Skip to main content
🔥  AI GOVERNANCE IS THE MOMENT:  ChatGPT, Copilot & AI scribes in your practice without governance = HIPAA violation waiting to happen.  See ISO 42001 Framework →
ISO 42001 · AI Governance Jacksonville, FL  ·  EN · FR · PT

AI Governance is Essential.
HIPAA Compliance is the Proof.
Security Follows.

We Find Your Gaps Before the Auditors or the Hackers Do.
And we do it with CLASse.

ChatGPT. Copilot. AI scribes. Scheduling bots. Every one of them is a liability without a framework. One employee prompt with a patient name is a HIPAA violation. One undisclosed AI vendor is an audit finding. I build the governance framework that protects you — before the regulators ask for it.

HIPAA · ISO 42001 AI Governance · ISO 27001 · vCISO · Northeast Florida & Remote
CLAS by Fred Saraiva — Compliance Leadership Advisory Security
C
Compliance
HIPAA, ISO 27001, GDPR & regulatory frameworks that protect your business from risk and liability.
L
Leadership
Strategic fractional CTO/CISO guidance that aligns your technology decisions with business growth.
A
Advisory
Vendor-neutral counsel on compliance strategy, security posture, and regulatory risk priorities.
S
Security
Cybersecurity assessments, policy documentation, and staff training that build a lasting security culture.
What We Do

AI Governance First.
Then HIPAA & Security.

Your ChatGPT. Your AI scribe. Your scheduling bot. None of them are compliant without an AI governance framework (ISO 42001). Build the foundation first — HIPAA compliance and security hardening follow naturally.

Start Here
Risk Snapshot — $995

You run a small practice. You've got patients, staff, and a growing pile of technology — but no idea whether any of it is compliant. That fog is your biggest liability.

Most OCR fines and data breaches don't hit organizations that tried and failed. They hit organizations that never checked. The Risk Snapshot is designed for practices with 1–10 employees who need to know exactly where they stand — fast, affordably, and without a long-term commitment.

You choose the audit tool that fits your situation — HIPAA for healthcare practices, ISO 27001 for security framework, or ISO 42001 for AI governance. We review your results during a 30-minute onsite visit, check your M365 and Apple security posture, and deliver a clear priority matrix within 2–3 business days. No jargon. No scare tactics. Just clarity.

Delivered in 2–3 business days
You choose the audit tool: HIPAA, ISO 27001, or ISO 42001
30-minute onsite visit — no long engagement, zero obligation
1-page priority matrix + risk summary email — clear, actionable
What you get
  • Client completes audit tool (HIPAA, ISO 27001, or ISO 42001)
  • 30-minute onsite visit — Fred reviews results, checks environment
  • M365 / Apple security baseline check
  • Vendor & BAA gap identification
  • 1-page prioritized risk matrix
  • Risk summary email with immediate action items
  • Notes from onsite visit (audit tool HTML export included)
Ready for more depth? The CLARITY Assessment ($2,995) includes a 2-hour onsite visit, 6 custom-authored HIPAA policies, full findings report, gap analysis, and written remediation roadmap — your first compliance binder, delivered in 4–5 days.
When You're Ready to Go Further
HIPAA Risk Assessment

Full Security Risk Analysis covering all administrative, physical, and technical safeguards. Required by law. Your primary defense against OCR audits and breach liability.

From $4,500 · 2–3 weeks
AI Governance (ISO 42001)

Running AI scheduling tools, scribes, or clinical decision support? ISO 42001 ensures your AI systems meet HIPAA-aligned standards before they become a liability.

From $3,500 · 3–4 weeks
Fractional vCISO

Ongoing security leadership without a full-time hire. Quarterly reviews, policy maintenance, regulatory change monitoring, and incident response guidance — at SMB economics.

