bR2bR Compliance · Practitioner
v2.0

bR2bR Compliance Officer — Healthcare

Run HIPAA, breach, Part 2, information-blocking and clinical-AI reviews on bRRAIn evidence, with findings that hold up.

Level
Practitioner
Learning time
18 hours
Price
$499
Credential
Valid 3 years
What's new in v2.0

What changed in this edition.

  • Rebuilt on real bRRAIn mechanisms: per-project Read grants, two approvals recorded with record_decision, the hash-chained console audit log, Robo Compliance sealed audit sessions, auditor-portal shares and the MCP session method. The v1 scope letters, read-only mirrors and session logs taught as product features are gone.
  • Regulatory currency corrected: FDA's PCCP guidance for AI-enabled device software was finalized in December 2024 (non-binding); the 2024 reproductive health care privacy rule was vacated in June 2025; the January 2025 Security Rule changes are a proposal; the QMSR took effect on 2 February 2026; the 2024 Part 2 rule's compliance date was 16 February 2026.
  • New lessons on 42 CFR Part 2, individual rights, security incidents and ransomware, OCR investigations, clinical AI transparency and nondiscrimination, and reporting language.
  • Clinical AI review now uses LLMOps governance evidence: fairness runs, evaluations, model cards and drift monitoring, including what drift metrics cannot show.
  • Seven AI role-play labs (privacy officer, security officer, HIM director, OCR investigator, CMIO, chief compliance officer, CFO) and a written capstone scored against a published rubric.
  • A fresh LOFT exam bank replaces every v1 item: 87 selected-response and 6 AI-conducted performance items, each referenced to the lesson that teaches it.
Outcomes

What you will be able to do.

  • You will be able to scope a healthcare engagement, establish your HIPAA status and take least-privilege, twice-approved, audited access on an auditee's bRRAIn.
  • You will be able to plan and judge Robo Compliance sealed-session evidence and work findings and information requests through the auditor portal.
  • You will be able to test the HIPAA Security Rule, including required versus addressable decisions and the thoroughness of a risk analysis.
  • You will be able to analyze uses and disclosures, individual rights, de-identification, 42 CFR Part 2 and information blocking under the rules in force.
  • You will be able to determine whether an incident is a reportable breach, compute every notification obligation, and assess business associate chains and OCR readiness.
  • You will be able to evaluate clinical AI for regulatory position, bias, monitoring, override and nondiscrimination using LLMOps and vendor evidence.
  • You will be able to write evidence-backed findings, correct AI-drafted errors, present enforcement-relevant facts, and build corrective action plans and reports without unsupported claims.

Who it's for

  • HIPAA privacy and security officers at covered entities and business associates
  • Compliance officers at health plans, health systems, healthtech firms and EHR vendors
  • HITRUST assessors and healthcare auditors adopting AI-augmented practice
  • Clinical AI governance and compliance leads at hospitals and provider networks

Not covered here

  • Clinical practice and clinical judgment
  • Billing fraud, anti-kickback and Stark law
  • Preparing FDA submissions (this course covers how a provider evaluates clinical AI, not device approval)
  • Legal advice and penalty determinations, which belong to counsel and regulators
  • Other industry overlays (compliance-financial, compliance-energy, compliance-dod)
Syllabus

8 modules, 65 lessons.

About 18 hours of learning. Open a module to see every lesson.

  1. Engagement foundations: scope, access and evidence on bRRAIn 8 lessons · 2 h 15 min

    Establish your HIPAA status and a defensible scope, take least-privilege access on the auditee's bRRAIn with two recorded approvals, plan Robo Compliance sealed evidence and auditor-portal shares, recognize AI co-pilot failure modes, and keep a PHI-free working record with the MCP session tools.

    1. Pretest: engagement scope, access and evidence Diagnostic pretest · 5 min
    2. The healthcare audit engagement: your HIPAA role, scope and minimum necessary Reading · 15 min
    3. Least-privilege auditor access: per-project grants, two recorded approvals and the audit log Worked example · 15 min
    4. Robo Compliance sealed sessions and the auditor portal for HIPAA evidence Reading · 15 min
    5. AI co-pilot failure modes in healthcare compliance work Reading · 15 min
    6. Your working record: the MCP session method without PHI Worked example · 15 min
    7. Lab: Set up a HIPAA engagement with a privacy officer AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 1 Retrieval check · 10 min
  2. HIPAA Security Rule: safeguards, addressable decisions and risk analysis 10 lessons · 2 h 45 min

    Test administrative, physical and technical safeguards and documentation against evidence, apply 164.306(d), evaluate risk analysis and risk management, keep the January 2025 NPRM in its place, and build test work on Robo Compliance evidence.

    1. Pretest: the HIPAA Security Rule Diagnostic pretest · 5 min
    2. Administrative safeguards: testing 45 CFR 164.308 Reading · 15 min
    3. Physical safeguards: testing 45 CFR 164.310 Reading · 15 min
    4. Technical safeguards and documentation: testing 45 CFR 164.312 and 164.316 Reading · 15 min
    5. Required versus addressable: applying 45 CFR 164.306(d) Reading · 15 min
    6. Evaluating a risk analysis: 164.308(a)(1)(ii)(A)–(B) and NIST SP 800-66 Rev. 2 Reading · 15 min
    7. The proposed Security Rule changes: advising on a rule that is not yet law Reading · 15 min
    8. Worked example: building Security Rule test work on Robo Compliance evidence Worked example · 15 min
    9. Lab: Walk a Security Rule sample with a security officer AI role-play lab · 45 min
    10. Retrieval: 8 questions across Module 2 Retrieval check · 10 min
  3. Privacy Rule, individual rights, Part 2 and information blocking 9 lessons · 2 h 30 min

    Classify uses and disclosures, test authorizations and minimum necessary, evaluate de-identification, test the right of access and other individual rights, apply 42 CFR Part 2 after the 2024 final rule, analyze information blocking under 45 CFR Part 171, and keep rule status current.

    1. Pretest: the Privacy Rule, Part 2 and information blocking Diagnostic pretest · 5 min
    2. Uses and disclosures: 45 CFR 164.502–164.514 and minimum necessary Reading · 15 min
    3. Authorization, consent and the opportunity to agree Reading · 15 min
    4. De-identification and limited data sets: 45 CFR 164.514(a)–(e) Reading · 15 min
    5. Information blocking: 45 CFR Part 171 and its exceptions Reading · 15 min
    6. Individual rights and the Privacy Rule's administrative requirements Reading · 15 min
    7. 42 CFR Part 2 after the 2024 final rule, and keeping rule status current Reading · 15 min
    8. Lab: Privacy, Part 2 and information-blocking analysis with an HIM director AI role-play lab · 45 min
    9. Retrieval: 8 questions across Module 3 Retrieval check · 10 min
  4. Breach notification, business associates and OCR 9 lessons · 2 h 30 min

    Determine breach status and every notification deadline, evaluate four-factor risk assessments, trace business associate chains, structure reviews on the OCR Audit Protocol, analyze security incidents and ransomware, and prepare verifiable evidence for OCR.

    1. Pretest: breach notification, business associates and the OCR protocol Diagnostic pretest · 5 min
    2. Breach notification mechanics: 45 CFR 164.400–164.414 Reading · 15 min
    3. The four-factor risk assessment: demonstrating low probability of compromise Reading · 15 min
    4. The business associate chain: covered entity to business associate to subcontractor Reading · 15 min
    5. Walking the HHS OCR HIPAA Audit Protocol against evidence Reading · 15 min
    6. Security incidents, ransomware and the line to a breach Reading · 15 min
    7. Worked example: preparing for an OCR investigation with verifiable evidence Worked example · 15 min
    8. Lab: Walk an OCR investigator through a late-reported breach AI role-play lab · 45 min
    9. Retrieval: 8 questions across Module 4 Retrieval check · 10 min
  5. Clinical AI safeguards and HITRUST 9 lessons · 2 h 30 min

    Classify clinical AI under FDA framing including the final PCCP guidance, recognize QMSR, Part 11 and device reporting duties, evaluate bias with subgroup metrics and LLMOps fairness evidence, assess override, monitoring and drift, apply transparency and nondiscrimination obligations, and use HITRUST results correctly.

    1. Pretest: clinical AI, FDA framing and HITRUST Diagnostic pretest · 5 min
    2. FDA framing for clinical AI: device software, clinical decision support and PCCPs Reading · 15 min
    3. QMSR, Part 11 and device reporting: the FDA record rules that reach a provider Reading · 15 min
    4. Algorithmic bias in clinical decision support: scoping, metrics and LLMOps evidence Reading · 15 min
    5. Clinical override, monitoring and drift: keeping clinicians in control after go-live Reading · 15 min
    6. AI transparency, nondiscrimination and governance obligations around clinical AI Reading · 15 min
    7. HITRUST CSF in scope: assessments, maturity and what they do not prove Reading · 15 min
    8. Lab: Review a clinical AI expansion with a CMIO AI role-play lab · 45 min
    9. Retrieval: 8 questions across Module 5 Retrieval check · 10 min
  6. Findings, AI-draft correction, enforcement and remediation 9 lessons · 3 h

    Write five-element findings with calibrated severity, review and correct AI-drafted reports, present facts that bear on enforcement, build corrective action plans, and report to leadership without compliance, certification or residency claims.

    1. Pretest: findings, AI correction, enforcement and remediation Diagnostic pretest · 5 min
    2. Writing healthcare findings that hold up Worked example · 15 min
    3. Reviewing and correcting AI-drafted findings before they ship Worked example · 15 min
    4. Enforcement exposure: the penalty tiers and the factors behind them Reading · 15 min
    5. Remediation roadmaps and corrective action plans Worked example · 15 min
    6. Reporting to leadership: structure, scope statements and claims you must not make Reading · 15 min
    7. Lab: Defend findings and severities with a chief compliance officer AI role-play lab · 45 min
    8. Lab: Negotiate a corrective action plan with a CFO AI role-play lab · 45 min
    9. Retrieval: 8 questions across Module 6 Retrieval check · 10 min
  7. Capstone preparation: same-day engagements 5 lessons · 1 h

    Understand the capstone's evidence package, deliverable, rubric and hard fails; pace a same-day engagement by severity; and calibrate your own work against the four anchor exemplars.

    1. Pretest: the capstone and same-day engagements Diagnostic pretest · 5 min
    2. The capstone: what you receive, what you submit and how it is scored Reading · 15 min
    3. Worked example: running a same-day engagement from evidence to package Worked example · 15 min
    4. Anchor exemplars: what 92, 78, 71 and 54 look like Reading · 15 min
    5. Retrieval: 6 questions across Module 7 Retrieval check · 10 min
  8. Exam readiness and capstone 6 lessons · 1 h 50 min

    Review the nine recurring decisions across all domains, learn the exam format and timing, practice with an interleaved set, and complete the capstone.

    1. Pretest: exam readiness Diagnostic pretest · 5 min
    2. Interleaved review: the decisions that recur across every domain Reading · 15 min
    3. The certification exam: format, blueprint and timing strategy Reading · 15 min
    4. Practice set: 12 interleaved questions across all domains Retrieval check · 20 min
    5. Retrieval: 6 questions across Module 8 Retrieval check · 10 min
    6. Capstone: Same-day HIPAA review package for Larkspur Valley Health AI role-play lab · 45 min
Labs and capstone

Practice against someone who pushes back.

Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.

  • Lab 1 · Engagement foundations: scope, access and evidence on bRRAIn

    AI role-play: agreeing scope, access, approvals, evidence shares and PHI handling with an auditee's Privacy Officer

  • Lab 2 · HIPAA Security Rule: safeguards, addressable decisions and risk analysis

    AI role-play: walking ten Security Rule evidence items with a Security Officer who pushes back

  • Lab 3 · Privacy Rule, individual rights, Part 2 and information blocking

    AI role-play: analyzing five privacy, Part 2 and information-blocking scenarios with an HIM Director

  • Lab 4 · Breach notification, business associates and OCR

    AI role-play: presenting a late-reported breach to an OCR investigator

  • Lab 5 · Clinical AI safeguards and HITRUST

    AI role-play: reviewing a sepsis tool expansion with a CMIO

  • Lab 6 · Findings, AI-draft correction, enforcement and remediation

    AI role-play: defending findings and severities with a Chief Compliance Officer

  • Lab 7 · Findings, AI-draft correction, enforcement and remediation

    AI role-play: negotiating a corrective action plan with a CFO

  • Lab 8 · Exam readiness and capstone

    Written same-day HIPAA review package from a nine-exhibit evidence package

Capstone

Same-day HIPAA review package for Larkspur Valley Health (fictional)

Artefact submitted in the capstone lab, AI-scored against the published rubric

Pass mark: 72%

Scored on

  • Evidence-backed findings and citation accuracy25%
  • Breach determination and notification analysis20%
  • Security Rule and business associate assessment15%
  • Clinical AI and information-blocking assessment15%
  • Severity calibration and corrective action plan15%
  • Engagement integrity and reporting10%
Exam and credential

One exam. A credential anyone can verify.

The exam

Items per form
59
Time allowed
120 min
Pass mark
72%
Performance tasks
4
Attempts included
2
Wait between attempts
7 days
  • Online and timed, taken on learn.brrain.io.
  • Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
  • Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.

The credential

  • A verifiable digital badge in your name.
  • A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
  • Valid for 3 years.
  • Renewal: Renewal at 3 years by passing the then-current exam
Before and after

Where this course sits.

Questions

Frequently asked.

Do I need to install anything for the labs?

No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.

How is the exam delivered?

Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.

What if I don't pass first time?

You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.

How long is the credential valid?

3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.

I hold the v1 credential. Is it still valid?

Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.

Can my company enroll a team?

Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.

Enroll

bR2bR Compliance Officer — Healthcare

Run HIPAA, breach, Part 2, information-blocking and clinical-AI reviews on bRRAIn evidence, with findings that hold up.