// clients.profile()

Compliance work for people who don't have a security team

Healthcare is the practice we built the firm around, and it is where the deepest work happens. Three other groups come to us regularly — here is exactly what each one gets.

Primary

Solo & small healthcare practices

Private practices, specialty clinics, therapy and behavioural health, dental, and allied health — typically 1–25 staff, running a hosted EHR with no internal IT security function.

  • Annual SRA
  • BAA review
  • Audit evidence
  • Staff training

Business associates

Primary

Billing companies, transcription services, IT providers, and SaaS vendors that touch ePHI on behalf of a covered entity and need to demonstrate their own compliance.

Risk analysisClient questionnairesSubcontractor BAAs

Regulated financial & defense firms

Secondary

RIAs, broker-dealers, and family offices under Regulation S-P, plus defense suppliers preparing for a CMMC assessment against NIST SP 800-171.

WISPIR program800-171 gapSSP & POA&M

Executives, advisors & families

Individual

Personal account and device protection for people whose work makes them a target — identity hardening, password and MFA hygiene, and help untangling a compromise.

Account hardeningMFA rolloutIdentity monitoring

// frameworks.supported()

Built Around HIPAA. Fluent in the Rest.

Healthcare is where we go deepest — it is the practice we built the firm around. When a client answers to a different regulator, the same method applies and we say plainly how far we take it.

How to read this

Every consultancy claims every framework. The bar beside each one is how far we actually take it — five means we own the outcome, two means we get you to someone who does.

End to end
Analysis through audit file
Advisory
We build it, counsel files it
Readiness
Prep for a certified assessor

Shared method

  • NIST CSF 2.0Govern → Recover
  • CIS Controls v8Prioritised safeguards
  • NIST SP 800-61Incident handling

The controls overlap heavily, which is why a second framework costs far less than the first.

The annual Security Risk Analysis required at 45 CFR § 164.308(a)(1)(ii)(A), plus the safeguards, documentation, and evidence that make it defensible.

  • Annual Security Risk Analysis & rated risk register
  • Administrative, physical & technical safeguards
  • BAA review and vendor due diligence
  • Breach response, tabletops & audit evidence

Where we stopEnd to end. We run the analysis, scope the remediation, and hand you the audit file.

Not sure which applies to you? Ask on a scoping call

Scoping conversations are free, and we will tell you when something is outside what we should take on.


// services.list()

Healthcare Compliance First, Security Built Around ePHI

Risk analysis and audit evidence are the front door. Everything else here exists because a finding pointed at it — safeguards get implemented on the systems the assessment actually flagged.

HIPAA Security Risk Assessment

Annual SRA support for covered entities and business associates: ePHI workflows, threats, vulnerabilities, likelihood, impact, and prioritized remediation evidence.

HIPAA SRAePHI

Audit Readiness & Evidence

Prepare documentation that administrators can defend: policies, procedures, risk register, remediation plan, vendor artifacts, and executive-ready status reporting.

Audit PrepEvidence

Security Rule Safeguards

Administrative, physical, and technical safeguard reviews mapped to practical controls for clinics, specialty practices, and healthcare operators.

SafeguardsControls

Incident Response for ePHI

Breach triage, containment planning, tabletop exercises, notification decision support, and post-incident hardening for patient-data events.

IR PlanBreach Triage

Secure Healthcare Email

Phishing defense, BEC reduction, spoofing protection, account takeover monitoring, and encrypted delivery for regulated patient communications.

EmailEncryption

Identity & Access Reviews

MFA, role-based access, risky sign-in review, credential exposure monitoring, and workforce access processes for systems touching ePHI.

MFAAccess

Endpoint & EHR Workflow Protection

Endpoint detection, device hardening, patch visibility, and practical security controls around workstations used for EHR and patient operations.

EDREndpoints

M365, SaaS & Cloud Hardening

Tenant configuration, file-sharing controls, backup readiness, SaaS permissions, and cloud data exposure reduction for healthcare teams.

M365SaaS

Clinic Network Segmentation

Firewall, Wi-Fi, VPN, DNS filtering, and segmentation guidance to separate clinical systems, guest access, and administrative operations.

NetworkVPN

HIPAA Security Awareness

Workforce-ready training, phishing simulations, and administrator reporting focused on patient privacy, social engineering, and credential theft.

TrainingPhishing Sim

AI Governance for Patient Data

Approved-tool policies, prompt/data handling guidance, agent guardrails, and shadow AI controls so staff do not leak PHI into unsafe systems.

AI PolicyPHI

Multi-Framework Compliance

One control set, mapped across the regulators you answer to — SEC Regulation S-P, FINRA, and CMMC / NIST SP 800-171 readiness alongside your HIPAA program.

SECCMMCNIST

Fixed fees, scoped before you commit

Two risk-analysis tiers by practice size, remediation quoted per project, and senior advisory by the hour.