Twelve tools for health systems, provider networks, and health-tech teams, built from primary regulatory sources. Everything runs in your browser, and nothing you enter is transmitted or stored unless a card says otherwise.
Run a structured assessment and get back a scored, prioritized gap summary.
Three modules (HIPAA, CMIA/HSC §1280.15, Civil Code §1798.82) with rationale, citations, and draft notification letters, plus an HHS OCR Breach Portal worksheet and a 50-state reference table.
Score your program against the OIG's seven elements from the 2023 General Compliance Program Guidance. Feeds a color-banded scorecard and a gap summary you can copy or print.
Assess ambient scribes, AI coding tools, and LLM products across BAA terms, de-identification, §1557 and Colorado AI Act nondiscrimination, clinical rules, AKS/Stark, research, and records.
Resume screeners, video-interview scorers, and monitoring tools tested against Title VII, ADA, ADEA, EEOC vendor liability, NYC LL144, the Illinois AI Video Interview Act, and the Colorado AI Act.
Work through the regulation text item by item, check off what's in place, and copy a gap summary. Progress saves in your browser.
Covers the current Security Rule (45 CFR §§164.308–316) alongside HHS's 2025 NPRM cybersecurity changes. Filter to today's obligations, the proposed rule, or both.
Uses and disclosures, individual rights, the Notice of Privacy Practices, business associates, and administrative requirements, with status flags for the 2024 reproductive-health amendments after Purl v. HHS.
Aligns substance use disorder record handling with the 2024 Part 2 final rule: consent, redisclosure, counseling notes, and breach notification, with separate program/recipient views.
Layers California on top of the HIPAA baseline: CMIA authorizations, the AB 352/AB 254 sensitive-services and digital-health rules, and state breach clocks that run faster than the federal one.
The health privacy laws that reach past HIPAA: Washington's My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act. In all three the HIPAA exemption is data-level, not entity-level.
Screen against exclusion lists or explore active enforcement settlements.
Screen staff, clinicians, contractors, and vendors against the OIG exclusion list (LEIE) and the Medi-Cal Suspended and Ineligible list. Upload a roster or check one name, with recheck reminders on the OIG cadence.
Filter and explore active HHS OIG Corporate Integrity Agreements from 2023–2026: a violation summary, the material obligations each settlement imposes, and a plain read on what it means for your own program.
One intake form, three cited policy libraries.
Complete one intake form and generate three customized policy libraries: Privacy (HIPAA Privacy, breach notification, California overlays), Security (Security Rule safeguards), and Compliance (OIG seven-elements policies), each cited with a currency status.
More tools are in development and will appear here as they're ready.
Tools published here draw on publicly available regulatory sources and are provided for general compliance-learning purposes. They are not legal advice. Brandon Goulter is not an attorney, and using these tools creates no professional advisory relationship. Verify current requirements against primary sources and a licensed attorney before acting.