Compliance

If the auditor showed up Monday, what would you actually have ready?

The audit is the easy part. The prep is the year of paperwork, policy drafts, vendor BAAs, and evidence collection that nobody warned you about. HIPAA, WISP, SOC 2, PCI and FINRA: this page is what we actually do.

CISSP-Led Security

Encrypted in Transit & at Rest

Background-Checked Techs

BAAs Signed

Which rules apply to you

Four rulebooks. One IT shop.

Most Utah businesses fall under one of these. A few fall under two. Either way, the work is real and someone has to do it.

HIPAA

Senior care and skilled nursing, dental practices, therapy, PT, medical clinics

We build the file of signed vendor agreements, run the security risk analysis, and write the plan for the first hour of a breach.

What this means for you ↓

WISP

Accounting, tax prep, bookkeeping firms

We write the Written Information Security Plan, put the FTC Safeguards controls behind it, and map the whole thing to IRS Publication 4557.

What this means for you ↓

PCI & FINRA

Card acceptance, financial advisors, RIAs, broker-dealers

We keep card traffic on its own network, help you answer the self-assessment questionnaire, set how long records are kept, and write the continuity plan Rule 4370 asks for.

What this means for you ↓

SOC 2

SaaS companies, B2B services

We map the controls your auditor will test, gather the evidence for each one, and hand you the checklist to work through before they arrive.

What this means for you ↓

Healthcare & HIPAA

Your EHR vendor’s BAA covers the database. Not the building.

Software compliance is one row on a much longer checklist. The other rows are the unencrypted laptop that left the building, the printer caching scanned IDs, the imaging device running firmware from 2017, and the vendor nobody remembered to paper, down to the shredder service and the answering service.

A federal auditor or a state surveyor does not ask whether your software is HIPAA-compliant. They ask whether your organization is. Different question, and the evidence for it has to already exist, including a breach notification process you can run in 60 days flat.

In a dental practice

  • The device problems nobody flags

    Intraoral sensors with hard-coded admin passwords. DICOM imaging boxes on the same flat LAN as the guest Wi-Fi. Dentrix or Eaglesoft data sitting at rest on a Windows workstation with full-disk encryption turned off because “it slowed the computer down.”

More dental-specific detail lives on the /dental page.

In a skilled nursing or assisted living facility

  • The EHR is not the whole environment

    PointClickCare or MatrixCare holds the clinical record. It does not hold the med-cart tablet parked in the hallway, the fax line still receiving hospital discharge summaries, or the guest Wi-Fi sitting on the same flat network as the nurses’ station.
  • Shared logins on the floor

    Night shift signs in as the station because it is faster. When a surveyor asks who opened a resident’s chart at 2am, "the station did" is not an answer. Named accounts scoped to the unit, with a login trail, is the fix people actually keep using.
  • Staff are already using AI on their phones

    Someone has pasted a resident’s history into a chatbot to make a note read better. Consumer tiers carry no BAA, which makes that a disclosure. The fix is a written acceptable-use policy plus a tool staff are actually permitted to use.
  • Every vendor that touches resident data needs a BAA

    Pharmacy, therapy contractor, billing service, transport, the answering service, the shredding company. Most facilities have three of them on file and assume the rest were handled by somebody.

More senior-care detail lives on the /senior-care page.

Security Risk Analysis, on paper

The document an auditor expects, and what it takes to build.

Quoted before it starts
ScopeThe whole environment
Typical timelineTwo to four weeks
Practice sizeTypically 5–30 people
DeliverableOne auditor-ready document

Asset inventory. Network diagram. Threat-and-vulnerability table. Workstation-by-workstation encryption check. BAA register. Written remediation plan with owner and date. Not a 4-page PDF you bought on a compliance site.

Talk to us about a Security Risk Analysis

Accounting & tax firms

Every firm with a PTIN needs a WISP. Most have a PDF.

The Written Information Security Plan is the one compliance deadline in this market that recurs every year, applies to firms of every size, and lands on the desk of a partner who already has a full-time job.

The rules, on paper

Recurs every year
Federal ruleFTC Safeguards, 16 CFR 314
IRS guidancePublication 4557
Applies toEvery firm with a PTIN
Size exemptionRemoved, 2023 update
Breach at 500+FTC notice within 30 days

Accounting firms count as financial institutions under Gramm-Leach-Bliley, which is how the FTC rule reaches you. The two rulebooks overlap heavily, and one properly built plan satisfies both instead of two half-built ones.

