Compliance Perspectives: Recent Episodes

SCCE

An SCCE Podcast

View Details

By Adam Turteltaub

Michael Savicki, Senior Vice President and Chief Risk & Compliance Officer at American Express Global Business Travel (Amex GBT), best known as Amex GBT, knows the challenges and opportunities in merger’s and acquisitions. The company recently completed the acquisition of CWT, a global business travel and meetings solutions provider.

In this podcast he shares their playbook for effective due diligence, born out of their experience and the heightened regulatory requirements that they face. Among the insight he provides:

  • Integrate your efforts with the business unit’s and work cross-functionally
  • Partner with finance and the commercial team
  • Have a solution-oriented “yes and” mindset
  • Be sure the due diligence process focuses on all the risks: legal, regulatory, operational and reputational

Perhaps most importantly: think beyond the transaction. Look to what the acquired entity will need post-acquisition. Embrace the technology that will help get you where you want to be, including AI, which can help spot emerging risks sooner, while freeing your team up to do more strategic work.

View Details

By Adam Turteltaub

Neurodiversity tends to be spoken of as an issue to be recognized and, quite often, as a barrier to overcome. Katie Roemer, Vice President, Compliance & Privacy Officer at Alta Hospital Systems see it differently: as an asset to your compliance team.

In this podcast she points out that many neurodivergent people excel at pattern recognition and system level thinking, as well as root cause analysis, all of which are of great value to compliance teams.

They can also help us to communicate better. Meeting their needs can help with general workforce training. Some examples include:

  • Avoiding densely packed slides with light fonts that are hard to read
  • Breaking the learning up into discreet pieces
  • Previewing what is going to be learned and the length of training
  • Letting the audience know what is the most important part of the training
  • Giving key takeaways and highlighting key points

To leverage the neurodiverse fully, she recommends creating a psychologically safe environment that encourages everyone to speak up without fear of consequences. This enables the expression of a diverse range of ideas from the entire team.

Listen in to learn more about the how the neurodivergent can be an asset to your compliance efforts.

View Details

By Adam Turteltaub

What do a secret wedding and Richard Nixon have in common with HIPAA? A lot more than you might think, shares Bailey Mack, Chief Compliance Officer at Together for Youth.

In this podcast she tells us the interesting history of privacy and the law. We begin in 1890 when a photographer trespassed to photograph a wedding he wasn’t supposed to be photographing. Thirty eight years later in the Olmstead case, wiretapping wasn’t deemed intrusive because no one entered the room. It was as if a privacy violation could occur only if there was trespassing involved.

That began to change in the 1960s in which thinking evolved and the idea gained currency that privacy was about violations of the person’s right to privacy, rather than to property.

Watergate led to further changes in which citizens were given access to government records about them. And, since then, more legislation has come and likely will.

Listen in to learn more, and if you’re an SCCE or HCCA member, don’t miss her article in Compliance & Ethics Professional® magazine.

View Details

By Adam Turteltaub

Executive presence isn’t simply walking in the room and having everyone instantly feel that that you are in charge. It is something different explains Jay Greenberg, the recently retired Chief Compliance Officer at the FBI. Instead, it is being powered by your core values and then making a maximum positive contribution to any situation by fully investing yourself to achieving that assigned mission.

Executive presence, he shares, is a skill acquired through the application of experience, coupled with a great deal of self-reflection that focuses on self-confidence, core values and the help of mentors.

Also of great value: preparation and confidence that is informed by past experiences, including failures. Even star leaders didn’t magically emerge, he reminds us. They learned from their failures, missteps and other learning experiences.

It doesn’t matter, he explains, if you are working with leadership or rank and file employees. Know your core values, who you are, your positive character traits and focus ahead of time. It will help you feel self-contained and confident. He also advises keeping a bit of mental distance, being both a participant and an observer at the same time. It will help you tailor your approach to the outcome you want. Also, be sure you understand the perspective of your audience.

Listen in to learn more about how you can master the skills of executive presence.

View Details

By Adam Turteltaub

Listen up people: It’s all about the people.

That’s the key message from Gabor Sulyok, Global Head of Commercial and Healthcare Compliance at BioNTech and experienced senior compliance counsel Luciane Mallmann.

At its core, ethics and compliance is a human endeavor. While regulations and standards provide the structure, it’s the people within an organization who bring these principles to life. A people-centered approach to compliance programs enhances engagement, supports better decision-making, and fosters a culture of integrity. From design to execution, every aspect of the program should reflect a deep understanding of how people learn, behave, and interact.

This means rethinking how we educate, maintain awareness, and ensure accountability. Policies must be relatable and actionable. Training should be immersive and role-specific. And accountability should be balanced with support to avoid creating a risk-averse culture.

They explain in the podcast that there are three key elements of a people-centered framework:

  1. Speak-Up Culture A healthy program starts with psychological safety. Employees must feel empowered to raise concerns without fear of retaliation.
  2. Transparency and Accountability Transparency builds trust. Training should include real-life ethical dilemmas and storytelling that resonates with employees. Sharing actual cases from within the company helps humanize compliance and makes it more relatable. Accountability, meanwhile, must be visible and fair. Leaders should model ethical behavior and be the first to complete training, setting the tone from the top.
  3. Ethical Decision-Making Decision-making frameworks should incorporate diverse perspectives and encourage thoughtful deliberation. Employees need tools to navigate ambiguity, and those tools must be grounded in the organization’s values.

Listen in to learn more about how to put people front and center in your ethics and compliance program.

View Details

By Adam Turteltaub

The rise of generative AI has brought transformative potential to healthcare—from streamlining administrative tasks to supporting clinical decision-making. But alongside these benefits comes a growing concern: Shadow AI. Alex Tyrrell, Chief Technology Officer, Health at Wolters Kluwer explains in this podcast that this term refers to the use of unauthorized, unmonitored AI tools within organizations. In healthcare, where data privacy and patient safety are paramount, Shadow AI presents a unique and urgent challenge both now and in the future.

Healthcare professionals often turn to generative AI tools with good intentions—hoping to reduce documentation burdens, improve workflows, or gain insights from complex data. However, many of these tools are unproven large language models (LLMs) that operate as black boxes. They’re prone to hallucinations, lack transparency in decision-making, and may inadvertently expose Protected Health Information (PHI) to the open internet.

This isn’t just a theoretical risk. The use of public AI tools on personal devices or in clinical settings can lead to serious consequences, including:

  • Privacy violations
  • Legal and regulatory non-compliance
  • Patient harm due to inaccurate or misleading outputs

Despite these risks, many healthcare organizations lack visibility into how and when these tools are being used. According to recent data, only 18% of organizations have a formal policy governing the use of generative AI in the workplace, and just 20% require formal training for employees using these tools.

It’s important to recognize that most employees aren’t using Shadow AI to be reckless—they’re trying to solve real problems. The lack of clear guidance, approved tools, and education creates a vacuum that Shadow AI fills. Without a structured approach, organizations end up playing a game of whack-a-mole, reacting to issues rather than proactively managing them.

So, what can healthcare organizations do to address Shadow AI without stifling innovation?

  1. Audit and Monitor Usage

Start with what you can control. For organization-issued devices, conduct periodic audits to identify unauthorized AI usage. While personal devices are harder to monitor, you can still gather feedback from employees about where they see value in generative AI. This helps surface use cases that can be addressed through approved tools and structured programs.

  1. Procure Trusted AI Tools

Use procurement processes to source AI tools from vetted vendors. Look for solutions with:

  • Transparent decision-making processes
  • Clear documentation of training data sources
  • No use of patient data or other confidential information for model training

Avoid tools that lack explainability or accountability—especially those that cannot guarantee data privacy.

  1. Establish Structured Governance

Governance isn’t just about rules—it’s about clarity and oversight. Develop a well-articulated framework that includes:

  • Defined roles and responsibilities for AI oversight
  • Risk assessment protocols
  • Integration with existing compliance and IT governance structures

Make sure AI governance is not siloed. Those managing AI tools should be at the table during strategic planning and implementation.

  1. Educate and Engage

Education is the cornerstone of responsible AI use. Employees need to understand not just the risks, but also the right way to use AI tools. Offer formal training, create open forums for discussion, and build a culture of transparency. When people feel informed and supported, they’re more likely to choose safe, approved tools.

  1. Protect PHI with Precision

In clinical workflows, PHI is often unavoidable. That’s why it’s critical to:

  • Deidentify patient data whenever possible
  • Ensure only authorized systems, processes, and personnel have access to PHI
  • Maintain up-to-date business associate agreements and data processing contracts

As you get closer to the bedside, the margin for error shrinks. Public devices and unlicensed LLMs should never be used in direct patient care.

The regulatory landscape around AI is evolving rapidly—especially at the state level and in the EU. Even if federal guidelines are still catching up, organizations must be proactive. Bake privacy by design into your AI strategy from the beginning. Treat compliance not as a burden, but as a strategic advantage that protects patients and enables innovation.

And be sure to listen to this podcast to learn more about the risks of shadow AI

View Details

By Adam Turteltaub

There are few parts of an investigation that are more stressful than the interview with the investigation’s subject. Done right it can close all the loops. Done wrong, everything can unravel.

To learn how to handle things best we turn in the second of our two podcasts on investigations to Wendy Evans, Senior Corporate Ethics Investigator, Lockheed Martin and Georgina Heasman, Senior Manager, Global Investigations at Booking Holdings. The two of them are the co-authors of our new book Fundamentals of Investigations: A Practical Guide and lead our Fundamentals of Compliance Investigations Workshop.

In this podcast they offer a host of great insights including:

  • While it’s generally best to interview the subject last, there are times, such as in cases of alleged harassment or data theft, where you likely will need to sit down for a preliminary interview sooner
  • Be sure to get a read on the subject and be respectful of the stress that they are under, including giving them psychological space before asking tough questions
  • Clarify your role in the process as a collector of facts and that you have not already decided that they are guilty
  • Invite them to share their perspective both in the interview and, if other things come to mind, afterwards
  • Remind them of the confidentiality of the process and the need to focus on the allegation, not who made it

Listen in to learn more, and be sure to investigate their book Fundamentals of Investigations: A Practical Guide and the Fundamentals of Compliance Investigations Workshop.

View Details

By Adam Turteltaub

Few people know more about conducting a compliance investigation than Georgina Heasman, Senior Manager, Global Investigations at Booking Holdings and Wendy Evans, Senior Corporate Ethics Investigator, Lockheed Martin. The two of them are the co-authors of our new book Fundamentals of Investigations: A Practical Guide and lead our Fundamentals of Compliance Investigations Workshop.

Not wanting to miss out on their expertise, we scheduled two podcasts with them.

In this, the first of the two, they share a broad overview of best practices for conducting investigations. Those include ensuring that even compliance team members not responsible for investigations have at least a fundamental understanding of them.

As for the investigation itself, they explain, to go well it begins with the first report. There has to be a clear line of communication and a culture that encourages employees to come forward.

Once you receive that initial contact, it’s important to remember that it tells the story only from one side. You need to ask questions to clarify what was seen and heard and start thinking about what other information you will also need to gather. To keep the information flowing, they recommend telling the reporter and everyone else you interview to reach out to you again if additional information comes to mind.

While testimonial evidence is invaluable, don’t stop there. As you gather the who, what, when and where, be sure to look for the documentary evidence that you need, which requires having strong relationships with departments that have it, such as HR and security.

And, throughout the process, stay focused to avoid going down rabbit holes or getting inundated with more information than you need.

Listen in to learn more, and be sure to check out Fundamentals of Investigations: A Practical Guide and the Fundamentals of Compliance Investigations Workshop.

View Details

By Adam Turteltaub

Uh oh. The Feds are in the front lobby with a search warrant. Things are bad, and you don’t want anyone on site to make it worse.

The secret is preparation, shares Veronica Xu, SCCE & HCCA Board Member and Chief Compliance Officer, HIPAA Privacy Officer, ADA Administrator at Saber Healthcare Group. That begins with establishing a cross-functional team that likely includes compliance, the general counsel, CEO, CTO and, depending on your industry, the chief medical officer and others.

Each should play a part in shaping the plan and be ready to play their part if a raid occurs.

In addition, onsite staff, right down to the receptionist, needs to understand their responsibilities, including whom to call for help. Not only will that avoid very costly mistakes, it will help reduce errors, fear and stress at what will likely be an extremely difficult time.

What an individual gets trained on will vary by role. Yet, there is one commonality to the training. Everyone needs to know the importance of staying calm, being polite and respectful.

Be sure to also outline the do’s and don’ts.

There’s one other thing she strongly advises: remember to communicate with your workforce. Be as transparent as possible and avoid conflicting messages. That will keep the lines of communication open and help avoid the speculation that can make the disruption even worse.

Listen in to learn more, and then take a fresh look at your current plans for responding to a government raid.

View Details

By Adam Turteltaub

Employees may trust an AI chatbot more than they trust you, and that’s not necessarily a bad thing, if it leads to more reporting.

In this podcast, Debbie Sabatini Hennelly, Founder & President of Resiliti shares that a recent survey conducted by Case IQ reveals that nearly 70% of respondents expressed no concerns about AI being involved in the helpline process. This openness is driven by several key factors: increased anonymity, ease of use, and a perception that AI offers a fairer, more impartial experience than speaking directly with a human.

These findings underscore a broader theme that continues to emerge in conversations about helplines: trust. Employees are more likely to report concerns or misconduct when they trust the system—when they believe their information will be handled confidentially, their identity protected, and their report taken seriously.

Not surprisingly, they also want to understand how their information is being used and how their anonymity is being safeguarded. This is especially important when helplines are outsourced to third-party vendors. Communicating clearly that the helpline is external—and therefore more secure and impartial—can go a long way in building trust.

But transparency doesn’t stop there. Employees also want to know what happens after they make a report. What’s the process? What can they expect next? Setting clear expectations and following through with updates helps reinforce that the organization is responsive and serious about addressing concerns.

It’s not enough to share this information only once a year during compliance training, she warns. Employees are constantly bombarded with messages and unless helpline communication is consistent and visible, it risks being forgotten or ignored.

Still, even with those reminders, barriers remain, especially fear of retaliation.

Organizations must address this head-on. First, there must be a clear, well-communicated prohibition against retaliation. But more importantly, leaders need to understand that retaliation isn’t always overt. It can be subtle—being passed over for key assignments, being excluded from team activities, or receiving the cold shoulder from colleagues.

Creating a culture where employees feel safe to speak up starts with leadership. Managers and executives must model the right behaviors, reinforce anti-retaliation policies, and foster an environment where concerns are welcomed, not punished.

One of the most critical—and often overlooked—elements of a successful helpline program is training leaders on how to respond when a report is made. Too often, well-meaning managers try to “get to the bottom of it” themselves. But when they start asking who reported what or conducting their own informal investigations, they can unintentionally obstruct the formal process and make employees feel unsafe.

A favorite tactic of hers for addressing this is to ask persistent leaders: “Do you want to be a witness and be deposed?” It’s a powerful reminder that involvement in an investigation has consequences—and that the best way to support the process is to let it unfold professionally and confidentially.

Listen in to learn more, and, hopefully, get employees to trust and speak-up more.

View Details

By Adam Turteltaub

If all you’re worrying about is tone at the top, you’re missing a key portion of the choir. With most people reporting to middle managers, they play in integral role in ensuring a culture of compliance and ethics truly permeates the organization.

Evie Wentink, Senior Compliance Consultant at Ethical Edge Experts observes that while many organizations invest in crafting comprehensive codes of conduct and articulate expectations for ethical leadership, they often fall short in equipping managers with the tools, training, and support necessary to fulfill those expectations. This gap can undermine the effectiveness of compliance efforts and leave companies vulnerable to ethical lapses.

At the heart of the issue is a lack of intentional communication. Middle managers are frequently expected to embody and promote ethical leadership, yet they are rarely given a clear understanding of what that entails. To bridge this gap, organizations must develop structured plans that define ethical leadership in practical terms. These plans should include specific deliverables, resources, and expectations tailored to the manager’s role. By doing so, companies can ensure that managers are not only aware of their responsibilities but also empowered to carry them out effectively.

Authentic, ongoing conversations led by these managers are a cornerstone of a successful compliance culture. These discussions should not be limited to formal training sessions or annual reviews. Instead, they must be woven into the fabric of everyday operations. Managers should be encouraged—and required—to initiate “ethics or integrity minutes” at the start of team meetings. These brief segments provide a consistent opportunity to address ethical topics, reinforce values, and normalize open dialogue about compliance issues.

To support these conversations, organizations should provide managers with practical tools. These might include:

  • Ethics spotlight cards that highlight key compliance themes.
  • News articles that can be used to spark discussion around real-world ethical dilemmas.
  • Access to updated policies and codes of conduct, with notifications when changes occur.

Tracking and analyzing these conversations is equally important. Compliance teams should maintain records of who is engaging in discussions, what topics are being covered, and which issues are generating the most questions. This data can be invaluable in identifying risk areas, refining training programs, and tailoring future communications. Often, the most common questions arise immediately after a training session, indicating that such moments are prime opportunities for deeper engagement.

Moreover, it’s essential to recognize the broader impact of middle management on organizational integrity. Prosecutors and regulators increasingly view middle managers as pivotal figures in corporate misconduct cases. Their actions—or inactions—can significantly influence whether a company succeeds or fails in maintaining ethical standards. Consequently, fostering a culture of accountability and proactive communication at this level is not just beneficial—it’s critical.

Ultimately, the goal is to create an environment where ethical conversations are natural, frequent, and valued. When managers consistently lead by example and facilitate open dialogue, employees become more comfortable raising concerns and asking questions. This cultural shift enhances transparency, reduces risk, and strengthens the overall integrity of the organization.

In summary, bridging the compliance gap at the middle management level requires a multifaceted approach: clear expectations, practical tools, authentic conversations, and ongoing tracking. By investing in these areas, organizations can transform their compliance programs from static documents into dynamic, living systems that truly support ethical behavior at every level from the top on down.

View Details

By Adam Turteltaub

Why did the AI do that?

It’s a simple and common question, but the answer is often opaque, with people referring to black boxes, algorithms and other words that only those in the know tend to understand.

Alessia Falsarone, a non-executive director of Innovate UK, says that’s a problem. In cases where AI has run amok, the fallout is often worse because the company is unable to explain why the AI made the decision it made and what data it was relying on.

AI, she argues, needs to be explainable to regulators and the public. That way all sides can understand what the AI is doing (or has done) and why.

To create more explainable AI, she recommends the creation of a dashboard showing the factors that influence the decisions made. In addition, teams need to track changes made to the model over time.

By doing so, when the regulator or public asks why something happened, the organization can respond quickly and clearly.

In addition, by embracing a more transparent process, and involving compliance early, organizations can head off potential AI issues early in the process.

Listen is to hear her explain the virtues of explainability.

View Details

By Adam Turteltaub

Despite being a Civil War era statute, the False Claims Act (FCA) always has something new going on. To find out what’s hot these days, we spoke with Joshua Drew (LinkedIn), a former federal prosecutor and chief compliance officer and currently a Member at Miller & Chevalier.

Lately, he explains, there has been a steady stream of activity.

  • May: The Civil Rights Fraud Initiative was announced by the administration and proposes to use the FCA against any federal funding recipient that it believes are operating DEI initiatives that violate antidiscrimination laws.
  • July: A new working group was created between the DOJ and HHS to focus on healthcare and life sciences. It encouraged whistleblowers to file action in areas such as Medicare Advantage, drug device and biologics pricing and barriers to patient access, amongst others.
  • August: A trade task force was created to encourage whistleblowing against tariff violators.

All of this occurs against a backdrop of activity by the Administration to identify and fight waste, fraud and abuse.

Listen in to learn more about where the Administration is focusing and what compliance teams can learn from recent actions.

View Details

By Adam Turteltaub

The possibilities of AI don’t stop with generative AI such as ChatGPT. Agentic AI may have more potential for compliance teams, Zahra Timsah, co-founder and CEO of i-GENTIC AI tells us.

Unlike generative AI, which is well known for its ability to create content, agentic AI can be used an internal enforcement agent. Trained properly, she tells us, it can look for a potential violation and stop it. For example, it can spot personal health information that is about to be transferred and redact the sensitive data automatically.

This ability to step in and take action will, she believes, free compliance teams from many routine tasks and allow them to shift their focus to matters that are more complex and fall within the grey area. It will also help teams speed up the rate in which new laws and regulations turn into effective internal policies.

In addition, agentic AI will be able to produce measurable value by demonstrating what it can do to manage risk, improve trust and increase efficiency.

Listen in to learn more about agentic AI’s ability to improve your compliance program.

View Details

By Adam Turteltaub

Lewis Eisen (LinkedIn) is the author of the book RULES: Powerful Policy Wording to Maximize Engagement, and he wants to change the way people think about and write policies.

Too often, he observes, policies contain parent-child language, with a scolding tone that turns people off and keeps them from wanting to read the policy, or even follow it. It also contains a great deal of complexity, laying out all the many processes and procedures.

Instead, he recommends that companies adopt policy statements that are simpler and can tie values that people can identify with. All the other stuff – complex procedures, examples, backgrounds and so forth – belongs elsewhere he argues, for employees to see after they have had the opportunity to see the policy and buy into it.

It’s an intriguing approach. Listen in to learn more about how to reimagine your policy-making process.

View Details

By Adam Turteltaub

Andrew McBride, Founder & Chief Executive Officer at Integrity Bridge, recently wrote an article entitled Generative Artificial Intelligence Use Cases for Ethics & Compliance Programs. Intrigued by the topic, I sat down with him for this podcast.

He shared that many compliance teams are charged with using AI but may not have the desire or know how to create and implement a use case.

He shares that AI is very good at doing a specific role and a specific activity. Consequently, compliance teams should consider not just the use of AI as a whole but specific needs that they have for it. He gives five specific use cases:

  • Interpreter. AI can translate documents and training in seconds. It can also help you distill long documents into pithy, usable summaries both for you and management.
  • Drafter. It can draft from scratch or improve what you have already put together, even creating interactive scenarios that can be useful in training.
  • Researcher. You do have to be mindful of hallucinations, but if you set up the AI to only use your own data or a trusted set of ources, it is more reliable. Do, though, always check its work.
  • Data Analyst. As compliance teams are called to amass and analyze more data, AI can help you do it, identifying, for example, relationships between training and calls to the helpline.
  • Monitor, Investigator, Auditor. AI can review both structured and unstructured data, helping you identify red flags.

Listen in to learn more, and then, start building your own use case for generative AI.

View Details

By Adam Turteltaub

Why?

Why are you asking that?

Do you really need to know it?

Is it going to tell you something you need to know?

Is it a question that anyone could even answer?

All of these are questions to ask yourselves and colleagues when they propose adding an item to your due diligence questionnaire.

As Kristy Grant-Hart (LinkedIn), author, speaker and Head of Advisory at Spark Compliance, which is now owned by Diligent, explains, too often due diligence questionnaires are filled with questions that are unnecessary at best and counterproductive at worst. They are born out a desire to cover all the bases not necessarily get you just the information you need.

Instead of throwing in everything including the kitchen sink, it’s far better to take, as elsewhere, a risk-based approach. Work directly with those who own the risk review. And, if the response doesn’t matter, don’t ask the question.

Listen in to learn more about how to create a due diligence questionnaire that gets the answers you need, and not the ones you don’t.

View Details

By Adam Turteltaub

With ever more attention paid to the role of boards in overseeing compliance, the question naturally comes up: Do boards even understand what makes for an effective compliance program? To help answer that question we spoke with Vera Cherepanova (LinkedIn), Executive Director of the non-profit Boards of the Future.

She shares the unfortunate news that many boards are not where they should be. They are not fully seeing culture as a risk factor and driver of misconduct. Nor do many understand their own duty to manage it.

That’s dangerous in these times, especially now that governments are paying closer attention to culture.

Forces, though, are starting to change the equation and force boards to understand the role they and compliance play together in ensuring both integrity within the company and business success. Supply chain issues and ESG, for example, have brough compliance in closer contact with the governing authority. So, too, is regionalization. As countries take divergent paths into more and more issues, the compliance team will be essential in helping the board understand the risks that they face.

More, though, will need to be done. Boards need to start addressing issues such as values conflicts like they do other risks. And, more people with compliance experience should be added to boards.

Listen in to learn more about what boards are and are not doing.

View Details

By Adam Turteltaub

With a rising focus on value-based care, and a new program seeking to make the approach mandatory, we spoke with Ed White (LinkedIn), Partner at Nelson Mullins.

Previous efforts to move toward value-based models, such as Accountable Care Organizations (ACOs), faced significant barriers due to regulatory frameworks like the Stark Law and Anti-Kickback Statute. These laws were designed to prevent financial incentives from influencing medical decisions, but they also limited the ability of hospitals and physicians to collaborate in ways necessary for effective value-based care implementation.

Recognizing these constraints, CMS and the Office of Inspector General (OIG) collaborated in 2020 to issue new regulations aimed at facilitating the transition to value-based care.

The next step in the transition is the new Transforming Episode Accountability Model or TEAM program, which will become mandatory in 2026. This program includes 740 hospitals across the country and targets five specific surgical procedures. Participating hospitals must coordinate care with a range of providers—including specialists, primary care physicians, labs, durable medical equipment (DME) providers, hospice agencies, and others.

The TEAM program is designed to last for five years, during which time hospitals are responsible for ensuring that patients are connected to appropriate post-discharge care, including follow-up with primary care providers. The goal is to reduce complications, avoid emergency room readmissions, and promote better health outcomes—all while keeping costs below a CMS-established target price.

To drive efficiency, the TEAM program introduces three financial risk “tracks”:

  1. Upside-only track – Hospitals can earn shared savings if costs come in below the target price.
  2. Moderate risk (upside/downside) track – Hospitals can either earn savings or incur penalties depending on performance.
  3. Full-risk track – This track will offer both greater risks and rewards.

According to industry consultants, two-thirds of participating hospitals are expected to lose money in the early phases of the TEAM program.

Hospitals must rethink their compliance, care coordination, and partnership strategies in the wake of these changes. Listen in to learn more about what this all means for your compliance program both today and in the future.

View Details

By Adam Turteltaub

Imagine that it’s time to move on from compliance to another role, either by choice or being voluntold. Does what you learned in compliance help?

Absolutely, according to Kortney Nordrum, Vice President and Senior Corporate Counsel at Deluxe. Amongst other benefits, it taught her how to break down large issues into more manageable pieces, better identify and manage risks and help deals close.

That isn’t to say the transition has come without challenges. She has had to learn to trust others to run compliance and also to be less risk averse.

Listen in to learn more about how your compliance skills can help if your career ever takes you to another profession.

View Details

By Adam Turteltaub

When Garth Jordan learned about the opportunity to lead the SCCE & HCCA, he was excited about the idea of helping to build trustworthy organizations. And, the more he spoke with the board and talked to his peers, the more convinced he was that this was the role for him.

Unlike our previous CEOs he came to the association not from compliance, but from the field of association management. He has served in leadership roles for the American Animal Hospital Association, Healthcare Financial Management Association and Medical Group Management Association. As he looked at SCCE & HCCA he saw a great opportunity for growth and greater impact.

He tell us in this podcast that he will be focusing on the complete range of things that we do, from publishing to creating events to providing certifications to facilitating networking.

Listen in to learn more about him and how he plans on using design thinking to help create a robust future for the SCCE & HCCA.

View Details

By Adam Turteltaub

What do cupcakes, cookies and compliance training have in common? More than you might think, reports Barbara-Ann Boehler, Senior Director of the Program on Corporate Compliance and Ethics at Fordham University School of Law. She successfully used the act of frosting the treats a part of a compliance learning exercise.

It’s a great, if unusual, example of experiential learning, which seeks to teach people by getting the learner to do the thing that they are learning rather than just sitting and listening.

A more common example of experiential learning is to create a case study in which the participants play different roles and see how the situation plays out.

This interactive approach to learning can be much stickier, figuratively and literally (if you use frosting) with lessons sinking in deeper and discussions lasting long after the session is over.

Listen in to learn more but, maybe, eat something healthy first.

View Details

By Adam Turteltaub

Being a leader is hard. Being a compliance leader is harder. Being a compliance leader in fast-changing times takes it up yet another level, but it’s not impossible.

Kim Jablonski, Chief Compliance & Ethics Officer at Bristol Myers Squibb shares that with these challenges it’s important for leaders not to think in static terms but to recognize that the landscape is constantly changing. The transformations include not just new laws and regulations but also new expectations for compliance programs, such as when it comes to taking a more data-driven approach.

At the same time, though, some things don’t change. For example, you need to communicate with the workforce the importance of acting with integrity, even when there is business pressure to deliver. That same message should come from leadership as well so that employees see integrity as a part of the culture and behavioral expectations.

For their part, compliance leaders, and their teams, need to have a deep understanding of the business and how it works. They must also be flexible with more than one solution to a problem.

She also advocates for a collaborative approach. Working together with a wide range of internal teams leads to better outcomes, both from a compliance and business perspective.

Most notably of all, she shares an insight that is relatable and very eye opening: We all have obstructed view seats. As she explains, we all only see a part of the picture and need to be mindful that we benefit from the views of others and that bad decisions are often the product of not being able to see the whole panorama before us.

Listen in for more eye-opening insights.

View Details

By Adam Turteltaub

There’s a car pulling up to your facility loaded up with a patient and a trunk full of risk.

Non-emergency medical transportation (NEMT) plays an important role in getting elderly and poor patients to their medical appointments and pharmacies. But, explains Colin May, Professor of Forensic Studies and Criminal Justice at Stevenson University, the amount of fraud is exploding. There are cases of billing when service was not provided, trips to facilities that are closed, overbilling, upcoding, overcharging for tolls, and more.

Enforcement authorities have been doing more to crackdown on this fraud, but providers need to be on the lookout for a host of schemes, including kickbacks.

Frontline employees, he argues, should be trained to look out for questionable, unusual situations that may be the sign that something improper is happening. Technology can also be deployed in areas such as pre-trip screening.

Listen in to learn more about this growing problem and what your organization could and should be doing about it.

View Details

By Adam Turteltaub

Things are a bit out of balance when it comes to Business Associates (BAs) in healthcare. Organizations invest a great deal of time and resources in vetting these third parties to make sure that they will safely handle data from the covered entity. But, when the relationship ends, those same organizations may overlook the risks to their data post-separation.

The problem is complex because different BAs will fall under different regulations and use data differently. Some may process but not retain data. Others may have terabytes of your data to return or destroy immediately. For others, there may be a law or regulation requiring them to hold onto that data for several years.

The compliance team, explains Marti Arvin (LinkedIn), Vice President, Chief Compliance and privacy Officer at Erlanger Health System, needs to ensure it is part of the process whenever a BA relationship is coming to an end. At that point, it’s time to reach out to the BA to ensure there is a plan in place for how data will be handled, and to begin documenting the process. This helps in case there is an incident later.

Listen in to learn more about what you can and should be doing to ensure that the close-out process is as healthy as it should be.

View Details

By Adam Turteltaub

Ahmed Salim wants you to change how you approach change. An active consultant to the compliance community and Healthcare Compliance & Regulations Adjunct Professor at DePaul University, he is passionate about following a disciplined approach to change management. Not surprisingly then, he’s the author of a new book from the SCCE & HCCA: Mastering Compliance Through Change Management.

In this podcast he explains that the concepts behind change management are simple. It contains 8 critical steps:

  1. Vision and strategy
  2. Building leadership and sponsorship
  3. Communications and awareness
  4. Training and acceptability building
  5. Implementation and reinforcement.
  6. Continuous monitoring and improvement
  7. Sustaining the change
  8. Feedback and adaptation.

So what are the keys to success along the way? First, have a vision and strategy you want. Second, get leadership and senior management buy in. Third, effective communication because if people don’t know about the change, what’s the point. Fourth, continuous monitoring to ensure that you are making the progress you want, and if you aren’t why.

To all that I would add two more keys: listen in to learn more about how to make change management a part of your compliance program. Then, get your copy of Mastering Compliance Through Change Management.

View Details

By Adam Turteltaub

As with so many other areas, communication, or a lack of it, can be a big problem when it comes to eDiscovery. Legal doesn’t always adequately communicate what it needs. The business unit doesn’t share information about all the technologies its teams are using to communicate, and compliance may be giving the wrong message as a result.

The cure, as Joey Seeber, CEO of Level Legal lays out in this podcast, is making sure that everyone is aware of the issues, the technology and what proper practices look like. That means understanding what platforms are being used for collaboration, and deletion schedules need to be understood and consistent, wherever possible.

To understand more about navigating around these problems, and how to find a vendor that will help your efforts, listen in to discover more about eDiscovery.

View Details

By Adam Turteltaub

On July 10, 2025 the European Commission posted The General-Purpose AI Code of Practice. Unlike the EU AI Act, this new Code of Practice is not compulsory, at least not yet.

Still, it seems prudent to start understanding what it says and what expectations are being laid, as well as what the definition of general-purpose AI (GPAI) is. To that end, we spoke with London-based Jonathan Armstrong, Partner at Punter Southall.

Jonathan explains that GPAI systems perform generally applicable functions such as image and speech recognition, audio and video generation, pattern recognition, question answering and translation. It is similar to generative AI but is not the same.

He then shares that the Code of Practice contains three sections: transparency, copyright, and safety and security.

Transparency is a hugely important issues for AI. Organizations need to keep their technical documents related to their AI use current and address topics such as how the AI was designed, the technical means by which it performs functions and energy consumption.

Copyright is a significant source of litigation at present. Authors and other content creators see the use of their work by AI engines as a violation. AI developers see the use of those works as furthering a greater good. The Code of Practice sets out measures designed to help navigate these difficult waters.

Safety & Security guidance is targeted predominantly at the most impactful GPAI operations. The Code calls for extra efforts to examine cybersecurity and the impact of the technology. This chapter of the document also includes 10 commitments for organizations to make.

Listen in to the podcast and then spend some time reviewing The General-Purpose AI Code of Practice. It’s worth seeing where regulations, and perhaps your AI efforts, are going.

View Details

By Adam Turteltaub

Managing whistleblowers is always a hot topic, and you’ll find it on the agenda at the 2025 SCCE Annual Compliance & Ethics Institute. To provide a preview of what you will see if you join us in Nashville, we sat down with the speakers for the session “Someone Blew The Whistle: Perspectives from Former Whistleblowers, In-House Compliance, and External Investigators”.

The speakers in Nashville, and guests of this podcast, are:

  • Jordan Segall, Senior Counsel, Ethics & Compliance, Xylem
  • John Pease, Partner, Morgan Lewis
  • Andrew Bakaj, Chief Legal Counsel, Whistleblower Aid.

In our conversation they share the work Xylem has done to encourage internal whistleblowing. The compliance team’s efforts include not just having a policy but ensuring that it is clearly accessible as well as explaining confidentiality, anonymity, and even investigative standards and processes.

The company offers their employees multiple avenues to speak up, including HR, internal audit, the hotline, compliance, and even the audit committee of the board.

These efforts are important, the speakers explain, because when whistleblowers go outside and bring a matter to the qui tame bar, typically it’s because they felt that their concerns weren’t taken seriously.

To help keep employees from going outside, they offer several recommendations. First, show employees that their concerns are appreciated and will be looked into. Second, explain the investigative process. Third, to the extent possible, provide regular updates. Fourth, clearly communicate what the next steps are.

Listen in to learn more, and then be sure to join their session at the Compliance & Ethics Institute in Nashville.

View Details

By Adam Turteltaub

There’s a lot new going on in healthcare enforcement, and, at the same, there’s a lot that hasn’t changed, reports Greg Demske (LinkedIn), partner at Goodwin Proctor and, formerly, Chief Counsel to the Inspector General at HHS.

While the US Department of Justice has changed its priorities in areas such as anticorruption, if you look at what they and the Office of Inspector General (OIG) at Health and Human Services have been doing, he observes, the long-time bipartisan effort to stop fraud in healthcare is continuing.

Yet, there are some significant changes. At CMS a major shift has occurred when it comes to Medicare Advantage. In the past there were audits of fifty plans a year, but now the goal is to audit all six hundred or so annually. Backing that up is an expansion in the number of coders from 40 to 2000. This has huge implications both for the plans and providers.

Meantime the Department of Justice and HHS have created a False Claims Act Working group to further their efforts.

Then, of course, there are qui tam claims, which hit a record high in 2024, and we have dispositions in the courts as well.

So what should compliance teams do? He recommends keeping a close eye on what the government is saying to ensure your program is staying ahead of the curve.

And, of course, you should listen to this podcast to gain more of his insights from private practice and over 16 years at HHS.

View Details

By Adam Turteltaub

I live in Los Angeles and was fortunate enough to get through the fires unscathed. Around me, though, were others who were not so fortunate. A cousin and several friends lost everything.

After the fires came a cleanup of epic proportions. For Glenn Sweatt, Vice President at ECC, the company charged with remediation at all those burned out lots in Altadena and the Palisades, that’s when the work began.

The workforce had to be assembled, contractors brought in, and everyone needed to be trained and trained well, since the company is a federal contractor.

Making that all happen required flexibility and agility. The compliance organization, like the company, had to be adaptable to changes in conditions and be responsive to local communities which suddenly, and unhappily, had thousands of trucks running through them.

Language had to be considered since Los Angeles is a diverse city. Spanish translations were expected. Hindi turned out to be more common than anticipated.

Listen in to learn more about the challenges the compliance team overcame, and, maybe, pick up some tips for how to handle compliance requirements at your organization when things are bad, urgent, and everyone is watching.

View Details

By Adam Turteltaub

Here’s a little nightmare every compliance officer dreads. You leave your current job for an exciting new one, only to find out that you just walked into a position where the compliance efforts are token at best because the organization’s leadership doesn’t take compliance seriously.

In this podcast Mary Shirley, Vice President, Chief Compliance and Privacy Officer, Scion Health, shares what to look for and how to protect yourself if this bad dream becomes your reality. And, for the record, she has not run into this disaster at Scion Health.

So, what are the signs there is insufficient commitment? Any or all of the following could be, although generally one or two, she notes, may not be definitive:

  • The title and standing of the top compliance officer is relatively low with little authority
  • The compliance teams is greatly understaffed compared to industry benchmarks (cross-industry, healthcare data), without some compelling reason such as the organization is undergoing financial difficulties
  • There is insufficient or no budget for necessary outside resources
  • A lack of management appetitive for even inexpensive compliance initiatives
  • Lack of support for professional development for the compliance team
  • Compliance not included in major deals or transactions
  • A chief compliance officer with no background in compliance

If you find yourself in a situation where the compliance role is not worth keeping, it’s best to determine if there is hope for change or if it is best to leave.

Either way, take the time to protect yourself by documenting what you have done and recommended, including what management ultimately decided.

To prepare to leave, turn to your network, if you have one. If you don’t have one, it’s time to start building it out.

And, regardless of whether you are in a bad situation looking for a better one, or just looking at a potential career move, she advises asking these questions during the interview to determine if the new position is one that is set up for success or failure:

  • What gets people fired around here? It’s a good way to see if there is real and consistent discipline.
  • Can I speak to my predecessor?
  • What would you like to see improved in the compliance program in the next six months?
  • How would you describe the company’s risk appetite?
  • What would the rank and file say about whether leadership is held to the same standards as they are?
  • What deliverables from the compliance team were rewarded?
  • What types of meeting does compliance attend? Does it have a seat at the table?
  • What professional skills development programs were the compliance team sent to or given last year?
  • What is the full-time staffing of the compliance office? What percentage of that is dedicated vs. liaisons?
  • Is there budget for travel for investigations, training, compliance and ethics week activities and other purposes as needed?

Listen in to learn more about how to find the right compliance role.

View Details

By Adam Turteltaub

There is so much hype and drama when it comes to AI, that it’s good to hear the voice of Mujo Vilasevic, Senior Compliance Officer, Raiffeisen Bank International. Contrary to most, he makes the case that the problem with AI is overdramatization. Despite the fears, it’s not going to take over the world or our jobs, as he sees it.

So what should be doing when it comes to AI? Educating ourselves is a very good start. Also, look at AI both, as he describes it, outside in and inside out: Look to see where it can be useful for the compliance department and how the business unit is putting it to use.

Do so, he advises, recognizing that there is, as of yet, no global regulatory consensus. While laws are emerging, there is still a patchwork out there.

However, there are some principles of responsible AI use that do seem to have global relevance. The EU law, for example, is based on the principles of integrity, data confidentiality, consumer data protection, personal data protection and the reliability of data used. Few would argue against them.

In sum, he argues for avoiding the easy temptation of fearing the unknown. Instead, learn what you need to know to understand this technology (starting with this podcast), and be prepared for global regulations to provide helpful guardrails.

View Details

By Adam Turteltaub

It’s time to think bigger when it comes to helpline data. Yes, it’s still important to look at traditional metrics such as the number of calls and the substantiation rate. But, there is so much more that can be done.

Justin Ross, Vice President, Chief Compliance Officer at Sysco and Carrie Penman, Chief Risk and Compliance Officer at NAVEX will be addressing what you can do with your helpline data during their 2025 SCCE Compliance & Ethics Institute session “Numbers That Matter: Moving Beyond Hotline Data to Identify and Build an Ethical Workplace.”

For one, they encourage compliance officers to think about whom they are sharing the data with. What the board, management and others will want to see is likely to be different. As a result, it’s important to tailor your reporting accordingly.

Second, they argue in this podcast that it’s important to not just look at the data reactively. Instead, think proactively and use it as a way to identify where there are issues to be addressed, either now or potentially in the future.

The data can also provide a window into the culture of the organization as a whole, as well as the differences by region or even office. This approach can help you better understand your risks and where you need to address potential problems.

Some of the data they suggest using is:

  • Outcomes of allegations: are they leading to discipline and is it consistent
  • Retaliation issues
  • Substantiation rates
  • Patterns of employee vs. non-employee reports
  • Number of days between allegation and conclusion of investigation
  • Number of days between incident and helpline call

Be sure, too, to look at the helpline data in concert with other data your organization has such as employee turnover, exit interviews, culture surveys, audit results and more.

In sum, to get the most out of your helpline data, think about all the data that you have, what it can tell about the past and present, how it can guide the future and what’s the best way to share it with each of your audiences.

Listen in to learn more, and plan on joining them for the 2025 SCCE Compliance & Ethics Institute.

View Details

By Adam Turteltaub

I recently learned that at the US Department of Justice’s law library, one of the most common requests the librarians receive is for vintage dictionaries. Why? Because the lawyers often need to find out what the definition of a word was at the time a law was passed.

Meanings change over time in the law and in the vernacular. Remember when describing something as “sick” meant that it was bad? Now it’s the opposite.

Stacey Parks, Ethics Officer, Enterprise Operations and International Ethics at Lockheed Martin will be taking on our evolving language at the 2025 SCCE Compliance & Ethics Institute. Her session is, appropriately, entitled, “Divided by a Common Language: No Cap. Here’s the Tea on How Being a Mom of a Teenager Made Me a Better Communicator.”

With five generations in the workplace today, it’s important to understand that each has its own communications style and what works for one may not for another. Millennials, Gen Z and Gen Alpha are all digital natives and are much more comfortable than their predecessors with online communication. They also tend to prefer shorter, more succinct messaging, including pictures and diagrams. For them, less is more.

Many are also “telephobic,” afraid of and uncomfortable using the phone for talking. They prefer texting and have a poor understanding of telephone etiquette.

What’s a compliance team to do? Think differently. Use lots of imagery, and even memes to communicate. Look to short form training, rather than long.

Learn their language, too, so you can be a better listener when they share their concerns.

And, before you dismiss these ideas, don’t forget how your felt when your parents (or grandparents) threw in the word “groovy” long after it was no longer so groovy to do so.

Listen in to this podcast and then be sure to join her in Nashville at the Compliance & Ethics Institute. It’s going to be sick!

View Details

By Adam Turteltaub

If you’re looking for compliance direction only from the US Department of Justice, you’re missing the wider picture. There is a lot going on in Europe that companies operating in that geography need to be complying with.

Dr. Tobias Kruis, Head of Corporate Compliance, Giesecke+Devrient, shares what is going on both in this podcast in his session “Dancing with the Acronyms: Jiving Through LkSG and CSDDDD in the European Compliance Ballroom” at the 2025 SCCE Annual Compliance & Ethics Institute.

The German Supply Chain Due Diligence Act, also known under the acronym LkSG, is focused on human rights, occupational health and safety and environmental projects. It requires regular and systematic risk assessments as well as remediation and preventative measures if risks are found. Grievance procedures are also a mandate, as are annual effectiveness reports on the supplier due diligence process.

Sanctions for non-compliance can be as high as 2% of annual turnover. The German regulator has already conducted over 1,000 proactive reviews since the act was adopted.

The EU Corporate Sustainability Due Diligence Directive was adopted in 2024 and builds on some existing national laws. The aim is to ensure a level playing field for companies in Europe by requiring them to address human rights and environmental concerns in the supply chain. It has much broader reach than the German law in its requirements, including a mandate to conduct due diligence beyond the first tier of suppliers.

While enforcement has not yet begun and several changes are contemplated, compliance teams can begin preparing now, taking a risk-based approach to their due diligence efforts. They should also start building cross-functional partnerships with HR, quality, management, procurement and the sustainability teams.

Listen in to learn more about what’s happening in Europe, and then don’t miss his session “Dancing with the Acronyms: Jiving Through LkSG and CSDDDD in the European Compliance Ballroom” at the 2025 SCCE Annual Compliance & Ethics Institute.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

There’s always a “but” when it comes to AI. It has great potential, but there’s always the risk of bad things happening.

In the case of the False Claims Act and healthcare, that’s very much the case.

In a recent article for Compliance Today – “AI and the False Claims Act: Navigating compliance in the age of automation” — Phoebe Roth and Colton Kopcik of Day Pitney warn that the same “but” applies to medical coding. AI and coding seem to be a match made in heaven. There is enormous potential for ensuring that bills get processed quickly and all the proper charges are made. But (of course) plenty of risks come with it.

First and foremost, a lack of human oversight can lead small errors to quickly multiply, especially if the AI model was trained on biased historical data or follows patterns of mis-billing. False claims can then can quickly spiral out of control, leading to expensive refunds and settlements.

Other areas of risk include telehealth and remote care fraud, especially at a time of increased government scrutiny of medically unnecessary services or improper billing.

So what should you do? It is prudent when embracing AI, they warn, to ensure that the algorithm is always up to date on the latest changes to the regulations. Whether the AI was created in-house or by a vendor, be sure there is a plan in place to monitor for changes and make accurate, real-time adjustments.

Having in place an AI steering committee is also a good idea. Be sure to include IT, coders, clinical staff, compliance and others.

Finally, turn the staff into your front line of defense. Help them be on the alert for potential issues so that you can head off problems before they become big problems.

Listen in to learn other ways to manage the “buts” of AI.

This podcast is for educational purposes only and does not constitute legal advice.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

As important as gaining access to the board is, using that time properly is even more crucial. Becky Rohr, Chief Compliance Officer and head of Investigations at Ericsson, will be sharing her insights and advice on this topic in her session “Board Reporting, Not Bored Reporting: Presenting to Boards and Other Senior Stakeholders by Using Data and Storytelling” at the 2025 SCCE Annual Compliance & Ethics Institute in Nashville.

In this podcast and preview of her session, she advises that, even before entering the boardroom it’s important to take the time to know your audience. Talking to the board, a board committee or senior executives is different since each has its own priorities. Be sure that what you say and show them speaks directly to their role. Remember, too, that the board is focused on the organization as a whole.

She cautions that the board will feel obligated to read anything you send it. So, be sure to avoid overwhelming them and to focus on the larger issues that could materially affect the organization.

When presenting data, don’t just give them the raw numbers. Prepare a concise analysis that tells them what those numbers mean and what the key takeaways are.

She found that a slide showing opportunities, challenges, highlights and lowlights in a simple quadrant graphic can be particularly useful. Dashboards, too, can be valuable, so long as every light on it isn’t green. That’s bound to raise suspicions.

Take the time, too, to anticipate what questions they are likely to ask. She warns that boards tend to want to know how the organization stacks up against its industry peers. So, be sure to take the time to benchmark.

Be sure to also take the time to listen to the podcast and join us in Nashville, September 14-17, at the SCCE Annual Compliance & Ethics Institute.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

What you don’t know can hurt you. And what you do know can hurt you. Such is the dilemma of background screening. Companies want to know who they are hiring, but, explains Al Firato, CEO & Founder of HireSafe, some information is off limits.

The 1964 Civil Rights Act and Title VII prohibit examinations of race, religion, ethnicity and more. In addition, federal and state regulations set limits on what background check firms can look at.

That’s not always a bad thing, Al points out. A conviction for a criminal offense from decades earlier should not be cause for immediate disqualification, especially if the person has since made amends. In addition, the conviction may not be relevant for the job at hand: a DUI for a prospective delivery driver is a lot different than one for someone who will be working at a desk all day. The EEOC has also made it clear that people are, in most cases, entitled to a second chance.

With that said, background checks can be very useful for revealing exaggerated academic and work histories. Many prospective employees take advantage of the fact that, with so many mergers, it may be difficult, if not impossible, to verify previous employment.

Listen in to learn more about the do’s and don’ts of background screening.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

Dr. Hemma R. Lomax, Vice President, Deputy General Counsel and Global Head of Ethics and Compliance for DocuSign thinks a lot about leaving a legacy, not just for herself but in general. She’ll be addressing the topic Beyond the Rules: The Future of Compliance is Legacy-Driven Leadership at the SCCE 24th Annual Compliance & Ethics Institute, which takes place September 14-17, 2025 in Nashville.

She is a strong advocate for thinking beyond quarterly goals and looking to operationalize best intentions to leave something behind that is more enduring. Getting there, she explains, requires first helping leaders understand that they know that a legacy is not out of reach, if they focus on doing the right thing and for the long run. Done correctly, the legacy they create can be an enduring strategic asset.

For compliance teams it means recognizing that every human has a survivor and a sage brain. And, while we in compliance need to embrace that survivor brain and embrace bad scenarios, we cannot be prophets of doom, raising already high anxiety levels.

Instead, we need to lead with transparency, embed purpose into processes, make ethics a design feature, and create internal accountability.

Listen in to learn more and then join her session in Nashville at the SCCE 24th Annual Compliance & Ethics Institute.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

Joint ventures are created to capitalize on a business opportunity, but they come with challenges. Each partner may have a different experience with or attitude towards compliance. They may have distinctly different cultures, and, in the worst case, may each be expecting the other to be watching compliance when, in fact, no one is.

Hassan Chaudry, a member of the SCCE & HCCA Board and Chief Compliance Officer of POSCO JV, a General Motors joint venture, recommends several keys to success in JVs. First, having meaningful conversations with leadership right at the start is important, especially if it is face-to-face. This helps establish rapport and makes top management more comfortable with the role of compliance.

Look to commonalities between the partners, not just the difference. In his case, with one party being from North America and the other from South Korea, there were different approaches and laws, but both countries are members of the OECD, and its guidance for compliance programs provided a common reference point.

Once the groundwork is set, take the time to meet with employees from senior and middle management, as well as the front line. Also, don’t forget the board: setting expectations with them and building an ongoing line of communication is essential.

He also recommends treating the JV like a start-up, not an established company.

Finally, put yourself in the shoes of joint venture partners. Look at the business from their perspective, and that will help you better understand what will make for a truly successful compliance program.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

Don’t take it personally if it’s taking you forever to find a new compliance job. According to Matt Kelly (LinkedIn), Editor and CEO at Radical Compliance, you’re far from alone.

It’s not that there aren’t jobs out there, he explains. There is just a hesitancy to hire due to the macro-economic environment. With so much economic instability and unpredictability, organizations are slower to hire.

Adding to the challenge is technology. A job posted on LinkedIn can generate hundreds or thousands of applications, making it more difficult for organizations to wade through them.

So how do you make yourself stand out and become a must-hire? He recommends moving beyond showcasing your ability to manage regulatory issues and instead focus on how your skills can help the organization navigate the range of operational risks that they face. Be sure to also shift from focusing on what you can do to defend the company to how you can help the company grow.

Finally, he advises showcasing your certifications and cutting edge experiences, and using technology to help. There are AI tools out there which will help you tailor your resume to the posted job description.

Listen in to learn more and accelerate your job hunt.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

Professors Todd Haugh (LinkedIn) and Suneal Bedi (LinkedIn) of the Institute for Corporate Governance & Ethics at the Kelley School of Business at Indiana University recently published a paper: Retheorizing Corporate Compliance. In it they argued strongly that compliance needs to be seen not just as a defense against potential corporate legal liability. It also needs to be recognized as a proactive offensive tool for building market share and competitive advantage.

On this podcast they explain that compliance creates numerous non-market strategies for helping the business. For example, organizations with stronger programs can demonstrate to regulators that they would be a good choice to acquire a troubled company. Leading compliance programs can also help to set the standard of practices for their industry, giving their organizations an advantage over those with lagging compliance practices.

In sum, by thinking of how compliance can help the business, not just protect it, there are significant opportunities created to grow the business, and change the way people think about compliance.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

In November 2024, the Office of Inspector General at Health and Human Services released its Nursing Facility: Industry Segment-Specific Compliance Program Guidance. The document is part of an effort to modernize how HHS OIG is communicating to industry and providing information about risks, how to mitigate them and best practices for compliance programs.

Jillian Willis (LinkedIn/Firm Page) and Melissa Scott (LinkedIn/Firm Page) of Nelson Mullins explain that the new guidance contains four main sections: quality of care and quality of life, Medicare and Medicaid billing requirements, Federal anti-kickback statute and other risk areas such as physician self-referral, HIPAA and related-party transactions. It shares best practices.

Notably, the guidance, complements other guidance out there, including the Department of Justice’s. And, in addition to focusing compliance efforts, it can be helpful for promoting operational efficiency.

Listen in and then spend some time reading the Nursing Facility: Industry Segment-Specific Compliance Program Guidance.

Listen now

The Compliance Perspectives Podcast is sponsored by Athennian, a leading provider of entity management and governance software. Get started at www.athennian.com.

View Details

By Adam Turteltaub

Professors Guido Palazzo and Ulrich Hoffrage are skeptical. When they hear that there was a bad apple at the core of a scandal, they are hesitant to accept that explanation. Instead, they argue in this podcast and in their new book, The Dark Pattern: The Hidden Dynamics of Corporate Scandals, that the problem is typically much deeper and wider.

There are dark patterns, as they call them, that lead to bad behavior. Underlying the patterns are nine building blocks. They explain:

  1. Rigid ideology is a shared belief system that narrows the view of decision-makers at the expense of other views, risking them losing sight of ethical dimensions.
  2. Toxic leadership can create fearful contexts when narcissistic, Machiavellian, or psychopathic leaders abuse their power and cause harm, be it through direct orders, leading by example, or a carrot- and- stick approach.
  3. Manipulative language restricts how things are perceived and evaluated, influencing people’s judgments, decisions, and behaviors in ways that contribute to evil.
  4. Corrupting goals and unrealistic targets divert people’s attention so that they lose the ability to see the bigger picture in which their decisions are embedded— and the ethical dimension of their behavior.
  5. Destructive incentives create a tunnel vision of reality and lead to unhealthy competition and fights.
  6. Ambiguous rules create a gray area where people at best are confused and at worst can morally disengage when they do something bad because, after all, they were just following the rules.
  7. Perceived unfairness can lead people to engage in illegal practices while feeling that they are restoring justice.
  8. Dangerous groups may force individuals to conform, encourage aggression against members of out- groups, or pressure those who are considering speaking up not to do so.
  9. Finally, people who are on a slippery slope may not realize how they are straying from the right path to the point of escalating their commitment to evil things without even realizing how they have changed.

While there are ways to manage for these risk areas, the challenge is that they are too often missed.

The solution they advocate for includes compliance teams educating themselves more in areas such as social psychology so that they are more attuned to the human factors.

Within the office there is a need for companies to resist the need to move on from scandals and to instead engage in deeper soul searching to understand what went wrong and why.

Finally, they are advocates for making ethics a much more important part of compliance programs.

Listen in to better understand what dark patterns are and how to keep them from taking hold of your organization.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

So you’ve got a case of AI fever and want to put the technology to work for your compliance team. What should you do?

Jordan Domash, Founder of Rersponsiv, urges you to first take a deep breath and think through the process starting with defining your goals. Interestingly, he shares, the goals can be affected by the solution you choose, whether you go with a solution that is homegrown or out of the box.

Either way, once the goal is set, expect an iterative process and regular testing to ensure that the solution is delivering what you were looking for, free from hallucinations and other problems.

To make that process work it’s essential to have an evaluation plan in place, which includes identifying all the potential failure points. Make a part of it conducting some manual tests to see if the AI is delivering the results it should.

In sum, AI can be invaluable to your program, but only if you put in the work to ensure that it is well designed and truly performing as it should.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

On May 12, 2025 the head of the Criminal Division at the US Department of Justice issued a memo to all Criminal Division personnel with the subject: Focus, Fairness and Efficiency in the Fight Against White Collar Crime.

To understand what the document means for compliance programs, we spoke with Amy Matsuo, leader for both Regulatory Insights and Compliance Transformation at KPMG. Overall, she sees the document as being good news for compliance programs. It reiterates the importance and value of quickly finding and remediating violations.

The DOJ also outlines some very favorable terms for organizations that self-disclose. These can include a declination with no requirement to enter into a criminal resolution, a non-prosecution agreement and a 75% reduction in potential fines.

The Department of Justice will also be reviewing settlements that are already in place and may provide relief if the organization is found to have made substantial progress, has a reduced risk profile and self-reported.

This review is a part of an effort to revisit monitorships and to ensure the cost to organizations is justified.

The Department of Justice also shared where it will be focusing its efforts. Procurement and program fraud, trade violations, sanctions violations and support to foreign terrorist organizations will all be in the cross hairs.

Listen in to learn more about what the DOJ’s expectations are and what you should be doing to ensure your organization meets them.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Andres Cuevas, Compliance Director LATAM for EmergentCold explains from Chile that for compliance officers to be successful in Latin America they need to stop thinking about Latin America as a whole and start thinking much more about each country and its culture.

And, of course, we must be mindful that each company also has a culture of its own.

To navigate the differences and build consistency, he advocates for having a strong set of baselines rules that are common across your enterprise and the region. Establish what is non-negotiable. But, at the same time, it’s important to work with local leaders to have an understanding of what the local realities are, work with them and respond accordingly when variations are necessary.

Compliance leaders also need to be mindful of the legal requirements of each country. In Chile, for example, he reports that there are more than 250 crimes that the company can be found liable for.

Listen in to learn more about how to navigate your compliance efforts successfully across this diverse region. He also shares what he has learned about managing compliance in a company growing through acquisition.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Mark Diamond wants you to stop thinking of records retention as a chore and start thinking of it as a driver of compliance. In this podcast the President & CEO of Contoural shares that retention schedules have grown in importance with increased requirements for privacy and safeguarding personal data. That, in turn, is having an enormous impact on the risks and costs of ediscovery.

Proper retention schedules also have significant impact on employee productivity and collaboration, as well as using AI in less risky ways.

Organizations are now increasingly treating records based on their business value and are developing retention schedules that reflect their worth.

One of the greatest challenges they face, though, is the tendency of employees to want to hold onto everything just in case. While it’s understandable, it adversely affects efficiency, as employees are forced to wade their way through obsolete records.

Part of the solution, he suggests, is to develop a “super schedule” for document retention. Rather than having multiple different policies which can cause confusion, having one overall policy vastly simplifies things for employees and allows for greater automation.

Listen in to learn more, but don’t retain this podcast longer than you should.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

In a recent issue of Compliance & Ethics Professional ®, Nick Gallo, Chief Servant and Co-CEO of Ethico addressed the control paradox, a situation in which the controls designed to prevent misconduct, actually encourage it. Think of it like the person whose car has so many airbags that they no longer fear an accident and drive quicker.

So what’s the solution? He argues it’s creating an environment where we have faith in controls, but not too much, and focus on helping those on the front line make the right decisions. That includes, he says, teaching not just what you should do but why. It also means encouraging ownership of ethical issues, not outsourcing it.

Listen in to learn more about how to get better control on your controls.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Recently, Gartner released very intriguing research into third party risk. Chris Audet, Vice President and Chief of Research in the Gartner Assurance Practice tell us that they found business has it’s spending all wrong. Too much is invested in due diligence, and not enough time and effort is spent on monitoring.

There research found that the business unit knows the risks third parties pose and is seeing it firsthand. When relationship managers were surveyed, 84% had seen changes to the risk profile and 76% found a third party had provided materially inaccurate information. In fact, 95% had seen something troubling in the past year.

So why aren’t they reporting this information to the compliance team and what would get them to share more? There were three main answers, Chris reports:

  1. Creating more relationship ownership objectivity. Too many feel too strong a tie to the third party.
  2. Confidence in identifying red flags.
  3. Encouraging objectivity and providing reassurance that compliance won’t over-react.

He also advises making it easy for third party relationship owners to contact compliance and to work compliance into the workflow.

Listen in to learn more about the benefits of rebalancing the third party risk equation.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Risk assessments are not new in healthcare, and in specific regulatory areas are required. But, that doesn’t mean things aren’t changing. More and more organizations are embracing enterprise risk assessments (ERM) as a way to assess the range of risks that they face, including legal and regulatory concerns.

Getting the risk assessment right is particularly challenging for healthcare organizations, explains Robert Stratton, Executive Director – Enterprise Risk and Security; Corporate Compliance Official and Senior Counsel for Northwest Permanente. Robert is also the author of the chapter “Enterprise Risk Management in Healthcare” in the latest edition of the Complete Healthcare Compliance Manual. The mix of insurance, patient care professionals, large sums of money and complex structures makes the risk map challenging.

On the positive side, electronic health records can provide a wealth of information to inform your ERM efforts, as can frontline employees who can provide insights into what is going on behind the numbers.

Once the risks are mapped, there are four ways to manage them, he explains: transfer, accept, mitigate and avoid. It’s hard to do any of them cleanly, but it’s important to understand which approach or approaches are best for a given risk.

All four approaches, he adds, need to be accompanied by a culture which is aware of the risks, understands the risk appetite of the organization and their department, and acts accordingly.

Listen in to learn more about ERM and how compliance can play an effective role in identifying and managing risk.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

As if ransomware and phishing attacks weren’t enough to keep us up at night, now AI is enabling a whole new range of cyber threats.

Ryan Redman, Product Manager, Marketing and Brett Sommers, Director of GRC Products at Onspring warn that the nature of attacks is evolving. Vishing, in which criminals use technology to imitate the voices of colleagues and organization leaders, is being used to trick people into revealing passwords, share data or send money. Employees need to learn to be wary and even confirm requests, even from trusted voices, via email or other means.

Healthcare and manufacturing are two industries that have been singled out by bad actors for this kind of attack.

Aside from training, what else can compliance teams do? They recommend:

  • Focusing your resources on high value risk areas
  • Ensuring your cyber defenses are as strong as they need to be
  • Reviewing your third parties to ensure that a compromise won’t come from someone hacking into their systems
  • Understanding how AI is being used by your organization and vendors to make sure that the security is adequate
  • Being transparent about your expectations

Listen in to learn more. I swear it’s really us and not AI.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

These are fractious times, and it’s often difficult to figure out what to do, what comes next and keep people with divergent views working together.

