Specimen

Built from a demonstration environment, not client work

This is what you get when the work is done.

Every engagement ends with a written report. Rather than describe one, here is a full specimen: a Security & Compliance Snapshot for a fictional 18-person dental practice, built from a demonstration environment so you can judge the format and the depth before you spend anything.

Security & Compliance Snapshot

Regional dental practice · 18 staff · Specimen

Prepared by
Jordan Beck, CISSP-ISSEP

1 · Executive summary

The practice is subject to the HIPAA Security Rule and currently lacks a documented Security Risk Analysis, which is a mandatory annual requirement and the most common OCR audit finding. The review identified three high, two medium, and one low priority item. None indicate an active breach, and all are addressable within 30 to 60 days. A documented SRA plus the prioritized remediation below would move the practice from undocumented to defensible.

Plain-language takeaway: you are not in trouble today. If OCR or a breach knocked tomorrow, the missing risk analysis is the gap that hurts, and it is the highest-value first fix.

2 · Compliance mandate status

Framework Applies Status Required artifact
HIPAA Security Rule Yes No documented SRA on file Annual Security Risk Analysis + remediation plan
HIPAA Privacy Rule Yes Partial; policies outdated Updated policies + workforce training records
PCI-DSS Conditional Not assessed Correct SAQ + attestation

3 · Prioritized findings

H-1 · No documented HIPAA Security Risk Analysis
High

Business risk: The most common OCR audit finding; direct penalty exposure

Recommendation: Conduct and document the SRA

H-2 · Shared and admin logins on front-desk workstations
High

Business risk: No accountability; easy lateral movement

Recommendation: Unique accounts, least privilege, MFA

H-3 · Backups never tested for restore
High

Business risk: Ransomware could be unrecoverable

Recommendation: Implement and test offline or immutable backups

M-1 · No staff security-awareness training
Medium

Business risk: Phishing is the top small-business breach vector

Recommendation: Quarterly micro-trainings

M-2 · Patching is ad hoc
Medium

Business risk: Exposure to known, already-fixed vulnerabilities

Recommendation: A defined patch cadence

L-1 · Guest and clinical Wi-Fi not segmented
Low

Business risk: Larger attack surface than the practice needs

Recommendation: Segment the networks

4 · Method and data handling

  • Non-intrusive review of configuration, policy, and posture against the applicable framework. No exploitation, no disruption.
  • Analysis performed on JBeck Cyber equipment for the duration of the engagement; nothing sent to third-party cloud services, and nothing retained after close.
  • Conducted under signed, scoped authorization. Findings reflect point-in-time observations.

This specimen is a professional starting framework, not legal advice, and every figure in it is illustrative. A real engagement populates findings from your environment.