisory Services | Interim Compliance Officer | Interim Privacy Officer | HIPAA Privacy Program Evaluations | Primary Focus | |
|---|---|---|---|---|---|
| Law Firms | Yes | No | No | Limited | Legal interpretation and regulatory risk |
| General Consulting Firms | Yes | Limited | Limited | Yes | Broad audit, tax, and advisory portfolio, with compliance as one service line among many |
| Large National Healthcare Consulting Firms | Yes | Yes | Yes | Yes | Broad healthcare consulting portfolio, with HIPAA as one line of business among many |
| Strategic Management Services | Yes | Yes | Yes | Yes | 100% healthcare compliance focus, since 1992 |
Law firms interpret the regulation. Consulting firms bring broad advisory experience. Strategic Management Services runs the program.
Why These Differences Matter
An organization that hires a law firm for a privacy opinion still needs someone to implement the change. An organization that hires a consulting an accounting firm for an evaluation still needs someone to staff the response when the evaluation finds gaps in access request handling or workforce training. Both paths end at the same questions: who is going to do the work? And how will you know if it’s done effectively?
These questions have gotten more expensive to leave unanswered, as demonstrated by the OCR’s enforcement record:
- The OCR settled its investigation into MMG Fusion, LLC, over a breach affecting 15 million individuals, citing impermissible disclosure of protected health information (2026)
- The OCR’s 2020 Right of Access Initiative and its 2026 enforcement program for Part 2 apply this same scrutiny to disclosures, patient requests, and confidentiality on the Privacy Rule side
- The OCR settled four HIPAA Security Rule ransomware investigations for a combined $1,165,000, tied to breaches affecting more than 427,000 individuals (2026)
This pattern spans both rules.

An organization operating under the Security Rule readiness framework already has one half of this covered. A Privacy Program Evaluation closes the other half, and it is worth doing with a firm whose primary focus is healthcare compliance, not a firm that added HIPAA to a broader audit or consulting practice.
Founded in 1992 by Richard P. Kusserow, Former Inspector General of the U.S. Department of Health and Human Services, Strategic Management Services has served more than 3,000 healthcare organizations with 100 percent of its practice focused on healthcare compliance. That focus is what separates a firm that can staff an interim privacy officer, complete a program evaluation, and monitor the result from a firm that can only produce the opinion or audit.
Organizations that want to see how their current program compares, whether through outside counsel, an accounting firm, or no dedicated privacy oversight at all, can review Strategic Management Services’ approach to interim privacy staffing alongside the evaluation itself.
The OCR doesn’t wait for you to find the gaps in your Privacy Rule program. Find out where you stand before they do.
Subscribe to blog