Compliance Action Plan
Critical regulatory findings from the February 2026 audit. All items require immediate attention.
Critical Items
Policies to Update
Training Required
Fastest Deadline
Due: 2026-04-15
Regulatory Change
Update NPP to include specific language regarding reproductive health information privacy and how PHI is handled in light of legal requests.
Impact on Evangeline
Evangeline must ensure privacy notices explicitly reflect protections for reproductive/gender-affirming care and staff understand attestation requirements.
Required Actions
- •Review existing NPP and identify gaps
- •Add reproductive health-specific language
- •Implement law enforcement request verification procedures
- •Train staff on new requirements
- •Document staff training completion
Related Policy: HIPAA Privacy Policy and Notice of Privacy Practices (NPP)
Due: 2026-04-24
Regulatory Change
All public-facing digital content must conform to WCAG 2.1, Level AA standards.
Impact on Evangeline
Evangeline's website and digital resources must be audited for accessibility to maintain federal/state grant eligibility.
Required Actions
- •Conduct WCAG 2.1 AA accessibility audit
- •Identify and prioritize accessibility barriers
- •Remediate critical issues (alt text, navigation, color contrast)
- •Test with screen readers
- •Document compliance efforts
Related Policy: Digital Accessibility & Website Privacy Policy
Due: 2026-06-30
Regulatory Change
Mandates use of secure web-based platform for child abuse reports and adds reproductive health facility personnel to mandated reporters list with 24-hour reporting window.
Impact on Evangeline
Employees and volunteers must be retrained on 24-hour timeline and DFCS secure portal requirements.
Required Actions
- •Train all mandated reporters on 24-hour requirement
- •Provide DFCS portal access and procedures
- •Clarify reproductive health personnel status
- •Document mandatory reporter status for all staff
- •Establish incident response procedure
- •Maintain training records
Related Policy: Child Protection & Mandated Reporting Policy
Due: 2026-06-01
Regulatory Change
Georgia's comprehensive data privacy law granting consumers rights to access, delete, and opt-out of data sharing.
Impact on Evangeline
Evangeline must implement data subject request mechanisms and update privacy disclosures.
Required Actions
- •Implement data subject request mechanism (web form)
- •Create data access/deletion/opt-out procedures
- •Update privacy policy with data processing categories
- •Establish 45-day response timeline
- •Train staff on privacy requests
- •Document all requests and responses
Related Policy: Data Privacy & Information Security Policy
Due: 2026-03-31
Regulatory Change
Prohibits the same individual from serving as both CEO and Secretary. Prohibits directors from voting by proxy.
Impact on Evangeline
Board structure and bylaws must be updated to ensure compliance.
Required Actions
- •Review current board officers
- •Ensure CEO and Secretary are different individuals
- •Remove proxy voting provisions from bylaws
- •Review board meeting procedures
- •File updated registration with GA Secretary of State
Related Policy: Corporate Bylaws and Board Governance Policy
1. Load Default Policies - Go to Admin → Compliance → Policies tab and load the compliance policy templates
2. Review & Customize - Review each policy and customize with Evangeline's specific details
3. Create Action Plan - Use the Action Plan tab to track remediation progress
4. Assign Owners - Assign each action to a staff member or team
5. Document Progress - Track progress, upload evidence, and mark items complete
6. Re-Audit - Run compliance audit after remediation to verify improvements