VanRein Compliance Podcast
Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.
VanRein Compliance Podcast
The Compliance Landscape: 26 Years of Change
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The compliance landscape has changed more in the last 26 years than most leaders want to admit and somehow the basics still win. We connect the dots between real-world HIPAA enforcement and what actually holds up when something goes wrong: evidence. Not a binder. Not a trust center page. Proof that you know your systems, control access, manage vendors, and can recover fast.
We start with the HIPAA Security Rule and why its administrative, physical, and technical safeguards still define the floor for protecting ePHI. Then we unpack the 2013 Omnibus Rule and the moment business associates stop being “adjacent” to HIPAA and become directly accountable. We clarify covered entity vs business associate, why incidental contact still counts, and how to use business associate agreements the right way without stuffing them full of unrelated cybersecurity obligations.
From there we look forward to HHS’s proposed HIPAA Security Rule rewrite and the themes leaders should already be planning around: multi-factor authentication, encryption, asset inventories, network maps and data flows, vulnerability scanning, penetration testing, stronger recovery expectations, and heavier documentation. To make it real, we pull up the HIPAA Wall of Shame and talk through the patterns that keep showing up: hacking, email compromise, and exposed servers impacting organizations of every size.
We close with what to do now: name an owner, build a repeatable rhythm, tighten access control and third party oversight, add AI guardrails to policies, and test backups and incident response until you can prove it works. Subscribe for updates on what HHS announces next, share this with the person who owns compliance at your company, and leave a review with your biggest HIPAA challenge so we can tackle it next.
Thank You for Listening to the VRC Podcast!
Visit us at VanRein Compliance
You can Book a 15min Call with a Guide
Follow us on LinkedIn
Follow us on X
Follow us on Facebook
Why 26 Years Matters
RobLast week, Don and I talked about 26 years of marriage. And to let all listeners know, we're still married. We made it an actual 26 years in a week so far. Right?
SPEAKER_01Yes, correct.
RobShe's like, yeah. A little bit of a pause there, Don. We dove into life, leadership, and legacy. And this week want to dive a little deeper into the number 26. But we're looking at it through a very different lens, aren't we, Dawn?
DawnYes, we are.
RobWe talked about last week about 26 years of being together. And this week we want to talk about 26 years of how the compliance landscape has changed literally, but underneath all of us. The technology has changed, the threats have changed, the rule books changed, but one thing hasn't changed is proof and evidence still beats a binder and your little trust center, doesn't it?
DawnCorrect. Every time.
SPEAKER_00Welcome to the Van Ryan Compliance Podcast with Rob and Dawn. We help growing teams reduce risks, build trust, and stay audit ready without the overwhelm. I'm Rob.
DawnAnd I'm Dawn.
RobAnd if you're new here, we're a husband and wife team, business partners, and founders of Van Ryan Compliance. And today we're going to walk you through the actual changes in compliance, what really hasn't, what has and has not changed, and what leaders should be doing right now. Correct. So welcome, Dawn. Yes. How's the first how's the first 26 years been?
SPEAKER_03Wonderful. It's just like yesterday. There it is. Yeah, just like yesterday. Yep. Still going. Exactly.
RobOh, well, why don't we talk about the landscape, right? So uh what's really changed? Not about a headline, not about the stuff that that does or doesn't matter, but let's kind of start at the floor.
HIPAA Security Rule Basics
RobLet's go way back to the HIPAA, as I like to call it, because it's the only law. The only law. Nothing else is a law.
SPEAKER_03It is.
RobBut it's the only law, and the HIPAA security rule was published in 2003. It's been a it's getting aged.
DawnIt's getting aged. Yep.
RobAnd for the first time, healthcare had a real federal security baseline for electronic protected health information.
DawnCorrect. And this included what you guys already probably know administrative safeguards, physical safeguards, and technical safeguards.
RobYep. Those are the three key pieces. Think about your risk, know where your information is, and protect it. And of course, you've got to document everything and where it goes. But from 2003 to 2005, a lot of covered entities require to actually be operating under that rule. And then there's something that dramatically changed in 2013.
SPEAKER_01Mm-hmm. Yeah.
unknownYes.
RobWalk us through the omnibus rule,
Omnibus Rule And New Accountability
RobDon.
DawnYeah. So the current rule, still the rule. Until we hear otherwise, there is a meeting with the HHS, there is a conference in a few weeks. So we will hear if there's more to come. But in 2013, we got the omnibus rule. And that's when ding, ding, ding, the big relationship between covered entities and business associates really changed. So business associates couldn't just stand next to HIPAA anymore. They were actually also had requirements.
