Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.
HIPAA compliance has a way of becoming your job without asking permission, and that’s when panic usually sets in. We take a different angle: confidence isn’t perfection and it definitely isn’t memorizing regulations. For us, confidence comes from clarity you can prove later, knowing who owns decisions, what got approved, and how to show evidence six months from now when an auditor or customer asks.
We dig into the places where compliance programs get shaky fast: vendor management and third-party risk. When IT, Legal, Compliance, and Procurement all point at each other, the risk ends up owned by nobody. We explain how to assign a real owner, document the workflow, and keep Business Associate Agreements and vendor due diligence from becoming an endless loop. From there we get practical about “evidence” and what actually holds up: policies, training records, screenshots of MFA and access controls, and documentation that matches how work happens day to day.
Then we tackle the biggest hot button right now: AI governance for healthcare and HIPAA-regulated teams. AI note takers, writing assistants, and meeting transcription tools can be powerful, but the real questions are where the data goes, what settings quietly share it, and whether the vendor’s security posture matches your risk tolerance. We also ground the conversation in fundamentals that never go away: backups, redundancy, testing, and staying aligned with the HIPAA Security Rule even as proposed updates evolve.
If you found this helpful, subscribe and share it with the person who just inherited compliance. Leave a review, and tell us what risk you’re tackling first this week.
Welcome to the Van Ryan Compliance Podcast with Rob and Dawn. We help growing teams reduce risks, build trust, and stay audit ready without the overwhelm. Don, confidence is not a mood. It's knowing who owns a decision and being able to show it. Right?
Dawn
Right.
Rob
Welcome back to the Van Ryan Compliance Podcast. I'm Rob.
Dawn
And I'm Don.
Rob
And Don, last week we talked a lot about what we're hearing that coming out of the HHS and NIST conference. Focus on cybersecurity, AI, regulatory priorities, all of that. But today I want to bring us back down to good old Monday, right? Or Monday afternoon or morning.
Dawn
Does someone have a case of the Mondays?
Rob
That's it. Exactly. We all do, right? Because somebody listening to this right now probably has HIPAA compliance sitting on their desk, whether they've asked for it or not.
And it might be the privacy officer, it might be the security officer, it might be the compliance officer, it might be an administrator, an IT person, or someone who suddenly became the compliance person overnight because someone had to own it, right? And that's really what we want to talk about today. How do you actually lead a compliance program with confidence when you don't have every answer? Because you won't have every answer.
Rob
Yeah, correct. You won't have them all. And that's probably important to say right away. Confidence doesn't mean knowing every regulation from memory.
Dawn
Not at all. To me, confidence starts with clarity. Who owns this? Who makes the decision? What did we decide? How can we show what happened six months from now? That's where a lot of organizations get into trouble. They may not have done the right thing, but nobody documented the decision, or everyone thought someone else was responsible.
Yep. So let me give you an example. What's something you see whose ownership gets blurry?
Dawn
Vendor management is a good one, right? Who's responsible for reviewing our vendors? And the answer might be IT. Then IT says, well, legal reviews it. And then legal says, well, compliance handles BAAs. And then compliance says procurement owns the vendor. So, okay, so who owns the risk?
Rob
Everybody or nobody, right? Who actually owns it?
Dawn
Yep. Yep. Kind of explain that, that, Rob. That exactly.
Rob
Yep. So if nobody has owns it, then everybody owns it. But if everybody owns it, then nobody owns it. And it has to have uh it has to have a seat. Somebody has to be responsible because even even in today's world of uh you know conversations of AI safety and compliance, there's still the human in the middle that keeps things on rail so that we can continue to scale and grow.
Dawn
Yep, exactly. The answer doesn't have to be complicated. You know, you can literally put it in writing. So as far as who owns it, you know, at the bottom of your policies, who's the policy owner? Is it IT? Is it your director of HR? Who, you know, who is it? And that's really what we need to know. So everyone knows in the organization who owns this piece.
Rob
Yep. Yeah, who owns that piece. You know, just basically what I like to do is making sure we have we have a written out that the the security review that, you know, Jane or Mike owns this and it's detailed. Don't just put generic privacy owner. Um, you could put just you can put the I I like to actually have a name, the real name of the person. And yes, that means you have to change it sometimes, but I think that's more important than just an ambiguous compliance officer, right?
So Yep. And also, you know, when we take we take our customers through through an audit, you know, we we need evidence, evidence um that adheres to the controls. And sometimes the compliance team's, you know, IT person says, Oh, evidence. I need, I need a binder of something. I need, you know, and no, you don't. Um you need is you need evidence. It could be a policy, could absolutely be a policy, but it could be a BAA. It could be show me your your team is taking their annual training. It could be a screenshot. Show me how your your security is is is set up, meaning like, you know, MFA, password complexity, you know, that type of thing. Um, so that's really the difference between having a compliance program on paper and being able to defend your program is two different things. Yeah.
Rob
Yeah, those are two different things. Um, you just said something that's probably one of the biggest confidence killers is policy versus reality. There's a lot of people that just have policies, but it's not the reality of either organization works. Um, this is why you have to have those audit and you have to determine where everything is and w where everything goes and what you really are doing and what you're really not doing, and what's in scope and what's out of scope and all of that. And those are the key pieces that we see are big confidence killers in
Right. And with AI, I mean, you know, I'll kind of expand on that is is HIPAA and AI. You know, uh, where does AI fit in your organization? How are you how are you showing, how are you proving, you know, what data AI touches or doesn't touch, um, that type of thing. So what other things and, you know, should they look for with that? Because AI is a big hot topic right now. Um, it is.
Rob
And then AI safety is a big thing. But it's also very exploded out of proportion. Um, you know, I think that has potential for the US market, for businesses, for creators, for people to create amazing new businesses, to stand up businesses they never were able to do and and help the economy. Um, and I think the AI safety is a little bit blown out of proportion, even from a compliance standpoint. Um, meaning that what we need to do is teach it, you know, give it the guard guardrails that we need, make sure things are in the right places, uh, roll it out effectively, but don't stop the don't stop the growth. I think it continues to to go forward. And you need this is where you need to lead with confidence is in the AI safety, making sure do you have, yeah, you have a policy, but is it actually doing what it's supposed to be going? Making sure you're verifying the steps, make sure you're doing everything that it needs to be done so that you can continue to expand AI. It's not going to go away. This is, you know, it's kind of like the internet, but it's just quicker and faster. Um, and it has so much capabilities that we need to make sure that we embrace and not just throw some political pundit at it thinking that, oh well, we can't do it because it's unsafe. Yeah. They probably said that about planes, right? Probably say that about ships, boats, cars. Yep. Probably sell that about electricity. Yeah. Imagine a world with electricity, really. Yeah. So you just you just need to to this is where you do your audit, your AI audits, you look at it all, and then you see how can it solve the problems and always keep in that kind of that human in the middle to check.
Dawn
Yep, absolutely. And that's where third-party vendor management comes into play as well. Um yeah. So AI needs to needs to be right up there is where is that data being stored? And what is that uh AI tool? What is their security posture? You know, it is we're we're talking on Monday. Um, our podcast comes out on Wednesday. So, you know, we're not saying try to fix the entire compliance program by Friday, you know, just pick something, pick something. If you're focused on AI, let's make sure we're, you know, vetting those AI vendors, making sure that you're using AI within guardrails, using it appropriately. Make sure your team knows how to use it. And then, you know, so that goes along with BAAs with HIPAA compliance. Do you have BAs with those that you need BAs with? So let's, you know, make sure we have that. So pick something. Pick something that that you see in your organization is a risk and work on it. Um, and you know, work on it till completion, you know, until you've resolved the risk or you've identified it and resolved it, you've got solutions. Maybe not, maybe you don't resolve it this week, but maybe you've got a solution for it or a few solutions. So yeah, what are some other things that uh maybe are are quick things in your program that maybe you could look at this week? We just talked about AI governance, um, you know, BAs.
Rob
What are some other things that we could Yeah, BAs are key, making sure you have all those in place, but also doing that that vendor due diligence downstream from your business associate to their subcontractors down the road. Making sure those are dialed in. Those are those are the the keys. Uh making sure you're able to to um get back to where you are today at whole. You know, the standard frameworks of of backups and redundancy are still in place. They're still required. So nothing's changed there. So making sure that that's all done correctly and uh and and how you do it. So making sure that backups are put together, making sure they're set, uh, make sure they're tested. You know, it sounds okay to test backups, but they're written out of the law, but also it's the business. You've got to be able to roll back to to a previous state, especially as fast as as everything is gonna go, as it continues to go. Yeah.
Dawn
Yep. Yeah. So those are those are big things. AI, you know, AI governance, AI guardrails, BAs, backups, that type of thing. Um, you know, we could probably talk about AI all day because that's really what's on everyone's mind, you know. Um AI note takers. Talk a little bit about that. AI writing assistants, you know, talk a little bit about that.
Rob
Uh, you know, it's all getting processed now. Yeah. Is it Gemini? Is it granola? Is it G Zoom? They all do it.
Dawn
Um Fathom and Fathom, there's all those.
Rob
I think they're great, but they're great at taking the notes, but where's the data going? Is it being harvested to train their models? Is it just private? Um, those that's kind of where you you that's where the concern always is, is where does that data go to make sure um using it as needed and making sure we're within that regulatory direction uh and knowing how to how to how it's expanding and where it's really going.
Dawn
And remember, if you do add it to your your video conferencing, your note taker, remember everyone gets a copy of the transcription. Yeah. So you also have to be careful of what you share. And yes, the settings. It's very important to go into the settings. And are you gonna share it, share it to help the model, help others? It that's those are very important settings. And the settings are changing probably on a daily basis. So that's what you should be very, very careful with.
And you know, the the proposed HIPAA security rule changes. Um, you know, those are still proposed changes. So we talked a lot about that that last week, July. That's what it's gonna be. That's the date now, July of next year. Um, so yeah, Rob, do you want to highlight any anything else in regards to that? I think we've covered it pretty much. Yeah, we've covered it well.
Rob
I mean, I think the key pieces that that nothing's changed. Yeah, the security rule is still a security rule. It doesn't matter if the technology changed, the law is still there. Every bit of technology plugs into the law, and um, the law covers everything that's ever created from it's been 30 years old and it still incorporates everything that's been created. So those are the key pieces. Um and that's you know, that's what we'll we'll look after. But um, I think I'm more focused on what NIST is doing now and and their RMF 2.0 because there's a lot of good works we could put in there. And then all of your data in your controls, your control access.
Dawn
Yeah. And and remember, if you're already, if you're already meeting current requirements of HIPAA compliance, you're already in a much better position. And so whenever the final rule, whatever it looks like, you've already been adhering to the controls. So it shouldn't be the only thing that, you know, maybe a, maybe a change is uh, you know, the annual pen test. I mean, that's a that's a you know, it's an expense to to have, but it's it's very important. Um, but that's gonna be probably one of the biggest changes and that will help you see if you have new vulnerabilities in your network and that type of thing. But um, but you're already on your way if you're adhering to the current requirements. So um we'll wait to see. Um, those are proposed rules. You know, who knows what can happen over the next uh six months or so. But yeah, again, it's just lead your program, lead your program with confidence, implement, have the right people on your team, and really uh just don't be afraid
So yeah, those are the big pieces. I think to be able to be find that leader, find someone that owns it, find someone that's passionate about it, um, because there's regulation around it and there there is law. So um those are the those are the key pieces. Um so you're you know, when you're you're coaching the organization, you're not policing the organization. I need to make sure people are aware of who to contact and what to do and how to make sure that um that you're doing the right things and you're staying within the regulations and keeping things going.
Dawn
Yep, absolutely. That is the key. We like to say key here at uh at Van Ryan. So the key piece. That's um, but you know, just build a stronger compliance culture. It becomes it becomes a an everyday thing that you just that you do, and everyone knows and everyone knows who to go to and what to do. And that's a that's a really uh strong culture. So yeah.
So let's just kind of make it practical, right? Everybody just listened to this episode and they're they're about to go on up their day and then get back to work and all that, or driving and listening and all those fun things. Uh, what's one thing you want them to do, Don? What's one thing, what's your takeaway?
Dawn
Your takeaway is pick one of those things that uh a risk that you think that you need to really focus on. And that could be vendor management. It could be backups, um, access control, AI. Pick something this week. And I, you know, that's my challenge to you. Pick pick a risk that you have, that you were like, whoa, I need to work on this and sit down and work on it. Come up with some solutions. If it's just you, your team, and try to work on what the next steps are.
unknown
Yep.
Rob
Yep. Yeah, I think that's one of the big takeaways. Go back to your leadership team and say, what's the next 30 days are we gonna take? Right? What are we gonna do? What are we gonna the items we're gonna take off the table? What are we gonna add to the table? What is a risk from not only HIPAA compliance, PCI compliance, state level, federal law, international law, you
know what you're gonna do. And if there's questions, you don't know how to navigate those conversations, just let us know. We could do a 30-minute readiness review.
Dawn
Yep. And remember, confidence isn't being perfect. That doesn't mean confidence does not mean perfection that you've got everything in line. Confidence just means you know you've got a program, you've built it, and you're doing your best to implement it and you're taking it step by step.
Rob
So that's exactly what you do. And if you have more questions, you can just the link is in the uh in the show notes. You can book 30 minutes with Don or I. Um, write to the owners here at Van Ryan, and we can go ahead and help navigate you through your compliance complexities.
Dawn
That's correct.
Rob
Well, thank you guys for joining us again on the Van Ryan Compliance Podcast. I'm Rob.