bR2bR Compliance Officer — Healthcare
Run HIPAA, breach, Part 2, information-blocking and clinical-AI reviews on bRRAIn evidence, with findings that hold up.
- Level
- Practitioner
- Learning time
- 18 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- Rebuilt on real bRRAIn mechanisms: per-project Read grants, two approvals recorded with record_decision, the hash-chained console audit log, Robo Compliance sealed audit sessions, auditor-portal shares and the MCP session method. The v1 scope letters, read-only mirrors and session logs taught as product features are gone.
- Regulatory currency corrected: FDA's PCCP guidance for AI-enabled device software was finalized in December 2024 (non-binding); the 2024 reproductive health care privacy rule was vacated in June 2025; the January 2025 Security Rule changes are a proposal; the QMSR took effect on 2 February 2026; the 2024 Part 2 rule's compliance date was 16 February 2026.
- New lessons on 42 CFR Part 2, individual rights, security incidents and ransomware, OCR investigations, clinical AI transparency and nondiscrimination, and reporting language.
- Clinical AI review now uses LLMOps governance evidence: fairness runs, evaluations, model cards and drift monitoring, including what drift metrics cannot show.
- Seven AI role-play labs (privacy officer, security officer, HIM director, OCR investigator, CMIO, chief compliance officer, CFO) and a written capstone scored against a published rubric.
- A fresh LOFT exam bank replaces every v1 item: 87 selected-response and 6 AI-conducted performance items, each referenced to the lesson that teaches it.
What you will be able to do.
- You will be able to scope a healthcare engagement, establish your HIPAA status and take least-privilege, twice-approved, audited access on an auditee's bRRAIn.
- You will be able to plan and judge Robo Compliance sealed-session evidence and work findings and information requests through the auditor portal.
- You will be able to test the HIPAA Security Rule, including required versus addressable decisions and the thoroughness of a risk analysis.
- You will be able to analyze uses and disclosures, individual rights, de-identification, 42 CFR Part 2 and information blocking under the rules in force.
- You will be able to determine whether an incident is a reportable breach, compute every notification obligation, and assess business associate chains and OCR readiness.
- You will be able to evaluate clinical AI for regulatory position, bias, monitoring, override and nondiscrimination using LLMOps and vendor evidence.
- You will be able to write evidence-backed findings, correct AI-drafted errors, present enforcement-relevant facts, and build corrective action plans and reports without unsupported claims.
Who it's for
- HIPAA privacy and security officers at covered entities and business associates
- Compliance officers at health plans, health systems, healthtech firms and EHR vendors
- HITRUST assessors and healthcare auditors adopting AI-augmented practice
- Clinical AI governance and compliance leads at hospitals and provider networks
Not covered here
- Clinical practice and clinical judgment
- Billing fraud, anti-kickback and Stark law
- Preparing FDA submissions (this course covers how a provider evaluates clinical AI, not device approval)
- Legal advice and penalty determinations, which belong to counsel and regulators
- Other industry overlays (compliance-financial, compliance-energy, compliance-dod)
8 modules, 65 lessons.
About 18 hours of learning. Open a module to see every lesson.
-
Engagement foundations: scope, access and evidence on bRRAIn
Establish your HIPAA status and a defensible scope, take least-privilege access on the auditee's bRRAIn with two recorded approvals, plan Robo Compliance sealed evidence and auditor-portal shares, recognize AI co-pilot failure modes, and keep a PHI-free working record with the MCP session tools.
- Pretest: engagement scope, access and evidence
- The healthcare audit engagement: your HIPAA role, scope and minimum necessary
- Least-privilege auditor access: per-project grants, two recorded approvals and the audit log
- Robo Compliance sealed sessions and the auditor portal for HIPAA evidence
- AI co-pilot failure modes in healthcare compliance work
- Your working record: the MCP session method without PHI
- Lab: Set up a HIPAA engagement with a privacy officer
- Retrieval: 8 questions across Module 1
-
HIPAA Security Rule: safeguards, addressable decisions and risk analysis
Test administrative, physical and technical safeguards and documentation against evidence, apply 164.306(d), evaluate risk analysis and risk management, keep the January 2025 NPRM in its place, and build test work on Robo Compliance evidence.
- Pretest: the HIPAA Security Rule
- Administrative safeguards: testing 45 CFR 164.308
- Physical safeguards: testing 45 CFR 164.310
- Technical safeguards and documentation: testing 45 CFR 164.312 and 164.316
- Required versus addressable: applying 45 CFR 164.306(d)
- Evaluating a risk analysis: 164.308(a)(1)(ii)(A)–(B) and NIST SP 800-66 Rev. 2
- The proposed Security Rule changes: advising on a rule that is not yet law
- Worked example: building Security Rule test work on Robo Compliance evidence
- Lab: Walk a Security Rule sample with a security officer
- Retrieval: 8 questions across Module 2
-
Privacy Rule, individual rights, Part 2 and information blocking
Classify uses and disclosures, test authorizations and minimum necessary, evaluate de-identification, test the right of access and other individual rights, apply 42 CFR Part 2 after the 2024 final rule, analyze information blocking under 45 CFR Part 171, and keep rule status current.
- Pretest: the Privacy Rule, Part 2 and information blocking
- Uses and disclosures: 45 CFR 164.502–164.514 and minimum necessary
- Authorization, consent and the opportunity to agree
- De-identification and limited data sets: 45 CFR 164.514(a)–(e)
- Information blocking: 45 CFR Part 171 and its exceptions
- Individual rights and the Privacy Rule's administrative requirements
- 42 CFR Part 2 after the 2024 final rule, and keeping rule status current
- Lab: Privacy, Part 2 and information-blocking analysis with an HIM director
- Retrieval: 8 questions across Module 3
-
Breach notification, business associates and OCR
Determine breach status and every notification deadline, evaluate four-factor risk assessments, trace business associate chains, structure reviews on the OCR Audit Protocol, analyze security incidents and ransomware, and prepare verifiable evidence for OCR.
- Pretest: breach notification, business associates and the OCR protocol
- Breach notification mechanics: 45 CFR 164.400–164.414
- The four-factor risk assessment: demonstrating low probability of compromise
- The business associate chain: covered entity to business associate to subcontractor
- Walking the HHS OCR HIPAA Audit Protocol against evidence
- Security incidents, ransomware and the line to a breach
- Worked example: preparing for an OCR investigation with verifiable evidence
- Lab: Walk an OCR investigator through a late-reported breach
- Retrieval: 8 questions across Module 4
-
Clinical AI safeguards and HITRUST
Classify clinical AI under FDA framing including the final PCCP guidance, recognize QMSR, Part 11 and device reporting duties, evaluate bias with subgroup metrics and LLMOps fairness evidence, assess override, monitoring and drift, apply transparency and nondiscrimination obligations, and use HITRUST results correctly.
- Pretest: clinical AI, FDA framing and HITRUST
- FDA framing for clinical AI: device software, clinical decision support and PCCPs
- QMSR, Part 11 and device reporting: the FDA record rules that reach a provider
- Algorithmic bias in clinical decision support: scoping, metrics and LLMOps evidence
- Clinical override, monitoring and drift: keeping clinicians in control after go-live
- AI transparency, nondiscrimination and governance obligations around clinical AI
- HITRUST CSF in scope: assessments, maturity and what they do not prove
- Lab: Review a clinical AI expansion with a CMIO
- Retrieval: 8 questions across Module 5
-
Findings, AI-draft correction, enforcement and remediation
Write five-element findings with calibrated severity, review and correct AI-drafted reports, present facts that bear on enforcement, build corrective action plans, and report to leadership without compliance, certification or residency claims.
- Pretest: findings, AI correction, enforcement and remediation
- Writing healthcare findings that hold up
- Reviewing and correcting AI-drafted findings before they ship
- Enforcement exposure: the penalty tiers and the factors behind them
- Remediation roadmaps and corrective action plans
- Reporting to leadership: structure, scope statements and claims you must not make
- Lab: Defend findings and severities with a chief compliance officer
- Lab: Negotiate a corrective action plan with a CFO
- Retrieval: 8 questions across Module 6
-
Capstone preparation: same-day engagements
Understand the capstone's evidence package, deliverable, rubric and hard fails; pace a same-day engagement by severity; and calibrate your own work against the four anchor exemplars.
- Pretest: the capstone and same-day engagements
- The capstone: what you receive, what you submit and how it is scored
- Worked example: running a same-day engagement from evidence to package
- Anchor exemplars: what 92, 78, 71 and 54 look like
- Retrieval: 6 questions across Module 7
-
Exam readiness and capstone
Review the nine recurring decisions across all domains, learn the exam format and timing, practice with an interleaved set, and complete the capstone.
- Pretest: exam readiness
- Interleaved review: the decisions that recur across every domain
- The certification exam: format, blueprint and timing strategy
- Practice set: 12 interleaved questions across all domains
- Retrieval: 6 questions across Module 8
- Capstone: Same-day HIPAA review package for Larkspur Valley Health
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · Engagement foundations: scope, access and evidence on bRRAIn
AI role-play: agreeing scope, access, approvals, evidence shares and PHI handling with an auditee's Privacy Officer
-
Lab 2 · HIPAA Security Rule: safeguards, addressable decisions and risk analysis
AI role-play: walking ten Security Rule evidence items with a Security Officer who pushes back
-
Lab 3 · Privacy Rule, individual rights, Part 2 and information blocking
AI role-play: analyzing five privacy, Part 2 and information-blocking scenarios with an HIM Director
-
Lab 4 · Breach notification, business associates and OCR
AI role-play: presenting a late-reported breach to an OCR investigator
-
Lab 5 · Clinical AI safeguards and HITRUST
AI role-play: reviewing a sepsis tool expansion with a CMIO
-
Lab 6 · Findings, AI-draft correction, enforcement and remediation
AI role-play: defending findings and severities with a Chief Compliance Officer
-
Lab 7 · Findings, AI-draft correction, enforcement and remediation
AI role-play: negotiating a corrective action plan with a CFO
-
Lab 8 · Exam readiness and capstone
Written same-day HIPAA review package from a nine-exhibit evidence package
Same-day HIPAA review package for Larkspur Valley Health (fictional)
Artefact submitted in the capstone lab, AI-scored against the published rubric
Pass mark: 72%
Scored on
- Evidence-backed findings and citation accuracy25%
- Breach determination and notification analysis20%
- Security Rule and business associate assessment15%
- Clinical AI and information-blocking assessment15%
- Severity calibration and corrective action plan15%
- Engagement integrity and reporting10%
One exam. A credential anyone can verify.
The exam
- Items per form
- 59
- Time allowed
- 120 min
- Pass mark
- 72%
- Performance tasks
- 4
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: Renewal at 3 years by passing the then-current exam
Where this course sits.
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bR2bR Compliance Officer — Healthcare
Run HIPAA, breach, Part 2, information-blocking and clinical-AI reviews on bRRAIn evidence, with findings that hold up.