The realistic HIPAA timeline
From "we need to get compliant" to a defensible program — phase by phase, with honest durations.
The phases
- Scoping & ePHI inventory (1–3 weeks). Map every system, vendor, and data flow that touches PHI. This is the highest-leverage phase: an undefined inventory expands scope everywhere.
- Risk analysis (4–8 weeks). The assessor evaluates threats, vulnerabilities, and current controls across all ePHI systems and produces the findings report — the foundation OCR requires.
- Remediation (1–4 months). Fix what the analysis found: encryption gaps, access controls, logging, missing BAAs. The long pole — and where most programs stall.
- Policies & training (4–8 weeks). Write or refresh privacy and security policies, designate officials, train the workforce, keep records.
- Validation & ongoing (continuous). Independent validation if customers require it, then the annual cycle: refresh the risk analysis, retrain, re-attest BAAs.
Planning windows by starting point
| Starting point | Realistic window |
|---|---|
| From scratch (no risk analysis, few policies) | 5–8 months to a defensible program |
| Partial program (some policies, outdated analysis) | 3–5 months |
| Mature program (current analysis, annual training) | 4–8 weeks to validated |
Planning windows compiled September 2026 from assessor-published process descriptions — not promises. Assessor availability and your remediation speed are the wildcards.
After the first program
Annual risk-analysis refresh, annual workforce training, policy reviews, BAA re-attestation, and incident-response testing. Budget it as an operating line, not a project — programs that decay between assessments are what OCR finds.
Frequently asked
How long does a HIPAA risk analysis take?
Typically 4–8 weeks of assessor fieldwork for a mid-size organization, depending on locations and ePHI complexity. Small practices can be faster; large health systems run longer.
How long until we're 'HIPAA compliant'?
There is no finish line and no certificate — HIPAA compliance is an ongoing program. A first full program build (risk analysis, policies, training, remediation, BAAs) typically takes 3–6 months for a mid-size organization starting from partial maturity.
How often must we redo the risk analysis?
OCR expects it to be current — at minimum annually, and whenever operations, technology, or threats change materially. A two-year-old risk analysis is a finding waiting to happen.
Start the clock with quotes
Tell us your size and timeline — matched assessors send scoped quotes in 1–2 business days.
How it works: tell us once (4 questions, 2 min) → we match HIPAA assessors to your size, setting, and timeline → they send scoped quotes directly. Free, no obligation.