Achieving compliance with security and privacy mandates like the Health Insurance Portability Accountability Act (HIPAA) is just the beginning. But wait; compliance is absolutely attainable and manageable-if you are vigilant. It helps to think of compliance as an ongoing process that is integral to everything from new-hire training practices to high-level IT decision making. However, many healthcare providers are mistakenly operating under the assumption that because they meet HIPAA privacy and security rules, now they are in the clear. This false sense of security is furthered by a relative lack of enforcement. HIPAA is currently complaint-driven; just because you haven't had a complaint filed against you, doesn't mean you are properly maintaining compliance. Be proactive! Use this simple list of questions to determine if your organization is as compliant as it could be: