AI Governance is Essential.
HIPAA Compliance is the Proof.
Security Follows.
We Find Your Gaps Before the Auditors or the Hackers Do.
And we do it with CLASse.
ChatGPT. Copilot. AI scribes. Scheduling bots. Every one of them is a liability without a framework. One employee prompt with a patient name is a HIPAA violation. One undisclosed AI vendor is an audit finding. I build the governance framework that protects you — before the regulators ask for it.
AI Governance First.
Then HIPAA & Security.
Your ChatGPT. Your AI scribe. Your scheduling bot. None of them are compliant without an AI governance framework (ISO 42001). Build the foundation first — HIPAA compliance and security hardening follow naturally.
You run a small practice. You've got patients, staff, and a growing pile of technology — but no idea whether any of it is compliant. That fog is your biggest liability.
Most OCR fines and data breaches don't hit organizations that tried and failed. They hit organizations that never checked. The Risk Snapshot is designed for practices with 1–10 employees who need to know exactly where they stand — fast, affordably, and without a long-term commitment.
You choose the audit tool that fits your situation — HIPAA for healthcare practices, ISO 27001 for security framework, or ISO 42001 for AI governance. We review your results during a 30-minute onsite visit, check your M365 and Apple security posture, and deliver a clear priority matrix within 2–3 business days. No jargon. No scare tactics. Just clarity.
- Client completes audit tool (HIPAA, ISO 27001, or ISO 42001)
- 30-minute onsite visit — Fred reviews results, checks environment
- M365 / Apple security baseline check
- Vendor & BAA gap identification
- 1-page prioritized risk matrix
- Risk summary email with immediate action items
- Notes from onsite visit (audit tool HTML export included)
Full Security Risk Analysis covering all administrative, physical, and technical safeguards. Required by law. Your primary defense against OCR audits and breach liability.
Running AI scheduling tools, scribes, or clinical decision support? ISO 42001 ensures your AI systems meet HIPAA-aligned standards before they become a liability.
Ongoing security leadership without a full-time hire. Quarterly reviews, policy maintenance, regulatory change monitoring, and incident response guidance — at SMB economics.
Additional services: Custom policy development, M365 security hardening, ISO 27001 gap analysis, security awareness training, Apple ecosystem security. Full service menu →
AI Governance Is the New
HIPAA Compliance
In 2024, OCR started asking about AI. In 2025, insurers started requiring it. In 2026, your competitors are already governing it. ISO 42001 is the standard — and CLAS by Fred is one of the few consultancies in Northeast Florida delivering it for SMBs.
One employee prompting ChatGPT with a patient name. One undisclosed AI vendor in your workflow. One AI-generated clinical note without a human override policy. Each one is an audit finding — or worse.
ISO 42001 is the international standard for AI Management Systems. It maps directly to HIPAA safeguards, giving you a defensible governance layer for every AI tool your organization uses today — and tomorrow.
Fred delivers a complete AI Governance Framework: AI risk register, acceptable use policy, vendor assessment, staff training plan, and a HIPAA crosswalk — all authored for your specific environment.
AI Governance. HIPAA. ISO 27001.
Pick Your Starting Point.
Three tiers for healthcare practices, law firms, and regulated SMBs in Northeast Florida. Every tier includes AI governance options — because no compliance program in 2026 is complete without one.
Comprehensive assessment + core policy set for small practices (1–10 employees). Your first compliance binder — documentation you can show an auditor, insurer, or credentialing committee.
- Client completes CLAS audit tool (HIPAA, ISO 27001, or ISO 42001)
- 2-hour comprehensive onsite visit with Fred
- Light HIPAA or ISO gap analysis
- HIPAA Core Policy Library — 6 custom-authored policies: Privacy, Security, Breach Notification, Sanctions, Device & Media Controls, Workforce Security
- M365/Apple security baseline + written hardening guidance
- Comprehensive findings report
- 1-page prioritized risk summary
- Written remediation roadmap with timeline
- • Add a 30-min discovery call for retainer planning: complimentary
- • Annual Security Awareness Training: +$1,200/year
- • AI Use Audit: +$1,500
Comprehensive compliance program for growing practices (5–12 employees). Full HIPAA assessment, custom policies, and semi-annual onsite check-ins.
- Comprehensive HIPAA Assessment (full SRA)
- Custom Policy & Procedures Documentation (8-policy core set: Privacy, Security, Breach Notification, Sanctions, Device & Media, Workforce Access, Incident Response, BAA Management)
- Semi-annual onsite compliance check-ins (2 visits/year, 90 min each)
- M365 security hardening guidance document
- Risk register with remediation roadmap
- • Policy update (operational changes): +$500 per update
- • ISO 27001 gap analysis: +$4,500
- • AI Governance Framework: +$3,000
- • Security Awareness Training: +$1,200/year
- • Upgrade to quarterly onsite check-ins: +$200/month
Full vCISO partnership for established practices (8–20 employees). Strategic leadership, ongoing monitoring, and annual policy maintenance.
