Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Tiffany Turner Lynch on Corporate Compliance & Ethics Week [Podcast]
    Posted by:  Adam Turteltaub

    There are lots of ways to make your organization’s Corporate Compliance & Ethics Week a success.  For Tiffany Turner Lynch (LinkedIn) and her colleagues at Winston-Salem State University that meant timing it to the launch of their compliance training initiative.  They saw the joint effort as an excellent opportunity to demonstrate that supporting a culture of compliance and ethics is the responsibility of everyone and is something that the university values highly.

    Before beginning the training, she and the chief counsel met with internal audit to discuss policies that are audited the most.  They also discussed issues that most frequently led to calls to audit and legal.  In addition, they identified issues that are central to compliance in higher education, such as the Family Educational Rights and Privacy Act (FERPA).  Throughout the week they reinforced elements of the training

    They also developed a five-part podcast series, each one featuring a different “no” department:  Internal Audit, Equal Employment Opportunity, Title IX, the police, legal and compliance.  The podcasts served to the lift the veil on what happens when an investigation is conducted.  They demonstrated not just the process, but also that these departments exist to protect the university and its staff.

    To add some fun to the celebration they conducted a virtual scavenger hunt.  Everyone who was able to answer all the questions was entered into a drawing to win one of two $100 cash gifts.

    As Tiffany reports in this podcast, the results were outstanding.  It helped people understand more about the compliance office, built rapport, raised the comfort level with reporting and engagement with the policy portal.

    Listen in both to learn more and get some inspiration for your own Corporate Compliance & Ethics Week efforts.
    12 min
  • Jeff Hahn on Delivering Bad News and Crisis Communications [Podcast]
    Posted by:  Adam Turteltaub

    Nobody likes delivering bad news, but if you’re in compliance and ethics, you’re going to have to do it sooner or later.  When that time comes, it’s essential you do so in the best way possible.

    In this podcast, Jeff Hahn (LinkedIn), author and the owner and principal of Hahn Marketing & Communications, reveals that one secret for sharing bad news is to provide the right context.  Give management the salient facts and avoid burdening them with every detail.  Second, he advises following what he has dubbed “The Goldilocks Rule”.  Present options that are not hot enough, not cold enough, and just right.  In practice this means ranging from doing nothing to doing something extreme.  Generally, the “just right” option prevails and enables leadership to feel bought in to the path forward.

    Once the goals are set and the organization’s response moves into the implementation stage, it’s time to bring in the line managers.  That conversation, he relates, needs to be focused on implementation, and the conversation switches from creative to directive.

    What about the wider workforce?  It’s important to remember that they are brand ambassadors.  Inform them to the best of your abilities.  Be authentic, and remember that they can check up on you from the inside.

    When it comes to external communications, the compliance team can be invaluable in creating stakeholder talking points, including a timeline of what happened when.

    Finally, the conversation explores what not to do a crisis.  There are three things to avoid:

    * Make an absolute and outright denial, unless the claim is obviously false and ridiculous
    * Attack the accusers
    * Scapegoat, especially those who are tangential to the core issue

    Listen in to learn more about how to break bad news and be an integral, appreciated part of a crisis response.
    13 min
  • Blaise Wabo on the Healthcare Cyberthreat Landscape [Podcast]
    Posted by:  Adam Turteltaub

    The war in Ukraine and pandemic have both dramatically changed the cyberthreat landscape for healthcare entities.

    There are many more employees working from home, as well as patients communicating with their physicians remotely.  At the same time, governments have warned of potential cyberattacks by Russia.

    Even without these threats, ransomware provides its own challenges.  As Blaise Wabo, Healthcare and Financial Services Leader for A-Lign explains in this podcast, it’s a fast-growing threat.  Deloitte research indicates that ransomware attacks increased by 1755% in 2021.

    So how should healthcare entities respond?  Start by focusing on your people, he advises.  They tend to be the weakest link in the security chain.  Some common challenges:

    * A lack of encryption of their home WIFI
    * Routers still with the default password
    * Connecting from Starbucks, the airport or hotel without using a VPN
    * Falling for a phishing attack

    To manage the risk, he recommends starting with a risk assessment that includes third-party suppliers and your supply chain.  Determine the vulnerabilities and rank the risks.  Then begin implementing controls.  Encrypt PHI, even in transit.  Conduct phishing training for your staff.  Hire a third party to do a penetration test and identify gaps in your security.

