Blog

    Notes on compliance & audit readiness

    A practitioner's perspective on SOC 2, HITRUST, HIPAA, enterprise security reviews, and building durable security programs at healthcare startups.

    July 8, 2026
    Featured

    I Help Companies Pass Their First Audit

    Nobody starts a company because they're excited about audits. You start a company because you're building something you believe in. Then one day, growth arrives — and it comes holding a 300-question security questionnaire.

    Read article
    July 3, 2026
    Featured

    The GRC Skill Nobody Puts in the Job Description

    Read any GRC job description. You'll see the frameworks: HITRUST, SOC 2, ISO 27001. You'll see "risk management," "policy development," "audit support." You know what you'll never see listed as a core competency? Managing other people's chaos.

    Read article
    June 26, 2026
    Featured

    Healthcare AI Has a Compliance Problem Your Security Program Doesn't Solve

    A healthcare AI startup can do everything a traditional security program asks for — SOC 2, HIPAA, tight access controls, encryption everywhere — and still have a serious compliance gap. Because the model itself introduces risks that classic security programs were never built to catch.

    Read article
    July 16, 2026

    AI Can Generate a Compliance Program. It Can't Build One.

    "AI got us compliant." I've started hearing this, and it makes me wince — not because AI has no place in compliance, but because of what that sentence usually means.

    Read article
    June 19, 2026

    You Probably Don't Need HITRUST

    I've led multiple HITRUST certifications over the past decade — from full r2 implementations across 19 control domains to recertifications under aggressive timelines. So believe me when I say: most companies pursuing HITRUST shouldn't be.

    Read article
    June 18, 2026

    The First People You Cut Are the Ones Holding Your Audit Together

    When "where can we trim?" comes up, DevOps engineers are often among the first names on the list. From the compliance seat, that's one of the most self-defeating cuts a company can make.

    Read article
    June 12, 2026

    The Mistake Startups Make Hiring Their First Security Person

    Founders say "we finally hired someone to own security" like it's a milestone. Sometimes it is. Often it's an expensive problem wearing the costume of a solution.

    Read article
    June 5, 2026

    You Probably Don't Need a CISO Yet. You Need Governance.

    A lot of early-stage founders think their next security move is hiring a CISO. Usually, it isn't. What they actually need is governance — and those are very different purchases.

    Read article
    May 22, 2026

    The Compliance Program That Exists Only in Google Drive

    Let me describe a compliance program I meet all the time. It lives entirely in Google Drive. There's a folder called "Policies (FINAL)." Right next to it, "Policies (FINAL v2)." Somewhere nearby, "Policies_USE_THIS_ONE."

    Read article
    May 8, 2026

    Compliance Isn't a Cost Center — Stop Folding It Into Someone Else's Job

    There's a tempting line of reasoning I hear every cost-cutting season: "Can't we just fold compliance into engineering? Or legal? Or have the ops person pick it up?" I get the impulse. I also think it's one of the more expensive mistakes a growing company can make.

    Read article
    April 24, 2026

    It's Wednesday. Sales Just Sent You a 300-Question Security Review.

    It's Wednesday afternoon. Someone from sales pings you: "Hey, quick one — a prospect sent over a security questionnaire. Who should fill this out?" You open it. It's 300 questions.

    Read article
    April 10, 2026

    The First 10 Controls I Look At When Assessing a Healthcare Startup

    When I start with a healthcare startup, I don't open with frameworks. I open with the same short list of controls — because they tell me almost everything about how seriously a company takes security before anyone says a word.

    Read article
    March 20, 2026

    AI in Compliance — Use It, But Know Where It Bites

    I built an AI/LLM governance framework for a health-tech company. I also use AI tools in my own compliance practice every week. So this isn't an anti-AI post. It's a "here's where AI will quietly wreck your audit" post.

    Read article
    February 27, 2026

    AI Governance Is Not an AI Policy Document

    A company tells me they've "handled AI governance." I ask to see it. They send me a two-page AI policy. That's not governance. That's a document about governance — a very different thing, and the gap between the two is exactly where the risk lives.

    Read article
    February 12, 2026

    An Audit Is a Character Analysis

    Strip away the frameworks and the acronyms, and an audit is asking a surprisingly human question: can you be trusted to do the right thing when no one's watching?

    Read article