Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.
By:
Schellman
February 13th, 2024
More and more, organizations are turning a keener eye toward ESG initiatives. Though the Social Governance pillars are no less important, it’s the Environmental cornerstone of ESG that is commanding more scrutiny—more specifically, greenhouse gas (GHG) emissions.
By:
Schellman
February 7th, 2024
As more aspects of society move online, digital assets—or any uniquely identifiable, discoverable thing that is stored online and used to realize value—have become increasingly prevalent, taking the form of data, cryptocurrencies, documents, credentials, and photos, among others.
Healthcare Assessments | HIPAA
By:
Schellman
February 1st, 2024
Successfully managing your HIPAA risk means accounting for those introduced by your vendors that are supplementing existing business processes in different ways. Vendors can make you vulnerable in a variety of ways, which means a variety of solutions becomes necessary.
By:
Schellman
January 17th, 2024
As you may remember, when Tom Sawyer was asked to paint a fence, he ended up outsourcing the job and even got his chosen “vendors” to pay him for the privilege. What was an assigned chore ended up being done by others and turning a profit for Tom.
By:
Schellman
December 7th, 2023
While they have become increasingly prevalent in modern life, offering opportunities for efficiency, automation, and improved decision-making in various domains, the proliferation of IoT devices also raises important considerations related to security, privacy, data management, and interoperability.
By:
Schellman
November 21st, 2023
With the escalation of climate and various environmental, social, and governance (ESG)-related risks, organizations are now actively setting bold sustainability objectives, and in recognition of the related concerns in their supply chains over which they lack control, companies are also asking for cooperation from their vendors in addressing their emissions to further minimize their environmental impact.
By:
Schellman
November 20th, 2023
With the introduction of the Cybersecurity Maturity Model Certification (CMMC) program, contractors working with the U.S. Department of Defense (DoD) will be required to meet a certain level of cybersecurity maturity ensuring the protection of the involved sensitive information and data, specifically controlled unclassified information (CUI) and federal contract information (FCI).
By:
Schellman
November 15th, 2023
With over two decades of HIPAA history behind us, more than a decade of mandatory compliance and federal compliance enforcement, and a shortage of resources to help hospitals achieve compliance, the healthcare industry is still plagued by non-compliance issues every year—particularly regarding risk and access management.