Compliance work for people who don't have a security team
Healthcare is the practice we built the firm around, and it is where the deepest work happens. Three other groups come to us regularly — here is exactly what each one gets.
Primary
Solo & small healthcare practices
Private practices, specialty clinics, therapy and behavioural health, dental, and allied health — typically 1–25 staff, running a hosted EHR with no internal IT security function.
Billing companies, transcription services, IT providers, and SaaS vendors that touch ePHI on behalf of a covered entity and need to demonstrate their own compliance.
RIAs, broker-dealers, and family offices under Regulation S-P, plus defense suppliers preparing for a CMMC assessment against NIST SP 800-171.
WISPIR program800-171 gapSSP & POA&M
Executives, advisors & families
Individual
Personal account and device protection for people whose work makes them a target — identity hardening, password and MFA hygiene, and help untangling a compromise.
Account hardeningMFA rolloutIdentity monitoring
// frameworks.supported()
Built Around HIPAA. Fluent in the Rest.
Healthcare is where we go deepest — it is the practice we built the firm around. When a client answers to a different regulator, the same method applies and we say plainly how far we take it.
How to read this
Every consultancy claims every framework. The bar beside each one is how far we actually take it — five means we own the outcome, two means we get you to someone who does.
End to end
Analysis through audit file
Advisory
We build it, counsel files it
Readiness
Prep for a certified assessor
Shared method
NIST CSF 2.0Govern → Recover
CIS Controls v8Prioritised safeguards
NIST SP 800-61Incident handling
The controls overlap heavily, which is why a second framework costs far less than the first.
The annual Security Risk Analysis required at 45 CFR § 164.308(a)(1)(ii)(A), plus the safeguards, documentation, and evidence that make it defensible.
Scoping conversations are free, and we will tell you when something is outside what we should take on.
// services.list()
Healthcare Compliance First, Security Built Around ePHI
Risk analysis and audit evidence are the front door. Everything else here exists because a finding pointed at it — safeguards get implemented on the systems the assessment actually flagged.
HIPAA Security Risk Assessment
Annual SRA support for covered entities and business associates: ePHI workflows, threats, vulnerabilities, likelihood, impact, and prioritized remediation evidence.
HIPAA SRAePHI
Audit Readiness & Evidence
Prepare documentation that administrators can defend: policies, procedures, risk register, remediation plan, vendor artifacts, and executive-ready status reporting.
Audit PrepEvidence
Security Rule Safeguards
Administrative, physical, and technical safeguard reviews mapped to practical controls for clinics, specialty practices, and healthcare operators.
SafeguardsControls
Incident Response for ePHI
Breach triage, containment planning, tabletop exercises, notification decision support, and post-incident hardening for patient-data events.
IR PlanBreach Triage
Secure Healthcare Email
Phishing defense, BEC reduction, spoofing protection, account takeover monitoring, and encrypted delivery for regulated patient communications.
EmailEncryption
Identity & Access Reviews
MFA, role-based access, risky sign-in review, credential exposure monitoring, and workforce access processes for systems touching ePHI.
MFAAccess
Endpoint & EHR Workflow Protection
Endpoint detection, device hardening, patch visibility, and practical security controls around workstations used for EHR and patient operations.
EDREndpoints
M365, SaaS & Cloud Hardening
Tenant configuration, file-sharing controls, backup readiness, SaaS permissions, and cloud data exposure reduction for healthcare teams.
M365SaaS
Clinic Network Segmentation
Firewall, Wi-Fi, VPN, DNS filtering, and segmentation guidance to separate clinical systems, guest access, and administrative operations.
NetworkVPN
HIPAA Security Awareness
Workforce-ready training, phishing simulations, and administrator reporting focused on patient privacy, social engineering, and credential theft.
TrainingPhishing Sim
AI Governance for Patient Data
Approved-tool policies, prompt/data handling guidance, agent guardrails, and shadow AI controls so staff do not leak PHI into unsafe systems.
AI PolicyPHI
Multi-Framework Compliance
One control set, mapped across the regulators you answer to — SEC Regulation S-P, FINRA, and CMMC / NIST SP 800-171 readiness alongside your HIPAA program.
SECCMMCNIST
Fixed fees, scoped before you commit
Two risk-analysis tiers by practice size, remediation quoted per project, and senior advisory by the hour.