Karen Johnston, Partner, Wipfli Advisory LLC

Karen Johnston, CCSFP, CIA, CISA, CCSFP-CHQP

Partner, Wipfli Advisory LLC

Location
Radnor, PA

Karen Johnston is Wipfli’s national healthtech industry leader. With over 20 years of experience, she works closely with technology companies to drive innovation and improve how her clients get things done. As the leader of our HITRUST, ISO and HIPAA service lines, Karen is also responsible for security and privacy engagements, successfully guiding organizations through their compliance challenges. She believes in fostering collaborative partnerships and the power of meaningful connections.

  • HITRUST assessments
  • ISO 27001, 27701 and 27017
  • SOC 1 and SOC 2 examinations
  • HIPAA risk assessments
  • Internal control assessments
  • Internal audits
  • Information technology (IT) audits
  • IT governance

  • HITRUST Alliance Assessor Council
  • The Institute of Internal Auditors (IIA) - Member
  • Information Systems Audit and Control Association (ISACA) - Member

Bloomsburg University
  • Bachelor of science degree in business administration
Expertise and services

Latest case studies, resources, and insights

  • Stock photograph depicting a professional team meeting in an office environment.

    ARTICLE | TECHNOLOGY INDUSTRY

    A SOC 2 report can be a launching pad for FedRAMP certification

    Learn how a SOC 2 report can accelerate your path to FedRAMP Class A certification and help your cloud solution enter the federal marketplace.

  • Stock image depicting two professionals working at computer stations

    ARTICLE | TECHNOLOGY CONSULTING

    You can now earn a standalone PIMS certification. But should you?

    ISO recently announced that the ISO 27701 data privacy framework now allows for standalone PIMS certification, independent of ISO 27001. Could this make sense for your organization?

  • Female doctor wearing scrubs working on tablet in exam room

    ARTICLE | TECHNOLOGY INDUSTRY

    Automating your SOC 2? Here are 4 frequently asked questions in healthtech

    Governance, risk management and compliance (GRC) tools, SOC 2 reporting, SOC 2 compliance, SOC 2 audit healthtech, Healthtech compliance