    In addition to preventing problem, steps like these can help when one occurs, given the provisions of the HIPAA Safe Harbor Act.

    Listen in for more advice and learn how to navigate an increasingly challenging cyber landscape.
    13 min
  • Sheila Limmroth on Hybrid Workforces [Podcast]
    Posted by:  Adam Turteltaub

    Hybrid work is likely here to say, and, as Sheila Limmroth, privacy specialist at DCH Health System, and the author of the chapter Hybrid Work Environment in the Complete Healthcare Compliance Manual  observes in this podcast, it’s up to compliance teams to manage the risks, many of which, even at this stage of the current era, aren’t always recognized.

    For example, we’re all familiar with the need to secure electronic PHI, but if your employees have printers at home, are they permitted to print out any data? If so, do they have shredders or some other way to destroy the document? Are employees even trained to destroy it?

    One other consideration: is Alexa listening in on what they are saying?

    These are but two examples that point to the need to think through all the implications of having a hybrid workforce, even after two years of remote working.

    So, what should compliance team be doing? Education is essential so that employees understand that certain behaviors are risky:

    * Talking on your cell about a patient while sitting in Starbucks is not a good idea.
    * Phishing remains a substantial risk in the home office as it is in the workplace.
    * The router needs to be secured with a password other than the default one that comes out of the box.

    At the same time there’s a need to also recognize the new challenges inside the facility.  When it comes to telehealth, not all videoconferencing software is created equal. The platform must be HIPAA compliant. Even for video conference calls it’s probably a good idea to issues PINs to the attendees.

    The bottom line is it’s time to revisit your organization’s risks and policies to determine what works and what doesn’t as more employees return to the office while many remain at home.

    Listen in to learn more, and be sure to check out the Complete Healthcare Compliance Manual.
    16 min
  • Isabella Porter on Privacy and Healthcare Business Associates [Podcast]
    Post by:  Adam Turteltaub

    Isabella Porter is the director of compliance and privacy officer of District Medical Group and author of the chapter “Patient Privacy and Security:  Business Associates” in the Complete Healthcare Compliance Manual.

    In this podcast she shares the key consideration that covered entities – physicians, hospitals, health plans and others who fall under the requirements of HIPAA – must consider when working with their various business associates (BA) with whom they share personal health information (PHI).

    When considering a potential new business associate she recommends ensuring that the vendor understand that it meets the definition of a business associate. Quite often they do and already have on hand a business associate agreement. It’s preferable to ask them to default to your own agreements, but if they do not – for practical reasons business associates with a large number of customers cannot accommodate each customer’s agreement – see if they are willing to amend their own, if necessary.

    When assessing a BA, also take the time to determine if they are using subcontractors. If they do, they should be referenced in the BA agreement. Also, ask the vendor what kind of checks they are doing on their vendors and their own ongoing monitoring efforts

    One important thing to also check: where the data is housed. If the servers are outside of the US, there may be other laws to consider such as the European General Data Protection Regulation (GDPR).

    Listen in to learn about the requirements of ensuring the safety of your BA agreements, including ten elements that need to be included in each one.
    16 min
  • Geert Vermuelen on the EU Whistleblower Directive [Podcast]
    Posted by:  Adam Turteltaub

    The EU Whistleblower Directive, enacted in 2019, has as its primary goal to protect whistleblowers. As Geert Vermuelen, CEO of The Integrity Coordinator and long-time compliance professional explains in this podcast, the Directive reflects a significant change in course for the EU where, for a long time, there had been a great hesitancy to trust whistle blowing.

    The Directive reflects a new approach that embraces the idea that, if whistleblowers are better protected, we can better detect and prevent harm to the public.

    The directive applies to organization of 250 or more employees, and from the end of 2023 companies as small as 50 employees. In addition, it applies to all companies in financial services, regardless of size, as well as those subject to AML legislations. These include real estate brokers, law firms and accountancies.

