Security and compliance leadership for regulated businesses.
Your IT company secures the building. I secure where your patient data actually goes — your EHR, your integrations, your cloud, and your vendors. When an auditor, an insurer, or a breach shows up, I make sure you're covered — and can prove it.
Architect of a healthcare SaaS platform serving 150+ hospitals · HIPAA & SOC 2 · AWS · Terraform Certified · U.S. Air Force veteran
The gap you're sitting in
Your IT company keeps the lights on. It doesn't keep the regulators off.
Most small organizations in regulated fields are caught in the middle — served by generalist IT that treats compliance as an afterthought, and priced out of the firms that specialize in it.
Who I Serve
Businesses the regulators actually check.
I specialize where a real forcing function exists — regulation with teeth, or an insurer asking hard questions. That's where compliance is a requirement, not a nicety.
Addiction & behavioral treatment
HIPAA and the stricter 42 CFR Part 2 for substance-use records — keeping patient data separated and access tracked, plus the audit-ready documentation OCR now enforces directly.
Financial & advisory firms
The FTC Safeguards Rule requires a written security program, a designated person in charge, risk assessments, and real protection for customer data — the exact program I build.
Law firms
Client-confidentiality and technology-competence duties, prime ransomware exposure, and malpractice and cyber insurers asking questions your IT vendor can't answer.
Cyber-insurance readiness
If your renewal questionnaire demands protections you can't truthfully confirm you have, that gap can void a claim when you need it most. I close it before you sign.
How I work
One path: assess, remediate, then hold the line.
A clear sequence — not three disconnected sales. Most engagements start with an assessment and grow into ongoing leadership.
Assessment
A risk assessment and compliance gap analysis mapped to your regime — HIPAA/Part 2, FTC Safeguards, accreditation standards, and the controls insurers require — with a prioritized remediation roadmap and audit-ready documentation.
Including: EHR tenant configuration review · integration and data-egress mapping · tracking-pixel and adtech exposure · AI tool and vendor governance · internal and external vulnerability scanning · physical, access-control and camera review · one on-site day.
The document regulators and insurers ask for first.
Remediation
Fixed-price projects that close the gaps: separating and protecting your networks, strengthening how staff sign in, encrypting devices, backups you've actually tested, activity monitoring, and written policies.
Fractional security & technology leadership
An ongoing retainer where I serve as your named Security Official — continuous oversight, vendor and access review, audit-season support, and board-ready reporting.
A compliance officer and a security engineer, for a fraction of the cost of hiring either.
Why Me?
Two decades building healthcare software, pointed at the part most IT shops skip.
The technical depth to design and configure the fix, and the compliance fluency to make it defensible when someone comes asking.
- I built the software your clinic runs on — twenty years architecting healthcare systems, including a platform serving 150+ hospitals. I know how clinical data actually moves between systems, because I've been on the inside of building them.
- I review your EHR the way an auditor would — roles, shared logins, MFA, audit logs, API keys, and every integration quietly moving data out of it. Most assessments stop at the firewall.
- I check whether your intake form is leaking to advertisers — the FTC has fined behavioral-health organizations millions for tracking pixels, with no breach involved. It takes five minutes to check, and almost nobody has.
- Compliance specialization most providers lack — HIPAA and 42 CFR Part 2, the FTC Safeguards Rule, accreditation standards, and the controls cyber insurers now demand.
- A fractional model — I own your posture and your documentation over time, not a one-off invoice.
What gets checked
The questions your IT vendor isn't being asked.
Good IT keeps systems running. Compliance asks a different set of questions — and they're the ones a regulator, an insurer, or an accreditor opens with.
What your IT company checks
- Is the firewall up?
- Is antivirus installed?
- Are backups running?
- Is everyone's email working?
- Is the Wi-Fi reaching the back office?
What a regulator or insurer checks
- Can you produce a written risk analysis, dated and signed?
- Who has administrator rights in your EHR — and when did anyone last look?
- Where does patient data leave your EHR, and who governs those integrations?
- Has anyone ever restored from a backup to prove it works?
- Can your guest Wi-Fi actually reach a clinical machine? Has anyone tested it, or just assumed?
- When a staff member is terminated on Friday, who disables their access, and by when?
- Is there a tracking pixel on your intake form?
Free resources
Score yourself before someone else does.
Plain-English readiness checklists for the three things most likely to come asking. No sign-up, no email required — take them, use them, share them with your team.
42 CFR Part 2 & HIPAA Readiness Checklist
What OCR asks for first, and what a Part 2 program needs to be able to produce.
FTC Safeguards Rule Readiness Checklist
The written program, the Qualified Individual, and the controls the rule actually requires.
Cyber Insurance Readiness Checklist
What renewal questionnaires ask — and what an inaccurate answer can cost you at claim time.
A 15-minute posture check
Walk through the highest-risk items with me on a call. If you're in good shape, I'll say so.
Find out where you stand.
Book a 15-minute posture check. If you're in good shape, I'll tell you and you've lost nothing. If you're not, you'll know exactly what's exposed — before the letter arrives.
Book a free 15-minute call