Regulatory Compliance for organizations that need a current program

Identity, devices, email, and backups operated with the program in mind. You keep the obligation. We run the controls.

Request a compliance reviewSee HIPAA Consulting

Professional reviewing workplace documentation at a desk

IT operated for the rule set you have to meet

Most organizations do not have one program. A clinic has HIPAA and an insurer questionnaire. A manufacturer has a customer security packet and Texas Cybersecurity Safe Harbor (SB 2610). A defense supplier has CMMC on top of the same identity, devices, and email everyone else runs.

Regulatory Compliance is the work of running those systems so the answers come from the live environment, not a binder that drifted. You keep the assessor and the attestation. We run the controls and sit with you when a customer, insurer, or regulator asks how the work is done.

HIPAA program writing lives on HIPAA Consulting. Day to day clinic support lives on Healthcare IT. The tighter security layer lives on Secure IT. This page is the map across programs.

Programs we support

The review names which programs apply and what the live environment already supports. Common work includes HIPAA, Texas Cybersecurity Safe Harbor, CMMC, PCI DSS, NIST CSF, the FTC Safeguards Rule, and customer or insurer questionnaires.

HIPAA

Accounts, devices, mailbox controls, and backups run with patient information in mind. Sign-in, privileged access, encryption, and restore paths have to match the HIPAA program the practice already owes.

BAAs are executed where our services require them. See HIPAA Consulting for the written program and the evidence file.

Texas Cybersecurity Safe Harbor

MFA, least privilege, endpoint standards, email authentication, and monitoring stay on the systems your team uses. Those are the controls the statute is asking Texas firms to show.

See Texas Cybersecurity Safe Harbor for the safe-harbor page.

CMMC

Identity, devices, and email are hardened for a defense-supply assessment. The same controls a customer already runs for office IT become the evidence the assessor will walk through.

You keep the assessment. We run the controls and sit with you when the assessor asks how the systems are operated. See Cybersecurity.

PCI DSS

Card data stays in the smallest possible footprint. Systems that do not need card data stay out of that footprint.

Identity and endpoints around what remains stay tight so the card environment is not the whole office.

NIST Cybersecurity Framework

Identify, protect, detect, respond, and recover mapped to accounts, devices, mail, and backups. Leadership gets a picture of what is already in place and what should change first.

Gaps become a work plan on Secure IT or a defined project.

Customer and insurer questionnaires

Answers come from the live environment: MFA, encryption, backups, logging, and admin access. The packet matches how the systems actually run.

Leadership can show that picture to a customer or a carrier without rebuilding it from memory.

FTC Safeguards Rule

Access, device standards, encryption, and incident handling stay in the same support relationship. The rule expects those controls to be operated, not only written.

That work sits with helpdesk and devices so the program does not drift from the environment.

How the program works

This work usually sits on Secure IT. It can also sit on a defined engagement through Managed IT Services or Co-Managed IT when you keep your own IT function.

Identity and access

Sign-in and admin rights stay tight. Multi-factor authentication, Conditional Access, and least-privilege admin roles live in the directory the organization already runs, including Microsoft 365 or Google Workspace.

Joiner, mover, and leaver changes stay current so unused access does not sit open. Guest and vendor access is part of the same picture when those accounts can reach business information.

Endpoints

Windows, macOS, iPhone, and iPad used for work stay updated, protected, and encrypted where they handle business or regulated information. A lost or unmanaged device is treated as something to close, with a named owner.

Hardware work in the office sits on the managed IT band that includes on-site support.

Email authentication

Inbound filtering, mailbox permissions, forwarding, and authentication stay current on the mail system the organization already runs.

That is where phishing and quiet data movement still show up, and where programs hold or fail in practice.

Logging and backups

You know what is logged, what is backed up, who can restore, and what back to work looks like when something fails.

Patient information is restored only into approved systems. Evidence and recovery stay part of the operating rhythm, not a scramble.

Written procedures

Procedures describe the environment the organization operates today: who approves changes, how the system list stays current, and how BAAs are kept where HIPAA applies. Staff can find them.

That supports your obligation. You stay accountable for the program.

Which path fits

A review of your needs and growth plans shows where the program work should live.

• HIPAA Consulting. The written HIPAA program and the evidence file.

• Secure IT, $250–$400 per user. Complete IT with tighter security and compliance built into the same support.

• Co-Managed IT. Your IT function stays. We take or share the controls the program needs.

Start with a review

A review of your needs and growth plans looks at which programs apply, what the environment already supports, and where the organization is going. You leave knowing whether HIPAA Consulting, Secure IT, or Co-Managed IT is the next step.

From there, your team has an ongoing support relationship, not a one-off project.

Request a compliance review

Related work

HIPAA Consulting · Healthcare IT · Texas Cybersecurity Safe Harbor · Secure IT · Cybersecurity · Managed IT Services · Co-Managed IT

Guides

Plain-language guides to the rules organizations ask us about for compliance and security programs.

See all guides

Support the program. Keep the obligation where it belongs.

You keep the assessor. We run the controls on the systems your team uses.

512-892-6900 · info@alcondts.com

Request a compliance review