VanRein Compliance Podcast
Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.
VanRein Compliance Podcast
Why We Built Two New HIPAA Certifications
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Two new HIPAA certifications are launching, and we built them for one reason: most “HIPAA training” proves attendance, not capability. We see smart, capable people get handed the compliance binder and suddenly they are the privacy officer, security lead, or HIPAA compliance officer with real legal and operational responsibility. That is a risky place to be for you and for your organization, especially when auditors expect evidence, not intentions.
We walk through our new professional credentials, Certified HIPAA Privacy Associate and Certified HIPAA Compliance Officer, and explain exactly who each path fits. The Privacy Associate track is for healthcare professionals and business associates who need practical HIPAA knowledge to make good decisions, spot problems early, and escalate issues correctly. The Compliance Officer track goes deeper into running a HIPAA compliance program: risk analysis methodology, breach response, policy ownership, training oversight, corrective action plans, and how to show proof during an audit.
We also dig into the modern reality of HIPAA compliance: vendor sprawl, downstream subcontractors, and AI in healthcare. If your team is connecting tools, experimenting with public AI, or relying on “my IT vendor handles it,” you need stronger governance, clearer questions, and better documentation. If you want credible HIPAA certification that supports audit readiness, risk management, and career growth, this is your roadmap.
Subscribe for more practical compliance guidance, share this with the person who just got assigned HIPAA, and leave a review with the question you want us to tackle next.
Thank You for Listening to the VRC Podcast!
Visit us at VanRein Compliance
You can Book a 15min Call with a Guide
Follow us on LinkedIn
Follow us on X
Follow us on Facebook
Welcome And Two New HIPAA Certifications
RobWelcome to the Van Rien Compliance Podcast with Rob and Dawn. We help growing teams reduce risks, build trust, and stay audit ready without the overwhelm. Welcome back to the Van Rien Compliance Podcast. I'm Rob.
DawnAnd I'm Dawn.
RobHey, Dawn. This is an exciting day for us, the first week of August, and we have two new amazing products.
DawnYes, we do. Yes, we do. We're officially launching not just one, but two new professional HIPAA certifications from Van Rien Compliance, not training. We're offering the Certified HIPAA privacy associate and the Certified HIPAA compliance officer.
RobBoom.
DawnYes.
RobNot just one, but two. And these are not simply training courses that hand you a certificate of completion at the end. Anyone can give you a certificate of completion, right? We have some of that training today. Watch a few videos, you click through some slides, you answer a handful of basic questions, and boom, you get a PDF. No, this is not that type of training. This is something that we've put together and curated so it's perfected to the point where it is a true certification taught by us, taught by other years of knowledge that Van Rien has on how you can show your dedication to HIPAA compliance.
DawnCorrect. And our goal was to create something more meaningful, a professional credential that demonstrates real working knowledge, a credential healthcare professionals can use to strengthen their careers. A credential compliance officers can point to when they're speaking with leadership, responding to auditors, evaluating risk, or managing an organization's HIPAA program.
RobAnd when someone successfully earns one of these certifications, they will receive more than a completion document. They will receive a professional certificate, a digital credential badge that they can add to the LinkedIn, to their resume, professional profiles, email signatures, and social media.
DawnYep. Because if you put in the work to earn a professional certification, you should have a credible invisible way to demonstrate that achievement and show what you've done.
unknownYep.
RobAnd organizations achieve compliance, professionals get certified, and now professionals can prove what they know. And we're very excited about this. Yes. So
The Gap Between Training And Competency
Robso Dawn, let's kind of talk about why. Why did we create here at Van Rien these certifications? HIPAA training has been around for a long time, as we know. Organizations have been required to train their workforce for decades. So why do we believe the industry needs something new?
