Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Kayne McGladrey on What Businesses other than Banks Need to Know about Gramm-Leach-Bliley [Podcast]
    By Adam Turteltaub

    The Gramm-Leach-Bliley Act (GLBA) is typically referred to in the context of financial institutions. It requires offerers of consumer financial products to explain how they share information and protect sensitive data.

    It’s not, however, only banks that fall under GLBA’s umbrella. New rules will affect retailers offering credit terms to their customers, higher education institutions that administer federal student aid and others a well, explains Kayne McGladrey, Field CISO for Hyperproof.

    The FTC, has set June 2023 as the deadline for compliance with the revised GLBA Safeguards Rule. It requires that affected organizations:

    * Have a qualified individual to implement and enforce an information security plan
    * Conduct a periodic cybersecurity risk assessment
    * Implement cybersecurity controls to manage those risk
    * Document who has access to customer data
    * Assess the risks of applications that can access the data
    * Securely destroy old data
    * Periodically test the controls to verify their effectiveness

    In addition, staff needs to be trained, there must be a written incidence response plan and ongoing testing.

    It is a considerable commitment, Kayne points out, but since it overlaps with the requirements of the European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), many organizations may already have significant structures in place.

    Even so, it’s important to conduct a gap analysis, he advises, to ensure all the requirements are being met.

    Listen in to learn more about what Gramm-Leach-Bliley now requires for your organization.
    15 min
  • Matt Kelly on the Big Stories in Compliance in 2022 [Podcast]
    By Adam Turteltaub

    Last year was an eventful one for the world and the compliance profession. In this podcast, Matt Kelly, Editor and CEO of Radical Compliance, looks back at what he sees as the biggest events, and looks into the future.

    The conversation begins with the impact of the war in Ukraine. He observes that the increasing number of sanctions of Russian individuals and entities, as well as the variations from country to country, have forced companies to improve their sanctions compliance efforts. The sanctions have also complicated procurement, forcing organizations to review their suppliers more carefully to avoid sanctions issues.

    With the war has also come of host of ethical considerations. Organizations have had to decide what to do with their Russian operations and the people that work at them.

    Also on the international front, 2023 brought increased cooperation among prosecutors, with a rising number of anti-corruption enforcement actions combining the resources of prosecutors in multiple countries. ABB, Glencore and Danske Bank are three notable examples.

    This activity comes at the same time as Europe continues to lead the world in privacy and data protection requirements.

    Looking domestically, he points to statements by Lisa Monaco at the Department of Justice and the push to require certification of the effectiveness of the compliance program by the CEO and chief compliance officer. This could be a dramatic shift for compliance programs.  On the one hand, it could create stronger ties between the CEO and compliance, Matt observes. On the other hand, compliance officers would see greater personal risk, especially given the real likelihood that, despite a strong program, wrongdoing may occur.

    Whether certification truly becomes established practice, though, has yet to be seen. Thus far it has only been imposed in the context of recently signed DPAs. As a result, certification will come in three years, if at all. He notes that a change in Administration could see a reversal of the policy.

    What does he see in 2023? For one, a need for compliance teams to improve their ability to access and analyze data. The US Department of Justice has made it clear that it expects organizations to have robust compliance data analytics processes.

    Second, he sees increased data protection enforcement actions, both abroad and in the US.

    Listen in to learn more about what happened and what to expect for your compliance program in the year to come.
    16 min
  • Beth Kastner and Shannon DeBra on Patient Steering and Charting [Podcast]
    By Adam Turteltaub

    It’s critical for patients leaving the hospital for a post acute care (PAC) provider that the handoff be conducted well. Some facilities will be better suited to the patients needs than others, which is why the process needs to be handled properly, with discharge planners making recommendations based on patient need, rather than the financial interests of the hospital or PAC.

    Unfortunately, explains Beth Kastner, Member, and Shannon DeBra, Senior Counsel, at Epstein Becker & Green, that’s not always the case. Patient steering and charting can take place, with bad outcomes for everyone involved.

