Security & compliance programs
Security programs that hold up to scrutiny.
Compliance Rehab builds and rebuilds security and compliance programs for organizations facing serious oversight: federal frameworks, defense contracts and regulated healthcare. We design the program, stand it up, and leave it running with evidence behind every control.
Engagements
Where we come in
Security program builds
Standing up or rehabilitating a security program: governance, policies, controls, monitoring and the evidence to prove it. Available as a project or as fractional CISO leadership.
Zero trust
Zero trust strategy, architecture and program execution — identity, devices, networks and data — built to the standards large federal health programs use.
CMMC readiness
Scoping, gap assessment, system security plans and remediation for defense contractors preparing for CMMC Level 2.
FedRAMP & continuous monitoring
FedRAMP readiness, including the FedRAMP 20x approach of automated, machine-readable evidence and continuous validation.
Experience
Led by Griffin Brown
Defense Health Agency
Stood up the DHA’s zero trust security program (2024–25).
Beth Israel Lahey Health
Security work for a Harvard teaching hospital.
Healthcare operator
Founded and grew Therapitas, a therapy practice in Oklahoma, and has served as security officer for One Therapy Network and its clinics.
Our brand for small healthcare
HIPAA Made Simple
For small healthcare and the companies that serve it: a named HIPAA security officer, monthly evidence-backed reviews, vendor risk management and trust sites.
Installing our software?
If you saw Compliance.Rehab LLC as the developer while installing the HIPAA Made Simple agent on a Mac, that’s us. Your organization or HIPAA Made Simple sent you the installer. Questions? Email griff@hipaa.inc before continuing.
Contact
Let’s talk about your program.
Compliance Rehab LLC · Dallas–Fort Worth, Texas · griff@hipaa.inc