Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Arvin, Greene and Podleski on Privacy and Patient Data [Podcast]
    By Adam Turteltaub

    At the 2023 HCCA Compliance Institute there is a sure to be fascinating roundtable discussion lead by Marti Arvin, Vice President, Chief Compliance Officer, Erlanger Health System, Joan M. Podleski, Chief Privacy Officer, Children’s Health and Adam Greene, Partner, Davis Wright Tremaine, LLP. They will be addressing a range of privacy and data-related issues.

    In this podcast one of the topics they discuss are the complexities around access. Often, for example, raw data is not kept in the main health information management system (HIMS).

    Another challenge is proper website disclosures and how visitor data is used and shared. OCR has issued guidance in this area that has earned a great deal of attention. But, it is likely to be a hard problem to solve since organizations will need to determine exactly what data they are collecting, using and storing.

    To help manage these issues they strongly argue for investing the time and effort in developing clear processes for responding to data requests. Then, monitor to ensure the policies are being followed.

    Take time also to understand what is in your designated record set and where it is stored. Then make sure your HIMS understands what qualifies as the designated record set.

    It’s time also to reassess how your organization is managing telehealth now that the public health emergency is ending. There will be decreased flexibility and increased emphasis on keeping these interactions on HIPAA-compliant platforms.

    When you do move onto one of these platforms, be sure to have a business associate agreement.

    When looking at technology, they advise compliance be a part of decisions related to the use of patient apps. Whether your organization is thinking of building its own or relying on a third party, it’s essential that the privacy requirements be a part of the discussion from the start.

    Listen in to a provocative conversation, but, be warned. It’s going to make you want to join them in person at the HCCA Compliance Institute, April 23-26 in Anaheim, and online April 24-26.
    17 min
  • Michael Volkov on What We Learned in 2022 and What it Means for 2023 [Podcast]
    By Adam Turteltaub

    A lot happened in compliance in 2022, with a large number of lessons for 2023. To sort it out we turned to Michael Volkov, of the Volkov Law Group and host of the Corruption, Crime & Compliance blog and podcast. In this Compliance Perspectives podcast he addresses several key pieces of learning for compliance teams.

    FCPA
    While 2022 may have started out slowly in terms of resolutions, the year ended on a busy note with several settlements and the revised corporate enforcement policy. One thing the DOJ made clear is that it is taking a sharp look at compensation policies to see if there are both incentives and disincentives for wrongdoing. The latter should include claw backs, deferred compensation and punishment for wrongdoing.

    Culture (more below) was also a keen area of focus and is likely to remain so. The perennial issue of third-party risk remains, as well.

    Where should compliance teams focus? The contract to invoice to payment stage of deals is where FCPA violations tend to occur.

    Also, be on the lookout for more major dispositions shortly.

    Sanctions
    Last year, he reports, was the year of the trade compliance officer. Complying with an ever-increasing and changing list of Russia-related sanctions kept teams busy day and night.

    The good news is that companies seem to be on top of things. The bad news is, he warns, that the Department of Justice has warned that this could be the new FCPA, with large fines for wrongdoing. He also warns that OFAC is a strict liability enforcer. Intent does not matter.

    As big an issue as this has been, there is often still too much of a separation between the trade compliance and main compliance groups. That will likely need to change, if it hasn’t already.

    Culture
    Culture has gotten the attention of the enforcement community with a particular focus on ethics. Done right, the culture can be the most effective corporate control an organization has.

    Done wrong, and it can cause not just problems, but liability for the organization. The DOJ is looking at culture closely and recent case law out of Delaware has extended the due care responsibility to senior leadership.

    To survive and thrive organizations, he believes, need to define their culture, attend and imbed it, monitor, and intervene when they see deficiencies.

    Finally, the board and senior management need to be educated on the importance of the right culture. It’s not just about saying “do the right thing.” It’s about expectations and norms around the mission, how we treat each other and how we treat those outside the organization.

