Healthcare organizations live with HIPAA exposure every day. This toolkit gives you a working framework to catch compliance gaps before regulators do — a triage model and checklist set built from years running compliance programs in large healthcare organizations. Built for compliance teams and general counsel who need to move past "we have a BAA" to "we've actually reviewed it." HHS gives you guidance and a risk assessment tool. This gives you the four decision instruments those tools assume you already have.
Who it's for: Healthcare organizations with regulated data, shared patient information, or vendors handling PHI. Best for teams with compliance infrastructure in place but gaps in incident readiness and BAA review rigor.
What's Included:
- BAA Review Checklist
- HIPAA Incident Decision Support Worksheet
- OCR Audit Readiness Assessment
- PHI Data Handling Addendum
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
Most organizations deploying AI tools have no structured way to evaluate them. This bundle starts there. It's the intake, triage, and approval workflow that catches problematic use cases before they ship, built from experience standing up AI review in regulated organizations. Built for teams that want governance without bureaucracy: fast intake, clear risk assignment, documented accountability. NIST gives you a framework. This gives you the intake form, the tiering rubric, and the approval path that make a framework operational.
Who it's for: Organizations rolling out AI tools across teams without a formal review process. Best for companies asking "which AI decisions need oversight" and "who owns this if it fails.”
What's Included:
- Draft AI Use Policy
- AI Use Case Intake Form
- Risk Tiering Rubric
- Governance Playbook
- Required Artifacts Checklist
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
California privacy law moves fast. This toolkit keeps you caught up. You get a gap assessment to find what you're missing, the playbook to handle the top 3 consumer rights requests (access, deletion, opt-out), and a side-by-side reference for GDPR teams. Built for California-facing companies building a privacy program without hiring a privacy team. Template mega-packs give you sixty-plus generic files. This gives you four you will actually use, plus the GDPR crosswalk.
Who it's for: Companies with California customers or operations but no dedicated privacy counsel. Works best if you already have some privacy infrastructure in place.
What's Included:
- CPRA Gap Assessment Template
- Consumer Rights Response Playbook
- CCPA/GDPR Crosswalk Reference
- CCPA Compliance Playbook
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
Lawyers are getting sanctioned for AI. This toolkit gives you the procedures to show you took it seriously. It's the turnkey office policy, the citation-verification protocol that prevents a fabricated-citation sanction, client disclosure language, and the training — built to the ABA Model Rules with California's rules and the proposed amendments flagged. State Bar guidance tells you the rules. This turns them into firm procedures, training, and a verification protocol.
Who it's for: For solos and small firms using AI to draft and research who want written procedures, a verification step, and a training record in place.
What's Included:
GenAI Use Policy (fill-in)
Citation & Output Verification Protocol
Client Disclosure & Consent Language
Confidentiality & Tool-Selection Guide
AI Competence training materials + 20-question assessment
AI Ethics Compliance Checklist
Educational templates, not legal advice. Training materials are self-study and do not by themselves confer MCLE credit.
California Rule of Court 10.430 required any court that does not prohibit generative AI to adopt a use policy by December 15, 2025. That date has passed. A court that never formally addressed AI is covered by the rule, not exempt from it. This kit gives you the policy and the supporting documents built to the rule's required elements: redaction, records access, vendor vetting, and public-facing AI guidance. Built by a former government attorney for courts that need the operational pieces without a consultant on retainer. The Judicial Council model policy addresses the rule. This addresses implementation, and covers redaction and records access too.
Who it's for: Court executive officers, presiding judges, clerk's offices, and court IT/records teams in California.
What's Included:
Court AI Use Policy (built to Rule 10.430)
PII Redaction Protocol (CRC 1.201)
Records Retention & Public-Access Guide (CRC 2.503)
E-Filing / Records / AI Vendor Vetting Checklist
Pro Se / Public-Interaction Guidance
Rule 10.430 Compliance Checklist
Educational templates, not legal advice. Confirm Rule 10.430 and your local rules with your counsel.
Teachers are already using AI, and student data is moving into tools no one vetted. This toolkit gives a district the board-adopted policy and the whole supporting stack — built to FERPA, COPPA, SOPIPA, and California Education Code § 49073.1 — including the board-adoption kit and a § 49073.1 vendor agreement. Built for districts that need it adoptable, not just downloadable. Start with California's model AI policy if all you need is a policy. Use this when you need to get it through your board and into district operations.
Who it's for: Superintendents, CTO/CIOs, data-privacy leads, and boards at K-12 districts.
What's Included:
Student-Data & AI Use Policy (keystone)
Risk Tiering + Required Controls + EdTech Vendor Vetting
Classroom AI & Academic Integrity (by grade band)
Parent/Guardian Notice & Consent (COPPA/PPRA)
Student Data Inventory; Staff Acceptable-Use + PD; Equity/Accessibility Review
Board-Adoption Kit + § 49073.1 Data Privacy Agreement
Educational templates, not legal advice. Adapt with your district's counsel and adopt through your board.
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
Financial-aid data is GLBA "customer information," and any AI tool that touches it is in scope for the Safeguards Rule — with two different clocks: 30 days to the FTC under the Safeguards Rule, and same-day reporting to Federal Student Aid on detection or even suspicion. This kit gives you the written program with an AI overlay, the vendor controls, the breach runbook, and the institutional policy. Built by a former government attorney who ran security and privacy programs at scale. Free AI policies exist. Free GLBA material exists. Nothing combines Safeguards, AI governance, vendor review, and IRB research data into one operating structure.
Who it's for: CISO/CIO, General Counsel/compliance, and the financial-aid and research offices at universities and community colleges.
What's Included:
GLBA Safeguards Program + Breach Runbook (FSA/FTC timelines)
Institutional AI & Data Governance Policy
Risk Tiering + Required Controls
AI/EdTech Vendor Vetting (service-provider safeguards)
FERPA & CA Public-Records Handling; Incident & Breach Response
IRB / Research-Data AI Governance (universities)
Educational templates, not legal advice. Confirm current FTC/FSA requirements with your counsel and security office.
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
This toolkit gives legal, privacy, security, and operations teams a practical incident-readiness package with intake workflows, escalation triggers, assessment tools, communication templates, and tabletop materials. No regulator publishes an incident response program. This one is built around the legal and privacy decisions, not just the technical ones.
Who it is for: Legal, privacy, compliance, security, IT, risk, and executive teams that want a documented incident-response structure before a privacy, security, vendor, or AI-related event occurs.
What is included:
• Incident Intake & Triage Form
• Severity Classification Matrix
• Legal / Privacy / Security Escalation Workflow
• Breach Assessment Worksheet
• Privilege & Investigation Documentation Guide
• Internal Communications Templates
• Vendor / Business Associate Incident Checklist
• Executive Briefing Template
• Incident Response Tabletop Exercise
• Post-Incident Lessons Learned Template
Need help putting this into operation? JHarris Advisory runs fixed-scope, fixed-fee engagements on program design, rollout sequencing, and staff training. Consulting services, not legal services. Start a scoping conversation at jharrisadvisory.com/contact
No results match your search. Try removing a few filters.