HIPAA, FTC Safeguards and California privacy obligations — configured in your tenant and documented as evidence.
No product makes a firm compliant. Every regulation that applies to you — HIPAA, the FTC Safeguards Rule, California’s breach statutes — asks the same two questions: what controls do you have, and can you prove they were operating.
Most small firms can answer the first question and fail the second. The controls exist. The evidence that they were configured, reviewed and enforced does not, because nobody wrote it down. That gap is invisible right up until an audit, an insurance renewal, or a breach.
For covered entities and business associates. Requires a documented risk analysis, access controls, audit logging, workforce training and signed Business Associate Agreements with every vendor touching PHI.
Binding on CPA firms, tax preparers and other non-bank financial institutions. Requires a written information security programme, a named qualified individual, and vendor oversight.
Civil Code 1798.29 and 1798.82 set breach notification duties; CCPA and CPRA add consumer rights obligations for firms over the applicable thresholds.
Increasingly the sharpest deadline. Enterprise clients send security questionnaires and cyber insurers require attestations — both need answers you can substantiate.
We will not tell you a tool makes you HIPAA compliant, because no tool does. Microsoft 365 can be configured to support HIPAA compliance and Microsoft will sign a BAA covering eligible services — a default tenant with the BAA signed is still not compliant, and firms are sold that misunderstanding constantly.
Our tool-by-tool compliance guides cover what individual vendors do and do not cover, including Microsoft 365, Google Workspace, Dropbox, DocuSign, Slack and others.
Compliance and security are the same work viewed from two angles — see cybersecurity services. Workforce training is a named HIPAA requirement: see security awareness training. If you are already in a breach, notification timelines start immediately — see incident response.
No. Microsoft will sign a Business Associate Agreement covering eligible Microsoft 365 services at no extra cost, which is a prerequisite. But a default tenant is not compliant: audit logging retention, access controls, MFA, encryption policy and data-loss prevention all have to be configured, and the risk analysis and written policies still have to exist. The BAA covers Microsoft's obligations, not yours.
If you prepare tax returns or provide financial services, almost certainly yes — the Rule defines non-bank financial institutions broadly enough to include most CPA and tax practices. It requires a written information security programme, a designated qualified individual accountable for it, a risk assessment, and documented oversight of service providers. Many firms discovered this obligation only when an insurer or a client asked.
It is a documented assessment of where regulated data lives, what could compromise it, and what you have done about each risk. Under HIPAA it is explicitly required and it is the single most common finding in enforcement actions — not because firms are insecure, but because they never wrote it down. It is not a one-time document; it needs revisiting when your environment changes.
We can usually configure the technical controls quickly, because most of them are settings in a tenant you already own. What cannot be compressed honestly is the evidence of operation — a log retention policy set yesterday does not produce a year of logs. We will tell you what is genuinely achievable in your timeline and what will have to be presented as in-progress.
Both, and they are not separable. Configuring a control without documenting it leaves you unable to demonstrate it, and a policy document describing controls that are not actually configured is worse than nothing — it is a written record of a gap between what you claim and what you do.
Schedule a free consultation today.