Despite these challenges, Anna Romberg, Executive Vice President, Sustainability, Legal and Compliance for Getinge, doesn’t believe that things are hopeless. In an article she co-authored with Richard Bistrong for Harvard Business Review, they laid out several strategies for successfully navigating the current era.

In this podcast, she reminds us that ethics and compliance programs are about more than following the law. They are also about encouraging good behavior, which includes following the company’s values, no matter how the political winds are blowing.

With that said, now is a good time to do what organizations need to do, which is assess their values periodically to ensure that they are relevant, and the organization is living up to them.

At the same time, she encourages the compliance team to embrace friction. It is inevitable when facing difficult discussions and different opinions. It’s also a sign of change and that the matter at hand needed to be dealt with.

She also cautions compliance teams to be alert and encourage speaking up. With increased pressure and changing norms, some may lose sight of the need to do the right thing.

Listen in for a bit of stability during unstable times.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Do you ever wish you were made of rubber, especially nowadays with so much change? Do you wish that you could be flexible enough to handle every new legal regulatory change or every business demand without breaking?

It’s not likely to happen, but compliance industry veteran Lisa Beth Lentini Walker believes that we can become more resilient. Resilience, she observes, is a mindset. We can work to become more adaptable and open to change by framing it in the right way. If you look at it with dread, you are less likely to succeed. But, if you recognize that nothing is permanent, change is inevitable and focus on what needs to be done, the chances of success are much greater.

Look at change as an opportunity to shine and show leadership. Become the person who management trusts to look to the future and find the path forward for the organization. The workforce, too, wants to know that they can count on you to keep them safe and the company operating strongly.

Listen in to learn more about becoming resilient and an effective compliance leader during changing times.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Uzbekistan, Kazakhstan, Tajikistan, Turkmenistan and Kyrgyzstan were all born out of the dissolution of the Soviet Union. With large energy deposits of national gas, many global companies and their suppliers are operating within these countries.

To better understand the compliance risks there, we spoke with Timur Khasanov-Batirov, a compliance officer with deep and wide roots in the region.

While we may think of this area as one region, he warns that there are substantial differences by country. Kazakhstan is the most developed, and compliance has gained significant traction in large companies, primarily in the oil and gas sector. Uzbekistan saw three major FCPA cases, and, as a result, compliance has garnered a great deal of attention. The other three countries have much smaller economies and less developed compliance cultures. In addition, Turkmenistan has a fairly-closed economy, which complicates the picture.

While it is easy to focus on the anticorruption risk in the region, there are other challenges. The area has become a significant transshipment point to Russia of prohibited and dual-use goods. In addition, child and forced labor is an issue, especially in the textile industry.

To mitigate these risks, especially for sanctions evasion and corruption, companies operating in the region will need to pay close attention to the ownership of companies. That is not always easy to do because corporate structures are often opaque. The desktop-based due diligence systems in the US and Europe are likely not sufficient, Timur advises. Having someone on the ground in the region is likely needed.

Listen in to learn more about what it takes to operate a compliance program in this important part of the world.

Listen now

View Details

By Adam Turteltaub

It’s not a good time to be a manufacturer of ten-foot poles. That’s because with the growing number of sanctions regimes, there are an increasing number of companies and individuals that businesses shouldn’t touch with a poll of ten feet, or any length for that matter.

Rachel Gerstein, who most recently served as Vice President, Global Ethics and Compliance Counsel for Gartner, explains in this podcast that trade sanctions are laws and regulations designed to prevent and punish engaging with countries, organization and individuals who the government has deemed a threat to national and international security, or has committed human rights violations.

Many countries have sanctions regimes, although the United States tends to have the strongest. The US, for example, has countrywide sanctions against Iran, Cuba, Syria and North Korea, as well as numerous sanctions against Russian individuals and entities.

The government’s enforcement arm is the Department of the Treasury’s Office of Foreign Assets Control (OFAC), which has developed comprehensive guidance for compliance programs. It includes five pillars that will sound very familiar to anyone in compliance:

  1. Management commitment
  2. Risk assessment
  3. Internal controls
  4. Testing and monitoring
  5. Training

In addition to the obvious similarities in compliance program design, there is also great practical overlap. Third party vetting for anticorruption risk, for example, can also include sanctions-related checks. When determining if the company’s owners are politically exposed, it’s an ideal time to determine if there is 50% ownership by a sanctioned individual or entity.

Training is another common element and particularly important. Individuals involved in payments and account receivable need to be educated in sanctions risks and what to watch out for. Employees across the workforce also need to be sensitized to the issue. Europeans, for example, may see Cuba as just another exotic Caribbean vacation destination and not realize the risk.

Of course, there are also different tools also used for sanctions compliance. Your bank, for one, may be an asset given that it may be keeping its own list of sanctioned entities.

Geoblockling is a tool that can be used to determine what country someone is communicating to you from and can be used by you to block interactions.

In short, there is a great deal of risk, but there are great similarities with other compliance efforts, enabling you to combine sanctions compliance with other compliance efforts.

But, you’re still not likely to need that ten-foot pole.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

The current fee-for-services model in healthcare has challenges, to say the least. Value-based care, explains, Colleen Gianatasio, Vice President of Compliance, CoventBridge, takes a different approach by asking four questions:

  1. What are the needs for both patients and providers?
  2. What are the challenges and barriers to meeting them?
  3. What technology and other resources are available?
  4. How will providers be measured for success, and when will they be reimbursed?

In answering these questions there is an underlying emphasis on a much more collaborative and transparent approach among patients, providers and payers. There is also a commitment to understanding the community as a whole.

For those looking for advice on how to pursue value-based care, she offers several thoughts, including:

  • Be thoughtful in your use of technology solutions
  • Give all your stakeholders a seat and voice at the table
  • Break down the silos, and communicate openly and frequently

Listen in to more about the practice and promise of value-based care.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Recently Protiviti released an intriguing report: Top Compliance Priorities for U.S. Healthcare Organizations in 2025. In this podcast their Global Healthcare Compliance Leader, Leyla Erkan, shares some of the key priorities they revealed:

  • Managing technology. This includes wearable devices, AI, telehealth platforms and more. All have great promise, but each comes with significant risk.
  • Privacy and security. Many organizations are struggling with right of access issues, reproductive health data, and using data more effectively to deliver care. Not to mention the issues of data breaches and ransomware.
  • Integrating quality and safety into compliance programs. As with value-based care, expectations have grown for compliance to play a key role in ensuring quality and safety.
  • Billing and coding. Cloning of documentation remains a key risk area along with lack of documentation. New technologies hold great promise but there are challenges in areas such as using AI.

Listen in to learn more about these issues and other identified as top compliance priorities for healthcare in 2025.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

How much is your cybersecurity program worth? Traditionally the thinking has kind of been: if we don’t have a breach it’s expensive but valuable, and if we do have one it’s both expensive and worthless.

Eric Shoemaker of Genius GRC advocates for a different way to value cybersecurity efforts. Instead of just looking at what it prevents, also look at what it enables: your organization to do business with less friction. A good cybersecurity program give customers the confidence that you are safe to do business with. It prevents business interruptions, and doesn’t get too much in the way of the business.

So track things like deals successfully closed after reviewing the company’s cyber defenses.

He also argues for using near misses as a way to demonstrate value. Each incident provides an opportunity to examine what could have gone wrong, what controls worked, and what enhancements could be made to strengthen them.

Listen in to learn more about how you can establish the value of your cyber protection efforts.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

Virginia MacSuibhne is not your typical compliance officer. It’s not surprising then that this former global chief compliance at Agilent and Roche, who also has an Etsy shop selling irreverent, NSFW compliance merch, decided she wanted to do an atypical podcast.

Rather than focusing on a brilliant idea she had or a huge success, she suggested we discuss the mistakes she has made. Each of them has an important lesson for others in compliance.

Mistake #1: Do the code of conduct yourself.
It’s far better to involve the business team both to gain their insights and get their buy in.

Mistake #2: Think working inside a company is like working for their law firm.
When you work in a company, even in the legal department, you need to focus on relationships and be less transactional. There’s no clock or timesheet to record billable hours. So spend the time getting to know your colleagues and building personal connections with them.

Mistake #3: Disregard the rhythm of the business.
Every business has its own rhythm, with busy and quiet times and its own processes for getting thing done. Take the time to learn them.

Mistake #4: React immediately and strongly to evaluations.
Sometimes it’s better to take a breath and understand the context as well as what drives you.

Unofficial mistake #5: Not listening to this podcast.

Listen now

Sponsored by Case IQ, a global provider of whistleblowing, case management, and compliance solutions.

View Details

By Adam Turteltaub

A good, juicy case study is great for compliance training. An artfully created scenario can also be remarkably effective, especially for ethics training.

What makes them so appealing, and how do you use them best? Colin May, Adjunct Professor at Stevenson University, explains that problem-based learning is very effective for adults both for knowledge transfer and retention. It also helps people apply what they have learned.

Case studies, which are based on actual incidents, and scenarios, which are fictional, also benefit from a human love of stories.

When determining whether to use a case study, scenario or some other learning method, he advises first thinking about the outcome: what do you want people to take away from the training. Next, think about the debriefing after employees have had a chance to either read the case study or act out a scenario. That subsequent conversation may prove to be the most valuable part of the learning exercise.

Be sure, too, to keep your case studies and scenarios current. They do have an expiration date. Even big, juicy ones can seem dated after a few years. Even something as big as Enron can get old: it happened 24 years ago, before a significant portion of your workforce was born.

Finally, be sure to listen to the podcast and reach out to him through LinkedIn if you would like the tool that he referred to.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

There’s a lot of discussion about the relationship between compliance and the general counsel. Less words, though, have been dedicated to the important relationship between compliance and HR.

Netherlands-based Asaf Shalev, Global Ethics, Risk & Compliance Lead for DLL rightly observes that maximizing synergy between the work of HR and compliance is a key for success of both the compliance program and the business. The departments share overlapping interests in a number of areas, including the code of conduct. He advocates both sides working closely together to ensure that it is human centric.

When it comes to compensation, HR can help by building in compliance-related metrics.

When it comes to discipline, HR can ensure that it is documented, consistent and fair. They can also be helpful for navigating local the labor laws that may apply.

Listen in to learn more about how to make the compliance-HR relationship work from recruiting and onboarding through the entire employee lifecycle.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

Stress can be a good thing. Burnout, though, is something altogether different and very real for compliance professionals.

Sarah Hadden (LinkedIn), CEO and Publisher of Corporate Compliance Insights shares in this podcast the not always encouraging data on stress and burnout from their 2025 Compliance Officer Working Conditions, Stress & Mental Health survey.

The research did reveal some very good news. Compliance officers are generally happy with their work. They have a sense of purpose and feel that what they are doing is important. The findings also revealed a small but notable increase in the belief that the organization is supportive of compliance efforts.

On the other side of the coin, though, only 7% said that job stress was not an issue. More concerning, 51% reported that they are experiencing burnout.

What causes that burnout? A variety of factors are in play including the fast pace of regulations, personal liability fears, lack of time and resources and even AI.

One of the greatest causes of stress, the survey revealed, is reporting structure, with those reporting to legal, rather than to leadership or the board, being the least satisfied and most stressed out.

Listen in to learn more, unless, of course, it’s going to stress you out.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

There is a tendency to think of risk assessment as one thing and demonstrating the value of the compliance program as another. In this podcast, Catherine Bruno, Assistant Director Office of Integrity and Compliance (OIC) at the FBI shows that the risk assessment process can also be a great way to demonstrate the value of a strong compliance program.

So how do they make that happen? First, the OIC ensures that individuals who are closer to the risk, the subject matter experts at each of the divisions at FBI headquarters, as well as each field office, are involved both from the start and on an ongoing basis. Every six months the OIC requires them to spend time assessing compliance risk and put forward at least one. This process ensures participation without demanding too much of the field’s time.

In advance of that meeting, the OIC conducts a training session, provides a model agenda, and may do a presentation on a particular risk area. They also require that, at the meeting, the participants also spend time examining the tier 1 risks that the OIC has identified.

In the future, she is looking to better spell out the cost of non-compliance and the savings of proactive measures. But, she cautions, quantifying the benefits does not have to be based on dollars exclusively. Reputational factors can and should also be considered.

Each field office is also required to provide data on the risk areas that they are tracking. That data gets compiled and gives them an opportunity to compare themselves to each other. The information is also shared at higher-level branch meetings a month later, and it helps executive assistant directors understand where field offices are focused in terms of their risks.

In sum, the process provides both a better understanding of risk and demonstrates the value of the compliance program.

Listen in.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

The words “works council” inspires fear and dread in the hearts and minds of many who have never worked with them. They need not, says Lisanne Winde, attorney at law at Wybenga advocaten and Alain Lambert, regional ethics and compliance officer for Central Europe at WSP.

In this podcast, they share how the works council can actually help compliance teams.

These entities are not unions but are specific to the company. They can be helpful for facilitating communication with employees and giving greater legitimacy to company policies. In practice they collaborate with management and can be more helpful than those unfamiliar with them may think.

However, there are times when working with the works council is not just a nice to have but a requirement. Issues relating to whistleblowing and disciplinary policies are two examples. And there may be others, as well. The laws vary by country.

To make the most out of the relationship they recommend taking time to listen to what the works council says. Make sure they understand your role and the independence it has from management, and invite their participation early. It’s better to find out what issues are and benefit from their expertise early rather than too late.

Listen in to learn more, then, take a deep breadth and relax next time you hear the words “works council.”

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

An audit by a Unified Program Integrity Contractor auditor, better known as a UPIC audit, can be a very scary thing. Providers are often shocked and even indignant to receive a letter notifying them of the audit and alleging fraud.

Jon Rawlson (LinkedIn), President & Founder of Armory Hill Advocates, reminds us that the audit was likely not triggered by an allegation but by an algorithm catching outlier events such as a provider processing claims outside of their normal daily work, utilizing a DME, a skin substitute or some other expensive item that is outside the norm.

Once you have calmed down after reviewing the letter, he advises acting immediately but calmly. Begin reviewing the documents you have been providing the Medicare program and bring in whatever help you need. And, don’t forget you have a five step appeal process that enables you to prove your innocence.

But, be mindful of the timeline the government gives. The consequences can be grave if you miss a deadline.

Listen in to learn more, and if you’re a member of SCCE or HCCA, be sure to read his article on the subject in Compliance Today magazine.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

As the sun set, the chief compliance officer stared out the window, wondering how she would communicate with her workforce in a way that they would understand. As much as she looked, the answer wasn’t outside in the skies turning from blue to black. She wasn’t finding it under the white LEDs in the ceiling above her desk, either.

Feeling a bit desperate, and a little bit bored, she decided to walk the halls to see if perhaps the answers were there. She got all of ten feet before a colleague stopped her, eyes open wide and voice a little breathless, to tell her about an incident discovered and resolved. As she listened to him speak, she realized the answer was right there in front of her in the power of storytelling.

Janine Fadul, Compliance and Privacy officer at GW Medicine, learned long ago to focus on the story she was trying to tell people, not just the facts. By following the elements of storytelling, she explains, you can grab people’s interest, keep it, and help them understand what you are trying to communicate.

That doesn’t just apply to training. It can also be useful for communicating with leadership.

Listen in to learn more about the elements of good storytelling. Then, apply them, and your compliance program may live happily ever after.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

In addition to releasing its General Compliance Program Guidance, the OIG at HHS announced plans to publish a series of Industry Segment-Specific Compliance Program Guidances (ICPG). The first of these, addressing nursing facilities, was released in November 2024.

As CJ Wolf, Professor in healthcare Administration at BYU Idaho explains in this podcast, the first ICPG is instructive both for skilled nursing facilities (SNFs) and those looking to anticipate what will be coming in future ICPGs. Currently, three more are expected to be published in 2025: Medicare Advantage, hospital and clinical laboratories. Two additional ICPGs – pharmaceutical manufacturers and hospice – are also planned, but with a publication date as yet to be determined.

There are several notable elements to the SNF ICPG. First, it interlinks compliance, quality of care and quality of life for patients. Second, there is an entire supplement focused on reimbursement, raising the scrutiny level of billing compliance. It addresses the prospective payment system, value-based payment models, Medicare Part D, Medicare Advantage, and Medicaid managed care, amongst other issues.

When it comes to Anti-Kickback, the ICPG provides specific examples that are close to home for skilled nursing facilities. These hot points include free or below fair market value goods and services, discounts, arrangements for services and supplies, pharmacist relationships, care coordination, value-based care arrangements and join ventures.

It is expected that future ICPGs will also have a focus on the Anti-Kickback statute. CJ also anticipates future guidances to continue to focus on greater accuracy and quality of care.

Listen in, whether you are working at a SNF or looking to learn what likely comes next with ICPGs.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

Sevda Huseynova is the Ethics and Compliance Officer for SOCAR Midstream, a state-owned enterprise (SOE) in Azerbaijan. The company manages the oil and gas export pipelines of the country.

If you think working for an SOE means you don’t have to worry about compliance, she warns you to think again. SOEs still faces risk in a wide range of areas including anticorruption, sanctions, third parties and more.

Investors want to ensure that the company operates up to global standards, which isn’t always easy since compliance is relatively new in Azerbaijan.

SOCAR midstream is up to the task, though, she reports. The company seeks to comply with local laws as well as international standards such as those of the OECD and the UN Convention on Corruption.

To meet its goals, the compliance program is based on the seven elements approach found in most compliance programs and has three tiers addressing prevention, detection and corrective actions.

She advises others working in SOEs to embrace five key strategies:

  1. Gain leadership buy-in and the corresponding tone at the top
  2. Customize the program to the SOE context
  3. Build a strong compliance infrastructure with adequate support
  4. Strengthen third party management
  5. Monitor, measure and improve on a continuous basis

Listen in to learn more about the challenges and opportunities of compliance programs in an SOE.

Listen now

Sponsored by Ethena – automated compliance training, an employee hotline, and case management, all in one tool.

View Details

By Adam Turteltaub

KISS takes on a new meaning in this podcast: Keep it Streamlined & Strategic.

Keeping it streamlined and strategic is also the topic of a session at the 2025 HCCA Compliance Institute that will be led by Krista Muszak, Senior Manager, Process Optimization at Pfizer and Angela Smart, Senior Compliance and Ethics Partner, Intermountain Healthcare. Specifically. they’ll be applying this new take on KISS to the topic of program effectiveness.

So how does it work? How do we keep our programs streamlined and strategic? First, we avoid scope creep and remain focused. That, they explain, begins with having and continuously referring back to a program charter that keeps you and everyone else involved from pursuing all the tangential issues that could derail your efforts.

Second, they advise following the PDCA formula: Plan, Do, Check and Act.

Third is conducting a root cause analysis that helps you understand not what happened but why. It will keep you thinking strategically and not just about the particular incident that called for the analysis to be done.

Want to learn more about KISS? Listen to this podcast and then join them in Las Vegas for the 2025 HCCA Compliance Institute.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

Business people are given all kinds of goals for revenues, profitability, efficiency and more. For compliance, though, not so often. Many organizations struggle with how to set compliance goals, or even if they should set them.

Madrid-based, Juan Ignacio Paillás, Head of Global Compliance Business Sectors for Merck KGaA, Darmstadt, Germany, explains how it should be done. First, he advises, understand the context in which you are working, particularly about how your organizations manages objectives. For example, some organizations embrace very rigid goals, while others take a more flexible approach.

When approaching management and the business unit about setting objectives, he cautions that you should expect pushback. To counter it, remind them this is about taking the company’s values and turning them into concrete, measurable behaviors. It is also an exercise in setting priorities within compliance efforts to have the greatest impact on the organization and its performance.

As you go to set the goals, determine which levels of the organization you will cover and what is important for each of them. Start with leadership and then enlist them in the efforts

Also, he advises being open to business people setting their own goals. Listen in to the interesting goal one person set, and what impact it had.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

Healthcare is often rife with fraud, and organizations struggle to prevent it. To gain a different perspective on how to prevent wrongdoing, we spoke with Alec Burlakoff, a convicted fraudster from Insys Pharmaceuticals who now leads Limitless! Consulting.

To prevent fraud, he recommends seriously looking at the incentives program in your organization, especially if there are individuals whose commissions may make up more than half of their compensation. Such high rates of reward, he warns, provide serious temptation to skirt, or outright disregard, the rules.

Look also at the messages that lucrative incentive programs send to others in the organization. Individuals who are inclined to do the right thing may find themselves envying those they see breaking the rules and getting rewarded. It can cause them to emulate the bad behavior that they see.

Better, he advises, is to seek ways to reward people who do things the right way and build sales for the long term.

When it comes to discipline, he takes a very hard line. Many companies, he finds, have zero tolerance policies, but they may not apply them. That, he believes, has to stop. The only way to get the attention of the workforce is to swiftly punish, including terminating, employees who break the rules.

Finally, he advises compliance teams to understand the thinking of businesspeople. Know what motivates them, understand their thinking, and get inside their heads. Only then will you be able to effectively reach them.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

Are your helpline calls being responded to properly? Are the investigations proceeding expeditiously and properly? To find out, it’s good to do an audit periodically.

Before you can begin, though, you need to determine if there is enough available data for an audit, cautions Juliette Gust, President of Ethics Suite, and author of the chapter “Auditing the Confidential Reporting Hotline and Case Management Program Effectives” in the new edition of The Complete Compliance and Ethics Manual. Many compliance programs still do not have formal processes in place, and for them, it’s best to start with a gap analysis.

If you do have data, look at how you are tracking both the allegations and the work being doing as a result. How quickly are allegations being reviewed? Is someone letting the reporter know that their allegation has been received and is being acted on? How are you safeguarding the data, including being sensitive to the potential need for attorney-client privilege?

Spend time, too, on auditing what is being done to encourage whistleblowing. What is the tone at the top? Are managers doing their compliance training and how quickly? How often does the compliance and ethics committee meet? Does it have a charter? Do the meetings have an agenda, and are they being followed?

Another area for potential audit is the investigator. Are your investigators properly trained? Is there enough staff to do the investigation? Is the investigation appropriately scoped?

Curious to learn more about how to audit your helpline and responses to allegations? Listen in now and check out The Complete Compliance and Ethics Manual.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

Think you don’t have to worry about the SEC because you’re at a private company or a non-profit? Think again says, Kevin Muhlendorf, attorney at Wiley Rein. You may still end up in the Commission’s crosshairs.

He warns that the SEC’s power of investigations expands far and wide, and just being a supplier to a publicly-traded company may lead them to focus on your business. If a private company is acquired by a public one or makes even a non-public offering, there is risk of fraud and SEC action.

Lie to an accounting firm and the SEC may become involved.

And don’t forget about the risk of parallel investigations involving multiple enforcement authorities.

Another risk area is shadow trading. Let’s say your hospital is a part of a clinical trial, and an employee sees it is going well. If that employee decides to short the stock of the drug’s competitor, that could be an issue that falls under the SEC.

So what should you do? Keep an eye out for these risks and pay attention to recent enforcement activity and dispositions. Oh, and listen to this podcast.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

Business transformations can be times both of risk and opportunity for compliance programs. Employees, struggling to understand the changes around them and feeling stressed, may opt to do the wrong or at least ill-advised things. By the same token, transformations provide an opportunity for compliance teams to change their roles within the organization and redefine the value that they bring.

Jill Swain, Global Ethics Manager and Dawn Wood, Engagement, Training and Programme Manager at Rolls-Royce went through a major business transformation and will be sharing their insights from that experience in a session at the 2025 SCCE European Compliance & Ethics Institute.

In this podcast they share an abbreviated version of the journey and lessons taken from it.

Rolls-Royce, as it transformed itself, wanted employees to understand that ethics and compliance are a part of “winning right” and helping the companies achieve its goals. The compliance teams met the challenge by embarking on several initiatives, both broad and narrow. They:

  • Conducted a Win Right Week
  • Identified the need for ensuring that conflicts of interest were reviewed when reporting lines changed
  • Helped employees understand common dilemmas and how to resolve them
  • Became an integral part of the employee hub to make it easier to access information and ask questions
  • Rolled out a new third party risk management platform

In sum, it was a transformation both of the organization and the compliance program within it.

Listen in to learn more about what they did and learned through a period of corporate transformation. Then, join them at the 2025 SCCE European Compliance & Ethics Institute.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

Oh, Artificial Intelligence. So much promise, and so much risk. What’s a compliance and ethics professional to do? Start by listening to this podcast about the chapter “Managing the Ethics and Compliance Risks of Artificial Intelligence” in the 2025 edition of The Complete Compliance & Ethics Manual.

We spoke with the article’s co-authors, Gwen Hassan (chief compliance officer at Unisys), Dr. Anthony J. Rhem (CEO and principal consultant at A.J. Rhem & Associates), and Patrick Henz (special advisor for compliance, Latin America, for Mitsubishi Heavy Industries Americas).

They explain that when we speak of AI we aren’t talking about one technology but a wide range of them. Generative Ai may be getting the most attention but there is also natural language processing, neural networks, expert systems, machine learning and many more. As a result, compliance teams need to understand what form of AI is being used at their organization.

When it comes to legal and regulatory frameworks to serve as guidance, it is probably best to look to Europe, which has taken a much more active approach than the US. The United States has just a patchwork of state laws. On the federal level, an executive order from the previous administration has been rescinded by the current one, leaving no national guidance.

Despite the legal vacuum, there ae still risks such as bias to manage. As a result organizations need to have clear guidance on what AI can and cannot be used for. There should also be a risk assessment framework that includes:

  • Assessing the data risk
  • Understanding the model
  • Assessing cybersecurity and compliance risk
  • Evaluating ethical risk
  • Continuous monitoring and updating

Listen in to learn more about how to manage the possibilities and risks of AI. Then be sure to check out the 2025 edition of The Complete Compliance & Ethics Manual.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

Sometimes you make a few technical changes to a compliance program because a law or regulation has changed. Autoliv didn’t want to do that and just meet technical requirement of the EU Whistleblower Directive. They wanted to use it as an opportunity to assess what they were doing to encourage employee reporting, whether it was working, and to improve support for people speaking up.

Erica Wikman, Vice President, Corporate Compliance, Autoliv and David Barr (LinkedIn), co-founder of Campbell Barr, tells us in this podcast that they shared a vision of moving away from just whistleblowing. Research showed it can have negative connotations. In addition, whistleblowing tended to be interpreted narrowly, with tremendous variations by region. They also found a fear of either retaliation or that nothing would be done.

So, the Autoliv compliance team began to think more broadly and encourage people not just to speak up when they saw a potential compliance issue but also when they saw something positive in the organization or just wanted to express gratitude.

Along with that change of scope, they decided to open the lines of communication and encourage employees to bring their concerns and praise wherever they were most comfortable.

To make it work they reached out to HR, manufacturing, quality and the health and safety team. Together these groups identified similar needs and dialogue and a willingness of leadership in those areas to come up with a common, welcoming approach to speaking up.

By making speaking up more natural and a part of the business dialogue, they were able to lower the barrier to raising issues and turn perceptions around. A potential negative had become a positive.

Listen in to learn more about what they did and how you could change the entire atmosphere around speaking up.

Listen now

Sponsored by Bluesight, providing industry-leading privacy monitoring with fast, reliable patient data violation detection.

View Details

By Adam Turteltaub

So the IT folk can’t wait for your business people to delete those old documents, meantime, the business people want to hold onto them because they never know when they might need that info again. Then, all of a sudden there’s a legal issue and a hold is in place. Instantly the game changes.

Chris Kruse, Executive Vice President & Advisor at CasePoint explains that when a legal hold is placed several things need to happen:

  1. Employees with relevant need to be identified
  2. They need to be placed on notice of the obligation to preserve any relevant information.
  3. They need to be instructed on how to proceed going forward
  4. The custodians of the data need to acknowledge that they have been notified and understand their obligations
  5. Individuals with the data need to be reminded that if they create new data it also needs to be retained

Securing all the documents and data can be difficult for several reasons. These range from the simple, such as an employee who doesn’t read the email with the instructions to preserve data, to the complex, such as identifying all the different kinds of documents and where they may be stored.

Get it wrong, and things can go south pretty quickly.

Listen in to learn more about how to ensure that your document hold doesn’t cause more problems than it solves.

Listen now

View Details

By Adam Turteltaub

You do all that work but how do you know you’re being successful? It’s not like people come running in the door and say, “Hey, guess what bad thing I almost did.”

The compliance team at the National Security Agency (NSA) had that same challenge. In this podcast, Natalie Knowles, Director of Compliance, and Zack Conyne, Manager, first provide an overview of the NSA. As they explain it has two primary missions: cybersecurity and signals intelligence. Every employee there annually takes an oath to defend the Constitution, which is, of course, a great reminder of the organization’s values.

The compliance team is there to ensure that NSA activities are consistent with the law, including policies and procedures designed to protect privacy and civil liberties.

The team measures the success of the program both using quantitative and qualitative metrics. Along the way they have learned a great deal, including the importance of telling a story, managing the complexity of data, and the importance of looking to trends.

Listen in to learn more and to benefit from the insights they have gained in measuring the success of their compliance program.

Listen now

View Details

By Adam Turteltaub

When we last spoke with Tyler Shultz back in 2020, he discussed his experience at Theranos as both an employee and a whistleblower. Four years later, the case is in the rearview mirror, the former CEO is in prison, he founded two startups of his own, and he now speaks to corporations about cultivating courageous work cultures

With the benefit of some time and distance, he shares in this podcast his experiences and what he has learned, particularly about corporate culture. The behaviors he saw at Theranos provided for him a lesson in what not to do.

There, he felt the dysfunctional culture was created intentionally. Management, he believed, wanted employees to fear them and reinforced that through locked doors, barricades and firing people who disagreed with leadership. here were even NDAs that restricted the ability of employees to speak with each other.

To create a good culture, he argues, companies need to do the opposite of what he saw at Theranos.

First, start by defining what the core values of the organization are to give employees a common language with which to discuss potential issues.

Next, create a culture that reinforces those values. That includes:

  • Ensuring that the policies match the values
  • Not having overly restrictive NDAs
  • Preventing the formation of silos
  • Encouraging collaboration
  • Watching out for high levels of turnover
  • Being transparent with regulators and investors

Listen in to learn more about how to create the right culture and avoid becoming the next Theranos.

Listen now

View Details

By Adam Turteltaub

Few things hold more promise, or cause more stress for compliance professionals, than AI. What is it? How does it work? And does anyone know how to keep it from showing so much bias?

David Silva, Chief Compliance Officer at Collaborative Imaging, will be addressing the topic of “Healthcare, Artificial Intelligence, and Compliance” at the 2025 HCCA Compliance Institute, which will takes place April 28-May 1 in Las Vegas. To get some of his insights now, we sat down for this podcast.

David explains that part of the challenge is that AI is so fast changing that it’s hard to keep up. We don’t yet know what we don’t know about it.

At the same time, though, the technology is showing great promise in healthcare in areas such as coding, simple reports and helping with third-party vetting.

Compliance teams have an important role to play in the implementation of AI in healthcare, he explains. Ideally, they should be a part of the AI governance team, working with a broad range of departments and helping to ensure that programs are monitored to avoid issues with privacy or the False Claims Act, for example.

So how should compliance professionals become a valued and effective part of AI efforts? He advocates for staying engaged and pushing to be invited to meetings. When there, keep your ear to the ground, learn more about operational workflows, and try to make sure that AI does what it is supposed to do, without crossing legal and regulatory lines.

Listen in to learn more, then join us for even more at the 2025 HCCA Compliance Institute.

Listen now

View Details

By Adam Turteltaub

Chart auditing may not be the sexiest part of healthcare compliance, but it plays an important role in discouraging Medicare fraud and catching problems early.

Madhavi Perumpalath, Director-Physician Practice Compliance at Northeast Georgia Health System and Alka Kumar, Compliance Director and Privacy Officer at Resolve Pain Solutions, explain that CMS provides good guidance to healthcare providers, such as diagnosis and procedure codes that are appropriate to bill for. Take advantage of it.

Embrace proactive auditing, they advise, to help identify issues and ensure the quality of the claim before it goes out the door. It can also prevent both over and under billing.

How frequently should you audit? It depends on several factors, including the size of your organization, regulatory requirements, resources available and the overall risk environment. And, remember, you can’t audit everything. Instead, they recommend developing an annual audit plan focusing on the high-risk areas, but also doing some random samples of other areas as well. This dual approach maximizes efficiency and minimizes overlooked issues.

Listen in to learn more about how to conduct the audits and what to look for.

Listen now

View Details

By Adam Turteltaub

With value-based care growing, what role does compliance play? To find out we spoke with Carolyn Barton, Vice President, West Regional Compliance Officer at Kaiser Permanente.

She explains that at Kaiser they define value-based care as a healthcare delivery and financing model that improves health outcome and increases access to affordable care in the community through evidence-based care, a commitment to equity and simplicity and aligned incentives. Doctors and health plans, she reports, work in an integrated system focused on the patient and delivering the right care at the right time and place.

To make that work their electronic health record (EHR) system is the foundation not just for collecting patient data but also for sharing protocols for treating patients. By implementing systematic, evidence-based approaches through these protocols, they help mitigate racial and ethnic inequities.

The results she shares are impressive. Kaiser patients are 20% less likely to die prematurely from cancer compared with others in their community, and they are 33% less likely to have a premature death from heart disease.

The compliance team plays a key role by helping, for example, physicians identify the scope of their practice risk such as ensuring that, as patients are moved to a lower level of care, there is proper staffing in place to treat them.

To ensure your compliance team succeeds in the values-based care world, she recommends being agile, supporting the organization’s efforts at risk mitigation, building trust, making yourself accessible when there are questions, and thinking creatively.

Listen in to learn more about how your compliance team can thrive in this environment, and also what mistakes to avoid.

Listen now

View Details

By Adam Turteltaub

No one would dispute that stress and compliance go hand in hand, but Scot Eibel (LinkedIn), a former chief compliance officer and currently leading Eibel Coaching and Compliance Consulting, warns that doesn’t mean it has to get out of control. There are steps we can all take to manage our stress levels.

One stressor to watch for is over vigilance. While we all need to be vigilant, assessing risk and watching out for threats, it needs to be tempered. Resist the temptation, he warns, to engage in worst case scenario thinking, which increases stress and makes it difficult to focus on any positives.

Catastrophic thinking isn’t healthy for you or for the organization.

Another stressor for compliance professionals can be feelings of isolation. In some ways it is inherent to the job, but that doesn’t mean it needs to be absolute. Look to others in the compliance community for connections and build cohesiveness on your compliance team. Stress is much more manageable when you have support.

When it comes to those problems that seem too difficult to solve, take a breath, he recommends, and focus on what you can do. Don’t seek perfection but seek progress and remember that excellence doesn’t happen overnight.

Finally, don’t be afraid to set limits. Compliance professionals can be, as he put it, “sacrificial people” who are willing to put others and the organization first. It’s noble, but sometimes you need to to say “no” or “no” and offer some advice.

Listen in to learn more about how better to manage your stress.

Listen now

View Details

By Adam Turteltaub

Benjamin Christenson, Trial Attorney and Special Assistant to the Director for Criminal Enforcement at the US Department of Justice Antitrust Division, joins us for this podcast in which he sheds light on the their document, Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations (ECCP). First issued in 2019, the ECCP was updated in 2024 to reflect changes in business, the law and technology, as well as what the Antitrust Division had learned over the last five years.

He shares that there are three significant areas of focus in the ECCP worth particular study:

  • AI and Emerging Technology. As companies deploy AI, it’s essential that compliance teams have visibility into what is being done, understand it and monitor antitrust issues such as using the technology to fix prices.
  • NDAs and Whistleblowers. Like others in enforcement, the DOJ is concerned when a non-disclosure agreement may have a chilling effect on potential whistleblowers who are considering reporting an issue to the US government. In addition, whistleblowers need to know that they are protected by Federal law.
  • Third party communication platforms. As employees increasingly move out of email and use texts or tools such as WhatsApp, organizations need to train their workers of the need to preserve the documents

Overall the ECCP is very similar to the Criminal Division’s document on evaluating compliance programs, but the latest Antitrust Division ECCP is worth spending time with on its own right, especially if you have risk in this area.

Listen in to learn more.

Listen now

View Details

By Adam Turteltaub

Want to improve your code of conduct? Don’t miss the session: Cornering the Code: A Multi-Disciplinary Approach Toward a Better Code of Ethics at the 2025 SCCE European Compliance & Ethics Institute.

In this podcast Matej Drascek, Head of Internal Audit at LON d.d. and Ursula Schmidt of Schmidt Advisory recommend starting with the right language. Research has shown, they explain, that people react more strongly to words like “we” and “our”, which can convey a stronger sense of shared responsibility than words like “you”, “I” or “it”. Also, words like “must” or “have to” carry more weight than “may” or “should”.

Of course, just using “we” and “must” won’t do it all. The code, they tell us, should have a service character that gives guidance to people and gives employees a sense of purpose. It should also be dynamic and work as a bit of a safety valve. It should provide reassurance that it protects them from making mistakes and helps them feel safer when addressing issues.

For the code of conduct to be valuable in a crisis, it must have first been written clearly and avoid ambiguity. It should fit the organization’s culture, be practical, and able to be applied in a reasonable manner.

Listen in to learn more. Then don’t miss their session at the 2025 SCCE European Compliance & Ethics Institute.

Listen now

View Details

By Adam Turteltaub

I want to write enough about this podcast to get you to listen to it, but not too much because then you might decide that reading this was enough.

I’m conflicted, and conflicts of interest are the topic of this podcast with Kasturi Venkatesh, who spoke on the topic “Ethics in Action: A Fun Guide to Tackling Personal Conflicts of Interest” at the 2024 SCCE Compliance & Ethics Institute.

When it comes to managing the issue, she explains, the primary goal for compliance teams is to help the workforce identify and bring forward potential conflicts. The challenge is that they often hesitate to bring these issues to management or the compliance team out of fear and a lack of understanding. Training is helpful, but it can’t demonstrate all the potential issues, nor can it always overcome the anxiety. That takes a personal touch of reassurance.

In this podcast, Kasturi makes the case for a gentle hand a nuanced eye. The compliance team needs to be aware of the sensitivities of workers and also that, in some geographies, for example, with limited talent pools, there are likely to be many potential conflicts of interest.

The nuanced eye needs to understand that challenge as well as see subtle issues, such as two connected workers who are “safely” in different departments, but there may still be some interaction between the two that could prove problematic.

Listen in to learn more.

Listen now

View Details

By Adam Turteltaub

On November 6, 2024, the U.K.’s Home Office issued Economic Crime and Corporate Transparency Act 2023: Guidance to organisations on the offence of failure to prevent fraud (the Guidance). It comes out of the Economic Crime and Corporate Transparency Act (ECCTA), which establishes that a corporation can be held criminally liable for failing to prevent fraud committed by any “associated person” for the benefit of the company. This “associated person” can be an employee or even a third party.

There is a defense, explains James Tillen, member at Miller & Chevalier, for organizations that had reasonable prevention procedures at the time of the offence. What constitutes reasonable? There are six principles:

  • Top level commitment
  • A risk assessment
  • Proportionate risk-based prevention procedures
  • Due diligence
  • Communication and training
  • Monitoring and review

Sound familiar? It is, since it builds off the guidance for the UK Bribery Act and is very similar to the US approach.

It’s not identical, though, since, unlike the US criteria for evaluating compliance programs, this guidance is fraud-specific, with details designed to address the risks posed by the fraud triangle of motive, opportunity and rationalization.

Listen in to learn more about the guidance and the particular attention it pays to monitoring the mental well-being of employees.

Listen now

View Details

By Adam Turteltaub

Auditing and monitoring of the compliance program is pretty standard these days. Entain’s Karen Nightingale, Group Director of Ethics & Compliance and Jonathan Fox, Group Head of Ethics & Compliance Programmes, make the case in this podcast for going to the next level and actively testing your program. The two will also be addressing the topic at the 2025 SCCE European Compliance & Ethics Institute, which will take place in Lisbon, 10-12 March.

Doing so, they suggest, can turn a reactive compliance program into a proactive one by actively searching for points of weakness, identifying red flags in advance and addressing them early.

In practice, testing is more like an audit. It should be done periodically and provide an in-depth look at whether processes and controls are working as intended. By going deeper, it can uncover where there may be a weakness in what may appear to be a strong process as a whole.

To determine what controls to test, there are several factors. First is recognizing that your organization likely has limited resources: don’t plan a test that you don’t have the resources to carry out. Second, identify the taxonomy of risks and which fall within the compliance team’s remit. Next, prioritize the risks: identify the highest risks and start there.

As you do this work, ask for help from other parts of the organization. HR, legal, internal audit and others may all be great help.

Listen in to learn more, and then plan on attending their session at the 2025 SCCE European Compliance & Ethics Institute.

Listen now

View Details

By Adam Turteltaub

Note: This podcast was recorded on December 17, 2024. Any changes made after this date will be addressed at the Compliance Institute.

At the 2025 HCCA Compliance Institute in Las Vegas, Adam Greene (LinkedIn), partner at Davis Wright Tremaine LLP will be leading the session “New Developments in Health information Privacy.” In this podcast he provides an overview of what he sees as notable privacy compliance challenges and what compliance teams need to be doing.

Starting with the HIPAA Privacy Rule, reproductive information is the top of the list. There was a December 23, 2024 deadline for covered entities and business associates to have implemented a prohibition of using any personal health information (PHI) for the purposes of imposing liability or investigating reproductive health care that is lawful under state or federal law.

That information, per the rule, should not even be provided to law enforcement or courts that seek to punish an individual for providing or facilitating that care. Relatedly, there is an attestation requirement in instances of judicial or law enforcement information requests that the requester is not seeking the PHI for this prohibited purpose.

That is causing a great deal of confusion and challenge for compliance officers.

Adding to the confusion is the possibility that the new Administration may reverse the policy.

For now, though, he shares, it’s prudent to follow the rule until such time that changes are made by the government.

Listen in to learn more about the complexities of this issue, the Confidentiality of Substance use Disorder Patient Record Rule, his insights on website disclosures of user information, and more.

Then plan to join his session at the 2025 HCCA Compliance Institute in Las Vegas, taking place April 28-May 1.

Listen now

View Details

By Adam Turteltaub

Well, it turns out that you can be in two places at once, if you are a surgeon. Even better, you can bill the government under the Medicare program for being at both of them.

It’s not quite as strange as it sounds, explains Sara Brinkmann, Partner, and Lauren Gennett, Counsel, of King & Spalding, and, of course, there are rules.

Overlapping surgeries occur when one attending surgeon is responsible for procedures that overlap in time. The attending may perform the critical part of the procedure in both, assuming they are not supposed to happen at the exact same time. Non-critical portions of the procedure, such as closing the patient, are left to a resident. There must also be a backup surgeon in case something goes awry.

Payment for both surgeries is possible so long as there are the requisite safeguards in place and the various other CMS rules are followed. There may also be state requirements to be mindful of as well.

If those rules aren’t followed, there is substantial risk. As they explain, overlapping surgeries have been the subject of intense scrutiny and enforcement actions.

Listen in to learn more, and, for the record, overlapping podcast listening is not approved.

Listen now

View Details

By Adam Turteltaub

On November 22, 2024, Principal Deputy Assistant Attorney General Nicole Argentieri recapped the changes made during the Biden Administration in enforcement policies and announced a few new ones. To better understand what this all means, we spoke with Daniel Kahn (LinkedIn) , partner at Davis Polk, and himself a veteran of the DOJ.

There were a number of meaningful changes during the last few years, he noted. Most notably the voluntary disclosure program was significantly expanded, with companies with aggravating circumstances now able to still have the possibility of a declination. There is a catch, though, the bar for cooperation has been raised. The organization must have disclosed promptly, engaged in extraordinary cooperation and remediation and have had an effective compliance program at the time of the incident.

A new change, just announced, is the addition of what we referred to in the podcast as “clawforwards” in addition to clawbacks. Organizations are expected to not pay bonuses to employees involved in suspected wrongdoing.

Perhaps the greatest change just announced is a difference in how the DOJ handles self-disclosures. In the past companies that did not have a perfect self-disclosure might find themselves a bit stranded. Now the DOJ is recognizing good faith efforts even when the voluntary disclosure may not have been as timely as it could have been.

Listen in to learn more and to hear what he says companies should do with an upcoming change in administration.

Listen now

View Details

By Adam Turteltaub

Once again it is time to sit down with Matt Kelly (LinkedIn), Editor and CEO at Radical Compliance and discuss what happened last year and where the compliance profession is going in the new one.

In this podcast we looked back at 2024 and explored five key topics.

Changes from the DOJ
The DOJ recently issued a recap of its key activities over the last year or so, and Matt notes that a key change has been an increased willingness to give credit to companies that work with the Department of Justice. In the past, the DOJ had only given full credit to companies that had self-disclosed, but now there is greater leniency for organizations who have demonstrated that they are willing to cooperate with the government and make serious remediation efforts.

Lessons from Recent Dispositions
Matt pointed to the TD Bank case and noted that, as he saw it, the company laid the seeds for its scandal by having a zero expense growth strategy across its business. That led to compliance spending shrinking, rather than growing, as the business rapidly expanded. The key lesson there: recognize the compliance risks of your business strategy.

Looking at Boeing’s continued woes he notes that the court has now made quality a central part of the company’s compliance metrics. The definition of compliance and scope of compliance programs could well be growing, with the recognition that having a speak up culture and effective controls isn’t just valuable for legal and regulatory compliance.

From the RTX case he finds a lesson for companies in the importance of thorough due diligence and taking the time to understand the risks fully prior to acquisition.

Compliance Team Struggles
Compliance teams still need to earn their place fully as a trusted advisor for issues outside of the traditional compliance lane, such as AI and supply chain risk, which is often divided up among several departments.

Compliance Program Progress
The vast majority of CEOs now see compliance as much more than a check the box exercise. They also recognize that having an ethical workforce is an asset.

Matt also notes great progress in anticorruption due diligence and an opportunity to show that the same tools that help vet third parties in this risk area can be useful in many others.

Listen in to learn more about his thoughts about 2024 and to prepare for a successful 2025.

Listen now

View Details

By Adam Turteltaub

Retaliation is the bane of every compliance program, with the potential of destroying employee confidence in reporting systems, not to mention embarrassing and expensive lawsuits.

It is also complex and can be subtle, explains Keith Read, a former chief ethics and compliance officer and author of the book The Unconventional Compliance Officer: Doing Things Differently. There is overt retaliation, such as firing an employee for blowing the whistle. But there is also softer, more subtle retaliation, such as not including the whistleblower in meetings or on projects.

He advises compliance teams to be sensitive to all of the many forms of retaliation and to treat it as a risk area. That means look at where and how retaliation can occur, and then take the time to determine if is occurring. Track how the careers of whistleblowers go and see if the trajectory has changed for the worse. Also, look to patterns in management. He found that retaliation followed certain managers around the organization.

With this data in hand, you are better able to both support the whistleblower and foster a stronger culture of compliance. Listen in to learn more about how to prevent retaliation from undercutting your compliance program.

Listen now

View Details

By Adam Turteltaub

How do you know your compliance program is working, both for your peace of mind or if the government comes knocking? It’s a tough question, and many wonder either how to start measuring or if they’re measuring the right thing.

Andrew McBride, Founder & Chief Executive Officer at Integrity Bridge, has a great deal of experience in this area from his time serving as Chief Compliance Officer at Albemarle. In the wake of an FCPA scandal, the company had to be able to demonstrate the strength and effectiveness of its efforts.

In this podcast he advises you remember three key questions from the US Department of Justice’s compliance program evaluation criteria: Is the program well designed? Is it applied earnestly and in good faith? Is it working?

At the same time, though, he cautions not to just seek simple metrics alone. It’s important to also track why you are measuring what you are measuring. Compliance teams need to take the time to build out the supporting narratives that explain why and how their choices were made and have a fully written out risk assessment. These documents help guide what is measured and establish why those measurements are worth taking.

Having the narrative in place also helps the program keep its focus. Over time people change and memories fade as to why a given compliance path was taken. With strong documentation of the original thinking, the compliance team can better assess if the program is delivering what it needs to or if it needs adjustment.

When it comes to who does the analysis of the data, he highly recommends hiring a data analyst. These individuals have the capacity to turn the numbers into meaningful dashboards and graphics that everyone can understand. They can also be adept at finding data where you might not think to look.

Listen in to learn more about how to effectively measure the effectiveness of your measurement efforts.

Listen now

View Details

By Adam Turteltaub

Oh, come on, we all know it: sometimes the business people get tired of all those compliance requirements. That’s okay and to be expected. But, how do you know when it has progressed beyond the usual (and maybe healthy) resistance to full-blown exhaustion?

Cecilia Fellouse, General Manager of Compliance for Good, warns that, ironically, when the business team stops pushing back, it can be a sign of compliance fatigue. They may just be going behind your back to get what they want. Another troubling sign to watch out for is systematic escalation. Instead of addressing issues to you, they’re taking the issue straight to higher-level management.

So, what can cause compliance fatigue and these bad behaviors? She cites several factors and ways to avoid them.

  1. Saying “no” too often and being perceived as operating from an ivory tower.
    Constantly denying requests without providing constructive feedback can make the compliance team seem out of touch.
  2. Lack of engagement with frontline teams.
    Take the time to talk with them and learn their needs
  3. Limited or lack of support from top management.
    Without their support, the job is all but impossible
  4. An isolated compliance team.
    Without interaction with others, including members of the compliance community, it’s easy for the compliance team to get burned out. You need to make the effort get out there and connect.

She also strongly advocates for taking the time to truly understand the business, not just as a whole but also on a more granular basis, down to what is done day to day.

Listen in to learn more, including some signs to watch for in the compliance team that suggests that it, too, may be suffering from compliance fatigue.

Listen now

View Details

By Adam Turteltaub

Do you ever ask yourself, “What kind of compliance officer am I?” Netherlands-based Susan du Becker, Director, Risk & Compliance at Microsoft, thinks we all should. To her experience, there are two answers to that question.

One is a regulatory compliance officer: someone who is focused on the requirements of regulators, potential fines and legal consequence. The other is a business compliance officer, who is focused on what the business needs and how to ensure it achieves its goals while staying within the multitude of white lines the laws and regulations have painted.

She envisions herself as the latter, balancing business and regulatory requirements. She recognizes that the business unit will test the limits, and that she is there to make sure there are always two feet solidly on the ground.

To keep the business team focused on their legal and regulatory obligations, she advocates for making it clear what lines absolutely may not be crossed, taking the time to meet with them regularly and being prepared to have some difficult conversations if necessary.

She also believes that compliance teams are most effective when not positioning themselves as just a gate keeper.

Listen in to learn more about the approach, the role of governance and how to ensure the business understand this it owns compliance.

Listen now

View Details

By Adam Turteltaub

Rob Tull (LinkedIn), Managing Director at Effective Compliance LLC wants every compliance officer to be both competent and able to demonstrate it. He advocates for the development of four sequential, underlying skills:

  • Communication
  • The ability to be aware of risks
  • Adaptability, and
  • Decision-making/judgement

Underlying all of them is knowledge, and together they form a framework for effective compliance programs.

The single most important competency area, he argues, is communication. The ability to translate complex laws and regulations into simple language that helps the business make good decisions is paramount. So, too, is the ability to tailor your message to the audience: management and the board likely need to hear something different than line managers.

Listen in to learn more about what makes for competency for compliance professionals.

Listen now

View Details

By Adam Turteltaub

Who are you talking to? When you think about all the employees in your organization, who do you see in your mind? You probably, and should, think of several people: the person in the plant, the R&D people, the sales team. They all have different needs, maybe even different cultures.

Adam Balfour, Carsten Tams and Karen Moore (LinkedIn), each of whom is a veteran compliance professional, explain in this podcast why it’s so important to truly know who the people are in your organization and the risks they interact with. They explain that you have to take the time to get in their heads to understand what their needs are and how best to communicate with them.

One technique they advocate for is developing personas: Create fictional, yet realistic descriptions of the types of people in your organization. That will help you better flesh out who they are, their goals and their skills. This process also helps you stand in their shoes and understand not what you want to say but how they are likely to interpret and use that information.

Listen in to learn more about how to bring your workforce to life in front of you and have a real impact on their behavior.

Listen now

View Details

By Adam TurteltaubThere is an expectation in many, if not most people, that at some point they will, or should be, promoted. But how do you know if you are ready? And, once you are promoted, what does it take to succeed in your new role?To find the answers we spoke with compliance veteran, Debbie Hennelly, Founder & President of Resiliti.The first piece of advice she shares is that not everyone needs or wants to be a manager. For many it’s okay to say that they love being a subject matter expert and advisor, and they aren’t ready, or maybe never will be ready, to be something else.If you are looking to move up, how do you know you are ready? She reports that you don’t until you are actually in the job. That’s especially true for compliance people, since we who often don’t benefit from the leadership and management training that is given to other parts of the organization.Once in the role, let the team know that you value them. If there was someone else on it that you beat out for the role, acknowledge the situation and let the person know you recognize the sensitivities and hope to earn their trust.If you are new to the organization, know that it’s okay and better to spend the first 90 days doing a lot more listening than talking. Resist the urge to make changes until you have a better understanding of the organization’s culture. Also, take the time to introduce yourself to peers and leaders. Ask them about their roles and how you can support them.Listen in to learn more about how to step up successfully.Listen now

View Details

By Adam TurteltaubWhat if you had a compliance program and nobody noticed? It’s not likely. But what if you had a compliance program, and nobody understood what it did? That, sadly, is more than a bit of an ongoing problem.To take on that challenge we spoke with Carolina Santos de Silva, Head of Ethics & Compliance EMEA for Bridgestone EMEA and Pauline Blondet, Co-Owner and Chief Operating Officer of Upright Solutions. The two recently published the article “How to Sell Ethics and Compliance to your Organization” in the October issue of Ethikos.They persuasively argue in this podcast for compliance teams to think about their product, brand and having a robust message.Start with your product. Is it ethics, ethics and compliance, integrity? Think through which best defines what you are offering.Your brand is the image the compliance team communicates within the organization and what differentiates you from other departments. It needs to reflect the department’s message.From the brand will come a pitch, or your department’s elevator speech. It should introduce yourself, present your why or purpose, explain what it is that the organization is facing as a challenge and introduce the solution you are providing, and include a call to action.Some other pieces of advice they offer are: Define who your target audiences are, including an assessment of where they are when it comes to compliance, what you expect from them and what the gaps are. To gain leadership support, help them understand the broader compliance context in which the organization operates. Don’t assume leadership understands its role within a compliance program. Show them and then thank them when they help. Seek out as many touchpoints with the workforce as possible. Remember that who sends the message can be just as important as the message itself.Listen in to learn more about strategic and innovative ways to sell your compliance program internally.Listen now

View Details

By Adam TurteltaubWith the explosion of sanctions regimes globally, and particularly in the US, most any company that exports just about anything now has to have a trade compliance effort. To understand what that entails we spoke with Julia Komarovskaya, Export Compliance Manager at MathWorks.It’s a complex challenge, she explains, with the Bureau of Industry and Security (BIS), International Traffic in Arms Regulations (ITAR), and Office of Foreign Assets Control (OFAC) all having a say, and often with overlapping jurisdictions. Organizations need to watch what goods they export, to where and to whom. Knowing your customer has never been more important.To navigate this minefield, she recommends first recognizing that the rules don’t apply only to goods. Services can be covered as well. Also recognize that exporting something as innocuous as a pencil could be prohibited, if sent to the wrong person.Developing an export control program right takes understanding what you are exporting now, working closely with the business team as early in the process as possible, and planning for the long term since regulations are guaranteed to grow more complicated over time.Listen in to learn more about the basics of the complex world of trade compliance.Listen now

View Details

By Adam TurteltaubReports are that there over 50 million people in the world living in modern slavery conditions, and, of those, 60% work in forced labor in the private economy. Ensuring that your organization isn’t sourcing from suppliers who victimize labor is both a moral and a legal obligation, with more and more jurisdictions enacting legislation in this area.Vera Belazelkoska, Managing Director at Ulula urges organizations to look to balancing this risk with a mixture of boots on the ground and technology. Both, she notes, have their virtues and limitations. While having someone visit a factory provides an eyewitness account, it’s expensive, and unscrupulous manufacturers may hide the truth from investigators. Technology solutions are less expensive, but they are not necessarily as precise as they could be, often providing country data, but not the granularity needed.Only with a prudent mixture of the two can an organization gain a better understanding of its supply chain and the presence, or absence, of modern slavery in it.Listen now

View Details

By Adam TurteltaubThere are hundreds of Compliance Perspectives podcasts, and this is the first one that is a podcast about podcasts. More specifically, the podcasts created by the compliance team at John Deere.The compliance team there had long looked to a wide range of tools for reaching the workforce including a monthly email newsletter, channel on internal social media, an intranet site and even digital signs on TV screens at their facilities. Yet, despite all this effort, they knew they could do more.As Wendy Davies-Popelka, the Associate Director, Global Ethics & Compliance, explains, the compliance team was listening to and hooked on several podcasts, and it occurred to them that they should try and create one of their own. So, they did.The podcasts are generally 5-10 minutes long and are based on actual cases that occurred at the company. Investigators, business people and others are interviewed to tell the story, from initial allegation through dispensation.The series has been very successful with a growing audience. Importantly, it has demystified the compliance program.To learn more about the podcasts and how easy they can be to create, be sure to listen to this podcast about John Deere’s podcasts.Listen now

View Details

By Adam TurteltaubPsychological safety is a term we hear a lot in business and elsewhere.  It’s also a concept that Jen Mason, Vice President, Enterprise Compliance & Ethics at McKesson, thinks we in compliance should embrace. It means creating an environment where employees can feel comfortable expressing their thoughts, ideas and concerns without facing negative consequences.It’s not about being nice. It’s about listening, following through on what you say you will do, being respectful of the workloads of others and showing empathy. It’s also about not punishing mistakes, pushing people until they burnout and talking more than you listen. It’s also about having policies that are flexible but consistent.Listen in to learn more about how to create psychological safety, including at those difficult times when there may be a conflict.Listen now

View Details

By Adam TurteltaubWe live, to say the least, in polarized times. While it’s easy to look to politicians as the cause, Karthik Ramanna, Professor of Business and Public Policy at the University of Oxford’s Blavatnik School of Government and author of the book The Age of Outrage: How to lead in a Polarized World, argues there are other causes to consider.In the latest Compliance Perspectives podcast he explains that multiple factors are leading to polarization. These include: Fear of the future: Many believe that the world is and will continue to change for the worse due to factors such as AI, climate change and shifting demographics. A belief that they have been handed a raw deal: They perceive leaders have not managed the issues well and that they have been short-changed in the process by globalization and other factors An Us vs. Them Mentality: A climate of decreasing trust has eroded the belief that we are all in it togetherSo what should compliance teams do in this era? He recommends humility. Set modest goals and don’t seek to radically transform the culture. Instead focus on setting boundaries for your program and focus on what you can do.Second, look to build trust before a crisis breaks. The more you can establish relationships now, the better off you will be later.Listen in for more insights into how to navigate through these polarized times.Listen now

View Details

By Adam TurteltaubThe Corporate Transparence Act was a part of landmark anti-money laundering legislation passed in 2021. It was designed to shift reporting of corporate ownership from a hodgepodge of different financial institutions to the owners or the companies.As Jamie Schafer (LinkedIn), Partner at Perkins Coie explains in this podcast, the goal is to create a national registry of non-public companies that would be transparent to law enforcement. These companies had previously not been required to provide ownership information, which increased the potential for them to be used for money laundering purposes.Due to the complexity of the law and the many exemptions, as well as the fact that publicly-traded firms may even have to report entities they control, she urges organizations to read the law carefully to determine whether they will need to report.Listen in to learn more about the complexities behind whether your organization will have to complete what is, quite often, a fairly simple report.Listen now

View Details

By Adam TurteltaubAre employees where you work suffering from ethical burnout? What is it exactly and how can you tell?To understand more we spoke with Richard Bistrong (LinkedIn), newsletter author and CEO off Frontline Antibribery, who co-authored with Dina Denham Smith and Ron Carucci an article for  Harvard Business Review, “4 Warning Signs of Ethical Burnout on Your Team.”Ethical burnout, as they defined it, is a state in which commercial goals and demands are so overwhelming that workers no longer have the time or energy to consider compliance and ethical obligations. They simply want to get the job done and over with any way that they can.It has a number of potential roots including: Increased commercial pressures and targets, including goals gone wild Survival mode thinking Decision-making overload and speed Envy of unhealthy status symbolsSo what should compliance teams do to prevent ethical burnout? First, be aware of when the stress levels are high and any of these potential roots are growing. That’s the time to double down on ethics and compliance. Also, keep your ear to the ground then reach out proactively and intentionally.Finally, be sure to pay attention to individuals who are particularly susceptible. That star performer may be so addicted to his or her status that they might do whatever they can, ethical or not, to keep it.Listen now

View Details

By Adam TurteltaubBack in November 2023 on a previous podcast,  Jason Meyer (LinkedIn), founder of Meyer Business Law and President of LeadGood Education, shared with us an interesting statistic: Estimates are that about 20% of the workforce has some sort of neurodiversity such as ADHD, autism, dyslexia, sensory integration and executive function issues.In this podcast, he shares that with such a large population there are two risks that the compliance team needs to be aware of and address. First, the training and other content being delivered may not be effective for segments of the neurodivergent population. Second, there are Americans with Disabilities Act (ADA) considerations to be addressed.The ADA, he explains, covers physical or mental impairments that substantially limit one or more of life’s activities. Thinking, reading and communicating all fall under major life activities and are affected by neurodivergence.Consequently, if you know or should know that one of your employees is neurodivergent then you are obligated to engage in a dialogue and make a reasonable accommodation. The ADA is not triggered, however, if the employee is making or not requesting one.There is also risk if your organization fails to hire or promote people because of their neurodivergence.So what should compliance teams do? Add this to the risk assessment and start working on mitigation plans, starting with your compliance messaging and training.Listen in to learn more about how to address this risk that affects one fifth, or more, of your workforce.Listen now

View Details

By Adam TurteltaubGovernments don’t only want to prosecute companies for paying bribes. Increasingly, they are looking for companies to join with them to reduce the global challenge of corruption.To learn more we spoke with Shruti Shah, Senior Policy Advisor, Office of Coordinator on Global Anti-Corruption at the US Department of State. In this podcast she outlines several initiatives in which the business community can play an important role, working alongside state actors and organizations like the OECD. These include: Blue Dot Network Galvanizing the Public Sector GPS initiative CIPE's PROTECT program on critical minerals USAID's JET Minerals Challenge USAID's Doing Business with IntegrityAll of these programs have in common a desire to engage all the parties interested in reducing corruption, particularly in the developing world. As importantly, they reflect a growing recognition that the business community is a part of the solution.Listen in to learn more about what each of these initiatives are and how you can become a part of them.Listen now

View Details

By Adam TurteltaubWoo hoo! You got the interview. Now, how do you make the most out of the opportunity to determine if this is the job of your dreams or of your nightmares?Lisa Fine, Senior Director, Global Ethics & Compliance at Pearson takes a break from her Great Women in Compliance podcast to share that you need first to focus on the basics, starting with who the job is reporting to, what the employer thinks the compliance program should be addressing, and what resources you will have in the role.Learning that information early, either from the position description, recruiter or your own online searches, will enable to you maximize the time in the interview on more sophisticated matters such what they anticipate the role becoming and how real the commitment to compliance is.Some other things to scope out during the interview: Is the job in-person, remote or hybrid, and how does the rest of the company work? If you’re the only remote employee, that may be a warning sign. What do the code of conduct and annual report indicate about the compliance program? Are you the chief compliance officer, or do multiple individuals hold that title? Why is the job currently open? What happened to your predecessor can be telling. Is there a helpline, and how easy is it to make a report?Finally, she advises spending some time asking yourself what it is that you want from the job. It’s very different if you are looking for your first compliance job, than if you are looking to it to be your last.Listen now

View Details

By Adam TurteltaubFair Market Value (FMV) calculations in healthcare, if done improperly, can lead you down the path to civil monetary penalties or even prison. To help understand the challenge and how to meet them, we spoke with Bob Wade, Partner at Nelson Mullins and host of the Stark Integrity Podcast Series.Calculating FMV has proven to be somewhat of a moving target. For some time benchmarking multiple sources and calculating an average was sufficient. Then in 2007 the expectation changes, as they did again in 2021 in the final regulations under the Stark law. Now, the rules are transaction specific, requiring compliance teams to look at the market, benchmarking data as well as business-specific factors.If that seems like a lot, it can be, which leads some to outsource the work. It may be better, though, to do so only for larger transactions. He notes that, if you do outsource, be sure to give the third party the best data you have available, otherwise garbage in can lead to a garbage FMV.When you receive the valuation, don’t just accept it at face value. He advises to take the time to study it to determine if it makes sense and accurately reflects the data and market situation.Listen in to learn more about how to get Fair Market Value calculations right.Listen now

View Details

By Adam TurteltaubSo how do you ensure the next time you’re searching for a chief or senior ethics and compliance officer that the search is successful? We put that question to executive recruiter Jamie Browne, Managing Director, Corporate Governance, Leonid Group. Jamie recently shared advice for candidates on finding their next position.In this podcast he offers a wealth of advice including: Focus more on a candidate’s hands-on experience as a compliance officer rather than education or industry background Be flexible on hybrid options: the fewer days you require in the office, the wider the geography it’s practical to recruit from Fully-remote jobs have the largest candidate pool since it’s possible to recruit nationwide Be sure to consider what personality will fit with the existing compliance team Define a reasonable set of stages for recruiting and the gaps in time between them so you can manage candidate expectations Be sure the salary is commensurate with the experience level you expect Don’t expect a candidate to have deep experience in every compliance risk areaListen in for more and deeper advice on how to increase the likelihood of success for your hiring effort.Listen now

View Details

By Adam TurteltaubYes or no: Do you do investigations? Do you prepare questions in advance? Are those questions yes or no in nature? Did you know that may not be the best way to do it?In this podcast, Michael Johnson (LinkedIn), Chief Strategy Officer, Traliant, explains that closed-end questions are often unproductive. Worse, questioning the target of an investigative with the goal of securing a confession can be dangerous since it may yield a false convention and, potentially, a lawsuit.Instead, he argues for a different approach. Start by thinking through the report that will eventually be written and what factual questions it will need to answer. That can help you think through the potential sources of evidence. Next, determine who needs to be interviewed and in what order.When it comes to the interviews, take a cognitive approach. Establish rapport and help get the person talking by asking about their background and responsibilities. Minimize the use of closed-ended questions, asking, instead, opened-ended questions which invite them to tell a story about what happened. If there are blanks or confusing parts, go back and ask more specific questions.Another technique to try is to ask them to tell the story in reverse order. It’s much more difficult for the person to do so if they are lying.Listen in to learn more about this technique and how it could help improve your investigative efforts.Listen now

View Details

By Adam TurteltaubThe new EU General Product Safety Regulation (GPSR) replaces the previous directive of 2001. While there are many similarities between the two of them, reports Ferry Vermeulen, Co-Founder of 24hour AR, there are a few key differences.  The GPSR now applies to all consumer goods sold, not just those that were not yet covered by other regulatory schemes. In addition, sellers are required to conduct a risk assessment to determine the hazards of the items they are selling.Other provisions include the requirement to have a responsible economic operator in the EU. It can be the manufacturer, itself, or if the manufacturer does not have operations in the EU, it can appoint an authorized representative, whose address must appear on the product.Manufacturers must also develop systems for tracing where their products go, in case of a recall.Listen in to learn more about the new EU General Product Safety Regulation and what your organization needs to do to comply.Listen now

View Details

By Adam TurteltaubThe Organization for Economic Co-operation and Development, better known as the OECD, has long played a role in the fight against corruption. It’s Convention on Combating Bribery of Foreign Public Officials in International Business Transactions has led to the proliferation of anti-corruption laws around the globe and encouraged compliance efforts.In this podcast the OECD’s Ingrid Hampe (LinkedIn), Lead Policy Analyst, and Santiago Wortman Jofre (LinkedIn), Team Lead – Anti-Corruption and Integrity in State-Owned Enterprises , share information about another initiative of the OECD: Compliance Without Borders. A part of the Global Initiative to Galvanize the Private Sector as Partners to Combatting Corruption, and developed in partnership with the US Department of State, it pairs a compliance professional from the private sector with a relevant professional in a state owned enterprises (SOE) for three to six months. During this time the private sector provides hands-on support to help build structures within the SOE to decrease corruption.The key to success for these partnerships is creating the right match of partners. Each participant fills out a detailed form which captures their expertise or needs. The match is made accordingly, with care to ensure that it is compatible on other levels as well and that there are no potential conflicts of interest.The program is part of a growing wave of collective action efforts designed to create new strategies for stemming corruption.Listen in to learn more about this effort, and be sure to take a look at the Compliance Without Borders Handbook.For further information you can contact:Rita Guelzim at the OECD via email.Listen now

View Details

By Adam TurteltaubHealthcare lives on data. Getting it to the patient and providers is essential for delivering quality care, but that can be a challenge.As Eden Avraham-Katz (LinkedIn), Vice President, Legal and Compliance at 1upHealth explains in this podcast, the CMS Interoperability and Prior Authorization Rule helps standardize how health plans and payers share information with individuals, in-network providers and other providers as well. Animating the rules is the goal of empowering the individual with relevant information so that they can make better, more informed decisions as well as benefit from more affordable care.Complying with the rule will require the development of multiple APIs to ensure data moves smoothly. To further ease the flow, the Fast Healthcare Interoperability Resources (FHIR) standard has emerged for structuring data, which helps ensure an accurate transfer.To ensure your organization meets its compliance obligations, she recommends beginning at once. You’ll need APIs to facilitate patient, provider and payer access plus another one for handling prior authorizations.You will also need to focus on your opt-in/opt-out process. Listen in to learn more about how best to address these issues and others to ensure compliance with the Interoperability and Prior Authorization Rule.Listen now

View Details

By Adam TurteltaubDan Longhouse, founder and president, LHT Learning, wants organizations to change their definition of successful compliance training. Rather than just being about avoiding risk, he believes the training strategy should be designed to help employees understand why compliance is critical to business success. They need to see, he argues, that compliance isn’t just about avoiding negative consequences. It’s there to help them do their jobs better and make informed, ethics-driven business decisions.So, what’s the formula for success? His recipe includes: A one-to-three year vision for your training program Ready data to inform the training roadmap Training customized for roles, including relevant content and a media format that works for them The ability to address emerging issues A commitment to promoting retentionListen in to learn more about how to improve the effectiveness of your training initiatives. He also recommends podcasts.Listen now

View Details

By Adam TurteltaubWhat should you ask when first approached about a job by a recruiter? What should you ask during the interview to ensure that there is a cultural fit, and that the compliance program has management support? What skills do hiring managers want in compliance officers? And what’s the overall market like?To get answers to these questions we sat down with a professional recruiter who specializes in compliance positions, Jamie Browne, Managing Director, Corporate Governance, Leonid Group.He had good news: there is strong demand for compliance professionals, especially in hot areas like export controls. But there is also strong demand for a broad range of knowledge, with compliance teams globally being asked to oversee directly or indirectly a wide range of legal and regulatory risk areas.For a compliance officer looking to test the waters or approached by a recruiter, he recommends by asking for as many details about the compliance program as possible right at the start. That includes understanding why there is an opening.  Is this a new position?  Is it a replacement, and if so, why is there now an opening?Be sure not to be shy and to ask early about the sometimes awkward but important practical considerations: what is the salary range, is the job in office, remoter or hybrid and will they pay for relocation? You don’t want to go down the road just to have one of these potential deal breakers get in the way.Once you are in the door and talking to the organization, he also encourages candidates to ask about the compliance culture to determine how strong it is. Also, ask about the overall culture so you can get a better feel for the company and the people you will be working with.He also advises asking about the travel budget. For one, the ability to see things firsthand and build rapport is crucial. Second, it can be a sign of the organization’s commitment to the compliance program.Listen in to learn more about these topics and the value of a legal degree in the current market.Listen nowTo hear Jamie’s advice to employers on recruiting the best candidate, click here.

