Working memos from a senior practitioner. Each one is written on the engagement that prompted it, signed by name, and retracted in print when we get it wrong. Written for the people who sign the audit response, not the ones who patch the finding.
Most HIPAA workforce-training programs end the day the certificate prints. OCR’s 2024 and 2025 enforcement actions name the ones that didn’t. No sanctions trail, no role-based reinforcement, no evidence the training changed behavior. A field reading on what business-associate-led organizations should package instead.
Agentic AI pentesting reached production in 2025. Seven additions your risk register needs before your next HIPAA, GLBA, Mass 201, or GDPR audit.
A senior practitioner’s case for replacing the Type 1 attestation with a 14-week readiness sprint, and the roughly $30k it tends to save.
CC9 vendor scrutiny, AI risk under CC3, ConMon-as-evidence, A.5.7 threat intel, A.5.30 ICT readiness. What changed since 2024, and what it costs to ignore.
Under the DoJ Civil Cyber-Fraud Initiative, the affirmation is the signature that carries the exposure. How to package one your senior official can sign without personal False Claims Act risk.
A training certificate is a receipt. OCR, in 2025, started writing settlements that turn on the sanctions program behind it.
No nurture sequence. No partner-of-the-week intro call. No “you might also like” cross-sell to a webinar. One email when a Field Note ships. Nothing else, unless you reply.