VanRein Compliance Podcast

Rob & Dawn Van Buskirk

Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.

  1. 1d ago

    Lead with Confidence: HIPAA, AI & Knowing Who Owns What

    Send us Fan Mail HIPAA compliance has a way of becoming your job without asking permission, and that’s when panic usually sets in. We take a different angle: confidence isn’t perfection and it definitely isn’t memorizing regulations. For us, confidence comes from clarity you can prove later, knowing who owns decisions, what got approved, and how to show evidence six months from now when an auditor or customer asks.  We dig into the places where compliance programs get shaky fast: vendor management and third-party risk. When IT, Legal, Compliance, and Procurement all point at each other, the risk ends up owned by nobody. We explain how to assign a real owner, document the workflow, and keep Business Associate Agreements and vendor due diligence from becoming an endless loop. From there we get practical about “evidence” and what actually holds up: policies, training records, screenshots of MFA and access controls, and documentation that matches how work happens day to day.  Then we tackle the biggest hot button right now: AI governance for healthcare and HIPAA-regulated teams. AI note takers, writing assistants, and meeting transcription tools can be powerful, but the real questions are where the data goes, what settings quietly share it, and whether the vendor’s security posture matches your risk tolerance. We also ground the conversation in fundamentals that never go away: backups, redundancy, testing, and staying aligned with the HIPAA Security Rule even as proposed updates evolve.  If you found this helpful, subscribe and share it with the person who just inherited compliance. Leave a review, and tell us what risk you’re tackling first this week. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  2. Sep 2

    What We're Listening for at this Week's HHS + NIST HIPAA Security Conference

    Send us Fan Mail A major HIPAA reset is brewing, and the timing couldn’t be more urgent. We’re headed to the HHS, OCR, and NIST Safeguarding Health Information conference to hear directly from the people shaping what “good” looks like for HIPAA Security Rule compliance in 2026 and beyond, and we’re sharing exactly what we’re listening for. We talk through the likely headline items: OCR updates after a long gap, a stronger push toward risk analysis that behaves like a real audit, and the patterns OCR keeps calling out when organizations fall short. We also dig into the controls that keep coming up in real enforcement and real breaches: multi-factor authentication, penetration testing, incident response planning, and disaster recovery testing. If your security work is still “we did it once and filed it,” this conversation is your nudge to build ongoing evidence and remediation into the way you operate. Then we zoom out to the messy, modern reality of healthcare data. Vendor risk management is still a huge weak spot, especially as third parties, subprocessors, and AI tools multiply the paths ePHI can travel. We also get nerdy about what’s next with AI in healthcare, the NIST AI Risk Management Framework, and why regulation will struggle to keep pace. And we don’t ignore the physical world: medical device cybersecurity and IoT mean ePHI no longer lives only inside an EHR or EMR. Subscribe so you don’t miss our post-conference breakdown, and if this helped, share it with a teammate and leave a quick review so more healthcare teams can find it. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  3. Aug 26

    The Compliance Landscape: 26 Years of Change

    Send us Fan Mail The compliance landscape has changed more in the last 26 years than most leaders want to admit and somehow the basics still win. We connect the dots between real-world HIPAA enforcement and what actually holds up when something goes wrong: evidence. Not a binder. Not a trust center page. Proof that you know your systems, control access, manage vendors, and can recover fast. We start with the HIPAA Security Rule and why its administrative, physical, and technical safeguards still define the floor for protecting ePHI. Then we unpack the 2013 Omnibus Rule and the moment business associates stop being “adjacent” to HIPAA and become directly accountable. We clarify covered entity vs business associate, why incidental contact still counts, and how to use business associate agreements the right way without stuffing them full of unrelated cybersecurity obligations. From there we look forward to HHS’s proposed HIPAA Security Rule rewrite and the themes leaders should already be planning around: multi-factor authentication, encryption, asset inventories, network maps and data flows, vulnerability scanning, penetration testing, stronger recovery expectations, and heavier documentation. To make it real, we pull up the HIPAA Wall of Shame and talk through the patterns that keep showing up: hacking, email compromise, and exposed servers impacting organizations of every size. We close with what to do now: name an owner, build a repeatable rhythm, tighten access control and third party oversight, add AI guardrails to policies, and test backups and incident response until you can prove it works. Subscribe for updates on what HHS announces next, share this with the person who owns compliance at your company, and leave a review with your biggest HIPAA challenge so we can tackle it next. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  4. Aug 19

    26 Years: Life, Leadership & Legacy

    Send us Fan Mail Twenty-six years goes fast when you’re building a life, not just chasing wins. Rob and Don celebrate their anniversary by getting honest about what actually holds up over decades: setbacks you didn’t plan for, career pivots you didn’t want, and the daily choice to keep moving forward without keeping score. We trace the through-line from marriage to leadership to business, including why “legacy” has nothing to do with leaving a pile of stuff behind. For us, legacy means the values, stories, and skills we pass to our son and to the team we get to lead. Along the way, we share practical lessons for entrepreneurs, small business owners, and growing teams who want more trust and less chaos, including how role clarity turns conflict into traction. A big part of that clarity is naming the lanes: visionary and integrator, strategy and operations, ideas and execution. That same discipline shows up in strong compliance programs, too. Whether you’re thinking about HIPAA compliance, staying audit-ready, or simply running a business that doesn’t burn you out, clear ownership and good communication reduce risk and make it easier to scale. We also talk about presence as a real leadership skill, especially in a phone-saturated culture and a remote-work world. If you want a stronger relationship, a healthier team culture, and a business built for the long game, this one will hit home. Subscribe, share this with a builder in your life, and leave a review with the season you’re in right now. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  5. Aug 12

    18 Years to Get Ready: What Sending Our Son to College Taught Us About Leadership

    Send us Fan Mail Sending our son off to college makes leadership feel personal, and it forces us to practice trust instead of control. We connect parenting, team management, and compliance by focusing on guardrails, good judgment, and the freedom to fail forward.  • Watching an 18-year-old build independence through deadlines, decisions, and preparation  • Seeing what kids learn from what we model, not just what we say  • Letting go to grow, at home and at work  • Giving teams tools and guardrails instead of relying on massive SOPs  • Hiring the right people so they can make decisions without constant approval  • Normalizing mistakes and coaching toward “fail forward” learning  • Asking “what’s your solution?” to build ownership and problem-solving  • Being available as leaders without staying in control  • Using weekly cadence and check-ins to create clarity without micromanagement  • Blaming the process first, then addressing repeated issues as people issues  • Connecting compliance culture to everyday decisions across HIPAA, SOC 2, ISO, HITRUST, GDPR  • Using the grocery cart question as a simple integrity signal  • Setting expectations for grades and communication, then trusting the next season  Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  6. Aug 5

    Why We Built Two New HIPAA Certifications

    Send us Fan Mail Two new HIPAA certifications are launching, and we built them for one reason: most “HIPAA training” proves attendance, not capability. We see smart, capable people get handed the compliance binder and suddenly they are the privacy officer, security lead, or HIPAA compliance officer with real legal and operational responsibility. That is a risky place to be for you and for your organization, especially when auditors expect evidence, not intentions.  We walk through our new professional credentials, Certified HIPAA Privacy Associate and Certified HIPAA Compliance Officer, and explain exactly who each path fits. The Privacy Associate track is for healthcare professionals and business associates who need practical HIPAA knowledge to make good decisions, spot problems early, and escalate issues correctly. The Compliance Officer track goes deeper into running a HIPAA compliance program: risk analysis methodology, breach response, policy ownership, training oversight, corrective action plans, and how to show proof during an audit.  We also dig into the modern reality of HIPAA compliance: vendor sprawl, downstream subcontractors, and AI in healthcare. If your team is connecting tools, experimenting with public AI, or relying on “my IT vendor handles it,” you need stronger governance, clearer questions, and better documentation. If you want credible HIPAA certification that supports audit readiness, risk management, and career growth, this is your roadmap.  Subscribe for more practical compliance guidance, share this with the person who just got assigned HIPAA, and leave a review with the question you want us to tackle next. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

  7. Jun 17

    Why We Built VRC1 OS: The Operating System for Compliance

    Send us Fan Mail We’re launching VRC1 OS, our compliance operating system built to bring structure, clarity, and real visibility to programs that have become scattered across tools, email, and spreadsheets. We explain why compliance has to run like a business function, how AI can reduce friction without replacing judgment, and what growing teams should expect when they stop chasing audits and start operating compliance.  • why compliance feels fragmented across policies, training, evidence, risk, and audit communication  • why trust centers and “green lights” do not equal real security proof  • what VRC1 OS centralizes: tasks, evidence, policies, training visibility, risk readiness, audit prep, client communication, and framework alignment  • why compliance is ongoing and touches HR, IT, legal, leadership, operations, vendors, and client trust  • how a rhythm reduces fire drills and keeps accountability clear  • why humans still provide judgment while automation removes friction  • how AI governance, vendor oversight, and cyber insurance pressure raise the bar  • who VRC1 OS is for across HIPAA, SOC 2, ISO, HITRUST, and security readiness  If your company is ready or you want to dive a little bit deeper, stop chasing compliance and start operating it. We’d love to show you what we’re building and continue to invite you into the Van Ride family. Thank You for Listening to the VRC Podcast! Visit us at VanRein Compliance You can Book a 15min Call with a Guide Follow us on LinkedIn Follow us on X Follow us on Facebook

5
out of 5
11 Ratings

About

Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.