Writing

The security questionnaire playbook: how to handle a 300-question health system assessment without losing two weeks

Health system security questionnaires are not the same as generic SaaS reviews. Here is the playbook I use to answer them faster and better.

Read more →

BAA structuring for healthtech startups: what your template is missing

Most healthtech startups sign the first BAA a health system sends. Here is what you are actually agreeing to and how to structure yours before they ask.

Read more →

Choosing a SOC 2 auditor for your healthtech startup

Most startups pick a SOC 2 auditor the way they pick a SaaS vendor. That sequence costs months. Here is what actually matters when your product handles PHI.

Read more →

What a 12-week SOC 2 + HIPAA timeline actually looks like for a Series A healthtech startup

A week-by-week breakdown of getting audit-ready for SOC 2 and HIPAA simultaneously, with specific milestones, realistic time costs, and the observation period trap most CTOs discover too late.

Read more →

SOC 2 for healthtech: which trust service criteria actually matter when you handle PHI

Most SOC 2 guides are written for generic SaaS. Healthtech startups handling PHI need a different scope. Here is which trust service criteria actually matter and where HIPAA overlaps.

Read more →

HIPAA 2026: the rule changes your healthtech startup is not prepared for

The proposed HIPAA Security Rule update eliminates the distinction between addressable and required specifications. If you handle PHI, everything that used to be optional is about to become mandatory. Here is what that means for your engineering team.

Read more →

The compliance wall: what happens when your healthtech startup's biggest deal asks for SOC 2 and HIPAA

The universal trigger moment for healthtech startups. A health system sends a security questionnaire, and the CTO realizes nobody owns compliance. Here is what it actually costs and what to do in the first 48 hours.

Read more →