844-740-7100

844-740-7100

  • HIPAA Compliance Experts
  • HIPAA Risk Assessment
  • Risk Management Plans
  • HIPAA Staff Training
  • HIPAA Compliance Services
  • About Colington
  • Blog
  • Contact Us
  • Virginia HIPAA Consulting
  • HIPAA FAQs
  • More
    • HIPAA Compliance Experts
    • HIPAA Risk Assessment
    • Risk Management Plans
    • HIPAA Staff Training
    • HIPAA Compliance Services
    • About Colington
    • Blog
    • Contact Us
    • Virginia HIPAA Consulting
    • HIPAA FAQs
  • HIPAA Compliance Experts
  • HIPAA Risk Assessment
  • Risk Management Plans
  • HIPAA Staff Training
  • HIPAA Compliance Services
  • About Colington
  • Blog
  • Contact Us
  • Virginia HIPAA Consulting
  • HIPAA FAQs
Colington Consulting

Helping Organizations Achieve HIPAA Complia

About Colington Consulting

What Makes Colington Consulting the Leading HIPAA Compliance Experts?

What Makes Colington Consulting the Leading HIPAA Compliance Experts?

What Makes Colington Consulting the Leading HIPAA Compliance Experts?

HIPAA compliance fails when no one owns the risk. At Colington Consulting, our role is not to deliver generic documents and disappear. We help organizations make defensible decisions, document them accurately, and stand firmly behind them when questioned by auditors, investigators, insurers, or regulators.


Unlike automated software providers that use rigid, web-based forms and expect you to answer complex regulatory questions on your own, we take a hands-on, consultative approach. We conduct the actual HIPAA Risk Assessment, value your real-time input, and apply a common-sense methodology to healthcare compliance.


Our Promise: We take the uncertainty out of what is "reasonable and appropriate" for your organization’s HIPAA compliance.


Industry Accolades & Recognition


Our vast understanding of compliance regulations has earned us consistent industry recognition, including being named:

 

  • Top 10 HIPAA Consulting Company by Atlantic.net
  • Top 10 Compliance Firm by Sprinto (2024, 2025, and 2026)
  • Top HIPAA Compliance Consultant by Uproot Security and leading AI/B2B growth strategists

 

Who We Serve: Diverse HIPAA Compliance Expertise


Whether you are a healthcare provider managing patient care or a technology vendor handling protected health information (PHI), we tailor our services to your exact regulatory landscape. We have proven experience across three core pillars:


Covered Entities (Healthcare Providers & Plans)


We provide comprehensive HIPAA Compliance Services for healthcare providers of all sizes, ensuring patient data remains secure:


  • Large Healthcare Systems: Multi-state skilled nursing, rehabilitation, and hospice organizations with thousands of employees.
  • Specialized Medical Practices: Surgical and clinical pathology, hematology/oncology, ophthalmology, and radiology groups.
  • Dental & Therapy Providers: Large group dental practices and multi-location Applied Behavioral Analysis (ABA) therapy providers.
  • Mental Health & Counseling: Organizations offering dedicated grief, loss, and trauma counseling services.
  • Public & Employee Health: Municipal fire/rescue services, public school systems delivering behavioral health (including FERPA/HIPAA integration), and companies managing self-insured health plans.
  • Digital Health & Wellness: At-home health and wellness screening companies.


 

HIPAA Hybrid Entities


We help complex organizations with overlapping public and private duties isolate and secure their healthcare components, including:


  • Combined Preferred Provider Organizations (PPOs) and Third-Party Administrators (TPAs).
  • Tribal organizations delivering integrated healthcare, behavioral health, substance use treatment, and emergency services.
  • County and regional health departments.

 

Business Associates (HealthTech & Vendors)


If your business handles PHI on behalf of a healthcare entity, you face strict legal liabilities. We specialize in securing modern vendors, including:


  • Digital Health & SaaS platforms: Multi-national chronic disease management platforms and international SaaS accounting systems serving U.S. healthcare clients.
  • Cutting-Edge HealthTech: AI-enabled radiology solution developers and surgical mapping technology providers.
  • Healthcare Operations: Dedicated medical billing companies and healthcare data analytics firms.
  • Educational & National Associations: School system vendors utilizing Medicaid billing software and national elder care associations.

Why Should Our HIPAA Services Matter to Your Organization?

What Makes Colington Consulting the Leading HIPAA Compliance Experts?

What Makes Colington Consulting the Leading HIPAA Compliance Experts?

With over $150 million issued in federal fines and penalties to settle non-compliance, healthcare data breaches are occurring at an alarming rate. While external hackers pose a severe threat, employee error and insider vulnerabilities remain leading contributors to data exposure.


If a breach occurs, your practice or business will face a formal federal investigation. Not knowing the rules is an excuse the government will never accept.


