Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Nick Culbertson on Data Breaches in Healthcare [Podcast]
    Post By: Adam Turteltaub

    Preventing data breaches is a critical task for all businesses these days, but it’s especially so in healthcare. No one wants to see health information disclosed, and the risks of a ransomware attack are enormous, literally putting lives at stake. And, of course, there are significant consequences under HIPAA.

    Nick Culbertson, CEO and co-Founder of Protenus, reports that there were well over 700 breaches in healthcare in 2020. Over 40 million records were affected. It’s a staggering number, and one such breach exposed over 3 million records.

    Breaches occurred in 49 of 50 states and Puerto Rico. In sum, nowhere is safe.

    What can healthcare organizations -- and others, too, for that matter -- do to protect themselves? He recommends taking a layered approach. That includes security measures such as strong firewalls but also extensive training of employees, penetration testing and audit log monitoring. In sum, embrace multiple layers of defense that can protect against a wide range of possible mishaps.

    In addition, as he explains in this podcast, it is important to take a broad view of the human risk elements. These range from snooping into records to find out if someone does or does not have COVID, to failing to dispose of paper records properly, to bad actors offering furloughed employees cash for their passwords and IDs.

    One other area to protect against: breaches through business associates. With increased integration of providers and their suppliers comes dramatically increased risk. The largest incident in 2020 was the result of one such breach.

    The bottom line, he reports, is that organizations need to invest more in their cybersecurity, but compliance and privacy teams also need to stay on the alert for simple, human failings.

    Listen in to learn more about how to protect your organization.
    14 min
  • Justin Beals on HIPAA and HITRUST [Podcast]
    Post By: Adam Turteltaub

    HIPAA?  HITRUST?  One you have to follow (or else), the other it may be time to pursue.

    In this podcast Justin Beals, CEO & Co-Founder of Strike Graph provides a primer on HITRUST and what companies thinking about pursuing certification need to consider.

    HIPAA, he explains, is a legal requirement providing rules for how healthcare data must be handled, and penalties for when it is mishandled.  HITRUST is not a legal requirement but a standard.  An organization can get assessed against it and even certified.

    Why should you pursue it? There are many reasons, but, likely the most compelling is that healthcare providers require HITRUST certification from their vendors.  With approximately 70% of data breaches traceable to third parties, organizations are demanding that their suppliers take strong steps to ensure the security of their systems.

    Pursuing HITRUST certification can be a long process, Justin explains.  As a result, one key to success is starting early and avoiding the temptation to go too fast.  It’s not supposed to be fast and easy.  Plus, it requires the collection of significant data.

    A second key to success:  recognizing that this represents a culture change.  Attitudes toward security will likely need to evolve, and data protection is now more important than ever, bringing with it a host of changes that need to be implemented.

    A concerted communications and education effort will be needed to achieve success.  With so many breaches beginning with human errors, the workforce has to know what to watch out for, what to avoid, and why cybersecurity must be taken so much more seriously.

    Listen in to learn more about HITRUST and the challenges and rewards in implementing it in your organization.
    12 min
  • Brooke Nelson on Reporting and Investigations [Podcast]
    Post By: Adam Turteltaub

    Brooke Nelson (LinkedIn), Executive Director, Worldwide Compliance and Business Ethics at Amgen had a unique and broad perspective on managing compliance during the pandemic.

    In this podcast she shares what she has seen, including a drop in incidents in many areas.  Part of that, she believes, is likely due to the fact that people were disconnected.  With sales reps less able to make calls on medical practices there were less interactions and less opportunities for things to go awry.

    When it comes to investigations the adjustment to the pandemic has gone better than might be expected.  As she notes, global organizations have always had to rely on some remote methods in the past when conducting investigations since you didn’t necessarily have compliance staff in every location.  During this era, though effective investigation practices in distant locations have likely grown more effective.

    However, there remains a strong case for conducting at least some aspects of the investigation in person.  An in-person meeting can give a clearer read of the individual.  In addition, the presence of an investigation team may lead other individuals on site to share information that they might not have.  An investigations team physically present also offers another benefit:  it demonstrates the company takes investigations seriously.