    Whistleblowers are protected against retaliation, and the burden of proof is shifted to the employer, who must prove that any adverse action taken against a whistleblower was unrelated.

    Other provisions of the Directive include:

    * Non-disclosure agreements are invalid in the context of whistle blowing
    * Reports at subsidiaries may only be reported up to the group level if the whistleblower permits
    * There must be secure and confidential whistle blowing channel for each legal entity
    * A neutral party must receive the report and follow up
    * The compliance team can be that party but its charter must reflect its independence
    * GDPR still applies, but when processing personal data of the accused person, he or she does not need to be immediately notified
    * The identity of the reporter must be kept confidential, unless the reporter agrees with making the identity public
    * The reporter should be notified of the receipt of the report within seven days and provided substantial feedback on the report within three months

    Adding to the complexity is that each country in the EU will need to pass its own laws to implement the directive, leading to subtle, and potentially significant, differences from nation to nation.

    All in all, it’s a substantial change and worth listening in to learn more about what the EU Whistleblower Directive means for your compliance and ethics program.
    12 min
  • Seth Whitelaw on the Opioid Crisis and the Risk of Diversion [Podcast]
    By Adam Turteltaub

    While the Covid pandemic has grabbed the headlines, opioids have continued to kill Americans in large numbers.  As Seth Whitelaw, President and CEO of Whitelaw Compliance Group  explains in this podcast and in the chapter “The Opioid Crisis and the Risk of Diversion” in the Complete Healthcare Compliance Manual, while prescription-related deaths have seen some decline, they remain far too high, largely due to the problem of diversion into illegal forms of distribution.

    To prevent diversion, healthcare providers and their compliance teams need to pay close attention to the information they are receiving.  Distributors, manufacturers, physicians and pharmacists all generate and have access to prescribing data.  It’s essential to ask questions such as is the patient demonstrating addictive behavior?  Is a physician writing prescriptions at a rate suggesting he or she is spending little to no time with patients before prescribing?  Did the pharmacy order ten times more opioids than usual because something is awry, or because someone innocently added a zero at the end of the order?

    All of this means there is a strong human element to controlling diversion.  While the automated systems are good at identifying outlying activity, there is still a need for a person to find out what exactly is going on.  That can include seeing if there is a line of people waiting outside a physician’s office, or if a pharmacy parking lot is filled with out of state license plates.

    There are not necessarily any bright lines, he explains, which makes it all the more important to pay attention and make the necessary disclosures to the DEA if a good explanation cannot be found.

    Listen in to learn more, and be sure to check out the Complete Healthcare Compliance Manual.
    12 min
  • Nathan Mendelson on the Latest in US Antitrust [Podcast]
    Post by:  Adam Turteltaub

    Antitrust is a long-time risk area for compliance teams to manage, but its longevity does not mean it is not evolving.  New issues arise as times and Administrations in Washington change.

    Nathan Mendelsohn, Associate in the Washington, DC office of the law firm Wilson Sonsini Goodrich & Rosati lays out what is new in antitrust in this podcast and in the chapter “Federal Antitrust Law Risks – 2022” in The Complete Compliance and Ethics Manual.

    Some areas of antitrust law are well known.  Agreements by competitors to rig bids, allocate markets or set prices are generally considered illegal per se and can open up the door to criminal prosecutions of both individuals and organizations.

    Other kinds of agreements, he explains, are subject to what is known as the “rule of reason”.  In a nutshell, it calls for an assessment as to whether the agreement makes sense and was not designed just to protect the parties and unfairly hurt others.

    As for compliance programs in antitrust, the ground is changing.  During the leniency program era, only the first company to self-report anticompetitive behavior received credit.  Its co-conspirators, no matter how good the compliance program, received none.  Then in 2015 the Department of Justice began giving credit for forward looking compliance programs:  what the company had done since the violation to protect against its reoccurrence by strengthening compliance efforts.  Then, beginning in 2019, the Antitrust Division began, at least on paper, giving credit for existing compliance programs.  Thus far, though, no organization has qualified for it.

    At the same the focus of attention for the DOJ has continued to evolve, most notably when it comes to the labor market.  The division has pursued several cases related to no poach agreements, in which companies agree not to poach each other’s workers.  Many believe that this has kept wages lower than they might be.   Non-compete agreements are also under scrutiny.

    Another trend to watch out for: transnational prosecutions.

    Listen in to learn more, and be sure to explore what’s available in The Complete Compliance and Ethics Manual.
    15 min
  • Kortney Nordrum on Social Media Risk in 2022 [Podcast]
    Posted by:  Adam Turteltaub

    Social media keeps evolving:  From MySpace to Facebook to Twitter to SnapChat to TikTok to whatever comes next.  One thing stays the same, though:  there are lots of compliance risk.

    In this podcast Kortney Nordrum, Regulatory Counsel and Chief Compliance Officer at Deluxe and author of the chapter “Social Media Compliance” in The Complete Compliance and Ethics Manual shares both the state of the regulatory landscape and practical advice on how to best manage the challenge.

    When it comes to regulators, several have weighed in, she reports.

    * The National Labor Relations Board (NLRB) has wavered back and forth on various issues but has consistently emphasized that employees may use social media, and employers cannot limit their activities so long as those activities do not have negative impacts on the reputation or credibility of the business. There are, however, a great number of nuances, including that griping about an employer is generally protected.
    * The Securities & Exchange Commission (SEC) is focused on ensuring that anyone who invests has access to company information at the same time. As we have all seen with Elon Musk’s ongoing battles with the SEC, they tend to frown on certain statements made on Twitter.
    * The Equal Employment Opportunity Commission (EEOC) has been consistent in its approach, warning that companies that do social media searches of their employees need to recognize that this may reveal an employee is a member of a protected class, and that information may not be used in a way that adversely affects the employee.

    For compliance teams it’s important to lay out social media policies using rules that are easy to understand.  The rules need to be reasonable, simple and use plain language.  An example may be, “Do not share confidential information,” with an explanation of what confidential information is.

    When working with the team that controls the organization’s social media account, have a separate policy for them since different issues likely apply.  Provide them with training and be prepared to serve as an ongoing resource eager to engage in conversation about what is good and bad practice.

    In short, social media and the related risks are here to stay.  In fact, you’re reading this on a form of social media.  So, it’s best to listen in and learn how to manage the risk.
    12 min
  • Lisa Beth Lentini Walker on Compliance in Remote and Hybrid Environments [Podcast]
    Posted by:  Adam Turteltaub

    Even if Covid were to disappear tomorrow, it’s clear that things will long remain different, including how we work.   Many employees will never spend eight hours a day, five days a week in the office again.

    So how should compliance teams address the new work environment and ensure a culture of compliance?  That’s the subject of this podcast with Lisa Beth Lentini Walker (LinkedIn), CEO & Founder of Lumen Worldwide Endeavors and a member of the board of the Society of Corporate Compliance and Ethics & Health Care Compliance Association.  It’s also the subject of the chapter “Building Cultures of Integrity in Remote and Hybrid Environments” in the latest edition of The Complete Compliance and Ethics Manual.

    As Lisa Beth explains, even though we have grown accustomed to new ways of connecting online, it’s still not the same as being in the same physical environment with someone.  That’s a challenge, she reports, because there is an element of proximity bias in how we interact, preferring people that are closer to us.  This bias will require a conscious effort to avoid creating an “us-them” culture where those who are in the office differentiate themselves from those who aren’t.

    Preserving and strengthening a corporate culture will also be a greater challenge since culture, itself, is an accumulation of experience of everyone in the organization.  When people are less connected, it takes more work, particularly when it comes to communication, to build clarity around vision and values, the stories people tell about the organization, and the support of leadership.

    Compliance teams will need to be alert for signs of trouble, including ethics incidents and disengagement.

    To address these problems, she recommends starting with the senior team.  Educate them as to what is happening and gain their support for a renewed, resilient culture of integrity.  Then, make sure the policies and procedures are designed to help support the culture.

    Throughout, it’s important to communicate, not just once but frequently,  More, you need to do so in a tailored way that reflects the needs and mindsets of the various groups within your organization and encourages their feedback.

    Listen in to learn more about how to build and sustain an effective compliance and ethics program in the new work world.
    12 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners