Practical instruments for the work of running a compliance program, built from primary regulatory sources and designed to be used, not just read.
Screen staff, clinicians, contractors, and vendors against the OIG exclusion list (LEIE) and the Medi-Cal Suspended and Ineligible list. Upload a roster or check one name; runs entirely in your browser with recheck reminders on the OIG cadence.
Open tracker → OIG Enforcement · AnalyticsFilter and explore active HHS OIG Corporate Integrity Agreements from 2023–2026: violation summaries, the material obligations each one imposes, and the lesson for your own program.
Open dashboard → Privacy · Breach NotificationA process-flow overview plus three modules (HIPAA, CMIA/HSC §1280.15, and Civil Code §1798.82) with rationale, citations, and draft notification letters, a worksheet that drafts your HHS OCR Breach Portal submission, and a 50-state reference table.
Open assessment → GCPG 2023 · Program Self-AssessmentScore your compliance program against the OIG's seven elements from the 2023 General Compliance Program Guidance: a four-level maturity scale per statement, a color-banded scorecard, and an auto-generated gap summary you can copy or print.
Open self-scoring tool → Policies · Document BuilderComplete one intake form and generate three customized policy libraries: Privacy (HIPAA Privacy, breach notification, California overlays), Security (the Security Rule safeguards), and Compliance (OIG seven-elements program policies), each policy with citations and a regulatory currency status.
Open policy builder →Work through the regulation text item by item, check off what's in place, and copy a gap summary. Progress saves in your browser.
A save-as-you-go checklist covering the current Security Rule (45 CFR §§164.308–164.316) alongside the cybersecurity changes proposed in HHS's 2025 NPRM. Filter to audit today's obligations, preview the proposed rule, or see both with citations.
Open checklist → Privacy Rule · Gap ChecklistA save-as-you-go gap checklist across uses and disclosures, individual rights, the Notice of Privacy Practices, business associates, and administrative requirements, with clear status flags for the 2024 reproductive health amendments after Purl v. HHS.
Open checklist → 42 CFR Part 2 · SUD RecordsAlign substance use disorder record handling with the 2024 Part 2 final rule: consent, redisclosure, counseling notes, and breach notification, with separate views for Part 2 programs and recipients. OCR civil enforcement has been live since February 16, 2026.
Open checklist → California · CMIA & OverlaysLayer California on top of the HIPAA baseline: CMIA authorizations, the AB 352/AB 254 sensitive-services and digital health rules, and the state breach notification clocks that run faster than the federal one.
Open checklist → AI & Emerging Tech · Vendor RiskAssess ambient scribes, AI coding tools, and LLM vendor products before they touch PHI: BAA terms for training-on-data and model retention, de-identification claims tested against 45 CFR 164.514, and California's AB 3030, AB 489, and SB 1120 clinical rules.
Open checklist → WA · NV · CT · Consumer Health DataThe health privacy laws that reach past HIPAA: Washington's My Health My Data Act and its private right of action, Nevada SB 370, and the Connecticut Data Privacy Act. In all three the HIPAA exemption is data-level, not entity-level.
Open checklist →More tools are in development and will appear here as they're ready.
Tools published here draw on publicly available regulatory sources and are provided for general compliance-learning purposes. They are not legal advice. Brandon Goulter is not an attorney, and using these tools creates no professional advisory relationship. Verify current requirements against primary sources and a licensed attorney before acting.