View Details

By Adam TurteltaubWhen we think of third parties we tend to immediately think of the risks. But what if it is a third party that differentiates itself by the rigor of its compliance program?Such is the case with Swiss-based DKSH, which serves the consumer goods, healthcare, performance materials and technology industries. Tal Freilich, Vice President, Group Governance, Risk & Compliance for the company, explains that the strength of its compliance efforts have been a value add for the company and a selling proposition.So what does he see as a third party being vetted by another company? For one, he learns a lot about the company vetting DKSH. The due diligence process gives him a sense of whether the prospective business partner truly is committed to compliance or whether it might pose a risk to DKSH’s own reputation.He also sees common mistakes such as reliance on a one size fits all due diligence process. There is also an over-dependence on a process of asking prospective third parties for information which is already available online. It is annoying for the third party and time consuming for both. DKSH increased its use of web-based due diligence tools and was able to reduce its own due diligence process in many cases from months to days.He also has found blind spots in many companies’ due diligence processes. They have not yet woken up to expanding requirements in areas such as responsible procurement, including human rights, child labor and carbon footprints.Listen in to learn more about how to improve your third party vetting and to understand the third party’s perspective.Listen now

View Details

By Adam TurteltaubJay Anstine (LinkedIn), President of Bluebird Healthlaw Partners, recently wrote a blog post I spotted entitled How to Sell Compliance Without “Selling” Compliance. It struck home, and I asked if he cared to do a podcast about it.He said yes and explained in the interview that compliance is often seen as the “hall monitor” rather than a welcome party to business conversations. To overcome that he recommends we focus on several methods for changing perceptions.Establish RapportBe more intentional about truly getting to know the business people. Learn about the market, the business partners and competitors that they have. Show them that you understand the business issues that they face. Take the time as well to better know them as people.Do Your HomeworkKnow your audience and their operation. Understand their point of view and the issues that they face. Walk a mile in their shoes. When he faced an issue with hospital registrations, he spent several hours working the registration desk to understand the situation better.Anticipate QuestionsThink like a healthcare leader, not a compliance officer, and how they may respond to what you plan on telling them.Package Your CommunicationsBring them both the problem and the solution. That helps alleviate anxiety and gets you closer to achieving the change you are seeking.Listen in to learn more about how to sell your compliance program internally.Listen now

View Details

By Adam TurteltaubIn 2023 the US Securities and Exchange Commission adopted rules “requiring registrants to disclose material cybersecurity incidents they experience and to disclose on an annual basis material information regarding their cybersecurity risk management, strategy and governance.”Michael Leach, Director, Global Compliance, for data security firm Forcepoint explains that with the rules comes a new focus on transparency. This was help markets and individuals better understand what publicly-traded companies are doing to manage this risk and in response to breaches. The rules also raise pressure on organizations to increase their cybersecurity efforts since no one wants to have to disclose a weak cybersecurity regime or worse, a breach..The rules, he explains, have real teeth, with fines ranging from the $1000’s to the millions. More importantly, the required disclosures are likely to have significant reputational impact on companies.So what should companies be doing in light of the rules? In addition to making any required disclosures he recommends taking the time to understand the impact a cyber incident would have on the organization as a whole. Then, from a hands-on data perspective, make the effort to identify high risk, high value data and invest in the tools to secure it.Listen in to learn more about the rules and what companies need to do to comply.Listen now

View Details

By Adam TurteltaubAt Transparency International’s International Anti-Corruption Conference I had the good fortune of meeting Olusoji Apampa, CEO of Integrity Nigeria. I appreciated hearing his insights on corruption risk in Nigeria, and, to share them with a wider audience, we sat down for this podcast.The risk, of course, is real and high. Worse, many have bought into the idea that there is nothing that can be done, which leads to more corruption. But, happily, he reports that you absolutely do not have to engage corruption to do business there.How? First, he advises understand the risk level; it varies considerably. The picture is very different in Abuja than it is in Lagos, and Lagos is not the Niger Delta. Economic sector matters as well. Doing business in the education sector is very different than doing so in oil and gas or banking.The size of the corporation also has an impact on the corruption risk profile. Generally speaking, larger corporations ore better able to resist the pressure to pay bribes than small or medium-sized ones.So what should companies do? First, take a hard look at the specific risks of where they do business and what industry they are in. Second, don’t embrace corruption as a strategy. Aside from being illegal, paying one bribe can lead to demands for ever more. Third, stick to and be clear about what your principles are, and have a compliance program backing them upHe also urges companies to think outside the box and never go it alone. Instead, they should embrace collective action, working with others who share a commitment to doing business the right way.Listen in to learn more about the risks and how to mitigate them when doing business in Nigeria.Listen now

View Details

By Adam TurteltaubMelanie Fontes Rainer recently marked the completion of her second year leading the Office for Civil Rights at HHS. In this podcast she shared some of the accomplishments over this time as well as what the health care community can expect next.She recounts the six rules that have been issued, ranging from reproductive rights to Section 1557 of the Affordable Care Act, which covers nondiscrimination and is inclusive of sex, race, disability, national origin, religion and color. Also of note have been activities designed to ensure access to documents in languages other than English.She also shares what OCR has been doing to engage with the provider community through in-person meetings, webinars, YouTube videos and resources on their site.Looking to the future, the Director warns that health care providers are likely to continue to be attractive targets for data breaches and ransomware attacks. She advises covered entities to do what they can to make themselves less attractive by having a risk plan and implementing it.Listen in to learn more about what OCR has been and will be doing.Listen now

View Details

By Adam TurteltaubThere isn’t one way to handle conflicts of interest. Much depends on the research the organization is doing, its history and other systems. Hilary Kitson, Research Compliance Business Partner at Saint Luke’s Health System, reports that typically the starting point is Title 42 PART 50 Subpart F in the Code of Federal Regulations. It lays out time points when disclosures are necessary: Annually When discovering or acquiring a new financial conflict of interest (COI) At the time of application for PHS-Funded researchDisclosures aren’t enough, though. There needs to be investigators and a review committee who are competent to examine potential conflicts and are sensitive to the confidentiality of the information involved.And what if there is a conflict? She advises involving regulatory and other professionals who can help develop a management plan, if one is necessary.Listen in to learn more about the very complex issue of conflicts of interest in research.

View Details

By Adam TurteltaubHere’s a terrifying thing I just learned: the average ecommerce website has 66 third-party tags on the page. That’s according to our podcast guest, Rui Ribeiro, CEO of Jscrambler. The tags, pixels and scripts control everything from the video to payment processing to the consent wall to the chat function. And, guess what: they may all be collecting user data, and, quite possibly, more data than they should.So what’s a compliance officer to do, other than lose sleep over the issue? First, make sure there’s an inventory on all those tags, pixels and pieces of JavaScript running on your site and what data they are collecting. While you’re doing it, don’t just ask what’s being run at HQ. There may be regional variations.Next, spend time with all the departments that touch the site to see what they truly need and that data isn’t being accessed without good reason.Then change your thinking around GDPR. It’s not about just getting consent to collect data, it’s time to use it as a warning to focus on knowing who the data is being collected from and why.Once you have that squarely in mind, you can find the right tools to control the data flow and ensure your organization and its third parties are only collecting essential data, not everything you can.

View Details

By Adam TurteltaubWhat have you done?What have you achieved?Have you forgotten?Did you succeed?What were your goals?Were they ever reached?What about your firewall?Was it ever breached?Jisha Dymond took inspiration from Dr. SeussAn annual tradition to give kids a boost.Take the time to note what you have done.It will be illuminating, and may even be fun.This is a podcast you truly must hear.It may change your outlook for many a year.

View Details

By Adam TurteltaubIn April 2024 the US Equal Employment Opportunity Commission released an update to the Enforcement Guidance on Harassment in the Workplace. This was the first update since 1999.Stephen Paskoff, the President and CEO of ELI, explains that the guidance now treats LGBTQIA+ harassment similar to other forms of harassment.The document now also addresses behavior outside of the workplace, making it clear that employers need to train and be more sensitive to behavior beyond the factory gates.Listen in to learn more about what is new in the EEOC Enforcement Guidance on Harassment in the Workplace.

View Details

By Adam TurteltaubDocument retention is one of those persistent issues that comes with a great deal of complexity. As Michael Kearney (LinkedIn), Head Solution Architect, Redgrave Data explains in this podcast, organizations have to deal with a dizzying array of rules. HIPAA has one set of requirements, state laws for medical records another, financial documents have a third, employment records a fourth and on and on it goes.In addition, there are business needs for retaining and disposing of records.So, what’s a compliance team to do? He recommends working with the business unit and other affected teams to write policies that meet the needs of all involved and work out any conflicts internally or among the regulations.Work, too, with employees who may want to hold on to documents longer than policy dictates. You may find that what they want to keep is the data, not the document itself.And, if there is a litigation hold, be prepared to work quickly with legal, IT and others to ensure that the relevant documents are preserved while your ongoing document retention processes continue.

View Details

By Adam TurteltaubData analytics is a pretty darn big deal in compliance and ethics these days, with rising expectations for compliance programs to be able to demonstrate their effectiveness using hard data. The word “data” even appears a dozen times is the US Department of Justice Criminal Division’s Evaluation of Corporate Compliance Programs document.Walter Appleby, formerly VP, Compliance & Ethics at Georgia-Pacific and Rosie Williams, Director, Compliance & Ethics there will be addressing “Harnessing the Power of Data:  Unleashing Compliance Excellence” at the SCCE 23rd Annual Compliance & Ethics Institute, which will be held September 22-25 in Grapevine, TX.In this podcast they explain that better use of data carries a number of benefits including a stronger risk assessment and management program, better informed decision making, and more effective use of compliance resources.Data analytics begins with collecting together the data you have and determining its quality. As the old adage says: bad data in, bad data out. Sources of data can include your helpline, training statistics, HR and even legal.You will also need to determine which metrics best reflect the performance of the compliance program. Here, the risk assessment is helpful, but so too is taking the time to listen to and think through the needs of your customers in the business unit.Next, determine the proper recipe for integrating the various data resources so you and leadership can gain insights into gaps and deficiencies. This likely includes taking the time to think graphically to determine how best to visualize the data in ways management finds useful.Listen in to learn more about how to use data to pinpoint issues, identify opportunities and assess the effectiveness of your program. And, don’t forget to catch their session at the 23rd Annual Compliance & Ethics Institute.

View Details

By Adam TurteltaubMobile devices are terrible if you need to retrieve information from them. Employees hate handing them over and there are a ton of apps in which data disappears automatically. All in all, it’s just a nightmare.But, the government still wants you to track what employees are saying, and you may have to produce that data.Matt Rasmussen (LinkedIn), CEO, and Ryan Frye (LinkedIn), Chief Innovation Officer of ModeOne want to discourage you from falling into despair over the prospect. Employee resistance can be overcome by taking a targeted approach and using electronic tools that only seek business-related data.Even before you get to that point, though, they recommend taking the time to train the workforce about what rights the company has to the data so this doesn’t come as an intrusive surprise.Listen in to learn more about how to make retrieving mobile device data a bit less painful.

View Details

By Adam Turteltaub“What else should the board be asking?”It’s a good question in general and the tile of a session at the SCCE Compliance & Ethics Institute, which will be held September 22-25, 2024 in Grapevine, TX.In this podcast, the leaders of that session, Deborah Spanic, Chief Ethics & Compliance Officer of Clarios, and David Gebler (LinkedIn), Principal of Leading with Ethics, share that there are three fundamental questions the board should be asking about the compliance program: Is the compliance program well designed and aligned with risk? Is the program being applied earnestly and in good faith with adequate resources? Does the compliance program work in practice?From there a host of other questions fall out including those focused on culture and on the connection between the compliance program and the enterprise’s overarching strategy.Making sure the board is asking the right questions, and getting the answers it needs, requires a strong relationship with the compliance team. In Deborah’s case that includes being a standing agenda item for the audit committee each quarter and having a one-on-one conversation each mid-cycle with the audit committee chair.Listen in to learn more, and then be sure to join their session in Grapevine at the  Compliance & Ethics Institute.

View Details

By Adam TurteltaubHow do you get employees working remotely, who may have less of a connection to the company, to make the effort and take the risk of reporting potential wrongdoing?For Evie Wentink, it starts with recognizing the need to encourage a culture of reporting for these workers. It also includes recognizing that, even though they are remote, it doesn’t mean that they aren’t victims of or witnesses to a range of bad behaviors including harassment and bullying.Compliance teams should also recognize that remote workers lack many of the casual opportunities to discuss with peers what they are seeing and what to do about it.To help overcome these challenges, she recommends training and creating multiple reporting avenues.She also recommends training managers in active listening so that they know what do when an employee walks through the virtual door with a concern.

View Details

By Adam TurteltaubIt’s not for nothing that there’s a year in the title of this blog post and podcast. Social media risks change frequently, explains Kortney Nordrum, VP, Regulatory Counsel & Chief Compliance Officer at Deluxe. She is the author of the chapter “Social Media Compliance” in The Complete Compliance and Ethics Manual and will be leading the session Social Media:  Old News and New Risks at the 23rd Annual Compliance & Ethics Institute.These days the range of those risks is substantial. TikTok poses a notable challenge, since it accesses most everything on the user’s phone, which means work email and files may be exposed.At the same time the FTC and NLRB have been very aggressive in their enforcement. The FTC has been scrutinizing endorsements – and a “like” may count as one – by employees of their employer’s products and services. Meantime, the NLRB has made it clear that it believes employees have wide, although not complete, latitude about what they say about their workplace online.And, if that wasn’t enough, the marketing and social media teams need to be trained (and monitored) for what they are saying and doing in the company’s name.What should you do? She recommends training with concrete examples, teaching people some common sense, and keeping lines of communication open.To learn more, listen in and then don’t miss her session at the 23rd Annual Compliance & Ethics Institute.

View Details

By Adam TurteltaubIn some ways it’s still the Wild West when it comes to AI, with developments happening faster than most can fathom and the law can respond. At the same time, though, the sheriff has begun to arrive.Gwen Hassan (LinkedIn), Deputy Chief Compliance Officer at Unisys and Adjust Professor at Loyola University Chicago School of Law explains that the EU already has a law in place with a particular focus on ranking the risks of AI, including those that must not be taken, and an emphasis on the privacy implications.In the US, there is legislation proposed that would require clear notification when content is created using generative AI. It has yet to pass.Thus far the strongest direction in the US comes out of the White House, where President Biden issued the Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.  The order urges ethical generative AI guidelines, sets key goals for what good uses of AI are and calls upon various departments of the government to provide further analysis and direction.So what should compliance teams do now, despite the legislative holes? She recommends looking at how to extend the existing compliance program to AI and, as AI evolves, develop more specific programs that maps to its risks.Listen in to learn more about the emerging regulatory climate for AI.

View Details

By Adam TurteltaubIf you’re thinking about attending an HCCA Research Compliance Academy, take a few minutes to l to this podcast featuring Kelly Willenberg (LinkedIn), one of the faculty members and founder of Kelly Willenberg & Associates.Listen in as she explains: Who the Academy is for. Basically anyone working in or with oversight of research compliance The teaching structure. All of the faculty members have deep research compliance expertise.  They will teach both compliance infrastructure and many of the complexities of the numerous legal risk areas. The attendee experience. Small class sizes lead to opportunities to learn from your peers and build an extensive and deep network.She also gives an overview of the Certified in Healthcare Research Compliance (CHRC) exam. To read more about the exam and see the detailed content outline click here.So spend ten minutes listening to the podcast, and then plan on attending an HCCA Research Compliance Academy.

View Details

By Adam TurteltaubCorruption is a well-known risk in Latin America, but how great the risk is on a country-by-country basis is less well understood. To fill in those blanks and many more, the law firm Miller & Chevalier just released its 2024 Latin America Corruption Survey.The firm has been fielding this survey every four years since 2008, reports Matt Ellis, Latin America Practice Lead. It provides comprehensive, country-by-country data as well as, more granular information on the risks of dealing with various governmental entities.This year’s report, he shares on the podcast, had interesting news for the compliance community. It found that, although corruption remains a pervasive problem, corporate compliance programs, more so than enforcement, are perceived as being the key driver for change.The survey also revealed significant nuances in the anticorruption risk picture: Chile, Uruguay and Costa Rica are generally perceived as the lowest risk countries Venezuela, Bolivia, Honduras and Argentina are on the riskier side In general, political parties are perceived as being corrupt as well as municipal governments Brazil’s customs authority, Peru’s judicial branch, Argentina’s executive branch and Mexico’s police and local governments were all singled out as areas of concernListen in to learn more about what the survey revealed, including corporate trends in investing in anti-corruption efforts.

View Details

By Adam TurteltaubHow do you tell someone something that they don’t want to hear in a way that they will listen? How do you overcome your own desire to avoid the conversation?To better understand why people hesitate to have difficult talks and how to communicate more effectively, especially when the conversation is going to be a tough one, we spoke with Jason Rosoff, CEO of Radical Candor (podcasts).People hesitate to speak candidly, he explains, for a number of reasons. For one, they may fear that the conversation will harm their relationship with the other person. They may also be nervous about facing a negative reaction, or even retaliation, for speaking out.To help challenging conversations go better, he advocates for radical candor, which he explains means challenging directly but also caring personally at the same time. Be clear about the problem, he advises, and what the potential negative consequences are. At the same time, though, show you care personally. That includes giving the other person the benefit of the doubt, avoiding sounding judgmental, and focusing on helping them.It also means being willing to listen to the other person’s side.Listen in to learn more about how to have better conversations and how to avoid the more common traps that we all can fall into.

View Details

By Adam TurteltaubISO 27001 is the leading standard for information security management systems. As Mel Blackmore, CEO of UK-based Blackmores explains, it is a framework that applies and is of value regardless of an organization’s size, sector or country.Organizations seek ISO 27001 certification to ensure that their IT security reflects best practices. It also brings to organizations a systematic approach to work in this area. In addition, potential business partners will have greater confidence that your organization has robust data defenses.Most organizations have a head start when it comes to becoming ISO 27001 certified. Many existing IT security practices are likely to be consistent standards. To get the rest of the way to certification, she outlines several steps including: Determine where your organization is already compliant Conduct a gap analysis Performing a risk assessment Creating policies and proceduresListen in to learn more about meeting this important ISO standard and what it will take to maintain certification.

View Details

By Adam TurteltaubWhat do we do with ESG? Is it a part of compliance? Something different? How do we handle it?Renee Murphy, Distinguished Evangelist at Diligent argues in this podcast that while there are compliance aspects to ESG, it is best to quickly make it a part of operations and under the general risk management structure.Of the three elements of ESG, it is the environmental sustainability side, she believes, that will be the most challenging. With new requirements for organizations to report on their fossil footprint, companies are being forced to march into unexplored territory. As a result, they will need to evolve their process, which, she believes, will become easier as management comes to understand the balance sheet implications.Listen in to learn more about what is happening with ESG, and what compliance teams need to know.

View Details

By Adam TurteltaubHealthcare enforcement is never quiet. There’s always something, or many things, going on, and compliance teams need to stay on top of the trends to ensure that their programs are staying ahead of the risks.To find out where things are today, we spoke with Ronald Chapman II, author of the book Unraveling Federal Investigations, defense attorney with Chapman Law Group and president of Chapman Consulting Group.In this podcast he identifies several areas of intense enforcement activity: Drug testing labs are under scrutiny, particularly around the number of panels and reflex testing Telemedicine continues to be a hot area as well Venture capital firms are entering healthcare and/or deepening their investment, often with complex payment arrangements and without sufficient antikickback review Aggressive telemarking in the durable medical equipment space persists Credentialing issues, especially for smaller entities, are resulting in non-payments and fraud allegationsOn the criminal side, he notes that controlled substance prescribing is in prosecutors’ eyes, often coupling these cases with fraud charges, leading to a one-two punch.Listen in to learn more about what healthcare enforcement authorities are doing and how to strengthen your compliance efforts.

View Details

By Adam TurteltaubCreating the right corporate culture is an idea that’s sacrosanct in the field of compliance and ethics. The folks at Gartner, though, are challenging that belief.In this podcast Chris Audet, Vice President and Chief of Research for General Counsels and Chief Compliance Officers, tells us that their newly released report finds that focusing on key quality measures in the compliance program may be more important.The firm reached the conclusion after surveying over 1000 employees about the situations that lead to employee noncompliance. To quote from the press release, “In the survey, 87% of respondents said they faced situations where they didn’t know how to comply in the last 12 months, followed by 77% of respondents who experienced situations of rationalization and 40% experiencing situations of malice.”Improved quality standards – the design and accessibility of policies, training and so forth – had much more of an effect on reducing uncertainty than culture did. As he notes, when employees are faced with uncertainty, the key thing is to have easily accessible policies and a workforce that knows where to find them.Most troubling, of course, is the reportedly high temptation, not always acted on, to be noncompliant for malicious reasons. Listen in to learn more about the challenges of malice and rationalization and how quality standards may help there as well.

View Details

By Adam TurteltaubThere’s no General Data Protection Regulation (GDPR) in the US. Absent a comprehensive, national privacy law, states have stepped in to fill the gap.As Adam Greene (LinkedIn), Partner at Davis Wright Tremaine explains in this podcast, that’s creating some complications. The California Consumer Privacy Act (CCPA) already differs from subsequent laws in several states which use language reminiscent of the GDPR. And while there are many similarities, some differences are substantial. For example, some state laws are targeted at businesses, not non-profits. That’s an important distinction for healthcare with so many non-profit institutions.Perhaps the greatest challenge for organizations is figuring out which standard to follow, if any. Do they take a state-by-state approach, or one national approach based on the toughest state laws? Whatever the choice, it’s important to determine what data you have since there may be limits on collection and a requirement to share that data with consumers who want to see it.Listen in to learn more about what the states are requiring and what you need to do to meet their expectations.

View Details

By Adam TurteltaubFor as much as there is talk about the force of the US Foreign Corrupt Practices Act (FCPA), the impact of the OECD’s anticorruption efforts deserves a great deal of credit. By encouraging laws against foreign bribery, anticorruption compliance efforts, and grading the work of the countries who are parties to their Antibribery Convention, the OECD continue to raise the bar.In Australia, the OECD’s push for more resources for small and medium enterprises (SMEs) seeking to avoid corruption led to the creation of the Bribery Prevention Network, explains Dan Wilcock (contact), Head of Sustainability Governance for the UN Global Compact Network Australia and Manager of the Bribery Prevention Network. This public-private partnership was born out of the work of more than thirty organizations working collaboratively.The end product is a robust online hub filled with practical resources on topics such as anticorruption programs and conducting risk assessments. The Network also facilitates sharing of expertise from larger organizations to the SMEs in their supply chain.Listen in to learn more about what they are doing and lessons for others seeking to start similar endeavors.

View Details

By Adam TurteltaubBest known as The FCPA Professor, Mike Koehler argues that that many people have it all wrong when it comes to enforcement of the Foreign Corrupt Practices Act (FCPA). Citing historical data he argues that there is not, contrary to popular opinion, a slow down in enforcement of the FCPA. The pace of roughly 12-13 resolutions per year has continued.In fact, the three resolutions in the first quarter of 2024, he notes, puts it on track to continue the trend.How do compliance teams get management attention to FCPA enforcement? He recommends against just focusing on the likely price of the settlement. Instead, outline all the costs. Those start with the multiple years before the resolution when the costs of legal, accounting and other fees may be as much as twice the resolution. Then, point to the eighteen months or so after the settlement when the organization will be under ongoing scrutiny, likely at a substantial cost.All of this, of course, is in addition to the diminished productivity and potential business losses.Listen in to learn more about how he sees anticorruption enforcement shaping out both by US and international prosecutors.

View Details

By Adam TurteltaubJessica Zeff (LinkedIn) loves government audits. I know, it’s hard to believe, given the dread they inspire. But, the founder and lead consultant of Simply Compliance makes a very good case in this podcast that audits can be much better than people expect and actually helpful for the compliance program.How is this possible?  She argues strongly that, given the inevitability of an eventual audit, compliance teams should prepare for them on an ongoing basis rather than just when the audit notification arrives in the mail. By assessing what data an auditor might need, what gaps they may find, and what concerns they may have, compliance teams can complement their risk assessment process and have a better handle on where they should be focusing their efforts.As importantly, having this information handy can be helpful during the audit. Not only does it reduce last minute rushing to prepare, it enables the team to tell auditors their story in a way that shows the organization is doing the right thing and that compliance is on the ball.When the auditors arrive, she advises being prepared logistically as well. This includes having relevant (and not irrelevant) data ready for the auditors. In addition, she recommends thinking through what they will need -- from space to meals -- and ensuring that the staff they need to interview is available.Listen in to learn more about how a government audit may not just be better than you think but also a positive experience.

View Details

By Adam TurteltaubIntegrity is like peace, love and brotherhood.  We’re all for it, but when it comes to practicing it, that’s when the challenges start.Paul Fiorelli hopes to change that. The Director, Cintas Institute for Business Ethics at Xavier University has just written a new book: Establishing Workplace Integrity. In it, Paul addresses six lessons in values-based leadership.To benefit from some of his long-established and well-recognized expertise we asked him to join us for this podcast. He discusses the importance, of values-based leadership. He also cites six factors that lead people into unethical or non-compliant behavior: Pressure to perform Going down a slippery slope Rationalization Groupthink Altruism (violating the law to help the company) GreedOne or several of them are at play when wrongdoing occurs.So what makes for success and helps to prevent wrongdoing? He makes an argument for SMART goals: specific, measurable, attainable, relevant and time-based.Listen in to learn more about values-based leadership and promoting a workplace of integrity.

View Details

By Adam TurteltaubWhat makes for an effective compliance program, not just from a legal perspective but from a practical one? Getting that answer, and sharing it is the focus of the LRN 2024 Ethics & Compliance Program Effectiveness ReportTo learn what it contains we sat down with Meredith Hunt (LinkedIn), Ethics and Compliance Specialist at LRN. In this podcast she shared that more effective programs are focused on values rather than rules, and underscore the importance of ethical culture. They are also taking a risk-based approach.Their research also revealed the importance of adapting to the current business environment. With employees working remotely has come a change in how they gather information. The code of conduct, policies and procedures have to be accessible wherever workers are.Within the compliance program’s internal operations, effective programs, they report, are focusing more on data and metrics, looking for the data that show where the program is and isn’t working, and enabling continuous improvement.Listen in to learn more about how to create a more effective compliance program in your organization.

View Details

By Adam TurteltaubThe 340B Drug Pricing Program was created to protect safety net hospitals from rising drug prices. It allows them to purchase outpatient drugs, and pharma companies to sell those drugs, at a discount.In this podcast, Jason Reddish (LinkedIn), Principal and Mark Ogunsusi (LinkedIn), Associate, at Powers Pyles Sutter & Verville provide an overview of the program and the compliance requirements. They are also two of the authors of the chapter “Pharmacy:  340B Drug Pricing Program” in the Complete Healthcare Compliance Manual.The 340B program helps hospitals that are the last line of defense for underserved communities, including those with a large percentage of Medicaid patients. Often, they are the only hospital around in rural areas. Also helped by the program are federal grantees such as Ryan White clinics and those providing treatment for STDs.The program dictates which entities can buy discounted drugs and have very specific requirements including two very important ones. First, the drugs cannot be resold or transferred to anyone who is not a patient of the covered entity. Second, double billing of Medicaid is prohibited and must be monitored for.There are a number of typical compliance problem areas, but the good news is that there has been a decline in non-compliance.Listen in to learn more about what covered entities are doing right, and what you should be on the lookout for.

View Details

By Adam TurteltaubCurrently on hold due to pending court challenges, the SEC’s rules to standardize climate-related disclosures created a fire storm of controversy and comments when first proposed.The final rules (assuming the courts sides with the SEC), explains Laura Ann Smith and Judy Mayo of the communications firm Labrador (LinkedIn), reflected strong industry pushback, easing the burden on some 4000 filers.Nonetheless, there are serious demands on industry. To quote from the SEC press release, registrants will be required to disclose: Climate-related risks that have had or are reasonably likely to have a material impact on the registrant’s business strategy, results of operations, or financial condition; The actual and potential material impacts of any identified climate-related risks on the registrant’s strategy, business model, and outlook; If, as part of its strategy, a registrant has undertaken activities to mitigate or adapt to a material climate-related risk, a quantitative and qualitative description of material expenditures incurred and material impacts on financial estimates and assumptions that directly result from such mitigation or adaptation activities; Specified disclosures regarding a registrant’s activities, if any, to mitigate or adapt to a material climate-related risk including the use, if any, of transition plans, scenario analysis, or internal carbon prices; Any oversight by the board of directors of climate-related risks and any role by management in assessing and managing the registrant’s material climate-related risks; Any processes the registrant has for identifying, assessing, and managing material climate-related risks and, if the registrant is managing those risks, whether and how any such processes are integrated into the registrant’s overall risk management system or processes; Information about a registrant’s climate-related targets or goals, if any, that have materially affected or are reasonably likely to materially affect the registrant’s business, results of operations, or financial condition. Disclosures would include material expenditures and material impacts on financial estimates and assumptions as a direct result of the target or goal or actions taken to make progress toward meeting such target or goal; For large accelerated filers (LAFs) and accelerated filers (AFs) that are not otherwise exempted, information about material Scope 1 emissions and/or Scope 2 emissions; For those required to disclose Scope 1 and/or Scope 2 emissions, an assurance report at the limited assurance level, which, for an LAF, following an additional transition period, will be at the reasonable assurance level; The capitalized costs, expenditures expensed, charges, and losses incurred as a result of severe weather events and other natural conditions, such as hurricanes, tornadoes, flooding, drought, wildfires, extreme temperatures, and sea level rise, subject to applicable one percent and de minimis disclosure thresholds, disclosed in a note to the financial statements; The capitalized costs, expenditures expensed, and losses related to carbon offsets and renewable energy credits or certificates (RECs) if used as a material component of a registrant’s plans to achieve its disclosed climate-related targets or goals, disclosed in a note to the financial statements; and If the estimates and assumptions a registrant uses to produce the financial statements were materially impacted by risks and uncertainties associated with severe weather events and other natural conditions or any disclosed climate-related targets or transition plans, a qualitative description of how the development of such estimates and assumptions was impacted, disclosed in a note to the financial statements.Even with all these requirements, Smith and Mayo recommend that companies realize that this is just a baseline. For those with operations in Europe there are requirements to meet as...

View Details

By Adam TurteltaubIt used to be that tracking email usage was considered tough. These days the workforce is also communicating via text, WeChat, Slack and countless other channels both internally and externally. That can be a total nightmare since prosecutors want access to all those conversations.What makes things harder is that employees may be resistant, feeling that the communications they have on their phone, especially in organizations with a Bring Your Own Device (BYOD) policy, is private. The employee owns the phone, not the company.Eddie Green (LinkedIn), CEO of SnippetSentry advises companies get their heads around this problem. Digital compliance is broadening out from the investment community to pharma and elsewhere.To manage the issue, some companies are now scrapping BYOD policies and making it clear that all work communications need to go on work-owned devices. They are also looking for solutions which enable employees to communicate in familiar ways, but with the tracking that logs all those communications.Listen in to understand the challenge and how to approach it more effectively.

View Details

By Adam TurteltaubIn January 2024 the US Attorney’s Office for the Southern District of New York (SDNY) set a shockwave through the business world by announcing a new whistleblower pilot program. To understand what the policy says and what it likely means for compliance programs, we spoke with Todd Haugh (LinkedIn), Associate Professor of Business Law and Ethics, Arthur M. Weimer Faculty Fellow in Business Law at the Kelley School of Business at Indiana University.Under the policy, he explains, individuals who have participated in a fraud may be eligible for a non-prosecution agreement, if the individual meets three key criteria: They provide information that is not previously known to prosecutors and is produced voluntarily, not subsequent, say, to an arrest. The information is full, substantial and truthful. The individual is not otherwise disqualified, such as serving as a government official or the CEO or CFO of the company.Given the incentives already in place for companies to self-report wrongdoing, this is in many ways an extension of what already exists.However, it’s impact should not be underplayed. The SDNY is a leader in white collar prosecutions and other US Attorney’s offices are likely to follow suit. At least one already has.Second, while the SEC has encouraged whistleblowing at publicly traded policies, the SDNY policy is open to public, private and even non-profit organizations.The new policy also may create situations in which employees and their employers find themselves in a race to disclose first.This, in turn, means that organizations need to significantly increase their efforts to create a culture that encourages internal whistleblowing. That includes creating easy paths to follow for potential whistleblowers and prompt investigations.Listen in to learn more about the policy and how your compliance program may need to evolve as a result of it.

View Details

By Adam TurteltaubIn late 2023, The Office of Inspector General (OIG) at the Department of Health and Human Services issued its new General Compliance Program Guidance. In this podcast, David Schumacher, Partner and Co-Chair of the Fraud & Abuse Practice at Hooper Lundy & Bookman explains that this document is both evolutionary and revolutionary.For years the OIG’s office had been offering guidance through the Federal Register. To make that information more accessible it moved it online, consolidated the information, added interactive features and created a much richer resource which makes it both easier for compliance teams to understand the OIG’s expectations and more difficult for some to claim that they were unaware of the rules.The changes, though, are more than just the media used to communicate OIG expectations. The document demonstrates both the ongoing expectations by OIG for robust compliance programs and communicates changes in focus. For one, it reveals an enhanced emphasis on quality issues in healthcare and patient safety.It also reflects the OIG’s efforts to ensure effective compliance program in new entrants into healthcare, such as private equity and technology firms. Both may well discover that practices that are permissible elsewhere are not in healthcare.The guidance also encourages incentivizing compliance.Another gem in the guidance is the clear message to carefully scrutinize arrangements with third parties. Due diligence at the outset is important, but it is also necessary on an ongoing basis to determine if the relationship is necessary and the price tag is fair market value.Listen in to learn more, and be sure to check out the General Compliance Program Guidance.

View Details

By Adam TurteltaubTired of being last to the party and then perceived as a party pooper?There’s a solution to that problem embraced by Dana McMahon, Global Chief Compliance Officer, Head, Privacy & Enterprise Risk at Stryker. She works to have her team embedded in the business unit.It’s a process that begins with getting a seat at the table and being intentional about conversations. From there the relationship evolves into being a consultant on sticky issues and then on to being integrated into decision making and proving yourselves indispensable.The key to the process, she explains, is to show up with a problem-solving mindset. Throughout, the compliance team has to be aware of the needs of the business and its challenges.To solidify compliance’s place takes three things: Adopt a problem-solving approach Tailor your efforts to the most pressing issues Timing: anticipate what the business needs to move forwardListen in to learn more and gain other tips for fully embedding compliance into the business process.

View Details

By Adam TurteltaubAt the center of managing cyber risk in healthcare sits the Health Sector Coordinating Council Cybersecurity Working Group (LinkedIn). In this podcast, Executive Director Greg Garcia explains that healthcare has been designated as a part of the critical infrastructure, and the council has as its mission to: “identify systemic cybersecurity threats to critical healthcare infrastructure; collaborate on guidance and policies for mitigating those risks; and promote threat preparedness and incident response awareness and activities.”It’s a needed mission. The number of data breaches have soared, and ransomware has emerged as a top threat, crippling the ability of healthcare providers to care for patients.The Council recently released its Health Industry Cybersecurity – Strategic Plan. A five-year plan, it identifies trends, goals and objectives for securing healthcare technology infrastructure.One key goal, in the words of the plan, recognizes that, “A trusted healthcare delivery ecosystem is sustained with active partnership and representation between critical and significant technology partners and suppliers, including non-traditional health and life science entities”  It sets four objectives under that goal: Simplify access to resources and implementation approaches related to the adoption of controls and practices aligned with regulatory and sector standards for securing devices, services, and data Increase new partnerships with public/private entities on the front edge of evaluating and responding to emerging technology issues to enable safe, secure, and faster adoption of emerging technologies Enhance health sector senior leadership and board knowledge of cybersecurity and their accountability to create a culture of security within their organizations Develop meaningful cross-sector third-party risk management strategies for evaluating, monitoring, and responding to supply chain and third-party provider cybersecurity risksListen in to learn more about the document, the council and how the healthcare sector is working together to stem cyberthreats.

View Details

By Adam TurteltaubThe FCPA sure isn’t what it used to be, or is it?While the headline grabbing Foreign Corrupt Practices Act cases are much less frequent than they once were, there is still substantial risk both for individuals and companies, as recent dispositions have shown.To understand where things are we sat down with Markus Funk, partner at Perkins Coie and author of the chapter “Anti-Bribery and Corruption Compliance Programs” in The Complete Compliance and Ethics Manual 2024.He explains that just because there aren’t cases in the news, doesn’t mean all is quiet. There may remain a steady stream of companies self-reporting violations and reaching less-formal agreements with the DOJ.Whatever the trend may be, third parties remain the greatest risk, and the prescription stays the same. You need to know who the third party is and hire them for the right reason: their expertise and track record for success in the right way. Hiring a government official’s cousin to help get the deal remains a very bad idea.Another bad idea:  assuming your people are not a risk area. They are. Be sure to be sensitive to internal risks. Train the workforce and work with the finance team to help them serve as an extra sets of eyes when it comes to spotting misconduct.Above all, stay alert and be prepared to investigate possible incidents. Prosecutors still expect companies to bear the brunt of the investigative burden.

View Details

By Adam TurteltaubKrista Muszak is organized. More importantly, the longtime compliance professional and Senior Manager, Regional Process & Optimization Lead for Pfizer knows how to keep others organized as well.She will be sharing some of this wisdom in Nashville at the 2024 HCCA Compliance Institute in the session “Muda, Mura, Muri to Veni Vidi Vici: Applying Project Management and Process Improvement to Your Compliance Program.”  She also shares a bit of it here in the latest Compliance Perspectives podcast.First, she explains that the title comes from terms used by Toyota to improve the process flow at their plants and eliminate waste.Muda is about eliminating waste and activities that don’t add value.Mura speaks to addressing variability in operations to increase stability and reduce unnecessary variations.Mudi addresses not overloading people and the business with too many asks, such as releasing a round of training at the same time as year-end activities.Embracing these concepts can increase efficiency and effectiveness. At the same time adopting a project management approach helps build guardrails around your efforts. Use it to identify who is responsible, who is accountable, who needs to be informed and who needs to consulted. This brings clarity into who the key players are and their responsibilities.With the right people on board, a project charter can be extremely effective, identifying what the project goals are, and what they aren’t. From there it is time, she explains, to move on to measure, analyze, improve and establish controls for your initiative.Listen in to learn more about how to bring greater effectiveness and efficiency for your compliance efforts.

View Details

By Adam TurteltaubWhen it comes to compliance technology, there are two challenges. First is finding the right solutions to increase your programs effectiveness. Second is securing the resources to acquire and deploy the technology.Parth Chanda, Founder and CEO of Lextegrity, covers both topics in this podcast.When it comes to tech, he explains, you want tools that give you the confidence that your program is effective in practice and not just on paper. You also need to prioritize based on risk, and your organization’s own experience with technology. If the history is short or non-existent, start with something relatively simple such as training or policy management.  Tools that can make it easier for employees to report wrongdoing are also invaluable.To secure the resources you need, he advises making the business case by focusing on the ROI, for example, by showing that investigations can be completed in less time and with less staff.But, as you look at technology, be realistic and recognize that technology will not remove human judgement. It can expose gaps and gray areas, but then the compliance team will need to step in to understand the nuances and the appropriate solution.

View Details

By Adam TurteltaubImagine you are at a large company with thousands of suppliers. As a part of the compliance team you need to understand the risk of working with each and every one of them. To do that you may need to understand the ownership structure, where they source materials, where and how they manufacture, and a host of other data about each and every one of them.That’s a daunting task. It’s also one that Jenna Wells, Chief Customer and Product Officer at Supply Wisdom believes is ideally suited for AI. With human supervision it can help with such a large, seemingly impossible undertaking.AI, she argues, can be an effective tool for enabling compliance programs to better understand the risks they face and then focus on the most important ones.To get there, compliance teams need to get a handle on the data that they have that is normally siloed. Look to external sources for regulatory data and emerging legislation, she suggests.At the same time, though, it’s important to understand the limitations of AI. While it can handle the brute force exercises, such as combing through all the data on all those vendors, there is still a need for the human element.Listen in to learn more about putting the power of AI to work for your compliance efforts.

View Details

By Adam TurteltaubTraditionally, explains, Tanya Ganguli (LinkedIn), Principal Associate, Law Offices of Panag & Babu, India’s criminal law framework revolved around the Indian Penal Code, The Code of Criminal Procedure and the Indian Evidence Act, two of which dated back to the 19th century. That changed with the passage of three new laws: the Bharatiya Nyaya (Second) Sanhita, 2023, the Bharatiya Nagarik Suraksha (Second) Sanhita, 2023 and the Bharatiya Sakshya (Second) Bill, 2023.Together they seek to bring criminal law into the 21st century and build off of long-established precedents. They are designed, she reports, to address loopholes, enhance efficiency and ensure justice.The laws are now more victim centric, but may not be too transformative, according to Tanya, for most compliance and ethics programs. Nonetheless, there are changes. New rules for searches and seizures will likely require updated training on dawn raids. Summons can now be delivered electronically. There is much greater need to digitize and consolidate records. Having the right tone at the top will be more important than ever.However, the change is likely to come relatively slowly with many aspects of the law expected to be implemented in stages.So keep your eye on the horizon in India, and be sure to listen to this discussion.Also, don’t miss the first ever SCCE Basic Compliance & Ethics Academy in India.

View Details

By Adam TurteltaubAs of January 2024, there’s a new Code of Conduct of the Volkswagen Group, replacing one developed in 2017.To understand what led to the latest iteration of the code and the vision behind it we spoke with Silke Becker and Sarah Specht (LinkedIn) of Volkswagen Group Integrity & Compliance. They are part of a team lead by Tina Landsmann, Head of Volkswagen Group Center of Competence Integrity & Compliance Awareness & Qualification and Dr. Kurt Michels, Volkswagen Group Chief Integrity & Compliance Officer.The code was updated to reflect changing times, including the draft European Supply Chain Act. This required a change in content, but the team also chose to update the tone and feel.The language of the document now focuses on “we” and “us”, and it is very proactive, making the document less about what the board or management calls for and is instead about what we as a group are committing to. Each section of the code has a headline that reinforces this message: “We take responsibility for human rights,” “We lead based on our values,” “We like diversity.”The document embraces a magazine style to increase readability, and there is the opportunity to digitally drill down on individual topics, make it a one-stop shop for employees.As the team developed the document, in partnership with individuals around the company from multiple departments, they had several goals in mind. First, it had to be relevant for everyone, whether working in conventional auto manufacturing or battery development. Second, it had to work all around the globe given Volkswagen’s global footprint. It also had to be more human.Take some time to see all of these elements and more when you explore the code. Then listen to the podcast to hear the story behind it and, maybe, get some ideas for updating your code of conduct.

View Details

By Adam TurteltaubOn January 5, 2023 the EU Corporate Sustainability Reporting Directive went into force. The directive broadens the scope of companies report on sustainability issues, adds to the amount of information that needs to be reported, and even requires external assurance, reports Elena Sychenko (LinkedIn), Adjunct Professor at the Department of Management at the University of Bologna and currently a Fulbright Scholar at the Wharton School of Business.The directive now covers all listed companies with the exception of micro enterprises. Also falling under it are non-EU companies that have a significant presence in the EU.The reporting requirements, which are still being fully developed, closely follow the Global Reporting Initiative (GRI) standards and focus on ESG explicitly, with several areas of reporting under E, S, and G. These include: E: climate change, pollution, water, biodiversity S: the organization’s own workforce, the workforce in the value chain, affected communities, consumers and end users G: business conduct in generalCompliance teams will need to ensure that the reporting is accurate. One area to watch out for, she notes, is vagueness. A company may choose to provide overly vague information that could be misleading.Listen in to learn more about the directive and the risks involved.

View Details

By Adam TurteltaubThe No Surprises Act is a significant change to how healthcare coverage is handled and billed. In general, it eliminates balance billing in three typical areas: A patient is brought to an emergency room in an out of network hospital A patient is transported by air ambulance A patient is being cared for at an in-network hospital but, unbeknownst to him or her, a physician or service that is out of network provides care.To understand the Act more fully, we spoke with Brian Stimson, Partner, Arnall Golden Gregory, who will be leading the session The All Surprises Act:  Avoiding Compliance Pitfalls and Responding to Administrative Enforcement Actions under the Surprise Billing Laws at the 2024 HCCA Compliance Institute.As he explains, there is a two-tiered enforcement structure to the law, with both individual states and the federal government involved.Compliance teams looking to ensure their organizations are complying need to pay close attention to patient complaints. These can be a tip off to improper balance billing and a red flag of systemic issues. Be extra alert if a patient comes to them, and it can even be good to check social media for reports of wrongful billing.Listen in to learn more, and then join us in Nashville, April 14-17, for the HCCA Compliance Institute.

View Details

By Adam TurteltaubWhen it comes to risk assessments, the word “annual” comes up a lot. But, Kelly Alwin, Regional Compliance Officer North America for SAP America, believes that once a year may be more than a bit too long.To her, a risk assessment is more than a periodic assessment and an annual chore. It is critical to the program’s success and lends credibility and substance to the compliance program. She points out that from the Delaware Chancery Court to the US Department of Justice, the importance of a strong risk assessment is underscored.In this podcast she argues that, for the risk assessment to play the role it should, it can’t afford to sit on the shelf. It needs to be a dynamic document that both informs all the other elements of the program and evolves as risks evolve, whether due to a new go to market strategy, a merger or an entry into a new market.Bottom line: look at your risk assessment, she advises, not as a discrete activity but as a continuous analysis. Incorporate micro assessments, embrace continuous improvement, and, hopefully, enjoy a more effective compliance and ethics program as a result.

View Details

By Adam TurteltaubBehavioral health shares many of the same compliance challenges as the rest of healthcare, but it also has several of its own.To understand the risks, we sat down with Community Counseling Solutions’ Executive Director Kimberly Lindsay and Compliance & Privacy Officer Tim Timmons. They will be leading the session “Developing an Ethics and Compliance Program in Behavioral Health” at the HCCA 28th Annual Compliance Institute, which will be in Nashville, April 14-17 and also offered in a virtual format.In this podcast they identify several typical compliance challenges in the behavioral health setting: Managers and supervisors who are well intentioned but busy, not holding staff accountable and not reporting in a timely manner. Incidents after hours when a patient is in crisis. This is a very difficult situation.  The team is eager to help the patient get better, but with lots of adrenaline flowing in a difficult situation, they may find themselves sharing more information about the patient than they should. Sharing PHI improperly when working with community partners. Mishandling of subpoenas and court ordered requests for records which may not comport with 42 CFR. Coding and dual diagnosis treatment Treatment plans that are not updated before providing services Overly verbose documentationListen in as they outline these issues and ways to address them. Then, plan on joining us in Nashville for the 28th Annual Compliance Institute.

View Details

By Adam TurteltaubWhile Ericsson is best known for its mobile phones, the company’s reach in wireless is far greater. It is the creator of Bluetooth technology, owns patents on much of the critical IP that wireless systems depend on, and is active in more than 180 countries providing much of the hardware, and even cellphone towers, that enables all of us to talk, text, and surf the web wherever we are in the world.Jan Sprafke, Chief Compliance Officer at Ericsson, explains in this podcast that with that global reach – including operations in approximately 100 high risk countries – also comes a large network of suppliers. To manage the potential compliance challenges that go along with it, the company uses a risk-based approach to supplier managementThey assess the country risk, go to market approach and whether the supplier will be using subcontractors. Then they work closely with sourcing and other assurance functions on an ongoing basis.The company’s supplier code of conduct is shared with their vendors. But, it is just the start. There is also training provided, supplier days, meetings with them to discuss FCPA, AML, health and safety and other topics. All of these efforts and more help suppliers understand what Ericsson’s expectations are, not just in principle but also in practice.They even work with many of their contractors as they select their subcontractors.The goal is to create an end-to-end framework for managing third party compliance risk.Download the podcast (maybe even on your mobile device) to learn more.

View Details

By Adam TurteltaubJulie Janeway (LinkedIn), General Counsel and principal owner, Principled  Healthcare Consulting will be speaking about internal and parallel investigations at the 2024 HCCA Compliance Institute. In this podcast she slices off a bit of that expertise.A thorough investigation is needed, she advises whenever there is an issue that could require arbitration, a court case, administrative hearing, contractual dispute or reputational issues, whether by an employee, contractor or the organization itself. The same is true if there is a policy breach or alleged violation of the code of conduct.So how best to do it? Have both an investigation plan and a preplan which designates who will be responsible for the investigation depending on what the issue is. For example, a privacy officer would likely play the lead role in a HIPAA breach allegation.As for the plan itself, it should be thorough. The team executing it should include individuals with a wide range of skills and, she highly recommends it include an experienced investigations attorney.What should you avoid? Several things, she cites, including retaliation, making the plan as you go along, letting supervisors or managers interview subordinates and not having insurance for when investigations happen.The rules are largely the same with parallel investigations, which are required pursuant to statues that call for entities notified of an investigation by a governmental agency to conduct their own investigation. These absolutely must be done, or the organization may face sanctions. She highly recommends doing these investigation under attorney-client privilege.Listen in to learn more about what to do and what not to do in an investigation. Then, don’t miss her session at the 2024 Compliance Institute, March 18-20 in Nashville.

View Details

By Adam TurteltaubIn 1984 I went to my friend Chris’s wedding, and one of the other groomsmen, Drew Neisser (LinkedIn), his then boss, talked me into pursuing a career in advertising. Just a few months shy of 40 years later, I caught a video on LinkedIn of him with chief marketing officers discussing the struggles of managing remote workers. It didn’t matter that these were marketing people, the problems sounded just like we in compliance face.So, I asked Drew, who is the founder of CMO Huddles and the author of the book Renegade Marketing:  12 Steps to Building Unbeatable B2B Brands, to sit down and do a podcast on the topic.Drew points out that, despite workers being required to come into the office more often, there is still a cost to remote work. Churn is higher than before. Partners at law firms complain that their associates are years behind in their development, likely due to the inability to learn by osmosis.So what do we do? He recommends that we recognize the present reality and look to hire self-starters. People who need a great deal of hand holding will not work out in a world where their managers are miles, if not hundreds of miles, away.Second, make sure the team understands what the organization’s business is. Then, help them connect, intellectually and emotionally, with it. If they don’t, then it’s just another job to them.Incorporate virtual bonding activities, but also try to get the team together in person. That effort creates culture and connection.Looking outside your team, he recommends four tactics:Meet, ideally in person. Get to know your colleagues, and understand their business priorities. Focus on helping them solve their problems.Track all the people you want to meet and influence. Then, take active steps to connect with them and get to know them.Share something about yourself and encourage them to do the same. Get to know the person and stay in touch. For example, send them over articles you think they would find of interest based on what you learned about them.Join formal and informal work groups. If there is a team forming to tackle a problem, be a part of it. But also look to book groups and other less structured ways to connect.Throughout, he advises thinking of yourself as an impact player and a business leader.Finally, he advises understanding how people want to communicate these days, and meet them there. The era of relying solely on email are done, especially for the younger generation.Listen in for some very good insights for compliance officers from a career marketer.

View Details

By Adam TurteltaubSome people have a gift for invisibly attending a conference, and no one knows that they were even there. That’s great for a conference of spies, but most people at compliance conferences like to meet at least some of the other attendees.For many, though, connecting with strangers is difficult, whether they know no one or they are shy about going beyond their usual circle of contacts.So what do you do if you are one of them?To find out we spoke with Richard Bistrong (LinkedIn), newsletter author and CEO Of Frontline Antibribery, who will be moderating a general session at the 2024 SCCE European Compliance & Ethics Institute in Amsterdam.If you spot someone standing alone and looking a bit lost, he recommends you think like a host and invite them to join you. Even if you’re already talking with friends, he advises being a croissant and not a bagel: be sure there is an opening for others. Make the effort to catch them up with the conversation – “we were just discussing helplines”—and ask them to share their thoughts.If you hesitate to join conversations because you don’t feel you are good at small talk, think of a few questions in advance to use as ice breakers. They don’t have to be traditional compliance-related questions. You could ask people about what excited them the most in the last year. Richard often uses Vertellis cards to start or help conversations.For those at the conference with a friend or colleague, use the other person as your wingman or wingwoman. Tell them who you are interested in meeting and have them serve as a second set of eyes and ears.Also, don’t forget about the SCCE & HCCA staff as a source of connection. See if they know someone it would be good for you to talk with.Listen in to learn more, including how to follow up properly after the conference is over.Then, be sure to say hello to Richard (and offer him a croissant) in Amsterdam at the 2024 SCCE European Compliance & Ethics Institute, March 18-20.

View Details

By Adam TurteltaubCompliance programs have come far over the last few decades, but there is still more that they could do to elevate their performance. In this podcast, Alison Taylor, Clinical Associate Professor at NYU Stern School of Business and author of the book Higher Ground shares some intriguing and provocative ideas for improvement.She is a strong believer in what she calls “firm foundations”. These foundations avoid having too many rules which can, inadvertently, have a negative impact, causing employees to abdicate responsibility for their action and grow overly reliant on following rules. Instead, she argues for simplifying and being attuned to human behavior and the role of incentives.Be wary too, she advises, of mixed messages and potentially pernicious effects when it appears, whether true or not, that the rules for the rank and file do not apply to leadership. It degrades trust and the culture.To get more employees to speak up when they see wrongdoing, she advises investing the time in understanding why they don’t raise their hands more.When it comes to measuring the impact of the compliance program, she is a strong proponent of measuring the ethical culture. Do employees feel safe speaking up?  Whom do they speak to when there is a problem? Do they believe the whistleblower line is truly anonymous? Is leadership looking out for them?The answers to these questions, and how they change over time, can illuminate how well the program is working.Listen in to gain more insights, including how to build a common ethical foundation and the importance of adequate authority for the compliance and ethics program.

