Don’t Wait for the Audit: Three Compliance Gaps Hiding in Your Practice Featuring Dr. Natasha Guess, EP 270 

What does it actually take to run a successful medical practice that can withstand an audit, a breach, or a surprise records request? For most independent practice owners, compliance lives in a binder — a set of policies downloaded years ago, signed, and never opened again. In this episode of The Thriving Practice Podcast, Tracy Cherpeski sits down with Dr. Natasha Guess, a healthcare compliance consultant who believes compliance belongs in your daily operations, not your filing cabinet. 

Natasha is the founder of Guess Compliance Consulting, serving small and mid-sized healthcare practices across the U.S. and Canada. Born and raised in Guyana, South America, she witnessed preventable illness and loss in a country without strong healthcare structure — an experience that led her to fall in love with the rules and regulations that protect patients. Today she helps practice owners navigate HIPAA, CMS, Medicare and Medicaid requirements, state regulations, and vendor relationships without the fear-based messaging that dominates the compliance world. 

If you’re a practice owner focused on practice growth, profitability, and building a private practice without burnout, this conversation reframes compliance as something that protects all three — because a practice that collapses under an OCR investigation isn’t thriving, no matter how full the schedule is. 

Key Takeaways 

  • Compliance is an operational system, not a legal checkbox. A policy document means little if your team doesn’t know who to report a breach to, how to report it, and what happens next. 

  • Three gaps show up in nearly every practice: not knowing where your gaps are (and assuming silence means safety), outdated template policies that describe a practice that no longer exists, and no ongoing system to stay compliant as you grow. 

  • Your vendors are your responsibility. Business Associate Agreements matter — and many owners have never read theirs, or never received one at all. Regulators hold the covered entity accountable. 

  • Growth creates new compliance gaps. Adding providers, staff, or technology — or moving a team member into a new role without retraining — changes your risk profile, often invisibly. 

  • Don’t wait for an audit. The practices that hold up best are the ones with systems already in place. Waiting until something happens is when you have the fewest options. 

Q&A 

What are the most common compliance gaps in small medical practices? 

Natasha consistently sees three, regardless of specialty: owners who don’t know where their gaps are and assume everything is fine because nothing has gone wrong yet; outdated template policies downloaded at startup and never updated; and the absence of any ongoing system that keeps compliance current as the practice grows and changes. 

What is a Business Associate Agreement, and why does it matter? 

A BAA defines who is responsible for what between your practice and third-party vendors that touch patient information — EHRs, schedulers, AI-enabled tools. If something goes wrong, OCR and OIG hold the covered entity (your practice) accountable, so you need to know what your agreements actually say. Natasha recommends reviewing vendor agreements quarterly. 

Do small practices really get audited or investigated? 

Yes — small and mid-sized practices are not exempt from enforcement, and in some ways they’re more vulnerable because they lack the resources of large systems. A common trigger is patient records access: if a busy practice misses the required response window, a single patient complaint to the Office for Civil Rights can open an investigation. 

What’s one compliance step a practice owner can take this week? 

Reach out to your vendors, request your Business Associate Agreements, and read them. Know what your vendor is responsible for and what falls to you — and repeat that review quarterly, since vendors change and services get added. 

Episode Highlights 

  • Natasha’s path from Guyana, South America to healthcare compliance — and why patient protection is at the heart of her work 

  • The difference between having a policy and having a workflow: her breach-reporting example 

  • Why OCR enforcement should be on every small practice’s radar — without leading from fear 

  • Patient records access requests: the quiet trigger behind many investigations 

  • Vendor management in the age of AI: BAAs, responsibility allocation, and reading the contract 

  • The three compliance gaps Natasha finds in nearly every practice 

  • How growth creates new exposure: new providers, new roles, and retraining 

  • Inside Natasha’s compliance risk diagnosis process 

  • Her new service line for Canadian practices — and why province-by-province rules add complexity 

  • Why hhs.gov — not an AI chatbot — should be your primary source for HIPAA guidance 

Memorable Quotes 

"While I work with providers and it’s about protecting their business, it’s really about protecting the patients that trust them." — Dr. Natasha Guess 

"The gap between where you are and where you need to be never closes on its own — and it doesn’t get smaller with time." — Dr. Natasha Guess 

"You really cannot fix what you don’t know or what you haven’t named yet." — Dr. Natasha Guess 

"Every time they grow without updating their compliance structure, they’re creating new gaps — and a lot of times they don’t even realize it." — Dr. Natasha Guess 

"Winging it is not a very good business plan." — Tracy Cherpeski 

Dr. Natasha Guess offers a rare thing in the compliance world: reassurance backed by rigor. Her message to practice owners is simple — do not wait. Start with an honest assessment, name your gaps, and you’ll find that closing them is far less overwhelming than living with the unknown. Begin this week by pulling your Business Associate Agreements and reading them. Then explore Natasha’s free consultation, HIPAA template kit, and free compliance assessment (linked below), and visit thrivingpracticecommunity.com for more resources to help you build a practice that’s not just busy, but protected and thriving. 

Resource Mentioned: 

Practice Risk Check 

Compliance Assessment 

 

Guest Bio: 

Dr. Natasha Guess is the founder of Guess Compliance Consulting LLC, where she helps small and midsize healthcare practices build compliance programs that work in the real world — not just on paper. Born and raised in Guyana, South America, Natasha saw firsthand what happens when healthcare structure is missing, an experience that shaped her decade-plus career in regulatory compliance. Today she specializes in HIPAA privacy and security, vendor and Business Associate oversight, and audit readiness, translating complex regulations into clear operational systems. She's known for a practical, non-fear-based approach that lets practice owners meet regulatory expectations while staying focused on patient care.  

 

Find Dr. Natasha: 

Website: GuessComplianceConsultingllc.com 

LinkedIn 

YouTube @GuessComplianceConsulting 

Podcast: Guess What? Compliance Can Be Simple! Apple Podcasts 

 

Connect With Us: 

Be a Guest on the Show 

Thriving Practice Community 

Schedule Strategy Session with Tracy 

Tracy’s LinkedIn 

Business LinkedIn Page 

 

Next
Next

30 Seconds to Connect: What Healthcare Practices Get Wrong About Patient Communication Featuring Danny Bobrow, EP 269