Skip to content

Compliance

HIPAA, PCI, SOC 2, and the practical work of getting and staying compliant.

HIPAA Compliant AI for Medical Practices: Copilot or a Private Server?

Compliance

HIPAA Compliant AI for Medical Practices: Copilot or a Private Server?

HIPAA compliant AI for medical practices, and how a governed Microsoft 365 Copilot setup compares to a private AI server on cost, compliance, and local support.

Sep 4, 2026

Microsoft Purview for Copilot: Set Up the Guardrails First

Compliance

Microsoft Purview for Copilot: Set Up the Guardrails First

How Purview sensitivity labels, DLP, and audit control what Microsoft 365 Copilot can read, cite, and log, and the setup order that keeps the AI inside bounds.

Aug 28, 2026

PCI Compliance for Dentists: What to Prove and Submit

Compliance

PCI Compliance for Dentists: What to Prove and Submit

PCI compliance for dentists: pick the right SAQ, keep policies and scans current, submit the attestation packet, and avoid monthly non-compliance fees.

Aug 17, 2026

PCI Compliance for a Doctor's Office: What to Submit

Compliance

PCI Compliance for a Doctor's Office: What to Submit

PCI compliance for a doctor's office: the SAQ, policies, scans, and attestation your processor or EHR expects, so you avoid fees and keep taking cards.

Aug 17, 2026

HIPAA IT Requirements: What Your Practice Actually Needs

Compliance

HIPAA IT Requirements: What Your Practice Actually Needs

HIPAA names outcomes, not products. Here are the IT controls the Security Rule actually requires from a medical practice, and the document OCR asks for first.

Updated Aug 4, 2026

Microsoft Purview Audit: The Log That Answers Who Did What

Compliance

Microsoft Purview Audit: The Log That Answers Who Did What

Microsoft Purview Audit explained: what the Microsoft 365 audit log records, why Business plans ship with it turned off, and how to switch it on today.

Aug 3, 2026

How to Find Sensitive Data in Microsoft 365

Compliance

How to Find Sensitive Data in Microsoft 365

How to find sensitive data in Microsoft 365 with Purview: sensitive information types, Content Explorer, DLP test mode, and what your license includes.

Jul 28, 2026

Is Microsoft 365 HIPAA Compliant? Yes, With Setup

Compliance

Is Microsoft 365 HIPAA Compliant? Yes, With Setup

Microsoft 365 can be HIPAA compliant, but not out of the box. What the BAA covers, the licensing you need, and the Purview settings that actually protect PHI.

Jul 28, 2026

How to Send Encrypted Email in Microsoft 365

Compliance

How to Send Encrypted Email in Microsoft 365

How to send encrypted email in Microsoft 365 using the Encrypt button or sensitivity labels, what outside recipients see, and the licensing you need.

Jul 27, 2026

Securing Microsoft 365 Copilot with Microsoft Purview

Compliance

Securing Microsoft 365 Copilot with Microsoft Purview

How to secure Microsoft 365 Copilot with Microsoft Purview: DSPM for AI, sensitivity labels, DLP, audit trails, and fixing oversharing before you roll it out.

Updated Jul 26, 2026

What Is Microsoft Purview?

Compliance

What Is Microsoft Purview?

Microsoft Purview, explained in plain English: what it is, what it does inside Microsoft 365, and why it matters for your data, compliance, and security.

Updated Jul 26, 2026

Cyber Insurance Requirements: The IT Controls Insurers Expect

Compliance

Cyber Insurance Requirements: The IT Controls Insurers Expect

Cyber insurance requirements explained: the controls insurers now demand, from MFA to tested backups, and how to meet them without a renewal scramble.

Updated Jul 20, 2026

Microsoft Purview Retention and Data Lifecycle

Compliance

Microsoft Purview Retention and Data Lifecycle

Microsoft Purview retention in plain English: retention policies vs labels, what to keep and delete, records management, and the licensing you actually need.

Jul 8, 2026

How to Become PCI Compliant: A Plain-English Guide

Compliance

How to Become PCI Compliant: A Plain-English Guide

How to become PCI compliant, step by step: figure out which SAQ applies to you, meet the 12 requirements, keep the evidence, and report to your bank each year.

Jul 5, 2026

How to Implement the NIST Cybersecurity Framework

Compliance

How to Implement the NIST Cybersecurity Framework

How to implement the NIST Cybersecurity Framework 2.0: the six functions in plain English, a practical first-90-days plan, and how CSF differs from CMMC.

Jul 5, 2026

How to Prepare for CMMC: A Contractor's Guide

Compliance

How to Prepare for CMMC: A Contractor's Guide

How to prepare for CMMC: find your level, scope FCI and CUI, close the gaps against NIST 800-171, and get assessment-ready before the 2026 deadlines land.

Jul 5, 2026

Microsoft Purview Insider Risk Management, Explained

Compliance

Microsoft Purview Insider Risk Management, Explained

Microsoft Purview Insider Risk Management, in plain English: what it catches, the privacy safeguards built in, the licensing you need, and how it differs from DLP.

Jul 5, 2026

Microsoft Purview Sensitivity Labels Explained

Compliance

Microsoft Purview Sensitivity Labels Explained

Microsoft Purview sensitivity labels classify a file and can encrypt it, so the protection stays with the data after it leaves. How they work in Microsoft 365.

Jun 14, 2026

SOC 2 Compliance: What It Really Takes to Get Ready

Compliance

SOC 2 Compliance: What It Really Takes to Get Ready

SOC 2 compliance, explained plainly: what the report is, the Trust Services Criteria, the controls and tools you need, and a realistic timeline to get ready.

Updated Jun 12, 2026

Data Loss Prevention (DLP) with Microsoft Purview

Compliance

Data Loss Prevention (DLP) with Microsoft Purview

Microsoft Purview DLP, explained simply: what data loss prevention protects, where it works in Microsoft 365, and how to roll it out without slowing your team.

Jun 10, 2026

HIPAA Compliance for Dental Practices: What You Actually Need

Compliance

HIPAA Compliance for Dental Practices: What You Actually Need

A plain guide to HIPAA for dental practices: risk assessment, access controls, encryption, tested backups, BAAs, training, audit logs, and breach steps.

Jun 9, 2026

Find out where you stand

Tell us a little about your business and what is prompting this. We will come back with a clear scope and a fair, written quote, usually within one business day.

Call (855) 737-9500 / (480) 573-3349

Email [email protected]

15-minute response on critical issues, 24/7. Onboarding in two to three weeks.

We reply within one business day. No spam, no pressure.