Key takeaways for overlapping healthcare compliance requirements in North America
- Healthcare compliance is becoming harder because HIPAA, HITRUST, AI governance, cyber risk, Open Payments, conflict of interest and internal oversight are continuously updating and overlapping.
- The harder part is not understanding each requirement but proving that controls are owned, operating, evidenced and improving.
- Healthcare teams need a model that works for compliance professionals and non-GRC users, including physicians, researchers and administrators.
- IS Partners brings healthcare compliance depth across HIPAA, HITECH, HITRUST and assurance.
- CoreStream GRC helps turn compliance advice into visible, repeatable and auditable workflows.
- The goal is less chasing, clearer accountability and stronger evidence.
Introduction: why is healthcare compliance becoming harder to manage?
Healthcare compliance teams are no longer managing one major requirement at a time. They are dealing with HIPAA, HITECH, HITRUST, cyber risk, AI governance, Open Payments, conflict of interest and internal oversight at once. Those expectations are not static either.
Some examples include:
- In January 2025, HHS published a proposed update to the HIPAA Security Rule to strengthen cybersecurity protections for electronic protected health information.
- In June 2026, The Joint Commission launched its Responsible Use of AI in Healthcare certification, reflecting the growing expectation that healthcare organizations need clearer governance, safeguards, monitoring and training around AI use.
The detail of the HIPAA proposal is what creates the work. It would remove the long-standing distinction between “required” and “addressable” implementation specifications, make written documentation of all policies, procedures, plans and analyses mandatory, require a technology asset inventory and a network map showing how ePHI moves through the organization, add a documented Security Rule compliance audit at least once every 12 months, and require business associates to notify covered entities within 24 hours of activating a contingency plan. None of it is law yet, but each of those proposals creates evidence that someone will have to own, produce and keep current.
That pace of change matters because every new or updated requirement brings its own evidence expectations, control requirements, review cycles and reporting demands. The pressure often lands on the same small group of compliance, privacy, risk and audit teams, who are expected to interpret requirements, assign ownership, collect evidence, manage issues and report progress across the organization.
The result is as much an operational problem as a regulatory one.
The regulators are working from the same picture. In justifying the proposed Security Rule changes, OCR pointed to a 100% increase in reported breaches of unsecured protected health information between 2018 and 2023, and a 950% increase in the number of individuals affected by them. HHS put the first-year cost of the proposed rule at roughly $9 billion, with about $6 billion a year in recurring compliance activity after that. Those figures translate directly into workload for compliance teams.
Healthcare teams are left trying to answer practical questions that become harder as obligations overlap: who owns the control, where is the evidence, what issue is still open, who approved the exception and can we prove this happened?
Open Payments shows the scale of the challenge. CMS says Program Year 2025 Open Payments data included 17.07 million published records totaling $14.67 billion in payments and other transfers of value. That volume of data creates a real transparency opportunity, but it also creates a practical workload for compliance teams that need to compare external payment data with internal conflict of interest disclosures, review mismatches and keep a clear audit trail.
“Healthcare compliance teams are not short of requirements. They are short of clear, connected ways to understand what those requirements mean in practice and where the real control gaps sit.”
That is where the IS Partners and CoreStream GRC partnership matters.
IS Partners supports the interpretation side: understanding regulatory expectations, mapping requirements, identifying gaps and preparing for assurance or certification.
CoreStream GRC supports the operational side: turning those requirements into workflows, evidence capture, ownership, reporting and issue remediation.
In short, IS Partners helps define the right compliance direction, while CoreStream GRC helps healthcare teams run it in a way that is visible, repeatable and easier to evidence.
“The strongest compliance advice still needs an operating model behind it. CoreStream GRC helps healthcare teams turn requirements into workflows, evidence, approvals and reporting that people can actually use.”
Paul Cadwallader, GRC Strategy Director, CoreStream GRC
Speak to CoreStream GRC and IS Partners at the 2026 ISACA GRC Conference in San Diego from 17–19 August. Learn more here.
What is the healthcare compliance pile-up?
The healthcare compliance pile-up is what happens when multiple frameworks, regulations and internal oversight demands compete for the same time, data and evidence. HIPAA, HITRUST, AI governance, Open Payments, conflict of interest and internal reporting may each have different aims, but they often rely on the same controls, owners and proof.
Many healthcare organizations still manage these obligations through separate spreadsheets, inboxes, point tools and manual evidence requests. That makes it harder to see where controls already exist, where evidence can be reused and where the real gaps sit.
As IS Partners’ David Dunkelberger, CPA, HITRUST CCSFP, puts it in his comparison of HIPAA and HITRUST:
“HIPAA is an act that details the standards of compliance, while HITRUST CSF is a workable framework that helps you achieve compliance.”
David Dunkelberger, Partner, IS Partners
That distinction matters. A healthcare team may know what standard it needs to meet, but still struggle to prove how that standard is being met day to day. Without a connected operating model, compliance work becomes a series of disconnected tasks rather than a clear view of risk, control and assurance.
