Verity MedSpa Compliance

Who we are

Two people, two disciplines, one file.

The gap between clinical compliance and data compliance is not a staffing problem to be solved with a bigger portal. It is two people who read each other's work.

Clinical & Regulatory Principal

Kathryn Dalton

A surgeon who owns and runs an aesthetic practice — the same kind of practice, with the same staff questions, the same medical-director paperwork and the same consent forms as the ones we advise.

Owns clinical protocols, scope of practice and delegation, medical direction governance, consent and documentation, product sourcing and handling, workforce training and competency, and operational procedure.

Security, Privacy & Risk Principal

Ryan Buckley

A field and virtual CISO with a multi-client compliance practice across HIPAA, SOC 2, ISO 27001, NIST, PCI and HITRUST, serving as virtual Chief Information Security Officer and Chief Privacy Officer for practices that cannot hire either.

Owns the security program and risk analysis, privacy controls, vendor management, payments and PCI, marketing technology, and incident response.

How we work

Every deliverable is reviewed by the principal who did not write it.

A clinical protocol that creates a privacy problem, or a security control that breaks a clinical workflow, gets caught before it reaches you. That rule is why there are two of us.

We tell you where we are conflicted

One of us owns a practice in this market. We do not take clients near it, and we say so before the first meeting rather than after.

We cite and date everything

Every factual claim we publish carries its source and the date we last checked it, and we re-check them quarterly. In a sector full of uncited vendor marketing, that is not housekeeping — it is the product.

We do not guess at the law

Where a question is legal, it goes to your counsel, and we say so in writing in every engagement. Where a rule is genuinely unsettled — and several in this sector are — we tell you that too, instead of selling certainty that does not exist.

What we will not do

  • Give legal advice. We are not a law firm; legal questions go back to your counsel.
  • Serve as your medical director, or take a fee for introducing one.
  • Become your IT provider — doing both would destroy the independence of the risk analysis we sign.
  • Take commission on software, insurance or products.
  • Certify or guarantee compliance. No consultant can, and anyone who offers to is selling you something else.