Compliance
If the auditor showed up Monday, what would you actually have ready?
The audit is the easy part. The prep is the year of paperwork, policy drafts, vendor BAAs, and evidence collection that nobody warned you about. HIPAA, WISP, SOC 2, PCI and FINRA: this page is what we actually do.
CISSP-Led Security
Encrypted in Transit & at Rest
Background-Checked Techs
BAAs Signed
Which rules apply to you
Four rulebooks. One IT shop.
Most Utah businesses fall under one of these. A few fall under two. Either way, the work is real and someone has to do it.
HIPAA
Senior care and skilled nursing, dental practices, therapy, PT, medical clinics
We build the file of signed vendor agreements, run the security risk analysis, and write the plan for the first hour of a breach.
What this means for you ↓WISP
Accounting, tax prep, bookkeeping firms
We write the Written Information Security Plan, put the FTC Safeguards controls behind it, and map the whole thing to IRS Publication 4557.
What this means for you ↓PCI & FINRA
Card acceptance, financial advisors, RIAs, broker-dealers
We keep card traffic on its own network, help you answer the self-assessment questionnaire, set how long records are kept, and write the continuity plan Rule 4370 asks for.
What this means for you ↓SOC 2
SaaS companies, B2B services
We map the controls your auditor will test, gather the evidence for each one, and hand you the checklist to work through before they arrive.
What this means for you ↓Healthcare & HIPAA
Your EHR vendor’s BAA covers the database. Not the building.
Software compliance is one row on a much longer checklist. The other rows are the unencrypted laptop that left the building, the printer caching scanned IDs, the imaging device running firmware from 2017, and the vendor nobody remembered to paper, down to the shredder service and the answering service.
A federal auditor or a state surveyor does not ask whether your software is HIPAA-compliant. They ask whether your organization is. Different question, and the evidence for it has to already exist, including a breach notification process you can run in 60 days flat.
In a dental practice
The device problems nobody flags
Intraoral sensors with hard-coded admin passwords. DICOM imaging boxes on the same flat LAN as the guest Wi-Fi. Dentrix or Eaglesoft data sitting at rest on a Windows workstation with full-disk encryption turned off because “it slowed the computer down.”
More dental-specific detail lives on the /dental page.
In a skilled nursing or assisted living facility
The EHR is not the whole environment
PointClickCare or MatrixCare holds the clinical record. It does not hold the med-cart tablet parked in the hallway, the fax line still receiving hospital discharge summaries, or the guest Wi-Fi sitting on the same flat network as the nurses’ station.Shared logins on the floor
Night shift signs in as the station because it is faster. When a surveyor asks who opened a resident’s chart at 2am, "the station did" is not an answer. Named accounts scoped to the unit, with a login trail, is the fix people actually keep using.Staff are already using AI on their phones
Someone has pasted a resident’s history into a chatbot to make a note read better. Consumer tiers carry no BAA, which makes that a disclosure. The fix is a written acceptable-use policy plus a tool staff are actually permitted to use.Every vendor that touches resident data needs a BAA
Pharmacy, therapy contractor, billing service, transport, the answering service, the shredding company. Most facilities have three of them on file and assume the rest were handled by somebody.
More senior-care detail lives on the /senior-care page.
Security Risk Analysis, on paper
The document an auditor expects, and what it takes to build.
Asset inventory. Network diagram. Threat-and-vulnerability table. Workstation-by-workstation encryption check. BAA register. Written remediation plan with owner and date. Not a 4-page PDF you bought on a compliance site.
Accounting & tax firms
Every firm with a PTIN needs a WISP. Most have a PDF.
The Written Information Security Plan is the one compliance deadline in this market that recurs every year, applies to firms of every size, and lands on the desk of a partner who already has a full-time job.
The rules, on paper
Accounting firms count as financial institutions under Gramm-Leach-Bliley, which is how the FTC rule reaches you. The two rulebooks overlap heavily, and one properly built plan satisfies both instead of two half-built ones.
- W-01
What a WISP actually is
A Written Information Security Plan: the document naming who is responsible, what client data you hold, where it lives, who can reach it, how it is protected, and what you do in the first hour of a breach. Not a template with your letterhead on it.
- W-02
Your IT provider is in scope too
The rule makes you responsible for overseeing service providers through written contracts requiring appropriate safeguards. That includes us. We hand you the contract language and the evidence rather than making you ask for it.
- W-03
It has to describe your actual firm
Which tax software, where the workpapers sit, who has admin, how the portal is configured, what happens when a seasonal preparer leaves in April. A generic plan that does not match your environment is the version that fails when someone reads it closely.
This section is the framework. The accounting and tax firm page is where the firm-shaped version lives, with the bundle and its price. If you want the requirement in detail before talking to anyone, we wrote up what a real WISP contains and the four places templates fail.
Found your rulebook?
You don’t need the whole page. One scoping call sorts out which of this applies to you.
What this actually looks like
PCI applies even if you “rarely” take cards
The moment a client reads you a 16-digit number over the phone and you write it on a sticky note, you're in scope. Most accounting firms fall under SAQ A or SAQ C-VT. We help you stay there instead of accidentally drifting into SAQ D territory.FINRA Rule 4370 - business continuity, in writing
Business continuity plan, designated emergency contact, annual review, and the cyber-readiness expectations the SEC and FINRA started enforcing in earnest after the 2023 rules update. Most RIAs have a folder of templates. Templates don't survive an exam.Retention, on one schedule
SEC Rule 17a-43 or 6 years, some permanentIRS workpapers7 yearsState boardsAdd their ownThe fix is one retention schedule on paper plus the archive infrastructure to enforce it - not memory and goodwill.