    With the US and other regions hopefully soon reopening, she does warn that compliance teams should be prepared, if they aren’t already, for change.  It is time, for example, to reiterate the need for the workforce to reach out and report their concerns through the helpline and other channels.

    Compliance should also look out across the organization to better understand what is happening on a country-by-country basis, both for the business units and for the compliance team, itself.  There are likely significant disparities and a need to adjust efforts and expectations accordingly.

    And, of course, the way we all work has changed, perhaps permanently.

    Listen in to learn more about our recent past and what to consider moving forward.
    13 min
  • Suzanne Gellner on System Improvement Agreements [Podcast]
    Post By: Adam Turteltaub

    A Systems Improvement Agreement (SIA) comes at a time of crisis for a healthcare organization, one in which it may even risk being terminated by CMS. As Suzanne Gellner (LinkedIn), Principal, The Gellner Group explains, an SIA involves a lot of work that must be done quickly, typically within just 12 months.

    For organizations undergoing an SIA she recommends creating an oversight committee made up of C-Suite leaders and others with oversight of the service areas under the SIA. This will help make sure that these same service areas are accountable.

    The committee would ideally have each group meet with them monthly and provide status updates.

    Leadership support is critical, but so too is the support of middle managers. They are going to be the major change against, she explains, who understand what is happening on the front lines, and what leadership wants to see happen. They are also the individuals who will be coaching the staff into how to meet the goals of the SIA.

    To help the managers, take the time to learn what their likely pain points are, what their day-to-day work life looks like and what challenges they perceive. With that knowledge you can better demonstrate how the SIA initiatives will help them in their work. Done right, it can turn them into ambassadors for the changes the SIA requires.

    Suzanne also recommends taking a unit-by-unit approach rather than a system-wide approach to the SIA. Each service area is going to be different. The challenges and people will vary. As a result, it’s essential to understand where they are and how the program will benefit them the best.

    In addition, once there is success in one unit, the others will likely notice, recognize the benefits and be more eager to implement the SIA.

    Listen in to learn more about how to successfully navigate an SIA in your organization.
    12 min
  • Jabu Sengova on Government Ethics Programs [Podcast]
    Post By: Adam Turteltaub

    “Government ethics” is not an oxymoron. In fact, according to Jabu Sengova, Ethics officer for the City of Atlanta, government ethics programs are very real.

    In this podcast she provides an overview of how Atlanta’s works. She shares that when it comes to ethics in the public sector there are several areas of focus including conflicts of interest and the misuse of public assets such as credit cards and cars.

    Managing conflicts of interest has been a particular problem during the pandemic. With employees working from home there has been a noted increase of incidents revolving around second jobs and operating a business on the side. It is a problem likely facing the private sector as well.

    And, of course, there are the ongoing challenges involving gifts and gratuities, especially for those city employees who work regularly with contractors and vendors.

    Meeting these challenges isn’t easy for the ethics team. They serve a large 8,000 person employee base  with very limited resources. In addition, until recently there was a strong preference for in-person training. Atlanta is only now moving into elearning.

    Yet, despite lagging in some areas, there is much, Jabu argues, that corporate compliance programs could learn from government ones, including resiliency. She notes that in her time there she has worked for three different mayors.

    Business could also learn about doing more with less, she believes. For much of her time in Atlanta, there were only two or three members of the ethics team.

    Listen in to learn more about government ethics programs and what everyone can learn from them.
    12 min
  • Jim Passey on Making it to the Top [Podcast]
    Post By: Adam Turteltaub
    Jim Passey, Vice President, Chief Audit & Compliance Officer at Honor Health sat down with us to record three podcasts focused on compliance career development:


    Setting Career Goals
    Moving Your Career Forward
    Making it to the Top

    It isn’t enough just to set your eyes on the goal of chief compliance officer. Nor is it probably advisable to walk into the CEO’s office and make your pitch should the job become open.

    In this podcast Jim Passey, who has been a Chief Compliance Officer for six years and at two organizations, share his advice for crossing the threshold from staff to leadership.

    He advises that you start the process long before the job opens up. Be visible and make yourself known in meetings and on key projects as an active participant, not just another body in the room. Let people see you as an agent for positive change and a key voice at the table. That will both help your career, and help others take the compliance program more seriously.

