Folks who have known me awhile have probably noticed my pivot. After more than 25 years in IT consulting, I saw a recurring problem: organizations were relying on technology to support sensitive work, but they did not always have clear visibility into the compliance responsibilities that came with it.

That was especially true in healthcare.

Covered Entities often assumed their IT vendors had certain risks handled. IT consultants and MSPs often assumed compliance was mainly the client’s responsibility. But in practice, the lines can get blurry fast.

A vendor may have access to systems containing ePHI. A consultant may sign a Business Associate Agreement without fully understanding the obligations behind it. A client may ask whether something is “HIPAA compliant,” and the answer may be more complex than either side realizes.

That gap is where risk lives.

My approach is grounded in decades of real-world IT experience, so I do not treat compliance like theory. I translate it into practical decisions, better documentation, and clearer conversations.

It is also shaped by years of emergency preparedness training and volunteer work, which taught me to identify risks early, clarify responsibilities, and prepare before pressure exposes the gaps.

Today, I help Covered Entities, technology consultants, and MSPs identify compliance blind spots, strengthen privacy and security practices, and build practical safeguards around HIPAA, cybersecurity, sensitive data, and responsible AI use.

Compliance is not just about passing an audit. It is about building the habits, documentation, and accountability that protect your organization every day.