

I’m a Privacy, Compliance, Audit, and GRC Executive with over 15 years of experience helping organizations navigate complex regulatory environments and build programs that work in practice—not just on paper.
Over the course of my career, I’ve supported both a prestigious medical school and a Fortune 10 company, leading enterprise privacy and GRC programs, managing compliance investigations, and working closely with regulators, auditors, and executive leadership. These experiences shaped my ability to operate at scale while maintaining a practical, solutions-oriented approach.
My work focuses on translating complex regulatory requirements—such as HIPAA, HITRUST, SOC 2, and GDPR—into clear, actionable strategies. I design scalable GRC frameworks, develop policies and governance structures, and help organizations strengthen their risk posture without slowing down the business.
Today, as the Founder of EVRHealth Privacy Compliance Consulting, I partner with healthcare providers, SaaS companies, and growing organizations to build and mature their GRC and privacy programs. My services span audit readiness, risk assessments, privacy program development, and AI governance.
I combine large-enterprise discipline with a hands-on, tailored consulting approach—helping clients build trust, meet regulatory expectations, and operate with confidence in an increasingly complex environment.
Helping healthcare organizations and business associates build, strengthen, and maintain compliant HIPAA Privacy programs that reduce risk and support operational excellence.
Performing comprehensive privacy risk assessments to identify vulnerabilities, compliance gaps, and improvement opportunities—paired with clear, actionable remediation plans.
Developing and updating HIPAA‑required policies, procedures, and documentation to ensure regulatory alignment and audit readiness.
Delivering engaging, role‑specific HIPAA Privacy training that improves compliance awareness and reduces human‑factor risk across the organization.
Guiding organizations through incident evaluation, breach determination, documentation, notification requirements, and corrective action planning.
Supporting BAA drafting, review, negotiation, and lifecycle management to ensure compliance and reduce contractual risk.
Conducting internal audits and continuous monitoring to validate compliance, strengthen controls, and prepare for external audits or OCR inquiries.
Advising on patient access, amendments, restrictions, and disclosure requirements to ensure timely, compliant responses and reduce complaint risk.
Providing expert interpretation of HIPAA Privacy Rule requirements, OCR expectations, and emerging regulatory trends to support confident decision‑making.
Open today | 09:00 am – 05:00 pm |

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.