DawnThe biggest reason is there's an enormous difference between basic workforce training and professional level HIPAA knowledge. Most workforce training is designed to answer questions such as what is PHI, protected health information, what should I do if I send it to the wrong person? Yeah. How do I report a possible incident? When should I avoid discussing patient information? That training's important. Every work member needs to know it, it's their fundamentals of HIPAA, but that's not enough for someone who's responsible for actually managing HIPAA compliance and especially implementing HIPAA compliance in their organization.
RobYep. That's exactly right, Dawn. And there's, and this is something we've been really striving towards of Anne Rien, is just make me elevate the brand, elevate user clients, and create that that certification program. There is a big difference between teaching someone not to just leave PHI or sitting around or putting it into an AI platform or putting it into documents or texting it. It's really about how do you understand how to conduct a risk analysis? How do you understand and investigate an incident, review business associate uh relationships, interpret the minimum necessary standard or prepare for an audit? These are the questions we get a lot. So we're like, why don't we teach and train our customers and everybody on how to handle all this?
DawnAbsolutely. And we keep seeing professionals placed into compliance roles without enough preparation. Many times we've gotten a call where someone says, I'm new to this company. They told me, hey, you're going to be the compliance officer. How do I do this? So someone could be, or someone could be a practice manager, an operations director, human resources leader, IT manager, or office administration. And like I said, then one day they say, you're also going to be the compliance officer. And then they're like, what is this? How do I do this? Van Rijn, help train me. And that's that's usually the conversation that that we have with them.
RobYeah, they usually just throw you the binder, throw you the book and go, oh, well, compliance just ends up in HR or it ends up in financials. And you want to be doing financial work or HR work and not the compliance piece, but their training or certification training will give you what you need to uh to handle this correctly in your role.
DawnMm-hmm. Absolutely. They may be highly capable professionals. They probably are, but HIPAA compliance is a specialized responsibility. And it's not just, oh, create a policy or oh, do this or make sure everyone did their training. There's more to it. They're expected to understand privacy, security, breach response, policies, training, vendors, documentation, investigations, and regulatory expectations. They may also be expected to answer questions that they get from patients, employees, executives, legal counsel, insurance carriers, auditors, and technology vendors. And also, especially if it's like, you know, there is an issue, they are expected to know the answer. So this is a significant responsibility.
unknownYep.
RobAnd too often only preparation they receive is some annual training, or here's some slides, or here's some information. And that's not really fair to compliance officers that have a legal responsibility, not to the state, not just to state or federal levels, but to the business and also to the American citizens that entrust you to your patients that entrust you to handle that data or your customers that entrust you to handle that data. And it's not fair to that organization because we really want to make sure that we give professionals that structured path to build genuine knowledge and then demonstrate the knowledge through meaningful certification. So that's why we built two brand new certified training modules.
DawnCorrect.
RobYep.
Completion Certificates Vs True Credentials
RobSo should we dive a little bit, Dawn, and kind of dive into the certification of completion versus professional certification? Yes, let's do it. Let's do it. So a certificate of completion generally means that someone completed an educational activity, right? They entitled they attended a webinar, they took our general HIPAA compliance training, they finished an outline of course, and they could absolutely show the value and they've done that. But the certificate primarily approves participation or completion.
DawnThat's correct. And then conversely, a professional certification is different. A certification is intended to validate knowledge or competency against a defined body of information. It should require more than simply opening a course and clicking next. There should be a meaningful education, an assessment of knowledge, and a standard the professional must meet. Now, just so you know, our HIPAA training that we currently have is very robust. We have always elevated our training. It's not a quick fundamental, it is more robust. This is the next level. This is a true certification module. So I don't want to belittle the HIPAA training that our customers and potential customers are currently taking, but this is a true certification. So I just want to make that distinction.
RobIt's very, very clear distinctions between the two. And it and we're that's what's exciting about it, is it makes sure that everybody knows the difference in the certification and the regular, regular training. We issue those certificate of completions for many types of workforce education because they document require training or check the box. And everybody that works with us, we know we don't just want to do check the box compliance. We want you to know, we want you to understand, we want to teach you, we want to educate you and make you the best you can. When someone represents themselves as certified HIPAA professional, the credentials should mean something more.
