The Payer Data Classification Gap That's Going to Show Up in Your NPRM Asset Inventory
Why the NPRM's classification mandate traces to OCR's enforcement pattern rather than any single named breach, and what payers should be inventorying now.
TECHNOLOGY GROUP
Current Engagement · Purview Data Risk Assessment · A Major U.S. Cultural Institution
Free: Your Copilot Exposure Grade
An estimated A–F grade — outside-in, no tenant access. Based on two questions, your licensing, and how Microsoft 365 estates like yours typically drift. It answers one question: how worried should you be?
The Report Card is the diagnosis — your real grade, measured inside the tenant, with the receipts.
The license was treated as the deliverable, but it was only ever the starting material. Copilot didn't create a new risk, it made the existing one observable.
Featured engagement
Find out what Copilot can see, before your users do.
$2,500 flat. Founding rate for the first five organizations; $3,500 after. Five business days, start to readout.
You getWhy us: Built and personally delivered by one of a small handful of U.S. Microsoft MVPs recognized for Purview and data security...the practitioner, not a bench of juniors. Recent client: a major U.S. art museum, 500 seats, pre-Copilot rollout.
Priced to be signable without procurement. One week from now, you’ll know your grade.
Severian Technology Group is the data security practice of Matthew Silcox, a Microsoft Most Valuable Professional in Purview Data Security and a United States Marine Corps veteran.
The work is architecting and implementing Microsoft Purview programs for organizations that already own E5 licensing and need their Purview tenant to do what their auditors, compliance frameworks, and Copilot deployment plans already assume it is doing.
The clients are regulated enterprises (healthcare, financial services, government, defense, and nonprofit) operating under frameworks that assume data security controls already exist.
If this describes your situation: matt@severiansecurity.com · Book a 30-minute scoping call
Every engagement is fixed-scope and fixed-fee. No hourly billing. No scope ambiguity. The deliverable is something you can hand to an auditor, a board, or a remediation team.
Fixed-fee engagement
Where your attested compliance posture and your operational reality diverge.
$15,000 flat. Three weeks, start to readout.
You getSometimes the assessment is the entire engagement. More often it becomes the basis for the architecture and implementation work that follows.
Fixed-fee engagement
Copilot does not apply judgment to access — it operates within your users’ existing permissions.
$25,000 flat. Four weeks, start to readout.
For organizations deploying or planning M365 Copilot. This engagement quantifies the data exposure Copilot will amplify.
You getFixed-fee engagement
Full-stack Purview design for regulated enterprises with complex requirements.
$45,000–$75,000, fixed at scoping. Six to eight weeks. Scoped on seat count, workload count, and regulatory complexity.
You getMonthly retainer
Ongoing Purview support after implementation.
Retainers start at $4,000/month.
You getMost Purview tenants are configured to catch what the documentation demonstrates. The regulated data that actually lives in your environment rarely looks like the examples.
Matt is one of three U.S.-based MVPs whose recognized contribution area is Microsoft Purview. Matt holds SC-100 (Cybersecurity Architect Expert), SC-200 (Security Operations Analyst Associate), and SC-401 (Information Security Administrator Associate) certifications. Prior to technology, Matt served four years in the United States Marine Corps.
MVPs gain access to pre-release capabilities, roadmap briefings, and the architectural context that determines how these platforms will evolve before that evolution reaches public documentation.
The technical depth (implementation specifics, undocumented platform behaviors, the problems that emerge only at the boundary between what the documentation promises and what the software actually does) is published at severian.ghost.io for practitioners who do the work, not the people who approve the budget.
The Payer Data Classification Gap That's Going to Show Up in Your NPRM Asset Inventory
Why the NPRM's classification mandate traces to OCR's enforcement pattern rather than any single named breach, and what payers should be inventorying now.
The HIPAA Security Rule NPRM is a Forensic Document
Reading the proposed Security Rule as forensic reconstruction: how 2024's largest breaches dictated 2026's compliance map.
The Copilot Problem Is a Data Hygiene Problem
Copilot did not create a new security risk. The exposure was already there; the deployment just made it observable.
More at severian.ghost.io
Pick the engagement type that fits. The conversation takes 30 minutes.
Purview, Copilot readiness, and data security — written for the people who do the work. No more than weekly.