Compliance for Santa Clarita SMBs

Santa Clarita, Audit Ready

Compliance fails on paperwork far more often than on technology. The controls are usually somewhere in the building; what is missing is the dated record proving they were there before anyone asked. This page sets out which rules apply to a Santa Clarita practice or firm, the two misreadings that cost the most, and what usable evidence actually looks like.

Scope, Honestly

Which rules actually apply to you.

Four frameworks cover almost every regulated business in the Valley, and our depth in them is not equal. Here is where each lands, and where ours honestly stops.

HIPAA

The deepest hands-on area, from years of auditing and securing medical and dental practices. Three safeguard families, administrative, physical, and technical, with the Security Risk Assessment as the foundation everything else is measured against.

FTC Safeguards (GLBA)

The rule most accounting firms discover late. It requires a written information security program, a named qualified individual, and a risk assessment, and the IRS expects a WISP from tax preparers. Civil penalties run over $50,000 per violation, per day.

PCI-DSS

Applies if you take cards, which the front desk does. Scope shrinks fast when the payment environment is segmented off the clinical network, which is a network design question before it is a compliance one.

FINRA, SEC, and NIST

Framed accurately as controls, documentation, and evidence work rather than as expertise we do not claim. We build to the control expectations and organize what an examiner asks for. An opinion on the regulation itself is counsel's job, not ours.

The Expensive Misreadings

Two misreadings that cost the most.

Both are common, both are cheap to fix now, and both are what an investigation finds first.

Addressable does not mean optional

It means implement it, or document why it is not reasonable and appropriate for your environment and implement an equivalent alternative. Encryption is the classic case, and there is no equivalent alternative to encryption.

The practical consequence is worth knowing: an encrypted laptop that walks out of the office is generally not a reportable breach. The same laptop unencrypted is.

Nobody can certify you

There is no such thing as HIPAA certified. A vendor selling you a certificate is selling something that does not exist, and it is worth nothing to an investigator.

Our own Security Risk Assessment template says exactly this about us, in the document we hand you. A provider whose paper claims less than their website is telling you which one to trust.

The same reasoning, turned into eighteen questions you can put to any provider in writing, is published free at Observe Adapt Protect. It names no vendors and sells nothing.

Observe · Adapt · Protect

What the evidence actually looks like.

Controls you cannot date are controls you cannot prove. Every managed client gets the portal, and recorded staff training runs inside it, per person, on the record.

The compliance portal's imaging page, showing two machines with their tubes, detectors and service dates

The record, kept with you

Staff training per person, imaging equipment on separate maintenance and physics clocks, everything else in the practice and who has it, vendor contacts, onboarding status, dated departures, and your monthly reports. All of it prints, and you export it yourself.

It certifies nothing and verifies nothing you type into it. We store the record, date it, and say so on every sheet. Short read-and-answer training modules are assigned per person and produce a dated completion record, included with a regulated engagement. Awareness education, not certification.

The controls behind the documentation are deployed, not just written: multi-factor authentication and least-privilege access, ESET PROTECT Elite with XDR, ManageEngine Endpoint Central for patching and vulnerability management, encryption, and where elected, encrypted immutable backups with tested restores under disaster recovery. The daily work underneath it is managed IT.

The Paper Behind It

What it costs, and what you sign.

All of it is a promise until you can check it. The pricing calculator returns a firm number for your own environment, and all six agreements are published in full, including the BAA and the SRA template. Four clauses that bear on compliance work:

SecureLynx is not an auditor or certifying body, and this document is not a certification of HIPAA compliance, a legal opinion, or a guarantee that a security incident will not occur.
SRA Section 10, Limitations
Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement, any Security Incident, and any Breach of Unsecured PHI, without unreasonable delay and in no event later than seventy-two (72) hours after discovery.
BAA Section 2(f), Obligations
Onboarding includes discovery and documentation of the Client environment, deployment of the managed stack across supported endpoints, a remediation plan out of discovery, and remediation of the environment to SecureLynx's security baseline.
SLA Section 12, Onboarding
This SRA is reviewed and updated at least annually, and upon any material change to the environment (new systems, locations, vendors, or a security incident).
SRA Section 9, Review and Maintenance

Read them in context rather than trusting the excerpt. The 72-hour clock is materially tighter than HIPAA's sixty days or the FTC's thirty, and it applies to us. The Data Security Addendum carries the equivalent commitment for accounting and financial clients under the Safeguards Rule.

SecureLynx Assessment

Compliance Should Support Operational Stability.

Run your own numbers, read the agreements, then call. Serving the Santa Clarita Valley and Southern California.

Common Questions

Compliance, answered.

Which compliance needs do you support?

We support the major frameworks Southern California businesses answer to: HIPAA for healthcare, the FTC Safeguards Rule (GLBA) for accounting and financial services, FINRA and SEC control expectations, PCI-DSS for card handling, and NIST-based security programs. Our deepest hands-on experience is HIPAA, drawn from years of auditing and securing medical practices; across the others we implement the required safeguards, organize the documentation, and prepare the evidence that audits, partners, and cyber-insurance reviews call for.

Do you certify that we are compliant?

No, and be wary of anyone who says they do. SecureLynx is not a certifying body, and our own Security Risk Assessment template says so in writing: it states plainly that SecureLynx is not an auditor or certifying body and that the document is not a certification of HIPAA compliance. We help you implement the safeguards, organize the documentation, and prepare the evidence, so that a formal audit or attestation by an accredited assessor goes smoothly.

What does "addressable" mean in the HIPAA Security Rule?

It does not mean optional, which is the single most expensive misreading in the rule. An addressable implementation specification must either be implemented, or you must document why it is not reasonable and appropriate for your environment and implement an equivalent alternative measure. In practice there is no equivalent alternative to encryption, so treating addressable as optional is how a practice arrives at an investigation with nothing written down. Required specifications carry no such discretion at all.

Do you sign a Business Associate Agreement (BAA)?

Yes. For any engagement where we handle or can access protected health information, a BAA is put in place during onboarding, defining how PHI is safeguarded, how a suspected breach is reported, and each party's responsibilities under HIPAA. Ours commits to reporting any security incident or breach of unsecured PHI within seventy-two (72) hours of discovery, which is materially tighter than the sixty days the rule allows.

Is the Security Risk Assessment an extra charge?

Initial setup of the Security Risk Assessment is included in the onboarding fee, along with discovery, documentation, deployment of the managed stack, and remediation of the environment to our security baseline. The remediation labor out of that assessment is inside the onboarding fee rather than billed afterward, which is deliberate: an assessment that generates an invoice is an assessment clients learn to stop asking for.

What areas do you serve?

SecureLynx serves the Santa Clarita Valley and the surrounding region: the full San Fernando Valley, Pasadena, Glendale, Burbank, Palmdale, Lancaster, Castaic, Ventura, and the communities in between. Our SLA targets on-site response within sixty (60) minutes inside the Santa Clarita Valley; elsewhere in Southern California, on-site timing varies with distance and conditions.