← All insights

Compliance and professional-office security

Security Governance for Offices Handling Regulated Information

Professional offices can make compliance more manageable by connecting obligations to ownership, evidence, access control, and tested response.

A professional-office manager organizing security and compliance evidence in a secure records workspace

Compliance is not a substitute for security

Law firms, accounting practices, financial-services offices, medical practices, insurance agencies, and other professional organizations often handle information that carries contractual, ethical, regulatory, or legal obligations. The correct security program depends on the office’s services, data, clients, vendors, and jurisdiction.

No general checklist can declare an office compliant. A useful program starts by identifying obligations and then showing how daily controls address them.

Build an obligation register

Create a register with one row for each requirement or promise. Possible sources include:

  • Federal privacy or security rules.
  • State breach-notification requirements.
  • Client contracts and security addenda.
  • Cyber-insurance conditions.
  • Professional ethics or confidentiality duties.
  • Payment-card or financial-sector requirements.
  • Government-contracting requirements.

For each item, record the source, affected data, responsible owner, required evidence, review frequency, and counsel or compliance contact. Mark proposed rules separately from final requirements. This distinction matters: a proposal may signal direction and planning needs without being an enforceable final obligation.

Use the HIPAA example carefully

The HIPAA Security Rule establishes administrative, physical, and technical safeguards for electronic protected health information handled by covered entities and business associates. HHS published a proposed rule in late 2024 and January 2025 materials describing possible changes to strengthen cybersecurity. A proposed rule is not the same as a final rule. Medical and health-related offices should monitor official HHS and OCR updates and obtain advice specific to their status and contracts.

The practical response is not to wait for a rule change. Review access, risk analysis, workforce training, contingency planning, vendor agreements, logging, and incident response against current obligations.

Treat access as a professional responsibility

Confidential information should be accessible only to people who need it for their role. Review:

  • New-hire access approvals.
  • Role changes.
  • Departures and termination timing.
  • Shared accounts.
  • Remote access.
  • Vendor and temporary access.
  • Privileged administrator access.
  • Downloads, exports, and external sharing.

A professional office should be able to explain not only who can access a system, but why, when the access was reviewed, and how it is removed.

Create an evidence file

A security evidence file can include:

  • Current asset and data inventory.
  • Risk assessment and risk-treatment decisions.
  • Policies and approved exceptions.
  • Training completion records.
  • Access reviews.
  • Patch and endpoint reports.
  • Backup and restoration tests.
  • Vendor assessments and contracts.
  • Incident-response exercises.
  • Security alerts and corrective actions.

Evidence should be dated, owned, and understandable to a manager who was not present when it was created. Avoid collecting screenshots with no context. Add what was checked, the scope, the result, and the follow-up owner.

Do not overlook vendors

A practice may rely on a billing platform, electronic health-record system, document-management service, payroll provider, cloud email tenant, payment processor, or outsourced IT firm. The vendor’s security is part of the office’s operational risk, but a vendor questionnaire alone cannot prove that all risks are addressed.

Ask vendors about MFA, encryption, administrator access, logging, backups, incident notification, data return, subcontractors, and termination. Limit vendor access to the systems and time needed for the work.

Prepare for notification decisions

A suspected incident may involve privacy, professional confidentiality, contract, insurance, and regulatory questions at the same time. The office’s response plan should identify who preserves evidence, who contacts counsel, who speaks with the insurer, who communicates with clients or patients, and who determines whether notification is required.

Do not promise that an event is harmless before the facts are known. Do not send technical details broadly if doing so could compromise the investigation. Use qualified legal and forensic support when personal, health, financial, or confidential information may be involved.

A manageable operating rhythm

Monthly, review high-risk alerts, new administrators, failed backups, and open corrective actions. Quarterly, review users, vendors, policies, and evidence. Annually, perform a risk assessment and exercise the incident plan.

The confirmed point is that security and compliance both require documented, repeatable processes. The uncertain point is which specific rules apply to a particular professional office. That determination depends on the office’s activities, data, clients, contracts, and location, and should not be guessed from a generic article.

Sources

HHS HIPAA Security Rule: https://www.hhs.gov/hipaa/for-professionals/security/index.html

HHS HIPAA Security Rule proposed rule: https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html

FTC Cybersecurity for Small Business: https://www.ftc.gov/business-guidance/small-businesses/cybersecurity

FTC breach response guide: https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business

Sources