  • W-01

    What a WISP actually is

    A Written Information Security Plan: the document naming who is responsible, what client data you hold, where it lives, who can reach it, how it is protected, and what you do in the first hour of a breach. Not a template with your letterhead on it.

  • W-02

    Your IT provider is in scope too

    The rule makes you responsible for overseeing service providers through written contracts requiring appropriate safeguards. That includes us. We hand you the contract language and the evidence rather than making you ask for it.

  • W-03

    It has to describe your actual firm

    Which tax software, where the workpapers sit, who has admin, how the portal is configured, what happens when a seasonal preparer leaves in April. A generic plan that does not match your environment is the version that fails when someone reads it closely.

This section is the framework. The accounting and tax firm page is where the firm-shaped version lives, with the bundle and its price. If you want the requirement in detail before talking to anyone, we wrote up what a real WISP contains and the four places templates fail.

Scope a WISP for your firm

Found your rulebook?

You don’t need the whole page. One scoping call sorts out which of this applies to you.

What this actually looks like

  • PCI applies even if you “rarely” take cards

    The moment a client reads you a 16-digit number over the phone and you write it on a sticky note, you're in scope. Most accounting firms fall under SAQ A or SAQ C-VT. We help you stay there instead of accidentally drifting into SAQ D territory.
  • FINRA Rule 4370 - business continuity, in writing

    Business continuity plan, designated emergency contact, annual review, and the cyber-readiness expectations the SEC and FINRA started enforcing in earnest after the 2023 rules update. Most RIAs have a folder of templates. Templates don't survive an exam.
  • Retention, on one schedule

    SEC Rule 17a-43 or 6 years, some permanent
    IRS workpapers7 years
    State boardsAdd their own

    The fix is one retention schedule on paper plus the archive infrastructure to enforce it - not memory and goodwill.

  • Email archiving and WORM storage

    Write-once-read-many storage is the part of 17a-4 most firms quietly fail. Microsoft 365 with Purview, or a third-party archive like Smarsh or Global Relay, configured against a real retention policy. We set it up and verify it actually catches everything.

Card payments & advisory firms

PCI when you take cards. FINRA when you give advice.

The smaller the firm, the more compliance load lands on a single person who already has a real job. We take the recurring work off the partner's desk: archives, retention policy, cybersecurity attestation, the annual review nobody schedules.

And when the SEC or your state board sends the letter, the binder is already on the shelf.

Get a compliance scoping call

B2B SaaS

SOC 2 prep, scoped one step at a time.

Your enterprise prospect asked for your SOC 2. You either have one or you lose the deal. The audit firm (the CPA) costs what it costs: that's not the part we touch. The prep is the part that usually balloons.

Start SOC 2 prep

What the auditor asks for

  • Type I vs Type II

    Type I is a snapshot: on this date, the controls were designed correctly. Useful for closing a deal in 90 days. Type II is the same controls observed operating over a 3-12 month window. Real buyers want Type II. Year one usually means Type I then Type II.
  • What “evidence” really means

    Access-review screenshots dated and signed. Change-log exports. Onboarding and offboarding tickets. Backup-test results with timestamps. Incident-response runbook with one real fire drill. Vendor SOC 2s from every subprocessor. The auditor wants the artifact, not your promise.
  • Year one vs year two cost reality

    Year one is heavy: policies written from scratch, controls implemented, the first 90+ pieces of evidence collected. Year two and beyond is maintenance - the controls run themselves once the plumbing is right. Most firms quote both years the same. They shouldn't.

How we price the prep

  1. 01

    Baseline assessment

    Where you stand today, control by control.

  2. 02

    Gap assessment

    The distance between that and audit-ready, written down.

  3. 03

    Remediation roadmap

    The implementation work, scoped from the gap list: policies, controls, evidence plumbing.

  4. 04

    Type II maintenance

    The controls run and the evidence collects while the observation window is open.

Each rung is scoped and quoted before it starts, so you never buy the whole year blind - and you stop climbing whenever you have what you need.

What we actually do

Here’s what’s on our compliance checklist for a typical clinic.

Read this list and notice how many of these you have, written down, with a date on them. That number is the gap. Closing it is the job.

  • C-01

    BAA inventory and gap analysis

    Every vendor that touches protected health information gets a signed Business Associate Agreement on file. Missing ones get chased.

  • C-02

    Annual Security Risk Analysis (HIPAA Security Rule §164.308)

    Annual

    Asset list, threat table, plan of fixes with owners and dates. The document a federal auditor expects.

