I’m due for 12 CE hours by June and want options that go beyond policy slides to hands-on work — think SIEM log analysis, role-based access reviews, or a basic FHIR/HL7 data governance lab. Any vendor-neutral courses you’ve found that help harden PHI workflows and prep teams for audit and incident response?
SANS SEC555 has hands-on SIEM labs; vendor-neutral: SEC555: Detection Engineering and SIEM Analytics | SANS Institute. Would your board accept those CPEs toward the 12?
Try HL7’s FHIR Fundamentals for hands-on API work, then turn it into a governance lab by running ONC’s Inferno tests against a sandbox: https://inferno.healthit.gov/. For audit/IR, the CIS Controls Implementer workshop is vendor-neutral and gives actionable RBAC/logging checklists, though you’ll want to confirm your board accepts those CEUs. If that fits, I can share a short plan to map EHR audit logs into Wazuh so it’s not all ‘death-by-PowerPoint’.
Have you looked into how the ONC’s Interoperability Standards Advisory could tie into your hands-on work? It’s like turning your EHR system into a Swiss Army knife for audits and governance! And it might even give you a fresh perspective on how to strengthen PHI workflows.