Speaker Profile
Kevin R. Thompson
Kevin R. Thompson is an experienced GRC (Governance, Risk Management, and Compliance) and HITRUST Consulting Specialist with over a decade of expertise in enhancing organizations' cybersecurity and compliance frameworks. With certifications including CCSFP (Certified HITRUST CSF Practitioner) and CHSPA (Certified HIPAA Security Professional), Kevin has a proven track record of leading high-impact projects across various regulatory landscapes such as HIPAA, SOC, FEDRAMP, PCI, GDPR, and NIST.
Kevin's career spans roles as a vCISO Support Manager at Sunstone Secure, where he directed comprehensive cybersecurity initiatives, and as a GRC/HITRUST Manager at Cognizant, where he oversaw HITRUST certification and compliance projects. His proficiency in leveraging AI tools like Google Gemini and ChatGPT has empowered him to craft robust policies, training materials, and KPI presentations that align regulatory requirements with business objectives.
With strong skills in risk management, policy development, and audit processes, Kevin brings a wealth of experience in corporate governance, incident response, and data privacy. His deep understanding of cybersecurity frameworks, combined with his ability to drive operational efficiency and mitigate risks, makes him an expert in delivering impactful training and consultancy in governance and compliance.
Certifications:
• Certified HITRUST CSF Practitioner (CCSFP)
• Certified HIPAA Security Professional Accelerated (CHSPA)
Core Competencies:
• Regulatory Compliance & Risk Management
• Cybersecurity and Data Privacy
• Policy Development & Corporate Governance
• Incident Response & Audit Processes

Kevin R. Thompson
May 13 2025
12 : 00 PM EST
90 Minutes
Regulatory Compliance Frameworks - Overview of major compliance frameworks like HITRUST, HIPAA, and SOC
Regulatory compliance frameworks help organizations meet legal and industry standards for data protection and security. HITRUST offers a comprehensive, certifiable framework combining multiple regulations like HIPAA, NIST, and ISO, focusing on risk management across industries. HIPAA (Health Insurance Portability and Accountability Act) ensures the privacy and security of healthcare information, with specif..

Kevin R. Thompson
June 10 2025
01 : 00 PM EST
90 Minutes
Compliance Auditing and Monitoring - Techniques for Auditing Compliance and Monitoring Adherence to Regulations
Compliance auditing and monitoring are critical components of an organization's risk management strategy. These processes ensure that companies adhere to regulatory requirements, industry standards, and internal policies, helping to avoid legal penalties, reputational damage, and financial losses.Compliance Auditing involves a formal, structured evaluation of an organization’s processes, controls, and recor..

Kevin R. Thompson
July 08 2025
12 : 00 PM EST
90 Minutes
Data Privacy and Protection - Data protection laws and best practices for ensuring data privacy and compliance.
Data Privacy and Protection is a critical area of focus for organizations managing personal, sensitive, or confidential information. With the rise of global regulations such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and others, businesses must comply with strict guidelines on how data is collected, stored, processed, and shared. These regulations aim to pr..

Kevin R. Thompson
August 12 2025
12 : 00 PM EST
90 Minutes
GRC Integration and Strategy - How to Integrate Governance, Risk, and Compliance into a Cohesive Strategy
GRC (Governance, Risk, and Compliance) Integration involves unifying governance, risk management, and compliance functions into a cohesive strategy that supports business objectives while managing risks and ensuring regulatory compliance. Traditionally, these functions have been handled separately, leading to silos, inefficiencies, and increased complexity in managing risks and compliance across the organiz..