$2,500–$5,000 / month

Additional services: Custom policy development, M365 security hardening, ISO 27001 gap analysis, security awareness training, Apple ecosystem security. Full service menu →

The Moment Everyone's Talking About

AI Governance Is the New
HIPAA Compliance

In 2024, OCR started asking about AI. In 2025, insurers started requiring it. In 2026, your competitors are already governing it. ISO 42001 is the standard — and CLAS by Fred is one of the few consultancies in Northeast Florida delivering it for SMBs.

⚠️
The Risk

One employee prompting ChatGPT with a patient name. One undisclosed AI vendor in your workflow. One AI-generated clinical note without a human override policy. Each one is an audit finding — or worse.

📋
The Framework

ISO 42001 is the international standard for AI Management Systems. It maps directly to HIPAA safeguards, giving you a defensible governance layer for every AI tool your organization uses today — and tomorrow.

🛡️
The Deliverable

Fred delivers a complete AI Governance Framework: AI risk register, acceptable use policy, vendor assessment, staff training plan, and a HIPAA crosswalk — all authored for your specific environment.

See Full AI Governance Service Take the ISO 42001 Risk Snapshot →
Service Tiers

AI Governance. HIPAA. ISO 27001.
Pick Your Starting Point.

Three tiers for healthcare practices, law firms, and regulated SMBs in Northeast Florida. Every tier includes AI governance options — because no compliance program in 2026 is complete without one.

AI GOVERNANCE + HIPAA
CLARITY

Comprehensive assessment + core policy set for small practices (1–10 employees). Your first compliance binder — documentation you can show an auditor, insurer, or credentialing committee.

  • Client completes CLAS audit tool (HIPAA, ISO 27001, or ISO 42001)
  • 2-hour comprehensive onsite visit with Fred
  • Light HIPAA or ISO gap analysis
  • HIPAA Core Policy Library — 6 custom-authored policies: Privacy, Security, Breach Notification, Sanctions, Device & Media Controls, Workforce Security
  • M365/Apple security baseline + written hardening guidance
  • Comprehensive findings report
  • 1-page prioritized risk summary
  • Written remediation roadmap with timeline
Not the same as an SRA. CLARITY is a comprehensive advisory assessment with a policy foundation. A formal HIPAA Security Risk Analysis (45 CFR §164.308) is a separate, OCR-required deliverable starting at $4,500 — CLARITY often reveals whether you need one.
Optional Add-Ons
  • • Add a 30-min discovery call for retainer planning: complimentary
  • • Annual Security Awareness Training: +$1,200/year
  • • AI Use Audit: +$1,500
Travel: Jacksonville/St. Augustine metro included. Outside area: +$150 travel fee
AI GOVERNANCE + MONITORING
RESILIENT

Comprehensive compliance program for growing practices (5–12 employees). Full HIPAA assessment, custom policies, and semi-annual onsite check-ins.

  • Comprehensive HIPAA Assessment (full SRA)
  • Custom Policy & Procedures Documentation (8-policy core set: Privacy, Security, Breach Notification, Sanctions, Device & Media, Workforce Access, Incident Response, BAA Management)
  • Semi-annual onsite compliance check-ins (2 visits/year, 90 min each)
  • M365 security hardening guidance document
  • Risk register with remediation roadmap
Optional Add-Ons
  • • Policy update (operational changes): +$500 per update
  • • ISO 27001 gap analysis: +$4,500
  • • AI Governance Framework: +$3,000
  • • Security Awareness Training: +$1,200/year
  • • Upgrade to quarterly onsite check-ins: +$200/month
Travel: Jacksonville/St. Augustine metro included. Outside area: +$150/visit travel fee
FULL AI GOVERNANCE LEADERSHIP
SOVEREIGN

Full vCISO partnership for established practices (8–20 employees). Strategic leadership, ongoing monitoring, and annual policy maintenance.