View Details

By Adam TurteltaubClara Becerra Campos, Senior Compliance Analyst-Europe for TD SYNNEX, and Dr. Tobias Kruis, Head of Corporate Compliance, Giesecke+Devrient, will be addressing the new EU whistleblowing requirements at the 2024 SCCE European Compliance & Ethics Institute, which takes place in Amsterdam March 18-20.In this podcast, they delve into the challenges posed by the directive, which significantly expands the number of EU-based and non-EU-based companies that must comply.The directive not only provides protections for whistleblowers, they explain. It also establishes procedures and deadlines for handling reports. As significantly, it leaves the door open to variations among EU member states, which complicates the picture considerably.So what should you do? If your organization does not have a whistleblower line already in place they recommend you: Implement an internal reporting channel Be sure it’s aligned with legal and data privacy Consider who will manage the system and conduct the investigations Ensure confidentiality Communicate with your workforceFor those with a helpline already they recommend starting with a gap analysis to determine if your existing efforts are meeting the new requirements.Listen in to learn more, then join them in Amsterdam at the 2024 SCCE European Compliance & Ethics Institute.

View Details

By Adam TurteltaubAt the 2024 SCCE European Compliance & Ethics Institute, Segev Shani, Chief Compliance & Regulatory Officer at Neopharm Group will be leading the session “Corporate Use of Third-Party Artificial Intelligence (AI) Tools.”In this podcast he shares that a great deal of risk comes from the headlong pursuit of AI technology. Businesses believe that if they are not using Ai that they will be left behind, but the adoption rate is not being matched with a complete understanding of what AI is.To manage this issue, he recommends creating an AI governance model that balances the risks and rewards. It can help employees and managers understand the risks, including inaccuracy, bias and both misuse and improper use of intellectual property. And, of course, there can be substantial privacy risks as well.Listen in as he discusses proper governance, the need for training and the importance of integrating AI governance into business processes.Then plan on joining us in Amsterdam, 18-20 March, at the 2024 SCCE European Compliance & Ethics Institute.

View Details

By Adam TurteltaubA good employee survey on compliance and ethics can yield a wealth of data on how your program is and isn’t working, where the risks are, and how to move forward. The challenge is getting the survey right and getting employees to respond.Klaus Moosmayer, Member of the Executive Committee and Chief Ethics, Risk and Compliance Officer at Novartis, shares in this podcast that the compliance team has just completed the second round of their survey. The goal was to get first-hand data from as many employees globally as they could about any unethical behavior they perceive around them and how it is acted on.The survey was developed with substantial help from behavioral scientists, who created a questionnaire that captured where the company is now but also enabled them to dig deeper into key issues. For example, in the first round of the survey the Novartis team discovered that approximately 80% of employees go first to their leaders and managers when seeing unethical behavior. In the second survey they focused on what the leaders are doing with those reports.To encourage responses from employees, they invested the time in preparing the workforce and setting the context that the survey is a part of a broader effort to strengthen company culture.The messaging behind the survey was both local and global, with company presidents underscoring the importance of the study.After the first survey was completed, they made the effort to showcase how the data was used and what would be changing at Novartis as a result. That helped earn higher participation rates for the second survey.How does the data get used? The aggregated data helps inform leadership and enabled conversations as high as the board level.The data is also incorporated into the company’s integrated digital ethics, risk and compliance platform.Country managers are shown their data and told how it compared to other regions, which, of course, indicates how well they are or aren’t doing versus their peers. Local leaders are then encouraged to use the data to have roundtables, town halls and other meetings to understand why their scores are what they are.Listen in to learn what made the Novartis survey so successful and how to improve your own.

View Details

By Adam TurteltaubWhen it comes to AI, there is little agreement. Some see great potential, while others see great nightmares. Some see opportunities, and many see nothing but risks. In the EU, though, there is agreement on one thing, a new EU AI Law. In December 2023 the EU Parliament and Council agreed to  a bill “…to ensure AI in Europe is safe, respects fundamental rights and democracy, while businesses can thrive and expand.”Longtime compliance professional Letitia Adu-Ampoma (LinkedIn) explains that while the law won’t fully come into force for two years or more, it’s time for compliance teams to start paying attention and preparing.The act is a part of the EU digital strategy, which is very focused on human-centric legislation. Its goal is to keep positive the impact of AI on people and society.The approach it takes is risk-based, categorizing AI systems based on the level of risk: unacceptable (and prohibited), high risk, minimal risk and no risk. The act is very specific in how it defines which AI systems fall into each category. The unacceptable risk category, for example, includes social credit scoring, emotional recognition and behavioral manipulation.Creators and users of high risk AI will be required to register the system in a public record. They will also need to conduct an impact assessment and be transparent.Transparency will also be critical for generative AI. Providers will need to disclose the content generated and ensure that the models are not designed to create illegal content. There will also need to be governance in place to protect against copyright violations.So what should compliance teams do now? Letitia recommends reading the guidance and to start preparing the business unit for what is to come.Listening to the podcast would be good, too.NOTE: This podcast was recorded in January 2024. The final version of the EU AI Act is yet to be released - a final EU parliament debate on the text will take place before its release. In the meantime, some 'unofficial' pre-final versions of the text have been leaked online in advance of this debate. The final EU definition of AI and key timescales for enforcement mentioned in the podcast are based on proposals made public. Listeners should look out for the final position which will be detailed in the EU AI Act when it is officially published in the next few weeks.

View Details

By Adam TurteltaubHaving a compliance champions or ambassadors program can be a great boon for the compliance program, if you keep the champions engaged. Unfortunately, that doesn’t always happen. If not managed properly your champions may end up sleep walking through the job.In this podcast, Matt Silverman, author of the book The Champions Network and Global Trade Director and Senior Counsel at Viavi lays out several strategies for maintaining the involvement and commitment of your champions network.To ensure engagement, he recommends remembering that the people who decided to be champions did so for a reason. It may be for a wage stipend or for altruistic reasons.  Tapping into that motivation is essential.On an ongoing basis it’s important that they see the impact of their work on the organization and their own career. That means sharing outcomes, as best you can, and providing them with access to development opportunities. These could be specific to deepening compliance expertise or as broad as developing business and soft skills. Whichever you choose, it is a way for them to see what’s in it for them.Give them an opportunity, as well, to be recognized for their work, whether that’s an official recognition by the CEO or an opportunity to interact with leadership. Remember, appreciation can be a powerful reward.And, of course, make sure there is actual work that they need to do as a part of being a champion. Having the title alone is not enough.Listen in to more about how to create engaged compliance champions.

View Details

By Adam TurteltaubMergers and acquisitions create stress, opportunity and risk both for the organization and the compliance team. In this podcast, Sergio Leal, who until recently was head of M&A compliance at Ericsson along with Jan Sprafke, the company’s chief compliance officer, share their advice for compliance professionals in the midst of a transaction.They stress that the compliance team needs to be involved during the entire lifecycle, from target identification to due diligence to post-acquisition integration. This will help the organization avoid unanticipated liabilities and risks.To ensure success the compliance team needs to be embedded in the M&A team. Meet with the stakeholders regularly to ensure you are aligned with their processes. When you do, remember that compliance is just one piece of a very complex puzzle.Be prepared to move quickly. The DOJ amnesty program for issues discovered in an acquisition has a rapidly ticking clock.At the start of an acquisition or merger, they recommend focusing on three areas: The ultimate beneficial owner The operations of the business The already existing compliance program, if any, and internal controlsBe especially vigilant if the acquired entity had some government ownership or government contracts. And, be very diligent if there is not a compliance program already in place.Listen in to learn more about how to be an integral part of mitigating the risks of mergers and acquisitions.

View Details

By Adam TurteltaubTo quote CMS, “The Open Payments program is a national disclosure program that promotes a more transparent and accountable health care system. Open Payments houses a publicly accessible database of payments that reporting entities, including drug and medical device companies, make to covered recipients like physicians.”For this transparency to work, though, it’s important for the data to actually be used. Kelly Cooper (LinkedIn), Compliance Specialist at UF Health Shands Compliance Services, reports that too often it isn’t. There is a downward trend of providers reviewing the data collected, she reports, due to lack of awareness of the program and why it matters.That needs to change. Physicians and the hospitals that employ them are now required to post a notice for patients about the Open Payment system and how to access it. This will likely lead to more questions from patients and the need for providers to monitor the data more closely.So what should compliance teams do? She recommends looking at training, awareness and policies. In addition, be sure that the profiles of covered individuals are correct and up to date.And, be prepared to navigate the dispute process. It can be a long one, but there are shortcuts.Finally, she urges compliance teams to use the data to get a better handle on staffing, credentialing, what the payment trends are and any red flags.Listen in to learn more about what the Open Payments program is and how your compliance team should be working with it.

View Details

By Adam TurteltaubThe 2024 CMS Medicare Physician Fee Schedule extends no less than ten different pandemic flexibilities related to telehealth. In this podcast, Randi Seigel, partner and Jared Augenstein, managing director, at Manatt take us through all of them, including in-person visit requirements, audio-only services, physician supervision and opioid treatment.They also address: Changes in the structure of the telehealth services list Changes to payment by place of services Remote psychological and therapeutic monitoring Enrollment and revocation A new opportunity for payments for social needs of Medicare beneficiariesListen in to learn more about what’s new, what’s the same, and what will sunset at the end of 2024.

View Details

By Adam TurteltaubEffective investigative interviews are both important and sensitive. To get some pointers about how to conduct them properly, we turn in this podcast to Wendy Evans, Senior Corporate Ethics Investigator at Lockheed Martin. Wendy is also an instructor for the SCCE Fundamentals of Compliance Investigations workshops.She recommends starting by doing your homework. Before you talk with anyone, whether a possible witness or the subject, get all the information you can from the reporter. Then, review it to see if it includes the what, where, when, why and who. If you don’t have all that information, take the time to find it since it can identify what the potential motivation behind the incident was.With that information in hand, check your case management system to see if any of the parties were involved in previous reports. Follow that by notifying HR and the subject’s manager that you will be conducting an interview. They may have important insight.Think through what other evidence you may need for the investigation, including expense and audit reports.If you are going to conduct the interview remotely, she offers four pieces of advice: Be sure to schedule it appropriately. Sending a meeting request on a Friday for a Monday meeting can create an entire weekend of unnecessary stress for the individual. Mark the meeting request as private so you, and they, don’t have to worry about others seeing it. Ensure that the person has video and a private place to talk. Always include your phone number in case a technology glitch gets in the way.At the time of the interview, don’t just jump into the questions. Take time to build some rapport. This will help reduce the stress level.Then, when you start asking questions, begin with broad ones -- “tell me about your work” or “what were your last three business trips?” --  that aren’t simple yes or no. Then, over time, move in to more narrow, specific questions.When it’s time to get to the hard questions, help the subject prepare themselves psychology. Preface then by saying something along the lines of, “I have to ask you a tough question.”When concluding the interview, ask: Is there anything else I should know but didn’t ask you? That can prompt the sharing of additional information.Finally, be sure to thank them for their time and cooperation. Be sure to also reiterate what the investigation process is and what they can expect next.Listen in to learn more, and, maybe, join her at an upcoming Fundamentals of Compliance Investigations workshop.

View Details

By Adam TurteltaubMatt Kelly (LinkedIn), Editor and CEO at Radical Compliance is a close watcher of all things compliance, and in this podcast he shares his take on both the top stories of 2023 and what he sees in the cards for 2024.FCPAOn the Foreign Corrupt Practices Act front, he noted a change in enforcement. While the volume of resolutions declined on the DOJ side, the SEC has remained very active.Perhaps most notably, the Albermarle case had an interesting twist. The way the company did business was changed dramatically as a part of the settlement, he reports, with a restructuring of its overseas sales and the end of the use of third parties. He speculates this may be the start of a new trend in which monetary penalties are accompanied by required changes to the way companies do business.Also of note in FCPA was the announcement by Lisa Monaco at the SCCE Compliance & Ethics Institute of a leniency policy in mergers and acquisitions. Because of the relatively short timeline for finding and disclosing problems, there is a strong incentive for organizations to involve the compliance team early and deeply in these transactions.SEC Cybersecurity RulesThe July SEC rules on disclosures of cyber incidents require firms to disclose an incident within four days. Companies will need to describe the nature, timing and material consequences. That will increase the importance of thorough and prompt cyber materiality assessments, as well as both quantitative and qualitative impacts.Greenhouse Gas DisclosuresThe SEC’s proposed rule on greenhouse gas disclosures is now the longest and most commented rule in history. It also has not been finalized while, in the meantime, both California and Europe have passed their own laws.The rule is likely to be very complex and impose a significant burden on companies.HealthcareThe biggest news he saw in 2023 was the new General Compliance Program Guidance issued by the Office of Inspector General at HHS. The document makes it clear that it expects a fully independent compliance program. As the document states:The compliance officer should: report either to the CEO with direct and independent access to the board or to the board directly; have sufficient stature within the entity to interact as an equal of other senior leaders of the entity; demonstrate unimpeachable integrity, good judgment, assertiveness, an approachable demeanor, and the ability to elicit the respect and trust of entity employees; and have sufficient funding, resources, and staff to operate a compliance program capable of identifying, preventing, mitigating, and remediating the entity’s compliance risks.The FutureLooking to the future he asks if others will be as supportive as the OIG at HHS.He also points to other things to watch such as the Foreign Extortion Prevention Act, the PCAOB’s extremely controversial NOCLAR proposal and SEC v. Govil, which could eliminate disgorgement in many cases.Listen in to learn more about what has and may happen in the world of compliance.

View Details

By Adam TurteltaubWe all want the compliance team to be approachable. It would be ideal if, when people thought of compliance, they had positive, maybe even warm and fuzzy, associations in their mind.But, how do we get there? For BroadPath, a friendly blue koala was the answer.In this podcast, Jaime Watkins, the compliance officer there, explains that she drew inspiration from the Basic Compliance & Ethics Academy and an exercise that called for creating a compliance mascot. Back at the office she created a contest among employees to create a mascot as a part of the company’s celebration of their compliance and ethics week. A winner was selected, and, with the help of the marketing team, the blue koala was born.Since then, the furry critter has been a regular part of their training, newsletter and is used everywhere that they can, even sometimes straying to the activities of other groups in the company.The impact of the koala has been enormous. People enjoy seeing variations of how it is dressed up for holidays and it even plays a role in regular compliance trivia contests.Listen in to learn more about how a mascot could help your compliance efforts.

View Details

By Adam TurteltaubDecades ago, while at a bit of a career crossroads, I was thinking of making a dramatic change and moving halfway around the world. I was talking it through with a friend who said that one day he asked himself whether he wanted to have a successful career or an interesting one. He realized that interesting was more important to him. That decision led him from Missouri to New York to Hong Kong, Singapore and Thailand, where he ended up enjoying great success.Ricardo Weffer, Group Ethics and Compliance Head of Al Dahra, has had a similar career journey that ranged from Venezuela to Dubai with countless points in between.In this podcast he shares his almost two decades of work in compliance and anticorruption in Latin America, the Middle East, Sub-Saharan Africa, Central Europe and Asia. A lawyer by training, he has worked in energy, banking, tobacco, logistics and agriculture.Despite all this variety, both in geography and industry, he shares that there are professional commonalities wherever he has gone. These include great compliance and business leaders who stand for what is right and are willing to fight for it. He has also found, happily, that, no matter what the industry, companies are mostly made up of real, hard-working, well-intentioned people driven by values who want to do the right thing.What wisdom does he have for those thinking of having a global career?  He offers three pieces of advice: Be adventurous and open to new experiences. Be willing to be taught. Enjoy it. Working and living abroad can be tough, but the rewards are worth it.Listen in to learn more, including some inspiring words about the impact of compliance professionals.

View Details

By Adam TurteltaubCompliance professionals can face a lot of resistance in the course of their work: leaders who don’t have the time, budget limits, managerial indifference, and even outright hostility. But, sometimes the impediments are inside us.In this podcast, Kristy Grant-Hart, CEO of Spark Compliance Consulting and author of the new book Your Year as a Wildly Effective Compliance Officer, points out that sometimes we get in our own way. It’s just easier for us to see what the external blocks are than it is to see those we create for ourselves.Overcome them, she argues by trusting your own value. Ask for what you want, and don’t trust that others will see the need. And, when you do ask, be sure to make clear what value the compliance program provides.She also cautions against falling into Imposter Syndrome and feeling as if you don’t belong in the room. Sitting there quietly doesn’t help, in fact it hurts by giving others the impression that you and the compliance team are not adding value. Instead, speak up at every meeting so that you can be perceived as a contributor.On the personal level, set goals for yourself. Pick an area to deepen your expertise and another to grow personally, such as in speaking publicly or improving your productivity. Also, look to growing your network. Plan on attending in-person meetings and then follow up with the people you meet there. Don’t just make them another entry in your Outlook contact list.When it comes to those external barriers, she advises not taking push back personally because most often it isn’t personal. People have other commitments.In fact, look at why they are pushing back and evaluate if the criticism is fair. If it is, then adjust your efforts. If it isn’t, let it go. Not everyone is going to get along with you.Finally, she discusses how to ensure you don’t let work take over your life. Reserve time for family, friends and your passions, and keep those commitments. When it comes to after-hours emails and texts, don’t answer them if you don’t have to, or if you do, send a delayed respond. That way people learn you won’t be responding 24/7/365.Be considerate, too. If you think of something in the evening and want to get a note out that isn’t urgent, be sure to let the recipient know they don’t need to respond right away.Listen in to learn more about how to clear your internal path and become your own best ally in compliance.

View Details

By Adam TurteltaubWe are starting a new year of Compliance Perspectives podcasts by going back to basics with an episode designed for those who are charged with starting a compliance program. While the conversation is directed to this audience, there are some good reminders even for established programs.Providing guidance are Pam Cleveland, Compliance Officer – Medicare Advantage for UCLA Health FPG and Megan Grifa, Senior Director, Compliance at Sidecar Health.So, if you are charged with launching a program, where do you begin? They advise starting by taking the time to develop a work plan that outlines your compliance program elements. Look to see what the regulatory requirements are for the business you are in and make a catalog of them. That, in turn, will help you set the objectives of your program.Next, take the time to tailor those requirements to the unique aspects of your organization. To do so, first spend time with operations to understand their level of knowledge, processes, resources and documentation. That will help you prioritize what needs to be done.Take the time also to gain the support of leadership. They may need education in everything from what a compliance program is to the specific requirements of your situation. One very effective technique is bringing them examples of non-compliance in your industry and the consequences of it.On an ongoing basis, follow the seven elements of a compliance program and make sure that you prepare your colleagues for the fact that changes happen. Law and regulations evolve, and the compliance program must do the same. It will help things go a bit smoother when you have to institute a new direction.Listen in to learn more about the essential steps for starting a compliance program.

View Details

By Adam TurteltaubWhen compliance professionals discuss AI most of the conversation tends to focus on the risk.  Frank Orlowski (LinkedIn), Founder and President of Ation Advisory Group, though, is far from all gloom and doom on the topic. In fact, he believes AI can be an asset to compliance programs.AI, he explains, can be of great value for compliance any place where there are large amounts of transactions that need to be monitored and checked. Two notable examples are travel & entertainment and accounts payable/vendors. AI is very useful for identifying outlier transactions that could be a sign of trouble.In manufacturing, it can be very helpful in monitoring materials being used. AI can also be helpful, he believes, in ESG efforts.But, there are limits. AI is not ready for handling contracts, he argues. It is also chronically deficient when it comes to addressing the gray areas of ethics and fairness. There it’s important for compliance teams to work with the business unit closely to ensure decisions are adequately documented and AI does not make decisions that would be regrettable from an ethics perspective.Listen in to learn more about how AI could help your compliance efforts.

View Details

By Adam TurteltaubThe topic of conflicts of interest (COIs), especially in healthcare, is a very broad one. It can encompass professional activities, board membership, purchasing, procurement and more. But it is the financial conflicts, especially for those that conduct research, that can be most problematic.To help unpack the topic we are joined in this podcast by Will Crawford (LinkedIn), an associate in the DC office of Hogan Lovells. He explains that, in the case of research, a COI occurs whenever the interest of the investigator, their spouse or children can affect the design, conduct, or reporting of institutional research. And, of course, there is a potential conflict when activities like consulting and speaking can affect primary employment areas.Federal regulations have expanded greatly in this area, with the Public Health Service now being joined by the US Department of Energy and even NASA with regulations of their own. Compliance teams need to monitor the changing direction from all three.What else should compliance teams be doing? First, ensure the training is adequate and reflects the changing regulations. That includes helping others understand that the changing regulations are a necessary reflection of evolving risk. Second, ensure that the compliance team, itself, understands the current rules; there is much confusion out there.Other things to consider or embrace: Centralizing the process for managing COIs Requiring more disclosures and independent review boards Planning for greater transparency Developing policing and monitoring systemsFinally, be mindful of joint ventures. They can create great opportunity, but they also carry substantial risk.

View Details

By Adam TurteltaubRecord retention and information governance have grown exponentially more complex as the number of laws have proliferated and the amount of data housed has exploded. This has vastly complicated the question of what data to hold onto and for how long.Mark Diamond, CEO of Contoural, points out that sometimes there are even competing and conflicting compliance regimes. For the most part, the rules specify a minimum number of years that information must be retained. However, organizations can typically retain records longer if there is a compelling and documented business need. Still, the temptation to just hold onto the data must be resisted.In this podcast he outlines the importance of getting a good handle on what data the organization has, categorizing it appropriately, determining how long it will be retained, and how it will be destroyed.Typically, this is an exercise involving multiple disciplines, including compliance, legal, IT, security, privacy and the business unit. A committee is likely the best way to manage the challenge, and having a compliance person in the lead position can be very useful.Listen in to better understand how the information in your organization can be governed more effectively, who to involve, how to structure the effort, and the important difference between information governance and data governance.

View Details

By Adam TurteltaubRonnie Feldman (LinkedIn), CEO, Founder and Creative Director of Learnings & Entertainment, thinks that compliance teams play too much defense and not enough offense.What does that mean?  In this podcast he explains that offense is the proactive preventative measures designed to prevent problems. Defense is reactive and made up of investigating allegations and cleaning up issues. To his experience, the time and money are more focused on defense than offense.So what should we do? He recommends realigning efforts, starting with looking at the key influences of behavior: the social environment and the influence of leadership. That includes changing the perception of compliance and turning it into a more positive one. One specific step he advocates is making the training more relevant and enjoyable to take.On the leadership level, he advocates for making them a larger part of the ethics team by providing them with the tools they need to address ethics issues. This could include videos to share and simple learning exercises they could take their teams through.All of these efforts can promote an environment of psychological safety and lay the groundwork for a compliance program that works and delivers measurable results.Listen in to learn more about how your program can play more offense.

View Details

By Adam TurteltaubOn February 22, 2022 the European Commission adopted a proposal for a directive on corporate sustainability due diligence.  In this podcast, George Porter, Knowledge and Training Manager at Ground Truth Intelligence reports that the directive, which is still being negotiated, is both a continuation of past measures and something new. It is designed to unify a great deal of previous regulations and create an ESG framework for both EU-based companies and those doing business in the EU.The directive covers three key areas: environmental risk, social goals such as modern slavery and child labor, and governance.The governance portion, importantly, addresses the duty of care and the need to conduct due diligence. It also significantly expands the stakes for organizations. Due diligence of the supply chain continues but organizations will now be responsible not just for how they sourced materials, but also how their products are disposed of.To back it all up there will be substantial potential penalties, including civil liability and fines up to 5% of global turnover.So what should organizations expect to do differently or better from a compliance perspective? He recommends preparing for a greatly enhanced auditing and monitoring program. Action plans will be needed for suppliers who need to improve their efforts. On a continuous basis there will be a need to check that these plans are being followed and attestations are not just tick boxes.Listen in to learn more about how this directive will likely lead to substantial changes in the ways in which organizations do business and what compliance teams need to start preparing for.

View Details

By Adam TurteltaubWhile the pandemic seems, at least for now, to be receding into our past, many of the changes from it have not, including a large percentage of the workforce that works remotely. While in some ways we have gotten used to this new normal, Lori Tansey Martens (LinkedIn), President, International Business Ethics Institute warns that there remains cause for concern. Specifically, the prevalence of high number of remote works has been and continues to negatively impact corporate culture.Culture is made up of the shared values and beliefs, norms, values, mission and purpose, and in many ways it differentiates one organization from another. Recent research shows that the common fabric binding people together into one culture is fraying. Survey data she shares shows that employee feelings of alignment has decreased substantially, and while those declines have leveled off among in-office and hybrid employees, they have not among remote workers.Remote workers also have the highest turnover rate and intent to change jobs, which suggests that they view their work as more transactional and are less committed.That can have a huge impact on ethics and compliance. Research suggests that employees who feel less loyal and committed are less likely to take into consideration reputational risk and long-term damage to the organization. Add to that data suggesting they are less likely to speak up, and it’s a dangerous prescription.So what should organizations do? For one, strive to connect people more fully. When workers are in the office together it’s okay to bring in remote workers via Zoom, but be sure that the people in the room are not just staring at their own individual laptops. You don’t want to exacerbate the issue by making in office people wonder why they should bother, given that they are still on Zoom.Look to do more in person rather than virtual training, people are already staring at their computers enough.Managers also need to be trained on how to manage and build teams with hybrid and remote workers. As she notes, we have totally upended the way we do business without giving them any real training.When bringing on new remote employees seek to make them feel connected. Send them a package with items reflecting the local flavor of the office and notes from their new colleagues. Make a commitment to bring them into the office occasionally.  You can’t immerse them fully in the culture without doing so.Finally, track separately in-office, hybrid and remote workers on training, helpline calls and other metrics to make sure that the culture is present throughout your workforce, not just the in-house one.Listen in for more.

View Details

By Adam TurteltaubWhile most eyes have focused on the US Department of Justice’s document Evaluation of Corporate Compliance Programs when looking for guidance, it’s not the only DOJ source out there.Josh Drew (LinkedIn), Member, Miller & Chevalier explains that it would be wise to also look to Attachment C. What is it? It’s a document typically attached to Foreign Corrupt Practices Act (FCPA) resolutions. It specifies what the defendant company will need to do to establish and maintain an effective corporate compliance program. As a result, it, like the Evaluation document, provides very clear guidance as to what the DOJ’s thinking is when it comes to compliance.In August and September 2023 there were several changes to Attachment C. For one, it expanded the call for support from senior management down to include midlevel management as well. It specifically points to the importance of their tone and conduct:  “The Company will ensure that mid-level management throughout its organization reinforce leadership’s commitment to compliance policies and principles and encourage employees to abide by them.”In the realm of training, it calls for metrics to assess the effectiveness of the training, not just that it was given. That’s a theme consistent with other direction from the DOJ.Not surprising for an FCPA-related document, it also calls for documenting the business justification for engaging a third party and ensuring that contract terms are specific. Third parties should also be tracked after the initial engagement, which means ongoing due diligence.And, here, too, as elsewhere, the Department of Justice reinforces the importance of both incentives for good behavior and disincentives for bad.Listen in and then be sure to spend some time reading Attachment C.

View Details

By Adam TurteltaubAt this point anyone in healthcare who doesn’t have a plan for managing HIPAA compliance risks is behind the eight ball and times. But, for those who do have a program in place, the question is: does it currently reflect your risk profile?Nancy Roht (LinkedIn), Managing Principal at Compliance Pro Consulting points out in this podcast that just because the HIPAA regulations don’t specify how often a HIPAA risk assessment should be done it’s best to do so annually, and perhaps even more frequently if something significant happens. Changes in leadership, organizational structure, goals, quality and major vendors can all call for a fundamental reexamination of your strategy.When conducting the assessment, don’t mistake it for a gap analysis. Make it a true assessment of risk and put together a work plan to address any deficiencies.When conducting the assessment, she recommends interviewing both leadership and staff to get a comprehensive picture. Take an inventory of the PHI you have, potential threats, vulnerabilities and security measures. Then, assign risk levels, prioritize and document your thinking. Years from now no one will remember what decisions were made and why, without the documentation.Be sure to look externally at your business associates, particularly those with evergreen agreements. They may have run out of date.Listen in to learn more about how to make your HIPAA risk assessment stronger.

View Details

By Adam TurteltaubSteve Forman (LinkedIn), Senior Vice President at Strategic Management Services, had an eye-opening experience years ago when interviewing for the job of Vice President of Audit and Compliance for New York Presbyterian Hospital. The chair of the board’s audit and compliance committee told him that his main role was not to find problems or weaknesses but to validate through the discipline of the audit processes what management suspected were problematic areas in terms of audit and coverage of risk areas.That insight had several implications. First, it underscored that operational managers will always know more about their risk areas than auditors will, which means they are in the best position to identify problems and weaknesses. Second, it was a good reminder that there are never going to be enough auditors to even address the high risk areas. Once again, we are dependent on managers.So what does that mean? It means that monitoring should help drive the audit plan and strategy. In addition, managers need to be listened to on a regular basis, and they should be charged with monitoring.In addition, he observes that the risk assessment must also not be treated as a static document. Risks can go up and down during the course of the year, and the risk mitigation strategy needs to be adjusted with it.Listen in to learn more about how to improve your monitoring and auditing, as well as the role of management in it.

View Details

By Adam TurteltaubEconomic espionage sounds more like the stuff of a spy thriller than a day-to-day concern for business. Not so, as it turns out. To learn more we sat down with the FBI’s Counterintelligence Division Unit Chief Matthew Charles and Cyber Division Supervisory Special Agent Michelle Liu.Economic espionage generally refers to stealing trade secrets for the benefit of an overseas competitor, often one aligned with a foreign government. An employee at your organization working on a sensitive project may be leveraged, frequently with the lure of cash and other payments.Typical targets include technology with potential military use and, of late, pharmaceuticals.To counter this threat, the FBI Cyber Division maintains partnerships with many private sector companies to identify nefarious conduct on their networks. Meantime the Counterintelligence Division looks upstream for actors coming into the US seeking access to US technology.So what should companies do? First, protect yourself. Encryption can be helpful along with limiting access to sensitive information only to key people. Make sure, too, to track who in your firm is accessing trade secrets.Also, be sensitive to unusual employee behaviors or changes in affluence levels. An employee suddenly downloading large files at night, emailing their personal email address sensitive information or whose debt problems have inexplicably disappeared could be engaged in economic espionage.  Just don’t jump to any conclusions.  There could be legitimate reasons for these actions.Second, the FBI advises reaching out to them when an incident occurs. The FBI can’t investigate without ongoing collaboration of the victim organization. They also advise that it is never too early to call them in, and if you do not want them there, they will pull out.Finally, take the time to leverage government resources. Be sure to familiarize yourself with the US Department of Justice’s Criminal Division’s Computer Crime and intellectual Property Section (CCIPS) website.You will find there information on reporting computer, internet-related or intellectual property crime.And, of course, listen in to the podcast to learn more about the risks of economic espionage and what you can do to mitigate it.

View Details

By Adam TurteltaubHow do you understand “neurodiversity” or “neurodivergence”? It starts with the recognition that no two human are exactly alike and not two brains function exactly the same way. It then goes on to recognize that for people with ADHD, autisms, dyslexia, sensory integration and executive function issues, those differences can be substantial.Estimates are that about 20% of the workforce has some sort of neurodivergence.In this podcast, Jason Meyer (LinkedIn), President of LeadGood Education, explains that compliance teams need to recognize neurodivergence when communicating with the workforce. This means looking for more structured communications that make it easy for learners to see things step by step.Another technique to pursue is reducing cognitive loads and demands on working memory. A test at the end of a two-hour course may be too much for many people to be able to manage successfully.Some other tips include having visual cues to accompany text and offering an audio option. That way if someone is limited in one sense, they can rely on another.If you have someone neurodivergent on your team, start with watching your assumptions. If a person is person not making eye contact or responding to questions haltingly, don't assume they don't care. They may be neurodivergent.Above all, be empathetic and listen, and park your preconceived notions at the door.Listen in to learn more about the challenges and opportunities with neurodiversity.

View Details

By Adam TurteltaubCurrently there is a patchwork of anticorruption laws across the EU. What has been lacking, though, is a EU-wide approach. That is likely to change soon, reports Vera Cherepanova, founding partner of Studio Etica.Change is afoot.  In May 2023 the EU issued a new proposal to combat corruption, including a new Directive of the European Parliament and the Council on combatting corruption by criminal law.The new directive, she explains, makes it clear that actions by senior executives can have significant consequences both for the individuals involved and their organizations. Companies could face fines of no less than 5% of worldwide turnover.Notably, like the US Foreign Corrupt Practices Act, the new EU directive has extraterritorial reach, which raises the prospect of more enforcement actions.The directive also includes incentives for compliance programs consistent with what is found in law elsewhere: “…where legal persons have implemented effective internal controls, ethics, and compliance programmes, it should be possible to consider these actions as a mitigating circumstance.”Meantime, across the English Channel, the UK Parliament is considering a new Economic Crime and Corporate Transparency Bill, which could be represent a hugely significant change in the enforcement landscape. It includes a crime of failure to prevent fraud. In addition, corporations can be held liable for acts of senior managers.Listen in to learn more about the upcoming changes and what they may mean for your compliance program.

View Details

By Adam TurteltaubKristine Coy-Foster (LinkedIn), Senior Manager, Compliance & Employee Engagement at Vulcan, had a challenge many in compliance face: tracking all her to-dos, and then, once a to-do turned to done, tracking the accomplishment. It was important for her to be able to capture the challenges she faced, new ideas tested and processes developed.Trying to keep it all straight in Outlook or Excel spreadsheets wasn’t enough. To solve the problem she invested the time to learn Smartsheet, a platform that primarily is for managing projects and automating processes. In it, she created workstreams, alerts, dashboards and more.She also created categories for each of the functional areas she oversees and organized her to-dos accordingly.The solution has worked well for her, but, she cautions, it does take a strong commitment to keeping everything up to date.Listen in to learn more about how to put this tool to work for you, or, maybe, customize the tool you are already using to track your own compliance team’s progress.

View Details

By Adam TurteltaubSince the 1930s the United State has had import bans on forced and convict labor. But, the rules were tightened, explains Evelyn Suarez, Principal, The Suarez Firm and Thad McBride, Partner, Bass, Berry & Sims PLC, in 2021. That is when Congress passed the Uyghur Forced Labor Prevention Act (UFLPA). The act has a rebuttable presumption that goods made in whole or part with labor from the Xinjian region in China is made with forced labor.If US customs suspects that goods are made in this region, they can stop them until the importer can provide the necessary assurances. In addition, goods made in other regions are also being stopped because their supply chain includes labor from Xinjian.So, what should compliance teams do to help the business unit navigate the issue? For one, it’s key to go beyond the first line supplier, as is typical, and start looking deeply into the supply chain and start researching your supplier’s suppliers.Suppliers should be asked what connections they have to China. Mapping questionnaires should be developed and issued. Training needs to be given, and third-party vetting vendors will likely be needed.In addition, develop interdisciplinary teams to create a plan for responding should a shipment be held. Even before that, start developing a good relationship with customs and take advantage of their expertise.As is the case with so much else in compliance, keep good records that you can present to customs, maybe even on a proactive basis.Finally, keep your eyes open for customs ruling and court cases that may provide guidance on what to expect next.

View Details

By Adam TurteltaubWe spend a lot of time in compliance discussing how to encourage employees to come forward and report any wrongdoing they see around them. Considerably less time, though, is spent on how to handle employees who report their own wrongdoing.In this podcast, Stefani Sonzzini Navarro, LATAM Compliance Officer for Corteva Agrisciences balances the scales.Encouraging employees to come forward with their own questionable acts, she explains, begins with having the right culture. People need to be comfortable and feel safe to report.Getting there takes time and repetition, she explains, along with a strong anti-retaliation policy that covers self-report wrongdoing as well.When an employee first brings the potential issue to your attention, she advises letting them know that if they report something you are obligated to act on it, and that you have to do what is in the best interest of the company. Let them know you will protect their confidentiality as much as possible, but that you also will have to remediate.This will help build trust, but also let them know what is likely to happen.The subsequent investigation should be conducted as quickly as possible, in recognition of how anxious the subject likely is.Throughout, she advises, be open and make yourself available.  If you let the employee grow too anxious, there could be adverse behaviors and consequences.If the employee has in fact done something wrong, their willingness to report much be recognized.  Let them know that things would have been worse if they had not spoken to you.Listen in to learn more about how to encourage and support self-reports of wrongdoing.

View Details

By Adam TurteltaubWhile many of the world’s governments are struggling to determine what to do about AI, Brazil already has a track history in this area. As Maria Victoria Mota, Corporate Attorney at Viapol (a subsidiary of RPM), explains in this podcast, the roots of government action in Brazil go back to 2018 with data protection regulations that are similar to the European General Data Protection Regulation (GDPR).This initial legislation was followed by a second in 2020 created to develop the rules of how the government, companies and individuals may use AI. It was followed by more legislation, most recently in 2023.The latest came after a committee of jurists was created to help frame the bill. Working with scientists and experts in technology, they examined how AI should be used and AI laws of 31 different countries. The goal was to creation legislation specific for the needs of Brazil.Privacy is a central pillar of the bill, which is also based in human rights and sound data protection practices. It is designed to ensure accountability, and organizations seeking to comply need to follow eight steps, Maria explains: Create a multidisciplinary work group. Empower the group with knowledge so they can bring learning to company. Map AI in the company.  Understand what departments are using it and how much. Create a policy and procedures around AI and document them. Train employees on the policies and procedures created so they can understand how important they are. Apply the policy and procedures. Stay current with changing laws and regulations. Audit compliance regularlyListen in to learn more about both Brazilian AI law and what makes for effective internal controls around the use of AI.

View Details

By Adam TurteltaubFast Company recently ran an article with the headline “Research Shows High Performing Employees are More Prone to Unethical Mistakes.” It’s both an alarming and an intriguing proposition.To understand more I spoke with Richard Bistrong, CEO of Front-Line Anti-Bribery LLC, who co-authored the article along with Ron Carucci and Dina Smith.Why are high performers potentially so dangerous? For one, he explains, success tends to block scrutiny. People don’t like to question it and are just grateful to see so much of it. They may not think to look or not want to look too deeply.Another challenge is that the more successful people are, the more addicted to success they may become, something Richard knows from his own experience. The challenge of being a corporate hero, he explains, is that once you earn that status, you typically don’t want to give it up and may end up going down what has been called the rabbit hole of success.At the same time, the company may be exerting pressure on the individual to do ever more, partially because it is standard practice in business to set higher goals. But also, the company may grow disproportionately dependent on the results the high performer can generate.Fortunately, there are several things that can be done to mitigate the risk without clipping the wings of the highflyer. For one, compliance teams should try to look at the incentive plans to both identify the risks and help mitigate them. While there, look to also include compliance measures that make it clear that it’s not just about achieving the goals, it’s also about how you achieve them.Second, connect rewards and good performances with the company’s values and mission. This helps the high performer understand both what the rules are and why they are important.Listen in to learn about how to get the most out of higher performers while avoiding the risk that can come with them.

View Details

By Adam TurteltaubIn the September 2023 issue of Compliance and Ethics Professional® (CEP) magazine, Andrea Falcione (LinkedIn), Chief Ethics and Compliance Officer and Head of Advisory Services of Rethink Compliance LLC, wrote about fostering a speak-up culture. Institutional justice, she wrote, is a critical part of that effort and “paramount to gaining and keeping employee trust.”To learn more about the topic, I sat down with her for this podcast, in which she explains that there are four elements of institutional justice.The first is Respect for everyone involved in an incident. That includes the person who comes forward with an allegation of course, but it should also include those the allegation was raised against, any witnesses and also people who come forward to self-report. By doing so, you make it clear that it is safer and better to come forward when there is wrongdoing.Voice is the second element. She shares that this means allowing people to speak and share their story. It also means listening attentively, showing interest, making good eye contact and asking open-ended questions.Neutrality is about making unbiased decisions and not letting a conflict of interest get in your way, such as when investigating a high performer in the organization.Transparency, about both the process and the outcome, is the fourth key element. It helps build trust that the process is fair and demonstrates that there will be a thoughtful response by the organization.Listen in to learn more about what institutional justice is and how to improve it in your organization.

View Details

By Adam TurteltaubWhere is the compliance profession now and where is it going?To find out we sat down with Chris Audet, Chief of Research at the Gartner Center for Legal, Risk & Compliance Leaders. Gartner recently issued a report: “Key Budget, Staffing and Spending Trends for Compliance in 2023”, and in this podcast he shares some of the insights in it.When it comes to budgets, compliance teams are strained, but not how they expected. During the pandemic there were fears of large funding cuts. While there have been some reductions, on the whole they have been minor.However, workloads have increased dramatically. This has led, he explains, to overstretched departments where the loss of even one FTE can be devastating.Three key issues have led to the increase in demands on compliance teams: The challenge of tracking regulations. A rising number of issues, such as ESG, that may have begun in another department but are now considered compliance’s responsibility Conducing internal investigations in an expeditious manner. With workers in the office less, the pace of investigations has slowed.To help get the work done compliance teams are investing more heavily in technology, particularly in risk management systems. The pace of investment is expected to grow as compliance teams contend with flat budgets and reduced staff.To retain staff, Gartner advises creating a strong value proposition that includes a work-life balance and career development.Listen in to learn more about the state of compliance and how teams are coping.

View Details

By Adam TurteltaubWhen an organization begins to expand globally, or even when a global organization enters a new market, the compliance challenges can be considerable and multiple.In this podcast, Dr. Shan Nair, President of Nucleus explains that companies need to worry not just about issues such as anti-corruption and data privacy. There are a host of HR, accounting, corporate taxation, indirect taxes, withholding taxes and other compliance issues.In addition to these obligations there may also be filing requirements. Germany, for example, requires a special filing if a local subsidiary is not self-funding.Making things more complicated is that a trusted source for compliance advice in one area likely is completely unaware of the challenges in another.The bottom line is that it takes a concerted effort and a very local approach to meet all these obligations and ensure that the organization is compliant not just on the big issues, but on the dozens of less headline grabbing ones as well.

View Details

By Adam TurteltaubYou may not realize it, but your compliance program has a brand. Line employees and management all have a host of impressions about the compliance department that color how they respond to what you say and do. A strong brand means that your actions are more likely to be appreciated. A weak brand means it’s a very steep uphill climb.Adam Balfour, Vice President & General Counsel for Corporate Compliance at Bridgestone Americas and author of the book Ethics & Compliance for Humans, is an advocate for compliance teams making the effort to invest in creating a strong, positive brand that communicates the value of the program.As a part of that effort, compliance teams need to move beyond simply building awareness to ensuring that the brand resonates and is relevant to the organization. To do that he advocates taking a people centric approach and using three methods of motivation: Start with why. Don’t just tell them what to do. Tell them why they need to do it beyond “the law requires it”. Emphasize group safety. Share what others in the organization are doing and use community as a motivator. Use incentives. The US Department of Justice is calling for them, and they can be very helpful, even non-monetary ones.Finally, leaning on his United Kingdom roots, he encourages compliance teams to think like soccer midfielders, players who can both defend and attack.Listen in to learn more about how you can strengthen your compliance program’s brand.

View Details

By Adam TurteltaubOn October 4, 2023 at the SCCE Compliance & Ethics Institute in Chicago, US Deputy Attorney General Lia A. Monaco spoke live from Washington to the attendees and used this opportunity to announce a new Safe Harbor Policy for voluntary self-disclosures made in the context of the merger and acquisition process.Under the policy, acquiring companies that promptly disclose criminal misconduct voluntarily within the six-month safe harbor period, cooperate with investigators and engage in remediation, restitution and disgorgement will receive the presumption of a declination. She also explained that, absent aggravating factors at the acquired company, it will not impact the acquiring company’s ability to receive a declination.She also shared how the Department of Justice has been fighting corporate crime including: The expansion of corporate enforcement efforts in the national security realm New tools DOJ is using to penalize corporate misconduct and provide invectives for good corporate citizenship Areas where they see further opportunity for innovation and expansionListen in to learn more and hear her underscore the importance of compliance programs, proper corporate incentive plans, and the DOJ’s expectation that the compliance team will have a seat at the deal table.

View Details

By Adam TurteltaubMuch of the day to day of compliance isn’t about understanding laws. It’s about influencing human behavior and steering people in the right direction.In this podcast, Scott Young, Principal Advisor and Head of Private Sector at Behavior Insights Team, Americas shares that understanding how people make decisions can help compliance teams be more effective. To do so, he advocates for using behavioral science to gain a broader perspective for thinking about human behavior.The field has shown, for example, that the classic economics model of rational thinking doesn’t always apply. Too often we operate in a semi-automatic mode, making decisions quickly, not really aware we are even making them.So what do compliance teams do? Adopt what he describes as the EAST Framework.Easy. Make sure the proper choice is the default choice.Attractive. Make compliance fun and engaging. Embrace gamification and other ways to make compliance more attractive to people.Social. Humans are social being and we are curious what others are doing. Thinking about tapping into the power of the group, such as leveraging social norms.Timely. Having reminders and controls in place when they are timely is difficult but not impossible. Look for the right moments of intervention and the right, often quick, reminder of what is the right thing to do.Listen in to learn more to learn how you put a behavioral approach to work for your compliance program.

View Details

By Adam TurteltaubNAVEX earlier this year issued its very substantial 2023 State of Risk & Compliance Report. To learn about the key findings we sat down with longtime ethics and compliance leader Carrie Penman, who serves as the company’s Chief Risk and Compliance Officer.Overall, the data reveals strong management support for compliance and ethics programs, although there are cracks showing. When asked whether this commitment persists in the face of competing interests, the numbers show a troubling drop. Worse, there was an increase in the number of survey respondents indicating that middle managers encouraged employees to act unethically or impeded compliance personnel from their job. It was still a minority, but a larger one than before.Turning to specific risk areas, data breaches and privacy/security threats were the top fears for compliance professionals. Not surprisingly, cyber came up as a top training topic. It was followed by codes of conduct and privacy.Looking globally – the survey also has data broken out for Germany, France and the UK – there was a far from uniform picture, with country-by-country variations showing varying priorities and levels of satisfaction. For example, risk and compliance professionals in Germany reported their ability to measure training and behavior higher than their peers in France and the US.All in all, the report makes for a fascinating, and sometimes troubling, picture of the practice of compliance.Listen in to learn more about what the data said and what it may indicate for your compliance program.

View Details

By Adam TurteltaubIt may be time to rethink background checks.  Brent Douglas (LinkedIn) partner at the law firm Hahn Loesser, explains that their use has been greatly reduced in many industries. This reflects the increase in the number of what are known as “ban the box” laws, which prohibit employers from asking job applicants to tick a box if they have a criminal history.He also warns that in some jurisdiction screening applicants wholesale for criminal backgrounds may not be permissible. Only after a job offer has been conditionally made can a firm conduct a check.That doesn’t mean background checks are always prohibited. In certain industries, such as healthcare, defense and transportation they are often obligated. Even screening for marijuana usage may be permissible, but be careful. California, starting in January 2024, will enforce a new testing methodology.If your organization conducts background checks, it may be best to have a third party conduct it for you. This both leverages their expertise and may shift liability if the check is done improperly. He also cautions that even a casual internet search of a prospective employee may turn up a past criminal conviction and cross the line into what legally constitutes a background check.For those concerned about the risks of hiring a criminal, he points out that roughly 95% of the population does not have a criminal background. Amongst those with a conviction, about 95% of those were for marijuana possession or a DUI. He asks; is it worth doing the background check given these odds?Listen in to learn more about the risks of background checks.

View Details

By Adam TurteltaubMary Shirley (LinkedIn) has had a fascinating journey as a compliance professional. Born in Hong Kong and raised in New Zealand, she has worked in Singapore, Dubai and across the US. She currently serves as Head of Compliance at Masimo, and she just authored the book Living Your Best Compliance Life: 65 Hacks & Cheat Codes to Level Up Your Ethics & Compliance Program.In this podcast she argues for embracing professional development and owning your own advancement.Among the hacks she recommends is creating a notebook on yourself. Record in it what you have done, the key steps along the way, and some of the larger details. That way, when annual performance time comes around, you are prepared to share what you have accomplished and won’t have to scramble to reconstruct what you did over the past year.The same information, she points out, is very helpful when looking for your next position. It can help  you both recall what you have done and prepare to answer questions about key accomplishments and solutions you have developed.When it comes to speaking at conferences and writing, she offers some simple advice: Just start. If you don’t you will always wonder what might have happened if you did.From a practical perspective, she urges people to remind themselves that the first draft doesn’t have to be the last. You can turn to others for feedback who can help you revise and improve that article or speaking proposal.To get the best advice, she recommends creating what she calls a wisdom council: a group of individuals whose advice you can trust. The council should be made up of people with diverse skills and experiences who have practical expertise and the comfort level with you to offer both encouragement and honest feedback, even if it is uncomfortable.Listen in for more advice on how to level up your skills and how to find the courage to pursue your goals.

View Details

By Adam TurteltaubYou’re all signed up for the Compliance & Ethics Institute or another SCCE or HCCA conference. Now, how do you make the most out of your time there?Kristy Grant-Hart CEO of Spark Compliance Consulting and a former compliance officer, herself, shares in this podcast several excellent tips for making your conference time truly valuable.Her recommendations: Plan out which sessions you want to attend before you arrive. It makes for a much more strategic and less stressful approach than picking sessions hurriedly at the breaks. Pick the sessions based on both the topic and the speakers you want to listen to and meet. Map out time to do work and answer email. It’s a lot easier to sit and listen to a session when you have a defined times to work and a defined time to be fully present at the conference. Start your networking before you go. Announce on LinkedIn that you’ll be there and try to connect with others who will be attending. Take advantage of vendor receptions and dinners to meet more people. When you connect onsite, also connect on LinkedIn right then and there. If you promise you’ll send someone a follow up email, do it that night before you forget. Don’t be afraid to approach people you don’t know. They’re probably there to meet new people, too. Put your follow-ups for once you’re back in the office into a list that you can easily find.Listen in to hear more great ideas for getting the most out of your time at the conference.

View Details

By Adam TurteltaubFirst there was Safe Harbor, then there was Privacy Shield, both of which were struck down, leaving an enormous chasm in the rules for sharing data between the EU and the US. Now, explains, Andre Bywater, Partner, Cordery, there is a bridge: the EU-US Data Privacy Framework.The new framework seeks to address the issue that led to the court striking down Privacy Shield: access to data by US intelligence agencies. To allay European concerns the US has now put in place a two-level system to redress grievances. EU citizens can lodge a complaint with the Civil Liberties Protection Office. If not satisfied with the results there, they can escalate to the US Data Protection Court, which has the power to issue orders to have data deleted.The new framework is likely to be a big step forward, but it’s not the only one data processors will have to take. Organizations will first need to determine if they are eligible to participate. Next, they will need to self-certify their processes for handling EU data, a process that will be overseen by the US Department of Commerce, with enforcement handled by the FTC.Whether self-certifying for the first time or recertifying, there are countless details to be watched. There are special provisions, for example, when it comes to HR data.And, of course, there is a question of whether courts in Europe will allow the new regime to stand. There is already speculation that a new case may be brought in January 2024.For now, though, there is a new EU-US Data Privacy Framework in place. Listen in to learn more about what your organization needs to do to comply.

View Details

By Adam Turteltaub

Payment Card Industry (PCI) compliance is driven by a set of rules that set a standard of security for any entity that takes, stores or processes credit card data. Any time you or I make a credit card purchase, we rely on PCI compliance by all involved to keep our information safe.

Now, the standard is evolving to PCI 4.0, explains Mark Schreiber, Senior Counsel at McDermott Will & Emery. PCI 4.0 is far more robust and clarifies the misunderstandings in the previous standard. It also imposes more than 50 new obligations.

Most notable of the changes is the new emphasis on third parties and the need to monitor them. Now, merchants must maintain lists and descriptions of all third-party providers, have written agreements with them that accounts for security standards and includes a process for due diligence before engaging with them.

Central to the process is a responsibility matrix, which outlines which party is responsible for each aspect of credit card security.

Perhaps needless to say, this is not likely to be a quick process. Also likely to be time consuming is the mandatary self-assessment questionnaire.

Listen in to learn all that PCI 4.0 requires and to hear an important warning: just because you outsource your credit card processing, doesn’t mean you outsource the risk.

View Details

By Adam Turteltaub

Stamford Health has just a bit less than 4000 employees spread out in over 40 local offices. For some that would be a nightmare when figuring out how to put together a celebration of Corporate Compliance & Ethics Week, but it’s not for Cheryl Gilbert, the director of compliance and privacy.

To make the annual event work she uses a wide range of communications vehicles to get the word out. The organization has a new employee orientation every other week, and compliance is a part of it. The organizational newsletter, which publishes twice each week, is also put to use. So, too, is the compliance intranet site.

What aren’t used? Posters. The team found that the effort involved in creating them, putting them up and taking them down just wasn’t worth it.

To make the week fun they have developed a wide range of activities including a:

Haiku contest. Employees are challenged to write a haiku based on the organizations core values. Where’s Waldo type game in which employees have to spot all the breaches on a messy desktop. Question of the day. Word search, which is probably the most popular of all.

There is also the opportunity to nominate compliance heroes, with rewards to both the hero and the person who nominates them.

While all of these are great for building the relationship between compliance and the rest of the organization, she advises that you shouldn’t let your Corporate Compliance & Ethics Week be the only time a year in which the barriers come down. She recommends investing wherever possible in face-to-face interactions. You would be amazed, she tells us, at what a coffee cake can do to help.

Listen in to learn more about how to make your Corporate Compliance & Week celebration a success.

View Details

By Adam Turteltaub

Cancer is not just a diagnosis between a patient and physician. In this podcast Jeremy Laws, Operations Supervisor at the Ohio Cancer Incidence Surveillance System, explains that a cancer diagnosis triggers state-by-state reporting requirements for healthcare providers.

In general, there are two areas of reporting: cancer information and patient information. Cancer information generally includes where it is on the body, the type of cancer, what type of tissues is affected and how the cancer is behaving. Patient information includes name, age, sex, race, address, date of diagnosis and date of first treatment.

And, for those concerned about HIPAA, he points out that there is a public health exception that his falls squarely under.

The data provided feeds into the US Cancer Statistics Report that is published annually. It is also used by policy makers and researchers.

Compliance teams need to ensure that their facilities are reporting the data, which many fail to do. There is a tendency to believe that, for example, the lab is reporting the results and so the physician does not need to. That’s not the case, he explains. Worse, many facilities do not even know that they need to report cancer findings.

Listen in to learn more about how to ensure your health care facilities are meeting their cancer reporting requirements.

View Details

By Adam TurteltaubWhen it comes to networking and sharing ideas with other compliance professionals, people tend to think of attending conferences. That’s not the only way to do it.In this podcast Steve Pavlicek, Community Engagement Manager at SCCE & HCCA shares the free resources the association provides and how to take advantage of them.First stop are HCCAnet and SCCEnet. They were created to be a social network just for the compliance community. People post and answer questions, share their opinions and even documents.To see all that’s there, first login on the SCCE or HCCA site. Next, click the Login button on HCCAnet or SCCEnet. You’ll find approximately 40 different communities discussing issues such as auditing and monitoring, the Foreign Corrupt Practices Act, privacy and more. There are also communities organized by industry.If you’re looking for real-time interactions try one of our Meet Ups. You’ll find a schedule of them at HCCAnet and SCCEnet. These sessions take place via Teams. The group selects topics to discuss, breaks up into smaller groups for conversation, then returns for further conversation.In addition, there are active LinkedIn groups for SCCE and HCCA. Read the messages there, share insights of your own, or use the group to connect directly with other compliance professionals.In sum, there are a host of vehicles out there for you to connect with and meet the wider compliance community. Be sure to take advantage of all of them.

View Details

By Adam TurteltaubWhen planning for disasters, organizations are typically focused on things like call trees, backup data servers, and alternative work locations. In the crush to survive the immediate threat it’s easy to forget about compliance, and even during disaster planning, compliance may come last.That’s a dangerous mistake, explains Laura Fey, Principal, Fey, LLC; Tom Leatherbee, Manager, Recovery Division, Hagerty Consulting; and Jillian Cusack, AVP, Privacy Officer, American Fidelity. Just because normal business operations are interrupted doesn’t mean compliance obligations are also on pause.Ensuring compliance plays a role in disaster planning is more important than ever. Natural disasters, ransomware attacks, a pandemic and other threats seem to be more frequent and can turn into situations that last days, weeks, months or even years. When they do, not only do existing compliance considerations continue but new ones can arise ranging from OSHA to employee obligations – you still have to pay into pension plans and make insurance payments – to financial reporting.There may also be state laws and standards under ISO and SOC 2 that may be implicated.If your institution is a recipient of federal grants, the reporting requirements don’t stop during disasters. Plus, if your organization will be seeking federal disaster grants, there will be compliance obligations there as well, including the need to document the damage.To ensure the compliance team is a part of disaster planning, establish a relationship with the person in charge of leading that effort. Learn who else they work with and get to know them as well.Take the time to understand what the risks are using resources such as Ready.gov. Think through what data you will need to collect and track during the pandemic, and be prepared to help your colleagues understand that compliance can play a vital row in disaster planning and recovery.

View Details

By Adam Turteltaub

There has been, to say the least, a great deal of controversy over the US Department of Justice’s plan to require compliance officers to provide a certification as a part of corporate resolutions. Many fear that it could lead to significant legal risk for compliance teams and fewer individuals willing to assume compliance roles.

Jonny Frank, Partner, and Kat Nolan, Senior Consultant, at StoneTurn are not concerned.  They point out that in the 20+ years since Sarbanes-Oxley, despite the predictions, there have not been the lawsuits and empty CFO and CEO chairs that some feared.

Instead, they believe, these certifications could lead to increased power and prestige for chief compliance officers.

In the podcast they lay out a five-step process for certification:

Select a framework for the certification criteria that the organization will grade itself against. Conduct a scenario-based compliance risk assessment. Assess and design key control activities. Create a sub-certification waterfall: set accountable owners throughout organization to certify compliance effectiveness in their area. Arrange for a third party or internal audit to assess the program.

Listen in to learn more, including the importance of documenting your processes.

View Details

By Adam Turteltaub

So, you’ve got a global compliance program. But, what do you do when a local team says, “That doesn’t really work here” or “We think it would be better if it were changed to something else for us”?

Kristy Grant-Hart, CEO of Spark Compliance Consulting recommends keeping your values the same wherever you operate. Values are typically based on universal ideas. They and your code of conduct should remain constant wherever possible.

Communications from the CEO and leadership should also be the same everywhere. You don’t want the CEO saying one thing in one country and something else in another.

Categories used for reporting and investigations should also be the same everywhere, otherwise it will be difficult, if not impossible, to track where the issues are. Similarly, root cause analysis and risk assessment methodology must be the same globally.

So where can you localize? She recommends looking at areas such as gifts and hospitalities. What’s reasonable in one region may not be in the other.

Look also at employment practices. Having a policy of non-discrimination is good, but in some regions there may be requirements to hire certain indigenous groups.

To avoid confusion, she advises defaulting to one policy wherever possible, and be sure to have a version control process in place. You don’t want one office to still be operating under an old policy.

Listen in to learn more about how to make thoughtful localization decisions, how to get honest feedback locally, and what to do about facilitation payments.

View Details

By Adam Turteltaub

Melinda Shapiro, Senior Director of Compliance at San Diego-based National University, knew she needed to do something different with the school’s approach to enterprise risk management (ERM). When she took on the compliance role, she discovered that risks tended to be aggregated into large buckets, such as human capital, which made it difficult to assess individual risks. In addition, risk ratings varied widely by affiliate.

Adding to the challenge, the document produced took a narrative approach, with long explanations of the risks and mitigation efforts. Sometimes there was a lack of alignment between risks and controls. Worse, the format made it difficult to track changes year to year.

Inspiration came from speaking with two other participants at the SCCE Higher Education Compliance Conference. She was able to see a new way of approaching ERM, including switching from a one-year to a two-year cycle.

The results have been highly positive. She reports that there is a much better understanding of risks and controls. In addition, there is now better alignment and very strong support from the board’s audit committee.

Listen in to learn more about what she did differently, how she learned from others, and new ways to think about your own ERM process.

View Details

By Adam Turteltaub

Healthcare and healthcare compliance are often thought to be very country specific, due to the many variations of healthcare structures. To learn more about how healthcare compliance works in one country outside of the US we spoke with Emeka Obiora, Vice President, Ethics and Compliance at NMC Healthcare in Abu Dhabi.

Emeka explains that the United Arab Emirates (UAE) has something of a split system. Public sector hospitals primarily serve Emiratis, who are provided with healthcare by the government. Foreign workers in the UAE are required to carry insurance and typically see private providers.

As a result, the risk profile is very different. It is there, though, with several key ones to manage.

The first is licensing. The UAE relies upon medical professionals who come from all over the world and have vastly different training and backgrounds. All must be qualified and licensed locally, which represents a substantial undertaking.

The second common risk area is conflicts of interest, which is focused on interactions with pharmaceutical and medical device manufacturers. To ensure that there is undue influence, contact between clinicians and providers may be completely prohibited.

As is the case elsewhere in the world, privacy is also a significant concern, and in the UAE it has grown to be a greater challenge now that there is a new, tougher law.

So, is working in the UAE in healthcare right for you? Emeka recommends asking yourself if you have a sense of adventure. As importantly, ask the same about your family and what impact a move may have on them.

If you do decide to take the plunge and find a potential opportunity, assess it like you would any other compliance position. Look at the organization and its governance structure: Will you have access to the senior level of the organization?

Question carefully their approach to compliance and ethics. While it may likely not be as advanced as what you are used to in the US, if the tone and the commitment are there it’s worth considering, especially because there is a growing emphasis on accountability, corporate responsibility and ethics in the UAE. That portends well for the future.

Listen in to learn more, including one myth about the UAE that needs to be dispelled.

View Details

By Adam Turteltaub

Compliance professionals are trained to point out downsides, identify risks and educate others on what can go wrong. But, points out, Ami Simunovich, Executive Vice President, Chief Quality, Regulatory Officer & Public Affairs for BD, they need to balance that with a need to see and encourage others to take the right risks.

A compliance officer who can do that earns credibility with business leaders.

So, how do compliance professionals get there? She recommends reorienting thinking to focus on how to advance the business in the right way. That begins with tying decisions back to the purpose of the company. This can help enable the right leadership mindset and avoid reckless decision making.

Grounding decisions in the code of ethics, along with a focus on the business’s purpose, helps create a framework for better decision making. Next, make sure business leaders are keeping up with the regulations. Also, encourage them to ask gut-check questions such as: Are we making the right decision? Would our partners be proud of what we have done?  Is this who we are?

Along the way, embrace open conversations that ask whether the decision or initiative is the right one. At the same time, be sure that, as the business proceeds, there are controls in place that are fit for purpose for the risks at hand.

Listen in to learn more about how the compliance team can help the business grow.

View Details

By Adam Turteltaub

One of the more well-attended sessions at the SCCE 22nd Annual Compliance & Ethics Institute, promises to be “ESG and DEI: How to Position for Stakeholder Success”. The session will be lead by Adrian Taylor, Director of Diversity, Premier Health; Ahmed Salim, Chief Compliance Officer, iRhythym; and Nakis Urfi, Product Compliance Officer, Babylon Health.

