Practice · 01

Regulatory compliance & auditing

The work is built on time spent inside an actual research-compliance office, not on a certificate mill. Protocols, consent, PHI pathways, and education records are treated as operational systems: if they cannot be reconstructed, they are not controls.

What we review

IRB and human-subjects programs: protocol inventory, amendment control, consent versioning, close-out, and the gap between the binder and the lab. HIPAA: system inventory, BAAs, access reviews, minimum necessary as a practiced rule, incident clocks. FERPA: education records versus directory information, disclosure logs, vendor control, access SLAs.

We also look at the places institutions hide risk in plain sight — shadow tools, "temporary" exceptions that became policy, and research programs that outgrew their last review. The deliverable is an exposure narrative with owners, not a stack of green checkmarks.

What this is not

This is not a substitute for retained counsel, a covered-entity's required privacy officer, or an accreditation survey. It is an independent structural review. Findings can be handed to counsel; they are not themselves legal advice.

Quiet institutional corridor

Institutional fabric

Hands reviewing documents

Document trail