The Audit Defense Library

Practitioner-depth analysis across federal and private compliance: FISMA and NIST RMF, FedRAMP, CMMC, federal AI governance, SOC 2, AI governance, cybersecurity, and GRC engineering. Written by a CPA, CISSP, CISA with Big 4 audit experience.

All FISMA & NIST RMF FedRAMP CMMC Federal AI Governance GovCon Compliance Federal Cybersecurity Federal Zero Trust Federal GRC Engineering AI Governance GRC Engineering Cybersecurity Cloud Security HIPAA SOC 2
HIPAA

Is Zoom HIPAA Compliant? 2026 Config Guide

How many applications join your telehealth calls? Not Zoom itself. The third-party tools your clinicians installed without IT approval. The AI transcription service that auto-joins every meeting. The recording bot saving calls to a personal...

Read the Guide
AI Governance

5 HIPAA AI Violations Auditors Find (And How to Fix Them)

How many AI tools process protected health information (PHI) in your organization right now? Not the ones your compliance team approved. All of them. The AI scribe your physicians adopted six months before anyone signed...

Read the Guide
HIPAA

Is Microsoft Teams HIPAA Compliant?

Fourteen external guest accounts. Seven months of unrestricted access. One Team channel containing patient intake forms. Zero audit log entries flagging the exposure. The default Guest Access setting in Microsoft Teams allowed a single physician...

Read the Guide
AI Governance

Technology Risk Landscape 2026: The Rise of “Shadow Agents”

Non-human identities outnumber human users 82-to-1 in enterprise environments [CyberArk 2025]. Service accounts, API keys, bot credentials, and AI agent tokens now constitute the largest attack surface in the average organization. Most identity and access...

Read the Guide
HIPAA

Is Slack HIPAA Compliant?

When Slack launched in 2013, the platform positioned itself as a consumer-friendly messaging tool for startups. No encryption at rest. No compliance certifications. No enterprise controls. Healthcare organizations adopted it anyway because clinicians preferred its...

Read the Guide
HIPAA

Is Google Workspace HIPAA Compliant? 2026 Guide

Clinic A signs up for Google Workspace Business Starter at approximately $7 per user per month. The administrator sets up email, creates shared drives, and begins routing patient communications through Gmail. The plan is paid....

Read the Guide
HIPAA

Is Notion HIPAA Compliant? Enterprise Only (2026)

Every healthcare startup I advise uses Notion for something it was never designed to hold. Patient intake workflows embedded in databases. Treatment protocols linked to scheduling templates. Vendor contracts stored alongside clinical documentation. The workspace...

Read the Guide
AI Governance

Is Microsoft Copilot HIPAA Compliant? 2026 Audit Guide

Microsoft Copilot is HIPAA compliant. Microsoft Copilot is also not HIPAA compliant. Both statements are simultaneously true because "Copilot" is not one product. Microsoft sells at least six AI features under the Copilot brand. The...

Read the Guide
Cybersecurity

Vulnerability Management vs Patch Management Explained

Patch compliance dashboards are the most dangerous metric in cybersecurity. A 98% patch rate creates board-level confidence while leaving the most critical gaps untouched. Misconfigurations, default credentials, excessive permissions, and zero-day exposures carry no vendor...

Read the Guide
SOC 2

SOC 2 Audit Preparation Checklist: Field Manual

The pattern repeats in every first-time SOC 2 engagement I advise. Thirty days before audit fieldwork, the auditor sends a 47-item evidence request list. The engineering lead estimates 200 hours of work. Two senior developers...

Read the Guide
Cybersecurity

NIST Password Guidelines 2026: Why 90-Day Rotation is Dead

Forced password rotation is a security vulnerability, not a security control. NIST SP 800-63B Revision 4 formally prohibits arbitrary rotation because the practice produces the opposite of its intended effect [NIST SP 800-63B Rev. 4]....

Read the Guide
SOC 2

11 SOC 2 Audit Failures in Healthcare SaaS (2026 Analysis)

A failed SOC 2 Type II examination can stack to nearly $1 million in year-one impact for a healthcare SaaS company when re-audit fees, remediation, and lost enterprise deals combine. The illustrative model later in...

Read the Guide
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.