HIPAA Compliance – Understanding Basic Best Practices
by Patrick Hughes on March 7, 2023 at 2:30 PM
Health Insurance Portability and Accountability Act (HIPAA) compliance is a critical facet of any healthcare organization's security measures. It is essential for businesses to take proactive steps to ensure that they comply with the regulations set forth by HIPAA. To help ensure comp …
The Difference Between IT Risk Assessments and IT Audits
by Patrick Hughes on July 7, 2021 at 1:00 PM
While information technology (IT) risk assessments and information technology (IT) audits go hand in hand with one another, the two terms are often misused. There are quite a few key differences to note when it comes to IT risk assessments and IT audits and determining which is best f …
The Anatomy of an IT Policy
by Patrick Hughes on March 31, 2021 at 1:00 PM
What are policies and why do we need them? Every organization should have a set of policies in place. Policies are essentially the laws and regulations of an organization. They pertain to the health, safety, and accountability of employees and how the organization interacts with clien …
Succession Planning and Testing – Who Will Step Up to the Plate?
by Patrick Hughes on February 1, 2021 at 9:52 AM
Succession planning is so important to organizations, yet so often overlooked. Many folks are not really sure what it is. For those that get the idea of it, many are at a loss for where to start. In the next couple of minutes, I will take you through what succession planning is, how t …
California Privacy Rights Act of 2020 – CCPA 2.0?
by Patrick Hughes on November 13, 2020 at 3:45 PM
During last week’s election, the state of California voted to pass the new California Privacy Rights Act (CPRA). This legislation is intended to expand and strengthen the current California Consumer Privacy Act (CCPA). Last October I published a blog post outlining the implications of …
Elements of Quality Security and Privacy Awareness Training
by Patrick Hughes on September 3, 2020 at 3:00 PM
As information technology professionals, we often hear the term security awareness training. Most organizations know they need to be conducting continuous security awareness training, whether the goal is to check a box for a framework/regulation they must adhere to, or they genuinely …
.webp?width=2169&height=526&name=Compass%20regular%20transparent%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)
.jpg)




