Compliance Help: HIPAA, PCI DSS, SOC 2, GLBA, Reg S-P

Can you help us meet compliance requirements like HIPAA, PCI, and SOC 2?

Yes. NerdSquad helps businesses put the technical controls and documentation in place that HIPAA, PCI DSS, SOC 2, GLBA and SEC Regulation S-P call for, and we support you through audits and assessments. We don't certify compliance; auditors, assessors and regulators do that.

Most compliance frameworks ask the same underlying questions: who can get to sensitive data, how is it protected, how would you know if something went wrong, and can you prove all of that on paper? Our job is to make the IT side of those answers true, and to keep the evidence organized so your compliance officer, auditor or insurer can see it. Below is how that works for the frameworks we see most, starting with the one our financial clients ask about first.

Financial firms: SEC Regulation S-P and GLBA

Registered investment advisers and broker-dealers

SEC-registered advisers and broker-dealers fall under Regulation S-P, which the SEC amended in 2024. The amended rule requires a written incident response program, notice to affected customers within 30 days of discovering unauthorized access to sensitive customer information, oversight of service providers that handle that information, and records showing you did all of it. Compliance dates have now passed for both larger firms (December 3, 2025) and smaller firms (June 3, 2026).

Other rules sit alongside it: Regulation S-ID (identity theft red flags) and books-and-records requirements such as Advisers Act Rule 204-2 and, for broker-dealers, Exchange Act Rule 17a-4. FINRA's rules apply to broker-dealers, not to advisers that are only SEC-registered. The SEC's 2023 cybersecurity disclosure rules apply to public companies, and the SEC withdrew its proposed cybersecurity rule for advisers in 2025.

Other financial businesses: the FTC Safeguards Rule

Under the Gramm-Leach-Bliley Act (GLBA), non-bank financial institutions that aren't SEC-registered (tax preparers, mortgage brokers, some CPAs and financial planners) follow the FTC Safeguards Rule. It requires a written information security program (WISP), a designated qualified individual, risk assessments, multi-factor authentication (MFA), encryption, and an annual report to your board or owner. Since May 2024, you must also notify the FTC within 30 days of discovering an event involving unencrypted information of 500 or more consumers.

For more on how we support advisers and wealth managers, see IT for financial advisers and wealth managers and Do you help financial advisors stay SEC, FINRA, and GLBA compliant?

Healthcare: HIPAA

Medical practices, dental offices and their vendors must follow the HIPAA Security Rule for electronic protected health information (PHI). That means a documented risk analysis, access controls, audit logs, security incident procedures, a contingency plan, workforce training, and Business Associate Agreements (BAAs) with vendors that handle PHI. Breach notices to patients are due without unreasonable delay and no later than 60 days after discovery, and HIPAA documentation must be kept for six years. HHS proposed significant Security Rule updates in January 2025 (such as making MFA and encryption explicit), but that rule is still a proposal. See Do you help us stay HIPAA compliant? for the practice-level view.

Card payments: PCI DSS

If you accept credit cards, the Payment Card Industry Data Security Standard (PCI DSS) applies. Version 4.0.1 is current, and the requirements that were future-dated under version 4.0 became mandatory on March 31, 2025, including MFA for all access into the cardholder data environment and targeted risk analyses. The most useful first step is usually reducing scope: keep card data off your own systems wherever a payment processor can handle it, and segment the systems that still touch it.

SOC 2

SOC 2 is an attestation report issued by an independent CPA firm, common for software companies and service providers whose clients ask for it in vendor reviews. It's built on the AICPA Trust Services Criteria (security, plus optional availability, processing integrity, confidentiality and privacy). We help you put the IT controls in place, document them, and collect the evidence your auditor will request.

Florida law: FIPA

The Florida Information Protection Act (FIPA, Florida Statutes s. 501.171) requires businesses holding Floridians' personal information to take reasonable measures to protect it, and to notify affected individuals within 30 days of a breach. If 500 or more Floridians are affected, you must also notify the Florida Department of Legal Affairs.

What we actually do

  • Risk assessments and gap analyses mapped to the framework that applies to you, so you know where you stand. See What is a compliance risk assessment?
  • Security controls: MFA, encryption at rest and in transit, firewalls, endpoint detection and response, patching and vulnerability management.
  • Backups that are hard to tamper with: immutable, encrypted copies that are tested so you know restores work.
  • Logging and monitoring so there is a record of who accessed what, and alerts when something looks wrong.
  • Security awareness training, a standard part of NerdSquad cybersecurity plans, with records you can show an examiner.
  • Policies and evidence: help drafting the technical sections of your WISP, incident response plan and security policies, plus organized evidence for auditors, examiners and insurers.
  • Vendor and BAA support where the framework requires it.

What we don't do

We don't issue certifications, sign attestations or give legal advice, and no IT provider can guarantee a regulatory outcome. What we can do is make sure the technology matches what your policies say and that the proof is ready when someone asks for it. If your framework isn't listed here, ask. We'll tell you plainly whether it's something we can support.

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity and compliance services