  • Everything in Resilient, plus:
  • Fractional vCISO advisory (8–12 hours/month remote · email, phone, document review, strategic guidance)
  • Quarterly onsite compliance check-ins (4 visits/year, 90 min each)
  • Regulatory change monitoring · proactive alerts on HIPAA, state privacy laws, AI regulation updates
  • Annual policy full review & refresh · all 12 policies re-read, re-read, updated for regulatory changes, delivered as updated documents
  • 12-policy extended set (Core 8 + Third-Party Risk, Remote Work & BYOD, AI Acceptable Use, Data Retention & Disposal)
Optional Add-Ons
  • • Policy update (operational changes): +$750 per update
  • • ISO 27001 gap analysis: +$4,500
  • • AI Governance Framework: +$3,000
  • • Security Awareness Training: +$1,200/year
Travel: Jacksonville/St. Augustine metro included. Outside area: +$150/visit travel fee
All Tiers Include Professional Deliverables

Every engagement includes professionally formatted, editable deliverable templates: SRA spreadsheet, HIPAA policy library, DPIA template, and executive slide deck, authored and tailored by Fred Saraiva for your specific environment. No generic templates. No copy-paste compliance.

About

Why I Built CLAS

Fred Saraiva - Founder, CLAS by Fred
HIPAA Privacy Law (Penn State) ISO 42001 AI Governance Lead Implementer ISO 27001 Lead Implementer GDPR Compliance Expert CompTIA Security+ vCISO Certified ITIL Foundation

I know what enterprise compliance looks like: IT Security Lead for Apple vendor across Europe, raising audit scores from 72% to 96% and training over 1,000 agents in several countries. I've built disaster recovery plans for telecom companies, security frameworks for SaaS platforms, and access control systems for multinational operations.

But I also know that a 12-person chiropractic office doesn't need a 200-page security manual. CLAS by Fred takes the precision of enterprise governance and scales it down: custom HIPAA audits, AI governance frameworks, and compliance roadmaps built for practices where the owner is also the decision-maker, the budget holder, and the person who has to explain it to their staff.

I pioneered Apple's first remote support model for the German market. I scaled a SaaS startup to €4M ARR. I've navigated OCR inquiries, GDPR enforcement actions, and ISO 27001 certification audits. And I've done it in three languages, across two continents, for more than two decades.

Now I'm based in Jacksonville, certified ISO 42001 Lead Auditor & Implementer, building compliance programs for Northeast Florida healthcare practices, law firms, and all regulated — or not yet regulated — environments seeking AI Governance, physical security guidance, or audit-ready documentation without enterprise bureaucracy. No generic templates. No copy-paste policies. Just custom frameworks built by someone who's been in the CISO & CTO chair and knows what actually holds up under scrutiny — and knows what keeps hackers out before they ever find a way in.

Frederic Saraiva, Founder

ISO 27001 Lead Implementer
ISO 42001 AI Governance
HIPAA Privacy Law — Penn State
UVA Darden Executive Program
20+ Years in Cybersecurity & Compliance Leadership
Before You Decide

The Questions Small Practices
Ask Before Booking

"We're only a 4-person practice. Does HIPAA really apply to us?"

Yes. There is no small-practice exemption in HIPAA. If your practice transmits health information electronically — billing, lab orders, referrals — you are a covered entity. OCR has issued corrective action plans and fines to solo practitioners and practices with fewer than five employees. Size does not protect you. The absence of documentation is what makes you vulnerable.

Read: HIPAA requirements for small practices →
"Our IT company and our EHR vendor handle all of that."

They handle the technology. HIPAA compliance requires written policies, a Security Risk Analysis, workforce training, Business Associate Agreements, and documented procedures — none of which your IT company or EHR vendor produces for you. Your EHR vendor signs a BAA with you. That is not the same as your practice being compliant. When OCR investigates, they ask for your documentation — not your vendor's.

Find out what your practice is missing — $995 Risk Snapshot →
"We can't afford compliance consulting right now."

The Risk Snapshot is $995 — a flat fee for a 30-minute onsite visit, a HIPAA audit tool, and a 1-page priority report delivered in 2–3 business days. No retainer, no long-term commitment, no obligation after. Compare that to the minimum OCR fine for a missing Security Risk Analysis: $100 per violation, with no cap on how many violations they find. One phishing incident without an incident response plan on file can cost more than a year of compliance work.