RobYep. And for they had to adhere to the security rule, administrative, technical, and physical, just like a covered entity.
DawnRight. Now, should we explain if people still don't know what a covered entity versus a business associate is?
Covered Entities Business Associates BAAs
RobWhich one do you want?
DawnPossibly.
RobWhich one do you want to explain first?
DawnI'll I'll do covered entity. You'll use business associate. Covered entity. That is basically doctor, covered entity. They have, they are the medical facility that has the the the medical record. You know, they are, you know, the covered entity. There's there's more to it than just a doctor or a dentist or a chiropractor, but that's just kind of all in a nutshell, or a hospital clinic, that type of thing.
RobBut they're the ones that create the medical record. Yes, they create it. And the business associate is the company that supports the medical practice or hospital or clearinghouse. So yes, it could be an IT provider, it could be an MSP, it could be your IT provider, it can be a SaaS company, it could be the clouds, the Amazon, the Google, the Azure, Personal Cloud, Data Cloud, any cloud. It could be your AI bots, it could be a courier service, an answering service, it could be a shipping service. Anybody that anybody or any entity that comes in contact with the health information, even incidental, is considered a business associate. Therefore, you have to have a business associate agreement with every contract before you it before you actually see or support any health information.
DawnAnd what is a BIA BAA, you may ask?
RobExactly.
DawnA BAA is about a 12 to 15 page agreement between yourself and the covered entity and each of your responsibilities in regards to handling ePHI, disclosing EPHI, and if there was a breach that occurred, notification of that. So it it tells what each responsibility is. And there's also, you go take it a step further, you could be a business associate working directly with a business associate, which means now you've got a business associate and then you've got a subcontractor business associate versus just a business associate and covered entity. So there's lots of iterations, but more importantly, this was very important that this this was now a rule that that came to play. Very important in HIPAA.
RobYeah, and business associate agreements, BAAs should only have what's needed for the healthcare law. It's not a place to put the requirements for your cyber, for your MFA, for your, you know, penetration testing, for other requirements. You need to certainly strip it down to just what's needed for the BAA. Everything else goes like your service agreement or other contract. Keep it all separate. I starting to see a lot of it blend, and you don't want to blend it in there. You want it, you want it separate separate different things. But it's a whole economy. And this is where in, you know, in that mid 2010s, 2020s, I know going to the Wayback Machine, that's where platforms and cloud and everything started exploding, and healthcare was a m was a major t target and opportunity, uh, just kind of like financials for cloud computing. And that's where a lot of the uh the reasons for business associate agreements came out is because we've got to protect the whole, protect the data in the cloud. All the whole data. Yeah. Because all from that, what came the claims, the pharmacies, the providers, providers, the patients.
DawnYeah.
RobIt keeps going.
DawnThe cash flow, the care delivery, the operations, all that. Yes.
RobYeah. That's kind of the conversion between the old cybersecurity and what we have today. And uh it not just can someone see the record, but can they can they uh download access the record?
DawnOr incidental access.
RobIncidental. Yeah.
DawnWhich could be they never access, but incidentally, if they do, you still you have to have a BA.
RobIncidental would be like a courier service, which we have clients that are courier services. Yes, the health information or the script is in an envelope, but you're still carrying that script. How do you handle that? It's the access control.
SPEAKER_03Yep. Yep. Yep.
RobCan you take care of patients? Right. Yeah. Can you build? Can you get paid? Can you recover? And those are kind of some of the areas that we that we really see. So that's kind of where you see the difference between the business associates and the actual covered entities.
DawnAnd then a step further, if you were in Texas, everyone's considered a covered entity. So that's a whole nother, whole nother ball of wax right there. Texas has its own uh BAA and its own uh even the compliance steer, right?
RobRight. Because you got to have a compliance steer.
DawnYes. There you go.
RobYou definitely have to have that.
DawnSo But yes, that was a big, big important part of HIPAA compliance is is that BAA. And it's it's very important to have with your customers and uh and to make sure that it is separate from the contract, correct?
RobSo we got we got we created everything in 2003, we got to 2000 uh, you know, five and thirteen, then we got omnibus, we got the high-tech regulations, and then all of a sudden 2025 came around. So
Proposed HIPAA Security Rule Rewrite
Robabout a year and a half ago, uh HSS published its proposed rewrite of the HIPAA security rule. It was supposed to be completed in June of this year. We'd heard fall of this year. Uh last week I heard February of next year, and and there's, you know, it's kind of a moving target. But like Don said, the uh HHS NS has a conference next week, well, two weeks next month in uh DC. And we're gonna be attending that and bring that information back to the podcast because we need to know what's going on so we can support our clients and give the information back to you. So it's gonna be a lot more in-depth. And what are what are some of the areas, Don, that they're looking to change?
DawnYep. So MFA, which required again, that's been around for a while, but they're finally saying nope, you need it.
SPEAKER_01Yep.
DawnUh, encryption, technology, asset inventories, you got to keep track of your assets. Network maps, your data flows, very important, especially with AI coming in and integrations. Where's your data flowing? Vulnerability scanning, pen testing, huge, huge, huge, huge right there. That is gonna be a requirement. And there's gonna be more specific recovery expectations and more documentation. Again, this is all very loose, not really sure if there's gonna be any specifics to dates to certain things. Is it all gonna be in effect in 2027? We're gonna find that out for you.
RobYep. These are all proposed, pretty much all the addressable items that are in today are gonna become required. These are also ones that align with all the industry standards and recommendations from NIST, you know, ISOSOC, high trust, all that. So everything went, I think it aligns very well. So that's what we're gonna do is keep an eye on everything between now and the first of the year to see what changes, and we'll keep everybody updated on the uh on the podcast.
SPEAKER_03Yep.
RobAnd that's long term, but security rule is still enforceable right now. It hasn't changed. There are there are multiple, multiple actual, you know, breaches on the HIPAA wall of shame. Which we should bring that up, right?
DawnWhich is a fun thing to look at if y'all haven't looked at that.
RobWhich is not a bad thing to look at. Yeah. Um because there's still a lot of breaches and it happens all the time.
DawnYep. Absolutely. Absolutely. So, so again, the plan, it was supposed to be, it was, it's per was proposed earlier this year. It was supposed to go into effect this year. Doesn't look like that's gonna happen. We're gonna go and, you know, attend the the uh seminar, see what they have to say um in a couple weeks and see what what else is, you know, is that are those just the proposals? Is there more? Is it going to be effective in January? Are they gonna wait till middle of next year? What else is coming to play? That type of thing. So um my guess is that because AI has been such a huge piece of everything lately, is my guess is that they're probably going I they well, they are gonna be talking about AI and and HIPAA, but my guess is they're kind of probably trying to work some of the things in. But again, that's just a guess. So we'll
The HIPAA Wall Of Shame
Dawnsee.
RobNow, I think since since it'll be fun, Dawn, I'm gonna share the actual HIPAA wall of shame. Because if you're listening on the podcast, obviously you won't see it, but if you're on the YouTube channel, you're gonna check it out. So I'm gonna share it and we're just gonna take a look at this thing. Um this is the HIPAA wall of shame. So the easiest way to do it is just go to your Google and do Hip A Wall of Shame and it pops right up. Um, it looks like 1993 with an old MacBook from 1993 or 2002. Um, it has the old icons of you know, it's very governmental, right? Like I think that's like Excel 2007. I don't know, PDF, CSV. But here's the deal. Um, look at the dates. That's less than a month ago was already there. Um, and look at the amount of people's lives impacted. So part of the old hip-hop of shame here is you get to be publicly shamed. And this means that every every SEO, every engine, every AI, every customer knows that you had a breach. Even your insurance providers knows you have a breach. Um, and look through here of all the issues. Now, Don and I go through this, oh, I get it kind of each week as they update it pretty much weekly, or sometimes every look a little behind every couple weeks. Here's a few days, right? But there's a big theme, is the hacking is the big things. Email is a big issue, desktop servers are a big big issue. Look at that. Paper films from 10 care. They're still they're still in films, they're probably and there's the care cloud.
DawnLook at that one. Care cloud three, is that three million?
RobOr is that three million, yeah.
DawnWe have clients that have been part of that. That is a huge, huge one. Um yeah. Look at Vanderbilt University. High-end university. Doesn't matter. Doesn't matter how much money you have. It um yeah.
RobUnlimited technology systems, another 3.8 million.
SPEAKER_01Yep.
RobUm it doesn't matter if you have a thousand dollar budget for security or a hundred million dollar budget for security. If you don't do things properly, you will end up on this list. But the worst part is look at all these lives. There's seven million lives impacted right there between those two.