Email archiving and WORM storage
Write-once-read-many storage is the part of 17a-4 most firms quietly fail. Microsoft 365 with Purview, or a third-party archive like Smarsh or Global Relay, configured against a real retention policy. We set it up and verify it actually catches everything.
Card payments & advisory firms
PCI when you take cards. FINRA when you give advice.
The smaller the firm, the more compliance load lands on a single person who already has a real job. We take the recurring work off the partner's desk: archives, retention policy, cybersecurity attestation, the annual review nobody schedules.
And when the SEC or your state board sends the letter, the binder is already on the shelf.
Law firms
Client confidentiality is a technical control now
ABA Model Rule 1.6(c) expects reasonable efforts to prevent disclosure of client information, and the duty of technology competence stopped being optional years ago. For a small Utah firm, that translates to specific infrastructure, not a policy memo.
Matter-level access control
Shared drives where every paralegal can open every matter are how conflicts and privilege problems start. Access scoped per matter, with an audit trail.
Encrypted email and client file exchange
Attachments over plain email are the default breach. We set up encrypted transport and a client portal your clients will actually use.
Retention and litigation-hold readiness
A written retention schedule plus the archive to enforce it, so a hold notice is a switch you flip and not a scramble.
More detail lives on the /legal page.
B2B SaaS
SOC 2 prep, scoped one step at a time.
Your enterprise prospect asked for your SOC 2. You either have one or you lose the deal. The audit firm (the CPA) costs what it costs: that's not the part we touch. The prep is the part that usually balloons.
What the auditor asks for
Type I vs Type II
Type I is a snapshot: on this date, the controls were designed correctly. Useful for closing a deal in 90 days. Type II is the same controls observed operating over a 3-12 month window. Real buyers want Type II. Year one usually means Type I then Type II.What “evidence” really means
Access-review screenshots dated and signed. Change-log exports. Onboarding and offboarding tickets. Backup-test results with timestamps. Incident-response runbook with one real fire drill. Vendor SOC 2s from every subprocessor. The auditor wants the artifact, not your promise.Year one vs year two cost reality
Year one is heavy: policies written from scratch, controls implemented, the first 90+ pieces of evidence collected. Year two and beyond is maintenance - the controls run themselves once the plumbing is right. Most firms quote both years the same. They shouldn't.
How we price the prep
- 01
Baseline assessment
Where you stand today, control by control.
- 02
Gap assessment
The distance between that and audit-ready, written down.
- 03
Remediation roadmap
The implementation work, scoped from the gap list: policies, controls, evidence plumbing.
- 04
Type II maintenance
The controls run and the evidence collects while the observation window is open.
Each rung is scoped and quoted before it starts, so you never buy the whole year blind - and you stop climbing whenever you have what you need.
What we actually do
Here’s what’s on our compliance checklist for a typical clinic.
Read this list and notice how many of these you have, written down, with a date on them. That number is the gap. Closing it is the job.
- C-01
BAA inventory and gap analysis
Every vendor that touches protected health information gets a signed Business Associate Agreement on file. Missing ones get chased.
- C-02
Annual Security Risk Analysis (HIPAA Security Rule §164.308)
AnnualAsset list, threat table, plan of fixes with owners and dates. The document a federal auditor expects.
- C-03
Workstation lockdown to NIST 800-53 moderate baseline
Disk encryption, screen lock, USB control, local-admin removal, patch cadence. Verified, not assumed.
- C-04
Backup-and-restore drill with quarterly attestation
QuarterlyA backup you have never restored is not a backup. We run the restore, document it, and sign the attestation.
- C-05
Incident response runbook (who calls whom in what order)
On one page. Names, numbers, decision tree. The thing you grab when something goes wrong at 11pm on a Saturday.
- C-06
Vendor risk register (every SaaS your practice uses)
LivingWhat it stores, who owns it, what their SOC 2 says, when their BAA expires. Living spreadsheet.
- C-07
Phishing simulation cadence
QuarterlyQuarterly send. Reporting on click-throughs. Training the people who clicked. Not a one-time training video.
- C-08
Annual policy review and re-signing
AnnualAcceptable use, mobile device, remote access, sanctions. Reviewed, dated, signed by every employee.
- C-09
Endpoint encryption verification
QuarterlyBitLocker or FileVault enabled, key escrowed, reported. We verify quarterly, not just at setup.
- C-10
Audit-readiness binder (the thing the auditor actually wants)
Policies, evidence, attestations, BAAs, training records. One PDF (or one shelf). Updated as we go.
How this gets billed
A plan for the day-to-day. A ladder for the compliance work.
Each rung is priced before it starts, and you climb only as far as you need.
Not sure where you stand? The first rung starts with the free IT audit on the /audits page - it tells you where the gaps are before you spend anything.
One boundary worth naming: we prepare the evidence. We are not your auditor. HIPAA, WISP, SOC 2, PCI and FINRA readiness is work we deliver, never a certification we hold.
FAQ
The questions worth asking
What happens if you fail an audit, how long a security risk analysis takes, and why the IT company who “did HIPAA” didn't.
Get the binder built before the letter arrives.
Book a compliance scoping call. We’ll tell you what’s missing and what it takes to close the gap.
Already a customer? Open a compliance ticket