Skip to content

Search

Contact Us
  • CUSTOMER PORTAL
Drummond logo.
Contact Us
  • Testing & Certification
    • ONC Health IT Certification
    • ISO 27001
    • FHIRplace Interoperability Testing
    • CMS Patient Access
    • DEA EPCS Certification
    • DEA CSOS Certification
    • pDSI-Risk Assessment
    • AS2 Interoperability
    • AS4 Interoperability
    • ebMS
    • GS1 GDSN
    • OCI (Drug Supply Chain)
    HIPAA, NIST, Cybersecurity, ISO, SOC 2

    Build Once Comply Many Times with NIST SP 800-53

    Your HIPAA Program Probably Wasn’t Built for AI

    Your HIPAA Program Probably Wasn’t Built for AI

    “We’ve Never Had a Breach” Is Not a HIPAA Compliance Strategy 

  • Compliance Audits & Support
    • PCI QSA (RoC and AoC)
    • HIPAA
    • FTC Safeguards
    • FDA CFR 21 Part 11
    • MARS-E
    • ONC Compliance Learning Series
    FHIR Intermediary Testing: Real-World Transactions and Compliance

    Intermediaries in Practice: Real-World FHIR Testing and Transactional Roles

    HIPAA, NIST, Cybersecurity, ISO, SOC 2

    Build Once Comply Many Times with NIST SP 800-53

    The Hidden Costs of Ignoring Penetration Testing in Healthcare

  • Risk & Security Assessments
    • Penetration Testing
    • Vulnerability Scanning
    • Code Analysis
    • SOC 2
    • NIST Risk Assessments
    • Comprehensive Healthcare Risk Assessment
    • NYDFS 23 NYCRR 500
    FHIR Intermediary Testing: Real-World Transactions and Compliance

    Intermediaries in Practice: Real-World FHIR Testing and Transactional Roles

    HIPAA, NIST, Cybersecurity, ISO, SOC 2

    Build Once Comply Many Times with NIST SP 800-53

    The Hidden Costs of Ignoring Penetration Testing in Healthcare

  • Certified Products
    • ONC Health IT
    • EPCS
    • AS2 / AS4 / ebMS
    • FHIRplace
    • Payer and Patient Access
    • pDSI-Risk
    • Open Credentialing Initiative (OCI)
    • CSOS
    • Testing Calendars & Registration
  • Resources
    • All Resources
    • Blog
    • Case Studies
    • Upcoming Events
    • Events & Video
    • Insights & Guidance
    • News & Announcements
    • Special Offers
    • Updates
    • Newsletter Sign-up

    Your Vulnerability Scans Are Leaving Gaps

    Your HIPAA Program Probably Wasn’t Built for AI

    Your HIPAA Program Probably Wasn’t Built for AI

    Why Prior Auth API Certification Matters Now 

  • About Drummond
    • About Drummond
    • Is It Drummond Certified
    • Our Services
    • Our Team
    • Careers
    • Contact Us
  • Testing & Certification
    • ONC Health IT Certification
    • ISO 27001
    • FHIRplace Interoperability Testing
    • CMS Patient Access
    • DEA EPCS Certification
    • DEA CSOS Certification
    • pDSI-Risk Assessment
    • AS2 Interoperability
    • AS4 Interoperability
    • ebMS
    • GS1 GDSN
    • OCI (Drug Supply Chain)
  • Compliance Audits & Support
    • PCI QSA (RoC and AoC)
    • HIPAA
    • FTC Safeguards
    • FDA CFR 21 Part 11
    • MARS-E
    • ONC Compliance Learning Series
  • Risk & Security Assessments
    • Penetration Testing
    • Vulnerability Scanning
    • Code Analysis
    • SOC 2
    • NIST Risk Assessments
    • Comprehensive Healthcare Risk Assessment
    • NYDFS 23 NYCRR 500
  • Certified Products
    • ONC Health IT
    • EPCS
    • AS2 / AS4 / ebMS
    • FHIRplace
    • Payer and Patient Access
    • pDSI-Risk
    • Open Credentialing Initiative (OCI)
    • CSOS
    • Testing Calendars & Registration
  • Resources
    • All Resources
    • Blog
    • Case Studies
    • Upcoming Events
    • Events & Video
    • Insights & Guidance
    • News & Announcements
    • Special Offers
    • Updates
    • Newsletter Sign-up
  • About Drummond
    • About Drummond
    • Is It Drummond Certified
    • Our Services
    • Our Team
    • Careers
    • Contact Us