DawnYeah. And they should be able to shout it out loud, you know, and put it out there to all their professional organizations, their their certific certificate. And the certification should indicate the person studied the subject in depth, completed a comprehensive curriculum, passed an examination, demonstrate an understanding of how HIPAA operates in the real world.
RobYeah, and once they've earned that certification, they should be able to display it professionally. This is the exciting piece of this. Our team has worked extremely hard for you to be able to take the training, to get the certificate, the actual certification, and show that in a formal certificate and a digital badge you can share on LinkedIn, in your resumes, include your email signatures, or display across professional social profiles. There's also something you can put in your reviews with your management or your team, right? You can say, hey, I took this three-hour course, and yeah, it is, it's a full course. I am now a certified HIPAA compliance officer or a HIPAA certified professional. So then I can I can bargain. I can bargain for additional cash or different additional money, right? But also look at what I've done to invest in myself that also invests in the company.
DawnYeah. Yeah. And you know, this certificate documents the achievement. Uh the digital badge helps communicate it. Together, they give professionals a tangible, visible way to show employers, clients, colleagues, and leadership teams what they've learned. So it it's that it's that add value of showing that this is an actual certification, that they took this course. Um, and it's a longer course than half an hour.
RobIt is. And and what we really wanted to show is we want you as the professional to be able to walk in any leadership meeting, speak to any auditors, even speak to the OCR, attorneys to whoever, and make sure you know how to have those conversations. Make sure that you know how to deal with a breach or an incident, and that certificate is carries that credibility so that you can stand out and uh in the crowd, right? And you know what you've actually built.
What The Privacy Associate Covers
DawnSo let's dive into Rob, the both the courses. Okay. Um let's take the let's talk about first the certified HIPAA privacy associate and what this means and what this is about.
RobOkay. Well, let's do it. The Certified Privacy Associate designed for healthcare professionals who need a strong practical understanding of HIPAA. Now, that could be in healthcare as a clinician, right? Or it also can be someone that is in technology, someone that is in an answering service, someone's in a SaaS environment, someone's in an AI environment, any business associates. It covers both. Uh, may include practice managers, administrators, department leads, IT professionals. Uh, we even have some healthcare consultants that worked with us that take our training, but also valuable professionals uh working for business associates that create, receive, maintain, or transmit protective health information. We have a lot more of those than we do traditional medical practices. This is someone who uh who may not be the person ultimately responsible for the entire HIPAA program, but maybe as an administrator or an advisor, that is that's an important part of their job, that HIPAA is a piece of it. And it's a lot, it's bigger than you think. It's HIPAA is kind of sprinkled everywhere. Uh, they need to understand the rules well enough to make good decisions, recognize risks, answer questions, and escalate those concerns appropriately.
DawnRight. And the course goes far beyond the basic definition of protected health information. Participants learn how the privacy rule works in practice. They learn when information when information may be used or disclosed. They learn about patient rights, authorization, uh, authorizations, minimum necessary requirements, documentation, workforce responsibilities, and the role of business associates.
RobThey also dive into the security role, which we're excited about. I'm hoping this fall will get revised and updated. It's been a while, right? This is an important point because privacy and security cannot be treated as completely separate worlds. It's all one. A professional may understand that information should remain confidential, but they also need to understand how administrative, physical, physical, and technical safeguards protect electronic protected health information.
DawnRight. And they need to understand why access controls matter, what unique user accounts matter, why passwords and multi-factor authentication matter, why risk analysis matters, why devices, systems, vendors, and data transmission methods create compliance risk. And this is not just, oh, my IT vendor knows this. I don't need to know this. We hear that a lot. Yep. Uh no, you need to know it. You need to know how your organization is set up, how your access controls are set up. And if you don't know, you need to get with your IT vendor and you need to understand how it all works. Because when you go through an audit, you're going to need these items, and your IT vendor may not always be there to help you. You know, they may be assisting others, and so you need to know that. Yeah.
