Skip to content
Seb Smith
Services

Security and compliance help for healthtech teams

A lot of compliance work ends up landing on the engineering team. I've been through SOC 2, ISO 27001, HIPAA and GDPR on BEACON at Hunter Healthcare, so I can help you work out what the controls mean for your product and what needs to change.

The details

Usually includes

  • Gap analysis against SOC 2, ISO 27001, HIPAA or GDPR
  • Reviewing access control, audit logging and encryption
  • Change management and deployment controls
  • Setting up evidence collection so audits are less painful
  • Help with security questionnaires and due diligence

What you get

  • A plain-English gap analysis for the frameworks you care about.
  • A prioritised list of engineering work, with rough effort.
  • Hands-on help closing the gaps if you want it.

A good fit if

  • A customer or investor has asked for SOC 2 or ISO 27001 and you're not sure where to start.
  • You handle health data and want a second pair of eyes on how it's protected.
  • You've bought a compliance platform and the engineering tasks are piling up.

How it usually goes

  • Understand the product, the data it holds and what's driving the compliance work.
  • Compare the relevant controls with what's already in place.
  • Prioritise the gaps by audit risk and effort.
  • Close them with your team, or hand over a plan you can run with.

Things I look out for

  • Shared or over-privileged production access
  • Missing or unreliable audit logs
  • Health data ending up in logs, analytics or third-party tools
  • Vendors handling health data without the right agreements
  • Changes reaching production without review
  • Retention and deletion rules that only exist on paper

Questions

Which frameworks do you cover?

SOC 2, ISO 27001, HIPAA and UK and EU GDPR. They overlap a lot, so the same engineering work often helps with more than one.

Are you an auditor?

No. I help you get ready for an audit and keep the controls running afterwards. The audit itself has to be done by an independent firm.

Is this a penetration test?

No, that's a separate specialist service. I can help you prepare for one and work through the findings.

Want to talk it through?

Book a quick call, or send me a bit of context and I'll let you know if it sounds like something I can help with.