Privacy Advisory Services

Privacy Compliance Advisory for Healthcare Organizations and Professional Services Firms

Privacy law is changing faster than most organizations can track. Virginia’s Consumer Data Protection Act is live and enforceable. The FTC Health Breach Notification Rule now applies to health apps. COPPA compliance requirements extend to any digital service used by children. We advise on what these laws actually require — and build the documentation to prove compliance.

Schedule a Privacy Advisory Consultation

Advised by a Juris Master in National Security, Cybersecurity, and Information Privacy Law

Why the Legal Credential Matters

Advising organizations on privacy compliance is different from advising on technical security. The regulatory frameworks are different, the liability exposure is different, and the client trust obligations are different. Kenneth holds a Juris Master in National Security, Cybersecurity, and Information Privacy Law from Antonin Scalia Law School at George Mason University — which means we understand the compliance environment as written, not as interpreted by a salesperson.

Regulatory Frameworks We Address

The privacy laws most relevant to healthcare organizations, professional services firms, and any Virginia business with a digital presence

Virginia Consumer Data Protection Act
Virginia CDPA

Virginia’s CDPA is live and creates enforceable consumer rights: the right to access, correct, delete, and opt out of the sale of personal data. It applies to organizations that control or process data of 100,000+ Virginia consumers annually (or 25,000+ if data is sold).

We assess applicability, review data processing practices, build required privacy notices, and document consumer rights procedures that hold up under enforcement scrutiny.

HIPAA & FTC Health Breach Notification Rule
Healthcare Privacy

HIPAA’s Privacy Rule governs protected health information for covered entities and business associates. The FTC Health Breach Notification Rule — now actively enforced — extends similar requirements to health apps and wellness platforms that handle identifiable health data outside traditional HIPAA coverage.

We review BAA compliance, build required privacy notices, and prepare breach response documentation that satisfies both frameworks.

FTC Safeguards Rule
Financial Services Privacy

The FTC Safeguards Rule requires a written information security program (WISP) from non-bank financial institutions — including mortgage brokers, CPAs, investment advisors, and auto dealers. Full enforcement is active. Civil penalty exposure is real.

We build the WISP, document the required risk assessment, and support ongoing compliance obligations. Most small practices do not have a compliant program in place.

COPPA
Children’s Online Privacy

COPPA applies to any digital service that knowingly collects personal information from children under 13 — including pediatric practices, behavioral health providers, educational platforms, and any app used in pediatric or school settings.

We review data practices, build required parental consent mechanisms, and document compliance controls for the populations your service touches.

What Privacy Advisory Looks Like

Practical advisory — not a policy template you implement alone

Privacy Program Assessment

Review your current data collection practices, vendor agreements, and existing notices against applicable law. Identify gaps and produce a written findings summary with prioritized remediation steps.

Privacy Notice & Policy Development

Draft or revise privacy notices, data processing agreements, and internal policies to meet current regulatory requirements — written in plain language for your clients, not just your lawyers.

Vendor & BAA Review

Review business associate agreements and data processing addenda with your technology vendors. Identify contractual gaps that create regulatory exposure and recommend remediation language.

Breach Response Preparation

Build a documented breach response plan that satisfies HIPAA, FTC Health Breach Notification Rule, and Virginia CDPA notification requirements — so you are not figuring it out during an incident.

WISP & IRS Safeguards Compliance

Build a Written Information Security Plan that satisfies FTC Safeguards Rule requirements for CPAs, tax preparers, mortgage brokers, and other non-bank financial institutions. Most small firms do not have a compliant plan.

Workforce Privacy Training

Plain-language training that helps staff understand what data they handle, what they can share, and what to do when something goes wrong — documented and tracked for compliance purposes.

Who We Work With

We work with organizations across the United States. Privacy compliance is not one-size-fits-all — the regulatory exposure depends on who your clients are, what data you handle, and which laws apply to your organization.

Healthcare & Behavioral Health
Physician practices, mental health providers, pediatric specialists, and any organization handling protected health information or health app data
Law Firms & Legal Practices
Firms nationwide navigating ABA Model Rule 1.6 security obligations, state bar breach notification requirements, and client data confidentiality
CPAs & Financial Advisors
Non-bank financial institutions required to maintain a compliant Written Information Security Plan under the FTC Safeguards Rule
Nonprofits
Organizations handling donor data, beneficiary information, and grant compliance requirements that increasingly include documented privacy programs
State Privacy Law Compliance
Organizations in Virginia and other states with consumer privacy laws — including the Virginia CDPA — that need to understand their obligations and document a compliant response

Ready to Know Where You Actually Stand?

Schedule a 30-minute consultation. We’ll identify your highest-priority privacy compliance obligations and tell you exactly what a remediation program looks like — whether you hire us or not.

Schedule a Privacy Advisory Consultation

For our website privacy policy, click here.