Fixed scope. Fixed fee.
A defined finish.
Every engagement below states the number, the timeline, and the specific thing that has to be true before I stop billing. No discovery phase to find out what it costs.
Six engagements.
Every one priced.
Healthcare, education, courts, and privacy teams that are past the template stage. You know what is being built, how long it takes, what it costs, and what done looks like before the work begins.
AI Governance Implementation
You get: intake workflow, risk-tiering rubric, approval matrix, vendor-diligence process, minimum-viable controls, and a governance-committee model.
A new AI use case moves from intake to approval without me in the room, with the rubric and approval matrix in active use.
HIPAA Compliance Support
You get: HIPAA gap review, policy and workflow remediation, BAA issue-spotting, incident-readiness support, and leadership briefing support.
You hold a prioritized gap report, remediated policies, a BAA fix list, and an incident-readiness brief leadership has reviewed.
Legal, Court & Clerk AI Governance
You get: AI-use policy, citation-verification standard, confidentiality and court AI policy, redaction and records-access protocol, and vendor review.
An adopted AI-use policy, a citation-verification standard staff follow, and a redaction and records-access protocol are in place.
Privacy & Data Governance
You get: data-use review, privacy gap assessment, vendor and data-sharing issue-spotting, remediation roadmap, and an executive summary.
Leadership has a gap assessment mapped to the regulations, a vendor and data-sharing risk list, and a roadmap they can act on.
Incident Readiness Support
You get: severity framework, Day-1 checklist, escalation map, breach decision support, a tabletop scenario, and an executive debrief.
Your team has walked the escalation map, run one tabletop, and holds a severity framework and Day-1 checklist ready to use.
Education AI & Data Governance
You get: district or institutional AI policy, student-data controls under FERPA and COPPA, vendor-vetting rubric, board and executive adoption package, and a GLBA overlay.
An adopted AI policy, documented student-data controls, a vendor-vetting rubric in use, and a delivered board adoption package.
Not ready for five figures?
A Readiness Review gives you the prioritized gap report and remediation roadmap for $2,500 to $5,000, delivered in two weeks and credited against a full engagement if you proceed within 90 days.
Operational build.
Legal confirmation.
I build the governance infrastructure your organization has to operate every day. Your attorneys confirm legal sufficiency where legal judgment is required. That division of labor is why this does not compete with your law firm, and why your law firm will not object to it.
These are management consulting and operational governance services, not legal advice or legal representation. Jeremy Harris is a licensed attorney, but JHarris Advisory is not a law firm and no attorney-client relationship is created.
Practical insight.
Built to drive action.
Keynotes, panels, workshops, and executive briefings for legal, compliance, security, and executive audiences. Twelve years in-house at Sutter Health and a 20-year Air Force career leading legal offices, so the examples are ones that actually happened. That is usually why the room asks better questions.
Check availability →
30–60 minutes
moderation
60–90 minutes
Half or full day
Current speaking topics
Delivered virtually or in person, tailored to the audience, the sector, and how deep into operations you want to go.
AI governance that survives operations
Intake, risk tiering, guardrails, vendor oversight, and the reporting leadership actually needs.
Privacy operations in practice
From data inventory chaos to structured operations: remediation, retention, and vendor oversight.
Incident readiness: the first 72 hours
Severity models, escalation paths, notification triggers, and the gaps organizations find too late.
Health data and HIPAA beyond the policy
Business associate oversight, workforce readiness, breach analysis, and incident documentation.
Cybersecurity governance
Where regulatory exposure, vendor risk, security operations, and organizational resilience intersect.
Governance lessons from JAG service
Leadership under pressure and decision-making in high-stakes environments, translated for civilian organizations.
Tell me what you're working on.
I read these myself and come back within two business days with a scope, or with a straight answer that you don't need one. If a $399 toolkit solves it, I'll say so.