  • C-03

    Workstation lockdown to NIST 800-53 moderate baseline

    Disk encryption, screen lock, USB control, local-admin removal, patch cadence. Verified, not assumed.

  • C-04

    Backup-and-restore drill with quarterly attestation

    Quarterly

    A backup you have never restored is not a backup. We run the restore, document it, and sign the attestation.

  • C-05

    Incident response runbook (who calls whom in what order)

    On one page. Names, numbers, decision tree. The thing you grab when something goes wrong at 11pm on a Saturday.

  • C-06

    Vendor risk register (every SaaS your practice uses)

    Living

    What it stores, who owns it, what their SOC 2 says, when their BAA expires. Living spreadsheet.

  • C-07

    Phishing simulation cadence

    Quarterly

    Quarterly send. Reporting on click-throughs. Training the people who clicked. Not a one-time training video.

  • C-08

    Annual policy review and re-signing

    Annual

    Acceptable use, mobile device, remote access, sanctions. Reviewed, dated, signed by every employee.

  • C-09

    Endpoint encryption verification

    Quarterly

    BitLocker or FileVault enabled, key escrowed, reported. We verify quarterly, not just at setup.

  • C-10

    Audit-readiness binder (the thing the auditor actually wants)

    Policies, evidence, attestations, BAAs, training records. One PDF (or one shelf). Updated as we go.

How this gets billed

A plan for the day-to-day. A ladder for the compliance work.

Scoped per rung
Day-to-day ITYour monthly plan
Compliance workScoped rungs, quoted first
Top of the ladderThe Foundation bundle for your industry

Each rung is priced before it starts, and you climb only as far as you need.

Not sure where you stand? The first rung starts with the free IT audit on the /audits page - it tells you where the gaps are before you spend anything.

One boundary worth naming: we prepare the evidence. We are not your auditor. HIPAA, WISP, SOC 2, PCI and FINRA readiness is work we deliver, never a certification we hold.

FAQ

The questions worth asking

What happens if you fail an audit, how long a security risk analysis takes, and why the IT company who “did HIPAA” didn't.

For HIPAA: penalties from the federal Office for Civil Rights scale with how careless they judge you to have been, plus a corrective action plan that can run for years. For PCI: your acquiring bank passes through fines from the card brands until you remediate, and can revoke your ability to take cards. For SOC 2: you don't fail in the same legal sense, but a report with exceptions flagged by the auditor is the one you have to hand prospects, and it tanks deals. The real cost in all three cases is the months of fixing, not the fine.
Two to four weeks for a typical 5-30 person practice. Week one is asset inventory and interviews. Week two is the technical scan and BAA review. Weeks three and four are the writeup and remediation roadmap. You get a document at the end you can hand to an auditor. We don't sell the 4-page template version.
Yes. Because we handle protected health information in the course of supporting your network and endpoints, we’re a business associate, and we sign the BAA at onboarding. It’s part of the welcome paperwork, not an add-on you have to ask for. You can read the standard agreement at app.techgig.ai/baa. Healthcare organizations review and accept the BAA in-app before any purchase.
No, and this is the single most expensive misunderstanding in dental and medical IT. HIPAA-compliant hosting (AWS, Azure, your EHR vendor) means the cloud provider has signed a BAA and meets their part of the Security Rule. It does not cover your network, your endpoints, your employee training, your physical security, or your BAAs with non-cloud vendors. Those are your responsibility. Your EHR being HIPAA-compliant is one row on a 60-row checklist.
Type I is a point-in-time report: on the audit date, the controls were designed properly. It's a snapshot. Type II is the same controls observed operating over a window (commonly 3, 6, or 12 months). Enterprise buyers want Type II because it proves the controls actually run, not just that they existed on one Wednesday. Year one of a SOC 2 program is usually Type I followed by a Type II covering the next 6-12 months. After year one it's annual Type II reports.
Two reasons. First, most MSPs sell a HIPAA add-on that produces a generic policy template, a one-time risk analysis, and an annual training video. None of those are wrong, but together they don't pass an actual audit. Second, the work has to be ongoing: quarterly attestations, vendor BAA refreshes, policy re-signing, phishing cadence. A one-time package doesn't keep the binder current. If you want to test your current MSP's compliance work, ask them for last quarter's backup restore attestation and last year's vendor risk register. The answer will tell you everything.

Get the binder built before the letter arrives.

Book a compliance scoping call. We’ll tell you what’s missing and what it takes to close the gap.

Already a customer? Open a compliance ticket