That creates a coordination problem. If ownership is unclear, teams duplicate effort or miss gaps. If evidence is scattered, assurance becomes painful. If the process is difficult for occasional users, disclosure quality and participation drop.
“Healthcare compliance cannot be designed only for compliance professionals. It has to work for the physician, researcher or administrator who may only enter the process once or twice a year.”
Rich Eddolls, Co-Founder and Chief Product Officer, CoreStream GRC
Why does AI governance make the healthcare compliance pile-up harder to manage?
AI governance is not a separate compliance lane for healthcare organizations. It cuts across privacy, security, risk, clinical governance, vendor oversight and assurance, which is what makes it so hard to place with a single owner.
If an AI use case relies on patient data, supports clinical decision-making, processes operational data or influences how services are delivered, it immediately raises wider questions:
- What data does the tool use?
- Who approved it?
- Has the use case been risk assessed?
- What safeguards are in place?
- Is there a review process for bias, safety, privacy and security?
- Who monitors performance over time?
This is where AI governance adds pressure to an already crowded compliance environment. An AI policy on its own is not enough; healthcare organizations also have to show how it is being applied to real use cases, with controls, owners, decisions and evidence attached.
In practice that means a single register of AI use cases, where each entry records the named business owner, the data categories involved and whether they include PHI, whether the tool informs clinical decision-making, the approval decision and who made it, the date and outcome of the last bias, safety and privacy review, the monitoring cadence and thresholds, and the assurance evidence obtained from the vendor. If a use case cannot be described in those terms, it is not being governed in any meaningful sense.
NIST’s AI Risk Management Framework gives a useful structure for this. It organizes AI risk activity around four core functions: “Govern, Map, Measure, and Manage.” That structure is useful because AI oversight is a continuing cycle of governance, risk identification, measurement and management rather than a one-off approval.
That framework is also becoming a practical benchmark rather than a voluntary one. Texas’s Responsible Artificial Intelligence Governance Act took effect on January 1, 2026, and substantial compliance with the NIST AI Risk Management Framework is treated as a defense under it. Healthcare organizations operating across state lines should expect their AI governance evidence to be read against that standard, alongside sector expectations from the Joint Commission.
The healthcare-specific challenge is even sharper. The Joint Commission says responsible AI in healthcare is “not only a technology issue; it is a patient safety, quality, governance, privacy, and trust issue.” Its Responsible Use of AI in Healthcare certification focuses on governance, data management, risk and bias reduction, safety monitoring, transparency, education and training.
For healthcare compliance teams, the pressure is practical. If AI use cases are logged in one spreadsheet, approvals are sitting in email, privacy reviews are stored somewhere else and issues are tracked manually, oversight becomes fragile. The organization may have the right intentions, but still struggle to prove who approved the use case, what risks were reviewed, what controls were applied and what monitoring is in place.
Where do healthcare compliance teams get caught out?
“We think this happened” does not survive an audit. Teams need a clean trail showing ownership, evidence, decisions and follow-up.
That point is built into the HIPAA Security Rule itself. HHS says covered entities must “ensure the confidentiality, integrity, and availability of all e-PHI they create, receive, maintain or transmit,” “identify and protect against reasonably anticipated threats to the security or integrity of the information,” and “ensure compliance by their workforce.” Those expectations go beyond having policies to being able to show that safeguards are in place, risks are managed and responsibilities are followed through.
“The gap we often see is not a lack of intent. It is the distance between what the organization believes is happening and what it can actually evidence.”
CoreStream GRC’s client, UNT Health’s success story shows what changes when the process becomes easier to use and easier to evidence. UNT Health identified 52 potential conflicts in its first campaign, including many that may previously have gone unnoticed. The case study also points to significant time savings through automation, stronger cross-department collaboration and improved transparency through direct Open Payments integration.
As April Daniel from UNT Health explained:
“I like the way that the people can go in and complete it and then it automatically uploads… we have a centralized place. Just in case somebody needs to go back and review it, it’s already in the system.” She also said: “It has cut down time tremendously… I’ve gone from days of trying to logistically get the information to minutes.”
April Daniel, Director Compliance Operations, UNT Health
That is the difference between a process that exists on paper and one people actually use. Healthcare compliance teams need systems that ask the right questions, route the right reviews, trigger reminders and record decisions without requiring heavy training.

How can healthcare teams make overlapping requirements easier to manage?
The starting point is mapping. Healthcare teams should map HIPAA, HITRUST, AI governance, Open Payments and internal oversight requirements against existing controls, which shows where controls already exist, where evidence can be reused and where genuine gaps remain.
After mapping, the next priority is workflow. Requirements need to move from documents into day-to-day processes. That means assigning owners, setting review frequencies, collecting evidence, triggering approvals, escalating issues and tracking remediation.
A spreadsheet can list requirements, but it cannot reliably manage accountability at scale. Teams need workflows that show who needs to act, when they need to act and what happens if they do not.
In practice this means moving requirements into owned workflows, capturing evidence as work happens and giving teams a single view of control status, issues and follow-up.
Why does Open Payments show the need for a connected approach?
Open Payments is a clear example of healthcare compliance becoming an operational challenge.
CMS publishes data on payments and other transfers of value made by reporting entities, including drug and medical device companies, to covered recipients such as physicians. That transparency matters, but it does not automatically tell a healthcare organization whether a relationship was disclosed internally, reviewed properly or managed in line with policy.
The calendar is part of the problem. CMS publishes the prior program year’s full dataset on or before June 30 each year, but the pre-publication review and dispute window runs April 1 to May 15, with a further correction period to May 30. The data is then refreshed again each January, which means records a team reviewed in the summer can change after year end. A once-a-year reconciliation exercise will always be looking at a version of the data that has already moved.
Reconciliation is also rarely one-to-one. Records are attributed to individual covered recipients, not to the organizations they work for. Those recipients include physicians, physician assistants, nurse practitioners, clinical nurse specialists, certified registered nurse anesthetists, anesthesiologist assistants and certified nurse midwives. Matching a published payment to an internal discloser depends on identifiers your HR system was never designed to hold.
For compliance teams, the real work starts after the data is published. Teams still need to compare external Open Payments data with internal conflict of interest disclosures, review mismatches, investigate exceptions, record decisions and escalate issues where needed.
“Transparency data is only useful if organizations have a process for reviewing it. Open Payments gives visibility, but healthcare teams still need controls, review routes and evidence around what they do with that information.”
Conclusion: healthcare compliance does not need more noise. It needs a clearer operating model.
Healthcare compliance is only going to get more complex. HIPAA, HITRUST, AI governance, cyber risk, Open Payments and internal oversight will continue to overlap, so treating each requirement as a separate project creates duplication, evidence gaps and unnecessary pressure.
The better approach is a connected operating model: mapped requirements, shared controls, clear ownership, workflow-based approvals, issue tracking and evidence captured as work happens.
That is where IS Partners and CoreStream GRC come together. IS Partners helps define the right compliance direction; CoreStream GRC helps teams run it through connected workflows, evidence, approvals, remediation and reporting.
Compliance knowledge only pays off when it is executed, and the organizations that manage the pile-up best will be the ones that connect the two.
Explore how CoreStream GRC helps healthcare teams manage Conflict of Interest, Open Payments and connected compliance workflows. Speak to IS Partners about HIPAA and HITRUST readiness.
Speak to CoreStream GRC and IS Partners at the 2026 ISACA GRC Conference in San Diego from 17–19 August. Learn more here.
About IS Partners
IS Partners, an Axiom GRC company, is a leading provider of IT compliance and risk advisory solutions. With more than 20 years of experience, IS Partners has guided companies across software, healthcare, fintech, telecom, the defense industrial base and more to turn complex regulatory requirements into a strategic advantage. Led by seasoned CPAs and cybersecurity experts, the firm delivers customized, technology-backed solutions that ensure rapid onboarding, precise control mapping and predictable outcomes. IS Partners specializing in compliance frameworks, including SOC 1, SOC 2, CMMC, HITRUST, ISO 27001 and PCI DSS, empowering clients to strengthen their security posture and accelerate business growth.
FAQs on CoreStream GRC, IS Partners & healthcare compliance
Healthcare compliance means meeting the legal, regulatory, ethical and internal requirements that govern healthcare operations. In practice, it is about proving the organization has the right controls, owners, evidence and escalation routes in place.
Healthcare compliance is becoming more complex because obligations are overlapping. Teams are managing HIPAA, HITECH, HITRUST, cyber risk, AI governance, Open Payments, conflict of interest and internal oversight at the same time.
HIPAA is a US law that sets requirements for protecting health information. HITRUST is a certifiable framework that helps organizations structure security, privacy and risk controls. HIPAA tells covered organizations and business associates what they need to protect. HITRUST helps organizations demonstrate a more structured approach to managing those controls.
AI governance matters because AI tools in healthcare can affect patient privacy, clinical safety, fairness, transparency and accountability. Healthcare organizations need to know where AI is being used, what data it relies on, who approved it, what risks were assessed and how the use case is monitored over time.
Open Payments makes financial relationships between reporting entities and covered healthcare recipients publicly visible. For healthcare compliance teams, the challenge is comparing that external data with internal conflict of interest disclosures, reviewing inconsistencies, recording decisions and keeping an audit trail.
Healthcare compliance software helps teams move from manual tracking to connected execution by centralizing workflows, ownership, evidence, issue tracking, approvals and reporting.
Better workflow design removes unnecessary friction while keeping the right controls in place. Users should only be asked relevant questions, disclosures should route automatically to the right reviewer, reminders should reduce manual chasing, and decisions, comments, approvals and management plans should be stored against the record. This gives compliance teams clearer data, stronger evidence and a better view of what is complete, overdue or needs attention.