ESG and DEI are two of the hottest issues in compliance, and in this podcast preview of their session they start by taking on a controversial topic: Should DEI and ESG be combined? Traditionally, DEI has been its own discipline. Many now argue it should considered a part of the S (Social) in ESG, while others feel that doing so would diminish the emphasis on DEI.

Ideally, DEI should not be affected by being included in ESG, they say. If handled correctly, it can maintain its focus and management commitment and even strengthen ESG efforts. When the two are aligned they create a more sustainable business model that balances people, profit and planet. Together they can also help foster engagement with stakeholders, improve culture, encourage greater accountability, and help the company’s reputation.

To be successful, Nakis, Ahmed and Adrian argue, organizations need to manage four key challenges of ESG ratings:

A limited focus on DEI Having accurate, valid data A lack of standardization Subjectivity

All of these can lead to ratings that are more judgement scores than a true measure of an organization’s commitment to DEI and ESG.

Listen in to learn more, including how to identify data that is truly useful for measuring your organization’s DEI and ESG success.

Then, don’t miss their session at the SCCE 22nd Annual Compliance & Ethics Institute.

View Details

By Adam Turteltaub

Crystal Jezierski, Senior Managing Director, Guidepost Solutions thinks that at this point we have enough guidance documents and frameworks for compliance programs.

That’s not a criticism but a compliment. She finds the existing prescriptions to be helpful, instructive and reflective of the evolving understanding of best practices for effective compliance programs. They are also flexible enough for new and emerging risks.

What’s needed now, she believes, are more opportunities to benchmark, share, apply and test how programs are implemented.

As with compliance programs as a whole, that begins with understanding how to assess risk and how others are doing so. If done correctly, of course, a risk assessment can  orient resources to both current and future issues as well as change how the company is doing business.

When managing a new issue, she recommends involving a combination of the standard partners – HR, internal audit, finance and technology – as well as additional partners who bring expertise to addressing the risk at hand.

One other partner needs to be considered throughout: the board. It can be a tremendous asset for compliance, sometimes more so than leadership.

To gain and keep board support, she advocates for regular contact, updates, and conversations about emerging issues.

Listen in to learn more about how to leverage the compliance frameworks, learn from others and work with the board to create a stronger compliance program.

View Details

By Adam Turteltaub

Email isn’t enough anymore, if it ever really was. Employees are communicating with each other, clients and prospects via texts, WhatsApp, Teams, Slack and many, many more tools.

Much attention has been paid to the US Department of Justice’s call for organizations to be able to produce all that communication, which is not an easy task. Eric Baim, partner at Dovetail Consulting Group, explains that focusing on producing the communications is important, but it is isn’t enough. Compliance teams need  to train employees to use these technology appropriately.

That education process begins with compliance developing an understanding of what these applications were designed to do;  facilitate quick, back and forth interactions, brainstorm, and ask a question less formally than one would via email. The problem is that often these interactions lack context because they are continuations of other conversations. As a result, an outsider seeing them can draw very incorrect conclusions about what was being said.

With that understanding in mind, it’s important to make it clear to employees that if they are conducting company activity via these communication tools, they still need to follow company policy. Next, help them to understand the risk of comments taken out of context and to ensure that they add some. If the text, for example, is a follow up to an in-person meeting, reference it.

Be sure also to underscore the importance of avoiding jargon, being truthful or making assumptive statements. Stick to the facts and keep personal commentary out.

Internally, compliance teams, he argues, should take the time to understand how they can use these channels to communicate with the workforce. Communicating with the business where it is can help keep compliance top of mind and relatable. It can also help foster greater dialog which is, after all, what these applications were designed for.

View Details

By Adam Turteltaub

In a perfect world, whenever employees face a difficult decision or outright compliance issue, the right policy would automatically pop up in front of them. While that is not likely to happen soon, Jannica Houben, Vice President, Global Legal Transformation and Travis Waugh, Director, Training, both at TD SYNNEX can envision a word in which Outlook could spot issues as they are typed, flag them for the employee and give guidance and pointers to where to call for help.

Until then, there are still many things compliance teams can do using off the shelf software to automate compliance processes. It’s a topic they explore in the podcast and in greater depth in their Session “Interactive Policies: Using Technology to Enhance Decision-Making” at the 2023 SCCE Compliance & Ethics Institute.

So how do you create this automated future? They recommend beginning by thinking not about what tool you want, but what benefits you want the tool to deliver. Think about the value you want to provide and what would make employees’ lives easier. In addition, expect an iterative process: you won’t get everything right the first time.

Once you have that in mind, you can begin the pursuit of the tool itself.

At TD SYNNEX the compliance team tried to create the path of least resistance for employees to compliance, including developing an adaptive policy guidance tool. Using BRYTER, which requires no coding, they developed a tool which asks a series of questions to determine what the issue is, gives advice and routes a form to the employee’s manager. The manager can then add notes and recommendations.

The tool has a dashboard that can track the whole process. It also can help identify gaps and what the organizations risks are, what policies need to be created and when more training is required.

This program has freed up time for the compliance team, enabling it to invest in relationships and add more value.

Getting started is surprisingly easy, they report. Listen in for more inspiration, and then don’t miss their session at the 2023 SCCE Compliance & Ethics Institute.

View Details

By Adam Turteltaub

With the consent requirements built into privacy regimes, you can’t help but focus on them. Bill Piwonka, Chief Marketing Officer at Exterro, cautions, though, that there is much more than consent to worry about.

Consent is very specific around whether people you are interacting with giving you permission to have and use their data for specific purposes. Much focus is given to the pop-up warnings on websites and cookies.

Compliance teams, he advises, need to look at all the places where the organization collects data and uses data, including apps, to ensure proper consent is obtained.

One other area not to be overlooked: Data subject access requests. It can be an enormous undertaking when a consumer demands to know what information you have on her or him.

Even more daunting are similar requests by departing employees. Think of the hundreds of thousands if not millions, of documents that contain data from an employee, everything from HR records to emails to conversation on Teams.

So great is the challenge of tracking them all down that employees are starting to use the threat of requiring all this data as a way to leverage a better severance package.

Listen in to learn more about these issues and what you need to do to prepare to meet your privacy compliance obligations.

View Details

By Adam Turteltaub

The proliferation of computer-based due diligence tools, combined with the travel restrictions of the pandemic led to a shift away from in-person due diligence efforts. Technology-based approaches increased dramatically, and, according to Jen Hoar (LinkedIn), Managing Director of Forward Risk, relying solely on them can be a mistake.

Talking to human sources, she argues in this podcast, helps augment and provides nuance to open-source public records. Talking to people who have worked with the third party can flesh out what it is like to do business with them and if there are any concerns.

Sources to interview can include prior investors, customers, industry experts, and even trade journalists.

When conducting the interviews with these individuals, she advocates for an open-ended, conversational approach. Rather than trying to get through a list of questions, give them the opportunity to talk about whatever is important to them and pursue the conversation wherever it leads. Be sure, though, to take note if someone is oversharing.  It may be a sign of an agenda.

In terms of your own agenda, she advises against going in with a hypothesis to prove or disprove. Instead, go in with an open mind. Your job is to gather information and to find out what the truth is rather than to test a theory.

Listen in to learn more about the role and value of human-based due diligence.

View Details

By Adam Turteltaub

For organizations working to avoid corruption it can be a lonely fight. While a sales or compliance team may know that there are many others out there who would not pay a bribe, when facing a corrupt demand, they tend to be on their own.

The maritime industry, though, has taken a major step to change the dynamic. In this extended, in-depth podcast, Cecilia Muller Torbrand, Chief Executive Officer at Maritime Anti-Corruption Network (MACN), explains how they pursued a collective action approach that now includes about 200 companies.

The maritime industry is very exposed to corruption risk. A given ship can touch many jurisdictions over a short period of time. Captains are often very far from their headquarters and encounter multiple government touch points when approaching a port.

The corruption they face varies dramatically, but it is frequently manifested with requests for facilitation payments: some token of appreciation. The challenge is a legal one since facilitation payments are prohibited under the UK Bribery Act. It is also a practical one, when the appreciation turns into a demand and expectation. When a captain turns down the request, it can lead to a host of problems, ranging from confiscated passports to endless, time consuming inspections.

To help fight this problem MACN began about 10 years ago with just 8-10 companies. It has since grown to around 200. The companies recognized they could not fight the problem alone and had to work together.

Success has been driven by a focus on solutions rather than finger pointing. They also, when possible, seek to bring in the local government. Armed with a database of over 50,000 incidents of corrupt demands they are able to use data, rather than anecdotes, to advocate for change and demonstrate how systemic the issue is.

The results have been substantial, and over time the MACN logo on a ship has come to mean a great deal in countries where they are active. It actively helps dissuade bribe seeking.

MACN has also created a Global Port Integrity Program (GPIP). It leverages the data collected on corruption incidents to provide members with a port-by-port look at corruption risk, enabling better preparation.

Secondly GPIP has enabled them to provide a level of transparency not before seen that can help ports understand how they need to improve.

All these efforts have led to remarkable results with measured improvements on the ground.

Listen in to learn more about what MACN has done, and, perhaps, use it as a model for your industry.

View Details

By Adam Turteltaub

More and more organizations seem to be adopting compliance ambassadors or champions programs. In a nutshell, these efforts involve having members of the business unit serve as the eyes and ears, and sometimes arms and legs, of the compliance office.

Guillem Casoliva Cabana (LinkedIn), Compliance Manager, Training & Education, at Booking.com shares his insights on the topic in this podcast. The company’s ambassadors program began over 10 years ago.

Recruiting and training ambassadors is a critical part of the process at Booking.com. They are not nominated by their managers. Instead, all are individuals who volunteered to take on the role. At times, it can even be competitive. If more than one person in a given unit volunteers, there is a vote taken in the unit to make the selection.

The onboarding process includes seven distinct steps, including a live session with the compliance and ethics team that goes deep into the scenarios that they may face. Experienced ambassadors serve as mentors to newer ones. And, on an ongoing basis, ambassadors are supported through in-person meetings, an online portal, newsletter and quarterly webinars.

The program’s durability is a reflection of how successful it has been. The ambassadors have helped support the ethical tone of the company, served as examples of the company’s values and proven to be a cost-effective means of embedding compliance without adding to headcount.

Listen in to learn more about how the program has worked and what you need to do to start a successful ambassadors effort of your own.

View Details

By Adam Turteltaub

While many would say that you couldn’t pay them enough to take a job in compliance, managers often feel as if compliance officers are being paid too much. So how do you get what you deserve?

In this podcast, and at the 2023 SCCE Compliance & Ethics Institute, Amii Barnard-Bahn, Partner, Kaplan & Walker and Melanie Sponholz, Chief Compliance Officer, Waud Capital Partners, take on this touchy subject.

Before asking for more money, they advise doing your homework. Take the time to talk to peers and recruiters to see what the market rate is. Also, know your employer’s compensation system. Do they tend to pay at the top, bottom or middle of the range. You can also check the SCCE or HCCA compensation survey and sites like Glassdoor and Indeed.

When you do meet with your manager or leadership, go in knowing that this is a difficult conversation for them as well as for you. Do your best to keep things professional. Focus on why the increase in compensation is beneficial for them and not just for you. Spell out what contributions you have and will be making. Above all, be realistic and don’t go in angry.

Want to know more? Listen in to learn how to make the conversation successful, what to do if it isn’t, and how to ask for more compensation or a changed title when your role is expanded. And, don’t forget to attend their session at the 2023 Compliance & Ethics Institute.

View Details

By Adam Turteltaub

When an employee announces a departure to another job, there is a temptation to think that it was for more money. That’s probably a mistake, says Mike Lifshotz (LinkedIn), founder and CEO of Hatch Compliance. The new position may pay better, but employees are more likely to depart due to issues such as work/life balance, room for advancement, greater challenges, lack of appreciation and what they perceive to be a bad culture.

To get them to stay, he advises, first and foremost demonstrate respect. That should begin with the hiring process, during which you should both lay out your expectations for the candidate and what they should expect from you.

The organization’s values are particularly important in this regard. They are integral to setting expectations and need to be communicated from the onboarding process and on an ongoing basis.

Be sure to keep the communication process going in general. Employees cannot be expected to trust their managers if the managers don’t take the time to know them.

From a compliance perspective, knowing employees and their personalities can help identify when something is wrong and help you act accordingly.

Compliance can also help with employee retention by providing a safe place for workers to share their concerns without fear of retaliation.

One last piece of advice he offers: take the time to survey the workforce regularly. Use the survey both to measure the culture and as a way to demonstrate that the organization is willing to listen. Then, act on the results.

Listen in to learn more about how to manage the challenging issue of employee retention.

View Details

By Adam Turteltaub

Regina Gurvich, Chief Compliance & Risk Officer for Omni Opthalmic Management Consultants knows from first-hand experience that it’s not always easy for compliance officers to stay motivated. There is often a strong headwind, and sometimes a brick wall.

To stay motivated she advises focusing on getting your voice heard, staying true to yourself and finding enjoyment in what you to do a daily basis. For her, that begins with clinging to her idealism and the belief that few people wake up in the morning looking to do the wrong thing.

Focus, she advises, on the fact that for many people the right thing just isn’t clear enough.  Think about ways to educate them and look to do so on a continuous basis. Encourage them not to just know what the law is but understand what it means and how to operationalize it.

Also, grab onto your natural curiosity. Take the time to learn as much as you can about the business and how people go about doing their jobs. Understand where the money comes from and where it goes. That’s more important than ever over the last five to ten years, especially in healthcare.

Then, as you work with others on putting compliance controls in place and seek solutions for a problem, be willing to negotiate and don’t lose your sense of humor.

Listen in to learn more about how to make the day go a bit better.

View Details

By Adam Turteltaub

ChatGPT is, like the movie title, seemingly everywhere, all the time, and all at once. Individuals and corporations have rushed to embrace it, sometimes with great results, other times, not so much.

For better or worse, ChatGPT and other AI-driven solutions are here to stay, and with it comes a host of new risks to manage. In this podcast, Lauren Kornutick, Director Analyst, Legal and Compliance at Gartner shares the findings of recent research the firm conducted on ChatGPT.

They found several risks for compliance teams to focus on:

Fabricated and inaccurate answers. As with the case of the lawyer linked to above, ChatGPT sometimes make things up because it was trained on inaccurate material of it was unable to understand the context of the question. IP Risks. Employees may not understand that once data is put into an open source tool it becomes part of the public domain. That means more training on how to protect IP in the new AI era. Often the data set used to train the AI relies on data that is biased. A human review is absolutely essential to ensure that existing biases aren’t furthered. Fraudsters are particularly adept at finding nefarious uses for new technology. Consumer Protection. Some states require that it be made clear when consumers are interacting with a person, and when they are interacting with a bot. The FTC has also stressed that AI needs to be transparent, accountable and empirically correct.

Listen in to learn more about how to protect your organization from the risks of ChatGPT. Be sure, too, to check out the press release. Gartner subscribers can learn more detail by accessing “What Legal and Compliance Leaders Need to Know About Large Language Model Risks."

View Details

By Adam Turteltaub

For the cynical, business ethics, itself, is a myth. For those of us in the profession, we know it is not.

Still, that doesn’t mean that certain urban myths don’t arise. Matej Drascek (LinkedIn), in this provocative podcast, and in an article from Compliance and Ethics Professional® (CEP) magazine, argues that there are, in fact, a number of them. They are:

Myth 1: The code of conduct supports ethical behavior. Myth 2: The compliance program helps the organization become more ethical. Myth 3: Whistleblowing tools reduce the risk of unethical behavior. Myth 4: More training in ethics is better. Myth 5: Individual “unethical” characters can be curbed with the right controls. Myth 6: Goals related to ethics or compliance help people behave more ethically.

Sound more like truths than myths? As you will hear, his comments are more warnings about the complacency traps that can arise. For example, we may think a code of conduct is helpful, but if it’s read once and then forgotten, it’s not. Or, just because there’s a whistleblower line doesn’t mean it will be used; the fear of retaliation may keep an employee from reaching out.

Listen in to learn the subtle nuances. If you don’t, your ears will fall off. Okay, maybe that’s Myth 7.

View Details

By Adam Turteltaub

The excitement over Artificial Intelligence (AI) is often met with concerns about its negative potential. That’s especially true in healthcare where the potential gains are met by the principled and practical requirements of protecting patient data.

Anitha Vittal, Head, Risk and Compliance, Providence Global Center in India tackles the topic head on in this podcast. She sees AI as having great potential to revolutionize research, diagnosis and treatment, if we can successfully create guardrails for its responsible use.

To do so, she recommends focusing on the risks. The big ones are:

Data protection and security. AI requires huge amounts of data, which raises potential privacy concerns. If the data is biased, then the output will be as well. Transparency and Accountability. It can be very difficult to understand AI systems. That’s why it’s essential to bring transparency and accountability into the process.

Compliance teams also need to be educators, helping the AI team and businesspeople understand the ethical considerations involved. One potential technique involves creating case studies and requiring participants to play different roles to better understand perspectives and risks.

Listen in to learn more about managing the  opportunities and risks of AI, including the importance of what she calls the Four E’s: Establish, Embed, Enforce and Evolve.

View Details

By Adam Turteltaub

Stephen Paskoff, the President and CEO of ELI, believes that we need to think about compliance training differently.  Instead of it being about communicating information, it needs to be about cultivating a culture of compliance and activating organizational values.

So how do we get there? He recommends focusing on education designed to be retained and applied by the learner. To do that you need to be clear not on just what the standards are but also why they are important.

As importantly, the training can’t stand alone. It has to be linked to broader initiatives and relevant to employees. Even if employees don’t get every nuance of the law or regulation, they have to have a sense of what is right and wrong and be reassured that they will be welcomed if they speak up and raise a concern.

Getting to that point requires making compliance as normal a part of the dialog as discussing sales, manufacturing and other issues. Organizations need to stop treating compliance as something separate and apart and more of a norm of doing business.

That begins with the CEO and leadership team treating it that way. It also means knowing what the barriers are and implementing programs to overcome them.

Listen in to learn more about how to improve your compliance training, including the five C’s and how they can help.

View Details

By Adam Turteltaub

Our colleagues expect to be treated like adults, and that should include the compliance training we assign them.

CJ Wolf, a professor at Brigham Young University-Idaho and founder of Codermedschool.com, explains we need to embrace adult learning theory, which recognizes that adults learn differently than children. Making mistakes, for example, is particularly powerful. Good compliance training, consequently, should be less about telling them what they need to know and more about providing them with an opportunity to work through scenarios and make their errors in a safe classroom setting rather than out in the real world.

He shares a host of similar good advice in this podcast and in the SCCE Creating Effective Compliance Training Workshop.

Click below to hear other do’s and don’ts to make your training more relevant:

Do assess the effectiveness of the training. Be sure to include testing. Don’t assess the effectiveness just once. See what employees remember several months later. Don’t overload new employees on the first day. A lot of departments are throwing information at them.  Be judicious in terms of what you expect them to tackle right away, and what can wait until later. Do have a training plan based on your organization’s risk. Don’t give everyone the same training. Tailor based on their needs.

Want to know more? Think about joining him for the Creating Effective Compliance Training Workshop.

View Details

By Adam Turteltaub

Contract lifecycle management has grown to be an increasingly critical issue for healthcare providers. Staffing issues, shrinking margins and changing regulatory requirements are all adding to the challenge, report David Paschall, CEO, and Stephanie Haywood, SVP of Sales and Client Engagement at Ntracts.

Pursuing a contract lifecycle management strategy, they report, can help alleviate these issues by reducing the number of days a contract spends being reviewed, increase transparency and help the organization adopt standardized language and processes to ensure greater adherence to internal policies.

It can also reduce the number of contracts that get auto renewed by mistake, are not renewed when they should be or overlap needlessly with other agreements.

Listen in to learn more about how adopting a contract lifecycle management strategy can bring greater efficiency and a host of other benefits to your organization.

View Details

By Adam Turteltaub

For years Caremark has set the standard for expectations for board members. The notable Delaware case made clear that boards should exercise reasonable care in overseeing an organization. In practice that includes obtaining information about the organization’s compliance efforts and responding when signs of potential violations are found.

As Jay Cohen, of counsel at the law firm Giordano, Halleran & Ciesla, PC explains, now a new decision (In re McDonald’s Corporation Stockholder Derivative Litigation) extends that same duty of oversight to corporate officers within their area of expertise. This significantly raises the bar for executives when it comes to ensuring the organization is operating in a compliant manner.

Perhaps even more significantly, only two executives at a corporation – the CEO and Chief Compliance Officer – are expected to exercise oversight throughout the entire organization. This, he argues, has the impact of increasing both the scope and importance of the compliance role within the organization.

So, what should organizations and their compliance teams do in the wake of this decision?  Jay recommends that organizations raise the stature of the compliance team. Second, look at recruiting individuals for compliance who have a history in leadership to match the role. Third, build the compliance program around impact, not just activity.

Listen in to learn more about what the McDonald’s decision says, and what it means for your compliance program.

View Details

By Adam TurteltaubYou really should listen to this podcast. That’s my advice.If you do you’ll hear Scott Garland, Managing Director, Sanctions, Cyber, Fraud and Ethics Compliance & Monitoring at Affiliated Monitors give better advice on giving advice.He begins by advising a bit of humility: remember that having a quick and ready answer is not always best. You are likely the newest person to learn about the problem and least familiar with it. As a result, you need to take the time to learn and determine not just what the immediate problem is but also what the situation as a whole is. Don’t be afraid to ask others to slow down to ensure you understand things completely.Then, make sure you get the facts and context right. Be sure, too, to identify assumptions being made by the advice seekers to ensure that they are correct. They may not be.Once you have that information and the goal that the advice seekers have in mind, as well as what they see as the ideal outcome, then it is time to give advice.When you do, give them, he advises, a recipe and not a treatise on cooking. They don’t need to know the long history of the rules and the many exceptions. Instead focus on bite-sized information that they can use and share with others.The BLUF approach can be very effective: Bottom Line Up Front. By summarizing the issues succinctly at the top, you are more likely to reach people who are far more focused on the advice than the reason behind it.Listen in to learn more about how to give advice wisely, the importance of documentation and the role of empathy, and if you’re in SCCE member, read two articles on the topic by Scott on COSMOS.

View Details

By Adam TurteltaubJay Mumford is a long-time compliance veteran and Senior Global Compliance Manager at Bio-Rad Laboratories. There he developed an approach he calls MTR, which stands for Metrics, Targets and Response Plans. It’s an approach, he explains, based on ideas from the quality movement.At its heart, MTR recognizes that whatever the compliance process may be, there is a need to manage at scale. To do so, you need standards and measurements, targets, and response plans in case you miss those targets.An MTR approach, because it is disciplined and focused on goals, helps avoid a whack-a-mole approach to compliance. It enables building your program in repeatable ways, whether that’s training or, as was the case for him with document retention, ensuring that all the documents are both accounted for an not retained unnecessarily.In this podcast he explains how MTR has worked in practice and the technology tools available to compliance teams, typically at no cost, to help them take an MTR approach. These include the Power Platform embedded in Microsoft’s Enterprise platform and Visual Basic for Applications in Excel.Listen in to learn about how you can put MTR to work for your compliance program.

View Details

By Adam TurteltaubOver the last decade private equity has discovered healthcare, and with that discovery has come a rush of money and compliance nightmares.  Valerie Rock (LinkedIn), Principal, and Kristen Lilly-Davidson (LinkedIn), Consulting Senior Manager, at PYA explain that there has also come a growing awareness of the importance of compliance due diligence.Five to seven years ago, they explain, private equity (PE) firms were focused on business valuations and financial reviews.  Over the years, though, they have learned to appreciate the importance of compliance and coding reviews, including clinical compliance.  The shift was the result of too many instances of finding significant non-compliance issues post-acquisition.  These, of course, can be very expensive.Firms today need to take the time to do site reviews to examine everything from the culture to the business practices to the condition of the building to the devices used.  Often paperwork doesn’t match what actual practices are, and a dysfunctional culture can’t be identified by looking at a spreadsheet.Risks include the revenue cycle but also operational processes.  If they are poor, the potential for fines and other penalties is substantial.Listen in to learn more about what PE firms are, or should be, doing as they enter the healthcare market.  Plus, pick up some tips that can be useful for non-PE firms that are making acquisitions and conducting their own due diligence.

View Details

By Adam TurteltaubNon-compete agreements may soon be going the way of the dodo. The FTC just concluded its public comment period for its plan to eliminate them in most cases, and new rules are expected to be released later this year.Already, though, many states have restricted these agreements. In this podcast, and in his article in Compliance & Ethics Professional, John Gardiner of Bodman explains that the new FTC rule was designed to counter agreements that many felt were overly broad and restricted the ability of employees to find gainful employment elsewhere. The agreements also raised antitrust concerns since they could stifle competition; the FTC saw behavior among employers that appeared to them to keep employees from finding work elsewhere.The new rule could change that, greatly narrowing when a non-compete agreement could be enforced. It also means that non-disparagement and non-disclosure agreements that could have the same chilling effect on employment changes will likely fall on the wrong side of the line.So, assuming the rule goes into effect, what should compliance teams do? First, dust off existing agreements to determine how they measure up against the new rule and existing state laws. Second, be on the lookout for non-solicitation agreements and provisions requiring employees to reimburse their employer for training should they switch jobs. Third, make sure that the businesspeople understand what is and isn’t permissible.Finally, remember that this may be a moving target, especially if the courts start weighing in.Listen in to learn more about the changing and eroding ground under non-compete agreements.

View Details

By Adam TurteltaubThe U.S. Department of Justice (DOJ) Criminal Division Evaluation of Corporate Compliance Programs document was updated in March 2023. Since then compliance teams and the broader compliance community have examined it closely, searching to better understand the government’s expectations.Gaurav Kapoor, co-CEO and co-founder of MetricStream, sees an overarching key message to the update: The DOJ expects organizations to have a well-designed compliance, ethics and risk program and, with it, the ability to closely evaluate and monitor its effectiveness. The bar has definitely been raised.So what should the compliance team do? First, to his reading, the DOJ is encouraging organizations to follow connected, holistic approaches to compliance programs. Second, how you train and communicate must be well organized and integrated into business processes. Third, third-party risk must be scrutinized and the interconnectedness with the business must be made more visible.As for boards, they need to understand that they must continue to play their role in the business and risk governance. They must also, though, act in overseeing the risk management and compliance programs and ensuring they are successful. To that end, boards need to ensure that these programs are sufficiently funded and led, understand where compliance reports and remove any conflicts of interest.Listen in to learn more about these topics as well as adopting a compliance culture, looking beyond the guidance, and the proliferation of guidance documents that compliance teams need to navigate.

View Details

By Adam TurteltaubThese days, the term “blockchain” is no longer novel. Yet, many still struggle to understand what exactly it is and what implications, if any, it may have for a compliance program.Segev Shani (LinkedIn), Chief Compliance & Regulatory Officer at Neopharm explains that it is more than the tool underlying cryptocurrency. Blockchain is a technology in which data is stored in blocks, and once that block is full, another one is formed, creating a chain. This data is not held in one place but is distributed on multiple servers, which ensures that it cannot be improperly manipulated.When it comes to privacy, though, there is a privacy-blockchain paradox. While the security of the data is protected via blockchain, the data, itself, cannot be deleted. So, should compliance teams simply say “no” to using blockchain with personal data?According to Segev, not necessarily. A growing number of tools have been developed to manage this issue, including the ability for a data subject to turn their data on or off, making it either public or private as they see fit.It’s an intriguing area, and well worth the time to listen in to learn more.

View Details

By Adam TurteltaubAh, social media. The cause of so much joy and pain, both for individuals and organizations. For compliance teams it can be a breeding ground for breaches, particularly in healthcare where HIPAA violations and social media tend to go hand in hand.Pinnacle Healthcare Consulting’s Sheila Limmorth tackled the issue of social media and compliance in the latest edition of the Complete Healthcare Compliance Manual and does so in this podcast.Some issues, such as a worker posting a photo with a patient, persist. Often innocent, these breaches are nonetheless serious. It’s the reason why ongoing training is necessary. A new worker coming, for example, out of fast food probably is unaware of the restrictions of HIPAA. Even veteran staff may lose track of the rules, and the marketing team may not realize that the testimonial they want to run still requires a signed consent form from the patient.In addition, the rapid turnover in healthcare workers means that if you have training on an annual cycle, it’s highly likely that a significant portion of the workforce has not received the education it needs.To make that training effective, she recommends providing examples of how to use social media  properly, and ways that people may use it very improperly.Unfortunately, it’s not just accidental breaches and a lack of training you need to worry about. The website and the software on it are also important. She points to the Meta Pixel JavaScript Code that many hospitals were using and which allegedly could share the data with Meta, the parent of Facebook.As with other compliance risks, ongoing monitoring is essential for managing social media. Fortunately, there are providers of software that will scour the various platforms to look for posts and even identify material that was likely submitted by an employee. In addition, she advises encouraging employees to be on the lookout for and report material that shouldn’t be on the web.The goal of this vigilance shouldn’t be to catch and punish, but prevent, educate and avoid future social media disasters.Listen in and learn more in the Complete Healthcare Compliance Manual.

View Details

By Adam TurteltaubFor all the talk of tone at the top, the reality is that few employees report to the top. Virtually all report to a manager somewhere in the middle, and it’s the tone that leader sets that is often most important.Susan Du Becker, Director Risk & Compliance at Microsoft believes that compliance teams need to focus on managing from the middle and getting this important level of the organization on board.So how do you get these managers to work with you? How do you earn their commitment to help, especially in risk areas like privacy and anticorruption? For her, it’s about being inventive and thinking about how you can get them to drive compliance rather than you. To do that, she looks for the key influencers who can serve as champions for the program. They can go upstream or downstream and will help carry the message.Gaining the support of these people requires some effort, she reports. You have to sell them on your vision and let them know that it is to their benefit to further it. If, for example, you can show the sales VP that getting expense reports right reduces the risk of an audit, keeps the salesforce out of trouble and increases the speed with which the team gets reimbursed, you have a supporter.Once you have middle managers on board, make their life as easy as possible. Take away the pain, and give them the tools, templates and PowerPoints they need to put the policy into practice.What should you not do? Become overexuberant. It’s critical to avoid running ahead and instead focus on a stair step approach. Also: remember you have to keep them committed. You can’t take them for granted.Listen in to learn more about how to make the middle of your organization your greatest supporter.

View Details

By Adam TurteltaubMost of the time people look at the termination of a problematic employee as solving a problem. Bob Woolverton of Top Tier Leadership Training believes that thinking is a mistake. As he points out in this podcast, it’s not an end point. Instead, it’s the time to start, if you haven’t already, assessing how the organization got to this point.The employee’s supervisor was responsible for ensuring the worker’s success and safeguarding his or her welfare. The termination begs several questions the manager should be asking: What should or could I have done to prevent this from happening? What is my culpability? If it’s a policy violation, am I certain the employee understood the policy, or did we just have him/her sign off? Did the policy not make sense in this environment? Was there an opportunity for misapprehension or misapplication?The bottom line it is the time to start a reassessment process.On an ongoing basis he recommends organizations’ managers take a “rudder tap” approach. What this means, in practice, is providing small adjustments to course when things begin to go awry, rather than waiting until things are so far off that a bad outcome is inevitable.Making this method successful requires fostering an environment where people – both employees and managers – understand that corrections can be positive and a part of a healthy corporate culture.Listen in to learn more about how a termination can lead to a process of positive change for the organization.

View Details

By Adam TurteltaubWith the proliferation of sanctions in the wake of the war in Ukraine and more focus on responsible sourcing, trade compliance has grown exponentially in complexity. It has also become less of a compliance silo and become more integrated with other compliance efforts.To understand the state of trade compliance we sat down with Lindsay Bernsen Wardlaw (LinkedIn), Director, Trade Advisory Services, Amalie Trade Compliance, who outlined the four areas of trade compliance: sanctions, export controls, antiboycott and customs.Each has great complexity, and there’s much more than Russian sanctions to worry about. Restrictions on importing goods manufactured by forced labor have increased dramatically with the passage of the Uyghur Forced Labor Prevention Act that presumes good sourced from the Xinjiang region of China were made with forced labor.The law has real teeth, she explains. Of the approximately 3,000 shipments stopped under the law, none have been released.So what should organizations be doing? First, take the time to understand your risks, including the primary inputs for your products and who your suppliers and customers are, including agents and channel partners. Understand, too, where the goods are being made, sold to and for whom.Have a restricted party screening process in place and an import/export classification strategy. Also, be sure to have a transaction review team in place for any deals that may be sensitive.She also recommends creating a crisis task force for when things go wrong, as they may. It will likely include the trade compliance, supply and procurement teams. Other potential members include IT, engineering, product management, and even communications.Listen in to learn more about what you need to do to ensure compliance in this ever-more complex risk area.

View Details

By Adam TurteltaubCompliance teams have long advocated for building more trust in the workplace. That is good idea for the corporate culture, but, counsels Sese Bennett, a virtual CISO for CereCore Advisory Services, going the exact opposite way may be better for your IT security. There he advocates organization never trust and always verify.So, what is a zero trust approach? It assumes that just because someone has logged in to your system doesn’t mean that person is who he says he is or that she can access the entire system. In practice that means carefully controlling access both into the network and within it. It means preventing people from accessing a low value part of the network and giving that person access to higher value servers. It means having a system that knows an individual doesn’t, say, normally login from Pakistan at 4:00 in the morning. It monitors sudden changes of usage.Importantly, he explains, a zero trust approach is not necessarily intrusive. Users won’t be forced to login repeatedly to prove who they are. Instead, it can work behind the scenes and be invisible to the end user.Listen in to learn more, including what teams you will need internally to adopt a zero trust approach and potentially better protect your data from breaches.

View Details

By Adam TurteltaubWhen discussing AI around compliance professionals these days you can instantly feel the tension. AI, for all its promise, has proven to be a bit of a compliance and ethics nightmare. Stories abound of AI embracing redlining and other discriminatory practices.Anthony “Ant” Stevens, CEO and Founder of Melbourne, Australia-based 6Clicks sees opportunities, though, for putting AI to work for your compliance program. It has the potential, he believes, to streamline activities, better tie policies to the underlying legal requirements and enable compliance teams to better understand the overlap of similar laws around the world.In this podcast he explains how the technology can help compliance operations, particularly ChatGPT.He also makes clear that there are limits to AI. A human element remains important for ensuring that what AI says makes sense, both on its face and for your workplace.Listen in to learn more about how AI can stop being the stuff of a compliance professional’s nightmares and start becoming a dream come true.

View Details

By Adam TurteltaubIn 1986 the Emergency Medical Treatment & Labor Act (EMTALA) was enacted. As Mary Ellen Palowitch (LinkedIn), Senior, Managing Director, Dentons Health Care Group, explains in this podcast, just because it is long established doesn’t mean health care providers have it completely under control. Issues continue to come up.EMTALA requires hospitals that participate in Medicare, including rural emergency hospitals, provide medical screening to determine if there is a medical emergency. If, in fact, the patient requires treatment, the hospital must provide stabilizing treatment within their capabilities, regardless of whether the patient has the means to pay.Two areas often cause confusion and real issues under EMTALA. They are best known by the phrases “clinically stable” and “stable for transport”, neither of which is defined in EMTALA.Clinically stable, she explains, may be anything from a comparison to how the patient presented when first presenting or reflecting the patient’s overall condition.Stable for transport is a term commonly used in hospitals. It does not technically mean the patient is stable, but it signifies that the patient has achieved the level of care that the hospital can provide. Basically: the hospital has done all that it can, and it may be more prudent for the patient to be transferred elsewhere for the care needed.Complaints do arise under EMTALA and may come from patients or their families. When one is sent in to the government, a multistep process begins. The complaint is reviewed and can lead to an onsite investigation that may include comparisons to how other patients were treated, interviews with staff, a tour of the emergency department and review of records.Hospitals found to be deficient are required to remediate promptly.Listen in to learn more about how to avoid and manage EMTALA issues in your emergency center.

View Details

By Adam TurteltaubWhile we tend to think of colleges and universities as being filled with college students, children much younger are often on campus. In fact, Lindsay Meyer Bond, Executive Director of the Higher Education Protection Network, that there may be more minors on campus than regular students. Everything from enrichment programs to sports camps can bring hundreds of children with them.When looking for guidance as to how to keep campuses safe for children, there is no federal law to turn to. Instead, there is a patchwork of state regulations, and many universities have had to create policies of their own.For the most part, these policies require the reporting of suspected abuse or neglect. Many now require background checks for those interacting with kids that may be go beyond the initial screening when hiring.Often universities have codes of conduct that prohibit one-on-one interactions with minors, but there is complexity there. A professor may not know that the student showing up for office hours is under eighteen.In addition, there may be conflicts of law and regulations. Ohio State University has a program, she explains, where students can learn to fly. FAA regulations stipulate that only the student and instructor may be in the plane. Their solution: when the student is on the ground, he or she is never alone with an instructor.To successfully navigate the challenges of minors on campus, she recommends strong policies and ongoing communications plans. With turnover frequent in youth programs, it is risky to assume that the adults have been fully trained, unless that training is continuous.In addition, keep an eye on your campus Name, Image and Likeness (NIL) program. College athletes may be running their own programs and not be aware of all the rules.Listen in to learn more about how to manage this difficult and sensitive issue.

View Details

By Adam TurteltaubW. Bruce Cameron is the author of 8 Simple Rules for Dating My Teenage Daughter and a whole series of novels about dogs including A Dog’s Purpose which spent 63 weeks on the New York Times bestseller list. His latest novel is Love, Clancy: Diary of a Good Dog.So, why is he on a compliance and ethics podcast? Well, because his writing has a lot more to do with it than you might think, and he learned some painful lessons about setting and enforcing rules. It was easy enough to write those simple rules for dating his then two teenage daughters, but that didn’t make him popular. He was seen as a despot and met resistance (both overt and subtle).As for those daughters, one is now a CFO and the other, ironically, works in law enforcement.The experience taught him several lessons that compliance teams can relate to: You have to recognize that you can’t have complete control Just because you think thing will go better if others do what you say, they may not There is a need for human expression and accommodation for itDogs have proven less argumentative for him. As he observes, they have been bred over the centuries to be absolutely dedicated to us. We raised them to be our tools first and then pets. Today they are thrilled when we come home and bring their optimism and hope, and their love of play, into our lives.Dogs, though, he believes, lack an innate sense of right and wrong. Instead, they are born with instincts where what pleases us is “right”. That, he explains, is why dogs owned by bad people turn out “bad”: they are doing what they think will please their owner and, to them, that’s the right thing to do.We have an ethical duty to dogs, he argues, because they are wired to please us. In addition, they were bred to depend on us even to survive.Listen in for a fun conversation about dogs, ethics and the often frustrating outcomes of setting even the most basic of rules.

View Details

By Adam TurteltaubThe cyber landscape these days can be terrifying. Malware, ransomware, spyware, phishing, cloud-based computing and so much more are enough to keep even a compliance veteran up all night.There are other risks to consider, too, says Ganesh Krishnan (Twitter), co-founder and CEO of Anzenna. One major issue is scalability of IT security resources. As organizations grow larger and increasingly reliant on cloud-based software providers, the size and complexity of security challenges increase. If the cybersecurity team does not grow with it, problems increase, work doesn’t get done, and vulnerabilities quickly emerge.A second problem is the attitude the data security is the responsibility of the data security team.  He argues persuasively that it isn’t. Technology can’t solve cyber problems. The entire company has to be focused on it.That includes the workforces, which has been labeled wrongly, he argues, the “weakest link.” Instead, organizations need to recognize that employees can be the strongest link and have to be treated accordingly. This means more frequent training and less punitive measures when things go wrong. Employees should not be fearful to come forward and report a mistake they made.He also encourages organizations to be more open when there is an incident, sharing internally what happened and what employees can do in the future to help prevent it from reoccurring.Listen in to learn more about how to improve your cybersecurity program.

View Details

By Adam TurteltaubWhile the trade compliance focus these days tends to be on Russia and the hundreds of sanctions imposed, one old issue remains: The Arab League Boycott of Israel. Despite improving relationships between Israel and some of its neighbors, progress has not been uniform and risk remains.In this podcast, Matt Silverman, Global Trade Director and Senior Counsel at VIAVI Solutions and author of the chapter “U.S. Antiboycott Laws: Understanding the Impact and Ensuring Compliance” in the Complete Compliance and Ethics Manual, explains that the boycott prohibits companies and individuals from doing business in Israel or with other companies that do business with the country. The US antiboycott law makes it illegal for US companies and persons to support the boycott, or, for that matter, any boycott that the US does not endorse.It would seem simple enough, but it isn’t. Individuals not familiar with the issue may not think twice of signing an agreement that says the company will follow the laws of the country where the sale is made. What they may not realize is that the country has laws on its books prohibiting business with Israel.Examples of boycott language can be found on websites of the US government.To comply with the US antiboycott law, both in the Middle East and elsewhere where boycotts may be in place, it is essential that employes be trained in what to watch out for. The company should also have an antiboycott policy. In addition, companies need to remember that there is an obligation to report any boycott requests.Listen in to learn more or read the chapter about the topic in the Complete Compliance and Ethics Manual.

View Details

By Adam TurteltaubESG, cyber risk and privacy are all hot topics in compliance, but that doesn’t mean people typically identify the data issues as ESG topics.  Lisa Beth Lentini Walker (LinkedIn), CEO & Founder of Lumen Worldwide Endeavors  and Assistant General Counsel at Marqueta, thinks that’s a mistake. Cyber and privacy, she believes, fall very much under the Social in Environmental Social and Governance. Just look at the many ethical issues surrounding data usage these days as proof.She explains in this podcast and in the chapter “ESG, Cyber and Privacy: Bridging the Divide” in the 2023 Complete Compliance & Ethics Manual, that privacy and security are not separate and apart from ESG. They are central to how the organization navigates the world and people around it. Keeping data secure is squarely under the social mission of the enterprise.To live up to that obligation, organizations have to focus more on keeping data safe and building proper systems around how individuals interact with the data. Simply believing “well, we have a good practice” is not enough. The practices have to support the ESG framework in terms of meeting the company’s commitments.In addition, the temptation to be data hoarders has to be tempered. Collecting data is easy to do, and it’s generally inexpensive to store. That makes it easy to rationalize indefinite retention. But, a clear path to data destruction is essential. Think of it like cleaning out the closet. It may not be easy, but it needs to get done.Organizations also need to embrace greater transparency about the processes in place to safeguard and use data. That helps investors and rating agencies better assess how the entity is measuring up against the SASB and other standards.Listen in to learn more, and then check out the 2023 Complete Compliance & Ethics Manual.

View Details

By Adam TurteltaubThe Gartner Legal Risk & Compliance Practice recently released a report on the state of third party risk management. To learn more we talked with Chris Matlock, Gartner’s Vice President, Advisory – Corporate Strategy & Risk Practice.The report was developed, he explained, because of the substantial changes in business over recent years. As the size of businesses has grown – many of the Fortune 500 are 50%-100% larger than they were a decade ago -- the number of third parties they work with has increased dramatically and with it the “threat surface”. Complicating the challenge, much of the pandemic took place during the pandemic, when normal third party vetting processes were not possible.Today, with a threat of a recession, third parties are often under extreme pressure to meet the expectations of both their owners and their customers. The likelihood for compliance failures is higher.Gartner’s research found that the typical risk factors remain, but they have been intensified by both new regulations and stresses on supply chains. IT and cyber risks are growing larger at the same time that companies have made substantial investments in technology to enable their team to collaborate and interact with customers electronically.Adding to the challenge, many organizations do not have a mechanism for centrally managing their third parties, which makes it more difficult to ensure consistency in practices and respond when things go awry. Pushing the “stop” button with one vendor may trigger unexpected consequences three steps downstream.Additional stress has been created through, as noted earlier, a heightened regulatory environment. Anticorruption enforcement continues while the number of privacy laws grows.To manage the risks, many have turned to tools to collect more data on their supply chain, but that has posed the problem of having too much data and, as a result, difficulty in determining which pieces of data are truly important.To help manage these risks, Chris recommends enlisting the enterprise risk management team to create key indicators that can help monitor risks in a forward-looking way.

View Details

By Adam TurteltaubAt the 2023 HCCA Compliance Institute there is a sure to be fascinating roundtable discussion lead by Marti Arvin, Vice President, Chief Compliance Officer, Erlanger Health System, Joan M. Podleski, Chief Privacy Officer, Children’s Health and Adam Greene, Partner, Davis Wright Tremaine, LLP. They will be addressing a range of privacy and data-related issues.In this podcast one of the topics they discuss are the complexities around access. Often, for example, raw data is not kept in the main health information management system (HIMS).Another challenge is proper website disclosures and how visitor data is used and shared. OCR has issued guidance in this area that has earned a great deal of attention. But, it is likely to be a hard problem to solve since organizations will need to determine exactly what data they are collecting, using and storing.To help manage these issues they strongly argue for investing the time and effort in developing clear processes for responding to data requests. Then, monitor to ensure the policies are being followed.Take time also to understand what is in your designated record set and where it is stored. Then make sure your HIMS understands what qualifies as the designated record set.It’s time also to reassess how your organization is managing telehealth now that the public health emergency is ending. There will be decreased flexibility and increased emphasis on keeping these interactions on HIPAA-compliant platforms.When you do move onto one of these platforms, be sure to have a business associate agreement.When looking at technology, they advise compliance be a part of decisions related to the use of patient apps. Whether your organization is thinking of building its own or relying on a third party, it’s essential that the privacy requirements be a part of the discussion from the start.Listen in to a provocative conversation, but, be warned. It’s going to make you want to join them in person at the HCCA Compliance Institute, April 23-26 in Anaheim, and online April 24-26.

View Details

By Adam TurteltaubA lot happened in compliance in 2022, with a large number of lessons for 2023. To sort it out we turned to Michael Volkov, of the Volkov Law Group and host of the Corruption, Crime & Compliance blog and podcast. In this Compliance Perspectives podcast he addresses several key pieces of learning for compliance teams.FCPAWhile 2022 may have started out slowly in terms of resolutions, the year ended on a busy note with several settlements and the revised corporate enforcement policy. One thing the DOJ made clear is that it is taking a sharp look at compensation policies to see if there are both incentives and disincentives for wrongdoing. The latter should include claw backs, deferred compensation and punishment for wrongdoing.Culture (more below) was also a keen area of focus and is likely to remain so. The perennial issue of third-party risk remains, as well.Where should compliance teams focus? The contract to invoice to payment stage of deals is where FCPA violations tend to occur.Also, be on the lookout for more major dispositions shortly.SanctionsLast year, he reports, was the year of the trade compliance officer. Complying with an ever-increasing and changing list of Russia-related sanctions kept teams busy day and night.The good news is that companies seem to be on top of things. The bad news is, he warns, that the Department of Justice has warned that this could be the new FCPA, with large fines for wrongdoing. He also warns that OFAC is a strict liability enforcer. Intent does not matter.As big an issue as this has been, there is often still too much of a separation between the trade compliance and main compliance groups. That will likely need to change, if it hasn’t already.CultureCulture has gotten the attention of the enforcement community with a particular focus on ethics. Done right, the culture can be the most effective corporate control an organization has.Done wrong, and it can cause not just problems, but liability for the organization. The DOJ is looking at culture closely and recent case law out of Delaware has extended the due care responsibility to senior leadership.To survive and thrive organizations, he believes, need to define their culture, attend and imbed it, monitor, and intervene when they see deficiencies.Finally, the board and senior management need to be educated on the importance of the right culture. It’s not just about saying “do the right thing.” It’s about expectations and norms around the mission, how we treat each other and how we treat those outside the organization.Listen in to learn, including what he sees for the future of compliance programs.

View Details

By Adam TurteltaubTelehealth is here to stay, but that doesn’t mean the rules will all be staying the same, reports Holly Hester, Senior Director, Strategic Client Partnerships for Net Health and Yolunda Dockett (LinkedIn), Chief Compliance Officer at Anne Arundel Dermatology.While the Public Health Emergency is set to end on May 11, 2023, the Consolidated Appropriations Act of 2023 extended many telehealth flexibilities through the end of December 2024. These include the ability to provide telehealth to patients in their homes, in both rural and urban settings, and the ability of physical and occupational therapists, along with speech pathologists, to provide telehealth.Yet, there are inconsistencies, with some CPT codes used by rehab therapists set to expire at the end of 2023.  Plus, some are being continued only for 151 days after the end of the emergency.One other change to expect centers on privacy requirements. While many platforms have been used to provide telehealth, soon only HIPAA-compliant platforms will be allowed. It’s a change that makes the provision of care less flexible and perhaps less friendly.Regardless, if your organization has not yet done a risk assessment about telehealth, now is the time. Leverage the relationships established in rolling out the service and then look collaboratively at the risks and start thinking about remediation techniques.Some other things to consider: Understanding how to decide if a patient has the physical and mental capacity for telehealth Business and operational risks Privacy considerations, on both the provider and patient sides Reimbursement and billing Documentation requirements.It’s a lot of work, but it helps to ensure that telehealth can be delivered in a complaint manner.Finally, don’t miss learning more at their session “Incorporating Telehealth into Your Compliance Workplan” at the 2023 HCCA Compliance Institute.

View Details

By Adam TurteltaubThese days it’s easy to identify people using technology and databases, and that’s a problem if you are trying to comply with HIPAA or even GDPR because a lot of sensitive data eventually needs to be de-identified in a proper manner.Thora Johnson (LinkedIn), Partner at Orrick and Mark Fox (LinkedIn), Privacy and Research Compliance Officer at the American College of Cardiology explain that there are two permissible methods of de-identification under HIPAA. Safe Harbor De-Identification is a process in which eighteen identifiers are removed. The second option is Expert Determination De-Identification, in which statistical principles are used to determine if there is low risk a person can be identified.It's not an easy process, either way. Information on the individual and family members likely needs to be removed. In addition many struggle with how to do de-identification right because the work is often done only periodically and not on a regular, frequent basis.One area of particular challenge is understanding the difference between de-identification and a limited data set. There are significant requirements with these limited data sets, too, including the need for a signed agreement with the data recipient and proper permissions to share the data.Adding to the complexity, under GDPR there are the concepts of anonymization and pseudo-anonymization to reckon with.What should you do? Listen in to understand the issues, and then plan on attending Thora and Mark’s session “It’s De-Identified, or Is It?” at the 2023 HCCA Compliance Institute.

View Details

By Adam TurteltaubWith one of the largest economies in the world and serving as the South American home for many global businesses, Brazil is a country for compliance teams to watch, and their laws are very much worth heeding. That includes the Brazilian General Data Protection Law (LGPD), which entered into force on September 18, 2020.As Andre Paris (LinkedIn), Professor and Privacy & Compliance Consultant explains in this podcast, the law contains 10 principles including: Data should be processed only for specific, legitimate, explicit purposes Data quality needs to be maintained Companies must be transparent about how data is used A security regime must be in place The data should not be used in a discriminatory matterIt is very similar to and consistent with the European General Data Protection Regulation (GDPR) and includes a number of rights for data subjects, such as access to personal data held by the organization, the ability to correct outdated and incorrect data, and the blocking or deletion of unnecessary data.The law applies to any data collected in Brazil, regardless of the citizenship of the individual.So how can compliance teams address the law’s requirements? He recommends several steps: Secure the support of leadership Search for someone with privacy expertise to serve as the data protection officer Train the workforce on what is essential data Map your data Determine which law authorizes the processing of data Identify any and all risks inherent in the organization’s operationsListen in to learn more about how to ensure your organization is in compliance with Brazil’s LGDP.

View Details

By Adam TurteltaubPatient safety remains a challenge for organizations, and not for want of trying to address the problem. Improving it is an issue addressed here and at the 2023 HCCA Compliance Institute by Deb McCracken, Chief Risk Officer, and Julie Wall, Senior Vice President, Benefis Health System.Problems such as fall prevention remain, along with improper medication administration, misidentifying patients and preventing infections. They persist because, as healthcare and technology change, procedures may as well, leading to a departure from safe behavior.Adding to the challenge, often, is an unwillingness to speak up and raise issues. Many fear that they will be retaliated against if they point out potential problems.To better understand patient safety risk they recommend a close working relationship among compliance, quality and risk management. These three departments should help form a committee focused on patient safety that includes individuals skilled in capturing and coding root cause analyses.To close safety gaps effectively, they recommend looking to best practices and implementing them. Also use lessons learned from your organization and others across the industry. That begins with debriefing after an incident.They also recommend running simulations of real-life situations. These can help you be better prepared when an incident occurs. When you do, don’t forget about practicing for workplace violence scenarios.Listen in to learn more about how you can promote better patient safety practices. And, to learn even more, join us in Anaheim for the 2023 Compliance Institute.

View Details

By Adam TurteltaubWith seemingly constant news stories about layoffs, many are starting to wonder what they would do if they found themselves suddenly out of work and looking for their next compliance position.There are several ways to make the process go smoother, explains Brittney McDonough, partner at the recruiting firm Barker Gilmore. That starts with making the right decision of how much time to take off after a layoff.Many people, not surprisingly, are tempted to use their severance package to take a much-needed respite from work. Be careful, though, she advises. A job search can take three to six months, so taking six months off could lead to a year out of work.That doesn’t mean, though, you shouldn’t take advantage of this time. You should embrace it; just be sure to use it strategically, balancing recharging your batteries with a thoughtful approach to finding your next opportunity.When it comes to pursuing a job search, she recommends three key steps: Develop professional objectives. Think through what you want out of your next position:  What role do you desire? What level are you open to? What type of company? What size and industry? What do you want to make? Where do you want to live? Develop a marketing plan for yourself. Think about how you are going to sell yourself and end up on the radar of recruiters and prospective recruiters. Update your resume accordingly, and be sure that you have a current and accurate presence on LinkedIn.  Recruiters depend on it. Be intentional about how you network. Put together a list of contacts who could be helpful. Reach out to them and ask what they can recommend and who they can connect you with. Be sure to also offer to help them, too. Also pursue speaking and writing opportunities. They are a way to increase your contacts and open up more opportunities.What do you do when a prospective employer asks about the job that you lost or maybe still have? Be honest but don’t go into any more details than you need to. You want to keep the focus on the job you want, not the job you have or had.Listen in to learn more, and if you want to learn more about networking, here is a link to a book that was discussed in the podcast.c

View Details

By Adam TurteltaubAs environmental expectations keeps rising and Environmental Social and Governance (ESG) metrics gain more importance to investors, some organizations will be tempted to greenwash, which is best described as making an environmental footprint look far better than it actually is.That’s a serious risk and one that will be addressed by Elena Durante, ESG Risk Audit Manager, ING Corporate Audit Services, Risk & Finance, at the SCCE European Compliance & Ethics Institute, which takes place in Amsterdam March 20-22.As she explains in this podcast, at its roots greenwashing is about misleading information supplied to investors and customers, taking advantage of the fact that these outsiders cannot fully tell if what the organization is saying is true.While greenwashing is still relatively unregulated, she tells us, that has started to change.  In the EU there have been an increasing number of efforts to combat it. Plus, there is severe reputational damage to companies caught greenwashing.Compliance teams need to be on the lookout at their organizations to ensure the integrity of their organizations’ environmental statements. That starts with ensuring that what regulations that currently exist are followed. It also means keeping an eye out for new regulations.Compliance should also be working to develop and implement ESG protocols within the organization. These should identify clear rules and policies to ensure sufficient checks and balances are in place.A training element will also be needed to help the business people understand that environmental statements need to accurately reflect the  organization’s actual activities, not just its aspirations.Listen in and then keep an eye out for greenwashing in your organization.

View Details

By Adam TurteltaubAndrew Walker is the US Tennis Association’s (USTA) director of education and training for officiating and chief umpire at the US Open. He was good enough to join our Sports, Compliance & Ethics Conference, where he revealed something surprising. With the USTA having over 13,000 sanctioned events a year, ranging from adults to juniors, the vast majority of matches are technically unofficiated. Roving umpires are available but move from court to court. They don’t sit in the chair and call each point. Players do and keep the score. That’s often true as well at the college level.It's not too different from how things work in the business world, with compliance officers not there to make every call for the business unit.How does this work? Part of the role of officials at entry level events, especially those with children, he explains, is not to act only as officials, but to act as educators as well. They are there to teach kids to officiate fairly, even if it means making a call against oneself. That’s not easy, human nature being what it is and with, these days, the ultra-competitive environment in youth sports.The officials seek to ingrain sportsmanship, which includes integrity, respect for your opponent and respect for the game. It also includes being a good winner and a good loser.What happens when there is a dispute? First, officials recognize that honest mistakes are possible. A player, especially a young one, running to make a shot may not see things accurately. Even competitive players can lose track of the score.But, when the calls are questionable, they will stay and watch the match for a while. And, if a player is repeatedly overruled in his or her calls, points and games can be taken away. The player may even default.Listen in to get both a new appreciation of the world of tennis and maybe pick up a few ideas about how you could encourage more self-umpiring at your organization.

View Details

By Adam TurteltaubFraud and compliance issues often go hand in hand, which is why it’s important for fraud and compliance teams to work closely together. Christopher Knight (LinkedIn) of Knight Vision Fraud Investigations and Megan Grifa (LinkedIn), senior Director, Compliance Oversight for Sidecar Health, will be addressing the fraud-compliance relationship at the 2023 HCCA Compliance Institute, taking place in Anaheim April 23-26.In this podcast that point out that communication and follow up are central to building successful connections between fraud and compliance. Each needs to let the other know what it is doing, what has been found and what is coming up next. Also of great value:  setting up mechanisms to force yourselves to connect at a certain cadence to keep the lines of communication open.In addition, they advise taking the time to get to know each other on a personal level. That will help build the trust that is essential when addressing a crisis.Even during more normal times it’s essential to cooperate, aligning program structures and sharing risk assessments. Compliance teams can benefit from data mining and analytics tools that fraud has. Meantime, the fraud team can benefit from the seven elements approach used by compliance.Listen in and then plan on learning more at the 2023 Compliance Institute.

View Details

By Adam TurteltaubEthical leadership is about much more than being both ethical and a leader. It is also about the actions you take to encourage ethical behavior all around you.It’s the subject of this podcast and a talk that will be given in March at the SCCE European Compliance & Ethics Institute by Steven Pegg, Senior Ethics Officer, Europe, Middle East & Africa for Lockheed Martin.Ethical leadership comes with many challenges. Aggressive goals can cause executives to focus just on the task at hand and be tempted to cut corners. Studies have shown that positions of power can have an affect on behavior over time, leading to a loss of empathy, acts of disrespect, feelings of entitlement, selfish behavior and a tendency to think that the rules don’t apply to them. These factors can create a toxic culture not surprisingly.Smaller offices also face the challenge of developing a subculture that can be inimical to ethical conduct. Lacking the controls of larger locations, unethical behavior may be left unchecked.There is one other challenge to ethical leadership: a hesitance to talk about ethics. Some leaders, even virtuous ones, are uncomfortable discussing ethical issues.To overcome these challenges ethical leaders need to develop several skills. These include: Setting the tone. People model what their leaders do. If a leader is comfortable telling stories and discussing ethical issues, it’s far more likely the rest of the workforce will be as well. Act as a positive role model. They must be accountable for their actions and both talk the talk and walk the walk. They also must respond fairly to both positive and negative feedback. Know their limits. When leaders have exhausted their own skill sets, they need to be willing to reach out to others for guidance.How can executives exercise ethical leadership in a hybrid environment? Steven recommends being creative. Use technology when it is helpful, but look also to face-to-face, in-person interactions as well. Setting up regular check-ins with the team can be particularly useful.At those meetings, encourage people to share their ideas on all the issues. It will make them feel more comfortable raising their hand, knowing they are in a safe environment.Also, remember that different cultures around the globe have their own unique ways of seeing things and behaving. Take the time to understand those differences and communicate sensitively.Finally, he discusses what to do when an employee comes forward with a concern. His central advice: listen, listen, listen.Listen in for more and then be sure to join him at the 2023 SCCE European Compliance & Ethics Institute.

View Details

By Adam TurteltaubAt the 2023 HCCA Compliance Institute, which takes place April 23-26 in Anaheim (and in a virtual format  April 24-26), Niurka Adorno-Davies, AVP Compliance, Molina Healthcare, and Scott Intner, Chief Compliance Officer, GW Medical Faculty Associates, will be leading the session “Swimming with Sharks: A Compliance Officer’s Guide on Working with Legal Counsel.”Their session, and this podcast, will examine some of the friction points in the Compliance-GC relationship and how to make things go smoother.There are a number of causes of stress in the relationship, they explain. A GC controlling access to the board and senior leadership is one of them. Having legal as the gate keeper can be detrimental to the relationship and the effectiveness of the compliance program.  Another cause for stress is overlapping responsibilities. If legal and compliance are unsure where one ends and the other begins, the lack of clarity can lead to turf battles or issues falling between the cracks.To make the relationship a positive one they recommend beginning with respect for each other’s role. Second, compliance should be sure to give legal a seat at the table as soon as a potential issue is identified. Having them as a part of the team early can yield multiple benefits. Also, don’t overstep your role and start giving legal advice. That’s for them to do.To protect privilege, be prudent when confronted an issue that may lead to litigation or a settlement conversation with the government. Bring in the GC’s office, or if your organization doesn’t have one, reach out to outside counsel.Outside counsel may also be helpful if the investigation is likely to involve senior leadership or delves into an area of specialized expertise that in-house counsel lacks.Finally, be sure to share information both ways, understand each other’s roles and embrace a commitment to respect.Listen in, and be sure to check out their session at the Compliance Institute.

View Details

By Adam TurteltaubSo what do escalators in Japan have to do with compliance and ethics? As Christian Hunt found, quite a lot. In this podcast the author of Humanizing Rules and founder of the consultancy Human Risk shares an interesting tale.A community outside of Tokyo found that the rate of injuries on escalators to and from train platforms had grown alarmingly high. The culprit was a tendency of some people to walk or run on the escalator, rather than just stand there. They ended up jostling other passengers, many of whom were older. This led to several injuries.To combat the problem a campaign was launched requiring people to stand on the escalators. Signs were posted telling people that hurrying up or down the escalator was prohibited. There was no rigid enforcement, just a reliance on people’s goodwill.At first there was near universal compliance. People saw that no one else was running or walking on the escalators, which provided social proof that standing was the only acceptable behavior. Also, with so many people just standing, it was more difficult to get by them all, effectively forcing people to stand where they were.Not surprisingly, injury rates plummeted.Over time, though, compliance rates dropped. For some, resisting the urge to hurry and not be late was just too strong, but, happily, injury rates remained far lower than their peak.As Christian explains, this case of what he calls “compliance in the wild” – something compliance-related we see in everyday life that we can learn from – provided several lessons for compliance teams: Maintaining 100% compliance is extremely difficult for long periods of time Even less than 100% compliance can be a big win Battling human urges (including simply feeling you are late) is extremely challengingHe also provides a warning that, when seeking to influence human behavior one must be mindful of not annoying them any more than you need to. If you go too far, it may well provoke bad behavior elsewhere.Listen in, but maybe not while riding an escalator.

