Compliance support

IT compliance support for Jacksonville businesses

When a regulator, a prime contractor or your insurance carrier asks how you protect client data, the answer needs to be written down, current and true. We handle the security side of HIPAA, the FTC Safeguards Rule, CMMC Level 1 and cyber insurance requirements, alongside the IT we already run for you.

  • HIPAA
  • FTC Safeguards Rule
  • CMMC Level 1
  • Cyber insurance
Which rules apply

Four requirements we work with

Each one is written differently, but they ask for a lot of the same things: know your risks, write down how you protect data, train your people, and be able to show it.

Healthcare

HIPAA

Who it covers

Medical and dental practices, and the businesses that handle patient information on their behalf.

What it asks for on the IT side

  • A security risk analysis, kept up to date
  • Written security policies and procedures
  • Staff training, with a record that it happened
  • Controls on who can reach patient data

See medical practices and dental

Financial

FTC Safeguards Rule

Who it covers

CPA firms, tax preparers, mortgage brokers, auto dealers and other businesses the FTC treats as financial institutions.

What it asks for on the IT side

  • A written information security program
  • A named person responsible for it
  • Risk assessment, multifactor sign-in and encryption
  • Security training for your staff

Tax preparers also need a written security plan for the IRS. See accounting and CPA firms

Defense

CMMC Level 1

Who it covers

Defense contractors and subcontractors whose contracts involve Federal Contract Information.

What it asks for on the IT side

  • The basic safeguarding requirements in FAR 52.204-21
  • A self-assessment every year
  • An annual affirmation in SPRS by a senior official

If your contracts involve Controlled Unclassified Information, you are looking at Level 2, a much larger project. We will tell you plainly which one you are in.

Any business

Cyber insurance

Who it covers

Any business buying or renewing a cyber policy. The application is a security questionnaire, and your answers become part of the policy.

What it asks for on the IT side

  • Multifactor sign-in on email and remote access
  • Endpoint protection and patching
  • Backups kept separate from the network
  • Security training for staff

An answer that does not match what is configured can put a claim at risk. We answer from what is actually running.

What the service includes

Compliance that keeps running after the binder is printed

Most of these rules expect an ongoing program, not a one time project. So the work runs on a schedule, every quarter, for as long as you need it.

Quarterly risk reviews

Every quarter we look at what has changed: new staff, new software, new devices, anything that left. You get a written report of what we found and what we are fixing.

Written policies, kept current

We write the security policies your framework asks for, and update them when your setup changes. They describe how your systems are actually configured, because we are the ones configuring them.

Training, assigned and tracked

Security awareness training goes out to your staff, and completion is tracked, so when someone asks whether everyone was trained you have the record, not a guess.

Why it breaks

The policy says one thing. The network does another.

The usual pattern goes like this. A consultant writes a policy binder, everyone signs it, and it goes on a shelf. The office changes around it. People leave, new laptops arrive, a new app gets added, and nobody goes back to the binder.

A year later the documents describe a business that no longer exists. That gap is what an auditor, an investigator or an insurance adjuster finds first.

When the people writing your policies are also the people running your systems, the two stay in step. That is the whole idea behind running compliance alongside your IT support and cybersecurity rather than as a separate project.

Example: a policy written two years ago
The policy says
The network shows
Accounts are removed when someone leaves
Two former employees can still sign in
Every laptop is encrypted
The three newest laptops were never checked
Staff are trained every year
Last training was at each person's first week
Multifactor sign-in on all email
The shared front desk mailbox is exempt
Where our part ends

What we handle, and what stays with you

Compliance is partly technical and partly a business and legal matter. We are clear about which half is ours.

We handle

  • Quarterly risk reviews and the written reports
  • Security policies, written and kept current
  • Security training, assigned and tracked
  • The technical controls on your systems
  • Answering insurance and contractor security questionnaires accurately

Stays with you and your advisors

  • Legal advice and contract terms, including business associate agreements
  • Formal audits and certifications, which come from an independent assessor
  • Signing your annual affirmations and attestations
  • Business decisions, like how long you keep client records

We are not a law firm or an auditor. We work alongside yours.

How it is billed

An add-on, not part of a tier

Compliance is sold together with our vCIO service, as a per seat monthly add-on to a managed or co-managed agreement. It is not bundled into any managed tier, so you only pay for it if you need it, and you can add it later. If you have IT staff of your own, co-managed IT lets them keep running things while we handle the compliance side.

Questions

Questions people ask about compliance

Not sure which rules apply to you? Call us at 904-204-6870 and we will work it out with you.

Will you make us compliant?

We handle the security side: quarterly risk reviews, written policies, tracked training and the controls on your systems. Compliance also includes legal and business decisions that only you can make, so it is not something any IT provider can promise on its own. What we can promise is that the IT side will be done and documented.

Which rules apply to our business?

It depends on the data you handle. Patient information points to HIPAA. Client financial information, including tax returns, usually points to the FTC Safeguards Rule. Federal Contract Information on a defense contract points to CMMC. Most businesses with a cyber policy also have insurance requirements to meet. We sort this out with you on the first call.

Do we need CMMC Level 1 or Level 2?

If your contracts only involve Federal Contract Information, Level 1. If you receive Controlled Unclassified Information, Level 2, which is a much larger undertaking. Your contract and the data you are given decide it, and we will tell you plainly which one you are in.

Can you help with our cyber insurance application?

Yes. We go through the questionnaire with you and answer from what is actually configured, and fix the gaps before renewal where we can. An answer that does not match reality can put a claim at risk.

Do we have to be a managed client?

Compliance is an add-on to a managed or co-managed agreement. If you have IT staff of your own, co-managed lets them keep running day to day while we handle the compliance side.

Do you replace our auditor or our attorney?

No. We are not a law firm or an auditor, and we do not certify anyone. We make the IT side true and documented, and work alongside the people who do those jobs.

Find out which rules apply, and where you stand

Thirty minutes to go through the data you handle, the requirements that come with it, and what is already in place.