CLAS by Fred Saraiva ("CLAS," "we," "our," or "us") provides cybersecurity, compliance, and advisory services designed to help organizations strengthen their compliance posture and prepare for audits.
This page clarifies our role in relation to the Health Insurance Portability and Accountability Act (HIPAA) and the handling of Protected Health Information (PHI).
CLAS is:
We operate strictly as an independent compliance and security advisory firm. Our services are designed to guide, assess, and support — but not to assume operational control of your compliance program.
Unless explicitly agreed in writing:
This policy is intentional and aligned with our risk-minimization and security-first approach.
In cases where services may require access to PHI:
Without a signed BAA: CLAS will not access, process, or be responsible for PHI in any capacity.
HIPAA compliance is a shared responsibility. CLAS provides:
However, final implementation decisions remain with the client. Ongoing compliance, monitoring, and enforcement are the client's responsibility.
While CLAS applies structured methodologies and best practices:
Our role is to help you identify gaps, reduce risk, and improve readiness.
We encourage all clients and prospects to:
"Compliance is not about handling sensitive data — it is about structuring systems so that sensitive data is protected."
Our focus is on:
CLAS is built on the principle that our value lies in structuring your compliance program — not in acting as a data processor.
If you have questions regarding HIPAA scope, PHI handling, or engagement structure, please contact:
This page may be updated periodically to reflect regulatory or operational changes. Updates will be posted with a revised effective date.