CYBER RISK & LAW
HandSigning.jpg

Compliance Reviews

Compliance Obligations and Planning


Compliance Reviews



A university medical center was fined $2.75M by the HHS Office of Civil Rights and ordered to create a Risk Management program.

OCR Transaction No. 13-157615, HHS.gov


Meeting Your obligations

Many businesses face compliance obligations. Financial institutions, healthcare providers, government contractors, even game developers have compliance obligations under the law. And now, with the arrival of the California Consumer Privacy Act, most moderately sized companies are facing compliance requirements.

It is no longer enough to simply have an incident response plan in place. Today’s compliance laws require regular risk assessments and the costs can be overwhelming. Our cost effective compliance reviews are based on a comprehensive analysis of your practices, processes, policies and procedures. We interview your IT and business leaders and review your third party contracts for compliance and privacy issues. Our reports follow a template that you can update year over year to satisfy regulators, customers, and even juries.

When we’ve completed our review, you’ll be provided with a report that will identify threats, vulnerabilities, controls and action plans. We’ll also highlight additional steps that need to be taken, such as regular scans and tests including guidance to help you retain the right security solutions.

Our services include:

  • Review of your particular compliance obligations and the development of a comprehensive compliance plan.

  • Preparation of high level risk assessments for presentation before third parties reviewing your compliance obligations.

  • Assistance with the vetting and selection of third party certification providers.

  • Regular updates on compliance obligations and changes in the law that impact your business.

  • Review of your contracting practices to ensure that compliance obligations are met throughout the contracting chain.

  • Representation in legal matters and before regulators.