Cybersecurity is simply risk mitigation. Strip away the complexity and that's what's left.
I’m an independent security advisor for Louisiana healthcare organizations and the vendors who serve them. I sell no products, resell no tools, and hold no vendor relationships — so an assessment from me is a finding, not a sales pitch.
Sources: LCMHS breach notice (2022) · LSU Health notice (2020) · HHS OCR settlement (Feb 2026)
Not hypotheticals. These are the situations that generate the call, stated plainly, with the rule or the number behind each one.
OCR runs a Risk Analysis Initiative and has designated at least fourteen enforcement actions under it since late 2024. In February 2026 it settled with a behavioral health provider for $103,000 over a breach affecting 1,980 patients. The penalty scales to the failure, not the patient count.
The Security Risk Analysis measure is pass/fail. Miss it and you forfeit the entire 25% Promoting Interoperability category — CMS says so explicitly, “regardless of whether other measures in this category are reported.” A prior-year analysis does not carry forward. And for performance year 2026 there are now two attestations: the analysis, and the risk management you did about it.
LAC 48:I.9393 requires hospitals to protect records under HIPAA and any Louisiana standard that is more stringent. That turns a federal compliance failure into a state licensing deficiency an LDH surveyor can cite. Rural Health Clinics and behavioral health providers carry parallel provisions. Almost nobody selling into this state mentions it.
Every organization has one on paper. Almost none have put it under pressure, which is why the gaps surface during the actual incident. Your carrier will also ask whether you have run a tabletop in the last twelve months, and the after-action report is the artifact they want to see.
A qualified Chief Information Security Officer commands $250,000 or more a year. For a twenty-five person practice that is not a budget decision, it is an impossibility. Fractional leadership is the only way that function gets covered at all — and HIPAA lets you name someone outside your organization to hold it.
Billing companies, EMR vendors, IT providers, data hosts. OCR has settled with all of them under the Risk Analysis Initiative — ambulance billing at $75,000, EMR and billing support at $80,000, a data hosting and IT support firm at $90,000. Your clients’ obligations flow down to you, and your BAA says so.
Fixed scope, fixed fee, fixed timeline — and the price is published, because you should not have to book a call to find out what something costs. As far as I can tell, no other firm in Louisiana publishes theirs.
Senior security leadership without the overhead of a full-time hire. I hold the named role for organizations required to designate one — HIPAA Security Officer, GLBA Qualified Individual, Louisiana Insurance Data Security responsible person. Board and executive risk communication, security roadmap, governance, IR readiness, and correspondence with regulators and auditors. Three tiers depending on your size and how many frameworks you answer to.
Compliance Steward $2,500 · Fractional Security Officer $4,500 · Embedded Leadership $7,500. Initial 90 days, then 30 days’ notice.
Fixed-scope project work for organizations facing a deadline. Every engagement below is a published price, a defined deliverable, and a stated timeline.
| HIPAA Security Risk Analysis — practice | $6,500 |
| HIPAA SRA — CAH, FQHC, multi-site | $12,500 |
| NIST CSF 2.0 gap assessment | $8,500 |
| Cyber insurance readiness review | $3,500 |
| Incident response tabletop exercise | $2,750 |
Also working in NIST 800-53, NIST 800-171, CMMC 2.0, CJIS, IRS Publication 1075, FFIEC, FINRA, ISO 27001, and PCI-DSS. Scope changes are quoted before any work begins — there are no hourly surprises.
One curriculum, two delivery formats. The curriculum covers programmatic cybersecurity topics: risk, frameworks, compliance, governance, and the business layer of security. Built for technical professionals who already have the depth and want to extend their value into the program level. Sold to organizations as In-House Teams training, or to individuals and small groups as scheduled cohorts. See training details →
A structured process built for people who do not have time for a long one. No jargon, no surprises, no deliverable that sits in a drawer.
Thirty minutes on your situation, your obligations, and whether I am the right fit. If you would be better served by someone else, I will tell you that on this call.
Fixed fee, fixed scope, from the table above. Findings prioritized by business impact rather than scanner severity. You get a finished deliverable whether or not anything follows it.
Every recommendation mapped to a business outcome and sequenced so you know what to do first and why. For HIPAA work this is the Risk Management Plan — OCR cites the failure to act as often as the failure to assess, so it is included, not upsold.
Optional, always. A retainer if you want the program owned and maintained — controls implemented, auditors satisfied, board briefed, and the program kept current as you and the threat environment change.
I started Red Stick Cyber on a specific premise: security programs built around compliance theater and technical complexity for its own sake don't protect organizations. They just create the appearance of doing so.
Across 29 years in IT and cybersecurity — U.S. Army, government contracting, and the commercial sector, with organizations in government, defense, healthcare, financial services, and transportation — security has always had one job. Support the mission, not compete with it. You identify the risks that matter to what you are trying to accomplish, you reduce them to an acceptable level, and you maintain that posture. Everything else is overhead.
I built this as a Louisiana practice deliberately. The organizations here that most need security leadership — rural clinics, independent practices, small hospitals, the billing companies and IT shops that serve them — are the ones national firms will not staff and local IT companies cannot objectively advise, because they sold the equipment they would be assessing. I have nothing to sell but the assessment. That is the whole reason this exists.
That is the standard I hold every engagement to. No manufactured urgency, no vendor-aligned recommendations, no deliverable designed to justify the work. An honest assessment of where you are, where you need to be, and the most direct path between the two.
The substance of cybersecurity as a discipline lives at the program level. Risk, frameworks, compliance, governance, and the business layer of security decisions. This is what I teach. Built for cybersecurity and IT professionals who already have the technical depth and want to extend their value into the program layer.
Multi-session intensive built around your organization's cybersecurity, IT, and adjacent staff. The organization sponsors. Staff are the students. Curriculum tuned to your environment. Suitable for IT and security directors building program capability across a team, or organizations that want their workforce to understand cybersecurity at the program level rather than the task level.
Scheduled cohort program for individual professionals or small groups of up to twelve. Sessions run on a published schedule. Self-enrollment and small-group enrollment both supported. Suitable for individual cybersecurity and IT professionals who want to add the program-level layer to their existing technical depth.
Training engagements are built around your situation. Where you are, where you want to operate, and what is standing between the two. Start with a conversation.
Would your Security Risk Analysis survive an OCR investigation? A fourteen-point self-check against the HIPAA Security Rule, with the exact CFR citation for every requirement and a plain explanation of what it actually demands. Including the three things most practices get wrong: that HIPAA does not require an annual risk analysis, that “addressable” does not mean optional, and that you can outsource the Security Officer role but not the liability.
No form. No follow-up sequence. Take it and use it.
Thirty minutes on where you are, what a regulator would say about it, and what would make the most difference. You will be talking to the person who does the work, because there is only one of us. No vendor pitch, no obligation.
Send a message and I will respond within one business day. For training inquiries, mention your current role and where you're trying to take it.
General: info@redstickcyber.com
Training: training@redstickcyber.com