- Everything in Resilient, plus:
- Fractional vCISO advisory (8–12 hours/month remote · email, phone, document review, strategic guidance)
- Quarterly onsite compliance check-ins (4 visits/year, 90 min each)
- Regulatory change monitoring · proactive alerts on HIPAA, state privacy laws, AI regulation updates
- Annual policy full review & refresh · all 12 policies re-read, re-read, updated for regulatory changes, delivered as updated documents
- 12-policy extended set (Core 8 + Third-Party Risk, Remote Work & BYOD, AI Acceptable Use, Data Retention & Disposal)
- • Policy update (operational changes): +$750 per update
- • ISO 27001 gap analysis: +$4,500
- • AI Governance Framework: +$3,000
- • Security Awareness Training: +$1,200/year
Every engagement includes professionally formatted, editable deliverable templates: SRA spreadsheet, HIPAA policy library, DPIA template, and executive slide deck, authored and tailored by Fred Saraiva for your specific environment. No generic templates. No copy-paste compliance.
Why I Built CLAS
I know what enterprise compliance looks like: IT Security Lead for Apple vendor across Europe, raising audit scores from 72% to 96% and training over 1,000 agents in several countries. I've built disaster recovery plans for telecom companies, security frameworks for SaaS platforms, and access control systems for multinational operations.
But I also know that a 12-person chiropractic office doesn't need a 200-page security manual. CLAS by Fred takes the precision of enterprise governance and scales it down: custom HIPAA audits, AI governance frameworks, and compliance roadmaps built for practices where the owner is also the decision-maker, the budget holder, and the person who has to explain it to their staff.
I pioneered Apple's first remote support model for the German market. I scaled a SaaS startup to €4M ARR. I've navigated OCR inquiries, GDPR enforcement actions, and ISO 27001 certification audits. And I've done it in three languages, across two continents, for more than two decades.
Now I'm based in Jacksonville, certified ISO 42001 Lead Auditor & Implementer, building compliance programs for Northeast Florida healthcare practices, law firms, and all regulated — or not yet regulated — environments seeking AI Governance, physical security guidance, or audit-ready documentation without enterprise bureaucracy. No generic templates. No copy-paste policies. Just custom frameworks built by someone who's been in the CISO & CTO chair and knows what actually holds up under scrutiny — and knows what keeps hackers out before they ever find a way in.
Frederic Saraiva, Founder
The Questions Small Practices
Ask Before Booking
Yes. There is no small-practice exemption in HIPAA. If your practice transmits health information electronically — billing, lab orders, referrals — you are a covered entity. OCR has issued corrective action plans and fines to solo practitioners and practices with fewer than five employees. Size does not protect you. The absence of documentation is what makes you vulnerable.
Read: HIPAA requirements for small practices →They handle the technology. HIPAA compliance requires written policies, a Security Risk Analysis, workforce training, Business Associate Agreements, and documented procedures — none of which your IT company or EHR vendor produces for you. Your EHR vendor signs a BAA with you. That is not the same as your practice being compliant. When OCR investigates, they ask for your documentation — not your vendor's.
Find out what your practice is missing — $995 Risk Snapshot →The Risk Snapshot is $995 — a flat fee for a 30-minute onsite visit, a HIPAA audit tool, and a 1-page priority report delivered in 2–3 business days. No retainer, no long-term commitment, no obligation after. Compare that to the minimum OCR fine for a missing Security Risk Analysis: $100 per violation, with no cap on how many violations they find. One phishing incident without an incident response plan on file can cost more than a year of compliance work.
Start at $995 — no commitment required →OCR investigations are not triggered by negligence alone — they are triggered by patient complaints, breach self-reports, and random audit programs. By the time "something happens," you are already in the enforcement process. A practice without a Security Risk Analysis on file cannot demonstrate good-faith compliance effort. That single gap is what turns an investigation into a fine. The time to build the documentation is before you need it, not the day OCR sends a letter.
What OCR asks for on day one →You don't — not from a website. That's exactly why the Risk Snapshot exists at $995. It's a single, low-commitment engagement that shows you the quality of the work, the depth of the assessment, and whether Fred's approach fits your practice — before you invest in anything larger. Most clients who start with the Snapshot know within the debrief call whether they want to continue. There's no pressure either way.
Book a no-obligation discovery call first →No sales pitch. No pressure.
What Sets This
Engagement Apart
Not a Vendor. A Partner.
CLAS operates as an extension of your leadership team, not a ticket queue. Fred's engagement model prioritizes understanding your business before prescribing solutions.
Compliance That Doesn't Slow You Down
Regulatory frameworks are often designed for large enterprises. CLAS translates them into right-sized, actionable programs that protect you without paralyzing your operations.
Global Thinking. Local Presence.
With experience across Europe, Africa, and the US, with fluency in English, French, and Portuguese, CLAS is built for organizations with international ambitions and local accountability.
Industries We
Specialize In
Ready to Know
Where You Stand?
Most security breaches are preceded by a compliance gap someone knew about but didn't act on. A HIPAA Risk Assessment or cybersecurity review with CLAS takes weeks. A data breach can take years to recover from.
Request a ConsultationServing Northeast Florida & Remote Clients Nationwide
Trilingual: EN · FR · PT