RobAnd we also dive into that breach notification. We'll get a lot of questions like this. We'll get like incidents that'll happen. Maybe there was an IT incident, maybe there was a physical paper incident, maybe there was a change to regulation and become an incident. Um, you need to understand what that what difference between incident and breach, and understand how to handle that and what do you, what do you do with that? And how do you how do you report that as needed, right? And how do you what are the what are the proper channels? Because there's not only reporting to the state or federal governments and to the patients impacted, but also there's media and then to the board or the owners of the business. And you need to understand how to work through those those channels properly. And this is what this certification program is going to do. It's going to really focus on taking understanding that all potential incidents need to be taken seriously, investigate those, and uh, and document everything.
DawnAaron Powell And the Certified HIPAA Privacy Associate is about building a strong foundation. It gives professionals the ability to participate intelligently in HIPAA compliance rather than simply memorizing a few definitions.
RobYes. And it's not check the box. So that's a great training. I'm really excited about that one. The next one
What Compliance Officers Must Prove
Robwe we worked on is pushing almost up to that four-hour mark because we know that compliance officers have a lot of responsibility. And so this is why we have created our certified HIPAA compliance officer education and credentials. This is a more advanced credential. So we go from one we just discussed about the privacy officer into the actual compliance officer.
DawnYep. And the certified HIPAA compliance officer is designed for the professionals leading the HIPAA program. So these are people managing risk, overseeing policies, coordinating the training, uh, responding to incidents, reviewing vendors, answering leadership questions, and preparing for audits.
RobAudit, audit, audit. That's what we do all year long. It's attended for those privacy officers and security and compliance officers, risk managers, operations leaders, consultants, supervisors, anybody that has a leadership responsibility in your organization for HIPAA and even data security oversight.
DawnAnd the compliance officer must understand the rules, but they also need to know how to operate a compliance program. They know how to, they need to know how to implement it into their organization. This includes identifying risks, documenting decisions, assigning responsibilities, maintaining the policies, tracking corrective actions, and showing the organization is actively managing the compliance.
RobYeah. The big thing is how to implement. We see, we see a lot of organizations were really good at writing the policy, creating the procedures, but actually, are you doing the work? Do you actually implement this in your environment and making sure that things are working as well? Because it's not just about having those policies, it's about being able to demonstrate with evidence in hand that those policies are implemented. Right.
DawnAnd the auditor is not only going to ask you whether you have an incident policy. They may ask, when was it last reviewed? Who's responsible for it? How are incidents reported? Can you show us an incident log? Can you show us an investigation? Can you show us the corrective action that followed? Yeah, they're going to ask you that and more. Yep.
RobYep. And then they're going to go away for about a month and figure out the next questions and they're going to ask you another set of questions. Then they're going to go away for another month and they're going to come back because we've done this. We know this. And it really focuses on that risk analysis and how many times have you gone through it, right? Have you done it annually? Have you done it by what's required by law every time there's a major upgrade or change in your environment? Can you understand that methodology? And this is what our certification program does is it helps you educate yourself and understand the methodology so that you can ensure that you know which systems are connected to who and what data is being included, what data is being excluded. Verify those threats and vulnerabilities and look at the risk levels and show what did you do with the findings? You know, it's kind of the caps, right? Corrective action plans. You know, when we do the when we do our audits and we go through and you have remediation plan, it's like, what do you do with that? Other, you know, hit high trust likes to call it caps, corrective action plans. What are you doing? You identified this issue. How did you resolve it? And then we come back and around and audit again. We've got to make sure, have you done what you're supposed to do?
DawnYep. And that's a level of thinking that we want certified compliance officers to develop, that level. Not just, I know HIPAA requires a risk analysis, but I understand how risk analysis fits in the overall compliance program and how to evaluate the results and how to move the organization forward.
