Tools

Compliance tools, not just commentary.

Practical instruments for the work of running a compliance program, built from primary regulatory sources and designed to be used, not just read.

Federal + California · OIG LEIE & Medi-Cal

Exclusion & Sanctions Screening Tracker

Screen staff, clinicians, contractors, and vendors against the OIG exclusion list (LEIE) and the Medi-Cal Suspended and Ineligible list. Upload a roster or check one name; runs entirely in your browser with recheck reminders on the OIG cadence.

100k+ exclusion records · Roster upload + quick check
Open tracker
OIG Enforcement · Analytics

Corporate Integrity Agreements Dashboard

Filter and explore active HHS OIG Corporate Integrity Agreements from 2023–2026: violation summaries, the material obligations each one imposes, and the lesson for your own program.

66 CIAs · ~$2.70B in settlements
Open dashboard
Privacy · Breach Notification

Breach Notification Risk Assessment

A process-flow overview plus three modules (HIPAA, CMIA/HSC §1280.15, and Civil Code §1798.82) with rationale, citations, and draft notification letters, a worksheet that drafts your HHS OCR Breach Portal submission, and a 50-state reference table.

3 modules + combined plan · Portal-ready worksheet
Open assessment
GCPG 2023 · Program Self-Assessment

Seven Elements Self-Scoring

Score your compliance program against the OIG's seven elements from the 2023 General Compliance Program Guidance: a four-level maturity scale per statement, a color-banded scorecard, and an auto-generated gap summary you can copy or print.

36 scoring questions · 7 elements + 2023 updates
Open self-scoring tool
Policies · Document Builder

Compliance & Privacy Policy Builder

Complete one intake form and generate three customized policy libraries: Privacy (HIPAA Privacy, breach notification, California overlays), Security (the Security Rule safeguards), and Compliance (OIG seven-elements program policies), each policy with citations and a regulatory currency status.

3 libraries · 37 policies · Print-ready per policy
Open policy builder
Checklists

Gap checklists, rule by rule

Work through the regulation text item by item, check off what's in place, and copy a gap summary. Progress saves in your browser.

Security Rule · Compliance Checklist

HIPAA Security Rule Checklist

A save-as-you-go checklist covering the current Security Rule (45 CFR §§164.308–164.316) alongside the cybersecurity changes proposed in HHS's 2025 NPRM. Filter to audit today's obligations, preview the proposed rule, or see both with citations.

79 checklist items · Current Rule + NPRM Proposed
Open checklist
Privacy Rule · Gap Checklist

HIPAA Privacy Rule Checklist

A save-as-you-go gap checklist across uses and disclosures, individual rights, the Notice of Privacy Practices, business associates, and administrative requirements, with clear status flags for the 2024 reproductive health amendments after Purl v. HHS.

78 checklist items · Binding + 2024 status flags
Open checklist
42 CFR Part 2 · SUD Records

Part 2 Alignment Checklist

Align substance use disorder record handling with the 2024 Part 2 final rule: consent, redisclosure, counseling notes, and breach notification, with separate views for Part 2 programs and recipients. OCR civil enforcement has been live since February 16, 2026.

50 checklist items · Program + recipient views
Open checklist
California · CMIA & Overlays

California Health Privacy Checklist

Layer California on top of the HIPAA baseline: CMIA authorizations, the AB 352/AB 254 sensitive-services and digital health rules, and the state breach notification clocks that run faster than the federal one.

44 checklist items · CMIA + AB 352/254 + breach
Open checklist
AI & Emerging Tech · Vendor Risk

AI Vendor Risk Assessment

Assess ambient scribes, AI coding tools, and LLM vendor products before they touch PHI: BAA terms for training-on-data and model retention, de-identification claims tested against 45 CFR 164.514, and California's AB 3030, AB 489, and SB 1120 clinical rules.

47 checklist items · Contract + clinical + governance
Open checklist
WA · NV · CT · Consumer Health Data

Multi-State Consumer Health Data Checklist

The health privacy laws that reach past HIPAA: Washington's My Health My Data Act and its private right of action, Nevada SB 370, and the Connecticut Data Privacy Act. In all three the HIPAA exemption is data-level, not entity-level.

45 checklist items · Per-state + shared views
Open checklist
In development

More tools on the way

More tools are in development and will appear here as they're ready.

Tools published here draw on publicly available regulatory sources and are provided for general compliance-learning purposes. They are not legal advice. Brandon Goulter is not an attorney, and using these tools creates no professional advisory relationship. Verify current requirements against primary sources and a licensed attorney before acting.