Category: Blog

ONC Certification is Not HIPAA Compliance: Why You Need Both

Many health IT vendors breathe a sigh of relief after achieving ONC Health IT Certification. It feels like a major compliance hurdle cleared. But here’s the reality: that certification doesn’t

WEDI Recap: A New Vision for Scalable FHIR Testing with FHIRplace

The HL7® FHIR® community has long relied on connectathons as crucibles of interoperability — intense, cooperative testing events where engineers huddle to make their systems talk to each other. But

How HIPAA Compliance Helps Startups Build Trust and Grow

Early-stage startups and small businesses building healthcare software quickly learn that HIPAA compliance isn’t just a legal formality. It’s a business essential. Healthcare organizations need to know that any vendor

How Penetration Testing Strengthens Compliance Strategies for Financial Institutions

AI Audio Summary In 2023 alone, the financial sector experienced a 20% increase in cyberattacks, with the average cost of a breach reaching $5.97 million. For financial institutions, the question

Breaking Down NIST Risk Assessments for Smarter Cybersecurity

Building a strong cybersecurity program takes more than just good tools—it requires a clear, structured approach that aligns with your organization’s goals. That’s where NIST risk assessment frameworks shine. Whether

Why Expert Guidance Matters for NYDFS and FTC Compliance

Managing one cybersecurity regulation is hard enough. Juggling two? That’s where things can escalate into a high-stakes compliance challenge. For many financial institutions, this isn’t just a hypothetical. Both the

Essential Insights from Drummond’s 2025 ONC Compliance Webinar

With the 2025 Office of the National Health Coordinator (ONC) compliance deadlines rapidly approaching, healthcare organizations and health IT developers are racing to implement critical regulatory updates that will shape

Maximizing the Benefits of Prior Authorization with Real World Testing

Maximize the potential of FHIR-based electronic Prior Authorization (ePA) with real-world testing. Drummond’s FHIRplace Pilot ensures seamless interoperability, compliance, and efficiency—helping you launch with confidence.

Simplifying PCI DSS v4.0.1 Mapping with Third-Party Support

With PCI DSS v4.0.1 now in effect, businesses must navigate complex security updates to stay compliant. Learn how third-party support can help identify gaps, validate controls, and reduce compliance risks before it’s too late.

← Previous
Next →

FREE EXPERT CONSULTATION

Do you have Compliance, Interoperability, or Security questions?
Book your FREE consultation with a Drummond expert and get answers.
Learn More

Drummond Group, LLC

3622 Lyckan Parkway, Suite #3003
Durham, NC 27707 USA

sales@drummondgroup.com
(877) 437-8666

Contact Us
Subscribe to our Newsletter

Services
Resources
About Us
Privacy Policy
Cookie Policy
Terms of Use

© 2026 Drummond Group, LLC. All rights reserved. All brand names and trademarked logos used on this website are for identification purposes only and are the property of their respective owners. Their inclusion here does not imply endorsement, sponsorship, or affiliation with Drummond. All content, including text, images, graphics, and other materials, is protected by copyright law and may not be reproduced, distributed, or transmitted without prior written permission from Drummond Group, LLC.

DISCLAIMER: The services provided as part of the ONC Compliance Learning Series are separate and distinct from the Drummond Authorized Certification Body (ONC-ACB) and Test Lab (ONC-ATL). The Learning Series purpose is to provide expert support and guidance for the preparation and planning of participants’ future testing and certification activities; it does not negate the steps or required actions of the certification process. Participation in the ONC Compliance Learning Series does not guarantee successful ONC Health IT testing or certification.