IT compliance support for Jacksonville businesses
When a regulator, a prime contractor or your insurance carrier asks how you protect client data, the answer needs to be written down, current and true. We handle the security side of HIPAA, the FTC Safeguards Rule, CMMC Level 1 and cyber insurance requirements, alongside the IT we already run for you.
- HIPAA
- FTC Safeguards Rule
- CMMC Level 1
- Cyber insurance
Four requirements we work with
Each one is written differently, but they ask for a lot of the same things: know your risks, write down how you protect data, train your people, and be able to show it.
HIPAA
Who it covers
Medical and dental practices, and the businesses that handle patient information on their behalf.
What it asks for on the IT side
- A security risk analysis, kept up to date
- Written security policies and procedures
- Staff training, with a record that it happened
- Controls on who can reach patient data
See medical practices and dental
FTC Safeguards Rule
Who it covers
CPA firms, tax preparers, mortgage brokers, auto dealers and other businesses the FTC treats as financial institutions.
What it asks for on the IT side
- A written information security program
- A named person responsible for it
- Risk assessment, multifactor sign-in and encryption
- Security training for your staff
Tax preparers also need a written security plan for the IRS. See accounting and CPA firms
CMMC Level 1
Who it covers
Defense contractors and subcontractors whose contracts involve Federal Contract Information.
What it asks for on the IT side
- The basic safeguarding requirements in FAR 52.204-21
- A self-assessment every year
- An annual affirmation in SPRS by a senior official
If your contracts involve Controlled Unclassified Information, you are looking at Level 2, a much larger project. We will tell you plainly which one you are in.
Cyber insurance
Who it covers
Any business buying or renewing a cyber policy. The application is a security questionnaire, and your answers become part of the policy.
What it asks for on the IT side
- Multifactor sign-in on email and remote access
- Endpoint protection and patching
- Backups kept separate from the network
- Security training for staff
An answer that does not match what is configured can put a claim at risk. We answer from what is actually running.
Compliance that keeps running after the binder is printed
Most of these rules expect an ongoing program, not a one time project. So the work runs on a schedule, every quarter, for as long as you need it.
Quarterly risk reviews
Every quarter we look at what has changed: new staff, new software, new devices, anything that left. You get a written report of what we found and what we are fixing.
Written policies, kept current
We write the security policies your framework asks for, and update them when your setup changes. They describe how your systems are actually configured, because we are the ones configuring them.
Training, assigned and tracked
Security awareness training goes out to your staff, and completion is tracked, so when someone asks whether everyone was trained you have the record, not a guess.
The policy says one thing. The network does another.
The usual pattern goes like this. A consultant writes a policy binder, everyone signs it, and it goes on a shelf. The office changes around it. People leave, new laptops arrive, a new app gets added, and nobody goes back to the binder.
A year later the documents describe a business that no longer exists. That gap is what an auditor, an investigator or an insurance adjuster finds first.
When the people writing your policies are also the people running your systems, the two stay in step. That is the whole idea behind running compliance alongside your IT support and cybersecurity rather than as a separate project.
What we handle, and what stays with you
Compliance is partly technical and partly a business and legal matter. We are clear about which half is ours.
We handle
- Quarterly risk reviews and the written reports
- Security policies, written and kept current
- Security training, assigned and tracked
- The technical controls on your systems
- Answering insurance and contractor security questionnaires accurately
Stays with you and your advisors
- Legal advice and contract terms, including business associate agreements
- Formal audits and certifications, which come from an independent assessor
- Signing your annual affirmations and attestations
- Business decisions, like how long you keep client records
We are not a law firm or an auditor. We work alongside yours.
An add-on, not part of a tier
Compliance is sold together with our vCIO service, as a per seat monthly add-on to a managed or co-managed agreement. It is not bundled into any managed tier, so you only pay for it if you need it, and you can add it later. If you have IT staff of your own, co-managed IT lets them keep running things while we handle the compliance side.
Questions people ask about compliance
Not sure which rules apply to you? Call us at 904-204-6870 and we will work it out with you.
Will you make us compliant?
We handle the security side: quarterly risk reviews, written policies, tracked training and the controls on your systems. Compliance also includes legal and business decisions that only you can make, so it is not something any IT provider can promise on its own. What we can promise is that the IT side will be done and documented.
Which rules apply to our business?
It depends on the data you handle. Patient information points to HIPAA. Client financial information, including tax returns, usually points to the FTC Safeguards Rule. Federal Contract Information on a defense contract points to CMMC. Most businesses with a cyber policy also have insurance requirements to meet. We sort this out with you on the first call.
Do we need CMMC Level 1 or Level 2?
If your contracts only involve Federal Contract Information, Level 1. If you receive Controlled Unclassified Information, Level 2, which is a much larger undertaking. Your contract and the data you are given decide it, and we will tell you plainly which one you are in.
Can you help with our cyber insurance application?
Yes. We go through the questionnaire with you and answer from what is actually configured, and fix the gaps before renewal where we can. An answer that does not match reality can put a claim at risk.
Do we have to be a managed client?
Compliance is an add-on to a managed or co-managed agreement. If you have IT staff of your own, co-managed lets them keep running day to day while we handle the compliance side.
Do you replace our auditor or our attorney?
No. We are not a law firm or an auditor, and we do not certify anyone. We make the IT side true and documented, and work alongside the people who do those jobs.
Find out which rules apply, and where you stand
Thirty minutes to go through the data you handle, the requirements that come with it, and what is already in place.