    Listen in to learn, including what he sees for the future of compliance programs.
    15 min
  • Yolunda Dockett and Holly Hester on the Changing Telehealth Rules [Podcast]
    By Adam Turteltaub

    Telehealth is here to stay, but that doesn’t mean the rules will all be staying the same, reports Holly Hester, Senior Director, Strategic Client Partnerships for Net Health and Yolunda Dockett (LinkedIn), Chief Compliance Officer at Anne Arundel Dermatology.

    While the Public Health Emergency is set to end on May 11, 2023, the Consolidated Appropriations Act of 2023 extended many telehealth flexibilities through the end of December 2024. These include the ability to provide telehealth to patients in their homes, in both rural and urban settings, and the ability of physical and occupational therapists, along with speech pathologists, to provide telehealth.

    Yet, there are inconsistencies, with some CPT codes used by rehab therapists set to expire at the end of 2023.  Plus, some are being continued only for 151 days after the end of the emergency.

    One other change to expect centers on privacy requirements. While many platforms have been used to provide telehealth, soon only HIPAA-compliant platforms will be allowed. It’s a change that makes the provision of care less flexible and perhaps less friendly.

    Regardless, if your organization has not yet done a risk assessment about telehealth, now is the time. Leverage the relationships established in rolling out the service and then look collaboratively at the risks and start thinking about remediation techniques.

    Some other things to consider:

    * Understanding how to decide if a patient has the physical and mental capacity for telehealth
    * Business and operational risks
    * Privacy considerations, on both the provider and patient sides
    * Reimbursement and billing
    * Documentation requirements.

    It’s a lot of work, but it helps to ensure that telehealth can be delivered in a complaint manner.

    Finally, don’t miss learning more at their session “Incorporating Telehealth into Your Compliance Workplan” at the 2023 HCCA Compliance Institute.
    16 min
  • Thora Johnson and Mark Fox on De-Identification Under HIPAA and GDPR [Podcast]
    By Adam Turteltaub

    These days it’s easy to identify people using technology and databases, and that’s a problem if you are trying to comply with HIPAA or even GDPR because a lot of sensitive data eventually needs to be de-identified in a proper manner.

    Thora Johnson (LinkedIn), Partner at Orrick and Mark Fox (LinkedIn), Privacy and Research Compliance Officer at the American College of Cardiology explain that there are two permissible methods of de-identification under HIPAA. Safe Harbor De-Identification is a process in which eighteen identifiers are removed. The second option is Expert Determination De-Identification, in which statistical principles are used to determine if there is low risk a person can be identified.

    It's not an easy process, either way. Information on the individual and family members likely needs to be removed. In addition many struggle with how to do de-identification right because the work is often done only periodically and not on a regular, frequent basis.

    One area of particular challenge is understanding the difference between de-identification and a limited data set. There are significant requirements with these limited data sets, too, including the need for a signed agreement with the data recipient and proper permissions to share the data.

    Adding to the complexity, under GDPR there are the concepts of anonymization and pseudo-anonymization to reckon with.

    What should you do? Listen in to understand the issues, and then plan on attending Thora and Mark’s session “It’s De-Identified, or Is It?” at the 2023 HCCA Compliance Institute.
    14 min
  • Andre Paris on Brazil’s Data Protection Law [Podcast]
    By Adam Turteltaub

    With one of the largest economies in the world and serving as the South American home for many global businesses, Brazil is a country for compliance teams to watch, and their laws are very much worth heeding. That includes the Brazilian General Data Protection Law (LGPD), which entered into force on September 18, 2020.

    As Andre Paris (LinkedIn), Professor and Privacy & Compliance Consultant explains in this podcast, the law contains 10 principles including:

    * Data should be processed only for specific, legitimate, explicit purposes
    * Data quality needs to be maintained
    * Companies must be transparent about how data is used
    * A security regime must be in place
    * The data should not be used in a discriminatory matter

    It is very similar to and consistent with the European General Data Protection Regulation (GDPR) and includes a number of rights for data subjects, such as access to personal data held by the organization, the ability to correct outdated and incorrect data, and the blocking or deletion of unnecessary data.

    The law applies to any data collected in Brazil, regardless of the citizenship of the individual.

    So how can compliance teams address the law’s requirements? He recommends several steps:

    * Secure the support of leadership
    * Search for someone with privacy expertise to serve as the data protection officer
    * Train the workforce on what is essential data
    * Map your data
    * Determine which law authorizes the processing of data
    * Identify any and all risks inherent in the organization’s operations

    Listen in to learn more about how to ensure your organization is in compliance with Brazil’s LGDP.
    15 min
  • Deb McCracken and Julie Wall on Patient Safety [Podcast]
    By Adam Turteltaub

    Patient safety remains a challenge for organizations, and not for want of trying to address the problem. Improving it is an issue addressed here and at the 2023 HCCA Compliance Institute by Deb McCracken, Chief Risk Officer, and Julie Wall, Senior Vice President, Benefis Health System.

    Problems such as fall prevention remain, along with improper medication administration, misidentifying patients and preventing infections. They persist because, as healthcare and technology change, procedures may as well, leading to a departure from safe behavior.

    Adding to the challenge, often, is an unwillingness to speak up and raise issues. Many fear that they will be retaliated against if they point out potential problems.

    To better understand patient safety risk they recommend a close working relationship among compliance, quality and risk management. These three departments should help form a committee focused on patient safety that includes individuals skilled in capturing and coding root cause analyses.

    To close safety gaps effectively, they recommend looking to best practices and implementing them. Also use lessons learned from your organization and others across the industry. That begins with debriefing after an incident.

    They also recommend running simulations of real-life situations. These can help you be better prepared when an incident occurs. When you do, don’t forget about practicing for workplace violence scenarios.

    Listen in to learn more about how you can promote better patient safety practices. And, to learn even more, join us in Anaheim for the 2023 Compliance Institute.
    12 min
  • Brittney McDonough on Finding Your Next Job [Podcast]
    By Adam Turteltaub

    With seemingly constant news stories about layoffs, many are starting to wonder what they would do if they found themselves suddenly out of work and looking for their next compliance position.

    There are several ways to make the process go smoother, explains Brittney McDonough, partner at the recruiting firm Barker Gilmore. That starts with making the right decision of how much time to take off after a layoff.

    Many people, not surprisingly, are tempted to use their severance package to take a much-needed respite from work. Be careful, though, she advises. A job search can take three to six months, so taking six months off could lead to a year out of work.

    That doesn’t mean, though, you shouldn’t take advantage of this time. You should embrace it; just be sure to use it strategically, balancing recharging your batteries with a thoughtful approach to finding your next opportunity.

    When it comes to pursuing a job search, she recommends three key steps:

    * Develop professional objectives. Think through what you want out of your next position:  What role do you desire? What level are you open to? What type of company? What size and industry? What do you want to make? Where do you want to live?
    * Develop a marketing plan for yourself. Think about how you are going to sell yourself and end up on the radar of recruiters and prospective recruiters. Update your resume accordingly, and be sure that you have a current and accurate presence on LinkedIn.  Recruiters depend on it.
    * Be intentional about how you network. Put together a list of contacts who could be helpful. Reach out to them and ask what they can recommend and who they can connect you with. Be sure to also offer to help them, too. Also pursue speaking and writing opportunities. They are a way to increase your contacts and open up more opportunities.

    What do you do when a prospective employer asks about the job that you lost or maybe still have? Be honest but don’t go into any more details than you need to. You want to keep the focus on the job you want, not the job you have or had.

    Listen in to learn more, and if you want to learn more about networking, here is a link to a book that was discussed in the podcast.c
    24 min
  • Elena Durante on Greewashing [Podcast]
    By Adam Turteltaub

    As environmental expectations keeps rising and Environmental Social and Governance (ESG) metrics gain more importance to investors, some organizations will be tempted to greenwash, which is best described as making an environmental footprint look far better than it actually is.