DawnHacking, hacking, network server, email, email, I mean, it, you know, people are still getting hung up on, you know, they're still getting email phishing is still a thing. Um, network servers, folks. Pen testing. You have open doors on your network. Pen testing is gonna find those. Um, I mean, it's just unbelievable. Yeah, look at all these, and that's just July. This is just July.
RobJuly. It goes all the way back to 2013.
DawnAnd it's all over the country. All over the country.
RobAll the different states, a lot of payer systems. Um, because we have to reason it's it's so valuable, is that I would say it's more valuable than financial data now.
DawnI mean, look at all these small, small uh clinics and stuff. Think of that. And and we hear this all the time. We hear the small chiropractic. Oh, I just started, it won't happen to me. You're small, you're gonna be a target. You're big, you're gonna be, you're gonna be a target any, I mean, anyway. But just because you're small and you just started out doesn't mean you don't need to be compliant. Um, this, I mean, this look at this. This, you know, 500 people, you know, and over 500, you have to go to the media. You have to tell every everyone has to know, and every individual that's affected has to know. Um, this isn't just one person. This is this is lots of people. Um, yeah.
RobBut it kind of really shows you, and it it's, I don't know, sometimes I'll get geeky and download it and put it in a sheet and graft it all out, but it's it's um it's unbelievable. Other thing while we're here is obviously here is well, the archive report that takes a little bit longer because they'll they'll archive off last year, which is massive as well. But here's help for consumers. Um you can now go ahead and request a copy of your own health information and amend your health record if you had a breach and you feel that your information was compromised. And also you can file a complaint with the FTC because now the FTC monitors HHS uh breaches. So now there's all of that as well. But um, these are just still under investigation. So they'll take, we've helped clients through them. We had people come to us after breach and we navigate that because it's a service that we provide, two months to four months, sometimes six months, and you gotta deal with the government on that. But I just figured it was kind of nice to show.
DawnYeah. And you know, HIPAA's been around, you know, a long time, but it's not going away. And it is the it is required by law to be HIPAA compliant. And you know, SOC2 is nice to have, ISO is nice to have, oh my my clients the you know, their you know, their contract tells me I need it, we can help you with that, sure. But HIPAA is the only required regulation.
SPEAKER_01Yeah. That's why I call it the HIPAA.
DawnThe HIPAA.
SPEAKER_01The HIPAA.
DawnIt's gonna be around forever.
RobIt it you know, laws, once laws are in, they're always there forever. So going on to the next section is kind of like what didn't
What Has Not Changed
Robchange, right? So let's talk about what hasn't changed. A lot of stuff that hasn't changed. You know, there's no new acronym, there's really not too much in the work except for the security rule on where health information is located. But I'm really starting to see more pressure around access controls. You talked about that earlier, Don, right?
DawnYep. Yep.
RobThe access controls of not only where your data is and and who accesses it, but your third parties.
DawnYeah. And third party is a huge piece of of HIPAA compliance. It is you need to know what your third party partners, vendors, whatever you want to call them, are doing with your data or your client or your client's data. You know, it it it just it is interesting to me that everyone will go get some fancy something, something, something, because it integrates or an AI or this or that.
RobMCP.
DawnJust to just to get things done and it's all fun and and everything, but where is that data actually sitting? Is it backed up? You know, so we have to be very careful. Yeah, very careful.
RobAnd a lot of people don't know the name of their systems. Yeah. To protect them. Or maybe they had it from last year and then we come into this year's audit and go, we've added 17. Really? Oh, what are they? Don't know. You have to go through that, or the vendor names and who's looking at that. You have to vet the vendors to understand that as well. Not just TIPA, but any compliance framework. Yes. Anything you're doing. I mean, even energy. You got NERC compliance, you got to do that. Shout out to the NURC folks, the nerdy NERCs, the nerdy NERC. There you go. Uh but every system has to be identified and documented. And there is, you know, agents and tools, yes, they can do that, but you still need the humans to take a look at that and see what's going on. And then really it kind of dives into policies, you know, the types of policies we have and what we need. Now, you do a lot more policy writing here because you're good at grammar. So what changes have you seen in policies and what's been updated lately?
AI Policies And Staff Signoffs
DawnYep. Policies, uh, a lot of AI. Because you really need to give your employees um the AI guard lines, guidelines, um, guardrails.
RobUm guard lines. Let's call them guard lines.
