Is Your Business Actually Compliant?
A Quick Checklist for New Mexico Companies
By David Luft | CEO, LDD Consulting | MCSE, MCT, MBA | Published July 2026 | 5 min read
By David Luft | CEO, LDD Consulting | MCSE, MCT, MBA | Published July 2026 | 5 min read
IT compliance means meeting the legal, regulatory, and industry-specific requirements that govern how your business handles data, protects systems, and maintains records. Most small business owners assume they’re covered — but without a deliberate review, it’s easy to have gaps that expose you to fines, audits, or worse
Compliance isn’t just a large-company problem. If your business handles patient health information, processes credit cards, stores employee records, or works with government contracts, there are rules about how that data must be protected — and consequences for not following them.
The challenge for small businesses is that compliance requirements aren’t always clearly communicated. You don’t get a letter in the mail telling you which regulations apply to your industry. Most owners find out about gaps the hard way — during an audit, after a breach, or when a vendor or client asks for documentation you don’t have.
Working with an Albuquerque IT services provider that includes compliance support can help you stay ahead of this, but the first step is understanding what applies to your business in the first place. Our Compliance & Risk Management services are designed specifically to help small and mid-sized businesses in New Mexico navigate this.
Not every regulation applies to every business. Here’s a quick overview of the most common ones LDD sees affecting small businesses in New Mexico:
If your business is in healthcare — or works with healthcare providers as a vendor — HIPAA requires specific protections for patient data, including access controls, encryption, audit logs, and breach notification procedures. Medical offices, billing services, and healthcare IT vendors all fall under this.
If you accept credit or debit card payments, you’re required to comply with the Payment Card Industry Data Security Standard. This applies regardless of business size — even a small retail shop or service provider processing cards needs to meet baseline PCI requirements.
If your business works with schools or handles student records in any capacity, the Family Educational Rights and Privacy Act governs how that data is stored and shared.
New Mexico has its own data breach law requiring businesses to notify affected individuals — and in some cases the state attorney general — if personal information is compromised. This applies to any business operating in New Mexico that stores personal data about residents.
If your business works with federal agencies or holds government contracts, the Cybersecurity Maturity Model Certification has become an increasingly important compliance requirement. Even small subcontractors can be affected.
This isn’t exhaustive, but it covers the fundamentals that apply to most small businesses. If you can’t check most of these off, it’s time to have a conversation with your IT provider.
Access Controls
☐ Employees only have access to the systems and data they need for their role
☐ Admin privileges are limited to those who genuinely require them
☐ Former employee accounts are disabled immediately upon departure
☐ Multi-factor authentication (MFA) is enabled on all critical systems
Data Protection
☐ Sensitive data is encrypted — both stored and in transit
☐ Cloud backup is running and tested regularly
☐ You know where your sensitive data lives and who can access it
☐ Personal data is not stored longer than necessary
Network Security
☐ Business network is separated from guest Wi-Fi
☐ Firewall is active and properly configured
☐ All software and operating systems are current on patches and updates
☐ Antivirus/endpoint protection is installed and actively monitored
Policies and Documentation
☐ You have a written acceptable use policy for employees
☐ You have a documented incident response plan
☐ Security awareness training is provided to staff at least annually
☐ Vendor agreements include data handling and security requirements
Industry-Specific
☐ If handling health data: HIPAA security risk assessment completed
☐ If processing payments: PCI self-assessment questionnaire completed annually
☐ If storing New Mexico resident data: breach notification procedure is documented
Want a downloadable version? Grab our compliance checklist here.
Pro tip: If you’re not sure whether a regulation applies to your business, assume it does and verify. The cost of finding out you were wrong after an incident is always higher than the cost of a compliance review upfront.
Compliance requirements don’t have a small business carve-out in most cases. HIPAA applies to a two-person medical billing office the same as it does to a hospital system. PCI DSS applies to a boutique retailer the same as it does to a national chain. Size determines the level of scrutiny you’ll face, not whether the rules apply.
Passing an audit or completing a self-assessment doesn’t mean you’re done. Regulations change. Your systems change. Your staff changes. Compliance is an ongoing process, not a checkbox you clear once and forget.
If a vendor has access to your systems or data, their security practices affect your compliance. A breach that originates with a third-party vendor can still create liability for your business. Your cybersecurity posture is only as strong as the weakest link in your vendor chain.
Compliance isn’t just about what you do — it’s about what you can prove you do. Without written policies, audit logs, and documented procedures, you have no way to demonstrate compliance if you’re ever audited or breached. Documentation is what protects you when it counts.
Start with your industry and the type of data you handle. Healthcare, finance, education, and government contracting each carry specific requirements. If you’re unsure, an IT compliance review is the fastest way to find out where you stand.
Consequences vary by regulation but can include fines, mandatory audits, loss of contracts, and in the case of a data breach, significant legal liability. In some industries, non-compliance can also affect your ability to maintain vendor relationships or professional licensing.
They overlap but aren’t identical. Cybersecurity is about protecting your systems from threats. Compliance is about meeting specific regulatory standards — which often include security requirements, but also extend to policies, documentation, and procedures. You can have strong security and still have compliance gaps.
If your business stores personal information about New Mexico residents — names combined with Social Security numbers, financial account numbers, or medical information — yes. The law requires timely notification to affected individuals and, in some cases, the state attorney general if a breach occurs.
Yes. Compliance support is part of what we provide for managed IT clients. We can assess where you stand, identify gaps, and help you implement the technical and procedural changes needed. Contact us to get started.
CEO, LDD Consulting
David founded LDD Consulting in 2003 with a straightforward mission: help small and mid-sized businesses in Albuquerque and across New Mexico get reliable, enterprise-quality IT support without the enterprise price tag. He holds an MBA with a concentration in Information Systems from the University of New Mexico, along with Microsoft Certified Systems Engineer (MCSE) and Microsoft Certified Trainer (MCT) credentials. He’s been solving business technology problems for more than 25 years.