VanRein Compliance Podcast

Rob & Dawn Van Buskirk

Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.

  1. 4d ago

    ChiroFest 2026 - What Chiropractors Need to Know About Compliance

    Send us Fan Mail HIPAA can feel like background noise in a busy chiropractic practice until a phone slip, a rushed front-desk moment, or a vendor breach makes it painfully real. After coming back from ChiroFest, we sit down with Emma from our team to talk about what we heard from chiropractors across the Pacific Northwest and what clinics are still missing when it comes to HIPAA compliance, patient privacy, and audit readiness. We dig into the patterns we saw on the expo floor and in real conversations: offices doing “something” but not the right things, teams relying on paper, and owners exhausted from trying to DIY policies, procedures, and training. We explain why staff training is the best first move if you want quick wins, fewer near-misses, and a clinic culture that actually knows how to handle PHI and ePHI day to day. We also share what makes training work in a chiropractic setting: realistic scenarios, short modules, simple quizzes, and proof of completion. Then we get blunt about vendor risk. New EHRs, AI tools, schedulers, and integrations can expand your exposure fast, and a “HIPAA compliant” seal on a website does not equal real safeguards. We talk about asking hard questions, looking for a trust center, and using vendor questionnaires so you know who is touching your data and what happens when something goes wrong. If you want to reduce risk without overwhelm, hit play, share this with a practice owner, and subscribe for more practical compliance guidance. If the episode helps, leave a review and tell us what HIPAA question you want answered next. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  2. Sep 16

    Lead with Confidence: HIPAA, AI & Knowing Who Owns What

    Send us Fan Mail HIPAA compliance has a way of becoming your job without asking permission, and that’s when panic usually sets in. We take a different angle: confidence isn’t perfection and it definitely isn’t memorizing regulations. For us, confidence comes from clarity you can prove later, knowing who owns decisions, what got approved, and how to show evidence six months from now when an auditor or customer asks.  We dig into the places where compliance programs get shaky fast: vendor management and third-party risk. When IT, Legal, Compliance, and Procurement all point at each other, the risk ends up owned by nobody. We explain how to assign a real owner, document the workflow, and keep Business Associate Agreements and vendor due diligence from becoming an endless loop. From there we get practical about “evidence” and what actually holds up: policies, training records, screenshots of MFA and access controls, and documentation that matches how work happens day to day.  Then we tackle the biggest hot button right now: AI governance for healthcare and HIPAA-regulated teams. AI note takers, writing assistants, and meeting transcription tools can be powerful, but the real questions are where the data goes, what settings quietly share it, and whether the vendor’s security posture matches your risk tolerance. We also ground the conversation in fundamentals that never go away: backups, redundancy, testing, and staying aligned with the HIPAA Security Rule even as proposed updates evolve.  If you found this helpful, subscribe and share it with the person who just inherited compliance. Leave a review, and tell us what risk you’re tackling first this week. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  3. Sep 2

    What We're Listening for at this Week's HHS + NIST HIPAA Security Conference

    Send us Fan Mail A major HIPAA reset is brewing, and the timing couldn’t be more urgent. We’re headed to the HHS, OCR, and NIST Safeguarding Health Information conference to hear directly from the people shaping what “good” looks like for HIPAA Security Rule compliance in 2026 and beyond, and we’re sharing exactly what we’re listening for. We talk through the likely headline items: OCR updates after a long gap, a stronger push toward risk analysis that behaves like a real audit, and the patterns OCR keeps calling out when organizations fall short. We also dig into the controls that keep coming up in real enforcement and real breaches: multi-factor authentication, penetration testing, incident response planning, and disaster recovery testing. If your security work is still “we did it once and filed it,” this conversation is your nudge to build ongoing evidence and remediation into the way you operate. Then we zoom out to the messy, modern reality of healthcare data. Vendor risk management is still a huge weak spot, especially as third parties, subprocessors, and AI tools multiply the paths ePHI can travel. We also get nerdy about what’s next with AI in healthcare, the NIST AI Risk Management Framework, and why regulation will struggle to keep pace. And we don’t ignore the physical world: medical device cybersecurity and IoT mean ePHI no longer lives only inside an EHR or EMR. Subscribe so you don’t miss our post-conference breakdown, and if this helped, share it with a teammate and leave a quick review so more healthcare teams can find it. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  4. Aug 26