DawnTo to to let them know how it can be used or it can't be used. And then also you need to make sure internally your systems, are they allowing it? Are they not allowing it? Does your IT, are they blocking it? You know, what how how are you handling it? You know, um, because if you roll it out, you need to tell people how to how to utilize it or how to not utilize it. So policies and procedures are still extremely important. The AI piece of it, very important now. A lot of people are having their employees sign off on a lot, a lot of documents now, making sure they understand it. So we're streamlining our policies here at Van Ryan, making them a little bit more, you know, kind of grouping them together, you know, making a really robust um access control policy with all these items kind of within it, just talking about all the access. You know, we're talking passwords, multi-factor, you know, and so really just have some have those policies and have your employees and your staff understand what what it means and where these policies are. And you should have them sign off if they've read them.
RobAnd kind of going from policies to going to procedures,
Backups Incident Response And Testing
Robright? Is the backup and incident response plans. How, you know, all those everybody on the hip wall of shame, what's the response? How, how are we going to talk to the media? How are we going to tell them our three million customers that we impacted them? Who's going to pay? Who's cutting the checks to to deal with the credit monitoring and the financial freezes and all that? Yeah. Uh, and it's a real contingency plan with a real backup capability, is really the key piece. Can we get back to where we were yesterday? You should be able to get back within the hour, would be the best, or within 10 minutes. But sometimes we've seen that fail. But can you get back to the last kind of last time good uh and really get dialed in there? And you know, our standard here at Van Ryan is really simple. Um, you've got to prove it and you gotta test it. Like, have you do you actually have that? And um, do you have your contingency plan? And not just upload it from last year. Have you touched it? Did you create it once from the last audit? Do you have meeting minutes that you've actually gone through? Do you have just even just a quick note of uh capturing what you went through to to go through and test those?
SPEAKER_01Mm-hmm.
RobBecause without dates and all that, then we have nothing, right, Don?
DawnYep. And can you restore? Can you restore it from your backup? Can you restore your your environment? You know? Um that's that's really important. So knowing how this all works and what to do and the steps and the procedure to it, that's important. And a lot of people just say, Oh, well, I just, you know, all my stuff's in any. HR and they they have to deal with all that. Well, no. Because the data's going from you to them and them to you. And you know, you're you're there's data moving back and forth on your network and within your network. And so you have to make sure that you yourself, you have disaster recovery. You have all that. It's not just not just it's not just your vendors.
RobYep. You know. Not just the vendors.
DawnYep.
RobAnd I think really it goes from, you know, we've talked, we've talked kind of the history of the HIPAA regulations into the compliance landscape of policies and procedures.
Culture And Daily Compliance Discipline
RobAnd now what I think is really important is culture. You know, we talk a lot about it. Culture, culture is very important to Don and I, but it's really about the culture in your business. Have you really gotten the folks on board with how we're handling data, the steps we're going through, how do we secure it, and who's on point? You've got to have your CISO, it's a compliance officer, a security officer. Someone's got to be designated. And there are clients that are very successful with their compliance and security has someone that's actively focused on it. Um, there's some clients that are fortunate enough to have just the compliance officer, and he or she manages everything. Sometimes it gets dumped in IT, and then one person's hold you know has multiple hats. But it's really about putting that uh the culture into the business and making sure people think about things before they sign up for the latest, you know, bot for the agent, the AIs, all of that. Take a look at subprocessor, take a look at the trust centers, take a look at the uh the documented, you know, do you really know where that data's going? Um, because we've gone from the days of, oh, it's kind of good to, oh, we have to start kind of prove it to, okay, now we need to see your third parties, because that's the really key is making sure we know where we are. And it's really kind of the same, same story, different room though, right?
DawnSo in the last 20, 30 years of HIPAA, you know, the big thing has changed is we used to have big binders, big binders of paper, big binders of all the policies and procedures. Now everything's electronic. Everything is like, oh, we put it in our employee, you know, HR platform, employee center, you know, whatever you're using, and they have to go through and sign off on it and and and that type of thing. And P you can do it on your phone, you can do it on your iPad, your laptop, whatever. And so, so that's big too, is that now it's becoming where you're not just sitting there at a cubicle and you're leafing through this, all these papers in this huge notebook, is you are now online reviewing stuff online and having to actually do an e-signature that's date and time stamped. And so there's a lot more at it at risk now because there's more data now. And and but you also we've gone more electronic. So, yes, that adds more risk, but it also is you've gotta, you've gotta be accessing certain things. You've got to be able to read through things and sign off on it. I mean, it it's a lot more in in detail and in depth now. So um, yeah, the old binders, oh, where's the binder and the, you know, on the bookshelf. That that's no longer. It's this is really important. And that's why it's important to have the right person that's a compliance officer or security officer, privacy officer, whatever you call them that's in charge of compliance and they can implement it to the team and tell everyone how they need to be compliant by taking their training, by reading certain documents and and signing off on them.
RobYeah. Because when you have an incident, and it will be a when, not an if, you have to make sure that you're ready for what to do. Um, you know, what to do when something happens. So as we're getting, you know, as the last few podcast episodes, we've talked about college, we've talked about our family, opened our playbook a little bit. So now, like we're all getting back to school. What do we do this fall? Like, what are we actually going to go through? Uh, we've done the history, we've gone through all that. I think right now it's not about waiting till 2027 for the final HIPAA rule. It's about living it every day because attackers, hackers, uh, and your customers depend on you to protect their data. You can't just wait on it. You can't just wait and go do whatever.
DawnYep.
RobI would definitely say do not wait, right, Dawn.
DawnRight, right. Compliance isn't just a one and done. It's a daily, daily discipline. Ooh, daily discipline.
RobDaily discipline.
DawnDaily discipline. There you go. And because something will come up. Something will come up, something will happen. It may just be just an innocent ins incident by someone, you know, in your staff, but something will come up, but you always have to be diligent and know what what to do. And it's a different landscape now. It is because there's so much more risk. And you just have to just pay attention. It's things are moving quickly. So we even noticed that with signing our our son up to college. It's there's a lot you have to sign off on. There's a lot of disclaimers now. There's a lot of I mean, it's like scroll, scroll, yes, yes. Okay, scroll, oh yeah, and I owe you this. Okay, yeah, scroll. I mean, it it it doesn't matter how much you pay. That you you got there's a lot, lot, a lot to lot to read, a lot of disclaimers now. So that's the world we live in.
RobIt is. And and the first thing to do you set up your team is name the owner, right? It's it's the kiddo to take care of himself, or it's a compliance officer
Setting An Owner And Getting Certified
Robin your organization. And then he or she creates that rhythm, yeah, right? Our compliance mindset. We know what's red, yellow, green, what's blocked, you know, what we'll do uh here at Van Ryan is every Monday the bot goes out. Yes, the Slack bot goes out until ask the team, what'd you do last week? What's your wins? Where's your blockers? And what uh what are you working on? And the team has clear visibility for everybody, the entire team. Now we're a small team. Yes, I know you've had you know hundreds of employees that could get noisy, but you can break those down into separate departments and then roll those up as needed. And then from that, you just make sure you're dialed in on the solutions, the policies, the procedures, and don't wait for it to happen because it will happen. You may not see the breach or the incident or have a lapse in your compliance, but your third parties and their downstream parties, fourth, fifth, sixth, seventh party down the road. Maybe there was a small hook, small MCP that had an issue or an API that had an issue and it impacted you. And you didn't even know it for weeks. Those those are the key things. So I think we did good this week, Don, kind of walking people through, getting things dialed in, kind of where the history of compliance is, kind of where we're going, and those call to actions for our for our listeners. Any parting words of wisdom?
DawnYeah, just uh it's important that your organization has someone that that can wrap their arms around it, has one person or a team that can uh handle the compliance, make sure everyone's on the same page, make sure there's there's things implemented because it, you know, there there needs to be needs to be documentation, there needs to be, you know, how do we do this? How do we do that? So just make sure that you know you're just keeping up with everything. Annual audit, um, policies, procedures, annual training. Good news is uh we launched a couple weeks ago certification. So if you want to be an actual certified compliance officer, go to our website and for $99, you can become a certified compliance officer. And that will give you all the tools. If you're just coming from, hey, I was an HR and now I have this job I have to do now, or I'm coming from being a manager. It's a great, great, robust training that you can take, get a certification, you can share it out to the world. You'll have an actual certification number. And and we did that because there is people that say, I do not know how to do this job. Help me with that. And it's great. So yeah, please, please visit our website if you want to sign up for it. You won't be you won't be uh sad about it. It'll be really good information and and you'll feel confident that then you can be able to handle the compliance at your company.
RobYou know exactly what to do. Yep.
DawnYep.
RobWell, I think that's good, Don. Yep. So thank you everybody for joining. I'm Rob.
DawnI'm Don.
RobAnd have a great week. Talk to you next week.
DawnBye bye.
RobBye bye.