GOVERNANCE SYSTEMS FOR REGULATED ORGANIZATIONS
Turn privacy and AI requirements into systems your team can run.
Fixed-scope advisory and practical tools for healthcare, education, and regulated teams that need more than another policy binder.
Start free. See your score immediately. No sales call required.
About JHA
Solutions Consultant
JH Advisory
Former Assistant General Counsel
Sutter Health
Lt Col, USAF (Ret.)
20 years, operational leadership
CISSP · CIPP/US · HCISPP
Privacy and security depth
We practice what we advise. JHarris Advisory uses enterprise AI tools to support research, analysis, drafting, and quality review. AI augments our work; professional judgment, substantive review, and accountability remain with JHarris Advisory
Start where you are
One problem. Three sensible ways forward.
DIAGNOSE
Find the gaps
Take a free assessment and get your score, readiness level, and highest-priority gap immediately.
No dead ends and no forced consultation. Each path leads naturally to the next level of help.
BUILD IT YOURSELF
Use the tools
Download practical policies, workflows, checklists and implementation materials matched to the gap
GET EXPERT HELP
Build the program
Start with a fixed-fee readiness review or bring in JHarris Advisory to implement the full system.
HEALTHCARE PILOT
From "we think we are ready" to a prioritized plan.
The HIPAA funnel becomes the model for the rest of the site: a useful free result, a transparent email exchange for the complete report, then one clearly matched next step.
Score and weakest domain shown free
Full report revealed on screen and sent by email
Tool, paid review, and implementation offers matched to need
Browse by sector
Incident Response
Breach triage, response playbooks, notification timelines, and tabletop readiness
Education
K-12 and higher-ed AI, student data, GLBA, FERPA
AI Governance
AI intake, risk tiering, approvals, vendor review
Healthcare
HIPAA privacy, security, vendor and incident readiness
Privacy
CCPA/CPRA, GDPR, data-use and sharing controls
Legal & Courts
AI use, citation verification, redaction records access
CLEAR NEXT STEP. NO PRESSURE
Start with evidence, then decide how much help you need.
WANT TO BUILD YOURSELF?
Featured toolkits
Most organizations deploying AI tools have no structured way to evaluate them. This bundle starts there. It's the intake, triage, and approval workflow that catches problematic use cases before they ship, built from experience standing up AI review in regulated organizations. Built for teams that want governance without bureaucracy: fast intake, clear risk assignment, documented accountability. NIST gives you a framework. This gives you the intake form, the tiering rubric, and the approval path that make a framework operational.
Who it's for: Organizations rolling out AI tools across teams without a formal review process. Best for companies asking "which AI decisions need oversight" and "who owns this if it fails.”
What's Included:
- Draft AI Use Policy
- AI Use Case Intake Form
- Risk Tiering Rubric
- Governance Playbook
- Required Artifacts Checklist
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
Healthcare organizations live with HIPAA exposure every day. This toolkit gives you a working framework to catch compliance gaps before regulators do — a triage model and checklist set built from years running compliance programs in large healthcare organizations. Built for compliance teams and general counsel who need to move past "we have a BAA" to "we've actually reviewed it." HHS gives you guidance and a risk assessment tool. This gives you the four decision instruments those tools assume you already have.
Who it's for: Healthcare organizations with regulated data, shared patient information, or vendors handling PHI. Best for teams with compliance infrastructure in place but gaps in incident readiness and BAA review rigor.
What's Included:
- BAA Review Checklist
- HIPAA Incident Decision Support Worksheet
- OCR Audit Readiness Assessment
- PHI Data Handling Addendum
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
Financial-aid data is GLBA "customer information," and any AI tool that touches it is in scope for the Safeguards Rule — with two different clocks: 30 days to the FTC under the Safeguards Rule, and same-day reporting to Federal Student Aid on detection or even suspicion. This kit gives you the written program with an AI overlay, the vendor controls, the breach runbook, and the institutional policy. Built by a former government attorney who ran security and privacy programs at scale. Free AI policies exist. Free GLBA material exists. Nothing combines Safeguards, AI governance, vendor review, and IRB research data into one operating structure.
Who it's for: CISO/CIO, General Counsel/compliance, and the financial-aid and research offices at universities and community colleges.
What's Included:
GLBA Safeguards Program + Breach Runbook (FSA/FTC timelines)
Institutional AI & Data Governance Policy
Risk Tiering + Required Controls
AI/EdTech Vendor Vetting (service-provider safeguards)
FERPA & CA Public-Records Handling; Incident & Breach Response
IRB / Research-Data AI Governance (universities)
Educational templates, not legal advice. Confirm current FTC/FSA requirements with your counsel and security office.
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact