Security · Compliance · Fractional Leadership

Security and compliance leadership for regulated businesses.

Your IT company secures the building. I secure where your patient data actually goes — your EHR, your integrations, your cloud, and your vendors. When an auditor, an insurer, or a breach shows up, I make sure you're covered — and can prove it.

Architect of a healthcare SaaS platform serving 150+ hospitals · HIPAA & SOC 2 · AWS · Terraform Certified · U.S. Air Force veteran


The gap you're sitting in

Your IT company keeps the lights on. It doesn't keep the regulators off.

Most small organizations in regulated fields are caught in the middle — served by generalist IT that treats compliance as an afterthought, and priced out of the firms that specialize in it.

The first documentIn any audit or complaint, regulators ask for your written risk analysis first — the one most small organizations can't produce.
$150K+ vs. $30KA full-time security director costs six figures. A national consultancy's assessment starts around $30K. Neither fits a lean operation.
The trigger isn't sizeA complaint, an audit, an insurance renewal, a breach — it arrives on its own schedule, and it's too late to prepare once it does.

Who I Serve

Businesses the regulators actually check.

I specialize where a real forcing function exists — regulation with teeth, or an insurer asking hard questions. That's where compliance is a requirement, not a nicety.

Behavioral health & SUD

Addiction & behavioral treatment

HIPAA and the stricter 42 CFR Part 2 for substance-use records — keeping patient data separated and access tracked, plus the audit-ready documentation OCR now enforces directly.

Financial · accounting · tax

Financial & advisory firms

The FTC Safeguards Rule requires a written security program, a designated person in charge, risk assessments, and real protection for customer data — the exact program I build.

Forcing function: FTC Safeguards Rule & GLBA
Legal

Law firms

Client-confidentiality and technology-competence duties, prime ransomware exposure, and malpractice and cyber insurers asking questions your IT vendor can't answer.

Forcing function: Bar ethics & cyber insurance
Any insured business

Cyber-insurance readiness

If your renewal questionnaire demands protections you can't truthfully confirm you have, that gap can void a claim when you need it most. I close it before you sign.

Forcing function: Underwriting & renewals

How I work

One path: assess, remediate, then hold the line.

A clear sequence — not three disconnected sales. Most engagements start with an assessment and grow into ongoing leadership.

Assessment

A risk assessment and compliance gap analysis mapped to your regime — HIPAA/Part 2, FTC Safeguards, accreditation standards, and the controls insurers require — with a prioritized remediation roadmap and audit-ready documentation.

Including: EHR tenant configuration review · integration and data-egress mapping · tracking-pixel and adtech exposure · AI tool and vendor governance · internal and external vulnerability scanning · physical, access-control and camera review · one on-site day.

The document regulators and insurers ask for first.

Remediation

Fixed-price projects that close the gaps: separating and protecting your networks, strengthening how staff sign in, encrypting devices, backups you've actually tested, activity monitoring, and written policies.

Fractional security & technology leadership

An ongoing retainer where I serve as your named Security Official — continuous oversight, vendor and access review, audit-season support, and board-ready reporting.

A compliance officer and a security engineer, for a fraction of the cost of hiring either.


Why Me?

Two decades building healthcare software, pointed at the part most IT shops skip.

The technical depth to design and configure the fix, and the compliance fluency to make it defensible when someone comes asking.

  • I built the software your clinic runs on — twenty years architecting healthcare systems, including a platform serving 150+ hospitals. I know how clinical data actually moves between systems, because I've been on the inside of building them.
  • I review your EHR the way an auditor would — roles, shared logins, MFA, audit logs, API keys, and every integration quietly moving data out of it. Most assessments stop at the firewall.
  • I check whether your intake form is leaking to advertisers — the FTC has fined behavioral-health organizations millions for tracking pixels, with no breach involved. It takes five minutes to check, and almost nobody has.
  • Compliance specialization most providers lack — HIPAA and 42 CFR Part 2, the FTC Safeguards Rule, accreditation standards, and the controls cyber insurers now demand.
  • A fractional model — I own your posture and your documentation over time, not a one-off invoice.

What gets checked

The questions your IT vendor isn't being asked.

Good IT keeps systems running. Compliance asks a different set of questions — and they're the ones a regulator, an insurer, or an accreditor opens with.

What your IT company checks

  • Is the firewall up?
  • Is antivirus installed?
  • Are backups running?
  • Is everyone's email working?
  • Is the Wi-Fi reaching the back office?

What a regulator or insurer checks

  • Can you produce a written risk analysis, dated and signed?
  • Who has administrator rights in your EHR — and when did anyone last look?
  • Where does patient data leave your EHR, and who governs those integrations?
  • Has anyone ever restored from a backup to prove it works?
  • Can your guest Wi-Fi actually reach a clinical machine? Has anyone tested it, or just assumed?
  • When a staff member is terminated on Friday, who disables their access, and by when?
  • Is there a tracking pixel on your intake form?

Free resources

Score yourself before someone else does.

Plain-English readiness checklists for the three things most likely to come asking. No sign-up, no email required — take them, use them, share them with your team.

Behavioral health & SUD

42 CFR Part 2 & HIPAA Readiness Checklist

What OCR asks for first, and what a Part 2 program needs to be able to produce.

Financial · accounting · tax

FTC Safeguards Rule Readiness Checklist

The written program, the Qualified Individual, and the controls the rule actually requires.

Any insured business

Cyber Insurance Readiness Checklist

What renewal questionnaires ask — and what an inaccurate answer can cost you at claim time.

Not sure where to start?

A 15-minute posture check

Walk through the highest-risk items with me on a call. If you're in good shape, I'll say so.

Book a call →

Find out where you stand.

Book a 15-minute posture check. If you're in good shape, I'll tell you and you've lost nothing. If you're not, you'll know exactly what's exposed — before the letter arrives.

Book a free 15-minute call