View Details

By Adam TurteltaubVeronique Roedolf, the Brussels-based Chief Compliance Officer at Solvay, was focused on developing and enhancing the compliance program.  As she shares in this podcast, the company evolved their efforts and developed what they call a “Four Cluster Compliance Program.” The clusters are:Protecting a Culture of IntegrityA culture of integrity, as they defined it internally, is about not just following the law but also acting with integrity according to the organization’s values.Building a Strong Speak-Up CultureHere they sought to raise the bar, overcome regional differences and help everyone understand that speaking up is not a negative thing. When done in good faith it enables the culture of integrity.Increasing Third Party OversightThese days every organization is only as strong as its weakest third party. Due diligence was expanded to include human rights and environmental issues.Addressing and Mitigating RiskCompliance and risk management are very much connected. The goal was to detect and address a broader spectrum of risk in an early stage.Overall the focus is on prevention, which goes hand in hand with being more efficient and effective as a compliance program.To achieve their goals they worked to become more embedded in and supportive of the business. They secured management commitment by involving leadership from the start. They also made sure there were opportunities or feedback and to have an impact.To launch and sustain the program the compliance team developed a strategic communication plan with consistent and repeated messaging around two key communication points: Acting with integrity in everything we do Thank you for protecting our culture of integrity at SolvayListen in to learn more about the development and implementation of the Solvay Four Cluster Compliance Program.

View Details

By Adam TurteltaubESG, or Environmental Social and Governance efforts, may not be a mandate quite yet for healthcare providers, but already there are heavy demands for ESG-related information from regulators, the public and bondholders.As organizations pull together the data they need to report, says Rebekuh Eley and Rick Kes of RSM, it’s important to make sure that you have a thoughtful process behind it so that the data is accurate, consistent and complete. The last thing an organization wants is to have faulty data.At the same time, many organizations only scratch the surface of what they can take credit for in terms of increasing health equity for the communities they serve or improving their environmental footprint. That information can be helpful in meeting federal tax compliance requirements.While some may see ESG as something new and different, they note that community health is squarely under the S (Social) aspect of ESG.Keeping a good score on your ESG efforts can help demonstrate that your organization is meeting its obligations to the community and 501(r) requirements. It can also earn you credit for your environmental and governance efforts, including the number of community members who are on your board.Listen in to learn more about ESG and its role in healthcare

View Details

By Adam TurteltaubLondon-based Keith Read (LinkedIn) is a longtime member of the compliance community and author of the book The Unconventional Compliance Officer: Doing Things Differently. He laments the fact that compliance officers spend their time “pushing”, as he describes it: pushing training, reminders, policies and so forth. That, he believes, leads to compliance fatigue and pushback.Instead, he is an advocate for creating pull, where employees don’t see compliance as a chore but as an asset. In this podcast he outlines several intriguing practices he has used throughout the year to stimulate pull: A compliance passport system to provide a more formal and valuable certification for employees of their achievement in meeting their compliance training requirements A competition to identify compliance and ethics issues, which exposed some genuinely real issues Creating “licensed professionals”. For example, by completing compliance training you are then licensed to perform your job. This helped identify gaps and tighten up the procurement process. Instead of just auditing third parties, providing them with a grade, similar to what is often done for health and safety ratings at restaurants. Vendors came to use good ratings as a badge of pride internally and to help them win additional businessListen in to learn more about these ideas and others that could stimulate new ways to think about your compliance and ethics program.

View Details

By Adam TurteltaubPharmaceutical and medical device companies use a number of methods to market their products. Among them, speaker programs get the most attention, often for all the wrong reasons. As Radhu Inguva (LinkedIn), Director of Compliance, The CM Group explains in this podcast, while these programs are designed to educate the medical community they often lead to wrongdoing, with “educational sessions” held at wine tastings, lavish dinners and even Hooters.To avoid problems, she and others are advocates for what is known as the optics test:  basically, asking how a program would look, sound and feel to others. If it doesn’t seem right, it probably isn’t.From a practical perspective, she advises looking at all aspects of the program. Are the menu selections appropriate? Is alcohol served (which it shouldn’t be)? Is there an appropriate amount of educational content? Is the venue consistent with learning? Are there some doctors attending the same program again and again for no apparent reason other than the free lunch? Are the speakers being paid an appropriate honorarium?Then, after a program concludes, spend time making sure that it makes sense from both a business and optics perspective.It isn’t just pharma and medical device companies that need to look at the optics. Health care providers are looking at them, too, with some creating blacklists of restaurants that they will not allow people to visit for presentations.Listen in to learn more about what makes for a speaker program that’s safe to listen to.

View Details

By Adam TurteltaubProvidence is a US-based healthcare system with over 165 years of history behind it. But, the Providence Global Center in India started just in 2020. It was founded as an engineering and operations hub and has a startup culture.Anitha Vittal, Head, Risk and Compliance, was charged with getting the program off the ground. To get things started she first spent time talking with staff. Happily, she learned that attitudes towards compliance were very positive. While each person may have had a different definition of compliance, there was an eagerness for guidance and, for some, to have others responsible for managing the many legal and regulatory requirements.After considering how to make the program effective and relevant, she ultimately decided to leverage the start-up culture and position compliance differently. Instead of speaking of it as a control, she positioned it as a way to make each endeavor successful.This approach includes three key elements: Each new hire, as part of their two-day orientation, is given a thirty-minute introduction to the compliance program featuring an engaging story-telling approach A compliance champions network Encouraging a speak-up cultureIn addition, the risk assessment results were characterized in a new way, with each area labeled either “asking for help”, “may need help in the future”, or “no help needed”. Using this nomenclature, she found, was much more successful at providing dimension to risk areas.Looking to the future, 2023 plans include embedding compliance into the organization’s DNA, exploring opportunities for insourcing resources, and leveraging technology to enhance productivity and bring efficiencies.Listen in to learn more about what she and Providence are doing.

View Details

By Adam TurteltaubOn December 7, 2022 The Speak Out Act became law. Stephen Paskoff, the President and CEO of ELI explains that the law was spurred by the #MeToo movement and the Non-Disclosure Agreements (NDAs) that limited recourse available for victims. It was designed to make it easier for victims to come forward, and for improper behavior to remain hidden.The new law, limits the ability of employers to include NDAs when it comes to sexual assault and harassment. Specifically, it states: With respect to a sexual assault dispute or sexual harassment dispute, no nondisclosure clause or nondisparagement clause agreed to before the dispute arises shall be judicially enforceable ininstances in which conduct is alleged to have violated Federal, Tribal, or State law.As a result of the law, compliance teams, no doubt working closely with HR and the general counsel’s office, will need to work to ensure that NDAs for sexual assault and harassment are no longer used internally or even externally with vendors. Existing agreements will need to be reviewed as well.Organizations will also need to recognize that the balance has shifted, making it easier for employees to air grievances publicly.To get ahead of this issue, they will need to take several steps that they likely should have already, including stressing standards and the value of respect. Training to prevent the bad behavior in the first place will be even more important, as will be good controls to catch it quickly when it happens.Listen in to learn more about what The Speak Out Act means for your compliance program.

View Details

By Adam TurteltaubPerhaps the biggest non-Covid change in the corporate landscape over the last few years has been the growth of the Environmental Social and Governance (ESG) movement and its call to measure business on more than P&L statements. While some consider it a passing phase, Stuart Pardau, Associate Professor of Business Law, Professional Practice at Miami Herbert Business School at the University of Miami, thinks it is here to stay.As proof he points out that BlackRock, Vanguard and State Street, with a combined $20 trillion in assets, have stated their commitment to making investment decisions informed by ESG considerations. He also notes that the SEC has proposed new rules to standardize climate-related disclosures.On the corporate side, bonuses are increasingly tied to ESG metrics, and annual reports are featuring ever more language on the topic. Organizations are also more willing to take a stand on social issues.With this revolution, though, has come new risks, he notes. Greenwashing – making marginal or fraudulent environmental claims – has grown to be a serious issue with the potential for reputational damage.With this and other risks have come new challenges for compliance programs. Compliance teams need to help in the assessment of which ESG risks are greatest for their organization. In addition, they must keep in mind that not all of these risks come from aspiring to be a better organization. Some, whether around environmental, forced labor, or other issues, already have laws behind them.There is also an internal risk around corporate culture. If there is a gap between the professed values and the everyday actions, the chances of a public and embarrassing failure are great.Listen in to learn more about where ESG is going and the role of compliance along the way.

View Details

By Adam TurteltaubThe Gramm-Leach-Bliley Act (GLBA) is typically referred to in the context of financial institutions. It requires offerers of consumer financial products to explain how they share information and protect sensitive data.It’s not, however, only banks that fall under GLBA’s umbrella. New rules will affect retailers offering credit terms to their customers, higher education institutions that administer federal student aid and others a well, explains Kayne McGladrey, Field CISO for Hyperproof.The FTC, has set June 2023 as the deadline for compliance with the revised GLBA Safeguards Rule. It requires that affected organizations: Have a qualified individual to implement and enforce an information security plan Conduct a periodic cybersecurity risk assessment Implement cybersecurity controls to manage those risk Document who has access to customer data Assess the risks of applications that can access the data Securely destroy old data Periodically test the controls to verify their effectivenessIn addition, staff needs to be trained, there must be a written incidence response plan and ongoing testing.It is a considerable commitment, Kayne points out, but since it overlaps with the requirements of the European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), many organizations may already have significant structures in place.Even so, it’s important to conduct a gap analysis, he advises, to ensure all the requirements are being met.Listen in to learn more about what Gramm-Leach-Bliley now requires for your organization.

View Details

By Adam TurteltaubLast year was an eventful one for the world and the compliance profession. In this podcast, Matt Kelly, Editor and CEO of Radical Compliance, looks back at what he sees as the biggest events, and looks into the future.The conversation begins with the impact of the war in Ukraine. He observes that the increasing number of sanctions of Russian individuals and entities, as well as the variations from country to country, have forced companies to improve their sanctions compliance efforts. The sanctions have also complicated procurement, forcing organizations to review their suppliers more carefully to avoid sanctions issues.With the war has also come of host of ethical considerations. Organizations have had to decide what to do with their Russian operations and the people that work at them.Also on the international front, 2023 brought increased cooperation among prosecutors, with a rising number of anti-corruption enforcement actions combining the resources of prosecutors in multiple countries. ABB, Glencore and Danske Bank are three notable examples.This activity comes at the same time as Europe continues to lead the world in privacy and data protection requirements.Looking domestically, he points to statements by Lisa Monaco at the Department of Justice and the push to require certification of the effectiveness of the compliance program by the CEO and chief compliance officer. This could be a dramatic shift for compliance programs.  On the one hand, it could create stronger ties between the CEO and compliance, Matt observes. On the other hand, compliance officers would see greater personal risk, especially given the real likelihood that, despite a strong program, wrongdoing may occur.Whether certification truly becomes established practice, though, has yet to be seen. Thus far it has only been imposed in the context of recently signed DPAs. As a result, certification will come in three years, if at all. He notes that a change in Administration could see a reversal of the policy.What does he see in 2023? For one, a need for compliance teams to improve their ability to access and analyze data. The US Department of Justice has made it clear that it expects organizations to have robust compliance data analytics processes.Second, he sees increased data protection enforcement actions, both abroad and in the US.Listen in to learn more about what happened and what to expect for your compliance program in the year to come.

View Details

By Adam TurteltaubIt’s critical for patients leaving the hospital for a post acute care (PAC) provider that the handoff be conducted well. Some facilities will be better suited to the patients needs than others, which is why the process needs to be handled properly, with discharge planners making recommendations based on patient need, rather than the financial interests of the hospital or PAC.Unfortunately, explains Beth Kastner, Member, and Shannon DeBra, Senior Counsel, at Epstein Becker & Green, that’s not always the case. Patient steering and charting can take place, with bad outcomes for everyone involved.While there is no official definition of patient steering, it has been informally defined as the practice of directing patients and/or their caregivers to PAC providers that do not align with the patient’s goals of care and treatment plan. It can also be defined as inappropriately influencing the patient and/or care giver.Traditionally this occurs when the hospital, or its discharge planner, has been remunerated in some way by the PAC. As recent cases have shown, that could come in the form of gift cards, massages or even a free cruise. It might also be delivered as staffing for the hospital paid for by the PAC.Whatever the form, it’s improper and could lead to a very large settlement and termination of the Medicare provider agreement.Patient charting is a scheme in which a PAC is given access to patient data to identify patients for referral to their facility. It’s a practice that holds multiple risks, including anti-kickback and privacy.So how can a hospital stay ahead of this risk? First, train the staff that remuneration comes in many forms and carries substantial risks. Second, reinforce that discharge planning must be done in the best interest of the patient. Third, watch carefully, including ensuring that all arrangements are in writing and reviewed by legal or compliance before signing.Listen in to learn more about the issue and the do’s and don’ts of preventing patient steering and charting.

View Details

By Adam TurteltaubIn December 2020 the Pandemic Response Accountability Committee (PRAC) issued the report:  Insights on Telehealth Use and Program Integrity Risks Across Selected Health Care Programs During the Pandemic. To better understand the PRAC and the report, we spoke with Erin Bliss, Assistant Inspector General for Evaluation and Inspections at the Office of Inspector General for the Department of Health & Human Services.As she explains in this podcast, the PRAC was formed as an outcome of the CARES Act. Its mission is to promote transparency and coordinate oversight of the federal coronavirus response; prevent and detect fraud, waste, misuse and mismanagement; and identify risks across agencies. The Offices of Inspector General from HHS, Justice, Veterans Affairs, Defense, Labor and Office of Personnel Management are all PRAC members.The report revealed how great an increase there was in telehealth. In the first year of the pandemic, telehealth usage increased from roughly 3 million people across six federal programs to 37 million. This change was largely the result of an expansion of the Medicare rules, which previously had limited telehealth to rural communities during in-office visits.While few today dispute the value of telehealth, that does not mean its use has not come without challenges. More data, the report notes, is still needed for oversight of telehealth’s use and impact, particularly on quality of care. In addition, data collection policies need to be improved since many providers have kept only rudimentary information.At the same time, the report identified activity that indicated waste, fraud and abuse. These included billing the same service twice, billing for extremely high amounts of telehealth services, billing for services that did not seem appropriate for telehealth, and billing at the highest, most expensive level.If there is good news to these findings, it is that the risks are ones already familiar to healthcare providers. Established risk management and compliance tools will likely be useful.Listen in to learn more about what the report revealed and what steps you can take, including active monitoring, to ensure the integrity of your organization’s telehealth services.

View Details

By Adam TurteltaubCompliance programs start with the laws and regulations, but compliance failures begin with people. That’s why, argues Jochen Vankerckhoven (LinkedIn), founder of Antwerp-based Compliance Explained, that it is essential to take an audience-driven view of compliance programs.What that means in practice is designing and implementing a program that is suited for the people who are the intended audience. It also means valuing your audience and realizing it is one of the main pillars of a successful program.Think, he advises, of your compliance program as having two parts: a front and a back end.  The front end is what the workforce sees. Then consider what the right message is and the right time to deliver it so it has the most meaning to your audience.Be reasonable with your communication goals. Strive for a not a deep understanding of a topic but awareness of an issue and where to go to get help.On the backend, have the right controls in place and recognize that it is better to prevent a problem in the first place than to rely on those controls.Listen in to learn more about this unconventional approach to thinking of compliance programs.

View Details

By Adam TurteltaubAuditing and monitoring is a required element for an effective compliance program, but it also carries with it a host of benefits. In this podcast, Jessenia Cornejo (LinkedIn), Chief Compliance Officer for Bridge Diagnostics and Brittani Summers, Compliance Manager for Sprinter Health, outline all you can get from a robust auditing and monitoring program and how to create one.Benefits of a strong auditing and monitoring program include: Measuring the effectiveness of your compliance program Identifying criminal or malicious conduct Highlighting risk areas Accountability Transparency Continuous improvement (which the government is looking for these days) Greater collaboration with other departmentsIn addition to all these benefits, a strong program in this area can be enormous dividends when a regulator of the Department of Justice comes knocking at your door.When launching an auditing and monitoring initiative they recommend putting a work plan in place. It will enable you to manage the implementation to your goals and objectives. Be sure to include scheduling, they advise. It will help you stay on track.Then share the plan with leadership or the compliance committee. That will help ensure buy in, identify constraints and risks, and help you get any additional resources you may need.They also offer one simple, but important, piece of advice: don’t try and do everything all at once. Don’t wait until everything is in place before beginning. Instead, focus on the top risks as soon as you can.Likewise, don’t try and audit everything all at once. It can be better to tackle one item at a time.Listen in and learn more about how to make your auditing and monitoring program a success.

View Details

By Adam TurteltaubWith increased focus on the board’s oversight of compliance programs by the US Department of Justice and the Delaware Courts, there is a strong case for adding compliance officers to boards of directors, and many compliance professionals have the skills.  Few, though, have been able to make the leap.Haydee Olinger (LinkedIn), Sr. Advisor at Barker Gilmore, and former longtime chief compliance officer at McDonald’s, is one of the few who have. She has now served on the board of two publicly-traded companies.How did she do it? She was able to find her way onto the first board through a combination of networking, and by virtue of the fact that she had such deep experience in the quick serve restaurant category.Her journey is a good reminder to compliance professionals that your position doesn’t just mean you have expertise in compliance. You also have expertise in the industry in which you work. The compliance role gives you insight into all the various aspects of the business. It’s an asset not to be downplayed when pursuing board positions.Despite have worked with boards as a compliance officer, she reports that serving as a board member greeted her with many surprises. For one, board members don’t have the opportunity to settle in and learn the business. They have to hit the ground running and address a wide range of issues, which these days include the lingering impact of covid, supply chain challenges, inflation, labor shortages, IT security and, of course, compliance.Second, as a board member you have to reorient your thinking away from an executive whose job it is to get things done to a role of strategy and oversight.That means as a board member you need to stay out of the weeds. One implication for compliance officers meeting with the board: don’t bog it down in detail. Instead focus on corporate risks, their likelihood of occurrence and what is being done to mitigate them.While in the meeting, listen carefully to board questions to anticipate what they will need for future meetings. Between meetings, build a relationship with the relevant committee chair, board chair and even individual board members. The more interactions you have with them, the easier it will be to anticipate what they will want to know.Listen in to learn more, and, perhaps, start thinking about how you can make the leap to board membership.

View Details

By Adam TurteltaubA lot of people, myself included, have wondered what it would be like to live and work, abroad. Matt Nobles, Chief Compliance Officer – Middle East & Africa for GE Gas Power has lived the life, even as a child. As he shares in this podcast he spent his childhood as an ex-patriot kid living in Southeast Asia, and for many years now he has lived in Dubai.It’s a life he has enjoyed greatly, meeting people from all over the world, and experiencing a wide range of cultures, food, music and art. It has also enabled him to expand his network and count friends all over the world.His family has benefitted too, with his children enjoying an experience they would not otherwise have had.In terms of one’s career, time spent in another country can have many benefits. A short-term assignment in a difficult region could leave to promotions when returning home. Alternatively, one assignment abroad could to another and another, and a life of living all over the world.So what should you do if you have the desire to live and work abroad? First, he recommends considering the unique aspects of the region you are contemplating, the cost of being far away from family and the opportunities in that region versus others.When you get to your new posting, he recommends spending the first 90 days listening as much as possible. Connect with your local team, learn their compliance challenges and the local dynamics. These include cultural, geopolitical, and legal factors.Next dig into legacy issues to understand what has gone wrong in the past, and how it has been fixed, or still needs to be.On the personal side, the first thing, of course, is getting yourself and family settled in. Then build out a local community for yourself to make the experience more enjoyable for you and your family. Be sure to take advantage of local experiences. Expat blogs and even books can be very helpful in helping you understand the region and the local mindset.One mistake to avoid, he warns, is trying to focus on the American or Western way of doing things. Don’t go charging in with a fixed view. Instead, listen carefully to learn how things are done locally.Listen in to learn more, and then, maybe, start packing your bags.

View Details

By Adam TurteltaubWith enhanced concerns and vigilance over cybersecurity has come an increasing number of yardsticks that organizations much measure themselves against. As Troy Fine, Director, Risk and Compliance at Drata explains, in addition to legal requirements such as the European General Data Protection Regulation (GDPR), HIPAA and the California Consumer Privacy Act (CCPA) two key standards have emerged: SOC2: This standard was developed by the accounting body ISACA and is primarily of import to US-based technology companies and startups. Audits are performed by CPA firms on internal controls related to security ISO27001: More popular in Europe, it is a certification on information security management systems, examining how risks are identified and mediated and what control plans are in placeTo prepare for an audit he recommends first getting a good understanding of the relevant standard so you understand all the elements it requires and what it will take to meet those requirements. Next determine when you will need the certification in hand and start building a timeline backwards to determine when you need to start. Calculate, too, what it will cost in terms of time, people and everything else, including the price of the audit.How you work with the auditor will depend largely on which audit you pursue. He explains that SOC2 audits allow for more consultation than ISO27001 does.When hiring an auditor, it can be tempting to use the one with the lowest price. He recommends, though, being careful before going down that route since the auditor is likely to have less time to give.Be sure also to ensure that the auditor has the necessary expertise to be able to evaluate your technology. Some may not be as well versed on various elements, including cloud services, as they should.Once the audit begins, compliance teams can be helpful by ensuring that all the data and people the auditor needs are available. And, he advises, be transparent, even about your gaps.Listen in to learn more about having a successful data security standard audit.

View Details

By Adam TurteltaubPersonal data, especially in healthcare, seems to breed on its own, which is why, like the dinosaurs in Jurassic Park, it’s critical to keep close tabs on where it is and how it is used. First stop: a data inventory.Nick Weil and Mayesha Awal (LinkedIn) of Epsilon Life Sciences explain that a data inventory is necessary because often organizations don’t have a strong handle on their data. You need to take a noun and verb approach, they explain. The noun addresses where the data is: what computers, servers and file cabinets it is stored in. The verb speaks to what is being done with the data. What are the processing activities? What functions are accessing the data?It's good information to have for its own sake, but under data protection regimes ranging from GDPR in Europe to HIPAA in the US, it is essential.It is also a project that is often filled with surprises. Compliance teams conducting an inventory may discover a wide range and types of data processing activities. These can include GPS information, payment card method, biometrics and much more. Plus, of course, there are the number of ways that vendors may be using the data, and what information may be in the Zoom call that just got recorded.Listen in to learn more about how to uncover and manage the data in your organization’s inventory.

View Details

By Adam TurteltaubThe holidays are here, and with them come good tidings of comfort and joy, and increased corruption risk. Holiday gifts, both given and received, can lead to serious compliance challenges.In this podcast Richard Bistrong of Front-Line Anti-Bribery warns that 2022 may be particularly difficult. For many this will be the first time in several years that they have had the opportunity to connect face to face with customers and vendors. There may be a desire to catch up for lost time, and the rules of the road for giving may have been forgotten. Some may even be tempted to dip into their own pocket to keep the gift off the books.Making things difficult is that it’s difficult to find a rule of thumb for gift giving that reflects all the various nuances from culture to culture around the globe. However, employees can learn to look to the code of conduct, reach out to managers and contact compliance to ensure that they are staying between the guardrails.It’s important that workers know that the rules apply to gifts given to government officials and also to employees at other companies. Commercial bribery is a real risk, and a gift that may be perceived as creating an obligation of some sort is not appropriate.Even charitable giving may be problematic. Although a part and parcel of the regular giving of many industries, it’s important to ensure that the funds are being used appropriately and that the charity is not tied closely with a government official.In general, organizations need to embrace reasonable and transparent gift giving. To that end, a gift registry can be extremely helpful, tracking both what is given and received, as well as any gift giving plans.Finally, don’t forget to train employees on what gifts they can accept, and to warn them that it’s easy, as Richard learned, for a seemingly innocent gift to lead them down a dangerous path.

View Details

By Adam TurteltaubHarsh Kariwala, CEO of VComply, warns that traditional tools for managing compliance programs, such as spreadsheets, may be hurting your compliance program. They often are not scalable and can lead to inefficiencies and unnecessary complexities.Automating your compliance program can be a natural choice, but organizations may resist doing so out of budgetary concerns or mindset. Budget is typically of greatest concern for smaller organizations, which have less to spend and are eager to build or sustain their cultures.If your organization is ready for automation, he recommends identifying the tools and technology that you would want, followed by defining what process you want to start with.Take a phased approach to automation rather than trying to do everything at once. Pick one area to start, and analyze what is going right and wrong in the process. This will give you a better sense of the tools you will need and challenges you face.Measure success by the value it provides to the end user in areas such as time saved versus manual projects and potential penalties that are avoided.Finally, he advises avoiding the mistake of trying to do everything at once. So, take the first steps now, and listen to the podcast, but not all the podcasts.

View Details

By Adam Turteltaub

A compliance budget is a lot more than the numbers in it, explains Betsy Wade (LinkedIn), Chief Compliance & Ethics Officer at Signature Healthcare. It should be a reflection of the organization’s priorities and risk profile.

The budget is also a point of focus of the US Department of Justice when examining a compliance program during an investigation. Their Evaluation of Corporate Compliance Program guidance for prosecutors asks not only if there are sufficient resources but if they are allocated on a “risk-tailored” basis.

So, what is the right budget to have? To determine that answer she recommends compliance teams do a risk assessment and determine what mitigation efforts will be needed. In addition, benchmark against other organizations to learn what they are spending and doing. Just try to make sure that you do so against as similar a business as possible.

Look also to publicly available resources such as benchmarking surveys from HCCA and SCCE.

Keep your eye out, too, for what regulators and enforcement authorities are saying. US Assistant Attorney General Kenneth A. Polite, Jr., she reports, recently called for compliance FTE for every thousand employees.

The compliance budget should include the cost for all that compliance personnel. Also in the budget should be any travel, certification costs of staff members, staff training, services purchased, and more.

To win management approval, she recommends continued analysis of the budget and making adjustments. She also advises using the risk assessment as a tool to support the compliance team’s budget request.

Listen in. Doing so won’t add a penny to your budget.

View Details

By Adam Turteltaub

Go back roughly twenty years and you wouldn’t find a country in South America that had corporate criminal liability laws. Today, though, the picture has changed dramatically.

Felipe Sottorff Araya (LinkedIn), a compliance consultant from Chile who recently moved to the US, reveals that half of the countries now have corporate criminal liability statutes, the latest being Colombia.

That doesn’t mean they all have the same laws. There are significant differences among the countries when it comes to triggers for corporate criminal liability. Some have adopted broad rules; others have taken a narrow route.

There are common elements, however. Bribery is treated as a corporate liability trigger throughout. In addition, the crime has to be committed to benefit the company.

Another common element: expectations for compliance programs. Each country follows the seven elements approach found throughout the world.

Listen in to learn more about the changing landscape of corporate criminal liability and also learn where organizations are most likely to fall short in their compliance efforts.

View Details

By Adam Turteltaub

The Winchester Mystery House is both an unusual tourist destination, and a good metaphor, as it turns out.  Built by an eccentric heiress who never stopped making changes and additions to it, the home is filled with dead-end passages and stairs that lead nowhere, a result of the constant building. Ultimately it grew to 24,000 square feet, 10,000 windows and 2,000 doors.

In this podcast, Deena King, author of Compliance in One Page and a working compliance professional, tips her hat to Andrew Nebbett of Ethisphere and the warning to avoid creating a Winchester House of a compliance program.

Too often compliance programs have one piece of another built onto them as they grow to accommodate more risk areas and parts of the organization. Worse, sometimes those pieces operate independently, leading to redundant efforts and a lack of cross pollination of ideas.

To avoid this chaotic mishmash, she advises pursuing what she calls “strategic compliance”. Instead of focusing on the seven elements of the program, focus on the ultimate goal: to prevent, find and fix problems. Then treat the elements as a means, not an end.

Develop a strategic model, she advises, and then push it out through the organization. It helps prevent additions that are separate from the main program and don’t really fit with it.

Set up, too, a network for your compliance teams to communicate with each other, share insights and avoid learning dead ends.

Listen in to learn more, and let us know if you’ve been to the Winchester Mystery House.

View Details

By Adam Turteltaub

The compliance team has a new initiative, or you need to tell the business unit that, if it wants to get into a new line of business, a list of compliance requirements need to be implemented. Even if there is no overt pushback, there may be some very severe reservations.

Doubt mining, explains Alan Wilemon (LinkedIn), Head of Privacy at Stellar Health, is about getting people to give feedback about what they are nervous about and what they feel will not work in a project. Put another way, it’s about searching for why they have doubts about the project and whether a goal can be achieved on schedule.

So how do you mine those doubts and identify where the risks are? First, create a safe environment and invite them to speak up. Reach out to project stakeholders first. Then, secondarily, talk to any people who have been spoken for in the meeting. If people are “volunteered” to be a part of the project, talk to them as well.

Also, avoid asking for questions or concerns only at the end of the meeting. At that point many people are eager to leave and won’t say or want to hear anything. And even if people do want to discuss the issue, you will quickly run out of time.

Instead, invite comments earlier and ask them questions such as “Do you think we are being too aggressive?” You need to be the first to admit that there may be issues and the plan could be improved.

Listen in to learn more, and then become a doubt miner.

View Details

By Adam Turteltaub

Whether you call it a layoff or a reduction in force (RIF) it’s a stressful time for the organization and the people who work there. Research shows that people under stress don’t make the best decisions, which could raise compliance risk. Plus, it is always feared that some may make retaliation claims in order to preserve their jobs.

Roxanne Petraeus, co-founder and CEO of workplace compliance training company Ethena, says that the good news for compliance teams is that they should continue to focus where they always have: the culture. The bad news is that culture and trust are both damaged during a RIF, which can lead to both an increase in misconduct and a decrease in reporting.

Because of that, communication is more important than ever, she observes. Employees are hungry for more information. And don’t forget another form of communication: just being visible. Let them know that you are there for them.

Other advice she offers:

Remind employees about the organization’s policies Embrace the idea that more is better Train effectively in a targeted way, such as focusing on the code of conduct Get in the habit of conducting regular surveys of the workforce

Listen in to learn more about how to better manage compliance programs during layoffs.

View Details

By Adam Turteltaub

There has been a lot of discussion over the last few years about nudges, although typically in the general business environment, rather than in the world of compliance and ethics.

A notable exception has been the work of Todd Haugh, Associate Professor of Business Law and Ethics at the Kelley School of Business at Indiana University, and a Board Member and Jesse Fine Fellow for the Poynter Center for the Study of Ethics and American Institutions. He has written about nudges and offers additional resources on behavioral compliance.

In this podcast, he explains that behavioral science has revealed that nudges – carefully crafted prods to make the right decision – can have a profound impact. A nudge takes advantage of choice architecture, which pushes people in a direction by structuring the environment in which choices are made.

Notably, this is not about tricking people. This is a pro-social effort.

So, how does it work in practice? It begins at the end. Look at the outcome desired and then examine the steps along the way. As you do, build a behavioral map that identifies when small interventions in existing processes can achieve positive compliance results. For example, one organization was receiving more anonymous reports on its help line than it desired. The organization realized that the default setting for reporters was set to anonymous. By simply shifting the default to including the person’s identifying information, non-anonymous calls increased 5%.

Another example comes in the area of travel. When an employee fills out a travel form for a high-risk country, it’s a good time to provide information on data security and the corruption risks of meeting with government officials.

Professor Haugh cautions that it is best to think of nudges as ways to have specific impacts on certain behaviors, not to do something broad like creating a positive corporate culture.

Have reasonable expectations and then test out various nudges to see which ones are having an impact and which ones aren’t.

Listen in.  It may nudge you to think of your compliance efforts differently.

View Details

By Adam Turteltaub

Rodrigo Cunha is Global Director, Legal, Ethics Compliance and Data Protection for AB InBev. There he focuses on digital ethics.

As he explains in this podcast, when it comes to data, traditional risk management, focused on making sure that what the company is doing is compliant, is only the first step an organization needs to take. They also need to incorporate risk management in the design of the program. In addition they have to focus on reputation and trust. Without a good reputation for protecting data and the trust that comes with it, a company will have an exceedingly difficult time doing business.

Digital ethics, he believes, is a business enabler. Organizations need to look beyond the compliance requirements, especially now with requirements increasing and varying so much by jurisdictions.

Instead, it is better to think about expectations of the government, consumers and other stakeholders as a guide.

At AB InBev that assessment led to the development of five principles that they stand for wherever they operate:

Collect only the data we need Use the data only in a matter that we say we would Protect the data we have Keep only what we need Be accountable

Further thought led to the development of a sixth principle: We use data how people expect we would.

Putting these principles into practice involves a deep partnership with the business units. It includes effective training but also modifying the three lines of defense model to make sure the business unit is better able to meet the challenge. That includes the compliance team working closely with them to respond effectively whenever issues arise.

Listen in to learn more how to better embed data ethics into your organization, and hear what Rodrigo sees for the future, including a potentially dramatic shift in consumer behavior.

View Details

By Adam Turteltaub

Why is it that so often leaders in organizations fail? They seemingly had all the skills, accumulated all the experience, and then something went wrong, sometimes disastrously. Not just the CEO, it can be leaders at other levels in the organization.

Bret Hood (LinkedIn), Co-Founding Partner of 21st Century Learning & Consulting provides some fascinating answers to that question in this podcast in which he draws from, amongst other things, his 25 years in the FBI.

He explains that as individuals move up the organizational ladder feelings of empathy may start to deteriorate without the person realizing it. They may grow to become self-centered, taking credit for the success of others, and distributing blame for failures, including their own.

This can be coupled with what he calls “illusory superiority”: the belief that you are better than everyone else. Most of us suffer from that to a degree. A very disproportionate percentage of people feel that they are smarter than their peers or even a better driver than most. In an exercise he frequently does, rarely do more than 3%-5% believe that they are in the bottom half for leadership skills. Clearly, it’s not possible for 95% to be in the top half.

Many leaders (and others as well) also suffer from what he refers to as “sunk cost bias.” A mistake is made, and instead of owning up to it there is a tendency to double down. A small fudge of the numbers in one quarter when thinking “well, it’s a small one-time dip” leads to greater fudging the next, and then on and on, rather than an honest accounting.

The bottom line is knowing your capabilities and performing an honest self-assessment is difficult. That’s why he recommends two approaches. First, think about what your gut says, and then ask: what if I made the opposite decision? What would be the consequences? This technique helps you see things from more than one perspective.

The second recommendation is to find people you respect who trust that it is safe for them to ask hard questions and offer opinions that contradict yours.

Listen in to learn more about leadership, and also the concept of followership.

View Details

By Adam Turteltaub

Exit interviews can be terrific sources of information for compliance teams, but how do you make the most of them? And do you need to be a part of all of them? That can be a very tough task in a large enterprise.

Shemekia Alexander, Director, Corporate Responsibility Officer of Mercy Health recommends focusing on live interviews with key individuals that are most likely to have insights into potential compliance issues. In her case, that includes compliance and legal personnel, the executive suite, revenue cycle staff and providers.

To get people to feel comfortable talking, she reaches out in advance to introduce herself and make the person comfortable with the process. Typically, she sends an email saying who she is, the purpose of the meeting and that it will be confidential. She also recommends that the departing employee, if the conversation will be via Zoom or a phone call, get to a place where they do not have to worry about being overheard.

During the interview she begins by explaining what she means by compliance since some are confused about what exactly compliance encompasses. She then asks several standard questions including:

Are you aware of any compliance concerns that should be addressed? How you raised any compliance-related issues previously that have not been addressed? Have you seen any associates engage in conduct that may be illegal or unethical? How would you describe the organization’s compliance culture? Is there anything else you would like to discuss?

The last, very broad questions, can be particularly helpful, opening the door for conversation.

As important as what the employees says can be how they are acting in the conversation.  She advises paying attention to their behavior: are they hesitant, disgruntled, scared, aggressive?

For those who are not interviewed face to face there are questions in an optional survey that HR provides to departing employees. Any issues raised there are forwarded to compliance.

It’s all a part of a team approach, and cultivating the team’s support is essential for success.

Listen in to learn more about how to turn an employee exit into a compliance opportunity.

View Details

By Adam Turteltaub

Third-party risk is the risk that keeps expanding. Data security and anticorruption risk have long been the focus. Now, though, the risks are broadening to include issues such as where materials are sourced and the labor that produces it.

Shu Min Ho, Partner in the Singapore office of the law firm Sidley and Sam Johnson, Senior Managing Associate there explain in this podcast that with the rapid adoption of ESG programs, the scope of risks is dramatically increasing, especially considering how much ESG encompasses.

To be effective, compliance teams need to focus their ESG third party risk efforts on those areas of the supply chain that are most likely to harm the business beyond the traditional legal framework. That means understanding your business and where the risks are. For example, in the technology hardware business that likely includes labor standards, worker protections and mineral sourcing.

Increasingly it also means looking beyond your suppliers to their major suppliers as well. That effort requires tremendous cooperation from the business unit, procurement and, of course, the suppliers themselves.

When looking at suppliers, take time to understand their business model to determine how they make money. Then watch out for signs that something may not be right. For example, if a product is suspiciously inexpensive, it may be the result of workers forced to labor long hours or outsourcing to companies with limited or no safeguards in place.

Be aware, too, that expectations are different. An environmental review in the past may have looked at how toxic waste is handled. Now, sustainability is likely much more of a consideration.

Finally, be especially sensitive to human trafficking and modern slavery. They are ESG issues increasingly subject to regulatory expectations. In fact, a separate due diligence effort may be necessary in this area.

Listen in to learn more about how ESG is calling for a second look at third party due diligence.

View Details

By Adam Turteltaub

An ethical audit is one that evaluates compliance with laws and regulations but also assess a vendor against ethical standards, explains Bruno Drummond, Senior Director, Global Compliance at DHL Supply Chain. These standards could come from an industry or other external organization or your company’s own code of conduct.  They likely would cover issues such as human rights, child labor, forced labor, discrimination, unfair and inhumane employment, working condition and even your supply chain’s own supply chain.

Why should you conduct one? Because these days regulators, enforcement and the public require it.

For a company such as DHL, with is heavily committed to ESG, ethical audits are at the top of their list. It’s a part of the company’s commitment to clean operations, being a good place to work and highly trusted.

DHL was first exposed to ethical audits when a customer conducted one of them. Seeing the value in it they adopted it themselves.

The audits are conducted both remotely and at customer locations. The DHL code of conduct is the benchmark against which the audit is conducted. Included in the process are roundtables with employees, interviews with managers and an office walk through.

Because of the cost, Bruno recommends taking a risk-based approach and looking at a cross-section of your supply chain when conducting these audits.

Listen in to learn more about the process and whether it’s time for your organization to embrace ethical audits.

View Details

By Adam Turteltaub

Most every compliance team would like the helpline to ring more, and Brooks Rehabilitation was no different, explains Compliance Operations Manager Christine Davenport (LinkedIn). To increase call volume they adopted a snappy slogan – “Better call compliance” – and put together a full marketing campaign to support it.

The efforts paid off big, doubling the number of calls over four years.

It wasn’t the slogan alone that helped. Central to their success was the combination of good internal marketing along with a serious behind the scenes effort to ensure that calls were acted on.

The team captured data on which line of business the call came from, type of issue and what response was provided. The data was kept on a shared drive to streamline the process and make it simple to spot a repeated question. This both saved work and decreased the time of response. Common areas of employee concerns included HIPAA and receiving gifts from patients.

When responding to calls, the compliance team, wherever possible, included information about the underlying regulatory requirement. This helped provide employees with context and enabled them to better educate themselves.

The compliance team also looked beyond the questions and treated the calls as a way to start a conversation and reassure employees that calling didn’t automatically get them or someone else in trouble.

Listen in to learn more about their efforts and get some ideas about how to convince your workforce it better call compliance.

View Details

By Adam Turteltaub

United States Deputy Attorney General (DAG) Lisa Monaco recently gave a speech in which she outlined both new policies at the Department of Justice (DOJ) as well as enhancements to existing ones that can have a profound effect on compliance and ethics programs.

To better understand both what she said and what it all means we sat down with DOJ veteran Daniel Kahn (LinkedIn), a partner in the Washington, DC office of Davis, Polk & Wardwell, for an in-depth and longer than usual podcast. He explains that while the emphasis on individual accountability is not new, there is a significant change. The Department expects that individual prosecutions will take place prior to or at the same time as corporate resolutions. Given the extra time it often takes to prosecute an individual, that will make it harder for organizations to reach a swift conclusion and move forward.

There is also one other significant change in terms of how individuals are treated: the Department is now looking to see if the organization is clawing back compensation from employees who committed wrongdoing, at least in those jurisdictions where it is permitted.

When it comes to leniency, the Department had previously stated that repeat offenders were not likely to receive a Non-Prosecution Agreement (NPA) or a Deferred Prosecution Agreement (DPA). The DAG’s latest comments reflected a more nuanced approach and reflect the idea that all incidents are not created equal, and that in a large organization it is possible for more than one violation to occur over time, without it being a sign of dysfunctionality.

Other notable elements of her comments:

The Department expects that when an organization seeking cooperation credit comes across hot new evidence it will share it with Justice immediately For the first time there will be policies on voluntary disclosures across all the various departments within Justice There will be a presumption against a guilty plea if a company voluntarily self-discloses, cooperates and remediates Non-Disparagement Agreement clauses will be looked at unfavorably if they interfere with whistleblowing

One other notable element of her talk, which was, perhaps, lost in most discussions about her comments, is the call for organizations to getter a better handle on messaging by employees on their personal devices.

Finally, Dan addresses what some perceive as a slowdown in corporate prosecutions over the last few years. He notes that during the Obama and Trump administration there was an uptick in cases. Any slowdown over the last two years is likely the results of changes in leadership at the DOJ with a new Administration. Bottom line is that now is not the time to assume the DOJ is not active.

Listen in to learn more about what you should take away from DAG Monaco’s comments.

View Details

By Adam Turteltaub

Good communication is a two-way street, with both sides sharing their perspectives. Yet, observes Laura Valdespino (LinkedIn), Chief Compliance Officer, Booking Holdings Financial Services USA, too often it is one way, with compliance doing the talking.

In this podcast, and in her in-person and virtual session at the 2022 Compliance & Ethics Institute, Laura outlines practices for creating a good dialogue with the workforce. It starts, she explains, by committing to listening. Engage with them, she advises, and look to creating opportunities for interactions through Q&A sessions or coffee and donuts.

Once you are there with the workforce be sure to listen with unbiased ears to what people say they want and need from compliance.

Be sure to also customize your message to the audience. Salespeople, manufacturing, IT and all the other parts of your organization will have different needs and will be listening for different information. Take the time to understand what motivates them. It helps build trust.

How you communicate is also important. Learn what the frequency of communication that works best for your workforce is. Be sure to avoid lecturing, legalese and focusing on what they can’t do. Instead keep the communication focused on the right way to achieve business goals and what we all need to do.

Listen in to learn more, and be sure to attend her session at the live or virtual 2022 Compliance & Ethics Institute.

View Details

By Adam Turteltaub

The Organizational Sentencing Guidelines have turned thirty, and what began as an experiment is now an established framework for compliance programs in the US and around the globe.

To commemorate the milestone, the United States Sentencing Commission has published The Organizational Sentencing Guidelines: Thirty Years of Innovation and Influence, which takes a look at the impact of the guidelines and what we have learned about their impact on organizational behavior.

In this podcast, the Commission’s General Counsel Kathleen Grilli identifies the three largest innovations of the Guidelines:

Incentivizing self-policing by organizations Providing guidance on effective ethics and compliance programs Holding organizations accountable based on specific culpability factors when they commit offenses

The approach has worked more successfully than had been imagined. As she notes, it has expanded beyond the criminal environment to encompass civil settlements with government agencies as well. In addition, the approach to compliance in the Guidelines has been embraced globally, with their outlines clearly visible in the laws of many nations.

Within the US, she shares, a strong difference has emerged between organizations with and without compliance programs. The overwhelming majority of organizations convicted had no compliance program at all. In fact, only 11 out of approximately 5,000 organizations had a program that a court found to be effective.

This points out that there is still room for improvement, particularly among smaller organizations who lack awareness of the need for and benefits of compliance programs.

Listen in to learn more about the remarkable effectiveness of the Organizational Sentencing Guidelines.

View Details

By Adam Turteltaub

Usually, a Compliance Perspectives podcast focuses on just one topic, but in this one Marla Berkow, Corporate Compliance Officer at Gateway Foundation tackles two: behavioral health and restorative justice.

In the first part of the conversation, we focus on the unique challenges of behavioral healthcare. They include maintaining both patient and organizational privacy. Physical and emotional safety of the staff is also important, along with a strong culture of reporting.

With many patients a part of pre- or post-trial diversions there are unique challenges created, especially in the privacy arena.

In the latter half of the conversation Marla focuses on a restorative justice approach, which she explains, is designed to differentiate between an intentional and inadvertent mistake, with discipline meted out appropriately.

With that comes a focus on ensuring the problem is not repeated.

Listen in to learn more about the challenges of behavioral health and potential benefits of a restorative justice approach to compliance.

View Details

By Adam Turteltaub

Having all the privacy policies and procedures in place is one thing. Having them practiced is another, and that’s where a privacy walk-through comes into play.

Jan Elezian (LinkedIn), Director Healthcare Provider Practice, Revenue Cycle Compliance, Regulatory Compliance at SunHawk Consulting, explains that the walk-through is a test of a facility’s privacy and security environment. It includes a tour of high-risk areas – registration, patient intake, wherever else PHI is accessed – to see what employees are actually doing. It can be used to identify how your administrative and technical safeguards are working in the real world and determine where they need to be strengthened.

Before beginning the walk-through, she recommends putting together a checklist of what you will be looking for.  Leave room for taking notes, and hold onto it. That way, when you return for a subsequent walk-through you can easily see how things have changed for the better and worse.

What should you be looking for? A variety of things including:

Is staff wearing badges? Are visitors escorted it? Are security reminders posed? Are printers improperly secured? Have papers piled up on the printer? Are privacy practices posted for patients?

Two other things to check for: fire extinguishers and smoke detectors. HIPAA requires safeguards on PHI, she points out, and that includes safeguards against fire.

After you have done your visit she recommends developing a post-assessment remediation plan. There inevitably will be corrective actions needed. Be sure to include follow up steps and dates when the work will be completed.

All this effort will help create a more secure data environment, and give management, the compliance committee and board  greater confidence in your program.

View Details

By Adam Turteltaub

Time with the board tends to be short, valuable and critical to the success of the compliance program.  Getting and keeping their attention is essential. To do so effectively, Jason Meyer (LinkedIn), President of LeadGood Education recommends keeping in mind that board members share one thing in common with the rest of us: they want to know if what you’re telling them is truly relevant to them or a waste of their time.

To communicate effectively he recommends an audience-centric approach. That means avoiding compliance jargon and focusing on terms that they care about such as “fiduciary duty”, “Caremark decision”, “oversight” and “DOJ Guidelines”. And, of course, where appropriate, “stock exchange rules”. Remember, too, that they are focused on existential risks to the organization, not the routine, everyday ones.

Stay laser focused on what is in it for them and combine hard information – what their duty or a risk area is – with scenario-based examples.

Think, too, like a marketer: repetition matters. Stress and keep stressing what’s important, but put some sizzle behind it. Avoid the pitfalls of simply echoing what management is saying and being just one more presentation. Have a message of your own to demonstrate independence and underscore the importance of a direct compliance-board relationship.

Also, don’t forget the education part of the equation. Opportunities for them to be better educated are rare, and showing you have information they could use may be the best way to get their attention.

Listen in to learn more about how to get the most out of your time with the board.

View Details

By Adam Turteltaub

Improving data security at your organization doesn’t just protect you, it can also increase your business, explain Meiran Galis, Chief Executive Officer of Scytale. Customers increasingly want to know that their business partners’ systems are secure and that critical data will not get stolen or held hostage in a ransomware attack.

To ensure that they are meeting data security standards and can provide their customers the assurance that they seek, many organizations pursue SOC 2 or ISO 27001 certification. As Meiran explains, there are key differences between the two.

SOC 2, he reports, has become the new gold standard for SaaS applications. It is generally considered of greater value in the US and is not technically a certification. An attestation report is made and independently certified. ISO 27001 is a traditional certification and is focused on information security management. It is more popular outside the US, especially in Europe.

So, should your organization pursue SOC 2 or ISO 27001? That depends on where your current and potential customers are and what they require. Ask sales if prospects and customers are already wanting a certification from your organization.

Once you decide on which certification to pursue, or if both make sense, don’t expect it to be a fast process. For small organizations it may take 250 hours of work.  For larger companies, it may take 1000 hours or more.

Once you earn the certifications, have a plan in place to continuously monitor and periodically audit your efforts.

Listen in to learn more about whether SOC 2, ISO 27001 or both are necessary to protect and grow your organization.

View Details

By Adam Turteltaub

The writing on the wall is pretty clear: regulators expect compliance programs to be custom designed for the organization and kept up to date. That means compliance teams need to stop periodically and reassess their program to ensure it is effective in practice and not just on paper.

In this podcast, LRN’s Ty Francis MBE, Chief Advisory Officer and Eric Morehead, Director, Advisory Solutions explain that regulators want to know if organizations are targeting their compliance resources to the risks that they are facing.

To allocate efforts successfully, it is essential to look at the data to see if your program is effective.

Yet, they point out, it’s not just a numbers game in which more spending leads to more results. If, for example, there is an issue with employees not speaking up and living in fear of retaliation, paying for more training is not going to be enough. Instead, compliance teams need to look holistically at the situation and address the underlying cultural issues. That includes demonstrating to employees that a manager who retaliates will face discipline.

So how do you conduct an effective assessment? First, they recommend budgeting enough time. The process tends to take longer than people think given the number of people you will need to interview and the time at the front end to gain support from leadership.

Next, make the effort to talk to people from the top of the organization to the bottom. Do so in person, or via surveys if necessary. As you do, be sure to learn how they feel about the compliance programs, the culture of the organization, violations they may be seeing and the ability to speak up without fear.

Finally, they advise looking outward. Benchmark your efforts against your peers. This can provide context and expose you to ideas and solutions you may not have been aware of.

Listen in to learn more, and then spend some time assessing your assessment program.

View Details

By Adam Turteltaub

GDPR, CCPA and HIPAA all pose daunting privacy challenges for organizations.  But, George Tziahanas (LinkedIn), Managing Director of Breakwater explains that there are many more national laws to consider. In this  podcast he takes us through five countries with laws and regulations that global compliance and privacy teams needs to consider.

The People’s Republic of China China’s law, he reports is very focused on the company’s national interest and a belief that preserving data, particularly critical data on firms and infrastructure, needs to stay in the country. The law affects whether data can be transferred outside China and under what circumstances. It also has limits on what information can shared with foreign law enforcement.

France The US Cloud Act triggered concerns in many jurisdictions around the world. The French National Security Agency established a certification program that now requires French nationals to run cloud-based services in France and limits the ownership levels of foreigners. It affects broad sectors of the economy.

Germany The largest economy in Europe is embarking on efforts similar to those in France, which is having the effect of creating digital borders in the EU. They have created a sovereign cloud, in partnership with the private sector, that affects government agencies, vital services and critical sectors of the economy.

The Kingdom of Saudi Arabia Saudi Arabia has classified certain data as needing to stay within the country. This has led to partnerships with cloud vendors to bring their infrastructure into the country.

Dubai The UAE, he reports, has long had limits on encrypted voice channels and VOIP. To gain access to cloud technology they, too, are slated to introduce new data and cybersecurity rules that are anticipated to be similar to Saudi Arabia’s.

In sum, organizations are now increasingly facing a world in which data transfers will be more complex and where data is housed will be closely scrutinized and limited. Listen in.

View Details

By Adam Turteltaub

Getting employees to come forward and raise issue can be difficult. There is often genuine fear of retaliation, and many don’t trust that the company will do anything. It’s a topic that Cindy Morrison CCEP (LinkedIn), Director, Global Ethics and Compliance, Post Holdings, Inc. will be addressing at the 2022 SCCE Compliance & Ethics Institute and tackles in the latest Compliance Perspectives podcast.

Her own journey of discovery in this area was jolted by an assessment revealing that employees did not think the company had a speak-up culture. The key to creating one, she realized, is encouraging respectful dialogue. A true, two-way discussion is necessary to help build the trust that is so essential. Employees want to be heard, and if the company isn’t listening to them, they are never going to feel safe.

Showing that the organization is listening begins with making the effort to know the employees, a difficult challenge in this remote-working world where employees tend to change jobs frequently. Still, it must be done and managers need to practice active listening and adapting communications style to the listener.

It also means demonstrating that when employees speak up, actions are taken: bad actors get disciplined or fired, policies are changed or publicly reinforced.

In addition, it is essential to remember that each facility may have its own distinct culture. That may stem from the history of the facility and who has worked there, or the ethnic makeup of the employees. It’s also important to remember that not all facilities in the same country will share a common culture. As she notes, their operation in Minnesota is 70% Somali.

Finally, she underscores the importance of constant education. Make sure the workforce knows all the ways it can raise issues and what to do if they feel they are being retaliated against.

Listen in to learn more, and then join us at the 2022 SCCE Compliance & Ethics Institute.

View Details

By Adam Turteltaub

What’s a risk assessment framework? How can it help?

Vin Lacovara, Institutional Compliance Leader, George Mason University and Corey Parker, Director, Baker Tilly, explain that the framework is a document that should be tailored to the organization’s needs and starts with an inventory of applicable laws and regulations. Next, the responsible personnel and controls that are in place should be added, followed by a preliminary prioritization of risk areas. Then, more details can be added, looking on the more granular level.

All in all, the process should take about a month. The harder, longer work comes next and involves filling out all the efforts that need to be put in place.

How often should the framework be reassessed? That depends on the organization’s priorities and how high a given risk is. Any high risk area that threatens to literally or figuratively shut the institution down should be looked at more frequently to see where the institution’s risk mitigation efforts stand.

To ensure that the framework is properly tailored to your organization, they recommend investing time in developing relationships with stakeholders to make sure their needs are met.

The most important thing is to start somewhere, don’t let yourself get bogged down, and look for the process to develop and improve over time. Perfection out of the gate is not likely.

Listen in to learn more about how to create a proper risk assessment framework.

View Details

By Adam Turteltaub

The challenge of complying with data protection laws is growing more complex, with US states increasingly having their own laws or considering adopting them. This had led many to call for one national data privacy law for the US.

Rich Hale, Chief Technology Officer, ActiveNav hopes that a national law emerges that identifies and normalizes the common threads in the various state requirements. Until then compliance needs to draw out those threads, itself, and provide clear advice on core requirements.

Compliance teams, he advises, also need to resist the temptation to boil the ocean and try to solve all the challenges at once. Instead, as elsewhere, it is better to identify and prioritize the risks. Then, work in partnership with operations to implement effective mitigation plans.

One key area to focus on is identifying what data the organization has and the justification for holding it, including understanding where the data is being used. That is often easier said than done, since many organizations do not have a full appreciation of all the uses of the data. Finding that information, he reports, is both a top-down and bottom-up exercise.

Here, too, prioritization is critical. You need to determine where the data is used most actively, including the unstructured data.

Listen in to learn more about how to get a better handle on your data in the face of regulatory complexity.

View Details

By Adam Turteltaub

Corporate culture, tone at the top, proper governance and the relationship between the board and compliance have all been frequent subjects of conversations of late. In this podcast, Marsha Ershaghi Hames, partner at Tapestry Networks, shares recent research into governing boards and their role in shaping corporate culture.

The report, Assessing Corporate Culture:  A Practical Guide to Improving Board Oversight, and the research leading up to it, revealed that culture Is most definitely a focus of directors, and there is a strong need for board alignment on what the culture should be.

Turning that vision into a reality requires building bridges and a partnership between the board and the management team. It also requires data to measure where an organization is and to track progress about where it is going.

That is not all, though. Directors who formerly held compliance roles were quick to point out that there is a need to think beyond the numbers and balance quantitative, qualitative and anecdotal evidence. All these measures are essential to developing a holistic view.

The report, which was developed after interviews with 40 directors from 65 publicly traded companies, revealed five keys to success:

Prioritize culture on the agenda The board has to challenge its own culture Monitor and measure, but also create blended data sources Ensure that the culture is articulated and simplified enough that it can be measured Calibrate the board and management structure to optimize the information flow

The last step means enabling managers, including compliance, to communicate directly with the board as needed to give it a fuller picture of the organization.

Listen in to learn more about how to help the board lead in shaping corporate culture.

View Details

By Adam Turteltaub

The 2022 Risk & Compliance Hotline & Incident Management Report from NAVEX included data that showed that helpline calls, while increasing, were not back to pre-pandemic levels.

New research from Gartner confirms that data, reports Chris Audet, Gartner’s Senior Director, Research. It also provides new insights into reporting and where organizations continue to struggle to win over their workforces.

The drop in observed misconduct reported likely reflects, he explains, a decline in actual misconduct – a reflection of less opportunity for it – and a significant change in the landscape: the type of misconduct is changing. Bullying, intimidation, unwanted behavior and misuse of time and resources are going up.

So what should organizations do with employees calling the helpline not as often? He recommends relying less on reporting and more on embedded controls, as was discussed in his previous podcast. In addition, many are seeking technologies that support narrow risk areas such as insider trading.

Gartner is also seeing an increase, he reports, in questions about wider views into risk through GRC and other third-party risk tools.

But, even with all that, the helpline is critically important to compliance programs. To increase its usage, the research suggests revisiting the value proposition about reporting. Expectations have change for the employer/employee relationship over the last few years. Feeling safe from retaliation is not the driver that it was thought to be. Their data suggest that there are other levers to pull.

Listen in to learn about what those levers are and how to use them most effectively.

View Details

By Adam Turteltaub

Melanie Sponholz, Chief Compliance Officer, WCP Healthcare, Nick Gallo, Chief Servant and Co-CEO of ComplianceLine, and Gio Gallo, Co-CEO and CTO of ComplianceLine have a simple message for compliance officers:  don’t be embarrassed about asking for the budget you need.

Historically, they report, compliance budget proposals have not been strong, and some programs have even lacked a formal budget, which is consistent with the historical perception that compliance is a cost center.

Changing that dynamic, they argue in this podcast, means taking a more positive approach and discarding any apologetic tones to the budget request. Instead, they counsel going in knowing the worth of the program and feeling empowered to create a budget based on the resources the program needs, just as other department do.

Let management know what your goals are, what it will take to achieve them, and how much of an investment is required now, they say. Also, don’t worry about the data you don’t have. Instead, focus on what you have and know, and use it to support your argument.

When presenting the budget, they offer three additional pieces of advice:

When facing feedback and hard questions, don’t freak out. It’s a normal part of the process. Anticipate objections and concerns, and be prepared to address them. Be honest.

If you can approach the budget meeting calmly and feeling prepared, you will be far better off.

Listen in to learn more, including what poker players can teach you about getting the right budget for your compliance program.

View Details

Post by Adam Turteltaub

No one likes to be the bearer of bad news, but if you sign up for a job in compliance, you are inevitably going to be one. The challenge is doing so in a way that is most productive.

Long-time compliance veteran and executive coach Amii Barnard-Bahn has invested a great deal of time in studying this challenge. She reports in this podcast that social science has discovered that bad events impact us five times more than positive ones. We are programmed not to want bad news. Worse, messengers of unwelcome information tend to be deemed unlikeable and less competent. There is even some malevolence towards them, believing, usually wrongly, that the person got some pleasure from sharing the unpleasant news.

So how do we overcome it? She developed a six-step process:

Psychologically prepare your audience Rehearse confident delivery Be present and fully focused Convey benevolent, proactive intent Explain without justifying Add a sense of urgency

Psychological preparation of the audience, she explained, is often overlooked. When people are surprised it can slow down their thinking and increase negative emotions. So, it is best to prepare people for what is coming. Then let them know what the cost will be, time involved and what needs to change.

Conveying benevolent, proactive intent is about overcoming the gut perception that somehow you were involved, wanted the incident to happen or are to blame. Chances are you were not the one at fault and you need to help people see it. When you did make a mistake, take the blame, accept responsibility and then show a path forward.

Listen in and learn more about how to make delivering bad news better.

View Details

By Adam Turteltaub These are different times. We all know that we are living in them, and that calls for different thinking. But, what does that mean? To help answer that question we spoke with UK-based Jane Mitchell (LinkedIn), an independent consultant who specializes in culture, ethics, values and leadership and Philip Winterburn, Ethics Principal at OneTrust.

As they look around at the business world they see that leaders are struggling to understand what the impact of the pandemic has been on the people that work for and with them. Given how much people have been affected by the last few years, there is a clear need to focus on culture, which Jane describes as the “corporate immune system”. It can be either an asset or liability when it comes to both preventing wrongdoing and managing the now significantly more difficult task of recruiting and retaining talent.

Meanwhile, outside the organization, attitudes towards purchasing are starting to change. Customers, whether consumers or other businesses, want to know where your goods are made, under what conditions and how the raw material are sourced. If they do not like what they see, they are turning away.

So what makes for a healthy organization in this environment? For one, broadening the conversation beyond the numbers and looking at how the organization can be smart, resilient and sustainable. That will be especially true over the next few yeas when a rocky, unpredictable economy is predicted.

In terms of leadership, it calls for CEOs who truly understand what is going on, welcome the truth and encourage people to speak up and openly disagree. It also calls on CEOs to recognize that people want to please them and may be painting too rosy a picture.

Listen in to hear more about how compliance and ethics teams can thrive and lead during these uncertain times.

View Details

Post by Adam Turteltaub

While in most cases the pandemic created nothing but challenges, Lola Adekanye (LinkedIn), Senior Program Officer for the Center for International Private Enterprise (CIPE) reports in this podcast that, in some respects, it provided some benefits.

While initiatives to encourage transparency and integrity were stretched, employees endured indefinite periods of working from home and governments were challenged with their budgets, the commitment by citizens and civil society to promote anticorruption and integrity grew.

So, even though the risk for corruption increased, there was also a rise in whistleblowing, particularly in Zimbabwe, Kenya, South Africa and Nigeria. Most of the activity in this area revolved around the acquisition and distribution of Covid-related supplies, not surprisingly.  The transportation sector also saw a rise in corruption.

Government procurement has continued to be a sore point, with many cases of collusion, price-fixing and kickbacks. But, consumer goods have seen a decline.

For the long term she sees a collision between two forces. On the one side are traditional, authoritarian regimes with higher corruption. On the other side, which she thinks will prevail, are young people and institutions coming together to find ways to hold government and companies accountable.

Listen in to learn more about the present and future of anticorruption efforts in Africa.

View Details

By Adam Turteltaub

Many organizations have grown accustomed to and developed protocols for vetting third parties for issues such as anticorruption compliance and privacy. But, with the rise of ESG, suppliers need to be reviewed for exposure on a much wider scale than ever before.  Can existing protocols be used, or do they need to be replaced?

To find an answer we spoke with Rebecca Wellum (LinkedIn), Vice President Compliance & Diversity at GEOTAB. In this podcast she explains that in many ways ESG is a repackaging of things many organizations have been doing for some time.

To make your process effective she recommends starting by defining the risk areas for your industry. Then, look at your material sourcing to understand where everything in your supply chain is coming from. Learn not just what the supplier is providing and how, but it’s suppliers practices and sources as well.