RobThat's the key piece is the compliance officer certification goes deeper into those business associate management as well. BAs are a big threat, meaning the threat is you don't have them. They're not updated. You haven't you don't have signatures on them. You've gone for years without a BA. And from a legal perspective, the way that the way the law is written, you cannot you cannot work with the client and or engage in that PHI or your PHI without a BA in fr in place first. We love to just get things going and then do documentation. It all needs to be done right up front because handling a business uh associate agreement is not just the end of the vendor oversight. It's kind of really the beginning.
DawnAnd a signed BA, it's important. It's required, but it doesn't answer every question. Uh vendor management is a big one that is missed. My IT guy signed my BA, so I'm good, right? Well, did you check to see if he is uh he has any sort of security, data security measures on his end? See, these are all the things that that you need to do. Um, what information does he access? How is it stored? Who can access it? Do they use any subcontractors? How are instance reported? How does the vendor return or destroy information? What happens if the relationship ends? You get a new IT guy. Where's all your data? So, like I said, that BAA is great, that that's their responsibility, your responsibility, but it doesn't answer any of these questions.
RobYep. And the biggest risk to your business that we're seeing, and we see this with our clients, is a third and fourth party, fifth and sixth party downstream suppliers. You may work with that IT company, right? Or you may even work with Amazon or a client that says they've got AWS or even Azure in the back end. But have they also connected additional AI platforms? Do they have other platforms that they're using that that that the data has gone from you to your to your uh business associate or client and then going two, three, four, five layers deeper because the it just has exploded with AI. Everybody's plugging in everything. And this is gonna help you be able to ask better questions, the certification training, and lead to better decisions. Those are the key pieces.
DawnSo let's
Curriculum Built For Real Audits
Dawndive into the curriculum of these courses. I'm gonna go a little granular here.
RobLet's do it. So at a high level, the curriculum includes HIPAA privacy rule, the HIPAA security rule, the breach notification rule, and responsibilities covered to entities and business associates are required to adhere to.
DawnBut it also includes patient rights, permitted use and disclosures, authorization requirements, minimum necessary standards, workforce access, sanctions, instant response, breach analysis, documentation, and training responsibilities.
unknownYep.
RobRemember, it's your health information. It's your, it's it's yours. It's nobody else's. So we have to make sure that on the security side that we address those, you know, from administrative the physical and those technical safeguards, we cover the risk analysis and the risk management. That's part of the curriculum. Access controls and authorization are also big. But the biggest things I'm seeing now is that contingency planning, right? Do we know what we're gonna do when something goes down? Or like last week, when T-Mobile goes down, what do we do? When Verizon has issues, right? When AWS or Azure or your platforms or your internet goes down, what are we gonna do? And what does that risk look like to the business?
DawnWe also address the operational side of compliance, how to build and maintain a compliance program, how to assign responsibilities, how to manage the documentation, review and update policies, prepare for an audit, and respond when something's going wrong.
RobYep. And we didn't want to just create a certification based only on risks to healthcare organizations faced 10 faced uh 10 years ago or two years ago or last year. This is current. You know, healthcare has changed, technology has changed, AI changes by the minute, and information is changing now as we're even recording this podcast. So this is current to date education and certification that you'll be able to take and really educate yourself.
AI Governance And New Tech Risks
DawnSo what this means is what Rob was saying is the curriculum also addresses emerging risks, and that includes AI and healthcare.
RobYep. The bots. The bots are here. And speaking of AI, that is probably the largest risk to healthcare, not only just healthcare, but also even financials in your business, right? It is the biggest risk, and this is kind of an area that we really expanded upon in both of the education and certification modules, is because healthcare organizations where everybody's using AI for documentation and transcripts, analyzing recordings, communications, analytics, scheduling, and administrative work. And employees are experimenting with publicly available AI tools. You may say we're just going to approve copilot or Gemini or Claude. Or GBT for our environment. Well, if there's restrictions around GBT, who says your um your team is not using their own devices working remotely, or if you're there, how are you gonna how are you gonna control that? What is your AI policy? And we're really gonna dive into that so people know what uh what to do with AI and how you can educate yourself on that.
