Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022

Protect Patient Data. Enable Digital Health.

From digital health startups to health systems, I help healthcare organizations build security programs that protect PHI, achieve HIPAA and HITRUST certification, and meet global privacy requirements including GDPR and CPRA.

Trusted by

  • The Coca-Cola Company
  • Cigna
  • Optum Health
  • Lumen Technologies
  • Fannie Mae
  • Marriott
  • CDW
  • WWT
  • Carter's
  • Katalon
  • Hood Container
  • Envista Forensics
  • Cardow Jewelers
  • COR Partners
  • Eberl's
  • Payspan
  • ABM

The pressure in this market

These are the challenges I hear from leaders in your space every day.

HIPAA Compliance Anxiety

Uncertainty about what controls you need, how to document them, and whether you'd survive an OCR audit.

PHI Protection Pressure

Every patient record is a potential breach. The stakes are higher than any other industry.

Healthcare Partner Requirements

Health systems and payers have security questionnaires that can make or break your deals.

Legacy System Challenges

Medical devices, EHR integrations, and legacy systems create unique security challenges.

Healthcare & Healthtech Track Record

Proven Results in Your Industry

Numbers that speak to my experience working with healthcare & healthtech organizations.

0+

Healthcare Clients

0%

Audit Pass Rate

0mo

Avg. HIPAA Timeline

0M+

PHI Records Protected

How I Can Help

Tailored solutions based on 20+ years of security experience.

HIPAA & HITRUST Program

Complete security program development aligned with HIPAA Security Rule and HITRUST CSF requirements.

  • Risk analysis
  • HITRUST CSF mapping
  • Technical safeguards
  • Workforce training
  • Certification support

Global Privacy Compliance

GDPR and CPRA compliance for healthcare organizations with international or California patients.

  • Privacy impact assessments
  • Data subject rights workflows
  • Cross-border transfer documentation
  • Consent management

Vendor Security Assessment

Evaluate and manage third-party risks across your healthcare supply chain.

  • BAA review
  • Vendor questionnaires
  • Risk scoring
  • Continuous monitoring

Incident Response Planning

Breach notification-ready incident response tailored to healthcare requirements.

  • IR playbooks
  • Breach notification procedures
  • OCR response preparation
  • GDPR 72-hour notification
Proven Results

Healthcare & Healthtech Success Story

Real outcomes from companies in your industry.

Client

Series A Digital Health Startup

4 mo
To Compliance
$2M
Contract Closed
100%
Audit Ready
Zero
Findings

Key Outcome

Achieved HIPAA compliance in 4 months, closed $2M enterprise health system contract

Built complete HIPAA security program from scratch
Implemented technical safeguards for AWS infrastructure
Created workforce training and policy documentation
Prepared for and supported first enterprise security review
Established ongoing compliance monitoring processes
Trained internal team to maintain program independently
Common Questions

Healthcare & Healthtech Security FAQs

Answers to the questions I hear most often from healthcare & healthtech leaders.

For most digital health startups, I can help you achieve HIPAA compliance in 3-6 months depending on your current maturity. Companies with existing security foundations may move faster, while those starting from scratch typically need the full timeline. The key is building a sustainable program, not just checking boxes.

Next step

Ready to secure your Healthcare & Healthtech business?

Thirty minutes is enough to map the specific challenges, the next audit or deal, and whether a fractional CISO or a scoped project is the fit.