Services / 02 · Compliance groundwork

The evidence, not the certificate.

Most frameworks that apply to your business are self-assessed and self-attested. What they actually demand is a control that works and a document proving it worked on a date. That is engineering work, and it is the half your compliance consultant cannot do.

01

Lead line · HIPAA Security Rule

Every recent settlement turns on the same missing document.

The Office for Civil Rights runs a Risk Analysis Initiative that had reached its fourteenth enforcement action by June 2026. In February 2026 a small treatment centre settled a breach affecting 1,980 individuals for $103,000. The finding, over and over, is failure to conduct an accurate and thorough risk analysis under 45 CFR 164.308(a)(1)(ii)(A).

That figure matters more than any larger one, because it removes the only objection that ever gets raised: we are too small to be worth anyone’s time. The majority of healthcare practices nationwide are under ten employees, and they are the enforcement population, not an exemption from it.

What the engagement produces

  • Security Risk Analysis under 45 CFR 164.308(a)(1)(ii)(A), documented and dated
  • Risk management plan — findings ranked, owners named, dates attached
  • Technical remediation: MFA, encryption at rest and in transit, access review, logging
  • Asset inventory and a network diagram that matches reality
  • Written policy set, workforce training records, sanction policy
  • Business associate agreement review across your vendors
  • Annual repeat, because a risk analysis from 2021 is an exhibit, not a defence

The part providers keep quiet

An IT provider with access to electronic protected health information is a business associate, signs a BAA, and carries direct liability under HITECH. In March 2026 OCR settled with a dental software vendor — a pure business associate — over exactly this. The Holm Team enters business associate status the moment we take a medical client, which is a reason to trust the programme we build: we operate under the same compliance rules as you.

The proposed Security Rule overhaul that would mandate MFA, encryption, six-monthly scanning and annual penetration testing is not final. It has slipped to July 2027. We build against the rule as it stands and against enforcement as it actually happens — never against a rule that has not been published.

02

Second line · CTPAT MSC §4

Cyber criteria in CTPAT, and nobody technical is addressing them.

The 2019 revision of the CTPAT Minimum Security Criteria added cybersecurity as a full criteria section. Any business engaged in U.S. import or export — whether you operate a customs brokerage, freight forwarding operation, warehouse, or manufacturing facility with international shipments — falls under CTPAT validation requirements. Most are small operations, under ten employees.

The usual failure at validation is not a missing policy. It is the gap between a written security profile and operational reality: compliance points at IT, IT produces a screenshot of a console, and the reviewer wanted policy plus implementation plus test result plus remediation log. Closing that gap is the entire product.

MSC §4, as delivered work

  • Gap assessment against Minimum Security Criteria §4, criterion by criterion
  • Individual named logins, no shared accounts, role-based access
  • MFA on privileged and remote access, and on the VPN
  • Documented password standard and a written disciplinary process
  • IT asset inventory, endpoint malware protection, documented patch cadence
  • Network segmentation between office systems and operations
  • Weekly backups with restore testing you can show evidence for
  • Annually tested incident-response plan and phishing awareness records
  • Evidence package assembled for the Annual Security Profile Review

Why this one fits here

The cyber criteria read like a systems administrator’s checklist: named logins, MFA on remote access, role-based access control, asset inventory, patch cadence, segmentation, tested backups, a rehearsed incident plan. That is the work we do in managed IT support. Your trade-compliance consultant understands the paperwork and cannot configure any of it; we are the inverse, and the two roles sit together well.

No credential exists for CTPAT advisory work — no licence, no assessor status, no accrediting body. The Annual Security Profile Review makes it recurring. Confirm the validation cycle with your supply chain security specialist at CBP before proceeding with any advisory engagement.

03

Attached line · PCI DSS 4.0.1

Not a reason to call. A reason the security work pays for itself twice.

Version 4.0.1 is the only active version, and the 51 future-dated requirements stopped being optional on 31 March 2025. Most merchants are Level 4 and self-assess — no auditor is coming. But the controls are real engineering, and you are buying most of them anyway. Done in the right order, a defensible questionnaire falls out of security work you needed regardless.

