The Compliance Calendar gathers every compliance due date in one place, so nothing has to be remembered separately. Most of it is a read-only view — each item lives in its own feature, and the calendar surfaces and links to it. The exception is Compliance Activities (below), the calendar's own managed layer of recurring obligations.
The calendar pulls due dates from across the app:
Manage activities opens your recurring compliance program: required activities drawn from a curated catalog (each with its regulatory citation — annual Security Risk Analysis, quarterly access reviews, monthly audit-log review, and more, matched to the frameworks you use) plus any custom activities your admins add on their own cadence.
Each activity has a due date that advances when it's completed, an optional assignee (a team member, or an outside helper via an emailed no-account link), and a history of completions, postponements (a reason is required), and notes — a defensible record for auditors. Email reminders go out when an activity is due soon or overdue; Slack/Teams can be notified too. Org admins manage everything; assignees can complete and annotate their own items.
Until your organization adopts activities (or if the module is toggled off in Settings → Organization → Features), the calendar shows a few generic recurring HIPAA obligations as placeholders — your annual risk assessment, quarterly BA-agreement review, and a monthly training check. Once the managed program is running, those placeholders disappear in favor of your real, tracked activities.
Items are grouped into Overdue, Recurring obligations, and Upcoming, each with a plain-language "in X days" / "X days overdue" label. Filter by type to focus on one kind of deadline, and click any item to jump straight to the record it came from.
Export iCal downloads an .ics file you can subscribe to in Google Calendar, Outlook, or Apple Calendar, so your compliance dates sit alongside the rest of your schedule.