    Let your supervisor know you are eager to advance. Couch it in terms such as “I want to take on more responsibility” or “I’m eager to add value.” An emotionally intelligent manager shouldn’t take that as a threat, but instead take it as an opportunity to help you grow. Plus, if you don’t make your intentions clear, you may be passed up for someone else who has.

    When the top job does open up, it’s important to remember that the CEO, board, or whoever else is doing the actual hiring probably has never worked in compliance and lacks a full understanding of the job. You will need to bridge that knowledge gap.

    You will also need to remember that, at the top level, technical skills, such as expertise in specialized areas of law, are likely to be less important than personality characteristics and fit. Leadership wants someone who is going to be able to partner with them.

    It’s also important to remember that the interview is a two-way street. Be prepared to ask questions that will you determine if the job (especially at an unfamiliar company) is right for you. Consider questions in your head such as: Does this conform to my perception of an environment I want to work with? What kind of support will I get? Are the leaders a strong, compliant type of a group, or are they just trying to fill the role?

    Listen in to learn more about how you can improve your chances of making it to the top of the compliance profession.
    12 min
  • Carrie Penman on Helpline Data Since the Pandemic [Podcast]
    Post By: Adam Turteltaub

    NAVEX Global recently released its 2021 Risk & Compliance Incident Management Benchmark Report.  It is a document rich in data about what’s going on with helplines and incident management.

    To understand lessons learned from the data we invited Carrie Penman, Chief Risk & Compliance Officer from NAVEX, to join us.

    She reports that there is finally an answer to a question many have wondered: what has the pandemic’s impact been on helpline call volume. Interestingly, Carrie reports that overall call volume declined. April and May 2020 saw the steepest drops, not surprisingly since that was the time when businesses were closing quickly and employees were adjusting. But, she points out, it was not just a two-month phenomenon. Even at the end of 2020 volume had not returned to pre-pandemic levels.

    Drilling down into the data there were significant variations by industry, with differences caused by whether organizations had switched to a work-from-home mode or had large number of essential workers still on the job site.

    But what about the quality of the calls? Carrie reports that the substantiation rate of 42% was in line with previous years.

    There was one exception, though: environmental health & safety. Substantiation rates were lower, and the number of reports increased substantially, likely due to COVID-19 related concerns.

    Interestingly, 76% of EH&S reports were anonymous vs. just 54% of business integrity claims, most likely not out of fear but because complaints about things like not wearing a mask where a call back was not likely necessary.

    The report also includes news that the median days between incident observed and reported increased from 21 to 28 days. That’s troubling for investigators given that memories fade over time.

    Finally, we discuss the perennial concern about whether anonymous reports can be trusted. The data showed that anonymous reports were substantiated at a much lower rate: just 35% vs. 50% of reports with a name attached

    Listen in to learn more, including some potentially troubling numbers about retaliation.
    15 min
  • Jim Passey on Moving Your Career Forward [Podcast]
    Post By: Adam Turteltaub
    Jim Passey, Vice President, Chief Audit & Compliance Officer at Honor Health sat down with us to record three podcasts focused on compliance career development:


    Setting Career Goals
    Moving Your Career Forward
    Making it to the Top

    You’ve set your career goals. You’ve mapped out the interim steps. Now, how do you keep moving along the path you have made for yourself?

    The first step that Jim Passey outlines in this podcast is to do your homework. Compliance, he explains, is about giving good advice. As a result, nothing can destroy your credibility (and prospects) faster than giving bad advice.

    To avoid that trap he advises investing the time to understand the government’s expectations. That begins, of course, with the Federal Sentencing Guidelines, but it doesn’t stop there. Stay on top of what is going on in enforcement. Focus on what the enforcement community is focusing on. Also, have a strong grasp of your organization’s business so you know to implement your program effectively within its culture. That includes understanding the structure and political flow of decision making, including who has formal and informal authority.

    That’s only the beginning. As we all know, compliance isn’t just about knowing what the law and regulations requires. In many ways that is the easy part. The more difficult challenge is getting people to comply. Success is guiding behavior comes from persuasion, collaboration, motivation and inspiration.

    So, to ensure success for your compliance program and your career, it is essential to develop strong communication skills, and even know a bit about salesmanship.

    Negotiation skills are also a necessity. There are lots of grey areas in compliance where the laws and regulations aren’t perfectly clear, or a new business idea doesn’t fall neatly within existing frameworks. Having the ability to navigate the grey and find a potential solution is an invaluable skill.

    What else does he recommend? Be dependable. Take initiative. Be the voice of solutions not problems. Work well with others. Build your network. Get involved in the compliance community, and take advantage of what SCCE and HCCA have to offer. You can even start with this podcast.  Listen in.
    14 min
  • Susan Roberts on Creating a Compliance Book [Podcast]
    Post By: Adam Turteltaub

    Cataloguing everything your compliance program does isn’t easy, but Susan Roberts (LinkedIn), who recently retired from full-time corporate life after serving as Chief Compliance Officer at three different companies, did just that. And in this podcast she advocates for doing the same for your compliance program.

    She made it a habit to create what she and her team referred to as, simply, “the book.” It is designed to be a comprehensive resource should the government (or even management) want to know whether the company has an effective compliance and ethics program.

    To make your book both useful and complete, she advocates breaking the book into several sections including:

    * An introduction
    * Background
    * Executive Summary
    * Relevant expectations for compliance programs from government, industry groups and elsewhere (US Sentencing Guidelines, DOJ Fraud Section compliance program guidance, FCPA Resource Guide, and so on)
    * A description of the compliance program including sections on:

    * Program oversight
    * Tone at the top
    * Risk assessment
    * Monitoring and auditing
    * Standards, policies and procedures
    * Training, communication and awareness
    * Confidential reporting systems
    * Investigations
    * Corrective actions
    * Discipline and incentives
    * Employee and other screening
    * Third-party management
    * Continuous improvement



    In sum, it should provide a full and rich picture of the compliance program including screen shots of training, the code of conduct and helpline posters.

    Having all that data in one place has paid off twice in very significant ways for Susan and the companies she worked for. In one case it helped convince the Department of Justice that a monitor would not be needed after trouble was discovered at a recently acquired business unit. The book helped demonstrate that the company was already doing everything listed in the Corporate Integrity Agreement. In another case, it helped an acquiring company have faith that there truly was an effective compliance program already in place.

    The book can also provide insight into where the program needs to improve, acting as something of a self-assessment tool. If you have much less to say in one section, it may be a sign of a program gap.

    List in to learn more about creating a book of your own, including how often to update it.
    14 min
  • Jim Passey on Setting Career Goals [Podcast]
    Post By: Adam Turteltaub
    Jim Passey, Vice President, Chief Audit & Compliance Officer at Honor Health sat down with us to record three podcasts focused on compliance career development:


    Setting Career Goals
    Moving Your Career Forward
    Making it to the Top

    In this podcast, the first in the series, he encourages individuals who are still early in their compliance career to take the time to gain a broad view of the industry they work in. For him, that is healthcare, and while many of the examples he cites in this podcast are healthcare-specific, they are equally applicable to other industries.

    As you gain an understanding of your industry, he recommends thinking about whether you want to make compliance a career or a stop along the way. If you think it is a potential career for you, he advises you ask yourself whether you are comfortable with conflict and being the bearer of bad news. Both are, for better or worse, an essential part of a being an effective compliance officer, and many are not comfortable in that role.

    Also, take the time also to assess what you aspire to do within compliance. Do you want to be the chief compliance officer or are you more comfortable at another level? Do you want to be a compliance generalist or focus on specific areas? To help find the answer pursue projects in a number of different compliance niches.

    One important consideration when setting career goals is geography. If you are committed to staying in one region, your prospects may be limited. There may be just one top compliance job in your industry in a given city. If that’s the case, you may need either to set your sights a little lower or be willing to look in other cities and states or industries. As he observes: the fast way to move up the ladder is to move to where the jobs are.

    Once you determine your career objectives take the time as well to identify intermediate steps along the way. This will help you set a path and measure your progress. Check regularly to see how you are doing, especially when major events take place, such as a new initiative that interests. It may encourage an adjustment in your plans.

    Listen in to learn more about setting your career on the right track.
    14 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners