Lead with Confidence: HIPAA, AI & Knowing Who Owns What

Practical guidance for leaders responsible for compliance: ownership, evidence, and decisions you can defend.

Team VRC is LIVE at ASTAA 2026!

We're on the ground in Baltimore for the Atlantic States Telephone Answering Association's annual conference, talking HIPAA, AI compliance, and everything in between.

From the booth to Rob's session on closing the AI compliance gap in your TAS, Team VRC is ready to connect, learn, and bring practical compliance solutions that move TAS providers forward.

If you're here, come find us and spin our Wheel of Risk! 🎡
If not, we're bringing the insights (and the swag) back with us.

Let's make compliance clearer, stronger, and more manageable together!


Last week we debriefed what we heard at Safeguarding Health Information. This week the calendar turns the page.

Dawn's theme for the week of Sep 14 is simple and hard: Lead With Confidence, practical guidance for leaders responsible for compliance.

If that title feels like it was written for you, it probably was. Privacy officer. Security officer. Compliance lead. Practice admin who inherited HIPAA when someone left. Consultant who has to translate "we should be fine" into something that survives a request for proof.

Confidence is not a mood. It is not a binder. It is knowing who owns the decision, what evidence backs it, and how you coach a team when the answer is not on a slide.

Three Places Leaders Lose the Plot

1. Ownership that lives in someone's head
Tasks get done. Nobody owns them. Approvals live in email. Exceptions get waved through under pressure. When OCR (or a board, or a buyer) asks who decided, the room goes quiet.

Write it down. Person. Next date. Where the evidence lives. That is leadership, not bureaucracy.

2. Policy that says one thing and practice that does another
Coverage weeks, vendor swaps, "just this once" workarounds happen. Then the doc never catches up. Maturity is alignment, not a longer policy.

Confirm how the work is actually done. Update the doc, or retrain the behavior. Do not pretend the gap is a branding problem.

3. Waiting for a future rule before fixing today's gaps
The proposed Security Rule rewrite (RIN 0945-AA22) is still a proposal. July 2027 is a planning estimate on the Unified Agenda, not a statute. It can move again. Encryption moving from addressable to required is still "would," not "is."

The current Security Rule remains in force. Risk analysis that is missing, stale, or "executive summary only" was already a finding before the conference, and it still is. AI tools that touch ePHI already sit under the Security Rule like any other system. BAA before the vendor. Inventory before the policy poster.

What leading with confidence looks like this week

Pick one. Do not stack five:

  • Name the owner of your risk analysis in writing: person, next date, evidence location.

  • Pull the vendor list. Mark anything with no BAA last-reviewed date.

  • Restore one backup. Write how long it took.

  • List every AI tool in use that can see PHI. If it is not on the inventory, put it there.

  • Ask one critical vendor: where does the data live, and who owns the crypto plan?

That is not a training checklist for the sake of training. That is how a leader turns noise into a program that can answer for itself.

If you want structured depth for the people who run the program, we built HIPAA for Compliance Officers for exactly that seat, practical program leadership, not a one-time slide deck:

If you want a second set of eyes on which of those five is your real gap, book 30 minutes with us. No deck. A punch list you can use this quarter.

Reply

or to participate.