DawnAnd how many organizations, uh, you know, and many organizations do not have a complete inventory of where AI is being used. Right now, you could go into an application, it says, oh, connect this, it'll make it easy. Okay, I'm gonna click on that, click on that, connect, connect, connect. And before the end of the day, you have so much connected to so many AI, you have no idea where your data is going at all. And again, this the the vendor risk is is huge here if you don't know. So you may not know what it what employees are entering in the systems. That's the thing, is so so there's no guardrails, there's no policies, procedures, you know, AI governance for these types of AI modules. Um they, you know, you may not know where the vendor retains the data, where that what they use it for. Are they a business associate? Did will they sign a business associate? And you know, and this doesn't include, like Rob said, you know, an an employee, just, oh, I'll just go quick on Chat GBT on my phone and just ask it the question. Yep. So that this is this is this is where we are today.
RobYeah. And and you as a a certified compliance professional, you need to know how to evaluate the use cases. You know, so when you have someone, we have a lot of this where like maybe finance or clinical or IT or uh one of your leaders read uh something on a flight and says, oh, we got to do this now, especially financials. We're seeing a lot of that, is um you need to ask yourself what information is involved? What is if if there is protective information, what's being entered, who has it, what vendors have it, do we have that BA in place? Do we have those security controls? Do we have human review required, right? Do we have that human in the middle that we've always talked about here at Van Rijn? And this is in this is in the curriculum. This is what you're gonna learn. They're gonna learn how to ask these questions, right? And go through that. And this is really the big difference, Dawn, between going through the check the box, which we don't like. We want to actually teach and educate. You want to have a leading compliance program. So a compliance officer does not know or not need to be a software engineer. He or she needs to understand the questions to ask. But they do need enough knowledge to identify the right questions, involve the right people, and document the right organization's decisions.
DawnAnd the same is true for cloud applications, mobile devices, remote work, messaging platforms, connected systems, and third-party vendors. HIPAA principles remain consistent, but the environment in which those principles are applied continue to change. Like I said, with all the AI integrations and, you know, integrations of everything, not just AI, just multiple integrations into software, you can integrate almost anything now.
Why Certification Helps Organizations
RobSo now we've we've talked a lot about the value for the individual professional, but what about the value for the organization, Dawn? What's, you know, when a when an organization says, I'm going to pay $99 USD so that Steve can take training or Tiffany can take training and get certified, what's the value back to the organization?
DawnRight. So organizations frequently tell us that they're unsure whether the person assigned to HIPAA compliance has received enough education. You know, they're coming from, you know, IT, they're coming from HR, whatever, wherever they're coming from in the organization. Yeah. They may have appointed someone because the regulations require a designated privacy or security uh responsibility, but designation alone does not create competency.
unknownYep.
DawnAnd that's where we come in.
RobThat's where we come in. That's the big piece. The title does not just create the compliance program, right? Um, you actually need that true certification.
DawnYep. And by supporting um professional certification, the organization is investing in the person responsible for protecting patient information and managing regulatory risk. That investment can improve decision making, documentation, accountability, and audit readiness. I used to be in financial services and I had to get financial certifications. And there was a long test, there was the four-hour class, there was all this stuff. And that is along these same lines. Financial information is behind is next in line to the most highly regulated industry behind healthcare. Why wouldn't you get a certification based, you know, be when you're going to be a compliance officer? You know, don't just add it as a duty to what you have to do. You you need to know what it what it means to be a compliance officer. You need to be up for that role. And this certification will help you with that.
RobYep, that's key. And it really shows consistency in the organization. When it's multiple members of compliance teams complete the certification, they begin working with the same foundation. So we are here to give you the foundation so that you can put in your organization and you can build upon that. So everybody's thinking the same way. Uh you can understand the same core expectations, you can have that. And then it also expands the community how to communicate more effectively across privacy, security, operations, legal, HR and executive leadership. It touches all of that.
