- VanRein Compliance
- Posts
- Ready for What's Next
Ready for What's Next
ChiroFest and a new HIPAA course, emerging risks, changing expectations, and technology.
Ready for What's Next:
What Breaks When Your Stack Changes
September started loud. Safeguarding Health Information. Wrap-ups. Leadership talk.
Dawn's calendar for the week of Sep 21 turns the page again: Ready for What's Next, emerging risks, changing expectations, technology, and building resilient compliance programs.
If you own privacy, security, or readiness, that title is not abstract. It is the Tuesday after the conference badge comes off. New tools land. Vendors change. Someone asks for proof. The stack you had last quarter is not the stack you have this morning.
Ready for what's next is not a slogan. It is knowing what still works when the tool, the vendor, or the threat changes.
Three places programs break when "next" arrives
1. Inventory that trails the stack
Marketing buys a platform. Ops spins up an AI helper. A contractor gets a portal. If it can see ePHI and it is not on the inventory, with a BAA where required, you do not have innovation. You have a finding waiting.
Put every system that can touch ePHI on the list. Then keep the list true.
2. Expectations that outrun the evidence
Boards want assurance. Partners want questionnaires answered. The proposed Security Rule rewrite (RIN 0945-AA22) is still a proposal. July 2027 on the Unified Agenda is a planning estimate, not a statute. It can move again.
The current Security Rule remains in force. Risk analysis that is missing, stale, or "executive summary only" was already a problem before the conference season, and it still is. Encryption moving from addressable to required in a proposal is still "would," not "is." Build proof against the rule you are under today.
3. Technology mistaken for a program
A new control deck does not replace named owners, dated BAAs, tested restores, and decisions that leave a trail. Tools restart systems. Cadence restarts discipline.
What resilience looks like this week
Pick one. Do not stack five:
Name the owner of your risk analysis in writing: person, next date, evidence location.
Pull the vendor list. Mark anything with no BAA last-reviewed date.
Restore one backup. Write how long it took.
List every AI tool in use that can see PHI. If it is not on the inventory, put it there.
Ask one critical vendor: where does the data live, and who owns the access/crypto plan?
That is how a program absorbs change without becoming a binder you hope survives.
If you want a second set of eyes on which of those five is your real gap, book 30 minutes with us. No deck. A punch list you can use this quarter.





Reply