VanRein Compliance Podcast
Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.
VanRein Compliance Podcast
Lead with Confidence: HIPAA, AI & Knowing Who Owns What
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
HIPAA compliance has a way of becoming your job without asking permission, and that’s when panic usually sets in. We take a different angle: confidence isn’t perfection and it definitely isn’t memorizing regulations. For us, confidence comes from clarity you can prove later, knowing who owns decisions, what got approved, and how to show evidence six months from now when an auditor or customer asks.
We dig into the places where compliance programs get shaky fast: vendor management and third-party risk. When IT, Legal, Compliance, and Procurement all point at each other, the risk ends up owned by nobody. We explain how to assign a real owner, document the workflow, and keep Business Associate Agreements and vendor due diligence from becoming an endless loop. From there we get practical about “evidence” and what actually holds up: policies, training records, screenshots of MFA and access controls, and documentation that matches how work happens day to day.
Then we tackle the biggest hot button right now: AI governance for healthcare and HIPAA-regulated teams. AI note takers, writing assistants, and meeting transcription tools can be powerful, but the real questions are where the data goes, what settings quietly share it, and whether the vendor’s security posture matches your risk tolerance. We also ground the conversation in fundamentals that never go away: backups, redundancy, testing, and staying aligned with the HIPAA Security Rule even as proposed updates evolve.
If you found this helpful, subscribe and share it with the person who just inherited compliance. Leave a review, and tell us what risk you’re tackling first this week.
Thank You for Listening to the VRC Podcast!
Visit us at VanRein Compliance
You can Book a 15min Call with a Guide
Follow us on LinkedIn
Follow us on X
Follow us on Facebook
Welcome And The Monday Reality
RobWelcome to the Van Ryan Compliance Podcast with Rob and Dawn. We help growing teams reduce risks, build trust, and stay audit ready without the overwhelm. Don, confidence is not a mood. It's knowing who owns a decision and being able to show it. Right?
DawnRight.
RobWelcome back to the Van Ryan Compliance Podcast. I'm Rob.
DawnAnd I'm Don.
RobAnd Don, last week we talked a lot about what we're hearing that coming out of the HHS and NIST conference. Focus on cybersecurity, AI, regulatory priorities, all of that. But today I want to bring us back down to good old Monday, right? Or Monday afternoon or morning.
DawnDoes someone have a case of the Mondays?
RobThat's it. Exactly. We all do, right? Because somebody listening to this right now probably has HIPAA compliance sitting on their desk, whether they've asked for it or not.
DawnRight. Exactly.
What Confidence Really Means
DawnAnd it might be the privacy officer, it might be the security officer, it might be the compliance officer, it might be an administrator, an IT person, or someone who suddenly became the compliance person overnight because someone had to own it, right? And that's really what we want to talk about today. How do you actually lead a compliance program with confidence when you don't have every answer? Because you won't have every answer.
RobYeah, correct. You won't have them all. And that's probably important to say right away. Confidence doesn't mean knowing every regulation from memory.
DawnNot at all. To me, confidence starts with clarity. Who owns this? Who makes the decision? What did we decide? How can we show what happened six months from now? That's where a lot of organizations get into trouble. They may not have done the right thing, but nobody documented the decision, or everyone thought someone else was responsible.
When Vendor Risk Has No Owner
RobYep. So let me give you an example. What's something you see whose ownership gets blurry?
DawnVendor management is a good one, right? Who's responsible for reviewing our vendors? And the answer might be IT. Then IT says, well, legal reviews it. And then legal says, well, compliance handles BAAs. And then compliance says procurement owns the vendor. So, okay, so who owns the risk?
RobEverybody or nobody, right? Who actually owns it?
DawnYep. Yep. Kind of explain that, that, Rob. That exactly.
RobYep. So if nobody has owns it, then everybody owns it. But if everybody owns it, then nobody owns it. And it has to have uh it has to have a seat. Somebody has to be responsible because even even in today's world of uh you know conversations of AI safety and compliance, there's still the human in the middle that keeps things on rail so that we can continue to scale and grow.
DawnYep, exactly. The answer doesn't have to be complicated. You know, you can literally put it in writing. So as far as who owns it, you know, at the bottom of your policies, who's the policy owner? Is it IT? Is it your director of HR? Who, you know, who is it? And that's really what we need to know. So everyone knows in the organization who owns this piece.
RobYep. Yeah, who owns that piece. You know, just basically what I like to do is making sure we have we have a written out that the the security review that, you know, Jane or Mike owns this and it's detailed. Don't just put generic privacy owner. Um, you could put just you can put the I I like to actually have a name, the real name of the person. And yes, that means you have to change it sometimes, but I think that's more important than just an ambiguous compliance officer, right?
Evidence That Survives An Audit
DawnSo Yep. And also, you know, when we take we take our customers through through an audit, you know, we we need evidence, evidence um that adheres to the controls. And sometimes the compliance team's, you know, IT person says, Oh, evidence. I need, I need a binder of something. I need, you know, and no, you don't. Um you need is you need evidence. It could be a policy, could absolutely be a policy, but it could be a BAA. It could be show me your your team is taking their annual training. It could be a screenshot. Show me how your your security is is is set up, meaning like, you know, MFA, password complexity, you know, that type of thing. Um, so that's really the difference between having a compliance program on paper and being able to defend your program is two different things. Yeah.
RobYeah, those are two different things. Um, you just said something that's probably one of the biggest confidence killers is policy versus reality. There's a lot of people that just have policies, but it's not the reality of either organization works. Um, this is why you have to have those audit and you have to determine where everything is and w where everything goes and what you really are doing and what you're really not doing, and what's in scope and what's out of scope and all of that. And those are the key pieces that we see are big confidence killers in
AI Governance Without Panic
Robthe industry.
DawnRight. And with AI, I mean, you know, I'll kind of expand on that is is HIPAA and AI. You know, uh, where does AI fit in your organization? How are you how are you showing, how are you proving, you know, what data AI touches or doesn't touch, um, that type of thing. So what other things and, you know, should they look for with that? Because AI is a big hot topic right now. Um, it is.
RobAnd then AI safety is a big thing. But it's also very exploded out of proportion. Um, you know, I think that has potential for the US market, for businesses, for creators, for people to create amazing new businesses, to stand up businesses they never were able to do and and help the economy. Um, and I think the AI safety is a little bit blown out of proportion, even from a compliance standpoint. Um, meaning that what we need to do is teach it, you know, give it the guard guardrails that we need, make sure things are in the right places, uh, roll it out effectively, but don't stop the don't stop the growth. I think it continues to to go forward. And you need this is where you need to lead with confidence is in the AI safety, making sure do you have, yeah, you have a policy, but is it actually doing what it's supposed to be going? Making sure you're verifying the steps, make sure you're doing everything that it needs to be done so that you can continue to expand AI. It's not going to go away. This is, you know, it's kind of like the internet, but it's just quicker and faster. Um, and it has so much capabilities that we need to make sure that we embrace and not just throw some political pundit at it thinking that, oh well, we can't do it because it's unsafe. Yeah. They probably said that about planes, right? Probably say that about ships, boats, cars. Yep. Probably sell that about electricity. Yeah. Imagine a world with electricity, really. Yeah. So you just you just need to to this is where you do your audit, your AI audits, you look at it all, and then you see how can it solve the problems and always keep in that kind of that human in the middle to check.
DawnYep, absolutely. And that's where third-party vendor management comes into play as well. Um yeah. So AI needs to needs to be right up there is where is that data being stored? And what is that uh AI tool? What is their security posture? You know, it is we're we're talking on Monday. Um, our podcast comes out on Wednesday. So, you know, we're not saying try to fix the entire compliance program by Friday, you know, just pick something, pick something. If you're focused on AI, let's make sure we're, you know, vetting those AI vendors, making sure that you're using AI within guardrails, using it appropriately. Make sure your team knows how to use it. And then, you know, so that goes along with BAAs with HIPAA compliance. Do you have BAs with those that you need BAs with? So let's, you know, make sure we have that. So pick something. Pick something that that you see in your organization is a risk and work on it. Um, and you know, work on it till completion, you know, until you've resolved the risk or you've identified it and resolved it, you've got solutions. Maybe not, maybe you don't resolve it this week, but maybe you've got a solution for it or a few solutions. So yeah, what are some other things that uh maybe are are quick things in your program that maybe you could look at this week? We just talked about AI governance, um, you know, BAs.
RobWhat are some other things that we could Yeah, BAs are key, making sure you have all those in place, but also doing that that vendor due diligence downstream from your business associate to their subcontractors down the road. Making sure those are dialed in. Those are those are the the keys. Uh making sure you're able to to um get back to where you are today at whole. You know, the standard frameworks of of backups and redundancy are still in place. They're still required. So nothing's changed there. So making sure that that's all done correctly and uh and and how you do it. So making sure that backups are put together, making sure they're set, uh, make sure they're tested. You know, it sounds okay to test backups, but they're written out of the law, but also it's the business. You've got to be able to roll back to to a previous state, especially as fast as as everything is gonna go, as it continues to go. Yeah.
DawnYep. Yeah. So those are those are big things. AI, you know, AI governance, AI guardrails, BAs, backups, that type of thing. Um, you know, we could probably talk about AI all day because that's really what's on everyone's mind, you know. Um AI note takers. Talk a little bit about that. AI writing assistants, you know, talk a little bit about that.
RobUh, you know, it's all getting processed now. Yeah. Is it Gemini? Is it granola? Is it G Zoom? They all do it.
DawnUm Fathom and Fathom, there's all those.