DawnYep. It also helps organizations demonstrate they look uh they took a reason reasonable steps to prepare the professionals responsible for compliance. Training doesn't eliminate risk. It doesn't guarantee an incident will never happen, but it can show the organization took compliance responsibility seriously and invested in qualified leadership.
RobYep. And so when an auditor, when you go through our audit or or internal audits, they're going to ask you what education has your compliance officer received? And your organization can say we're certified by Van Rien compliance to go through this and understand it. Those are the key pieces. So
Career Credibility And Which Path Fits
Robwhy now does it does this really matter to professionals, right? Um let's kind of dive into the professional side. Why should someone pursue one of these certifications, Dawn?
DawnWell, first of all, it builds confidence in the person. If they come into this and they're like, I have no idea what compliance even means, let alone HIPAA. You know, it can be intimidating. HIPAA can definitely be intimidating. Uh first of all, people typically don't know how to spell it. It's two A's, not two P's. It's not a answer questions, you know, you know, uh they're just because they know they're expected to answer certain questions. The certification program gives them a structured understanding of the regulations and how these regulations apply operationally and then how to answer some of these questions.
RobYeah. It adds that professional credibility that you really are looking for. Um, not just to HIPAA training, but you're a certified HIPAA professional. Uh the person may already be doing the work, right? There may be have multiple years of experience. But have you demonstrated that? Do you have an actual certification that states that you are knowledgeable in HIPAA and everything that entails?
DawnMm-hmm. Yep. And it shouldn't it the credibility, you know, shouldn't remain hidden inside a learning platform. You know, upon successfully earning the certification, the professional will receive a formal certificate and a professional digital badge they can add to LinkedIn, the resume, email signature, social media, and other professional profiles that says, hey, I've earned this certification. I took the time to earn this and I'm proud of it.
unknownYep.
RobIt gives an invisible way to communicate what you've achieved, right? Hiring managers, clients can see it. So when clients are doing prospectus and looking at your company, looking at you as an auditor, they can say, oh, you you have credentials. You know what you're doing. You have a leadership team can see it. And professionally, you elevate yourself, right? With this certification, you elevate your knowledge and you you're elevate your marketability as well.
DawnAnd it can support career development. Um, healthcare compliance continues to grow in importance, and organizations are looking for professionals who understand regulatory requirements and can translate those requirements into practical business processes.
RobYep. And the ability to value can valuably uh go well beyond just a single job title. You know, the practice manager with a strong hip and knowledge becomes more valuable. You show your certifications and it basically will make you a more valuable person. The IT leaders, the consultants, the compliance officers, you're in this space, this certification will elevate your knowledge, and well, you can actually charge more, right? Because you have the knowledge. And it's not just because you have the badge, but you actually have the knowledge to help to help yourself become more educated.
DawnAnd it gives a professional something tangible to show that they've invested in their learning. They're just not saying, Oh, yeah, I took some courses. They can say I completed a comprehensive professional certification that demonstrates my knowledge and I earn the credential for it.
RobSo now let's make it practical, Dawn. All right. So we've talked about what it is and everything. What does it really look like? How should someone decide what certification is right for them?
DawnSo the certified HIPAA privacy associate is the best place to start for professionals who rarely work with HIPAA requirements, but they aren't solely responsible for the entire compliance program. So this is this could be department leaders, managers, office managers, billing managers, human resources, IT consultants, trainers, or members of the of the privacy or compliance team.
RobYep. It also is a strong option for someone who wants to move into healthcare compliance and needs a build a credible foundation.
DawnRight. So then the certified HIPAA compliance officer, this one's intended for professionals uh that are with direct responsibility for leading, uh overseeing, and advising on a compliance program. Um, this includes privacy officers, security officers, compliance officers, risk managers, senior operational leaders, compliance consultants, and others who are expected to make or guide compliance decisions.
