John J. Trinckes, Jr. is the Director of GRC Services at Elevate Consult LLC, and the author of How Healthcare Data Privacy is Almost Dead… and What Can Be Done to Revive It!, The Definitive Guide to Complying with the HIPAA/HITECH Privacy and Security Rules, and The Executive MBA in Information Security all published by CRC Press. As a member of the senior leadership team, he is responsible for the delivery of quality cybersecurity, privacy, and AI advisory services to multiple clients. He maintains the following credentials: CMMC CCA/CCP, CISSP, CISM, CDPSE, CRISC, CSA CCSK, PECB ISO/IEC 27001 Sr. LA and Sr. LI, PECB ISO/IEC 42001 Lead Implementer and Lead Auditor, DHS Section 508 Trusted Tester, NSA IAM/IEM, and HITRUST CDA. As a former Data Protection Officer and Chief Information Security Officer, he led efforts and maintained several highly recognized (and coveted) certifications such as the ISO 27001 (Information Security Management System – ISMS) with enhanced ISO 27017 (Cloud Security controls), the ISO 27701 (Privacy Information Management System – PIMS) with enhanced ISO 27018 (Cloud Privacy Controls), the ISO 9001 (Quality Management System – QMS), the ISO 42001 (AI Management System – AIMS), and HITRUST CSF i1 certification. He also led efforts in maintaining SOC 2 Type II attestation, EU‑US Data Privacy Framework (DPF), General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and Asia‑Pacific Economic Cooperation (APEC) – Privacy Recognition for Processors (PRP) Certification.