Services
Each one starts with an applicability review, because recommending controls before knowing what actually binds you is how compliance budgets get wasted. Everything is structured on NIST CSF 2.0, so the work compounds instead of stacking up.
The rule covers any business significantly engaged in financial activities, which reaches far past banks: lenders, auto dealers, tax preparers, mortgage brokers, title companies, insurance-adjacent firms. Most discover they are covered late. Civil penalties run to tens of thousands of dollars per violation per day, and being non-compliant when a breach happens can also void your cyber insurance.
Firms with fewer than 5,000 consumer records are exempt from some elements, such as the written risk assessment and annual board report, but not from the rule itself. Part of this engagement is establishing exactly where you sit.
For providers, health plans and the business associates that serve them: software vendors, billing firms, IT providers, medical transcription. Enforcement has not slowed while the Security Rule overhaul is pending, and incomplete or missing risk analysis remains the single most cited failure in OCR settlements. The overhaul itself points clearly at where things are heading: encryption, MFA, asset inventory, regular testing.
If you are a business associate selling into health systems, this engagement also equips you to answer customer security questionnaires without improvising each time.
Your staff are already using AI tools, with or without a policy. Customers, insurers and regulators have started asking what controls sit around them. This engagement builds that layer: what is in use, what risk it carries, who reviews it, and what evidence exists that the oversight is real rather than declared.
This is the area where most security consultants have nothing to offer yet. If AI use is what triggered your question, start here.
Next step
Thirty minutes, no charge. If nothing here fits your situation I will tell you that.
Book a scoping call+1 786 664 1200