Controls we implement

  • Scope confirmation — which systems actually touch card data (12.5.2)
  • MFA for all access into the cardholder data environment (8.4.2)
  • Twelve-character passwords and the account policy behind them (8.3.6)
  • Payment-page script inventory and integrity monitoring (6.4.3, 11.6.1)
  • Automated daily log review (10.4.1.1) and authenticated internal scanning (11.3.1.2)
  • Segmentation so the scope stops growing every time you add a laptop

Honest framing

Nobody is fined for a weak self-assessment before a breach. Any provider leading with PCI urgency is selling fear with no enforcement behind it. What is true is that card-handling systems are the ones criminals actually target, and that a segmented, logged, MFA-protected card environment is cheaper to defend than to rebuild.

So: never a lead engagement, always a well-priced attachment to one. We complete the technical work and hand you the evidence; the questionnaire remains yours to attest.

04

Defense-adjacent · DFARS 252.204-7012

Read this before you buy a readiness engagement from anyone.

On 13 July 2026 the Department of War suspended Phase II of the CMMC rollout and froze the phases after it. Program managers may currently designate only Level 1 (Self) and Level 2 (Self); they are barred from designating Level 2 (C3PAO) or Level 3, and existing contracts carrying those requirements are being amended to remove them. A reform task force is reviewing the programme. The published regulation still contains the old Phase 2 date; it has not been amended and the memoranda control.

The arithmetic behind the pause is worth knowing: roughly 1,391 Level 2 certificates had been issued by May 2026, against the Department’s own estimate of 76,598–118,289 entities that would eventually need one. If anyone is currently selling you third-party certification preparation or telling you a certification deadline is bearing down on you, ask them for the memorandum.

What is still fully in force, and sellable

  • NIST SP 800-171 Rev 2 gap assessment against the 110 requirements
  • System Security Plan and Plan of Action & Milestones, written to be read by an assessor
  • Basic and, where applicable, scored self-assessment support
  • SPRS score posting and the annual affirmation process
  • Level 1 annual self-assessment support — the surviving, still-designatable requirement
  • A customer responsibility matrix covering the services we provide to you

The trap in hiring any IT provider

A provider becomes an external service provider the moment its tooling processes your security protection data — configuration, logs, vulnerability status, or credentials into your environment. Deploying a monitoring agent is enough. Those services then sit inside your assessment scope and get evaluated as security protection assets.

That is not a reason to avoid a provider. It is a reason to hire one who knows it, keeps defense-client tooling segregated from the general book, and hands you a service description and a customer responsibility matrix without being asked twice.

05

Limits

Where we draw the line.

The Holm Team is not a certifying body, and for HIPAA no such thing exists
Nobody can sell you a HIPAA certificate. There is no accrediting authority and no badge. Any provider offering one is either confused or counting on you being. What exists is a risk analysis you perform, a remediation programme you run, and evidence you can produce when OCR asks.
The Holm Team does not perform CMMC certification assessments
Assessment and remediation are separated by a conflict-of-interest firewall: whoever helps you implement cannot be the party who assesses you. We remain on the implementation side of that line. We hold no assessor credential and no third-party assessment organisation status.
The Holm Team will not host your controlled unclassified information
Running CUI on infrastructure we operate would make us a cloud service provider owing FedRAMP Moderate equivalency with an annual third-party audit. That is out of reach for an organization this size, and pretending otherwise would put your contract at risk.
The Holm Team does not provide legal opinions
Whether a specific disclosure is reportable, whether a clause flows down, whether a contract term binds you — that is your attorney's work. We produce the technical evidence they need and we say plainly when a question is outside our scope.

Compliance work also stops at the same licensing perimeter everything else does. Where a control requires new cable, a new circuit, an alarm system or door hardware, we write the specification and you contract the appropriately licensed trade directly. See the services index for the full boundary.

Next step

Find out what you can actually evidence today.

The IT Health & Risk Assessment establishes the baseline every one of these frameworks is measured against. A typical assessment runs 20–40 hours at $165/hr.

medical & dental · customs brokers & forwarders · card-taking retail · defense-adjacent suppliers