    That’s a serious risk and one that will be addressed by Elena Durante, ESG Risk Audit Manager, ING Corporate Audit Services, Risk & Finance, at the SCCE European Compliance & Ethics Institute, which takes place in Amsterdam March 20-22.

    As she explains in this podcast, at its roots greenwashing is about misleading information supplied to investors and customers, taking advantage of the fact that these outsiders cannot fully tell if what the organization is saying is true.

    While greenwashing is still relatively unregulated, she tells us, that has started to change.  In the EU there have been an increasing number of efforts to combat it. Plus, there is severe reputational damage to companies caught greenwashing.

    Compliance teams need to be on the lookout at their organizations to ensure the integrity of their organizations’ environmental statements. That starts with ensuring that what regulations that currently exist are followed. It also means keeping an eye out for new regulations.

    Compliance should also be working to develop and implement ESG protocols within the organization. These should identify clear rules and policies to ensure sufficient checks and balances are in place.

    A training element will also be needed to help the business people understand that environmental statements need to accurately reflect the  organization’s actual activities, not just its aspirations.

    Listen in and then keep an eye out for greenwashing in your organization.
    15 min
  • Andrew Walker on Self-Umpiring in Tennis [Podcast]
    By Adam Turteltaub

    Andrew Walker is the US Tennis Association’s (USTA) director of education and training for officiating and chief umpire at the US Open. He was good enough to join our Sports, Compliance & Ethics Conference, where he revealed something surprising. With the USTA having over 13,000 sanctioned events a year, ranging from adults to juniors, the vast majority of matches are technically unofficiated. Roving umpires are available but move from court to court. They don’t sit in the chair and call each point. Players do and keep the score. That’s often true as well at the college level.

    It's not too different from how things work in the business world, with compliance officers not there to make every call for the business unit.

    How does this work? Part of the role of officials at entry level events, especially those with children, he explains, is not to act only as officials, but to act as educators as well. They are there to teach kids to officiate fairly, even if it means making a call against oneself. That’s not easy, human nature being what it is and with, these days, the ultra-competitive environment in youth sports.

    The officials seek to ingrain sportsmanship, which includes integrity, respect for your opponent and respect for the game. It also includes being a good winner and a good loser.

    What happens when there is a dispute? First, officials recognize that honest mistakes are possible. A player, especially a young one, running to make a shot may not see things accurately. Even competitive players can lose track of the score.

    But, when the calls are questionable, they will stay and watch the match for a while. And, if a player is repeatedly overruled in his or her calls, points and games can be taken away. The player may even default.

    Listen in to get both a new appreciation of the world of tennis and maybe pick up a few ideas about how you could encourage more self-umpiring at your organization.
    12 min
  • Christopher Knight and Megan Grifa on Fraud and Compliance [Podcast]
    By Adam Turteltaub

    Fraud and compliance issues often go hand in hand, which is why it’s important for fraud and compliance teams to work closely together. Christopher Knight (LinkedIn) of Knight Vision Fraud Investigations and Megan Grifa (LinkedIn), Senior Director, Compliance Oversight for Sidecar Health, will be addressing the fraud-compliance relationship at the 2023 HCCA Compliance Institute, taking place in Anaheim April 23-26.

    In this podcast that point out that communication and follow up are central to building successful connections between fraud and compliance. Each needs to let the other know what it is doing, what has been found and what is coming up next. Also of great value:  setting up mechanisms to force yourselves to connect at a certain cadence to keep the lines of communication open.

    In addition, they advise taking the time to get to know each other on a personal level. That will help build the trust that is essential when addressing a crisis.

    Even during more normal times it’s essential to cooperate, aligning program structures and sharing risk assessments. Compliance teams can benefit from data mining and analytics tools that fraud has. Meantime, the fraud team can benefit from the seven elements approach used by compliance.

    Listen in and then plan on learning more at the 2023 Compliance Institute.
    15 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,492 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,359 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,717 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,249 Listeners

Pivot by New York Magazine

Pivot

9,616 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,447 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,244 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

801 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,882 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,446 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,254 Listeners