Drummond Group, LLC
Healthcare compliance testing, certification, and cybersecurity audit services
About Drummond Group, LLC
Drummond Group is a specialized compliance, certification, and security assessment firm serving the healthcare and B2B technology sectors for over 25 years. The company operates as an ONC-Authorized Certification Body (ACB), PCI Quality Security Assessor (QSA), and DEA EPCS Approved Auditor, providing third-party validation services for health IT developers and healthcare organizations.
The firm's core capabilities center on regulatory compliance testing and certification, including ONC Health IT certification, HIPAA gap assessments, DEA EPCS certification, PCI DSS audits, and FHIR interoperability testing. Drummond also provides SOC 2 and ISO 27001 audit services, AS2 B2B certification, and supply chain interoperability testing. The company positions itself as having conducted more ONC Health IT certifications than all other ACBs combined.
Drummond serves health IT software vendors, EHR developers, digital health companies, and healthcare organizations requiring regulatory compliance validation. The company recently expanded its cybersecurity portfolio with SOC 2 audit services and offers bundled compliance packages including HIPAA validation and FHIR interoperability testing memberships.
Best For
Health IT software developers and digital health companies requiring ONC certification, EPCS certification, or HIPAA validation. Organizations seeking PCI DSS compliance audits or FHIR interoperability testing. B2B technology providers needing AS2 certification for supply chain interoperability. Healthcare entities requiring third-party security assessments including SOC 2 or ISO 27001 audits.
Key Strengths
- Leading ONC-ACB with the largest volume of Health IT certifications in the industry, demonstrating deep regulatory expertise
- Multi-domain certification authority covering ONC, EPCS, PCI, HIPAA, SOC 2, and ISO 27001 under one provider
- 25-year track record specifically in healthcare compliance and interoperability standards
- Approved auditor status with DEA for EPCS certification and PCI Security Standards Council QSA designation
- Proprietary web-based testing tools and script-based certification processes for efficiency
- Bundled service offerings combining multiple compliance assessments with cost savings
Why Choose Drummond Group, LLC
Organizations should consider Drummond when they need authoritative third-party certification for regulatory compliance in healthcare IT. The firm's status as a leading ONC-ACB and approved auditor for multiple regulatory frameworks provides credibility and market recognition for certified products. Companies pursuing ONC Health IT certification, EPCS compliance, or PCI DSS validation will benefit from Drummond's specialized expertise and established processes.
Expect a structured, audit-focused engagement with script-based testing methodologies and comprehensive documentation. The firm emphasizes thorough examination against conformance criteria with weekly touchpoints and clear timelines, suitable for organizations with internal resources to address identified gaps.
Healthcare Focus
Drummond specializes exclusively in healthcare IT compliance and adjacent regulated industries. The company's healthcare services span ONC Health IT certification for ambulatory and inpatient EHR systems, DEA EPCS certification for e-prescribing controlled substances, HIPAA security and privacy assessments, and FHIR interoperability testing. They maintain expertise in healthcare-specific regulations including the ONC HTI-4 certification for prior authorization and emerging SCRIPT standards for e-prescribing.
The firm has completed thousands of ONC certifications, HIPAA assessments, and EPCS certifications specifically for healthcare technology providers. Their FHIRplace membership program and FHIR interoperability testing demonstrate ongoing investment in healthcare data exchange standards.
Ideal Client Profile
Health IT software vendors and digital health companies developing EHR systems, e-prescribing solutions, patient portals, or FHIR-based applications who require regulatory certification for market access. Mid-size to enterprise healthcare organizations needing third-party validation of HIPAA compliance, PCI DSS adherence, or cybersecurity controls. B2B technology providers in healthcare supply chain requiring AS2 or EDI interoperability certification.
Specializations
Client Types
Why Choose Drummond Group, LLC?
- 27+ years of industry experience
- 51-200 team members
- 6 certifications verified
- Elite Partner on Curatrix
- Verified on Curatrix
Quick Facts
- Category
- Healthcare QA Testing Companies
- Headquarters
- United States
- Founded
- 1999
- Company Size
- 51-200 employees
Certifications
Profile last updated: Jan 25, 2026
Need help evaluating healthcare partners?
Our team can help you find the right provider for your specific needs.
Similar Providers Other Healthcare Quality Assurance
Looking for similar providers? Looking for Healthcare Quality Assurance?
Browse our curated directory of pre-vetted healthcare B2B service providers.