CompyMax

About CompyMax

We publish researched HIPAA compliance verdicts — 47 and counting, each sourced from vendor documentation and dated — and build the software that turns a compliance programme into evidence a client will accept. The research is free and carries no affiliate links; the software is how we make money. Keeping those two things separate is the whole model.

How the research is produced, sourced and corrected is documented in our editorial standards. Last updated .

The team

Compliance officers, practicing clinicians, security professionals and healthcare counsel. Where a team member reviews checker entries in their area, the entry says so by name.

Margaret O'Brien

HIPAA Privacy Officer

Eighteen years in healthcare compliance, including hospital risk management and leading breach response for two major health systems. Focuses on Privacy Rule interpretation and policy development.

Dr. James Whitmore, MD

Chief Medical Officer, practicing orthopedic surgeon

Twenty-two years of clinical experience. Champions data security as a patient-safety issue and leads provider training on secure communication and minimum-necessary access.

Lisa Tran, CISSP

Healthcare Information Security Executive

Fifteen years in cybersecurity for covered entities and business associates. Specializes in encryption, access controls and vulnerability assessment.

Robert Hayes, CHC, CHPC

Compliance Director, multi-state medical group

Has worked through more than forty OCR audits and investigations. Focuses on risk analysis, corrective action plans and remediation strategy.

Dr. Anita Desai, MD

Psychiatrist, solo private practice

Fourteen years in private practice. Works on the privacy problems specific to behavioral health, where confidentiality expectations run highest.

Carlos Mendez

IT Security Manager, regional healthcare network

Twelve years in network security, breach prevention and incident response. Leads annual security risk assessments and workforce security awareness training.

Susan Caldwell, JD

General Counsel and Compliance Officer, health IT vendor

Twenty years of healthcare law across HIPAA, HITECH and state privacy regulation. Negotiates business associate agreements and advises on data sharing.

Dr. Rachel Foster, MD

Pediatrician and small practice owner

Ten years of clinical experience. Works on minor-patient record protection and consent, and on keeping a small practice's documentation current without a compliance department.

David Kim

Billing and RCM Operations Director

Thirteen years in medical revenue cycle management, at the intersection of HIPAA and billing compliance: secure claims transmission and patient authorization workflows.

Patricia Monroe

Healthcare consultant, former OCR investigator

Twenty-five years of regulatory experience, including inside the enforcement process. Advises practices on HIPAA readiness, breach notification and policy implementation.

Contact

Questions, corrections or anything else: support@hipaacompliancesoftware.org. Corrections to published research are made with a dated note in the entry’s change history, never silently.