RobYeah, and some professionals may begin with the privacy associate certification and later move into the compliance officer certification as responsibility grows. And this fall, we're gonna have additional certifications. So you can almost have that trieffective compliance, right?
DawnYep. Yep. And some experienced professionals may be ready to begin right away with the compliance officer program, but just depends on their role experience and their level responsibility.
What Makes Van Ryan Different
unknownYep.
RobAnd what makes Van Rien's approach different is this you know, there are HIPAA courses available. So let's talk about what makes our approach different. Um, the first difference is the depth. These programs are not designed for quick annual training. They have comprehensive professional level education and training. And secondly, they are practical. We do not want professionals to simply memorize regulatory language. We want them to understand how HIPAA decisions are made inside real organizations.
DawnAnd this means connecting the regulations to actual responsibilities. So policies, risk assessments, training, investigations, vendor management, corrective actions, documentation, and audit response, and leadership reporting. Yeah.
RobAnd lastly, the certifications reflect the work we perform every day. Uh Veteran Compliance works directly with healthcare providers, BRIS business associates, technology organizations, compliance teams, folks in the TAS industry, and we see where organizations struggle. We know what the auditors ask. We see what policies fail to match operations, and we see how new technology creates that unexpected risk.
DawnAnd that real world experience shaped the curriculum when we created it. The courses are built to help professionals operate in a real world, not just simply pass a test with fundamentals. What is what does PHI stand for?
RobYeah, we believe it compliance education should be understandable. HIPAA is serious. It comes with it's a law. There are fines, and you will pay from an organizational standpoint, and you can personally be liable as well. That's the high-tech regulations. It really is serious.
unknownYep.
DawnAnd our goal is to explain the complex requirements clearly while respecting the depth and importance of the subject, because it is a required law and it needs to be, it needs to be followed.
RobYep. So, you know, Dawn, we've gone through all of these steps and everything. So
Launch Details And How To Enroll
Robwhy don't we talk about the launch, right? How we're going to go ahead and launch these. So we've talked about right to the direction of our leaders and right to the direction of our compliance officers, but we're excited to go ahead and launch this. So this week, we will be launching the new training on RLMS. I think it's going to be Tuesday, the fourth, and Wednesday, the 5th. And we're going to broadcast that out so people know that you will can take an or certification training and you can understand what that looks like. You're going to receive that comprehensive in-depth HIPAA education designed around real professional responsibilities and complete the required curriculum to demonstrate their knowledge through certification process. Really excited about that.
DawnYep. And whether you're entering into healthcare compliance, expanding your current responsibilities, leading an established HIPAA program, or building the next generation of compliance leadership with your organization, there is now a clear path forward. And these certifications are it.
RobYep. Yep. And once again, it can be added to your your certification, be added to your LinkedIn profile. You share on social media, you include an email signature, and you're able to go ahead and bring that forward. So your call to action here is to get the certification, is to get the training, right? So we're going to launch it this week. We're going to do a soft launch this week. Never know. There may be some coupons out there to get things going. Juni's got some get some coupons up his sleeve and put things out. But we're excited to launch this because we know it's a first in the industry and we know how much important it is to make sure that you know how to do your job correctly and be prepared for that.
unknownYep.
DawnWe are excited. So look look for our launch information out on social media in our newsletter. Hopefully, after you listen to this podcast, go to vanrancomples.com and go and buy the buy the certification. And you will be you'll be happy that you did. And um would love any feedback that you have after you take the course. But this is uh really, really exciting for us. We're just really taking, we're just blowing up, we're just blowing up HIPAA, right? We're just making it yeah, we're just making making it huge now. So Yep.
RobYep, making it huge. We'll have the links here in the podcast. We'll also have the links to uh the new certification in our newsletter and on our website in the information to go out. So this is very exciting, Dawn. I'm really excited to get this rolled out. I know you are as well, and I know listeners will see a lot of value in our certification programs.
DawnYep. Absolutely.
Final Thoughts And Sign Off
RobAll right. All right, until next week. Have a good one. Bye bye.