MUSTER.
What we do

Services

Training is one deliverable. Most engagements start with something more urgent — a site visit on the calendar, a finding that needs remediation, or a program that grew faster than its documentation.

Assessment

Site visit readiness review

A structured walk-through of your compliance and risk program against what a reviewer will actually ask to see. Not a checklist emailed to you — a working review of documents, committee minutes, training records, policies, and the gaps between what your policies say and what your organization does.

  • Document and evidence review across the full program
  • Interviews with the people who actually run each process
  • A prioritized gap list, ranked by exposure rather than by ease
  • Findings written the way a reviewer would write them, so nothing is a surprise later
  • A board-ready summary memo

Typically two to four weeks depending on size.

Build

Regulatory crosswalk

Your organization's full training-to-regulation map, covering every funding stream, licensure condition, and state law that applies to you. Delivered in a format you own and can maintain.

  • Identification and citation of every applicable authority
  • Mapping against your current LMS assignments
  • Role-based assignment logic
  • Gap list for anything required but unassigned
  • A maintainable working file, not a locked PDF

Typically three to six weeks.

Build

Training program design & course development

The crosswalk tells you what has to be taught. This is the work of actually teaching it — courses written for your programs and your population, delivered into the system you already use, with reporting that closes the loop.

  • Courses authored to your programs and population, not generic modules with your logo on them
  • SCORM packages delivered into the learning management system you already run — no platform migration
  • Live instruction, virtual or on site, on layered confidentiality, consent authority, and risk management
  • Completion and attestation reporting formatted for the question a surveyor actually asks
  • A defined refresh cycle, so courses don't quietly go stale after a rule changes

Scoped to the engagement. A packaged course library is in development — ask about early access.

Build

Program & policy development

Compliance and risk policy suites, committee charters, incident and grievance workflows, and the documentation trail that demonstrates the program is running rather than merely written.

  • Policy and procedure drafting or redline of what you have
  • Committee charters and governance structure
  • Incident reporting, investigation, and grievance workflows
  • Audit tools and monitoring calendars
  • Board and committee reporting formats

Scoped to the engagement.

Ongoing

Fractional compliance & risk support

Standing support for organizations without a full-time compliance officer, or with one who needs a second set of eyes on the hard calls. Retainer-based, with a defined scope and a named point of contact.

  • Regular standing time, not ad-hoc availability
  • Escalation support on incidents and investigations
  • Committee and board reporting
  • Regulatory change monitoring relevant to your funding streams
  • Annual work plan and risk assessment

Monthly retainer, minimum term by agreement.

Ongoing

Designated Compliance Officer & Privacy Officer

Every covered entity has to designate a privacy official. Every compliance program needs someone accountable for it by name. Not every organization needs that person on payroll at full time — and for many, a full-time hire with salary, benefits, and recruitment costs is out of proportion to the size of the program it would run.

Here we hold the role rather than advise the person holding it: named in your policies, reporting to your governing body on your calendar, and accountable for the program itself.

  • Designation as Compliance Officer, Privacy Officer, or both, documented in your policies and board minutes
  • Standing report to the board or compliance committee on your governance schedule
  • Annual risk assessment and written compliance work plan
  • Intake, investigation, and disposition of complaints, incidents, and grievances
  • Breach risk assessments and notification determinations under HIPAA and state law
  • Policy maintenance and regulatory change monitoring across your funding streams
  • Training oversight and completion accountability
  • Direct access for your CEO and board — not routed through an account manager

Retainer with a defined minimum term. Executed business associate agreement, written designation, and defined escalation authority before the role takes effect.

How engagements work

Every engagement starts with a scoping call and a written scope before any invoice. You'll know what's included, what isn't, what it costs, and roughly how long it takes before you commit to anything.

Work is done by the person you spoke to. There is no bench of junior staff to hand your program off to, which is a limitation as much as a feature — it means capacity is finite and timelines are real.

What we don't do

We don't provide legal advice or legal representation, and we're not a substitute for your counsel. Where a question is genuinely legal — contract terms, litigation exposure, statutory interpretation with money on it — the right answer is your attorney, and we'll say so.

Training courses are educational. They don't carry continuing education credit unless the course says so, and they don't replace your own determination of what your organization is required to do.

We also don't take engagements that would put us on both sides of a matter. If there's a conflict, you'll hear about it before you hear a price.

Not sure which one you need?

Most organizations that call about training turn out to need the readiness review first. It's usually cheaper to find out what's actually wrong than to buy a fix for the wrong problem.

Start with a scoping call.

Twenty minutes to work out what you actually need, before anyone talks about scope or price.

Book a 20-minute call