How we protect you:


  • OCR Investigation Readiness: We ensure you can sufficiently answer every question the HHS Office for Civil Rights (OCR) asks, demonstrating the "reasonable diligence" required to legally mitigate and reduce civil monetary penalties.
  • Customized Risk Management: Your HIPAA Risk Management Plan—including all required policies and procedures—is written specifically for your unique operations.
  • Letter of Attestation: Because the OCR does not recognize commercial "HIPAA certificates," we issue an official Letter of Attestation once we verify your organization fully meets all HIPAA Security Rule requirements.
  • Workforce Education: We provide HIPAA Staff Training to empower your team with real-time best practices for securely handling protected health information.

 


Is Colington Consulting the Right Match for You?


We take pride in standing right next to our clients if compliance is ever questioned. Because we build customized, highly defensible risk management plans, our approach is ideal for businesses that want more than a generic template or a temporary fix. We are built for organizations ready to empower their workforce and truly mitigate operational risk.


We specialize in assisting organizations that do not have the current resources to perform these critical and required functions or need to set up a new HIPAA compliance program. 



 

Take the Guesswork Out of Your HIPAA Strategy


We believe every compliance journey starts with an expert conversation. When you reach out to us, you won't deal with high-pressure salespeople or automated bots.


Schedule an Initial Consultation with Our President & Lead HIPAA Expert today to discuss your unique business needs, evaluate your risk, and find a common-sense path forward.



Meet our Leadership Team

Jay Hodes - President & Founder

Deborah Ross - Vice President – Policy & Client Management

Deborah Ross - Vice President – Policy & Client Management

Jay Hodes is a leading expert in HIPAA compliance and President of Colington Consulting. Mr. Hodes has over 40 years of combined experience in risk assessments, site security evaluation, regulatory compliance, policy and procedures assessments, and Federal law enforcement management.  He served as the HIPAA Compliance Officer for the Coun

Jay Hodes is a leading expert in HIPAA compliance and President of Colington Consulting. Mr. Hodes has over 40 years of combined experience in risk assessments, site security evaluation, regulatory compliance, policy and procedures assessments, and Federal law enforcement management.  He served as the HIPAA Compliance Officer for the County of Fairfax, Virginia. In that role, Mr. Hodes managed the county-wide HIPAA security and privacy programs which included conducting security risk assessments, policy, and procedure development, conducting HIPAA breach, compliance, and privacy complaint investigations, and developing HIPAA Security Awareness and Privacy training. Mr. Hodes was an Assistant Inspector General for Investigations at the U.S. Department of Health and Human Services. He has provided expert witness opinions for litigation cases. 


Mr. Hodes has been the keynote speaker and provided presentations regarding HIPAA compliance and patient privacy to many professional healthcare organizations including the Health Care Compliance Association, the Maryland Medical Group Management Association, the Baltimore City (MD) Medical Society, the New Jersey Aging Life Care Association, the California Primary Care Association, the National Association for Speech and Hearing Centers, and the Virginia Academy of Elder Law Attorneys.  He has published over 80 educational articles regarding HIPAA compliance, been featured in Part B News articles, the Report on Patient Privacy, provided a guest post in the Electronic Health Reporter, interviewed and provided comments to the Journal of the American Health Information Management Association (AHIMA) regarding the use of tracking technologies and patient privacy concerns; interviewed and provided comments to Hospital Access Management regarding HIPAA privacy issues; interviewed four times by Renal & Urology News; interviewed by PracticeSuite EMR as part of their Expert Interview Series, and interviewed and provided comments to the Health System Specialist.  


Mr. Hodes is a member of the American Institute of Healthcare Compliance, Health Care Compliance Association, and the Healthcare Information and Management Systems Society. In his free time, Mr. Hodes is a volunteer for Lab Rescue of the Labrador Retriever Club of the Potomac.  

Deborah Ross - Vice President – Policy & Client Management

Deborah Ross - Vice President – Policy & Client Management

Deborah Ross - Vice President – Policy & Client Management

Deborah has over 30 years of experience in technical writing, editing, software training, and business document production.


Her specialized background includes:

  • Developing customized policies and procedures for HIPAA Risk Management Plans.
  • Design, editing, and production of National Baldrige Award applications in the healthcare sector, inclu

Deborah has over 30 years of experience in technical writing, editing, software training, and business document production.


Her specialized background includes:

  • Developing customized policies and procedures for HIPAA Risk Management Plans.
  • Design, editing, and production of National Baldrige Award applications in the healthcare sector, including the 2011 National Baldrige Award winner.
  • Technical writer and editor for an online medical information web portal for Washington, DC and Maryland-based clinicians.
  • Writing and designing training materials for a computer-based clinical information system for MedStar Health.
  • Writing and designing electronic health record (EHR) tutorials for medical staff and clinicians.

  • HIPAA Compliance Experts
  • HIPAA Risk Assessment
  • Risk Management Plans
  • HIPAA Staff Training
  • HIPAA Compliance Services
  • About Colington
  • Blog
  • Contact Us
  • Virginia HIPAA Consulting
  • HIPAA FAQs
  • Partners
  • Privacy Policy
  • HIPAA Audit Readiness
  • HIPAA for Small Practices
  • AI and HIPAA Compliance

Colington Consulting

Burke, Fairfax County, VA USA

844-740-7100

Copyright © 2026 Colington Consulting - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept