HIPAA, PCI DSS, and cyber insurance, kept current
An outdated risk assessment is the most common finding we see. We keep yours current, with the evidence behind it and a fix list your IT team can work from.
A current risk assessment, refreshed annually and whenever something material changes.
A dated fix list specific enough that your IT team can run it without a translation layer.
Nine documents in one portal, exportable as a single PDF when someone asks.

Three frameworks, one overlapping set of controls.
Most of our clients are under two of these, and the second one costs almost nothing to add.
Applies if
You create, store or touch protected health information, as a provider or as a vendor to one.
Usually triggered by
Payer questionnaires, MIPS attestation, BAA requests, insurance renewals.
Applies if
You accept card payments.
Usually triggered by
Acquirer questionnaires, SAQ deadlines, a processor threatening noncompliance fees.
Applies if
You're renewing or applying.
Usually triggered by
An application asking about MFA, backups, logging and offsite copies that you can't honestly answer yes to.
The controls overlap heavily. We assess once against the combined requirement and map the evidence to each, so you don't pay twice for the same work.
You're probably here because one of these just happened.
Tagged by who's asking, because that changes what you need first.
A payer, hospital or partner sent a security questionnaire and you can't answer half of it.
Someone requested your vendor agreements and you found three, in three different places.
Your cyber insurance renewal asks about a risk assessment in the last 12 months. You're not sure.
Your card processor is threatening noncompliance fees over an SAQ nobody has touched.
You attested to a Security Risk Analysis for MIPS and quietly hoped nobody would check.
A company down the road got hit and your leadership started asking questions.
You inherited a binder from a consultant and nothing in it has changed since.
Two or more of these?
Keep reading. None of them? You probably don't need us yet.
The difference between a project and a program.
Every framework asks the same three questions: what do you have, what could go wrong with it, and what did you do about it. Programs fail when the document stops matching the business.
A compliance project
Compliance as a service
What you get
A PDF, delivered once
A program, maintained year round
After the report
Remediation, policies, training and vendor agreements are your problem
Every finding becomes a dated, owned, prioritized task
When things change
The report starts going stale the day it lands
Reassessed annually and whenever something material changes
When someone asks
You rebuild the evidence in a hurry
You forward it to us
Who's accountable
Nobody after delivery
Us, on a cycle
A fixed monthly fee for the program, not the document.
Your team does most of the fixing, which is why the plan is written to be executed. If you'd rather we did the work, we scope and quote it separately, and you approve it before anything starts.
01
Assess
Weeks 1 to 2
Risk assessment against the frameworks that apply to you. A full inventory of systems, data and vendors, including the ones nobody remembers signing up for, and external exposure testing.
You get
Written findings, ranked by risk
02
Plan
After the assessment
Every finding becomes a dated, owned, prioritized task. Not “improve access controls”: which system, which setting, which order, and what it protects.
You get
A fix list your IT team can run
03
Maintain
Ongoing
Assessment refreshed annually and whenever something material changes. Policies matched to how you operate, training tracked by name, vendor agreements calendared, and a quarterly 30 minute review.
You get
A one page status, any time
04
Respond
When it lands
When the questionnaire, the renewal application, the audit request or the incident lands, you forward it to us.
You get
Someone else writes the answer
The most common serious findings.
A policy binder surfaces none of this. An assessment that includes external testing does, which is why we test from the outside every cycle.
01
Systems reachable from the open internet
Our single most frequent high risk finding. Remote access left open, or a server exposed during a project that nobody closed.
Most frequent
02
No current risk assessment
Several of the companies we assess have never done one at all.
Very common
03
Vendor agreements missing or expired
Often for vendors nobody realized were touching regulated data.
Common
04
Training records that don't exist
In organizations where the training genuinely happened.
Common
05
Backups never tested with a restore
A backup you haven't restored from is a plan, not a capability.
Seen regularly
A relative scale across the assessments we've run, not a published statistic.
Could you produce them today?
Whatever the framework, an assessor, an insurer or a customer's security team looks for the same artifacts. Clients get all nine in one portal, exportable as a single PDF.
Current risk assessment, dated within 12 months, with stated methodology
Risk treatment plan showing what you fixed, when, and what's still open
Written policies matched to your actual systems
Workforce training records with names, dates and completion
Asset and data inventory: what you have, where it lives, who can reach it
Vendor register with signed agreements and renewal dates
Access reviews with terminations proven
Contingency plan with a dated restore test, not just a written plan
Incident response runbook with the notification clocks built in
If you can't produce these today, that isn't a failure of diligence. It's what happens when compliance is treated as a project instead of a program.
From $350 a month.
We publish that because you're going to ask anyway. We won't quote a final number without seeing your environment, but we'll give you a bracketed range on the first call.
What sets your number
How many frameworks apply, how many locations, how many people touch regulated data, how many vendors need agreements, any legacy systems that can't be patched or encrypted, and how far behind you're starting.
What's included
Assessment and reassessment, external exposure testing, policies, training records, vendor register, evidence portal, questionnaire and renewal support, and a quarterly review.
What's not included
Remediation labor. If you want us to do the fixing rather than your own team, we scope and quote it separately, depending on findings. You approve it before anything starts.
Including the ones that don't involve us.
Approaches, not providers: what each one leaves you holding a year later.
Approach
Who assesses
Stays current
Turns findings into a plan
Someone accountable
DIY templates
You
No
No
You
Compliance software only
You, in their app
Only if you update it
A checklist, not a sequence
You
One time consultant
Them, once
Stale in 12 months
Rarely: the report ends at findings
Nobody after delivery
Compliance as a service
Us, on a cycle
Yes
Yes: dated, owned, sequenced
Us, from $350 a month
When we're the wrong call.
Three situations where you should spend your money somewhere else.
01
One location, one framework, and someone internal who likes this work?
Software plus a one time assessment is legitimate, and cheaper than us.
02
Big enough to justify a full time compliance hire?
Hire. We'd rather tell you that now than in month four.
03
“Our IT provider handles compliance.”
They might. Ask for the risk assessment and the training completion records. If both exist and are current, you probably don't need us. Most managed IT contracts cover uptime and security tooling, not compliance programs.
The limits, stated up front.
We can't make you “HIPAA certified”
There's no such thing. HHS certifies nobody and endorses no certifying body. PCI has a formal validation path; HIPAA does not. Anyone selling you a HIPAA certificate is selling you a logo. What exists is documented, demonstrable compliance, and that's what we build.
We can't give you legal advice
We build and maintain the evidence. A regulatory inquiry or a reportable breach needs counsel, and we'll work alongside them. We can refer you to an attorney if you don't have one.
We can't fix an organization that won't participate
Staff have to complete training. Leadership has to approve remediation and sometimes spend money replacing equipment that can't be secured. If your team won't sit through 60 minutes once a year, no service solves that.
We can't make unsupported software compliant
If you're running an operating system or a line of business application the vendor no longer patches, the honest answer is that it needs replacing, and you'll hear it in week two rather than month ten.
This isn't an audit of your IT team.
Most of our clients have their own IT staff. So the real question in the room is usually whether an outside assessment turns into a list of everything your people missed.
Your IT lead sees it first
Findings go to whoever engaged us first, and we walk your IT lead through them before anyone else sees a summary. No surprise slide in a leadership meeting.
Almost nothing we find is a competence problem
Internal teams are measured on uptime, tickets and projects. Nobody is measured on whether the risk assessment is current or the vendor register has renewal dates.
Your team gets a defensible plan, not a lecture
Prioritized, specific, sequenced and written to be executed. In practice, we're usually the thing your IT lead has already been asking for budget to address, arriving with the evidence attached.
We're not angling for your IT contract
We do the compliance program. If you ever want to talk about anything else, you'll have to bring it up.
Book a 30 minute gap review
We'll tell you where you stand against HIPAA and PCI DSS, what to fix first, and what it would cost to keep it current.
