HIPAA compliance fails when no one owns the risk. At Colington Consulting, our role is not to deliver generic documents and disappear. We help organizations make defensible decisions, document them accurately, and stand firmly behind them when questioned by auditors, investigators, insurers, or regulators.
Unlike automated software providers that use rigid, web-based forms and expect you to answer complex regulatory questions on your own, we take a hands-on, consultative approach. We conduct the actual HIPAA Risk Assessment, value your real-time input, and apply a common-sense methodology to healthcare compliance.
Our Promise: We take the uncertainty out of what is "reasonable and appropriate" for your organization’s HIPAA compliance.
Our vast understanding of compliance regulations has earned us consistent industry recognition, including being named:
Whether you are a healthcare provider managing patient care or a technology vendor handling protected health information (PHI), we tailor our services to your exact regulatory landscape. We have proven experience across three core pillars:
We provide comprehensive HIPAA Compliance Services for healthcare providers of all sizes, ensuring patient data remains secure:
We help complex organizations with overlapping public and private duties isolate and secure their healthcare components, including:
If your business handles PHI on behalf of a healthcare entity, you face strict legal liabilities. We specialize in securing modern vendors, including:
With over $150 million issued in federal fines and penalties to settle non-compliance, healthcare data breaches are occurring at an alarming rate. While external hackers pose a severe threat, employee error and insider vulnerabilities remain leading contributors to data exposure.
If a breach occurs, your practice or business will face a formal federal investigation. Not knowing the rules is an excuse the government will never accept.
How we protect you:
We take pride in standing right next to our clients if compliance is ever questioned. Because we build customized, highly defensible risk management plans, our approach is ideal for businesses that want more than a generic template or a temporary fix. We are built for organizations ready to empower their workforce and truly mitigate operational risk.
We specialize in assisting organizations that do not have the current resources to perform these critical and required functions or need to set up a new HIPAA compliance program.
We believe every compliance journey starts with an expert conversation. When you reach out to us, you won't deal with high-pressure salespeople or automated bots.
Schedule an Initial Consultation with Our President & Lead HIPAA Expert today to discuss your unique business needs, evaluate your risk, and find a common-sense path forward.

Jay Hodes is a leading expert in HIPAA compliance and President of Colington Consulting. Mr. Hodes has over 40 years of combined experience in risk assessments, site security evaluation, regulatory compliance, policy and procedures assessments, and Federal law enforcement management. He served as the HIPAA Compliance Officer for the Coun
Jay Hodes is a leading expert in HIPAA compliance and President of Colington Consulting. Mr. Hodes has over 40 years of combined experience in risk assessments, site security evaluation, regulatory compliance, policy and procedures assessments, and Federal law enforcement management. He served as the HIPAA Compliance Officer for the County of Fairfax, Virginia. In that role, Mr. Hodes managed the county-wide HIPAA security and privacy programs which included conducting security risk assessments, policy, and procedure development, conducting HIPAA breach, compliance, and privacy complaint investigations, and developing HIPAA Security Awareness and Privacy training. Mr. Hodes was an Assistant Inspector General for Investigations at the U.S. Department of Health and Human Services. He has provided expert witness opinions for litigation cases.
Mr. Hodes has been the keynote speaker and provided presentations regarding HIPAA compliance and patient privacy to many professional healthcare organizations including the Health Care Compliance Association, the Maryland Medical Group Management Association, the Baltimore City (MD) Medical Society, the New Jersey Aging Life Care Association, the California Primary Care Association, the National Association for Speech and Hearing Centers, and the Virginia Academy of Elder Law Attorneys. He has published over 80 educational articles regarding HIPAA compliance, been featured in Part B News articles, the Report on Patient Privacy, provided a guest post in the Electronic Health Reporter, interviewed and provided comments to the Journal of the American Health Information Management Association (AHIMA) regarding the use of tracking technologies and patient privacy concerns; interviewed and provided comments to Hospital Access Management regarding HIPAA privacy issues; interviewed four times by Renal & Urology News; interviewed by PracticeSuite EMR as part of their Expert Interview Series, and interviewed and provided comments to the Health System Specialist.
Mr. Hodes is a member of the American Institute of Healthcare Compliance, Health Care Compliance Association, and the Healthcare Information and Management Systems Society. In his free time, Mr. Hodes is a volunteer for Lab Rescue of the Labrador Retriever Club of the Potomac.

Deborah has over 30 years of experience in technical writing, editing, software training, and business document production.
Her specialized background includes:
Deborah has over 30 years of experience in technical writing, editing, software training, and business document production.
Her specialized background includes:
Colington Consulting
Burke, Fairfax County, VA USA