Skip to main content
Image coming soon

SEC1827 First 90 Days: Building a Security Foundation Aligned to Healthcare Compliance

$200.00
Adding to cart… The item has been added

What is the First 90 Days course about?

A step-by-step implementation guide to building your first 90-day security foundation aligned with healthcare compliance. Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

What situation is the First 90 Days for?

Security leaders spend weeks assembling evidence, chasing control ownership, and reworking documentation under audit pressure. The problem isn’t knowledge, it’s implementation structure. Without a repeatable foundation, even experienced CISOs burn cycles reinventing the wheel every quarter.

Who is the First 90 Days course for?

Healthcare CISOs and senior IT leaders with CISSP or CCSP credentials, responsible for standing up or refining security programs in regulated environments.

What do you take away from the First 90 Days course?

Ship a documented, assignee-mapped security foundation in 90 days Reduce recurring compliance preparation time by 80% Align CISSP domains directly to HIPAA, NIST, and internal audit requirements Eliminate last-minute evidence chasing with pre-built ownership templates Turn first-time control implementation into a repeatable pattern.

What's included with your purchase?

12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.

What does the First 90 Days cover on delivery and format?

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: 90 minutes per week for 12 weeks, with optional deep dives for complex modules.

How does this compare to the alternatives?

Consulting firms charge $25K+ for similar foundation builds; generic CISSP training lacks healthcare implementation detail. This course delivers the exact structure, templates, and sequencing needed , at 1% of the cost.

What does the First 90 Days cover on frequently asked?

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Closely related courses: First 90 Days as CISO in Pediatric Healthcare, First 90 Days Evaluation and First 90 Days Evaluation Kit, First 90 Days Toolkit, First 100 Days Toolkit.

More answers: what you get with every course, refund policy, all help answers.

A tailored course, built for your situation

First 90 Days: Building a Security Foundation Aligned to Healthcare Compliance

A step-by-step implementation guide to building your first 90-day security foundation aligned with healthcare compliance.

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
The first 90-day compliance lift takes 200+ hours, but it doesn't have to.

The situation this course is for

Security leaders spend weeks assembling evidence, chasing control ownership, and reworking documentation under audit pressure. The problem isn’t knowledge, it’s implementation structure. Without a repeatable foundation, even experienced CISOs burn cycles reinventing the wheel every quarter.

Who this is for

Healthcare CISOs and senior IT leaders with CISSP or CCSP credentials, responsible for standing up or refining security programs in regulated environments.

Who this is not for

Entry-level analysts, consultants selling compliance services, or leaders in non-regulated sectors without healthcare compliance exposure.

What you walk away with

  • Ship a documented, assignee-mapped security foundation in 90 days
  • Reduce recurring compliance preparation time by 80%
  • Align CISSP domains directly to HIPAA, NIST, and internal audit requirements
  • Eliminate last-minute evidence chasing with pre-built ownership templates
  • Turn first-time control implementation into a repeatable pattern

The 12 modules (with all 144 chapters)

Module 1. Defining Your Healthcare Security Scope
Map organizational boundaries, systems, and data flows to isolate compliance-critical assets.
12 chapters in this module
  1. Identifying regulated data types in clinical and administrative systems
  2. Mapping patient data pathways across cloud and on-prem environments
  3. Defining system boundaries for audit scoping
  4. Classifying third-party vendors with data access
  5. Documenting scope justification for internal reviewers
  6. Aligning scope with HIPAA Security Rule requirements
  7. Using CISSP Domain 2 to inform asset classification
  8. Creating a visual data flow diagram for stakeholder review
  9. Establishing scope change control for future systems
  10. Integrating scope documentation into annual review cycles
  11. Avoiding common scope creep pitfalls in hybrid environments
  12. Template: Healthcare system boundary statement
Module 2. Core Policy Framework Setup
Build the foundational policies that govern access, encryption, and incident response.
12 chapters in this module
  1. Drafting a minimum-viable acceptable use policy for healthcare staff
  2. Defining role-based access principles for clinical workflows
  3. Establishing baseline encryption standards for data at rest and in transit
  4. Creating a bring-your-own-device policy for clinical settings
  5. Documenting incident classification levels for medical systems
  6. Aligning policy language with NIST CSF categories
  7. Mapping CISSP Domain 5 controls to policy requirements
  8. Setting policy review and update cadence
  9. Gaining leadership sign-off with risk-informed rationale
  10. Distributing policies through secure, auditable channels
  11. Tracking employee attestation with automated reminders
  12. Template: Healthcare policy implementation checklist
Module 3. Access Control Implementation
Deploy role-based access models with clear ownership and periodic review.
12 chapters in this module
  1. Inventorying user roles across clinical, billing, and administrative teams
  2. Defining least privilege access for EHR and pharmacy systems
  3. Mapping access rights to job functions, not departments
  4. Integrating IAM with HR onboarding and offboarding
  5. Setting quarterly access review cycles with department leads
  6. Documenting exceptions with time-bound approvals
  7. Using CISSP Domain 5 to structure access control models
  8. Aligning access logs with audit trail requirements
  9. Implementing just-in-time access for admin functions
  10. Monitoring for anomalous access patterns in clinical systems
  11. Creating a compensating control process for legacy applications
  12. Template: Access review tracking workbook
Module 4. Asset and Configuration Management
Establish a living inventory of systems and baseline security configurations.
12 chapters in this module
  1. Automating discovery of clinical devices and endpoints
  2. Classifying devices by criticality and data access level
  3. Defining secure configuration baselines for Windows and macOS
  4. Standardizing mobile device settings for nursing units
  5. Maintaining an up-to-date hardware and software inventory
  6. Integrating configuration management with patch cycles
  7. Using CISSP Domain 7 to inform device security practices
  8. Documenting configuration exceptions with risk justification
  9. Creating a process for decommissioning retired systems
  10. Aligning inventory practices with HIPAA Technical Safeguards
  11. Generating evidence reports for internal auditors
  12. Template: Healthcare device inventory register
Module 5. Vulnerability and Patch Management
Implement a prioritized process for identifying, assessing, and remediating vulnerabilities.
12 chapters in this module
  1. Scheduling regular vulnerability scans across clinical networks
  2. Prioritizing findings based on exploitability and data exposure
  3. Establishing SLAs for critical and high-severity patches
  4. Coordinating patching windows with clinical operations
  5. Documenting risk acceptance decisions with executive sign-off
  6. Integrating scanner results into ticketing systems
  7. Using CISSP Domain 7 to structure vulnerability response
  8. Validating patch success with follow-up scanning
  9. Managing third-party patch dependencies for medical devices
  10. Reporting remediation status to leadership weekly
  11. Creating an emergency patch process for active threats
  12. Template: Vulnerability remediation tracking log
Module 6. Incident Response Preparation
Build a response plan tailored to healthcare-specific threats and reporting obligations.
12 chapters in this module
  1. Defining incident types relevant to healthcare operations
  2. Establishing escalation paths for ransomware and data exfiltration
  3. Creating roles and contact lists for incident response team
  4. Documenting HIPAA breach notification timelines and procedures
  5. Developing communication templates for patients and regulators
  6. Conducting tabletop exercises with clinical leadership
  7. Using CISSP Domain 6 to structure response workflows
  8. Integrating EHR downtime procedures into incident plan
  9. Logging and preserving evidence for forensic review
  10. Reviewing and updating plan after each incident
  11. Aligning response activities with NIST SP 800-61
  12. Template: Healthcare incident response playbook
Module 7. Business Continuity and Disaster Recovery
Ensure critical clinical systems can recover within required timeframes.
12 chapters in this module
  1. Identifying mission-critical applications in patient care
  2. Defining RTO and RPO for EHR and laboratory systems
  3. Documenting backup schedules and retention periods
  4. Testing failover procedures for on-prem and cloud systems
  5. Establishing alternate care sites for extended outages
  6. Using CISSP Domain 8 to structure continuity planning
  7. Aligning BCP with HIPAA Contingency Rule requirements
  8. Creating a communication plan for staff during outages
  9. Documenting lessons from past incidents and drills
  10. Reviewing insurance coverage for cyber events
  11. Integrating DR testing into annual compliance calendar
  12. Template: Healthcare BCP test results report
Module 8. Third-Party Risk Management
Evaluate and monitor vendors with access to patient data or critical systems.
12 chapters in this module
  1. Creating a vendor inventory with data access classification
  2. Conducting security assessments using SIG Lite or equivalent
  3. Requiring evidence of HIPAA BAAs from all relevant vendors
  4. Monitoring vendor compliance status throughout contract life
  5. Defining minimum security requirements for cloud providers
  6. Using CISSP Domain 5 to inform vendor control expectations
  7. Establishing a process for high-risk vendor onboarding
  8. Tracking vendor audit reports and renewal dates
  9. Responding to vendor security incidents with patient data impact
  10. Aligning third-party reviews with organizational risk appetite
  11. Creating a vendor offboarding checklist
  12. Template: Third-party risk assessment scorecard
Module 9. Security Awareness Training
Deliver role-specific training that reduces phishing and policy violations.
12 chapters in this module
  1. Designing training content for clinical, billing, and admin staff
  2. Scheduling annual and role-based training modules
  3. Creating phishing simulations with healthcare-themed lures
  4. Tracking completion rates and follow-up for non-compliance
  5. Using CISSP Domain 8 to inform security culture development
  6. Measuring training effectiveness with pre- and post-tests
  7. Incorporating new hire training into onboarding workflow
  8. Documenting training program for auditor review
  9. Updating content based on recent incidents and threats
  10. Engaging department champions to reinforce messaging
  11. Aligning training topics with current regulatory expectations
  12. Template: Security awareness completion dashboard
Module 10. Audit Preparation and Evidence Collection
Streamline the process of gathering and presenting compliance evidence.
12 chapters in this module
  1. Mapping controls to HIPAA, NIST, and internal audit requirements
  2. Creating a centralized evidence repository with access controls
  3. Documenting control operation with screenshots and logs
  4. Assigning evidence owners for each control
  5. Using CISSP Domain 10 to structure audit readiness
  6. Scheduling quarterly evidence reviews to avoid last-minute crunch
  7. Generating control status reports for leadership
  8. Responding to auditor inquiries with source-backed evidence
  9. Maintaining version history for policy and procedure documents
  10. Preparing walkthroughs with process owners
  11. Tracking open issues and remediation plans
  12. Template: Audit evidence tracker with ownership assignment
Module 11. Continuous Monitoring and Improvement
Implement metrics and review cycles to keep security current.
12 chapters in this module
  1. Defining KPIs for patching, access reviews, and incident response
  2. Generating monthly security dashboards for leadership
  3. Conducting quarterly control effectiveness reviews
  4. Using CISSP Domain 10 to inform continuous improvement
  5. Integrating feedback from audits and incidents into updates
  6. Benchmarking performance against peer healthcare organizations
  7. Identifying emerging threats to clinical systems
  8. Adjusting security program focus based on risk trends
  9. Documenting changes to controls and rationale
  10. Aligning review cycles with fiscal and audit calendars
  11. Engaging external assessors for objective feedback
  12. Template: Security program review meeting agenda
Module 12. Sustaining the Foundation Beyond 90 Days
Lock in momentum with ownership, documentation, and repeatable cycles.
12 chapters in this module
  1. Transferring control ownership to permanent roles
  2. Embedding security tasks into existing job descriptions
  3. Establishing a security committee with cross-functional leads
  4. Using CISSP domains as a reference for ongoing decisions
  5. Integrating security reviews into project lifecycle gates
  6. Creating a backlog of incremental improvements
  7. Planning for annual policy and control refreshes
  8. Documenting the foundation for new team members
  9. Measuring program maturity over time
  10. Aligning security roadmap with organizational strategy
  11. Celebrating milestones to reinforce team engagement
  12. Template: 90-day handover and sustainment plan

How this maps to your situation

  • First-time CISO in healthcare
  • IT leader expanding security oversight
  • Security program rebuild post-audit
  • Cloud migration with compliance implications

Before vs. after

Before
Security foundation efforts stall under complexity, audit pressure, and competing priorities , consuming hundreds of hours with inconsistent results.
After
A documented, assignee-mapped, audit-ready security foundation is delivered in 90 days , with reusable templates that cut future cycles by 80%.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 90 minutes per week for 12 weeks, with optional deep dives for complex modules.

If nothing changes
Without a structured foundation, security efforts remain reactive, evidence collection stays chaotic, and leadership trust erodes under recurring compliance pressure.

How this compares to the alternatives

Consulting firms charge $25K+ for similar foundation builds; generic CISSP training lacks healthcare implementation detail. This course delivers the exact structure, templates, and sequencing needed , at 1% of the cost.

Frequently asked

Who is this course for?
Healthcare CISOs, IT leaders, and security practitioners responsible for building or refining a compliance-aligned security program.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I use this if I’m not a CISSP?
Yes , the course uses CISSP domains as an organizing framework, but is designed for implementation, not certification prep.
$199 one-time. 90 minutes per week for 12 weeks, with optional deep dives for complex modules..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours