CLIENT PRACTICUM
Engagement: Client Practicum · Focus: Health-Sector Regulatory Compliance · Frameworks: Provincial Privacy Law · HIE Conformance · SOC 2
Building a Market-Entry Compliance Program for a Digital Health Vendor
Context
A Canadian digital health technology company planned to expand into British Columbia. The company held SOC 2 Type II certification but had no compliance program for BC's health-sector regulatory regime, which differs materially from its home province - including consent requirements, data residency, and mandatory conformance certification for connecting to provincial health information systems.
Objective
Design and build the full compliance program: identify every applicable legal and regulatory requirement, determine what documentation and evidence the company already held, produce what was missing, and sequence the regulator submission process.
Scope
-
Legislative and regulatory mapping across provincial privacy law, health information legislation, and the province's conformance standards for health information exchange
-
Gap assessment against the company's existing SOC 2 control set and evidence
-
Policy, procedure, and evidence documentation development
-
Regulator form identification and submission sequencing
-
Stakeholder input gathering across six internal groups
Out of scope: technical security testing and remediation. Existing test evidence was inventoried and mapped, not re-performed.
Approach
1. Legislation mapping. Read the primary legislation, regulator guidance, and conformance standards directly rather than relying on vendor summaries, then decomposed them into discrete, assignable requirements.
2. Requirements decomposition. Converted the requirements into a master register of 77 accountable deliverables, each with a named owner, format, and status.
3. Reuse before rebuild. Mapped existing SOC 2 policies and evidence against the new requirements to avoid duplicating work - 15 items carried over directly.
4. Document production. Drafted 50+ policy, procedure, and evidence documents in submission-ready format, with placeholders flagged where engineering confirmation was pending.
5. Submission sequencing. Verified the regulator's full forms set at the source (which surfaced five forms not referenced in vendor-facing documentation) and filed the first two submissions.

.png)


Lessons
The most useful discipline came from an independent review of my policy deliverables, which caught real corrections. Rather than treating that as a setback, I built a review checkpoint into the document workflow: no deliverable moves to final status without a second set of eyes. Accuracy in compliance documentation is the product - the review step is now standard in how I work.
Next Stage
Engineering confirmations, advancing work-in-progress documents to final, and completing the remaining regulator submissions.