Staff members were interviewed so that a model of the processes that were currently in
place could be built. After the staff members who had been interviewed confirmed the
correctness of the model, it was assessed against the privacy and security models and the
gaps relative to HIPAA compliance were determined and documented. Compliance recommendations
were developed based on the gaps. These recommendations suggested
changes to current processes or the implementation of new processes required to comply
with the regulations