I have spoken with a lot of patient privacy auditors and compliance officers, and the most common question that I get is:
“Where do I start?”
They go on to say, "Now that all the data is captured from the different systems that contain PHI, and we have information about the users and patients, what’s next?"
![](http://track.hubspot.com/__ptq.gif?a=395219&k=14&r=https%3A%2F%2Fblog.iatric.com%2Fpatient-privacy-blog%2Fslash-patient-privacy-auditing-man-hours&bu=https%253A%252F%252Fblog.iatric.com%252Fpatient-privacy-blog&bvt=rss)