RobI think they're great, but they're great at taking the notes, but where's the data going? Is it being harvested to train their models? Is it just private? Um, those that's kind of where you you that's where the concern always is, is where does that data go to make sure um using it as needed and making sure we're within that regulatory direction uh and knowing how to how to how it's expanding and where it's really going.
DawnAnd remember, if you do add it to your your video conferencing, your note taker, remember everyone gets a copy of the transcription. Yeah. So you also have to be careful of what you share. And yes, the settings. It's very important to go into the settings. And are you gonna share it, share it to help the model, help others? It that's those are very important settings. And the settings are changing probably on a daily basis. So that's what you should be very, very careful with.
HIPAA Still Applies To New Tech
DawnAnd you know, the the proposed HIPAA security rule changes. Um, you know, those are still proposed changes. So we talked a lot about that that last week, July. That's what it's gonna be. That's the date now, July of next year. Um, so yeah, Rob, do you want to highlight any anything else in regards to that? I think we've covered it pretty much. Yeah, we've covered it well.
RobI mean, I think the key pieces that that nothing's changed. Yeah, the security rule is still a security rule. It doesn't matter if the technology changed, the law is still there. Every bit of technology plugs into the law, and um, the law covers everything that's ever created from it's been 30 years old and it still incorporates everything that's been created. So those are the key pieces. Um and that's you know, that's what we'll we'll look after. But um, I think I'm more focused on what NIST is doing now and and their RMF 2.0 because there's a lot of good works we could put in there. And then all of your data in your controls, your control access.
DawnYeah. And and remember, if you're already, if you're already meeting current requirements of HIPAA compliance, you're already in a much better position. And so whenever the final rule, whatever it looks like, you've already been adhering to the controls. So it shouldn't be the only thing that, you know, maybe a, maybe a change is uh, you know, the annual pen test. I mean, that's a that's a you know, it's an expense to to have, but it's it's very important. Um, but that's gonna be probably one of the biggest changes and that will help you see if you have new vulnerabilities in your network and that type of thing. But um, but you're already on your way if you're adhering to the current requirements. So um we'll wait to see. Um, those are proposed rules. You know, who knows what can happen over the next uh six months or so. But yeah, again, it's just lead your program, lead your program with confidence, implement, have the right people on your team, and really uh just don't be afraid
Coaching Builds Compliance Culture
Dawnof it.
RobSo yeah, those are the big pieces. I think to be able to be find that leader, find someone that owns it, find someone that's passionate about it, um, because there's regulation around it and there there is law. So um those are the those are the key pieces. Um so you're you know, when you're you're coaching the organization, you're not policing the organization. I need to make sure people are aware of who to contact and what to do and how to make sure that um that you're doing the right things and you're staying within the regulations and keeping things going.
DawnYep, absolutely. That is the key. We like to say key here at uh at Van Ryan. So the key piece. That's um, but you know, just build a stronger compliance culture. It becomes it becomes a an everyday thing that you just that you do, and everyone knows and everyone knows who to go to and what to do. And that's a that's a really uh strong culture. So yeah.
Pick One Risk And Finish It
RobSo let's just kind of make it practical, right? Everybody just listened to this episode and they're they're about to go on up their day and then get back to work and all that, or driving and listening and all those fun things. Uh, what's one thing you want them to do, Don? What's one thing, what's your takeaway?
DawnYour takeaway is pick one of those things that uh a risk that you think that you need to really focus on. And that could be vendor management. It could be backups, um, access control, AI. Pick something this week. And I, you know, that's my challenge to you. Pick pick a risk that you have, that you were like, whoa, I need to work on this and sit down and work on it. Come up with some solutions. If it's just you, your team, and try to work on what the next steps are.
unknownYep.
RobYep. Yeah, I think that's one of the big takeaways. Go back to your leadership team and say, what's the next 30 days are we gonna take? Right? What are we gonna do? What are we gonna the items we're gonna take off the table? What are we gonna add to the table? What is a risk from not only HIPAA compliance, PCI compliance, state level, federal law, international law, you
30 Minute Readiness Review Offer
Robknow what you're gonna do. And if there's questions, you don't know how to navigate those conversations, just let us know. We could do a 30-minute readiness review.
DawnYep. And remember, confidence isn't being perfect. That doesn't mean confidence does not mean perfection that you've got everything in line. Confidence just means you know you've got a program, you've built it, and you're doing your best to implement it and you're taking it step by step.
RobSo that's exactly what you do. And if you have more questions, you can just the link is in the uh in the show notes. You can book 30 minutes with Don or I. Um, write to the owners here at Van Ryan, and we can go ahead and help navigate you through your compliance complexities.
DawnThat's correct.
RobWell, thank you guys for joining us again on the Van Ryan Compliance Podcast. I'm Rob.
DawnAnd I'm Dawn.
RobUntil next week. Bye bye. Bye bye.