Kul Bhushan headshot

Kul Bhushan, MBA, CISSP

Fractional Security & Compliance Consultant

SOC 2 • HIPAA / HITECH • NIST • IR • DR/BC for US Healthcare, SaaS & Fintech
SOC 2 Readiness HIPAA Programs NIST CSF / 800-53 Incident Response & Tabletop Disaster Recovery & Business Continuity

About

I’m a security founder and consultant focused on helping fast-growing healthcare, SaaS, and fintech companies in the U.S. build practical, audit-ready security and compliance programs.

With an MBA and CISSP, I bridge the gap between technical security work and executive expectations, aligning SOC 2, HIPAA / HITECH, and NIST frameworks with real business goals, customer contracts, and U.S. regulatory pressure.

Core Services

SOC 2 Readiness & Audit Support
  • Gap assessment and remediation roadmap
  • Control design, policies & procedures
  • Evidence collection and audit preparation
  • Continuous readiness and customer questionnaire support
HIPAA Compliance for Healthcare & Healthtech
  • HIPAA Security & Privacy Rule gap analysis
  • Risk assessments and PHI protection
  • Policies, procedures, and training
  • Vendor and BA risk management
NIST Framework Alignment
  • NIST CSF / 800-53 assessments
  • Control mapping and maturity roadmaps
  • Implementation guidance and coaching
Incident Response & Tabletop Exercises
  • Incident Response plans and playbooks
  • Roles, responsibilities & escalation paths
  • Scenario-based tabletop design and facilitation
  • After-action reports and improvement plans
Disaster Recovery & Business Continuity
  • DR/BC strategy and documentation
  • RTO/RPO definitions and validation
  • Backup and restoration planning
  • Continuity testing and refinement

Who I Work With

Healthcare & Healthtech (U.S.) HIPAA / HITECH programs, PHI security, NIST alignment, vendor and BA risk.
SaaS (B2B / Enterprise) SOC 2 readiness, security program build-out, and customer security reviews.
Fintech SOC 2, NIST alignment, IR/DR readiness, vendor risk, and support for U.S. regulatory expectations.

Engagement Models

Let’s Talk

If you’re preparing for SOC 2 or HIPAA, scaling into enterprise markets, or strengthening your security posture, I’d be happy to help.

Email: kul@kulbhushan.com

Website: kulbhushan.com