    While there is no official definition of patient steering, it has been informally defined as the practice of directing patients and/or their caregivers to PAC providers that do not align with the patient’s goals of care and treatment plan. It can also be defined as inappropriately influencing the patient and/or care giver.

    Traditionally this occurs when the hospital, or its discharge planner, has been remunerated in some way by the PAC. As recent cases have shown, that could come in the form of gift cards, massages or even a free cruise. It might also be delivered as staffing for the hospital paid for by the PAC.

    Whatever the form, it’s improper and could lead to a very large settlement and termination of the Medicare provider agreement.

    Patient charting is a scheme in which a PAC is given access to patient data to identify patients for referral to their facility. It’s a practice that holds multiple risks, including anti-kickback and privacy.

    So how can a hospital stay ahead of this risk? First, train the staff that remuneration comes in many forms and carries substantial risks. Second, reinforce that discharge planning must be done in the best interest of the patient. Third, watch carefully, including ensuring that all arrangements are in writing and reviewed by legal or compliance before signing.

    Listen in to learn more about the issue and the do’s and don’ts of preventing patient steering and charting.
    15 min
  • Erin Bliss on The Telehealth Risk Report [Podcast]
    By Adam Turteltaub

    In December 2020 the Pandemic Response Accountability Committee (PRAC) issued the report:  Insights on Telehealth Use and Program Integrity Risks Across Selected Health Care Programs During the Pandemic. To better understand the PRAC and the report, we spoke with Erin Bliss, Assistant Inspector General for Evaluation and Inspections at the Office of Inspector General for the Department of Health & Human Services.

    As she explains in this podcast, the PRAC was formed as an outcome of the CARES Act. Its mission is to promote transparency and coordinate oversight of the federal coronavirus response; prevent and detect fraud, waste, misuse and mismanagement; and identify risks across agencies. The Offices of Inspector General from HHS, Justice, Veterans Affairs, Defense, Labor and Office of Personnel Management are all PRAC members.

    The report revealed how great an increase there was in telehealth. In the first year of the pandemic, telehealth usage increased from roughly 3 million people across six federal programs to 37 million. This change was largely the result of an expansion of the Medicare rules, which previously had limited telehealth to rural communities during in-office visits.

    While few today dispute the value of telehealth, that does not mean its use has not come without challenges. More data, the report notes, is still needed for oversight of telehealth’s use and impact, particularly on quality of care. In addition, data collection policies need to be improved since many providers have kept only rudimentary information.

    At the same time, the report identified activity that indicated waste, fraud and abuse. These included billing the same service twice, billing for extremely high amounts of telehealth services, billing for services that did not seem appropriate for telehealth, and billing at the highest, most expensive level.

    If there is good news to these findings, it is that the risks are ones already familiar to healthcare providers. Established risk management and compliance tools will likely be useful.

    Listen in to learn more about what the report revealed and what steps you can take, including active monitoring, to ensure the integrity of your organization’s telehealth services.
    14 min
  • Jochen Vankerckhoven on Audience-Driven Compliance [Podcast]
    By Adam Turteltaub

    Compliance programs start with the laws and regulations, but compliance failures begin with people. That’s why, argues Jochen Vankerckhoven (LinkedIn), founder of Antwerp-based Compliance Explained, that it is essential to take an audience-driven view of compliance programs.

    What that means in practice is designing and implementing a program that is suited for the people who are the intended audience. It also means valuing your audience and realizing it is one of the main pillars of a successful program.

    Think, he advises, of your compliance program as having two parts: a front and a back end.  The front end is what the workforce sees. Then consider what the right message is and the right time to deliver it so it has the most meaning to your audience.

    Be reasonable with your communication goals. Strive for a not a deep understanding of a topic but awareness of an issue and where to go to get help.

    On the backend, have the right controls in place and recognize that it is better to prevent a problem in the first place than to rely on those controls.