    The Compliance Landscape: 26 Years of Change

    Send us Fan Mail The compliance landscape has changed more in the last 26 years than most leaders want to admit and somehow the basics still win. We connect the dots between real-world HIPAA enforcement and what actually holds up when something goes wrong: evidence. Not a binder. Not a trust center page. Proof that you know your systems, control access, manage vendors, and can recover fast. We start with the HIPAA Security Rule and why its administrative, physical, and technical safeguards still define the floor for protecting ePHI. Then we unpack the 2013 Omnibus Rule and the moment business associates stop being “adjacent” to HIPAA and become directly accountable. We clarify covered entity vs business associate, why incidental contact still counts, and how to use business associate agreements the right way without stuffing them full of unrelated cybersecurity obligations. From there we look forward to HHS’s proposed HIPAA Security Rule rewrite and the themes leaders should already be planning around: multi-factor authentication, encryption, asset inventories, network maps and data flows, vulnerability scanning, penetration testing, stronger recovery expectations, and heavier documentation. To make it real, we pull up the HIPAA Wall of Shame and talk through the patterns that keep showing up: hacking, email compromise, and exposed servers impacting organizations of every size. We close with what to do now: name an owner, build a repeatable rhythm, tighten access control and third party oversight, add AI guardrails to policies, and test backups and incident response until you can prove it works. Subscribe for updates on what HHS announces next, share this with the person who owns compliance at your company, and leave a review with your biggest HIPAA challenge so we can tackle it next. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  5. Aug 19

    26 Years: Life, Leadership & Legacy

    Send us Fan Mail Twenty-six years goes fast when you’re building a life, not just chasing wins. Rob and Don celebrate their anniversary by getting honest about what actually holds up over decades: setbacks you didn’t plan for, career pivots you didn’t want, and the daily choice to keep moving forward without keeping score. We trace the through-line from marriage to leadership to business, including why “legacy” has nothing to do with leaving a pile of stuff behind. For us, legacy means the values, stories, and skills we pass to our son and to the team we get to lead. Along the way, we share practical lessons for entrepreneurs, small business owners, and growing teams who want more trust and less chaos, including how role clarity turns conflict into traction. A big part of that clarity is naming the lanes: visionary and integrator, strategy and operations, ideas and execution. That same discipline shows up in strong compliance programs, too. Whether you’re thinking about HIPAA compliance, staying audit-ready, or simply running a business that doesn’t burn you out, clear ownership and good communication reduce risk and make it easier to scale. We also talk about presence as a real leadership skill, especially in a phone-saturated culture and a remote-work world. If you want a stronger relationship, a healthier team culture, and a business built for the long game, this one will hit home. Subscribe, share this with a builder in your life, and leave a review with the season you’re in right now. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  6. Aug 12

    18 Years to Get Ready: What Sending Our Son to College Taught Us About Leadership

    Send us Fan Mail Sending our son off to college makes leadership feel personal, and it forces us to practice trust instead of control. We connect parenting, team management, and compliance by focusing on guardrails, good judgment, and the freedom to fail forward.  • Watching an 18-year-old build independence through deadlines, decisions, and preparation  • Seeing what kids learn from what we model, not just what we say  • Letting go to grow, at home and at work  • Giving teams tools and guardrails instead of relying on massive SOPs  • Hiring the right people so they can make decisions without constant approval  • Normalizing mistakes and coaching toward “fail forward” learning  • Asking “what’s your solution?” to build ownership and problem-solving  • Being available as leaders without staying in control  • Using weekly cadence and check-ins to create clarity without micromanagement  • Blaming the process first, then addressing repeated issues as people issues  • Connecting compliance culture to everyday decisions across HIPAA, SOC 2, ISO, HITRUST, GDPR  • Using the grocery cart question as a simple integrity signal  • Setting expectations for grades and communication, then trusting the next season  Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  7. Aug 5

    Why We Built Two New HIPAA Certifications

    Send us Fan Mail Two new HIPAA certifications are launching, and we built them for one reason: most “HIPAA training” proves attendance, not capability. We see smart, capable people get handed the compliance binder and suddenly they are the privacy officer, security lead, or HIPAA compliance officer with real legal and operational responsibility. That is a risky place to be for you and for your organization, especially when auditors expect evidence, not intentions.  We walk through our new professional credentials, Certified HIPAA Privacy Associate and Certified HIPAA Compliance Officer, and explain exactly who each path fits. The Privacy Associate track is for healthcare professionals and business associates who need practical HIPAA knowledge to make good decisions, spot problems early, and escalate issues correctly. The Compliance Officer track goes deeper into running a HIPAA compliance program: risk analysis methodology, breach response, policy ownership, training oversight, corrective action plans, and how to show proof during an audit.  We also dig into the modern reality of HIPAA compliance: vendor sprawl, downstream subcontractors, and AI in healthcare. If your team is connecting tools, experimenting with public AI, or relying on “my IT vendor handles it,” you need stronger governance, clearer questions, and better documentation. If you want credible HIPAA certification that supports audit readiness, risk management, and career growth, this is your roadmap.  Subscribe for more practical compliance guidance, share this with the person who just got assigned HIPAA, and leave a review with the question you want us to tackle next. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

5
out of 5
11 Ratings

About

Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.