Privacy Advisory Services
Privacy law is changing faster than most organizations can track. Virginia’s Consumer Data Protection Act is live and enforceable. The FTC Health Breach Notification Rule now applies to health apps. COPPA compliance requirements extend to any digital service used by children. We advise on what these laws actually require — and build the documentation to prove compliance.
Schedule a Privacy Advisory ConsultationAdvised by a Juris Master in National Security, Cybersecurity, and Information Privacy Law
Why the Legal Credential Matters
Advising organizations on privacy compliance is different from advising on technical security. The regulatory frameworks are different, the liability exposure is different, and the client trust obligations are different. Kenneth holds a Juris Master in National Security, Cybersecurity, and Information Privacy Law from Antonin Scalia Law School at George Mason University — which means we understand the compliance environment as written, not as interpreted by a salesperson.
The privacy laws most relevant to healthcare organizations, professional services firms, and any Virginia business with a digital presence
Virginia’s CDPA is live and creates enforceable consumer rights: the right to access, correct, delete, and opt out of the sale of personal data. It applies to organizations that control or process data of 100,000+ Virginia consumers annually (or 25,000+ if data is sold).
We assess applicability, review data processing practices, build required privacy notices, and document consumer rights procedures that hold up under enforcement scrutiny.
HIPAA’s Privacy Rule governs protected health information for covered entities and business associates. The FTC Health Breach Notification Rule — now actively enforced — extends similar requirements to health apps and wellness platforms that handle identifiable health data outside traditional HIPAA coverage.
We review BAA compliance, build required privacy notices, and prepare breach response documentation that satisfies both frameworks.
The FTC Safeguards Rule requires a written information security program (WISP) from non-bank financial institutions — including mortgage brokers, CPAs, investment advisors, and auto dealers. Full enforcement is active. Civil penalty exposure is real.
We build the WISP, document the required risk assessment, and support ongoing compliance obligations. Most small practices do not have a compliant program in place.
COPPA applies to any digital service that knowingly collects personal information from children under 13 — including pediatric practices, behavioral health providers, educational platforms, and any app used in pediatric or school settings.
We review data practices, build required parental consent mechanisms, and document compliance controls for the populations your service touches.
Practical advisory — not a policy template you implement alone
Review your current data collection practices, vendor agreements, and existing notices against applicable law. Identify gaps and produce a written findings summary with prioritized remediation steps.
Draft or revise privacy notices, data processing agreements, and internal policies to meet current regulatory requirements — written in plain language for your clients, not just your lawyers.
Review business associate agreements and data processing addenda with your technology vendors. Identify contractual gaps that create regulatory exposure and recommend remediation language.
Build a documented breach response plan that satisfies HIPAA, FTC Health Breach Notification Rule, and Virginia CDPA notification requirements — so you are not figuring it out during an incident.
Build a Written Information Security Plan that satisfies FTC Safeguards Rule requirements for CPAs, tax preparers, mortgage brokers, and other non-bank financial institutions. Most small firms do not have a compliant plan.
Plain-language training that helps staff understand what data they handle, what they can share, and what to do when something goes wrong — documented and tracked for compliance purposes.
We work with organizations across the United States. Privacy compliance is not one-size-fits-all — the regulatory exposure depends on who your clients are, what data you handle, and which laws apply to your organization.
Schedule a 30-minute consultation. We’ll identify your highest-priority privacy compliance obligations and tell you exactly what a remediation program looks like — whether you hire us or not.
Schedule a Privacy Advisory ConsultationFor our website privacy policy, click here.