When assessing vendors, she has found that in-person meetings are invaluable. It provides an opportunity to assess the cues that something may be amiss. These can include environmental health and safety papers and certifications that are out of date or a lunchroom that doesn’t look quite rights. Data points like these can give you a strong sense of the treatment of labor, and even the organization’s own sourcing methods.

She also recommends insisting on audit rights upfront. That’s when your organization has the most leverage. And be sure, she advises, to allow for not just paper, but in person audits, including on a surprise basis.

Small and medium-sized organizations need to be aware, she cautions, that this is not a simple task, but it is an essential one. Even if the company is not public and subject to the scrutiny of the SEC and shareholders, its customers are already likely to be increasing their ESG investment and expectation of their suppliers.

She also highly recommends taking the time to document what you have done. Keep audit trails and be prepared to demonstrate what steps you took while selecting, onboarding and periodically reassessing your suppliers.

Listen in to learn more, including the growing importance of assessing diversity as well.

View Details

By Adam Turteltaub

The relationship between ESG and compliance is as of yet not a fully defined one.  That’s not surprising given both the newness of ESG and the many similarities between it and compliance.

While many see an overlap between the two, Reginald Youngblood, Associate Vice President Corporate Compliance at AT&T, sees more of an overlay with existing frameworks for managing risks.  As with other risk areas, there is a need to look at the financial impact, how often it occurs, the inherent risk and how it affects the business.

He also observes that, like compliance, ESG touches an enormous cross section of the enterprise, albeit in a somewhat different way.  By becoming involved with ESG the compliance team, he believes, can have more contact with the organization as a whole, address issues in a new way and help define what ESG means to the organization.

This approach has enabled the AT&T compliance team to open doors and become an active partner in projects that they never would have been asked to be a part of before.  In addition, it has provided compliance with greater visibility into the organization while acting as a bridge between compliance and the business.

As a side benefit, the compliance team has also discovered new repositories of data within the firm, enabling it to better assess risk.

In the end, he sees the relationship between ESG and compliance as a very happy one with great opportunity, earning compliance a seat at the table while creating greater appreciation for the risk management process and the focus on values and integrity that have long been a staple of compliance programs.

Listen in to learn more about how to leverage the relationship with ESG.

View Details

By Adam Turteltaub

One day the war in Ukraine will stop, and many companies will be looking to either enter or return to the country. But what compliance challenges might they face?

In tis podcast Eric Hontz, Director-Center for Accountable Investment at the Center for International Private Enterprise (CIPE) shares that business may be pleasantly surprised when they return. Despite the war the government has been functioning on multiple fronts and has continued to pass reform bills. They are particularly focused on EU-related reforms as a candidate for membership.

In addition, a great deal of government power has moved outward from the central government to mayors and regional governments, enabling greater transparency into how funds are being used.

All of this has made the corruption risk in the country less.

When doing business in the country, Eric recommends enlisting civil society groups as an ally. There are a large number of progressive business groups, he reports, working to stem corruption and encourage innovation. The success of their efforts can be seen in the many technology companies across the country.

After the war ends, he expects the country to continue its trajectory away from corruption. There is a growing consensus that corruption weakens the country, and he expects returning soldiers to have far less sympathy for it.

As for Russian sanctions, he does not see much risk when doing business in Ukraine.  Outflows of investment by Russians began long before the war.

Listen in to learn more about what to expect when the day comes that your organization begins working in Ukraine.

View Details

By Adam Turteltaub

For decades, if not centuries, the idea of being professional tended to focus on a cold, cognitive approach to work. Emotions were supposed to be secondary to a much more rationale form of management and work environments.

In this podcast, Gael O’Brien, executive coach and columnist for Business Ethics Magazine and The Week in Ethics, shares the research of the late Wharton School Professor Sigal Bersade, who examined the impact of emotions in the workplace.

Her work focused on how leaders can get culture right. Emotions, in particular compassion, were found to be very important.

She also found that employees who feel loved at work perform better. Kindness, caring and feeling connected have a strong impact on employee satisfaction and retention. In fact, she found that employees are 10.4 times more likely to leave because of a toxic culture than they are to depart because of compensation.

To create the right environment she is an advocate for an “emotional culture”, which she defines as the emotions necessary for a group to meet its goals. This culture, Bersade found, is transmitted through subtle signals such as facial expression and body language, especially of leaders. That’s a challenge in these Zoom times when traditional queues may be missing.

To get the right culture she advocates several steps including:

Executives verbalizing, modeling and rewarding the emotions they want to cultivate Mangers communicating that information to front-line employees Surveys and interviews that ask employees what emotions they see in colleagues around them

It’s both an intuitive and counterintuitive approach.

To learn more about Professor Bersade’s work, read some of her articles in Harvard Business Review (article 1 and article 2). You can also see the video of a talk she gave.

And of course, click above to listen to our podcast with Gael O’Brien.

View Details

By Adam Turteltaub

The recently-released Health Care Fraud and Abuse Control Program FY 2021 report contains a treasure trove of information for healthcare compliance teams. To gain a better understanding of lessons to be learned from this document we sat down with SCCE & HCCA board member Gabe Imperato, Partner at Nelson Mullins.

The report makes clear, he explained, how much coordination and review there is now among the Office of Inspector General at HHS, the US Department of Justice and also CMS. As a result, a subpoena, or even an inquiry needs to be taken very seriously. Compliance teams need to treat these external actions as if they are a report of non-compliant activity.

The report also reveals that there has been an increase in cases based on failures of organizations to appropriately collect copays. Some organizations have taken egregious activity that could be characterized as ignoring the obligation. In other cases the provider has made what it considers to be a reasonable effort to collect the payment – asking at time of service, sending follow up letters – others think that more could be done such as calling patients and setting up a payment plan. With no clear definition of what’s reasonable, the potential for a whistleblower case is high.

The report also illuminates the challenges of Stark and Antikickback cases. In his opinion these cases makes it clear that if you are looking at a circumstances where on the one hand there is a potential source of business and on the other hand a potential source of revenue, and there is a financial relations between the two, it is best to bring in competent outside counsel to determine if there may be a violation of these highly complex laws.

Kickback cases are very popular with qui tam attorneys, he notes, because of the difficulty in defending them completely.

Looking to the future, Gabe sees a large number of Covid-related fraud cases that will likely take years to play out.

Listen in to learn more, and be sure to read the report.

View Details

By Adam Turteltaub

The ethics and compliance team at the University of Southern California (USC) wanted to revamp their program. Stacy Giwa, Vice President Culture, Ethics and Compliance, and Marisa Hardy, Assistant Director Compliance, explain that they went into the initiative with several overarching goals. They wanted to:

Bring values and ethics-related behaviors to the compliance program Provide reasonable assurance to stakeholders that there are core compliance programs elements in place, no easy task in a large, complex organization Be more proactive, and identify gaps, trends and themes so that one part of the organization could learn from another Focus on partnership at every phase and build understanding of why a compliance program is important

To make the evolution a success they engaged the compliance and ethics committee to help enhance the university’s program’s standards and framework. As a part of that, they framed out what compliance is responsible for and what belongs to other departments. They also obtained strong leadership support.

The resulting program included an assessment tool that enabled both the team and the individual units of the school to evaluate their elements of the program. They also embraced transparency, letting departments know what information they are capturing and the dashboard they were using.

Findings were reviewed with departments and characterized in a positive way, as opportunities for improvement. Improvements plans were set with 1-3 year timeframes, which set goals, but did so in a less overwhelming way.

Their approach earned them overwhelmingly positive feedback from over 25,000 members of the USC community.

Listen in to learn how they did it and to get ideas for how to successfully evolve your compliance program.

View Details

By Adam Turteltaub

For a time monitorships were, if not endangered, out of favor.  After many years of embracing them, the US Department of Justice had begun calling for cost benefit analyses and looking for alternatives.

Then in 2021 Deputy Attorney General Lisa Monaco gave a speech announcing that the previous policy had been rescinded and that more monitorships would be coming in deferred prosecution agreements (DPAs) and non-prosecution agreements (NPAs). “I am making clear that the department is free to require the imposition of independent monitors whenever it is appropriate to do so in order to satisfy our prosecutors that a company is living up to its compliance and disclosure obligations under the DPA or NPA.”

In this podcast Dykema’s Mark Chutkow and Jason Ross explain what to expect when a monitor is appointed. First, recognize that different monitors will approach the job differently. You will need to understand if they are pragmatic, open-minded, familiar with the industry’s risk and challenges, and have a record as a monitor.

Typically, these questions are already answered since companies generally have a say in who their monitor will be. But, if your organization is the exception, do your homework on the monitor.

Take time, too, to understand what the scope of the monitorship is.

Also, make sure employees understand the role and benefits of a monitor. Leadership and the compliance team need to work to reduce  any negative impressions that employees may have so as to facilitate a construction relationship. To that end, take the time to educate employees that the monitorship will, in the long run, help them.

Once the monitor arrives, expect him or her to want to conduct interviews with individual at all levels of the organization in an effort to better understand the company. The monitor will likely want to understand the pressures middle managers are under and the expectations they are setting for those who report to them. Front line workers will likely be asked if they are comfortable speaking up and raising issues. The monitor may even reach out to customers and suppliers.

As for the compliance program, itself, expect the monitor to focus on whether it is properly resourced and implemented.

Turning to the ongoing working relationship during the monitorship, they warn that there will be tension periodically since the monitor is an outsider, but there needs to be some level of unity to ensure that the relationship is productive.

Finally, they discuss the importance of metrics.   The DOJ has made it clear that it expects data analytics from organizations when it comes to their compliance programs.

Listen in to learn more about the changes and how to prepare for and succeed during a monitorship.

View Details

By Adam Turteltaub

Joe Murphy (LinkedIn) is rightly considered one of the founders of the compliance profession, joining the field when compliance barely existed. Since then, he has been not only a member of the community, but an innovator and, although he might blush at the term, a philosopher. He constantly explores what compliance is, could be and should not be.

In this podcast he shares his insight as to how the profession has evolved in the almost 40 years that he has been a part of it.

Looking at the changes over the decades, what has surprised him the most is the large number of people who work in compliance but are not a part of corporate compliance programs as we know them. He cites individuals in anti-money laundering (AML), environmental compliance and privacy as examples. They often operate outside of the overall compliance effort and may not have the real access to power needed to be effective.

What should have been done differently at the start of the compliance field? In hindsight he believes there should have been a greater emphasis on having a strong, independent compliance officer, truly at the top level of the organization. That’s where the greatest risks are, he notes.

He offers another thought in what should have been different: There should have been a greater focus on incentives. Companies continue to struggle with incentives and rely upon discipline more heavily than they should or could.

What would he change today? First, our attitudes towards conflicting areas of compliance and law, such as areas where privacy law may get in the way of conducting an investigation. Conflicts have always existed, he observes, and compliance teams need to navigate them.

Compliance also needs to navigate what he sees as treacherous seas created by those academics who have no practical experience in compliance but, nonetheless, write articles about it that then get cited and repeated, even if they are wrong.

Joe closes the conversation by looking to the future.  Not surprisingly, he encourages us in compliance to stand up for the profession and keep others from defining us.

Listen in to learn more from a truly veteran compliance professional.

View Details

Post by Adam Turteltaub

Privacy is always a hot topic in healthcare, but even so, some areas are hotter than others. In this podcast Kara L. Hillburger, Privacy Compliance & Digital Accessibility Team Leader and Managing Director of the Octillo law firm, shares insights into the areas the enforcement community is currently focused on.

It’s not just the federal government that’s of concern these days, she points out.  State attorneys general are becoming more active in this arena. Under the HITECH Act they can bring actions of their own for HIPAA Violations, which has resulted in substantial financial penalties.

The pandemic has also led to changes in the enforcement landscape. With the rules for telemedicine changed and more data collected on patients, several states have increased their enforcement activity. For compliance and legal teams that means taking the time to understand both the federal and state perspective.

Data governance is, at the same, growing more difficult. On the one hand, ever-increasing cyber risks argue for locking down as much information as possible. At the same time, though, OCR is calling for greater data portability and transparency.

So what should organizations do?  In this podcast she suggests:

Making the effort to stay on top of the legal and regulatory changes. Ensuring that there is a strong data governance structure in place Having a clear delineation of roles and responsibilities: Figure out who is doing what and hire the right people. Keeping your policies and procedures up to date. Planning on annual policy reviews that reflect the realities of both in-office and at-home workers. Identifying proper resource. Providing regular data privacy and security training and document it. Having consequences in place for violations. Knowing your vendors and what they are doing to safeguard your data.

Listen in to learn more about what’s especially hot in healthcare privacy compliance.

View Details

Post by Adam Turteltaub

To get a better understanding of the state of antitrust enforcement we sat down with Andrew Mast, Counsel to the Assistant Attorney General for Antitrust at the US Department of Justice. In this podcast he shares key priorities of the Antitrust Division.

First up is a discussion of the Supply Chain Initiative, which is a partnership between the DOJ and FBI. Supply chain disruptions have caused prices to increase, as we have all seen, and the Initiative is tasked with determining whether the disruptions have been used as a cover for collusive conduct. As he notes, past disruptions, ranging from the Great Recession to a spike in the price of tuna, have led to collusive behavior.

To help protect consumers and businesses dependent on their supply chains, the Initiative is taking a proactive approach, working closely with the governments of the United Kingdom, Canada, Australia and New Zealand, sharing intelligence and working cooperatively.

The DOJ is also reaching out to the business community, providing education about antitrust laws, encouraging the development of compliance programs, and sharing details about the Antitrust Division’s leniency program. Under it, the first conspirator in a price-fixing conspiracy can avoid criminal prosecutions. But, he warns, companies must report promptly after discovering collusive behavior to enjoy the full benefits.

To help business understand the program fully, a new FAQ is now available.

Another priority for the Department of Justice is labor market collusion. Their goal is to ensure workers gain the benefits of competition. In the Department’s view, no-poach and similar agreements lead to lower wages, reduced mobility and less ability for workers to negotiate watches. Several firms have already been indicted.

Finally, he discusses the Procurement Collusion Strike Force, founded in the wake of increased government spending such as the $1.2 billion infrastructure bill. The goals of the Task Force are to deter antitrust activity and to facilitate more effective prevention, investigation and prosecution. Over 20,000 individuals have been trained as a part of this initiative, and it covers both US procurement domestically and internationally.

Listen in to learn more about what the DOJ is doing, and what compliance teams should be thinking about.

View Details

Post by Adam Turteltaub

Compliance programs continue to evolve, seeking new and better ways to prevent and detect violations of law. It was in that spirit, reports Chris Audet, Senior Director, Research at Gartner, that they began examining ways to improve program effectiveness.

At the time the survey began, many of their clients were dealing with peak Covid challenges, which included limits on training and the creation of new policies. Enhancing controls emerged as a potential alternative means of preventing problems. Of particular interest were embedded controls because they can both mitigate risk and reduce the burden on the workforce. Rather than training everyone on an issue or employees having to search for information, the control could flag a potential issue and help both the compliance team and the individual employee act appropriately. For example, travel and entertainment management software could automatically flag an issue and ask the proper questions.

As Gartner studied the issue they discovered that compliance burdens tended to fall disproportionately on department and management levels not identified as high risk:  research and development, engineering teams, strategy, planning and others. Because these groups were least attended to, individuals working in them needed to work the hardest to understand their compliance obligations.

Senior and Executive Vice Presidents also tended to be overly burdened because they are often trained less than others on compliance issues. As a result, they frequently struggle determining what to do in a given situation.

To reduce the compliance burden the Gartner report recommends three things;

Help employees remember better by putting controls closer to decision making. Reduce the number of judgement calls Help employees execute

Listen in to learn more about easing the compliance burden.

View Details

Posted by Adam Turteltaub

Being a compliance department of one can be a lonely job, but not for Susan Freccia, Director of Compliance at Oregon State University. Working in a small compliance department doesn’t feel like a challenge.

For one, she is not fully alone. There are compliance partners – professionals who have at least some compliance responsibilities – across the campus. More importantly, rather than focusing on her lack of a compliance team of her own she works at creating collaborative relationships far and wide. That includes the compliance partners, staff, HR, legal and audit.

For others in solo situations she advises not falling into the temptation of thinking, “If only I had X or Y the compliance program could be better.” Instead, she recommends focusing on how to work effectively and continue to improve processes.

She has also found success comes from the ability to help others get “unstuck” in their efforts.  She frequently meets with various individuals and teams to help figure out what the challenge is and to find a solution. She also may serve as a bridge between departments who may share responsibility in an area, helping them to collaborate more effectively.

Susan also advises against seeking perfection. It’s unattainable. Incidents will always occur. She notes that even the Sentencing Guidelines reflect that reality with several elements addressing how a program responds to the inevitable problems.

In sum, to make a small program work, take a collaborative, problem-solving approach. It will be more effective and help people see compliance not as the cause of problems but the solutions to them.

View Details

Posted by Adam Turteltaub

The Navex 2022 Risk & Compliance Hotline & Incident Management Benchmark Report provides a fascinating look into what’s going on in compliance in general and how employees are using helplines specifically.

The 2021 report had illuminating insight into the impact of the pandemic. To learn what is in the data from the latest report, we again sat down with Carrie Penman, Chief Risk & Compliance Officer from NAVEX.

This year’s report, which covers data from 2021, revealed four key trends, she reports:

Whistleblowers are more emboldened. They are more likely to use their names, rather than remaining anonymous, when making a report. Viewed against the SEC’s reported near doubling of leads to the Office of the Whistleblower, it’s clear that workers are more willing than ever to come forward. What is unclear is why the change. It may be due to employees feeling that it would be easy to find another job if they were retaliated against. Reports of retaliation have increased. The question here is whether retaliation has increased or employees are more willing to report it. One theory is that employees are much more attuned to issues of workplace civility. COVID continues to have an impact. While the number of calls to helplines has increased, they are still below pre-COVID levels. ESG related reporting is notably low. This may be due to employees not fully understanding ESG, or believing that those issues don’t need to be brought to compliance or the helpline. In both cases, more training may help affect the numbers

Finally, looking to the future, Carrie anticipates the possible recession leading to turmoil.  Fear levels rise when layoffs occur, and people see less opportunities to find new work. Managers may place excessive pressure on employees to make the numbers, despite the economy.

All of these factors could lead to a great deal of work for compliance teams, and a very different report for 2023.

View Details

Posted by Adam Turteltaub

Good and bad decisions are at the heart of compliance efforts. So much of our work is dedicated to helping people make better informed choices.

In this podcast, Rupert Evill, Founding Director of EthicsInsight shares practical advice for making good decisions.

He begins, though, with outlining several factors that lead to bad decision making. Pressure is, not surprisingly, a very large factor, whether it is time-based or financial.  Ethical hazing wrongly gives people permission to do something that they shouldn’t. Faulty assumptions are another persistent challenge. Still another factor is failure to plan. Not taking the time to foresee issues can leave individuals suddenly confronted with circumstances where it is already too late to do the right thing.

So how do we encourage and make good decisions?  He lays out four steps:

Consider possible outcomes. Take the time to assess what might happen and encourage diverse opinions. One handy trick he recommends is asking people to write down ideas rather than sharing them publicly. That can lead to more diverse thinking. Consider the likelihood of each outcome. When doing so, he recommends using a numerical scale rather than words like “it’s possible.” That phrase can mean very different things to different people. Rank the preferred outcomes and their likelihood. Look for assumptions in decision making and test them to see if they are true. Consider carefully your strategy for achieving your goals. Consider what can be done now to favorable affect the outcome. Think through what the options are, don’t show your cards too soon and remember that there is usually more than one option.

Listen in to learn more. It could be the best decision you make today.

View Details

Post by Adam Turteltaub

Ever-increasing sanctions of Russian individuals and entities are looking to be a long-term challenge for compliance teams.  That’s not surprising since, they are a part of a war of attrition, according to Oleksandr Pomoshnikov, Head of International Business Development for Ukraine-based YouControl, which offers RuAssets, a tool for tracking Russian and Belarusian assets.

In this podcast he underscores the importance of adopting a three lines of defense model and paying close attention to the origins of funds.  Russian companies have been actively changing beneficial owners to persons in neighboring jurisdictions and opening business units there as well.

This can lead to very complicated and hard-to-trace business structures, he explains, not just because there may be multiple holding companies.  Many of the jurisdictions in the region have closed systems, making it difficult to determine ownership and identify politically exposed persons.

Listen in to learn more.  But do listen carefully.  Oleksander was in Poland with a challenging internet connection while recording.

View Details

Post by Adam Turteltaub

When we talk about communications in the world of compliance, we tend to focus on training and other forms of mass information sharing. Not as often discussed, but just as important, are the individual one-to-one conversations between the compliance team, leadership, management, and frontline personnel. Getting these interactions right is essential to the success of a compliance and ethics program.

Donna Schneider (LinkedIn), Vice President, Corporate Compliance and Internal Audit, Lifespan, has been running a series of six columns in Compliance Today magazine focused on communication done well. In this podcast she touches on a few of the key topics that she addresses.

Her first piece of advice: stick to the facts. It's very important to be factual because if you do not rely on facts there is a tendency to tell yourself a story. By analogy she points out that when someone cuts you off driving we tend to come up with reasons why the person did it, even though all we know is that they cut us off. Likewise in a crucial conversation it's good to focus on what you know definitively:  the things you saw, heard or read yourself.

She also shares how to handle one of the ongoing challenges when it comes to compliance:  setting expectations for leadership. Often, management is eager to come to a quick resolution and put the issue behind them. That is not always the best course since a thorough investigation takes time. For that reason, she advocates consistent communication, establishing a collaborative rapport and setting reasonable expectations.  Periodic updates are also exceedingly important.

Before a difficult conversation she advises thinking through what outcome you want for yourself, others or the organization. Consider, too, the relationship between you and the person you are speaking to. Don't focus on the specific issue you are talking about but what you want to happen. Are you in a dialogue, do you want to share facts or are you there to learn facts? Think about your intent and then ask yourself: how would I behave to achieve that goal? Think through, too, both what verbal and nonverbal communication skills you will need.

Think through also how you would respond if the conversation went south. What would you say or do to bring it back to the direction that you want?

Listen in to learn more about how to best prepare for difficult conversations, including the power of “do” and “don't do” statements.

View Details

Posted by Adam Turteltaub

You just started leading a compliance program.  Whether you are new to the company or new to compliance, you probably have a lot of questions to ask as you get started, but where do you begin?

In this podcast, Beverlin Hammett (LinkedIn), Compliance Regulatory Risk Officer at Habersham Medical Center, offers an intriguing answer.  She met with leadership around the organization and asked them three questions:

How long have you been with the hospital? What are your main issues? What do you think I am here to do?

The first question helped her understand how much experience the person had both within the organization and their role.  This helped her gain an understanding of how much expertise the person had as well as the issues, challenges and triumphs that they had experienced.

Asking what the main issues they saw was a more subtle question than it appears.  It provided insights into their perspective on the institution and its challenges and helped her understand their focus.

The final question, “What do you think I am here to do?” helped illuminate attitudes towards compliance and begin laying the foundation for the idea that compliance is here to help solve problems.

The exercise helped her both get off on the right foot with operations and to better understand the challenges and opportunities.  It also helped illuminate several issues within the organizations that she was able to successfully address immediately.

Listen into learn more about her intriguing approach and the benefits it could have for other organizations.

View Details

By Adam Turteltaub

When it comes to encouraging internal whistleblowers, there are two main barriers to coming forward, reports Jeb White, CEO, Taxpayers Against Fraud.  First, is the belief that their concerns won’t be heard.  Put another way:  why bother.  The second is the fear that by sticking their necks out they risk getting their heads chopped off. Their careers could be ended.

Even for those who do come forward, there is always the challenge of keeping their trust so that they do not then go outside the organization to the press or regulators.

To solve these challenges he recommends embracing communication and transparency.  To the extent that you can, keep whistleblowers in the loop.  Let them know that the investigation is proceeding.  Embrace the lesson from food delivery apps that let you know that your pizza is in the oven.  Let the whistleblower know that the investigation is ongoing and active.  And, to the extent you can, let them know what the final disposition was.

If the organization does not find wrongdoing, he recommends sharing with the employee the broader context as to why what he or she saw was legal and proper.  Perhaps explain the laws involved. That will help them both understand the organization’s decision and stay engaged.

If the organization does find wrongdoing, Jeb is a strong advocate for sharing the lesson internally.  It will help demonstrate that the organization takes wrongdoing seriously.

It also helps mitigate the risk of a dysfunctional culture, in which the words in the code of ethics are nothing more than words, employees are afraid to speak up, and lines of communication are shut down.

Listen in to learn more about how you can improve your own internal whistleblowing efforts.

View Details

Post by Adam Turteltaub

The European General Data Protection Regulation (GDPR) already provides considerable requirements for compliance programs. With Brexit comes a new GDPR for the United Kingdom. Adding to the complexity, the UK GDPR also contains a Children’s Code, explains Jeff Kluge (LinkedIn), Founder & CEO of Holistic Ethics. The UK has long led in protecting the data of children, and the new code follows the UN Convention on the Rights of the Child.

For companies doing business solely within the United States it is not likely to be an issue but for those operating globally he advises being aware of and in compliance with the Children’s Code’s requirements. There are standards and rules in place for connected games and toys, for using artificial intelligence (AI) and processing children's data.

So, what should compliance teams do? First, they need to understand the algorithm used in the AI their organization employs, ideally while it is still being developed. Second there should be a children's data oversight committee in place. Third the company should be asking whether they should have an ethics committee overseeing their AI-based systems.

Also, the compliance team needs to recognize that AI initiatives are often created without their knowledge. It's important to get a handle on what's going on help people understand the importance of closely monitoring artificial intelligence, particularly those systems that are autonomous.

He reports that the compliance team can be particularly helpful in identifying what data is being collected and what is the right data to be using. The team particularly needs to be monitoring what decisions are being made based by the AI.

Listen in to learn more about the UK GDPR Children’s Code and what compliance teams need to do to protect both children and their own organizations.

View Details

Post by Adam Turteltaub

San Diego-based Qualcomm was having a tough 2018. The company was going through a whole host of highly destabilizing activity including an attempted hostile takeover. Needless to say, it was a challenging time for the company and the corporate culture.

The compliance team very much wanted to be a part of the solution, Krista Wolff, Senior Manager, Corporate Compliance Communications tells us.  Their goal was to amplify the positive and strengthen the organization's culture, despite all the challenges it faced.

To help, in the Spring of that year they launched the Lead the Way employee ethics recognition program. In the Fall they launched the newly revised code of conduct and their first Compliance and Ethics Awareness Week.

Through the years since they have rolled out a number of activities to involve employees and communicate important messages. One of their more fun ideas was a “spot the issues” exercise. They staged desks, photographed them, and asked employees to spot items on the desk that could be indicative of something problematic. When the pandemic struck and people began working from home, they continued this program although now featuring desks in a home setting.

One of the more interesting efforts they did was focused on protecting confidential corporate information. As a technology company IP is very important to Qualcomm and the compliance team wanted to stress to people the importance of protecting data.

They worked with the IT department to identify printers around the globe at Qualcomm offices. They then sent to the printers in these in these offices a document marked confidential company information with a message about the importance of protecting IP and asking the employee who found it to email compliance letting them know where they found that document and when. It was a great way to demonstrate that people sometimes send things to printers that they shouldn't and leave them there far too long.

This activity had an interesting response rate that illuminated cultural differences. They found that people in Asia rarely emailed in. From Europe, by contrast, the response rates were very high, and in the US employees tended to leave the document on the printer for others to find as well.

To make other parts of the program relevant globally they worked with their ethics liaisons and in-country compliance teams around the world to plan local events. The response has been very positive, and the level of innovation has been equally high.

Listen in to learn more about how Qualcomm’s Compliance and Ethics Awareness Week both helped to meet their compliance goals and strengthen the overall corporate culture.

View Details

Posted by Adam Turteltaub

Compliance teams spend a great deal of time and effort encouraging employees to contact the helpline.  But, points out Jay Anstine, Compliance Program Director, Western Division, Banner Health, we tend to make less of an effort to train them in what happens after they make that call.

That’s a mistake, he argues in this podcast, since employees who see perceived wrongdoing tend to feel anxious and vulnerable.  They are stressed because they are uncertain what is going to happen, if anything.

By helping them understand the post-call process, we can eliminate this blind spot, he argues, greatly reduce the stress level, and increase the likelihood that they will come forward.  That means providing training that brings greater clarity to the process during on-boarding and annually thereafter.  It also means taking the time to understand the questions the workforce may have about what happens from start to finish.

Also, he advises, include in the training information about what to expect when reporting face to face, either to their supervisor, or somewhere else, including the compliance team.

Finally, Jay provides insight into how to make the reporter feel comfortable when bringing the information to compliance, and what you can do to protect his or her anonymity.

Listen in to learn more about how demystifying the helpline could help yours ring more often.

View Details

Posted by Adam Turteltaub

Procter & Gamble (P&G) is one of the best-known companies in the world, boasting top brands such as Tide, Crest and Charmin. The company is also well recognized for its highly strategic marketing and its integrity. In fact, its reputation for principled behavior is what attracts and helps retain top talent at the organization, reports Jay Ernst (LinkedIn), Director – Ethics & Compliance Office, P&G, in this podcast.

How strong is the organization’s commitment to ethical behavior?  In annual surveys the company's purpose, values and principles are cited most frequently by employees as something that they do not want to change.

For its annual Corporate Compliance & Ethics Week celebration, which they have dubbed the “Do The Right Thing Celebration”, the compliance team ties the program and compliance training into one of three commitments – respect, integrity and stewardship -- that are part of their refreshed code of conduct.

In 2021 the theme was “Leading with Respect”. Activities included marquee events featuring external or high-profile internal speakers. They also had videos highlighting challenges people may face, risk areas and how to deal with them.

To make the program relevant to its employees around the world, they enlisted the help of the employee relations group, which helped them identify individuals to lead the local activation of the program. The same people each year now lead the activities in their region.

While the local activation follows the common theme, there is opportunity to customize the program to increase the relevance to their communities. Each year there are even global recognition awards for activations that demonstrate creative activity and engagement.

The company also has a peer recognition program known as the Power of You, which recognizes excellence across a range of areas, including ethics. Employees can nominate their peers who have gone above and beyond in their work. It has proven to be an excellent opportunity to recognize ethical actions on a peer-to-peer basis.

Listen in to learn more about P&G’s experience and how you may be able to apply it to your own organization.

View Details

Posted by Adam Turteltaub

Getting employees to come forward and provide feedback on the corporate compliance and ethics program is often a challenge. Many are hesitant to talk to compliance at all. Still others may fear that their conversation may lead to more scrutiny by the compliance team.

Mary Shirley, Head of Culture of Integrity and Compliance Education at Fresenius Medical Care and co-host of the Great Women in Compliance podcast, found an interesting way to change the dynamic. She made feedback an integral part of the organization's annual Corporate Compliance & Ethics Week celebration.

The compliance team there recognized that during the week-long celebration people are eager to participate. That means there is a golden opportunity to collect data from them that can provide insights that might not otherwise be captured. This includes both informal conversations and using things like quizzes to determine how much information from earlier training has been retained.

Also, games can help.  In one fun exercise they had a ring toss in which to get a ring the individual had to answer correctly a question related to compliance.

The program has yielded remarkable insights. For example, one part of the compliance team was concerned that it was sending too much email. When they used this opportunity to ask employees what they felt, they were surprised to discover that it was actually a preferred means of communications.

Listening has one other benefit: it enables the compliance team to demonstrate that it is responsive to employee workplace concerns.

Listen in to learn more about how you can turn Corporate Compliance & Ethics Week into a learning experience both for employees and for the compliance team.

View Details

Post by Adam Turteltaub

While we have all grown accustomed to seeing access ramps and automated doors in the physical world, it is easy to forget that the Americans with Disabilities Act (ADA) requires digital accessibility as well. In this podcast, Michelle Landis, co-founder of Accessible360, explains that the challenges start with organizations not even realizing that the ADA sets numerous requirements that organizations must comply with.

The challenge posed by this knowledge gap has been both exposed and increased by the pandemic, which has accelerated the need for online resources that are available to all. How do you bank, order groceries, and work from home if the websites you need are not accessible to individuals with physical challenges?

For organizations looking to catch up with the digital requirements of the ADA, she recommends starting by taking an inventory of your consumer facing websites and mobile apps.  Those are the ones most likely to be subject to litigation.

Next, get a live user assessment by individuals trained in this area and from people who are living with disabilities. She advises being cautious around companies promising to provide a quick fix with a simple overlay.

Another pitfall, she warns, is underestimating the time it takes to implement suitable changes to your websites and apps that need them. When faced with a demand letter for changes within 21 days, you should engage your legal team to respond in an appropriate way.

Finally, she advises that, as with the physical world, it is better to build in accessibility from the start rather than adding it later. That means keeping it front and center when designing and evolving your organization's digital assets.

View Details

Post by Adam Turteltaub

While we have all grown accustomed to seeing access ramps and automated doors in the physical world, it is easy to forget that the Americans with Disabilities Act (ADA) requires digital accessibility as well. In this podcast, Michelle Landis, co-founder of Accessible360, explains that the challenges start with organizations not even realizing that the ADA sets numerous requirements that organizations must comply with.

The challenge posed by this knowledge gap has been both exposed and increased by the pandemic, which has accelerated the need for online resources that are available to all. How do you bank, order groceries, and work from home if the websites you need are not accessible to individuals with physical challenges?

For organizations looking to catch up with the digital requirements of the ADA, she recommends starting by taking an inventory of your consumer facing websites and mobile apps.  Those are the ones most likely to be subject to litigation.

Next, get a live user assessment by individuals trained in this area and from people who are living with disabilities. She advises being cautious around companies promising to provide a quick fix with a simple overlay.

Another pitfall, she warns, is underestimating the time it takes to implement suitable changes to your websites and apps that need them. When faced with a demand letter for changes within 21 days, you should engage your legal team to respond in an appropriate way.

Finally, she advises that, as with the physical world, it is better to build in accessibility from the start rather than adding it later. That means keeping it front and center when designing and evolving your organization's digital assets.

View Details

Posted by Adan Turteltaub

There are a lot of things you can do to make your organization’s celebration of Corporate Compliance & Ethics Week a success. But sometimes, less is more.  Adam Balfour, vice president and general counsel for corporate compliance and Latin America, Bridgestone America's, explains in this podcast that they realized that it would be better to evolve their celebration from a lot of different activities to just a few and to make them bigger.

So what are they doing?

For the last few years they have bestowed a series of Leading With Integrity awards. These go to managers who have been nominated by employees for their exemplary leadership when it comes to compliance and ethics issues. All 50,000 of the organization's employees can nominate any leader, manager or supervisor that they think deserves the prize.

The nominations are evaluated by a cross functional panel which is good for bringing in and engaging other leaders in the organization. Then five or six winners are selected each year, and they are announced during a leadership panel with about 1100 employees on the call.

For the winners the greatest impact comes from the recognition and knowing that the CEO knows your name and for a very positive reason.

This program has also helped the compliance team gain exposure to people they didn't realize were embodying the organization's commitment to compliance.

Another event that they do, or more accurately two events, are leadership panels wherein employees are invited to join in and listen as leaders discuss compliance and ethics issues. It sets a clear tone at the top for the organization and illustrates ethical decision making.

Each year, for a little bit of fun, the compliance team puts together an event using ethics issues found in popular TV shows and movies. This helps teach compliance in a more relatable way and leverages good adult learning theory.

Finally, the compliance organization offers a Compliance Battle Royale every year.  It's a big production with a bracket of 16 teams competing against each other over a period of four days.  There is daily elimination, and it gets very competitive.

Got any good ideas of your own to share? If so add them to the comments below. And be sure to listen to this podcast.

View Details

Posted by Adan Turteltaub

There are a lot of things you can do to make your organization’s celebration of Corporate Compliance & Ethics Week a success. But sometimes, less is more.  Adam Balfour, vice president and general counsel for corporate compliance and Latin America, Bridgestone America's, explains in this podcast that they realized that it would be better to evolve their celebration from a lot of different activities to just a few and to make them bigger.

So what are they doing?

For the last few years they have bestowed a series of Leading With Integrity awards. These go to managers who have been nominated by employees for their exemplary leadership when it comes to compliance and ethics issues. All 50,000 of the organization's employees can nominate any leader, manager or supervisor that they think deserves the prize.

The nominations are evaluated by a cross functional panel which is good for bringing in and engaging other leaders in the organization. Then five or six winners are selected each year, and they are announced during a leadership panel with about 1100 employees on the call.

For the winners the greatest impact comes from the recognition and knowing that the CEO knows your name and for a very positive reason.

This program has also helped the compliance team gain exposure to people they didn't realize were embodying the organization's commitment to compliance.

Another event that they do, or more accurately two events, are leadership panels wherein employees are invited to join in and listen as leaders discuss compliance and ethics issues. It sets a clear tone at the top for the organization and illustrates ethical decision making.

Each year, for a little bit of fun, the compliance team puts together an event using ethics issues found in popular TV shows and movies. This helps teach compliance in a more relatable way and leverages good adult learning theory.

Finally, the compliance organization offers a Compliance Battle Royale every year.  It's a big production with a bracket of 16 teams competing against each other over a period of four days.  There is daily elimination, and it gets very competitive.

Got any good ideas of your own to share? If so add them to the comments below. And be sure to listen to this podcast.

View Details

Posted by Adam Turteltaub

If you have ever considered joining the Health Care Compliance Association (HCCA) but haven’t, this podcast will give you cause to reconsider.

Julie Sheppard, Founder and President of First Healthcare Compliance joined the association a decade ago when she was looking for a reliable source of information on healthcare compliance issues.  She wanted an unbiased, trusted sour of information that would keep her updated on the challenges of managing compliance.

Through the years she has taken advantage of a wide range of HCCA programs, from an Academy to web conferences to reading the magazine Compliance Today.

She also obtained her Certified in Healthcare Compliance (CHC) designation, which she sees as a means to differentiate herself and demonstrate her expertise.

Listen in to learn more about her journey with HCCA and how she sees healthcare compliance evolving over the next few years.

View Details

Posted by Adam Turteltaub

Conflicts of interest are a particularly challenging issue in healthcare.  Medical professionals may moonlight at a rival hospital, have an interest in a medical device or real estate a hospital is thinking of acquiring, and, of course, family members who might work at a key vendor.

Steven Melinosky, Regional Director Compliance/Investigations and Policy at Trinity Health of New England, explains in this podcast that managing conflicts of interest is possible, with the right policies and procedures in place.

That begins with recognizing that one policy is likely not enough.  The conflicts faced by leadership and the board are likely quite different than those faced by rank-and-file employees.  Conflicts for senior leaders and board members likely should be reviewed by the board chair.  Those for employees can typically be handled by the compliance team working with frontline managers.

Underlying  these efforts must be a culture of compliance from the top down and bottom up.  The danger of conflicts of interest must be taught from day one, along with encouragement to report and a clear explanation of the disclosure process.  Supervisors need to be trained to identify conflicts, and periodic reminders need to be scheduled.

One tool that can help make conflict of interest management simpler is something he created and calls a “Conflict of Interest Dictionary.”  It is a spreadsheet designed to help respond to common conflicts.  It contains several columns:

What the conflict is What else needs to be known about it, such as if the individual affected has purchasing authority, is in management and at what level Why this issue poses a conflict Standardized action plans that lay out expectations for behavior

Having this dictionary helps to ensure consistency in the process and greatly expedites actions since a starting point (and potentially an ending post) is already in place.

Along with this dictionary it’s important to take the time to assess the risk – both likelihood and potential impact – of a conflict and to ensure that the plans put in place are sufficient to mitigate the risk.

He also recommends providing both the affected employee and his or her manager with a written plan which includes the background, the risks and expectations.

Listen in to learn more about how to better manage conflicts of interest and whether a Conflict of Interest Dictionary is right for your program.

View Details

Posted by Adam Turteltaub

The 340B program was set up to providers of care to Medicaid patients to stretch federal dollars.  Hospitals and clinics are able to buy covered, outpatient drugs at a discounted price from manufacturers.

As usual, though, what sounds like a simple program poses compliance risks for manufacturers and front-line providers, explains Peggy Tighe (LinkedIn) and Mark Ogunsusi (LinkedIn) of the law firm Powers Pyles Sutter & Verville PC.

Providers can either pass the discounted price along to patients or dispense the drugs and get reimbursement from a private or federal payer at regular rates, using the difference to support their services.

While the 340B program is designed to be flexible, there are several strings attached.  Providers need to ensure that the drugs prescribed go to the patient.  In addition, the individual has to meet specific guidance as to what constitutes a patient.  Simply writing a prescription is not enough.  A set of criteria must be met, and those rules are strict enough that an entire category of software providers has emerged to manage this issue.

Other risks for providers to consider include virtual inventories and over purchasing 340B drugs

For drug manufacturers, it’s essential to ensure that price data is accurate, and that prices do not exceed the ceiling price.  A mistake could lead to civil monetary penalties and even termination from the program.  Duplicate discounts are also prohibited and pose another risk.

Listen in to learn more about how to avoid the many compliance challenges of 340B drug pricing programs.

View Details

Posted by:  Adam Turteltaub

There are lots of ways to make your organization’s Corporate Compliance & Ethics Week a success.  For Tiffany Turner Lynch (LinkedIn) and her colleagues at Winston-Salem State University that meant timing it to the launch of their compliance training initiative.  They saw the joint effort as an excellent opportunity to demonstrate that supporting a culture of compliance and ethics is the responsibility of everyone and is something that the university values highly.

Before beginning the training, she and the chief counsel met with internal audit to discuss policies that are audited the most.  They also discussed issues that most frequently led to calls to audit and legal.  In addition, they identified issues that are central to compliance in higher education, such as the Family Educational Rights and Privacy Act (FERPA).  Throughout the week they reinforced elements of the training

They also developed a five-part podcast series, each one featuring a different “no” department:  Internal Audit, Equal Employment Opportunity, Title IX, the police, legal and compliance.  The podcasts served to the lift the veil on what happens when an investigation is conducted.  They demonstrated not just the process, but also that these departments exist to protect the university and its staff.

To add some fun to the celebration they conducted a virtual scavenger hunt.  Everyone who was able to answer all the questions was entered into a drawing to win one of two $100 cash gifts.

As Tiffany reports in this podcast, the results were outstanding.  It helped people understand more about the compliance office, built rapport, raised the comfort level with reporting and engagement with the policy portal.

Listen in both to learn more and get some inspiration for your own Corporate Compliance & Ethics Week efforts.

View Details

Posted by:  Adam Turteltaub

Nobody likes delivering bad news, but if you’re in compliance and ethics, you’re going to have to do it sooner or later.  When that time comes, it’s essential you do so in the best way possible.

In this podcast, Jeff Hahn (LinkedIn), author and the owner and principal of Hahn Marketing & Communications, reveals that one secret for sharing bad news is to provide the right context.  Give management the salient facts and avoid burdening them with every detail.  Second, he advises following what he has dubbed “The Goldilocks Rule”.  Present options that are not hot enough, not cold enough, and just right.  In practice this means ranging from doing nothing to doing something extreme.  Generally, the “just right” option prevails and enables leadership to feel bought in to the path forward.

Once the goals are set and the organization’s response moves into the implementation stage, it’s time to bring in the line managers.  That conversation, he relates, needs to be focused on implementation, and the conversation switches from creative to directive.

What about the wider workforce?  It’s important to remember that they are brand ambassadors.  Inform them to the best of your abilities.  Be authentic, and remember that they can check up on you from the inside.

When it comes to external communications, the compliance team can be invaluable in creating stakeholder talking points, including a timeline of what happened when.

Finally, the conversation explores what not to do a crisis.  There are three things to avoid:

Make an absolute and outright denial, unless the claim is obviously false and ridiculous Attack the accusers Scapegoat, especially those who are tangential to the core issue

Listen in to learn more about how to break bad news and be an integral, appreciated part of a crisis response.

View Details

Posted by:  Adam Turteltaub

The war in Ukraine and pandemic have both dramatically changed the cyberthreat landscape for healthcare entities.

There are many more employees working from home, as well as patients communicating with their physicians remotely.  At the same time, governments have warned of potential cyberattacks by Russia.

Even without these threats, ransomware provides its own challenges.  As Blaise Wabo, Healthcare and Financial Services Leader for A-Lign explains in this podcast, it’s a fast-growing threat.  Deloitte research indicates that ransomware attacks increased by 1755% in 2021.

So how should healthcare entities respond?  Start by focusing on your people, he advises.  They tend to be the weakest link in the security chain.  Some common challenges:

A lack of encryption of their home WIFI Routers still with the default password Connecting from Starbucks, the airport or hotel without using a VPN Falling for a phishing attack

To manage the risk, he recommends starting with a risk assessment that includes third-party suppliers and your supply chain.  Determine the vulnerabilities and rank the risks.  Then begin implementing controls.  Encrypt PHI, even in transit.  Conduct phishing training for your staff.  Hire a third party to do a penetration test and identify gaps in your security.

In addition to preventing problem, steps like these can help when one occurs, given the provisions of the HIPAA Safe Harbor Act.

Listen in for more advice and learn how to navigate an increasingly challenging cyber landscape.

View Details

Posted by:  Adam Turteltaub

Hybrid work is likely here to say, and, as Sheila Limmroth, privacy specialist at DCH Health System, and the author of the chapter Hybrid Work Environment in the Complete Healthcare Compliance Manual  observes in this podcast, it’s up to compliance teams to manage the risks, many of which, even at this stage of the current era, aren’t always recognized.

For example, we’re all familiar with the need to secure electronic PHI, but if your employees have printers at home, are they permitted to print out any data? If so, do they have shredders or some other way to destroy the document? Are employees even trained to destroy it?

One other consideration: is Alexa listening in on what they are saying?

These are but two examples that point to the need to think through all the implications of having a hybrid workforce, even after two years of remote working.

So, what should compliance team be doing? Education is essential so that employees understand that certain behaviors are risky:

Talking on your cell about a patient while sitting in Starbucks is not a good idea. Phishing remains a substantial risk in the home office as it is in the workplace. The router needs to be secured with a password other than the default one that comes out of the box.

At the same time there’s a need to also recognize the new challenges inside the facility.  When it comes to telehealth, not all videoconferencing software is created equal. The platform must be HIPAA compliant. Even for video conference calls it’s probably a good idea to issues PINs to the attendees.

The bottom line is it’s time to revisit your organization’s risks and policies to determine what works and what doesn’t as more employees return to the office while many remain at home.

Listen in to learn more, and be sure to check out the Complete Healthcare Compliance Manual.

View Details

Post by:  Adam Turteltaub

Isabella Porter is the director of compliance and privacy officer of District Medical Group and author of the chapter “Patient Privacy and Security:  Business Associates” in the Complete Healthcare Compliance Manual.

In this podcast she shares the key consideration that covered entities – physicians, hospitals, health plans and others who fall under the requirements of HIPAA – must consider when working with their various business associates (BA) with whom they share personal health information (PHI).

When considering a potential new business associate she recommends ensuring that the vendor understand that it meets the definition of a business associate. Quite often they do and already have on hand a business associate agreement. It’s preferable to ask them to default to your own agreements, but if they do not – for practical reasons business associates with a large number of customers cannot accommodate each customer’s agreement – see if they are willing to amend their own, if necessary.

When assessing a BA, also take the time to determine if they are using subcontractors. If they do, they should be referenced in the BA agreement. Also, ask the vendor what kind of checks they are doing on their vendors and their own ongoing monitoring efforts

One important thing to also check: where the data is housed. If the servers are outside of the US, there may be other laws to consider such as the European General Data Protection Regulation (GDPR).

Listen in to learn about the requirements of ensuring the safety of your BA agreements, including ten elements that need to be included in each one.

View Details

Posted by:  Adam Turteltaub

The EU Whistleblower Directive, enacted in 2019, has as its primary goal to protect whistleblowers. As Geert Vermuelen, CEO of The Integrity Coordinator and long-time compliance professional explains in this podcast, the Directive reflects a significant change in course for the EU where, for a long time, there had been a great hesitancy to trust whistle blowing.

The Directive reflects a new approach that embraces the idea that, if whistleblowers are better protected, we can better detect and prevent harm to the public.

The directive applies to organization of 250 or more employees, and from the end of 2023 companies as small as 50 employees. In addition, it applies to all companies in financial services, regardless of size, as well as those subject to AML legislations. These include real estate brokers, law firms and accountancies.

Whistleblowers are protected against retaliation, and the burden of proof is shifted to the employer, who must prove that any adverse action taken against a whistleblower was unrelated.

Other provisions of the Directive include:

Non-disclosure agreements are invalid in the context of whistle blowing Reports at subsidiaries may only be reported up to the group level if the whistleblower permits There must be secure and confidential whistle blowing channel for each legal entity A neutral party must receive the report and follow up The compliance team can be that party but its charter must reflect its independence GDPR still applies, but when processing personal data of the accused person, he or she does not need to be immediately notified The identity of the reporter must be kept confidential, unless the reporter agrees with making the identity public The reporter should be notified of the receipt of the report within seven days and provided substantial feedback on the report within three months

Adding to the complexity is that each country in the EU will need to pass its own laws to implement the directive, leading to subtle, and potentially significant, differences from nation to nation.

All in all, it’s a substantial change and worth listening in to learn more about what the EU Whistleblower Directive means for your compliance and ethics program.

View Details

By Adam Turteltaub

While the Covid pandemic has grabbed the headlines, opioids have continued to kill Americans in large numbers.  As Seth Whitelaw, President and CEO of Whitelaw Compliance Group  explains in this podcast and in the chapter “The Opioid Crisis and the Risk of Diversion” in the Complete Healthcare Compliance Manual, while prescription-related deaths have seen some decline, they remain far too high, largely due to the problem of diversion into illegal forms of distribution.

To prevent diversion, healthcare providers and their compliance teams need to pay close attention to the information they are receiving.  Distributors, manufacturers, physicians and pharmacists all generate and have access to prescribing data.  It’s essential to ask questions such as is the patient demonstrating addictive behavior?  Is a physician writing prescriptions at a rate suggesting he or she is spending little to no time with patients before prescribing?  Did the pharmacy order ten times more opioids than usual because something is awry, or because someone innocently added a zero at the end of the order?

All of this means there is a strong human element to controlling diversion.  While the automated systems are good at identifying outlying activity, there is still a need for a person to find out what exactly is going on.  That can include seeing if there is a line of people waiting outside a physician’s office, or if a pharmacy parking lot is filled with out of state license plates.

There are not necessarily any bright lines, he explains, which makes it all the more important to pay attention and make the necessary disclosures to the DEA if a good explanation cannot be found.

Listen in to learn more, and be sure to check out the Complete Healthcare Compliance Manual.

View Details

Post by:  Adam Turteltaub

Antitrust is a long-time risk area for compliance teams to manage, but its longevity does not mean it is not evolving.  New issues arise as times and Administrations in Washington change.

Nathan Mendelsohn, Associate in the Washington, DC office of the law firm Wilson Sonsini Goodrich & Rosati lays out what is new in antitrust in this podcast and in the chapter “Federal Antitrust Law Risks – 2022” in The Complete Compliance and Ethics Manual.

Some areas of antitrust law are well known.  Agreements by competitors to rig bids, allocate markets or set prices are generally considered illegal per se and can open up the door to criminal prosecutions of both individuals and organizations.

Other kinds of agreements, he explains, are subject to what is known as the “rule of reason”.  In a nutshell, it calls for an assessment as to whether the agreement makes sense and was not designed just to protect the parties and unfairly hurt others.

As for compliance programs in antitrust, the ground is changing.  During the leniency program era, only the first company to self-report anticompetitive behavior received credit.  Its co-conspirators, no matter how good the compliance program, received none.  Then in 2015 the Department of Justice began giving credit for forward looking compliance programs:  what the company had done since the violation to protect against its reoccurrence by strengthening compliance efforts.  Then, beginning in 2019, the Antitrust Division began, at least on paper, giving credit for existing compliance programs.  Thus far, though, no organization has qualified for it.

At the same the focus of attention for the DOJ has continued to evolve, most notably when it comes to the labor market.  The division has pursued several cases related to no poach agreements, in which companies agree not to poach each other’s workers.  Many believe that this has kept wages lower than they might be.   Non-compete agreements are also under scrutiny.

Another trend to watch out for: transnational prosecutions.

Listen in to learn more, and be sure to explore what’s available in The Complete Compliance and Ethics Manual.

View Details

Posted by:  Adam Turteltaub

Social media keeps evolving:  From MySpace to Facebook to Twitter to SnapChat to TikTok to whatever comes next.  One thing stays the same, though:  there are lots of compliance risk.

In this podcast Kortney Nordrum, Regulatory Counsel and Chief Compliance Officer at Deluxe and author of the chapter “Social Media Compliance” in The Complete Compliance and Ethics Manual shares both the state of the regulatory landscape and practical advice on how to best manage the challenge.

When it comes to regulators, several have weighed in, she reports.

The National Labor Relations Board (NLRB) has wavered back and forth on various issues but has consistently emphasized that employees may use social media, and employers cannot limit their activities so long as those activities do not have negative impacts on the reputation or credibility of the business. There are, however, a great number of nuances, including that griping about an employer is generally protected. The Securities & Exchange Commission (SEC) is focused on ensuring that anyone who invests has access to company information at the same time. As we have all seen with Elon Musk’s ongoing battles with the SEC, they tend to frown on certain statements made on Twitter. The Equal Employment Opportunity Commission (EEOC) has been consistent in its approach, warning that companies that do social media searches of their employees need to recognize that this may reveal an employee is a member of a protected class, and that information may not be used in a way that adversely affects the employee.

For compliance teams it’s important to lay out social media policies using rules that are easy to understand.  The rules need to be reasonable, simple and use plain language.  An example may be, “Do not share confidential information,” with an explanation of what confidential information is.

When working with the team that controls the organization’s social media account, have a separate policy for them since different issues likely apply.  Provide them with training and be prepared to serve as an ongoing resource eager to engage in conversation about what is good and bad practice.

In short, social media and the related risks are here to stay.  In fact, you’re reading this on a form of social media.  So, it’s best to listen in and learn how to manage the risk.

View Details

Posted by:  Adam Turteltaub

Even if Covid were to disappear tomorrow, it’s clear that things will long remain different, including how we work.   Many employees will never spend eight hours a day, five days a week in the office again.

So how should compliance teams address the new work environment and ensure a culture of compliance?  That’s the subject of this podcast with Lisa Beth Lentini Walker (LinkedIn), CEO & Founder of Lumen Worldwide Endeavors and a member of the board of the Society of Corporate Compliance and Ethics & Health Care Compliance Association.  It’s also the subject of the chapter “Building Cultures of Integrity in Remote and Hybrid Environments” in the latest edition of The Complete Compliance and Ethics Manual.

As Lisa Beth explains, even though we have grown accustomed to new ways of connecting online, it’s still not the same as being in the same physical environment with someone.  That’s a challenge, she reports, because there is an element of proximity bias in how we interact, preferring people that are closer to us.  This bias will require a conscious effort to avoid creating an “us-them” culture where those who are in the office differentiate themselves from those who aren’t.

Preserving and strengthening a corporate culture will also be a greater challenge since culture, itself, is an accumulation of experience of everyone in the organization.  When people are less connected, it takes more work, particularly when it comes to communication, to build clarity around vision and values, the stories people tell about the organization, and the support of leadership.

Compliance teams will need to be alert for signs of trouble, including ethics incidents and disengagement.

To address these problems, she recommends starting with the senior team.  Educate them as to what is happening and gain their support for a renewed, resilient culture of integrity.  Then, make sure the policies and procedures are designed to help support the culture.

Throughout, it’s important to communicate, not just once but frequently,  More, you need to do so in a tailored way that reflects the needs and mindsets of the various groups within your organization and encourages their feedback.

Listen in to learn more about how to build and sustain an effective compliance and ethics program in the new work world.

View Details

Posted by:  Adam Turteltaub

The No Surprises Act is a patient-friendly piece of legislation designed to protect consumers from unexpected medical bills.  As Sandra Joe (LinkedIn), Senior Compliance Analyst at NorthShore University HealthSystem explains in this podcast, surprise bills had typically arisen in three cases:

A patient visits an out of network provider in an emergency While at an in-network facility, charges are incurred by an out-of-network provider When self-pay patients undergo a procedure and only find out what it costs after the fact

The No Surprises Act established new Federal protections to prevent these costly occurrences.  It bans out of network cost-sharing and balance billing.  It also requires that health care providers and facilities provide easy-to-read and understandable notices explaining their billing protections and providing information on who to contact for patients who are concerned that their protections were violated.

For the uninsured and those choosing to pay for their own procedures, the law provides that they receive a good faith estimate, at least one day in advance, for a scheduled procedure.  If the charges exceed the estimate by $400 or more, patients have the right to dispute the cost.

So what should compliance teams do?  Be sure to document the steps you take to put proper controls in place, including the training that is provided to the workforce.  Familiarize employees with how to update good faith estimates if there are changes, and make sure the necessary disclosures are posted in both provider settings and on the website.

Listen in to the podcast to learn more about how not to be surprised by the requirements of the No Surprises Act.

View Details

Post by:  Adam Turteltaub

ESG has exploded, but what is it and what is the role for compliance teams?  Lisa Beth Lentini Walker (LinkedIn), CEO & Founder of Lumen Worldwide Endeavors and a member of the board of the Society of Corporate Compliance and Ethics & Health Care Compliance Association provides her answers in this podcast.

ESG, which stands for Environmental, Social and Governance, she explains, is very much an evolution of the Corporate Social Responsibility (CSR) movement.  It focuses beyond shareholder value and looks at the role of the organization much more broadly, including who and what it is accountable to.

ESG does not work as an independent initiative, she warns.  Instead, it must be integrated into operations, much like privacy or safety.  It needs to be aligned with how the organization operates in the world and, importantly, the company’s values.

Because it is so broad in its sweep, encompassing a wide range of compliance issues such as human trafficking and rights, bribery, environmental laws, non-discrimination, and anticorruption, it’s a natural area for the compliance team to get involved.  But, ESG goes beyond the legal requirements and encourages organizations to set a higher floor for its behavior, which is, of course, very reminiscent of ethics programs.

So where do compliance and ethics teams fit?  They need to be a part of the solution, providing rigor around metrics and risk assessment.  Compliance professionals also need to be present to advocate for values-driven decision making here, as elsewhere.

Listen in to learn more about ESG, compliance and the relationship between them.

View Details

Post by:  Adam Turteltaub

There are, of course, many lawyers in compliance.  They typically enter the field after stints as prosecutors, white collar defense lawyers, or after careers in law firms and the general counsel’s office.  Less typical, and arguably wrongly so, are attorneys who have been in the military’s Judge Advocate General (JAG) Corps.

In this podcast, Matt Reid, General Counsel and Chief Compliance Officer for iron and steel producer Bradken, shares his journey from JAG to compliance officer, and, as he explains, his time in the JAG Corps was better preparation than many would think.

Practicing law in the Army gave him the opportunity to experience an enormous range of experiences.  He worked as a prosecutor in Germany and defense attorney in the DC area.  While stationed in Egypt, the position consisted of what the military calls “administrative law” but is very similar to compliance.  He regularly dealt with issues such as conflicts of interest and export controls, for example.

When he joined the civilian world he was surprised by the similarities but also one key difference:  the power of the compliance officer, particularly in healthcare  As he explained, in the military he was an advisor to the commander, who ultimately made the final decision.  In civilian life he discovered that saying “no” to something had much greater impact and there is a need to be careful to be judicious in the word’s use.  Instead it’s better to use “yes, but” and work with the business team on finding a solution.

Fortunately, that’s a skill JAG officers learn and one of the reasons why he is an advocate for bringing more former military attorneys into the compliance profession.  They are expert at finding solutions that accomplish the mission while still falling within the lines.

Listen in to hear more of his fascinating experiences and insights, and maybe change your perspective when next looking to add a member to your compliance team.

View Details

Posted by:  Adam Turteltaub

Joseph Suich has been enjoying an interesting and well-traveled career. His work at GE took him from Connecticut to Moscow to Prague to Zurich, where roles ranged from chief compliance officer to general counsel and later Global Chief Compliance Officer for GE Power.

After his time with them he joined the New York State department of Public services to form and run a net unit, the Office of Investigations and Enforcement, which investigates and prosecutes utilities.

He subsequently left there and is currently serving as US Chief Compliance Officer for National Grid, an electric utility that serves customers both in the US and United Kingdom. He also teaches compliance law at the Albany Law School.

In this podcast he shares his fascinating journey as a compliance officer and insights into the minds of regulators from his years of experience interacting with them. For companies facing a regulatory issue he advises approaching the regulator honestly. A company instantly loses credibility, he warns, if it pushes a bad position from the start. If the company or an employee clearly did something wrong, don’t argue otherwise. Admit the mistake and focus on what you did right.

Also, be aware that the regulator may not fully understand the context of your business. Be sure to invest the time in helping him or her appreciate the challenges and the reasons behind the actions your organizations took.

Joseph closes the discussion by looking to the future, particularly the fast evolving Environmental, Social and Governance (ESG) movement. While ESG is still in flux from a compliance perspective, he advocates compliance teams begin to get a handle on its scope, how the organization is monitoring it, and the risks involved.

Listen in to hear more about his career and experience.

View Details

Post by Adam Turteltaub

Every organization has policies, typically many of them, and often varying by department and location. Getting a handle on all of them can be a difficult task, and ensuring that there is consistency adds a layer of complexity.

Swagata Roy, Director, Compliance Strategy and Performance, Liberty Energy and Water, is an advocate for creating a policy hierarchy. It can help overcome common challenges, she argues, such as keeping policies current, relevant and accessible.

As she explains in the podcast, a policy hierarchy is a partially centralized and partially decentralized approach to managing policies that is risk based. It begins with assigning a level to each policy according to the risk and how widely applicable it is. At the top would be the code of conduct and those policies addressing the greatest risk areas. Other higher-level policies include those addressing health and safety, privacy, diversity and the environment. All of these tend to be reviewed and approved at the top level of the organization.

Below these policies are ones that are jurisdiction or procedure-based, such as gift and entertainment. And still others fit under these.

Careful thought must be given to ensure that lower-level policies fit squarely under higher level ones and both provide added details and consistency.

Once the hierarchy is created it needs to be monitored on an ongoing basis, she explains, to adjust for regulatory changes.

To get business ownership she offers two pieces of advice. First, make it clear that compliance has centralized the administrative aspects of policy management, which makes it easier for the business team. Second, if your organization has a compliance champions or ambassadors, use them to socialize the hierarchy and act as your eyes and ears.

Listen in to learn more about creating an effective compliance policy hierarchy.

View Details

Post By: Adam Turteltaub

The pandemic may, please, finally, we hope, be coming to an end. That’s great cause for celebration, but it also portends a period of adjustment for healthcare, according to Raul G. Ordonez (LinkedIn), Associate Vice President for Compliance at Jackson Health System.

Telehealth, which exploded during the Public Health Emergency (PHE), is likely to see several changes.

As he explains in this podcast, before the pandemic telehealth was largely limited to underserved rural areas. When the emergency began, though, the Centers for Medicare and Medicaid Services (CMS) which has latitude in determining which services were allowed and who was eligible, allowed for hundreds of new codes for telehealth that are reimbursable for Medicare patients. Eligibility was expanded to patients all over the US, even those seeing a doctor from their own homes.

