Built by someone who has run the program, not just reviewed it
We are led by Tim Williams, a former healthcare CISO who now brings the same discipline to practices and vendors that do not need a full-time security department.
Background
Tim served as Chief Information Security Officer at national healthcare companies, where he owned security, privacy engineering, and compliance across multi-state operations. In those roles he built the programs that regulators, payers, and health system customers examine most closely.
He led HITRUST r2 certification efforts end to end, from scoping and control design through assessor fieldwork and certification. That work sets the bar for how evidence is gathered and documented in every engagement here.
He also reported security posture directly to boards and audit committees, which is why our reporting is short, quantified, and written for people who do not work in security.
We exist because the same rigor is available to a fifteen-person practice or an early-stage healthcare vendor, at a price that is agreed before the work starts.
Four commitments
Numbers, not adjectives
Findings come with counts, costs, and dates. If we cannot quantify why something matters, it does not belong in the report.
No shame
Nobody gets lectured for what was not done before. We start from where you are and move forward.
No checkbox theater
A binder nobody reads does not protect patients or pass a real review. We build things your team can maintain.
One senior person
The work is delivered by the person you meet on the scoping call, start to finish.
About the practice
Talk with Tim directly
A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.