Frameworks and regulations · United States
Pick your industry. The frameworks that apply light up.
Eighteen frameworks and regulations, one control set. Map to it once and every other framework becomes a subset: evidence produced one time, reused for the auditor, the examiner, the prime and the customer questionnaire.
The map
Industry to framework to the package we start with.
Healthcare & Dental
Ransomware crews target small practices because records are valuable and defenses are thin; OCR treats a missing risk analysis as the violation itself.
HIPAA Security Rule · Administrative, physical and technical safeguards for ePHI, anchored on a documented, accurate risk analysis.
HIPAA Breach Notification Rule · Notify affected individuals within 60 days of discovery; breaches of 500 or more go to HHS and the media.
HITECH and the 2021 amendment · Business associates carry the Security Rule; recognized security practices in place for 12 months (NIST CSF, 405(d)) count in your favor at enforcement.
Where we start: Practice Cybersecurity, Data Protection and HIPAA Package · Mock Audit Package: SOC 2, HIPAA or CMMC · Cyber and Data Protection Assessment
All eighteen
Each one on its own page: what it asks for, who carries it, what satisfies it.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Not sure which apply? Thirty minutes settles it.
An engineer maps your data, your buyers and your markets to the frameworks you actually owe, and gives you a written scope with a fixed fee where one fits.