    Listen in to learn more about this unconventional approach to thinking of compliance programs.
    12 min
  • Jessenia Cornejo and Brittani Summers on Auditing & Monitoring [Podcast]
    By Adam Turteltaub

    Auditing and monitoring is a required element for an effective compliance program, but it also carries with it a host of benefits. In this podcast, Jessenia Cornejo (LinkedIn), Chief Compliance Officer for Bridge Diagnostics and Brittani Summers, Compliance Manager for Sprinter Health, outline all you can get from a robust auditing and monitoring program and how to create one.

    Benefits of a strong auditing and monitoring program include:

    * Measuring the effectiveness of your compliance program
    * Identifying criminal or malicious conduct
    * Highlighting risk areas
    * Accountability
    * Transparency
    * Continuous improvement (which the government is looking for these days)
    * Greater collaboration with other departments

    In addition to all these benefits, a strong program in this area can be enormous dividends when a regulator of the Department of Justice comes knocking at your door.

    When launching an auditing and monitoring initiative they recommend putting a work plan in place. It will enable you to manage the implementation to your goals and objectives. Be sure to include scheduling, they advise. It will help you stay on track.

    Then share the plan with leadership or the compliance committee. That will help ensure buy in, identify constraints and risks, and help you get any additional resources you may need.

    They also offer one simple, but important, piece of advice: don’t try and do everything all at once. Don’t wait until everything is in place before beginning. Instead, focus on the top risks as soon as you can.

    Likewise, don’t try and audit everything all at once. It can be better to tackle one item at a time.

    Listen in and learn more about how to make your auditing and monitoring program a success.
    16 min
  • Haydee Olinger on When a Compliance Officer Becomes a Board Member [Podcast]
    By Adam Turteltaub

    With increased focus on the board’s oversight of compliance programs by the US Department of Justice and the Delaware Courts, there is a strong case for adding compliance officers to boards of directors, and many compliance professionals have the skills.  Few, though, have been able to make the leap.

    Haydee Olinger (LinkedIn), Sr. Advisor at Barker Gilmore, and former longtime chief compliance officer at McDonald’s, is one of the few who have. She has now served on the board of two publicly-traded companies.

    How did she do it? She was able to find her way onto the first board through a combination of networking, and by virtue of the fact that she had such deep experience in the quick serve restaurant category.

    Her journey is a good reminder to compliance professionals that your position doesn’t just mean you have expertise in compliance. You also have expertise in the industry in which you work. The compliance role gives you insight into all the various aspects of the business. It’s an asset not to be downplayed when pursuing board positions.

    Despite have worked with boards as a compliance officer, she reports that serving as a board member greeted her with many surprises. For one, board members don’t have the opportunity to settle in and learn the business. They have to hit the ground running and address a wide range of issues, which these days include the lingering impact of covid, supply chain challenges, inflation, labor shortages, IT security and, of course, compliance.

    Second, as a board member you have to reorient your thinking away from an executive whose job it is to get things done to a role of strategy and oversight.

    That means as a board member you need to stay out of the weeds. One implication for compliance officers meeting with the board: don’t bog it down in detail. Instead focus on corporate risks, their likelihood of occurrence and what is being done to mitigate them.

    While in the meeting, listen carefully to board questions to anticipate what they will need for future meetings. Between meetings, build a relationship with the relevant committee chair, board chair and even individual board members. The more interactions you have with them, the easier it will be to anticipate what they will want to know.

    Listen in to learn more, and, perhaps, start thinking about how you can make the leap to board membership.
    12 min
  • Matt Nobles on Working Abroad [Podcast]
    By Adam Turteltaub

    A lot of people, myself included, have wondered what it would be like to live and work, abroad. Matt Nobles, Chief Compliance Officer – Middle East & Africa for GE Gas Power has lived the life, even as a child. As he shares in this podcast he spent his childhood as an ex-patriot kid living in Southeast Asia, and for many years now he has lived in Dubai.

    It’s a life he has enjoyed greatly, meeting people from all over the world, and experiencing a wide range of cultures, food, music and art. It has also enabled him to expand his network and count friends all over the world.

    His family has benefitted too, with his children enjoying an experience they would not otherwise have had.