Start at $995 — no commitment required →
"We haven't had any problems. We'll deal with it when something happens."

OCR investigations are not triggered by negligence alone — they are triggered by patient complaints, breach self-reports, and random audit programs. By the time "something happens," you are already in the enforcement process. A practice without a Security Risk Analysis on file cannot demonstrate good-faith compliance effort. That single gap is what turns an investigation into a fine. The time to build the documentation is before you need it, not the day OCR sends a letter.

What OCR asks for on day one →
"How do I know CLAS by Fred is the right fit for my practice?"

You don't — not from a website. That's exactly why the Risk Snapshot exists at $995. It's a single, low-commitment engagement that shows you the quality of the work, the depth of the assessment, and whether Fred's approach fits your practice — before you invest in anything larger. Most clients who start with the Snapshot know within the debrief call whether they want to continue. There's no pressure either way.

Book a no-obligation discovery call first →
Still have questions?
Talk to Fred directly.
No sales pitch. No pressure.
Book a Free Discovery Call
Why CLAS

What Sets This
Engagement Apart

Not a Vendor. A Partner.

CLAS operates as an extension of your leadership team, not a ticket queue. Fred's engagement model prioritizes understanding your business before prescribing solutions.

Compliance That Doesn't Slow You Down

Regulatory frameworks are often designed for large enterprises. CLAS translates them into right-sized, actionable programs that protect you without paralyzing your operations.

Global Thinking. Local Presence.

With experience across Europe, Africa, and the US, with fluency in English, French, and Portuguese, CLAS is built for organizations with international ambitions and local accountability.

Regulated Environments We Serve

Industries We
Specialize In

Healthcare & Medical Practices
Is your AI scribe tool leaking patient data? HIPAA requires a documented Risk Analysis. CLAS delivers one that holds up in an OCR audit.
HIPAA · HITECH · AI Governance
SMBs Under 25 Employees
You handle regulated data but can't afford a full-time CISO. CLAS delivers enterprise-grade compliance leadership at SMB economics starting at $995 for a Micro-Entity Snapshot.
HIPAA · CCPA · FL §501.171 · ISO 42001
AI-Adopting Organizations
Deploying AI tools in any regulated environment? ISO 42001 provides the governance framework to manage AI risk, demonstrate accountability, and stay ahead of incoming regulation.
ISO 42001 · AI Act · NIST AI RMF
Legal & Law Firms
AI tools that touch client communications must comply with ABA ethics obligations. We implement AI policies that protect billable work and attorney-client privilege.
ABA Ethics · CCPA · ISO 42001
Finance & Insurance
Regulatory pressure, cyber insurance requirements, and client data sensitivity demand more than a basic firewall. SOC 2 readiness and privacy compliance, built to scale.
SOC 2 · GLBA · CCPA · PCI-DSS
Office 365 Security Hardening
Most O365 tenants are dangerously misconfigured. Conditional access, MFA enforcement, DLP rules, and secure tenant configuration delivered right the first time for any regulated organization.
MFA · Conditional Access · DLP · Secure Score
Contact Centers
PCI-DSS for payment capture, COPC/CCSR for operational standards, and AI call-handling tools that raise liability questions. We map your compliance obligations across all three.
PCI-DSS · COPC · CCSR · AI Governance
HR & Recruiting Agencies
Healthcare clients expect HIPAA-level discipline — even from non-covered vendors. We make staffing and recruiting firms audit-ready with security policies, vendor documentation, and AI governance for recruiting tools.
HIPAA-Aligned · Security Policies · AI Governance · vCISO
Start the Conversation

Ready to Know
Where You Stand?

Most security breaches are preceded by a compliance gap someone knew about but didn't act on. A HIPAA Risk Assessment or cybersecurity review with CLAS takes weeks. A data breach can take years to recover from.

Request a Consultation
Location
Jacksonville & Saint Augustine, FL
Serving Northeast Florida & Remote Clients Nationwide
Connect
LinkedIn: saraiva-frederic
Trilingual: EN  ·  FR  ·  PT