Is Your Business Actually Compliant?

A Quick Checklist for New Mexico Companies

By David Luft | CEO, LDD Consulting | MCSE, MCT, MBA | Published July 2026 | 5 min read

Is Your Business Actually Compliant

What IT Compliance Actually Means for Small Businesses

Compliance isn’t just a large-company problem. If your business handles patient health information, processes credit cards, stores employee records, or works with government contracts, there are rules about how that data must be protected — and consequences for not following them.

The challenge for small businesses is that compliance requirements aren’t always clearly communicated. You don’t get a letter in the mail telling you which regulations apply to your industry. Most owners find out about gaps the hard way — during an audit, after a breach, or when a vendor or client asks for documentation you don’t have.

Working with an Albuquerque IT services provider that includes compliance support can help you stay ahead of this, but the first step is understanding what applies to your business in the first place. Our Compliance & Risk Management services are designed specifically to help small and mid-sized businesses in New Mexico navigate this.

Which Regulations Apply to New Mexico Companies

Not every regulation applies to every business. Here’s a quick overview of the most common ones LDD sees affecting small businesses in New Mexico:

HIPAA

If your business is in healthcare — or works with healthcare providers as a vendor — HIPAA requires specific protections for patient data, including access controls, encryption, audit logs, and breach notification procedures. Medical offices, billing services, and healthcare IT vendors all fall under this.

PCI DSS

If you accept credit or debit card payments, you’re required to comply with the Payment Card Industry Data Security Standard. This applies regardless of business size — even a small retail shop or service provider processing cards needs to meet baseline PCI requirements.

FERPA

If your business works with schools or handles student records in any capacity, the Family Educational Rights and Privacy Act governs how that data is stored and shared.

New Mexico Data Breach Notification Act

New Mexico has its own data breach law requiring businesses to notify affected individuals — and in some cases the state attorney general — if personal information is compromised. This applies to any business operating in New Mexico that stores personal data about residents. 

CMMC (for Government Contractors)

If your business works with federal agencies or holds government contracts, the Cybersecurity Maturity Model Certification has become an increasingly important compliance requirement. Even small subcontractors can be affected.

A Practical IT Compliance Checklist

This isn’t exhaustive, but it covers the fundamentals that apply to most small businesses. If you can’t check most of these off, it’s time to have a conversation with your IT provider.

Access Controls

☐ Employees only have access to the systems and data they need for their role

☐ Admin privileges are limited to those who genuinely require them

☐ Former employee accounts are disabled immediately upon departure

☐ Multi-factor authentication (MFA) is enabled on all critical systems

Data Protection

☐ Sensitive data is encrypted — both stored and in transit

Cloud backup is running and tested regularly

☐ You know where your sensitive data lives and who can access it

☐ Personal data is not stored longer than necessary

Network Security

☐ Business network is separated from guest Wi-Fi

☐ Firewall is active and properly configured

☐ All software and operating systems are current on patches and updates

☐ Antivirus/endpoint protection is installed and actively monitored

Policies and Documentation

☐ You have a written acceptable use policy for employees

☐ You have a documented incident response plan

☐ Security awareness training is provided to staff at least annually

☐ Vendor agreements include data handling and security requirements

Industry-Specific

☐ If handling health data: HIPAA security risk assessment completed

☐ If processing payments: PCI self-assessment questionnaire completed annually

☐ If storing New Mexico resident data: breach notification procedure is documented

Want a downloadable version? Grab our compliance checklist here.

Pro tip: If you’re not sure whether a regulation applies to your business, assume it does and verify. The cost of finding out you were wrong after an incident is always higher than the cost of a compliance review upfront.

Common Mistakes Businesses Make

Mistake 1 — Assuming Size Exempts You

Compliance requirements don’t have a small business carve-out in most cases. HIPAA applies to a two-person medical billing office the same as it does to a hospital system. PCI DSS applies to a boutique retailer the same as it does to a national chain. Size determines the level of scrutiny you’ll face, not whether the rules apply.

Mistake 2 — Treating Compliance as a One-Time Project

Passing an audit or completing a self-assessment doesn’t mean you’re done. Regulations change. Your systems change. Your staff changes. Compliance is an ongoing process, not a checkbox you clear once and forget.

Mistake 3 — Overlooking Vendors and Third Parties

If a vendor has access to your systems or data, their security practices affect your compliance. A breach that originates with a third-party vendor can still create liability for your business. Your cybersecurity posture is only as strong as the weakest link in your vendor chain. 

Mistake 4 — No Documentation

Compliance isn’t just about what you do — it’s about what you can prove you do. Without written policies, audit logs, and documented procedures, you have no way to demonstrate compliance if you’re ever audited or breached. Documentation is what protects you when it counts.

Frequently Asked Questions

How do I know which compliance regulations apply to my business?

Start with your industry and the type of data you handle. Healthcare, finance, education, and government contracting each carry specific requirements. If you’re unsure, an IT compliance review is the fastest way to find out where you stand.

What happens if my business isn't compliant?

Consequences vary by regulation but can include fines, mandatory audits, loss of contracts, and in the case of a data breach, significant legal liability. In some industries, non-compliance can also affect your ability to maintain vendor relationships or professional licensing.

Is compliance the same as cybersecurity?

They overlap but aren’t identical. Cybersecurity is about protecting your systems from threats. Compliance is about meeting specific regulatory standards — which often include security requirements, but also extend to policies, documentation, and procedures. You can have strong security and still have compliance gaps.

Does the New Mexico Data Breach Notification Act apply to my business?

If your business stores personal information about New Mexico residents — names combined with Social Security numbers, financial account numbers, or medical information — yes. The law requires timely notification to affected individuals and, in some cases, the state attorney general if a breach occurs.

Can LDD Consulting help us get compliant?

Yes. Compliance support is part of what we provide for managed IT clients. We can assess where you stand, identify gaps, and help you implement the technical and procedural changes needed. Contact us to get started.

David Luft

CEO, LDD Consulting

David founded LDD Consulting in 2003 with a straightforward mission: help small and mid-sized businesses in Albuquerque and across New Mexico get reliable, enterprise-quality IT support without the enterprise price tag. He holds an MBA with a concentration in Information Systems from the University of New Mexico, along with Microsoft Certified Systems Engineer (MCSE) and Microsoft Certified Trainer (MCT) credentials. He’s been solving business technology problems for more than 25 years. 

Linkedin |  Learn More About David