    In terms of one’s career, time spent in another country can have many benefits. A short-term assignment in a difficult region could leave to promotions when returning home. Alternatively, one assignment abroad could to another and another, and a life of living all over the world.

    So what should you do if you have the desire to live and work abroad? First, he recommends considering the unique aspects of the region you are contemplating, the cost of being far away from family and the opportunities in that region versus others.

    When you get to your new posting, he recommends spending the first 90 days listening as much as possible. Connect with your local team, learn their compliance challenges and the local dynamics. These include cultural, geopolitical, and legal factors.

    Next dig into legacy issues to understand what has gone wrong in the past, and how it has been fixed, or still needs to be.

    On the personal side, the first thing, of course, is getting yourself and family settled in. Then build out a local community for yourself to make the experience more enjoyable for you and your family. Be sure to take advantage of local experiences. Expat blogs and even books can be very helpful in helping you understand the region and the local mindset.

    One mistake to avoid, he warns, is trying to focus on the American or Western way of doing things. Don’t go charging in with a fixed view. Instead, listen carefully to learn how things are done locally.

    Listen in to learn more, and then, maybe, start packing your bags.
    10 min
  • Troy Fine on Data Security Standards Audits [Podcast]
    By Adam Turteltaub

    With enhanced concerns and vigilance over cybersecurity has come an increasing number of yardsticks that organizations much measure themselves against. As Troy Fine, Director, Risk and Compliance at Drata explains, in addition to legal requirements such as the European General Data Protection Regulation (GDPR), HIPAA and the California Consumer Privacy Act (CCPA) two key standards have emerged:

    * SOC2: This standard was developed by the accounting body ISACA and is primarily of import to US-based technology companies and startups. Audits are performed by CPA firms on internal controls related to security
    * ISO27001: More popular in Europe, it is a certification on information security management systems, examining how risks are identified and mediated and what control plans are in place

    To prepare for an audit he recommends first getting a good understanding of the relevant standard so you understand all the elements it requires and what it will take to meet those requirements. Next determine when you will need the certification in hand and start building a timeline backwards to determine when you need to start. Calculate, too, what it will cost in terms of time, people and everything else, including the price of the audit.

    How you work with the auditor will depend largely on which audit you pursue. He explains that SOC2 audits allow for more consultation than ISO27001 does.

    When hiring an auditor, it can be tempting to use the one with the lowest price. He recommends, though, being careful before going down that route since the auditor is likely to have less time to give.

    Be sure also to ensure that the auditor has the necessary expertise to be able to evaluate your technology. Some may not be as well versed on various elements, including cloud services, as they should.

    Once the audit begins, compliance teams can be helpful by ensuring that all the data and people the auditor needs are available. And, he advises, be transparent, even about your gaps.

    Listen in to learn more about having a successful data security standard audit.
    15 min
  • Nick Weil and Mayesha Awal on Data Inventories [Podcast]
    By Adam Turteltaub

    Personal data, especially in healthcare, seems to breed on its own, which is why, like the dinosaurs in Jurassic Park, it’s critical to keep close tabs on where it is and how it is used. First stop: a data inventory.

    Nick Weil and Mayesha Awal (LinkedIn) of Epsilon Life Sciences explain that a data inventory is necessary because often organizations don’t have a strong handle on their data. You need to take a noun and verb approach, they explain. The noun addresses where the data is: what computers, servers and file cabinets it is stored in. The verb speaks to what is being done with the data. What are the processing activities? What functions are accessing the data?

    It's good information to have for its own sake, but under data protection regimes ranging from GDPR in Europe to HIPAA in the US, it is essential.

    It is also a project that is often filled with surprises. Compliance teams conducting an inventory may discover a wide range and types of data processing activities. These can include GPS information, payment card method, biometrics and much more. Plus, of course, there are the number of ways that vendors may be using the data, and what information may be in the Zoom call that just got recorded.

    Listen in to learn more about how to uncover and manage the data in your organization’s inventory.
    14 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners