Notes from the operator side.

Cyber insurance renewals, HIPAA, breach lessons, and what it takes to run AI and security at a firm of 25 to 150 people. Written for the people doing the work.

Editorial line

Plain English, real sources, and no fear marketing.

Reading your renewal denial letter: a translation guide

A cyber insurance non-renewal, declination, or claim denial arrives in carefully chosen language. 'Material misrepresentation.' 'Failure to maintain stated controls.' 'Inadequate security controls.' Each phrase means something specific, and each has a different response. Here is the translation, and what to actually do.

The CISO cost math: $380,591 for what most SMBs actually need

A full-time CISO in Phoenix averages $380,591 in base salary. Fully loaded, the number clears half a million. Most small and mid-size businesses do not consume a full CISO's capacity. Here is the honest math on the gap between what the role costs and what the business actually needs.

When the new HIPAA Security Rule lands: a 90-day prep checklist

The HIPAA Security Rule update is still a proposed rule: published as an NPRM, contested, not final, and possibly months from a final form. But the direction is clear enough to prepare for. Here is the 90-day checklist we would actually run for a practice that wants to be ready regardless of the final rule's exact shape.

Phoenix-specific: what local underwriters are actually asking

There is no published report on what Phoenix underwriters ask, and any firm that claims proprietary local underwriting data should be read skeptically. What does exist: the national underwriting pattern, the Arizona breach-notification regime, and the documented Phoenix industry mix. Read together honestly, they tell you what a local SMB should expect.

The Evidence Pack: why most 'compliance binders' don't survive an audit

Most organizations have a compliance binder: a folder of policies and screenshots assembled the last time someone asked. It feels like preparedness. Then an underwriter or an auditor actually examines it, and it falls apart in a predictable way. Here is why the binder fails and what survives instead.

The Change Healthcare aftermath: what BAAs should say now

Two years after the Change Healthcare attack exposed PHI for roughly 192 million people through a single business associate, the durable lesson for a small practice is not technical. It is contractual. The Business Associate Agreement is the instrument that decides what happens when a vendor, not you, gets breached.

Reading the proposed 2026 HIPAA Security Rule update

HHS has proposed the most significant HIPAA Security Rule overhaul since 2003. The headline is the end of the 'addressable' safeguard. But it is a proposed rule: published as an NPRM, contested by more than 100 hospital systems, and not yet final. Here is what it would change, and what is still uncertain.

2026 cyber insurance market: what's changed since 2024

Two years ago the cyber market was still digesting the hard cycle. Entering 2026 it has settled into something more durable: competitive pricing on top of permanent underwriting discipline. The premium relief is real. The controls scrutiny is not going away. Both facts matter for your next renewal.

Year-end compliance: the 6-week panic and how to skip it

Every December, a predictable scramble: insurance renewals clustering at January 1, auditor deadlines, a Security Risk Analysis that hasn't been touched since last year's panic. The frameworks all say the same thing. Compliance is a continuous process, not an annual event. The fix is structural, not heroic.

MFA, EDR, backup: the three controls that decide most renewals

Across the modern cyber liability application there are ten or more control categories. But three of them (multi-factor authentication, endpoint detection and response, and tested immutable backups) carry disproportionate weight in the renewal decision. The loss data is why, and the government recommends exactly these three.

When fractional vCISO actually beats hiring full-time

By Q4 2025 the math on CISO hiring tilted decisively toward fractional for most SMB and mid-market organizations. Full-time CISO base salaries crossed $300K in major metros while credible vCISO retainers ran $2,600 to $11,600 a month. The question isn't whether the gap is real. It's whether your business has the scale to justify closing it.

What HHS actually does during an OCR audit

The mechanics of an HHS Office for Civil Rights HIPAA audit are not a mystery. The authority, the process, and the audit protocol are all published. For a small practice, the single most important fact is what OCR asks for first, and it is almost always the Security Risk Analysis.

The 30-question renewal questionnaire: a guided tour

Open any commercial cyber liability renewal application in 2025 and the shape is the same. Identity, endpoint detection, backups, patching, email security, remote access, privileged access, training, incident response, vendor risk. Here's what underwriters are actually weighing, and what good answers look like.

What recent healthcare breaches actually teach small practices

The public record of 2024 and early 2025 healthcare breaches teaches a remarkably consistent set of lessons. Business associate risk, identity-based attacks, and ransomware against healthcare keep showing up in the OCR portal, and the lessons travel down from the largest breaches to the smallest practices.

What gets cited in cyber claim denials: a pattern read from public reports

You do not need inside information to understand why cyber claims and coverage get denied. The public claims studies, the carrier reports, and the litigated cases describe a consistent pattern: misrepresentation on the application, controls that could not be verified, and documentation that was never assembled. Here is the pattern, read from sources anyone can check.

Why your cyber insurance renewal got harder this year

Premiums stabilized in 2025, but renewal applications didn't get easier. The questionnaire is longer, the evidence requirements are heavier, and the underwriter has a sharper read on what a defensible answer looks like. Here's what changed, and what to do about it before your next renewal.

Next step

Have a question we have not written about?

You want to adopt AI without putting client data at risk. We'll be with you at every step. It starts with a 30-minute call with our principal consultant. We ask about your firm, your tools, and your next insurance renewal. You leave knowing whether the Blueprint fits, and what to do first either way.

Where
Phoenix, and remote across the Southwest