Regulatory Compliance

ALCON DTS helps Austin and Central Texas organizations run identity, devices, email, and backups so day-to-day IT supports the programs you already have to meet — including HIPAA and Texas SB 2610.

Request a compliance reviewSee HIPAA Consulting

Professional reviewing workplace documentation at a desk

Who this is for

Regulatory Compliance support from ALCON DTS is for clinics and other covered entities, manufacturers, law firms, professional firms, and other SMBs that need the Microsoft 365 tenant, endpoints, and email operated with their rule set in mind — not bolted on after an audit letter arrives.

You stay accountable for your program. ALCON DTS brings the operator work: Entra identity hygiene, managed devices, email authentication, logging and backups, and written procedures that match how your firm actually runs.

When a customer asks for CMMC-style expectations, we help you see what that means for the tenant and devices you already use — and we will say plainly if Secure IT, a scoped engagement, or another path is the better fit. We do not sell a certification.

If you need a dedicated HIPAA engagement, start with HIPAA Consulting. If you need the security layer on managed IT, see Secure IT.

Programs we support

ALCON DTS helps you operate Microsoft 365, devices, email, and backups so day-to-day IT lines up with the programs and questionnaires you already face — with a clear next step for each.

HIPAA

Covered entities have to show that ePHI stays in approved systems, with access, audit, and recovery that match the program — not a policy binder sitting next to an open tenant.

ALCON DTS operates identity in Entra, managed endpoints, mailbox controls, and backups so those HIPAA safeguards have somewhere real to live. BAAs are executed where the service is in scope. The covered entity keeps the legal duty.

HIPAA Consulting · Healthcare IT

Texas SB 2610

Texas small businesses now have a defined path to a cybersecurity program scaled to size. The useful work is on the tenant you already run: MFA, least privilege, endpoint standards, email authentication, and monitoring you can keep.

ALCON DTS implements those controls in Microsoft 365 and on managed devices so the safe-harbor program is operable, not a PDF.

Texas SB 2610

CMMC

Defense contractors are scored on whether CUI and the systems around it are actually controlled — identity, devices, mail, and logging — not on whether someone bought a tool.

ALCON DTS hardens the Microsoft 365 tenant and endpoints so a CMMC effort has a current environment to assess. Your organization still owns certification and the assessor relationship.

Cybersecurity

PCI DSS

Card data should touch as few systems as possible. Most PCI pain is an oversized scope: mailboxes, shared drives, and unmanaged laptops that never needed cardholder data.

ALCON DTS helps shrink that scope, isolate what remains, and tighten identity and endpoints around it. The merchant keeps the PCI obligation. ALCON DTS does not issue an Attestation of Compliance.

Cybersecurity · Secure IT

NIST Cybersecurity Framework

NIST CSF is a shared language for leadership: identify assets, protect them, detect issues, respond, recover. It is useful when it is mapped to the live tenant — users, devices, mail, backups — not when it is a poster.

ALCON DTS uses CSF to show what is already in place and what is missing, then ties the gaps to Secure IT or a scoped project.

Cybersecurity · Secure IT

Customer and insurer questionnaires

Security questionnaires fail when the answers describe a program the tenant does not match. Insurers and customers now check MFA, encryption, backups, logging, and admin access against reality.

ALCON DTS helps you answer from the live Microsoft 365 environment so the form and the tenant agree.

Cybersecurity · Managed IT Services

FTC Safeguards Rule

Professional firms that hold customer financial information need a written safeguards program and someone operating the controls: access, device standards, encryption, and incident handling.

ALCON DTS puts those controls on the systems the firm already uses. You keep the regulatory obligation.

Cybersecurity · Secure IT

How the work runs

Regulatory support from ALCON DTS sits on how you already operate IT — usually Secure IT or a scoped engagement through Managed IT Services, and sometimes a written split of who owns what beside your internal team on Co-Managed IT.

Tenant and identity

Who can sign in, what they can change, and how privileged accounts are used. We tighten Conditional Access expectations and admin-role hygiene so access rules are lived in Entra — not left as a policy nobody can operate.

Endpoints

Managed Windows, macOS, and mobile devices stay on agreed updates, protection, and encryption where they handle business or regulated information. A lost or unmanaged device is an exposure we close with clear ownership — not a footnote.

Email authentication

Inbound filtering, mailbox permissions, forwarding, and authentication controls stay current on the Microsoft 365 tenant. That is where phishing and quiet data movement still show up, and where programs either hold or fail in practice.

Logging and backups

You know what is logged, what is backed up, who can restore, and what “back to work” looks like when something fails. ALCON DTS builds that into the operating rhythm so evidence and recovery are not a scramble.

Written procedures

Expectations are documented enough to run: what is in scope, who approves changes, and how BAAs and system lists stay current where HIPAA applies. That supports your obligation — ALCON DTS does not take it over.

Ready for a compliance review?

A compliance review with ALCON DTS is a practical look at which programs apply, how your tenant, devices, email, and backups are set up today, and what should happen next — HIPAA Consulting, Secure IT, a co-managed split, or a tighter scoped engagement.

You leave with a clear recommendation and a next step you can act on.

Request a compliance review

Related work

HIPAA Consulting · Healthcare IT · Texas SB 2610 · Secure IT · Cybersecurity · Managed IT Services · Co-Managed IT

Support the program. Keep the obligation where it belongs.

ALCON DTS operates the tenant, devices, and email so your program has something solid to stand on.

512-892-6900 · info@alcondts.com

Request a compliance review