Author: corestream-adm
-

Healthcare compliance and HIPPA
Read more: Healthcare compliance and HIPPAWhat is healthcare compliance and HIPAA? Healthcare compliance is the process of meeting the laws, regulations, standards, policies, ethical rules, and patient safety requirements that apply to healthcare organizations. HIPAA, often misspelled as HIPPA, is 1 of the most important healthcare compliance laws in the United States because it sets rules for protecting health information…
-

Audit management
Read more: Audit managementWhat is audit management? Audit management is the process of planning, coordinating, executing, documenting, reporting, and tracking audits from start to finish. It gives organizations a structured way to decide what should be audited, why it matters, what evidence is needed, who owns findings, and how remediation is tracked through to closure. In governance, risk,…
-

Beyond the RAG chart: effective GRC reporting at board-level
Read more: Beyond the RAG chart: effective GRC reporting at board-levelKey takeaways Introduction: from static snapshot to compliance story Picture a typical quarterly board pack. The compliance slide shows 98% green, no red flags and no open questions, so the board moves on within a few minutes. Then, months later, a control failure that had in fact been recurring quietly for a year surfaces as a genuine incident, and the first question anyone asks…
-

Health compliance: how to manage HIPAA, HITRUST, AI Governance and Open Payments
Read more: Health compliance: how to manage HIPAA, HITRUST, AI Governance and Open PaymentsKey takeaways for overlapping healthcare compliance requirements in North America Introduction: why is healthcare compliance becoming harder to manage? Healthcare compliance teams are no longer managing one major requirement at a time. They are dealing with HIPAA, HITECH, HITRUST, cyber risk, AI governance, Open Payments, conflict of interest and internal oversight at once. Those expectations…
-

Spotlight on Women in GRC: Sophie Walsh on trust, risk, and the Future of outcome-based GRC
Read more: Spotlight on Women in GRC: Sophie Walsh on trust, risk, and the Future of outcome-based GRCIn a recent Spotlight on Women in GRC podcast, Lucy Montague sat down with Global Director of Trust & Safety, Sophie Walsh, a risk, integrity and compliance leader whose career spans charities, global technology platforms, and some of the most complex risk environments in modern business. From social care and NGOs to digital regulation and e-commerce, Sophie’s work has been guided…
-

General Data Protection Regulation (GDPR) and Data Privacy management
Read more: General Data Protection Regulation (GDPR) and Data Privacy managementWhat is GDPR and Data Privacy management? The General Data Protection Regulation (GDPR) is the EU data protection law that governs how organizations collect, use, store, share, protect, and delete personal data. Data privacy management is the ongoing process organizations use to meet GDPR and other privacy obligations in practice. In governance, risk, and compliance…
-

Compliance audit
Read more: Compliance auditWhat is a compliance audit? A compliance audit is a structured review that checks whether an organization is meeting specific laws, regulations, standards, policies, contractual requirements, or internal controls. It helps confirm whether compliance requirements are understood, owned, evidenced, and operating in practice. In governance, risk, and compliance (GRC), a compliance audit matters because it…
-

Compliance reporting
Read more: Compliance reportingWhat is compliance reporting? Compliance reporting is the process of collecting, analyzing, and presenting information that shows whether an organization is meeting its compliance obligations. It helps leadership, boards, auditors, regulators, and internal stakeholders understand compliance status, control effectiveness, issues, breaches, remediation, and areas needing attention. In governance, risk, and compliance (GRC), compliance reporting matters…
-

Compliance management software
Read more: Compliance management softwareWhat is compliance management software? Compliance management software is a digital system that helps organizations manage compliance obligations, controls, policies, evidence, issues, remediation, and reporting in 1 connected place. It gives compliance teams a clearer way to understand what requirements apply, who owns them, what actions are due, and what evidence proves compliance activity has…
-

Too much faith in frameworks: The governance limits of industry standard certifications
Read more: Too much faith in frameworks: The governance limits of industry standard certificationsKey takeaways Introduction: when GRC certification becomes destination At a recent CoreStream GRC webinar on the modern CISO’s compliance stack, the panel was asked a blunt question: are there any regulations, frameworks or certifications that organizations place too much faith in? Tom Cornelius, founder of the Secure Controls Framework and senior partner at ComplianceForge, didn’t hesitate. He named SOC 2 and ISO 27001 directly, and called the market that…