Comprehensive state privacy laws carry HIPAA carve-outs, research exemptions, and employee-data provisions that generalist firms miss — so we scope per data stream, not per company.
Comprehensive state privacy laws include HIPAA carve-outs, research exemptions, and employee-data provisions that generalist firms often miss. We scope per data stream, not per company — the same organization may have PHI-governed clinical-trial data and non-PHI consumer-health or patient-services data, each treated differently under HIPAA, MHMDA, MODPA, CMIA, and the twenty state comprehensive laws.
Plain-English summaries, per-function action items, and reusable client conversation notes — refreshed monthly. Walk through it before we meet, filtered to your state footprint.
Open the Radar™We’ll start with the data streams and business activities that matter, then identify the obligations and evidence your program actually needs.