Once the PHE ends, CMS has stated that many of the waivers for telehealth services will also come to an end. While there will be a notable exception for many mental health services, the end of the vast majority of waivers calls for compliance teams to start planning for a very different future than the present climate. And, they must do so at a time in which the US federal government has a keen eye on False Claims cases and the OIG, as a part of its workplan, will be looking at a host of telehealth-related items.

Listen in to learn more about how to prepare for the upcoming, new era in telehealth.

View Details

Post By: Adam Turteltaub

For most of us, it’s hard to imagine a time before the US Federal sentencing Guidelines came into being and set the direction for compliance and ethics programs.

Jeff Kaplan, partner at the law firm Kaplan & Walker and longtime compliance leader remembers those pre-Guidelines times and in this podcast we discuss the changes that have come, didn’t happen and may yet occur with compliance programs.

Even after thirty years he reports that, in many ways, we are still getting started. While many organizations have developed robust compliance programs, a large number are still at the starting gate. In addition, many business people, particularly in management, tend to think of compliance as something less than sales, marketing or other departments, and not worthy of the investment.

A related challenge is what he called the “mission accomplished phenomenon”, which he defines as a tendency to see compliance as an event rather than an ongoing program.

Still, he sees the glass as something more than half filled and creating new challenges. For more developed programs, he believes, now is the time to maintain a sense of urgency and improve performance.

One approach he advocates for is a stronger embrace of the field of behavioral ethics. A part of social science, behavioral ethics illuminates what impacts our ethical decision-making and illuminates the biases which can lead to less than ethical decisions, even when there is intent to do the right thing.

Looking to the future, he sees more work being done in the area of incentives, a struggle with Artificial Intelligence, and more nanocompliance.

What is nanocompliance? Listen in to find out.

View Details

Post By: Adam Turteltaub

Matt Kelly, Editor & CEO of Radical Compliance makes a strong case in this podcast for a need to reassess cyber risk.  It is becoming, he says, less of a technical issue and more about how companies interact with others:  Employees, contract workers, vendors and customers are all risk points for cyber intrusions.

This calls for organizations to ask some key questions about outside partners:

Should they have access to the network? What access should they have? Are they straying where they shouldn’t?

These, he notes, are all questions compliance professionals are likely used to asking about other risk areas.

The solution, he argues, involves training, of course, but it also involves using some of the techniques developed for vetting third parties for anti-corruption risk.  Ask the business people:  How are they going to use the supplier?  Why are we outsourcing this?  Why did you select this third party?

Bottom line is that you need to understand what the business purpose is and ensure the relationship is fit for the purpose and properly monitored and audited.  It’s also critical to ensure that when a relationship ends, access to systems ends with it.

For existing relationships, make sure there is a clear understanding of who owns it.  In some cases, there may no clear owner, which can be a red flag that the vendor probably doesn’t belong on your systems.

Listen in to learn more and hear Matt discuss issues such as how to overcome vendor resistance to audits, understanding when a vendor’s IT security is even better than yours, and the importance of a software bill of materials.

View Details

Post By: Adam Turteltaub

Self-funded health plans are very common these days among larger employers and governmental entities. Private sector plans are typically subject to ERISA, which imposes a fiduciary duty, and even plans covering government employees have fiduciary obligations.

What does that mean in practice? Chris Deacon, Senior Vice President of 4C Health Solutions and former director of the State of New Jersey Health Plan, explains in this podcast that the plan administrator, vendors and the plan, itself, have a fiduciary duty. That means all actions have to be performed for the best and sole interest of the beneficiaries and the plan.

Vendors have to be selected and evaluated accordingly. Duties have to be carried out prudently. The plan’s documents must be followed consistently. So, for example, the plan can’t pay some out-of-plan claims and not others.

It sounds fairly clear, but, she explains it isn’t because of the opacity in health care pricing. It’s difficult to know if the charges are reasonable or not.

One step she strongly recommends is to demand ownership of the claims data and insist it be provided in a way that is usable. That will help ensure that the money is being spent properly, and the plan administrators are living up to their fiduciary obligations.

Listen in to learn more about how to live up to the fiduciary duties of your self-funded plan.

View Details

Posted by:  Adam Turteltaub

As the business world embraces Artificial Intelligence (AI) it’s important for compliance teams to understand what this technology is and what risks is can bring.  In this podcast and at the 2022 HCCA Compliance Institute oversight considerations for ethical AI are addressed by Shawn E. Marchese, Global Head of Compliance; Nakis Urfi, Product Compliance Officer; and Dr. Keith Grimes, Clinical Digital Health & Innovation Director all at Babylon Health.

At its root, they explain, AI is about automating tasks that would otherwise require human brain.  This means activities such as pattern recognition and even decision making.

The role of AI in healthcare is increasing because there aren’t enough people to fill all the positions.  It is already used for predicting which groups are at higher risks and for monitoring changes in X-rays.  And, if you have ever encountered a chat bot, that’s AI in practice.

Over time they anticipate AI being used in more places to optimize healthcare delivery, summarizing notes and as decision support for prescribing.  It can also, potentially, minimize the risk of false positives and even be used to track regulatory changes.

But, with AI come several concerns.  If unsupervised it can make decisions that can’t be controlled and have unintended consequences.  Bias is also a persistent problem, especially if the data is not representative of the population.  There have already been several examples of discriminatory behavior in hiring, loans, and facial recognition.  The AI team needs to take steps to ensure that it is feeding the AI accurate data and correcting for biases.

So what should the compliance team do?  Stay on top of the AI use in your organization.  Make sure that it is producing accurate results and ensure that there are safeguards in place with human oversight.  Be sure to address the privacy, security and safety concerns to avoid losing trust and damaging your organization’s reputation, not to mention some potentially large settlements.

Make sure, also, that there is ethical oversight that is cross functional.  There should be a process for raising and reviewing ethical issues, which can come up with some frequency.

Listen in to learn more, and then plan on attending their session at the 2022 HCCA Compliance Institute.

View Details

Post By: Adam Turteltaub

Operation Lava Jato (Carwash) had a profound effect on business in Brazil, with countless companies caught up in one way or another in the corruption scandal.

State oil company Petrobras was no exception, but, as is the case with so many compliance incidents, the question quickly moved from what happened to what are you going to do about it.

At the 2022 SCCE European Compliance & Ethics Institute, Salvador Dahan (LinkedIn), Executive Director, Chief Governance & Compliance at Petrobras will be addressing the company’s ethical journey. He shares some of the story in this podcast.

Petrobras entered into a Non-Prosecution Agreement (NPA) that included a provision that the company had to agree to collaborate with all the investigations underway, not just with the US. The company also agreed to $850 million in fines to authorities in the US and Brazil. And, of course, it was required to improve its compliance program and internal controls.

How did the company go about the transformation? Leadership provided a strong tone at the top. The head of compliance was placed at the Executive Director level and made a part of any major decision in the company. In addition, there is a direct line of report to the board of directors. There is even a formal hiring and termination process for the compliance team to protect the program against retaliation.

The company also embraced a three lines of defense model, with compliance playing an integral role.

Petrobras is continuing along its journey, Salvador reports. They are working to restore employee confidence and helping the workforce see the company is made up of individuals with strong ethical values. Supporting this initiative has been a great deal of communication designed to show that these are real actions, not just words. Every meeting in the company now starts with a five-minute discussion about ethics, integrity and transparency. They have also established a force of more than 200 ambassadors, known as Integrity Agents, to build bridges between the compliance team and the business unit.

What does he recommend for other organizations going through a crisis? Several things:

Quickly recognize the situation, accept what is happening and begin collaborating Talk to employees with transparency, outlining the next steps, long-term commitments, as well as do’s and don’ts. Provide a clear sense of direction. It mitigates noise and a lack of confidence. Find out your vulnerabilities, and then act as soon as possible. Get an independent opinion. An outside voice can be very helpful.

Listen in for more lessons, including how to continue to strengthen your organization, even after the NPA comes to an end.

View Details

Post By: Adam Turteltaub

Doctors, nurses and other medical practitioners must keep up often multiple licenses and certifications. There are everything from board certifications to confirmations of inoculations to track.  Adding to the complexity: equipment has its own set of licenses and certifications, and so do the facilities themselves.

Miss a deadline, and it’s not just simply a matter of paying a late fee. It may mean a surgeon can’t operate or a piece of equipment needs to be taken offline, negatively impacting both patient care and the bottom line.

Keeping on top of it all can be a nightmare, explains David Baule, CEO of MISO3 in this podcast. The challenge is amplified by the fact that each certification has its own renewal dates, frequency of renewal, and can be tracked in multiple different places, including third party databases.

How do you stay on top of it all? Like much else in compliance, he advises, by prioritizing. Also, look to automation.

Listen in to learn more about the risks and possible solution.

View Details

Post By: Adam Turteltaub

The relationships between Enterprise Risk Management (ERM) and compliance risk management is a complex and confusing one.  There is the potential for overlap and even conflict.

To help clear the air and improve the relationship among the various approaches to risk, Bret Bissey, Vice President, Chief Compliance Officer, Gateway Health and James Rose (LinkedIn), Managing Director, SunHawk Consulting will be leading a session “Establishing the Enterprise ERM/GRC Strategy with Compliance in Mind at the 2022 HCCA Compliance Institute, which will be taking place online and in Phoenix March 28-31.

In this podcast they offer a wealth of advice for compliance teams including:

Having the right sponsor is key This is about having a dialogue cross the organization The goal is to help business operators achieve their goals A good process helps prevent surprises There are naturally going to be some tensions, particularly when it comes to allocating resources Expect different views of how much data should be tracked and how useful it will be Be sure to capture the goals and interests of the C-suite and board

Listen in to learn more and then join us in person or online for the 2022 HCCA Compliance Institute.

View Details

Post By: Adam Turteltaub

The Challenger and Columbia disasters were as instructive as they were tragic, providing countless lessons for organizations, including for compliance and ethics professionals. The January 2022 issue of Ethikos focuses exclusively on them and features an extended article by Professor J. Mark Maier, Founding Chair of the Leadership Program at Chapman University

Professor Maier has dedicated much of his career to studying the disasters and sharing lessons from them, even producing a documentary. Of particular focus for him were the efforts of Roger Boisjoly and Allan McDonald, who refused to sign off on the Challenger’s launch. Professor Maier and McDonald frequently spoke about leading with integrity, including for US Space Command’s Leadership Development Program.

In the latest Compliance Perspectives podcast Professor Maier explores the many ethics issues that led to these disasters. The topics discussed include:

Speaking Truth to Power It’s not easy for people to speak up to individuals who are more senior than they are. There’s inherent risk, especially when delivering bad news that can imperil a project. Adding to it, management often signals, intentionally or not, that they want things to stay on track, schedule and budget.

This calls for a focused effort by leadership to create a different mindset, one that encourages people to bring up unpopular truths.

Risk Complacency In the case of the Columbia disaster, the spec was for no foam to fall off the external fuel tank, but it kept happening. In fact, it happened so frequently and with no effect. As a result, NASA grew complacent about the risk, until ultimately the foam did damage a wing and all aboard perished.

The Dynamic of Internal vs. External Risk It can be too easy to downplay the external risks and focus on the internal risks we perceive to ourselves and our careers.

The Fallacy of “It’s a Business Decision” Often a decision is treated as “just a business decision” when, in fact, there is an ethical issue at stake. Focusing solely on the results, dollars and cents fails to consider the importance of the means, and not just the end.

The Importance of Little Things It is easier to fix a problem when it is small than when it is big. However, when it is small it is too easy to ignore until it is too late.

The Value of Servant Leadership This often-misunderstood term is explained, and Professor Maier argues that when management leads as a servant of common cause rather than from a position just of power, it is far more advantageous.

Listen in to learn more lessons from these two tragedies.

View Details

Post By: Adam Turteltaub

Stephen Paskoff has some serious concerns about Diversity, Equity & Inclusion (DE&I) training. The President and CEO of ELI definitely believes training has advantages, but too often he has seen it done improperly.

Sometime is a part of a one and done proposition. Other times he has found the training to be divisive, which runs counter to the unifying message of DE&I. The training proposes stereotypes for a group, which can cause both internal problems, as well as legal risk.

So what’s the right way forward?

First, he argues for recognizing that the purpose of the training, like the DE&I initiative, is to change habits, which is very complicated. The new habits need to be specific, clear and few, and they have to be consistently reinforced.

Second, the training has to align behavior with the values, vision and mission of the organization, not an unattached initiative. It has to be a part of an organization imperative, like sales, quality and innovation.

Communication has to extend beyond the training. Leadership must support it publicly, and so too must line managers.

What else makes for success?

There needs to be consequences The effort must be continuous, like safety, quality and innovation The program needs to be seen as bringing values to life There needs to be clear standards that are linked to the organization’s growth

Listen in to learn how to make your DE&I initiative and training work.

View Details

Post By: Adam Turteltaub

At the 2022 HCCA Compliance Institute, Tonja Wise (LinkedIn), Corporate Director of Compliance, Sharp HealthCare will be leading a session “Your Audit Plan is on Point…but How is Your Moderating Game?”  It’s a very good question, and in this podcast she offers very helpful advice on how to improve your monitoring efforts.

First, since monitoring and auditing are often referred to together as if they are the same thing, she defines the difference between the two.  Monitoring, she explains, tend to come after a problem, or potential one, is identified and there is a need to ensure that the remediation in place is working.

Like other areas of compliance she advises a risk-based approach.  Health care entities should focus on areas of recent government audits or any place they already have a correction plan in place.  Avoid focusing on areas where the risk is low of either an incident or having to pay a substantial penalty.

To have a strong monitoring program in place, Tonja explains, you need an experienced staff and the right software.  An Excel spreadsheet to track things is probably not enough.

Listen in to learn more about how to effectively monitor your healthcare compliance program, and then join us for the 2022 HCCA Compliance Institute.

View Details

Post By: Adam Turteltaub

Given the dangers of third-party risk, it’s not surprising that so many organizations have developed supplier codes of conduct. Like everything else in compliance, though, the trick is in just having one, its in having the right one.

Patty Houser (LinkedIn), Compliance Counsel at Land O’Lakes reminds us in this podcast that a supplier code of conduct should be like an internal one: set high expectations ,provide guidance and promote ethical practices. It is also a chance for the company to confirm its commitment to integrity and sound business practices.

The supplier code should be recognized as a statement to suppliers and public about what it stands for, including the company it keeps.

Going much beyond that, and getting too far into the weeds, though, is not advisable she says. There are other documents for getting into the specifics, including the terms of the contract.

When drafting a supplier code she recommends:

Focusing on the challenges of the jurisdictions with the most risk Looking at what your own internal code of conduct says Examining supplier codes of others in your industry Taking the time to understand the sophistication of your suppliers Assessing the risks inherent in the industry Reviewing internationally-recognized standards Setting expectations and giving guidance Asking your suppliers for feedback to see if what you has written is workable. As she warns, “Compliance with the impossible is no compliance at all.”

Finally, don’t forget one other key audience for the supplier code: your organization’s business unit. To secure their buy in, take them back to your own code of conduct and the commitment to doing things the right way. Also, show them the risk of a supplier that doesn’t do things properly, including the reputational damage it can do to your firm.

In the end this is all about finding well qualified business partners that can both supply and protect your business.

View Details

Post By: Adam Turteltaub

The pandemic is both increasing burnout and making it harder to differentiate between needing a break and being, well, just completely done.

As Ellen Hunt of Spark Compliance and Melanie Sponholz, Chief Compliance Officer, Waud Capital Partners explain in this podcast (and will also share in their session at the HCCA Compliance Institute), common signs are fatigue (to the point of not wanting to get up and start work), feeling cynical or jaded, irritability, inability to concentrate, not feeling your usual self, and no sense of purpose. Another sign to watch out for: the inability to have a sense of accomplishment. If being able to cross something off of your list no longer brings with it any feeling of reward, it’s a telltale sign of burnout.

To avoid burnout they recommend building a separation between work and not working. That’s harder to do with so many of us working from home, but it’s necessary.

Try to focus on doing some things completely separate from work that make you happy. Anything involving movement – walking, running yoga – can help. Think about things that you used to do at home that filled your cup when you left work. It could be cooking a meal, reading a good book, or spending time with non-work friends (safely, of course).

At work, they recommend three specific behaviors:

Always assume positive intent. Don’t think that people are out to get you, even if their words may seem a bit hostile. Practice the pause. Take a deep breath and ask yourself, “Are they really insulting me, trying or be rude, not understanding?” Ask people why they asked the question or made the decision that they did. It could have just come from a misunderstanding. Ask yourself: Do I really care?  Is this something that is going to matter next week or year?

Finally, they advise making that effort to revive and build out your network. It will help you expand beyond the core people you normally interact with and find others than inspire you. It’s also beneficial to talk with others going through similar circumstances to be reminded that you are not alone.

So, schedule that 30-minute virtual coffee, or just send a note to someone you haven’t been in touch with to see how they are doing. Reach out to people you admire. Many will be surprisingly happy to hear of your support and be more than willing to talk.

You can even take the next step of creating something of a board of advisors for yourself.

Listen in to learn more, and then be sure to attend their session at the 2022 HCCA Compliance Institute, which takes place in Phoenix, March 28-31 and is also available online.

View Details

Post By: Adam Turteltaub

Markus Juttner, Vice President & Global Head of Compliance at E.ON doesn’t focus on individual blind spots or taboos. Instead, he focuses on the organizational ones. In fact, as he argues in this podcast and will explain during his talk at 2022 SCCE European Compliance & Ethics Institute, he thinks it’s a mistake to focus on the individual.

Since the core task for compliance teams is to prevent, detect and respond to corporate misconduct, it calls for an organizational level of analysis. You need to understand that the organization is an entity of its own.

There are four common challenges that he sees:

The compliance team not being transparent to the management board: If they ask if the program is effective, you need to be honest and admit if you do not know The risk assessment only addresses what we expect to see. There may be other factors we have not thought about. A lack of transparency by the business side when reporting to compliance The habits that are normal and a part of life in the organizations

All of these can have dramatic effects on the compliance program, and all reflect the culture of the organization. As a result, it is essential to take the time to determine what the culture is, as well as the many subcultures.

Listen in to learn more and then join him at the 2022 SCCE European Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

There are a lot of good reasons to do a periodic review of your healthcare compliance program, not the least of which is that the government expects it.

But when’s the right time?  How do you get the management support?  What outside experts do you need?  And how do you integrate the results into your workplan?

Those questions are tackled by Anne Daly, Vice President of Compliance, Samaritan health System, Judy A. Ringholz, Vice President of Compliance and Ethics & Chief Compliance Officer, Jackson Health System and Steven W. Ortquist, Founder & Principal, Arete Compliance Solutions in this podcast and at their session “How to Assure that Your Next Compliance Program Review Confirms Performance and Helps Improve Your Compliance Program” at the 2022 HCCA Compliance Institute.

It’s important, they explain, to make sure that you have your arms around the program before you begin the review.  If you’re new to the role, you probably don’t know enough about the program to make the review as successful as it could be.

Once you feel that you are ready and that it’s time to have outside eyes review the program, it’s important to select a vendor with healthcare-specific experience, ideally with experience interacting with enforcement.  Make sure they also have a solid understanding of the government’s expectations as well as your organization’s goals.  Be sure they also are well versed in the fiduciary duties of healthcare boards and have the personal presence to be able to present to the board.

One thing else to do: make sure the consultant is reasonable.  You want someone who will give you actionable recommendations, not someone caught up in a quest for perfection.

Be prepared to dedicate significant staff resources to help the review, most likely including a dedicated person who will be on point for the project.  A consultant is going to need your team to provide a lot of documents about the program and assistance in scheduling interviews with key employees.

Once the work is done and the report is drafted, it’s a good idea to review it with the consultant to make sure that he or she truly understands the organization and didn’t misinterpret any information.

Be sure also to meet with the board and key leadership so that they understand the purpose and benefits of the review, including that it is a part of their fiduciary duty to have an effective compliance program.

And, be sure to bring your workplan to the final presentation to the board.  That’s an ideal time to both demonstrate what you plan on doing and ask for the resources you need to get the job done.

Listen in to learn more, and then join us in Phoenix (in person or virtually) March 28-31 for the 2022 HCCA Compliance Institute.

View Details

Post By: Adam Turteltaub

At the 2022 SCCE European Compliance & Ethics Institute Dr. Jan Sprafke, Head of Compliance, Europe and Latin America and Jad Mhanna, Regional Compliance Officer at Ericsson will be leading a session entitled Cultural Divide and Compliance. The session, and this podcast, will examine some of the challenges in implementing compliance programs in non-Western countries.

There are three common issues that they find when implementing a program, especially in the anti-corruption area. First is the belief that it is a foreign law being imposed upon the local community. Second, there are different perceptions of what constitutes a bribe. Third, many believe that this is another Western way to mingle in local affairs. Some may also see anti-corruption laws as weaponized: designed to penalize economic competitiveness.

When considering how to overcome these barriers they caution to remember that not all of the workforce shares the same perspective when it comes to compliance. Some don’t really care and will do what they are asked to. Others will be smiling and saying “yes” but thinking about how to get around the rules to do what they want.

The third is a small minority who will speak up and share their concerns. This group needs to be handled carefully. It is easy to see them as opposition when, in fact, they are not.

So what should a compliance team do when faced with these challenges? Jan and Jad recommend avoiding the temptation to force compliance and instead take the time to understand the culture. In some places simply sharing the rules will be enough. In others it may mean taking the time to explain your goals and build a deeper understanding of why this initiative is important.

Other advice they provide:

Don’t make this a headquarters initiative, partner locally Leave room for discretion and flexibility Understand what the local definition of corruption is and what is considered a bribe Run frequent risk assessments and compliance audits Help the local business team understand their risk exposure

Finally, take the time to put yourself in the shoes of others. It will help you better understand your colleagues’ thinking and help make compliance more of a two-way street.

View Details

Post By: Adam Turteltaub

Anyone who works in healthcare knows that the regulations are complex, subject to change and hard to keep up with, especially if you don’t have a software solution tracking it all.

Jerry Shafran, CEO and Founder of YouCompli recommends identifying and focusing on the highly-regulated portions of your organizations first. For hospitals, he explains, those tend to be revenue cycle, lab, physician services and pharmacy. They represent about 70% of the regulations that come out.

Next, he advises nurturing relationships with the people in these parts of the enterprise. The keys to success include modifying how regulatory changes are perceived in the organization and making regulatory change management foundational to the compliance program.

Unfortunately, that can be trickier than it seems. Training needs to be checked regularly to ensure it is up to date. And, with the changes being so highly clinical and entering the organization in a disorganized fashion, there are ample opportunities for error.

To succeed, he suggests making things as simple as possible by creating repeatable processes, such as following the steps of know, decide, manage and verify:

Know that you are tracking all the regulator you need to and who in the organization is responsible. Decide if it applies to your organization and what needs to be done. Manage by ensuring all stakeholders are aware of what they are supposed to do and the deadlines Verify that the required changes have been put into effect, behavior changed and policies have been modified.

The verify step is especially important since that is what regulators will be looking for if they knock on your door.

Finally, as with so much else in compliance, communication is key. Every regulatory communication the compliance team shares with the organization has to be simple and simple to follow.  Write it for businesspeople and avoid legalese. Look to methods of communication other than email so the communication doesn’t get lost. And include in your communications plan a process for calling people to make sure that they have done what the regulation requires. That helps increase compliance and provides a record of the steps taken to comply.

Together this should make the process of keeping up with healthcare regulations more than a bit easier.

View Details

Post By: Adam Turteltaub

What does your organization have in common with a well-inflated basketball? Maybe not enough.

As Vanessa Mathews, Founder and Chief Resilience Officer at Asfalis Advisors explains, business resilience is like the air in the basketball: It’s what makes the ball bounce. And, we all want a business with the resilience to bounce back from a crisis.

Building resiliency depends on having the right capabilities, processes and people. It starts with understanding that a crisis is an incident that can impact your organization’s reputation, profitability, operations or all three.

Once you determine if you are in a crisis, the next step is assessment. This includes asking questions such as:

What is the scope? What are the likely consequences? How long will this be in the news? What risks are we willing to take?

Once you have those answers it is time to determine if you need to activate the crisis management team.

Surviving a crisis depends on preparedness, which includes leadership support, training and development, the resources to investigate, ongoing risk assessments, workforce tracking, and, of course, a culture of compliance.

Resilience in a crisis also requires a strong commitment to communications with regulators, third-party stakeholders, leadership, the board, employees, and in the case of healthcare providers, their patients, visitors and the community.

It’s not something that comes overnight, but it’s an investment well worth making to ensure that your business has the bounce it needs.

Listen in to learn more about how to build in resiliency, including what you will need from leadership, who needs to be on the crisis support team, and the role of organizational values.

View Details

Post By: Adam Turteltaub

When you think of online compliance and ethics training, you likely imagine courseware developed by a vendor and used by hundreds of other organizations.

USBank broke that mold, creating online training in house. It did so for a number of reasons, not the least of which is cost. While there were a lot of options out there from vendors, the expense of customizing and integrating it with their system was too high.

The training they created ranges from a humorous video showing people using chat to discuss a challenging (not in a good way) manager to a series of videos featuring Katie Lawler, SVP, Global Chief Ethics Officer, talking with various leaders of the bank while driving in her own car.

Jon Ackman, VP, Global Ethics Office at USBank explains that the chat exchange was designed to reflect the current time, in which so much communication is written rather than face to face. It delves into behavior that is culturally destructive while also showing the risks in this means of communication.  When people start writing there is more room for interpretation, and misinterpretation. Showing how to communicate more carefully was essential.

It also reflected the ethics team’s commitment to being authentic and empathetic to employee life, including the need to self-edit.

The driving videos drew their inspiration from both Carpool Karaoke and Comedians in Cars Getting Coffee. The team was thinking about ways to get people engaged and motivated while bringing important topics to life. They considered how people consume information these days and recognized that short videos are extremely popular and can be useful for sharing a more human story.

The result was a series of engaging conversations that the workforce could relate to.

Producing the videos was remarkably affordable, relying on a pair of GoPros, a microphone pack and some editing software.

For any organization thinking of pursuing something similar he recommends giving it a try, and not worrying about the small gaps, bugs and errors. They tend to make things more personal. Also, look at your communication plan and try a more targeted approach to communications.

Listen in, and be sure to watch the chat and driving videos.

View Details

By Adam Turteltaub

What if the face of your compliance and ethics program was a four-year old? It is at Ivy Rehab. Well, actually, several small children recently starred in a series of videos that the compliance team produced to support their annual compliance week. You can see an absolutely charming sample here.

In this podcast the company’s Director of Compliance Margarita Derelanko and Compliance Specialist Maria Campbell explain that they were inspired by other compliance-related videos that they had seen featuring kids. They had thought doing something of their own would be fun and attention getting. And, since the company was expanding its pediatric services, it made sense from a strategic perspective as well.

Working with the kids proved to be fun, and Margarita and Maria did their best to make it as easy as possible, including giving the flexibility to allow for some improvisation. Little kids aren’t always good at following a script.

Producing the videos took approximately two and a half months, and they recommend budgeting plenty of time since there are many steps involved. They brainstormed ideas, created a structure and brought in marketing. In the end they created a communications plan and a suite of tools to focus on a different topic each day: documentation, phishing, revenue cycle, social media and COVID-19.

In addition to the kids there was a trivia content, with badges for those who answered correctly, and raffles of a gift card.

What was the reaction of the workforce to the videos? Very positive. The videos engaged them and helped them see compliance people in a new light.

Be sure to watch a video and then listen to their podcast. If you don’t, we may send you to your room.

View Details

Post By: Adam Turteltaub

Due diligence during a merger or acquisition is difficult even in the best of circumstances. There is only so much you can see and so much time to see it before the deal closes. Add the complexities of a pandemic and business in emerging markets, and the challenge increases exponentially.

To determine how to conduct due diligence most effectively we turned to Krista Muszak, Global Services SOX Controls and Compliance Supervisor, Johnson & Johnson and Louis Perold, Principal, Citadel Compliance and a member of the Society of Corporate Compliance and Ethics & Health Care Compliance Association board. The two of them will be addressing the topic at the 2022 SCCE European Compliance & Ethics Institute.

To ensure that compliance due diligence is conducted effectively they recommended becoming activity engaged with the business and M&A team. This will help ensure you get sufficient information on the upcoming transaction and the business rationale behind it. Be sure also to understand the transaction itself and the various stakeholders. Together these can help provide guidance on how to conduct your due diligence.

From there it’s important to get a handle on the ownership of the target company and key staff. Meet with them, if possible, to learn about the compliance program.

When assessing the program, be sure to put data analytics to use. Helpline data is very worth reviewing: What is the volume? What issues are coming up? Are inquiries and allegations being responded to in a timely way?

Take a look, too, at the risk assessment and audits to see if there is any data that indicates trends of fraud, policy violations or other misconduct.

Try and make up for the lack of in-person meetings by increasing your number of touchpoints at the target company. Also, see if there are resources locally that you can turn to who can be your local arms and legs.

Finally, make sure you have a handle on the range of legal and regulatory issues that you will have to manage. Anti-corruption gets a lot of attention in emerging markets, but data protection and privacy, money-laundering, human trafficking, modern slavery and a host of other risk areas are present as well.

Listen in to learn more and then join us at the 2022 SCCE European Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

When a crisis hits, what do leaders and the crisis team want from the compliance team? It’s a question that Jonathan Armstrong, Partner at Cordery, addresses in this podcast and will be speaking to at the 2022 SCCE European Compliance & Ethics Institute in Amsterdam.

For starters he points out an oft-cited admonition: during a crisis the compliance team can’t be the department of “no”. Focusing on what can’t be done or on what happened in the past, for that matter, is counterproductive. The post-mortem will come later.  For now, the emphasis has to be on moving forward. The team is looking for people who will be able to find constructive solutions and alternatives.

Be sure, he advises, also to focus on how compliance can reduce the chance and size of penalties. To that end, focus on remediation as early as possible. Prosecutors will, after all, be focused on what the company has done to undo the problem and keep it from reoccurring.

Some of the other advice he provides in this podcast includes:

Rehearse a crisis before one occurs Be a single source of truth: these are the issues we have, this is what we will have to do, and this is where we are on the journey Bring crisis tools with you: crisis plans, templated press releases, specimen internal communications Be more directive than consultative

As importantly, take the time to understand the psychology and roles of leadership.  Leaders know stakeholders want to see action. Their predisposition will be to act and act quickly; if you’re too slow they may be ahead of you.

Recognize, too, that the board is sensitive to their own reputation as well. They will also be leaning to act quickly and decisively.

Listen in to learn more about how to prepare for a crisis, manage through one and come out the other end better than you might expect. Then plan on joining us for the 2022 SCCE European Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

When Katie Ignatowski (LinkedIn) stepped into a compliance role for the first time at the University of Wisconsin, she had to learn quickly and on the job. She spent time studying and learning from others and identified what she saw as two distinct approaches to compliance programs.

The first approach, which is the most popular, is risk-based. The compliance team provides experts that understand how to comply with high-risk areas. In her case, Title IX was of particular concern. She brought in a Title IX expert who could support the university’s Title IX coordinators and serve as an ongoing resource. This expert also helped write policies and develop training.

The second approach is to follow more of a second line of a defense model. Management serves as the first line of defense. Internal audit is the third line, and compliance is in the middle. The compliance team may convene a working group to address all aspects of compliance and culture, and, of course, risks as well.

So what makes sense for you and your organization? There’s no simple answer. She advocates in this podcast taking the time to decide which is better fit based on where you are starting out and how well you understand the risk landscape.

View Details

Post By: Adam Turteltaub

With the increasing attention paid to Environmental Social and Governance (ESG), questions have arisen as to what should be the relationship between compliance and ESG efforts. Some have argued for compliance to oversee ESG, while others see them as distinctly different endeavors.

Robert Smith [LinkedIn], Director, Business Compliance and Ethics for Serco Group plc provides his first-hand experience and insights in this podcast and will be sharing additional thoughts at the 2022 SCCE European Compliance & Ethics Institute.

ESG is not new to Serco since it had long been tracking the Corporate Social Responsibility (CSR) movement, which was in many ways ESG’s predecessor.

The more structure approach of ESG, he believes, is a natural progression. There are accounting standards and a growing body of laws and regulations.

To meet the organization’s ESG goals, the company has developed a clear framework with individuals responsible for ownership of the various elements of the company’s ESG efforts.  Each of these owners has clear KPIs. There is a structured reporting process that pull together strands from across the organization.

Robert, and compliance’s role, is to ensure the integrity of the reporting, as well as to connect the dots between the various reports. They are all assessed for materiality and eventually make their way into annual reporting.

Compliance is well suited to this role, he believes, both at Serco and likely elsewhere.  Compliance professionals are adept at helping create transparent structures and turning external frameworks into internal processes. In addition, with increased regulation of ESG and more and more laws addressing ESG-related issues, involvement of compliance teams is more than inevitable.

Listen in to learn more about the role of compliance in ESG efforts, including how to work with other stakeholders. Then be sure to join us at the 2022 SCCE European Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

The complexities of healthcare coding can be daunting, and they are all the more so now during the public health emergency.

To help clear things up are Bryan Beaudoin, Associate Director – Health Information Solution Lead at Protiviti and Kathy DeVault, Manager, HIM Consulting at USAI. In this podcast they explain:

As the Public Health Emergency continues clinical documentation and coding audit functions face an evolving list of compliance risks and limited resources to address these risks going into 2022. Although governmental enforcement agencies had briefly relented in enforcement activities during the onset of the pandemic, they have resumed enforcement activities moving into 2022. Key audit topics include: COVID-19 clinical documentation coding and billing, telehealth coding and billing, Evaluation and Management (E/M) selection, and documentation and coding of conditions determined by clinical indicators, such as Sepsis, Acute Renal Failure and Malnutrition. Prominent clinical documentation and coding audit risks in 2022 and tactics clinical documentation and coding audit functions can employ to more effectively audit target risk areas and collaborate with hospital stakeholders.

They also provide some good news: leadership is paying more attention to coding and clinical documentation because now they are more focused on quality data.

Listen in to learn more about how to manage coding in this fast-changing era.

View Details

Post By: Adam Turteltaub

Amanda Cohen is Director of Product at Resolver. Despite her work at a technology company, or maybe because of it, she has a very humble idea about the power of tech. As she explains in this podcast people tend to enter the technology buying process thinking that software can solve all their problems.

The reality is software doesn’t mean that automatically people will be behind compliance or that having a piece of software can make you compliant. You still need executive endorsement, leaders demonstrating that compliance matters and a compliance mindset in the organization.

She also cautions that just because there is a software solution in place doesn’t mean that there aren’t gaps in your program.

So what can good software do? It will help you, for example, track your regulatory requirements and provide a flow of usable information to you. And when it comes to regulations, it shouldn’t be a data dump, but instead extract the regulatory changes so you know what is happening and when changes go into effect.

Technology also can help you with the time-consuming task of creating reports by consolidating the information and generating data for you.

Other advice she provides:

Calibrate the software to your organization Engage with other stakeholders Be sure to pick technology that can grow with you and scale up Look to use technology in areas that are repetitive If pursuing AI, have a clear sense of what the objective is, and if it will bring in additional insights

Listen in to learn more about the limits and opportunities in compliance tech.

View Details

Post By: Adam Turteltaub

Daniel Garen, Chief Ethics and Compliance Officer at Vivint, divides compliance officers into two types. One is more comfortable running established, stable programs. The other is more comfortable diving in to a crisis.

A quick look at his LinkedIn profile and you can see he squarely sits in the latter camp, with a career being brought in to one company in the grips of a major compliance crisis and then another.

In this podcast he shares what he has learned from working inside organizations facing the fallout of a major compliance incident.

So how do you decide whether a similar path is right for you? Or how do you decide if the person you are about to hire in the midst of a major enforcement action is right for the role? Look for someone with a sense of both urgency and calm. You need (or need to be) someone who can work quickly without getting flustered.

When entering an organization in the midst of a major issue he advises immediately taking inventory of where things are, paying attention to two key buckets. Culture is one. The other is governance and structure. Ask: did the issue come up because of cultural issues or because people were trying to do the right thing but didn’t have the right structure in place? Or, was it a combination of both?

The answer will dictate how you proceed. And, if the answer is culture or both, start with culture. That’s the toughest challenge.

To help the organization start digging out he argues it is important to have the support from top to bottom.  With so much pressure coming from the outside – regulators, enforcement, the press, shareholders – having alignment inside is critical.

To get it both talk and listen. Communication will be key, as will be taking the time to hear and learn what the underlying problem is.

To get everyone moving forward, and to help enforcement see that you are making progress, he recommends data visualization tools. Even something as simple as a Gantt Chart can show what the process is that needs to be followed, and how far you are along in it.

As you work through the issues, pursue built-in rather than bolt on programs. It increases ownership and speed.

It also has two other benefits. First, it helps the regulator see what you are doing and build confidence that the company gets it.

Second, it helps the business team gain ownership of the issue and start seeing some benefits from the new processes that have been put into place. The changes become less about compliance mandates and more about process improvements. And isn’t that really compliance at its best?

Listen in to learn more about how to embrace and survive a major compliance crisis.

View Details

Post By: Adam Turteltaub

Most offices have art all around, generally of the not-so-special, bland, pre-printed poster kind. But many offices will have a few nicer pieces, whether it’s an oil painting, sculpture, mixed media work or perhaps some beautiful antiques to add a nice touch or spruce up the executive offices.

When you look at them, chances are you aren’t thinking of compliance risks, but in some cases you should. In this podcast Katie Steiner, attorney at the law firm Hahn Loeser & Parks, explains that acquiring art can be problematic if handled the wrong way. No organization wants to find out that the art on its walls was stolen, made from an endangered species or is a looted relic. Yet, it does happen.

To mitigate this risk she stresses that it is important to do your due diligence on the art. Take the time to make sure that someone is checking the provenance of the piece. An ownership history can provide reassurance that an ownership dispute is not likely to occur in the future, and that the piece is authentic and not a forgery.

Also, be mindful of the age of the piece. Generally speaking, newer art has less questions of provenance than older pieces

Ancient works of art, particular those made by traditional societies, often with religious meaning, may be subject to import restrictions in the United States. The 1970 UNESCO Convention on the Means of Prohibiting and Preventing the Illicit Import, Export and Transfer of Ownership of Cultural Property was adopted by the US. It limits import of objects from countries such as Cambodia and Syria. The State Department website lists several bilateral agreements that are in force.

Finally, be mindful of materials from endangered species, such as ivory and tortoise shell. These may be crafted into individual pieces or incorporated into antiques. Either way, it’s important to avoid violating any of the rules.

The bottom line is that corporate art doesn’t have to be limited to mass-produced posters. But, if your organization is investing in art, make sure that they are investing in a compliant manner.

View Details

Post By: Adam Turteltaub

Every three years the United Kingdom’s Institute of Business Ethics (IBE) releases its Ethics at Work survey, an international assessment of ethics in the workplace.

Much has changed since when the 2018 survey came out, and to learn more we sat down with Dr. Ian Peters MBE, Director of the IBE.

In this podcast he reports that while there are some dark clouds, overall the picture is much brighter than it was in 2018. Just 11% of survey respondents reporting feeling pressure to compromise ethical standards (down from 15%), and only 18% were aware of ethical misconduct.

Why the change for the better? He believes it is due to the efforts of compliance and ethics programs, which have grown more comprehensive. In addition, organizations have shifted their focus away from solely measuring success in terms of shareholder value to taking a broader stakeholder view.

When it comes to employee reporting of issues, the data showed something of a mixed bag. Fifty percent reported that they had raised concerns with management or an appropriate party. Sixty seven percent were fairly or very satisfied with the response. But, 43% reported retaliation of some sort as a result.

Clearly there is still room for improvement on this critical measure.

The survey also asked if employees perceived their line managers as setting a good example of ethical business behavior, and 71% said yes, an increase from 64% just three years ago. However, 32% thought that managers reward employees who get good results, even if they had bent the rules in doing so.

What impact has the pandemic had on the ethical climate? Their survey found that 37% reported ethical standards in the organization had improved, compared to just 8% who said that they had worsened.

Listen in to learn more about the survey, including anxieties about the future.

View Details

Post By: Adam Turteltaub

Perhaps the most intriguing title for a session at the 2021 SCCE Compliance & Ethics Institute was “Re-Thinking Employee ‘Engagement’: What’s on Your Compliance Program’s Dating Profile.” Not often you see references to dating the compliance department.

To learn more about the session and the ideas behind it we sat down with the speakers:  Asha Palmer, Chief Ethics and Compliance Officer, Convercent; Scheretta Wilson, Director, Ethics and Compliance, Endo1Partners; and Ronnie Kann, Head of Global Ethics & Compliance, Energizer.

While the title is a bit fun and out there, the lessons are very practical and close to home. The central idea is that people are watching and listening to see what compliance does and how it acts. That means compliance teams need to focus on being approachable, engaging with their audience and, frankly, trying to be likable. Or, as they put it, and to borrow from the dating apps, you want them to swipe right, not left.

So what does that mean in practice? For one, being a good listener. Just as someone who talks all the time is a bad date, while a good listener is usually a much better one, compliance needs to be a place where others feel comfortable speaking, raising concerns, and asking questions.

Compliance also needs to adjust to who is on the other side of the table. For leadership the keys they see are securing buy in early, keeping it simple, and using their own language, such as demonstrating financial ramifications.

For the rank-and-file workforce, success comes from helping them understand risk and what to look out for. It also means being approachable and present.

And, when it comes to middle management, a group that is often overwhelmed with demands from above and below, be collaborative. Ask them how things are going both personally and for the business. Find out what’s keeping them up at night. Talk about data, metrics, business impact and financial outcomes. It’s the love language of business.

Listen in to learn more, and then spend some time considering your own team’s dating profile.

View Details

Post By: Adam Turteltaub

In this podcast Rob DeConti, Assistant Inspector General for Legal Affairs within the office of counsel to the Inspector General at HHS, was good enough to share a tremendous amount of insight into what the OIG is seeing, thinking and doing.

As he explains, the public health emergency has had an enormous impact on the OIG, just like everyone else. It led to an opportunity to reassess, and also to handle things differently so as not to get in the way of the provision of care. Many corporate integrity agreements, for example, were paused, and discretion was used in investigations to reduce the impact on patients.

In addition, the office affirmatively took several steps, such as the November 2020 special fraud alert on speaker programs. They flagged several factors that seemed suspect, such as little or no substantive information presented, alcohol being served, lavish meals, an event held at a restaurant or sports venue, or other venues not conducive to learning.

Telehealth has also been an area of keen attention. As he notes, it has played a vital role during the current crisis and offers great promise. At the same time, though, fraudsters have stepped in with a number of schemes, including stealing patient information and billing for care that never was delivered.

Rob also provides insight into some of the issues facing nursing homes, charities set up by pharmaceutical companies that were not as independent as claimed, and the persistent problem of kickbacks.

Finally, and perhaps most importantly, he and the OIG’s office have reached out to the compliance community for feedback. As a part of their modernization efforts they are asking for the community’s comments on the efforts to improve the publicly available resource that the OIG provides. They are eager to hear from the compliance community about the best vehicles for delivering information, and the content and guidance that would be most meaningful.

He strongly urges the compliance community to submit their thoughts.

Listen in, learn what he has to say, and then feel free to share your thoughts with the OIG’s office.

View Details

Post By: Adam Turteltaub

Dr. Jennifer Williams, Director of Market Development & Education, Credentialing for GHX’s Vendormate reports in this podcast that the pandemic has had a broad and bold impact on credentialing, much of it overdo. In the past not everyone walking around a healthcare facility was adequately checked to determine if he or she belonged.

If your organization hasn’t done so already, she recommends tightening up procedures and examining the credentials of everyone who enters, even your own staff.

To make sure there aren’t gaps she recommends the development of scorecards, which can help define, measure, analyze and improve controls. They also can increase visibility and accountability.

And, as always, the activities of leaderships are important for success.

Listen in to learn more about how to improve the effectiveness of credentialing in your healthcare setting.

View Details

Post By: Adam Turteltaub

Bankruptcy doesn’t come up a lot at compliance conferences, but it did at the SCCE 2021 Compliance & Ethics Institute. Kasey Ingram, General Counsel & Chief Compliance Officer at ISK Americas and Rocco Debitetto, Partner at Hahn Loesser addressed the topic, which is one worth considering. There’s no guarantee that any company won’t end up in Chapter 11 or won’t acquire another company going through it.

As they explain in this podcast, while the importance of compliance doesn’t change during a bankruptcy, the environment in which it operates transforms dramatically.

Chapter 11 is designed to help the company breathe, reorganize, redeploy its assets and hopefully continue to operate. But while for rank and file employees it is likely business as usual (with a good amount of stress added) for management it’s a frantic time. More, who and where compliance reports may be very different.

The debtor in possessions appoints officers and managers to run the company, and these individuals may be different than the people the compliance team had reported to. They also are focused on, as quickly as possible, saving the company and getting it back on its feet.  Compliance is not a priority.

As a result, it’s important for compliance to do two things quickly. First, make sure the new management knows who the compliance team is and what it does. Second, let them know that you are not there to get in the way but to help avoid potential problems that will add greater complexity to the reorganization efforts.

On a tactical level there’s a need to ensure that leadership, when reviewing contracts, knows which ones are essential to running the compliance programs. Canceling the helpline contract, for example, may save money but should not be on the table.

Compliance also needs to be on the lookout for empty chairs. Chapter 11 is typically a time when there is substantial turnover. Keep a vigilant eye out for departures by people who have compliance responsibilities, and be prepared to backfill the positions.

What happens if your company is healthy and acquiring a company out of Chapter 11? Expect insufficient time to do the standard due diligence.

The good news is that the US Department of Justice generally understands that post-acquisition due diligence may be necessary, but don’t wait too long to do it. Then if you find issues, be sure they are addressed promptly.

In sum, even if bankruptcy seems far away, it’s worth taking the time to listen to this podcast. Even seemingly healthy companies can take a sudden downturn, or acquire another entity that is in Chapter 11.

View Details

Post By: Adam Turteltaub

False Claims Act cases often begin with a whistleblower, and worse, one who had reported the issue to management and nothing was done about it, at least not that the whistleblower knew.

David Schumacher (LinkedIn), a partner at the law firm Hooper, Lundy & Bookman and author of the Chapter “Government Investigations” in the new HCCA book False Claims in Healthcare is not surprised. As he explains in this podcast, compliance teams are often completely overwhelmed, making it difficult to determine what call is routine and what possibly raises a real and substantial issue.

Another complicating factor:  many calls get triaged and sent to teams outside of compliance. These teams may not follow up adequately, or at all.

To reduce these risks he recommends remembering that whistleblowers very much want to be heard. As a result, it’s important to respond, document responses to them and ensure that the issues that they raised are followed up on.

Once the investigation begins it’s important, he points out, that compliance stay deeply involved, even if legal is running point. The compliance team can assist the investigation, likely has a strong grip on the facts and will play a driving role in any subsequent remedial actions.

Once the government gets involved it’s important to realize the potential for disruption, and even paralysis, within then organization. As a result, an aura of calm needs to be projected.

Also essential: gathering the documentation and data to demonstrate to the government the effectiveness of the compliance program. That includes information such as the size of the compliance program, its scope of responsibilities, how many audits have been completed, what is on the workplan for next year, how many complaints have been fielded in the last several months (or years), and the number of educational events conducts, just to name a few.

And don’t wait to pull these documents together only once an investigation starts.  Documenting as you go is much more advisable.

Listen in to learn more about how to manage False Claims Act investigations, including what the current focus of the government is.

View Details

Post By: Adam Turteltaub

Healthcare risk doesn’t stop at the facility’s door. Covered entities have countless business associates (BA), each of which poses risks of its own. That, in and of itself, is a challenge, but Gerry Blass, President and CEO of ComplyAssistant observes in this podcast that many covered entities aren’t even sure of their complete list of vendors, let alone the risks that can reside in them.

To get a handle on this situation he recommends creating an inventory of your BAs and then dividing them into high, medium and low inherent risk. That involves looking at what each vendor does and the relative risks involved on a granular level. For example, an electronic medical record (EMR) vendor with a cloud-based solution is going to be inherently high risk. A vendor that transfers but does not store data may be just a medium-level risk.

With reports indicating that approximately 60% of breaches occurred at the vendor level in 2021, getting a handle on this risk is critical.

Of course, preliminary scoring of the risk level is only the first step. From there the organization needs to get more detailed information to ensure that there are adequate mitigation measures.

He recommends putting together a detailed list of questions both to ask during the onboarding process and later as a part of ongoing auditing and monitoring of the BA. Checking in periodically is essential because situations do change. The work being done by the vendor may have evolved, and so may the vendor’s internal risk management efforts.

He also advises looking at the BA’s own business associates. A given vendor may rely on 10 others.  As a result, it’s important to understand how the risk of the BA’s own BA’s are being managed.

Finally, he also addresses the need to reassess risk as organizations return to the workplace, including how remote access is handled.

Listened in to learn more about how to improve your healthcare vendor risk management processes.

View Details

Post By: Adam Turteltaub

Kerry Klewer (LinkedIn) is Director, Global Compliance Program for Tala, a Fintech firm providing financial services to the underserved in Kenya, the Philippines, Mexico, and india. These individuals, she explained, don’t have access to traditional credit sources, typically because they lack a credit score.

With Tala, individuals can apply for credit through an Android app. The company also offers card and account products. In addition, the company has recently partnered with Visa to offer crypto services to its customers.

The compliance challenges for Tala are substantial, she explains, with key risk areas such as consumer protection, tax, privacy and anti-corruption. Adding to the complexity: with many bad actors in this market, the number of laws have increased, and so, too has scrutiny.

The company has responded by launching a global compliance program. It conducted its first global risk assessment, and each country has its own risk assessment, as well. The common themes that emerged included data privacy and working with third parties in emerging markets.

Another challenging area is artificial intelligence. It raises a host of issues about how to handle data ethically and the need for a data ethics policy. To mitigate that risk, the data science team regularly checks for algorithm biases.

The company also recently launched a data governance committee to define what data is being collected, why and if it is accurate.

It’s not just data that is a risk, of course. People issues are also a factor and require the team to train and provide the proper tools for the workforce to do the right thing. These include ethics workshops to help individuals understand what can make or break a compliance culture, especially in a purpose-driven company. That’s a challenge when the corporate culture is spread among so many global cultures.

Listen in to learn more about Tala, and perhaps find lessons that can help improve your own compliance program.

View Details

Post By: Adam Turteltaub

As diversity, equity and inclusion efforts proliferate, Stephen Paskoff, President and CEO of ELI, warns in this podcast that organizations need to be mindful of existing equal employment laws. Allowing for differential treatment, no matter how well intended, can lead to claims of discrimination.

The intentions of DE&I programs are not, in and of themselves an issue, he explains. The issue arises from how these initiatives are pursued. Some employers have permitted conduct that can be seen as disparate treatment, even bordering on fostering a form of systemic discrimination. He notes that it can be highly problematic if systems of advancement give an advantage to one group without sufficient grounding in legal principles.

He recommends keeping the law clearly in mind since it is both supportive of DE&I initiatives and can help avoid problems.

He also advises looking to the organization’s value. Respect, inclusion and fairness are typically included and provide an opportunity to put the DE&I initiative in context, including that these values helps build a stronger, more successful enterprise.

He also argues passionately for an emphasis on civility. Setting standards of what one can can’t say, and how people act, is essential not just in this area but in others as well. It promotes proper communication, including helping people raise issues and speak up freely.  That, in turn, can help diffuse issues and enable the organization to deal with problems before they grow too large.

Civility, according to Stephen, also provides a platform of consistency that everyone can sign onto as citizens of their organizations.

Listen in to learn more about civility and how to ensure that your DE&I initiative doesn’t run afoul of labor laws.

View Details

Post By: Adam Turteltaub

Kim Brandt, partner at Tarplin, Downs & Young has long provided the healthcare community with her expertise in all things Washington, having spent substantial time at CMS, the OIG at HHS and on Capitol Hill.

She’ll be leading a general session at the Health Care Compliance Association Healthcare Enforcement Compliance Conference, which takes place November 8-10. In this podcast she provides a preview f her talk with insights into all that’s coming and likely to happen both from the Biden Administration and Congress.

Starting with CMS, which is in its regulatory cycle once again, expect big changes in physician fee payments. There is a 3.75% reduction across the board in the offing, with the goal of giving a bump up to primary care physicians. That means, she explains, reduction in payments to specialty care providers by as much as 8-10%. This will be on top of a delayed 2% sequester.

Telehealth, which became a standard part of care during the pandemic, will also see changes with proposals to make permanent rules permitting it for mental and behavior health, including audio-only treatment. Video will not be required.

Up on Capitol Hill she reports that Congress is considering expanding Medicare Part B to include hearing, dental, and vision. These had never been covered by Medicare before and come with a large $300 billion price tag over 10 years.

Also under consideration is increased support for home and community-based services, along with increased funding for them.

Another area of focus is likely to be the Medicaid gap. Thirteen states have not implemented a Medicaid expansion.  Under consideration are measures which would allow local governments in those states to contract with CMS to expand Medicaid.

Finally, she discusses the personnel changes at CMS and the OIG at HHS. The new administration has brought changes in people, but they are not exactly new, having served in the government before.

Listen in to learn more about what’s going on in healthcare in Washington, DC. Then be sure to be a part of the 2021 Healthcare Enforcement Compliance Conference.

View Details

Post By: Adam Turteltaub

It’s been an interesting and challenging times for efforts to encourage employees to speak up, reports Neta Meidav, co-Founder and CEO of reporting tool provider Vault Platform. Despite the increase in employee activism, there has been a decline in year-over-year helpline volume, which she attributes to both the nature of traditional help vehicles and a deficit of trust in the workplace.

Other factors having an impact are: a desire of employees to report to external avenues, COVID-related changes in the workplace, and a new focus on ethics and purpose. This last factor goes hand in hand, she argues, with a growing tendency of social issues to become business issues.

Regulators have also been stepping in. For some time, of course, the SEC has encouraged reports to its Office of the Whistleblower. The EU Whistleblower Directive has acted as a catalyst across the Continent, with countries in the midst of creating their own laws, with varying protections likely. She expects this to drive increased accountability and transparency.

In this podcast she encourages compliance teams to think about the activist sentiment in Europe, what it means and how it differs from the US. And, of course, organizations need to recognize the complications posed by GDPR.

She also advocates for a reassessment of how compliance teams encourage employees to report internally. With open door policies no longer relevant in a time of remote working, she believes it’s time to find new tools and increase efforts to promote psychological safety.

Listen in to learn more about how to foster a speak-up culture in the current era.

View Details

Post By: Adam Turteltaub

Codes of conduct are ubiquitous these days, and they are often digital. It’s a way to make them more accessible, and more in line with how people work.

But what if you took that virtual approach up a bit? That’s what TAQA and its Head of Ethics & Compliance Abdul Rahman Al-Ja’abari (LinkedIn) did. They created a Code of Ethics & Business Conduct that is experienced as a virtual reality walk through of representations of the some of the company’s facilities, in addition to a more conventional PDF.

TAQA had recently undergone a large merger that created one of the largest listed entities by market cap in the United Arab Emirates (UAE). The newly-formed company needed an ethics and compliance program that would both help it meet regulatory requirements and unify the culture.

Because the company operates around the globe, the code of conduct had to be put in a format that would be accessible to everyone. But, they also realized there was an opportunity to use it as a unifying tool. So, they created a version of it that employees could literally explore. They navigate room to room, as Abdul Rahman explains, where they see what different locations of the company look like and are able to explore different elements of the code.

This creative approach has received very positive feedback.  It was also a way for the compliance team to deliver on the company’s core value of innovation.

For anyone inspired by this approach, Abdul Rahman recommends beginning by building alignment with management on the approach, objectives, budgets and resources required. The communications team needs to be brought on board to help ensure you stay in line with their communications plan.

Of course, the IT group is also a crucial partner, helping ensure that the solution is compatible with the organizations systems and is readily accessible to the employee base.

Finally, be prepared for a positive reaction. People tend to see compliance as a staid, boring group.  Developing something creative, he explains, can help change minds very dramatically and for the better.

Listen in to learn more, and then spend some time exploring the TAQA Group Code of Ethics & Business Conduct.

View Details

Post By: Adam Turteltaub

The calls keep coming in to the helpline, which is great, unless you miss that all important, high risk one amidst all the minor issues. How do you avoid that problem? In this podcast, Mia Reini, Senior Manager-Corporate Compliance and Enterprise Risk Management at The Home Depot and Monica Lopez Reinmiller, Managing Corporate Counsel-Legal Affairs, Compliance at T-Mobile provide some intriguing answers.

Mia reveals that Home Depot has made a bot a part of its compliance team. Working with IT they developed software which scans helpline calls in real time, looking for buzzwords that correlate with high-risk incidents. If it finds them, they go straight to corporate compliance for review.

Launched in December 2020, the bot averages several cases a day by looking for terms such as SOX, FCPA, DOT, EPA and hazmat.

For the compliance team it’s proven invaluable since it is always at work, including on nights and weekends. But, they warn, vigilance is still required. Like all software, sometimes the bot goes down.

Of course, not every organization can have a bot, and for those, Mia and Monica advocate a risk-based approach. That includes watching out for terms that a bot might, but also having someone with the requisite skills to triage the calls and flag those needing an escalated response to the board or requiring an attorney to oversee the investigation.

Both Mia and Monica also argue for a root cause analysis as part of the investigation. The US Department of Justice has been encouraging them, but that’s not the only reason they are valuable. They can help in fostering a programmatic, preventative approach to compliance that is more disciplined.

And speaking of discipline, pushing for organizational justice, they explain, is key.

It is all a part of an active approach to managing employee helplines that helps foster a healthy compliance program.

View Details

Post By: Adam Turteltaub

As if Stark Law and the Anti-Kickback Statute aren’t complicated enough, they can also lead to False Claims Act issues, explains Charles Oppenheim, Partner at the law firm of Hopper, Lundy & Bookman and author of the chapter “The Stark Law and Anti-Kickback Statute as FCA Risks” in the new HCCA book False Claims in Healthcare.

In the case of Stark Law, where there is strict liability, something as simple as faulty paperwork can be highly problematic. If the documents don’t match up, no matter how innocent the mistake, an entity is prohibited from billing for services. And, when it comes to the Anti-Kickback Statute, the law is intent-based. So even if the remuneration is fair market value, corrupt intent can have drastic consequences.

To prevent issues from occurring, and effectively remediate them should they occur, he offers several recommendations in this podcast. First, have well-designed policies and procedures when it comes to entering into new relationships, including policies for when not to enter into a relationship. Second, document how fair market value is determined, how you entered into the relationship and alternatives considered.

Should a potential violation be identified, bring in experts who understand the subtleties of these very complex laws. And, he notes, don’t despair. It is quite possible that the relationship falls into an exception. For example, CMS has proven more flexible of late in its documentation requirements.

Should you need to make a disclosure, consider the Self-Referral Disclosure Protocol (SRDP). It can take some time, but the outcomes can be more positive than many think.

Finally, he advises healthcare entities to remember that we will one day come to the end of this pandemic emergency. During this crisis CMS issued a narrow waiver on Stark Law that many took advantage of while medical practices were in deep financial troubles. It’s important to document what you did and be prepared for the end of the emergency and, quite possibly, the end of the waivers.

To learn more, listen in to this podcast, and check out our new publication False Claims in Healthcare.

View Details

Post By: Adam Turteltaub

There are a lot of skills that compliance professionals need – communication, persuasion, negotiation, patience, and even legal – and now Lisa Beth Lentini Walker, CEO and Founder of Lumen Worldwide Endeavors and Stef Tschida, Founder, Tschida Communications, are suggesting another: organizational scholarship.

The co-authors of the book Raise Your Game, Not Your Voice suggest in this podcast that, to be effective in their roles, compliance professionals need to be skilled at navigating the organization. To do that requires a deep understanding of the organization.

They advocate for taking the time to understand the company’s strategy and culture. Consume as much information about the company as possible: the website, publicly filed documents, earnings calls, even what the marketing people are saying on social media. Is the company just sending out messages, or is it engaged in a dialogue?

Also, look to what others are saying on sites such as Glassdoor. Are people saying good or bad things?

If you are new to the organization, they recommend having a plan for your first quarter there to quickly build your knowledge base. Connect with key people, understand what the key relationships are, and what drives behavior.

Then, look beyond the walls of the organization to understand what is going on in the industry as a whole to better understand what are the key forces, what may happen next and how your company compares to its peers. And be sure to set alerts for news about competitors, as well. A crisis in one could provide clues for what to watch out for in your own organization.

Finally, take the time to learn how compliance is perceived. You only get permission to speak, they explain, when you first take the time to listen. If the business people know that your ears are open and that you are sensitive to their needs, they are much more likely to pay attention to what you have to say.

View Details

Post By: Adam Turteltaub

As the compliance profession matures an increasing number of professionals in the industry are thinking about going out on their own and setting up a consulting firm. In this podcast we learn from three people who did just that and are willing to share their wisdom and experience:

Kristy Grant-Hart, Spark Compliance Consulting Kirsten Liston, Rethink Compliance Joe Murphy (LinkedIn), Compliance Strategists and one of the founders of Integrity Interactive

Recently they wrote the book The Compliance Entrepreneur’s Handbook, and in this podcast they share insight into what they call the four corners approach to determining what the sweet spot is for your business. It’s difficult to be all things to all people, especially when first starting out. By looking at the four corners, they believe, you can narrow your focus to where you bring the most value to the market.

The corners are:

Function Rather than focusing on all elements of a compliance program, you can narrow your focus to those areas you have the most expertise in. That helps you become known for bringing in certain pieces of the puzzle.

Risk Area Privacy, anti-corruption, antitrust, and Stark Law are just a few of the areas that can be ripe for building a business around.

Geographic Region Do you want to serve a city, state, region or work globally? Think about where the market is and isn’t saturated. Ask yourself how much you want to travel. An international client base can be very enticing, but it means many days away from home, calls at strange hours of the day and night, and much jetlag.

Industry Choosing industries to focus on can be a tug of war. You want to leverage your expertise in a given industry or two, but you don’t want to set your sights so narrow that there are too few opportunities available.

In sum, it’s a complex calculus when it comes to going out on your own, but it doesn’t have to be overwhelming. It also takes great persistence and a strong network to get your business off the ground.

And one final piece of advice you will hear in this podcast: don’t forget it’s a business, with all the issues that brings.

Listen in to learn more and help you decide how to start your own compliance business, or whether you are better off staying right where you are.

View Details

Post By: Adam Turteltaub

Much has changed in the world of compliance, especially of late, but when it comes to healthcare investigations, not all should, says Pamela Para (LinkedIn) RN, MPH, CPHRM, ARM, DFASHRM, President and Chief Content Officer at CE Companion. According to Pamela the historical approach still works. And, interestingly enough, she notes that it relies heavily on several nursing techniques developed by Florence Nightingale, herself:  assessment, diagnosing, planning, implementing monitoring and evaluation.

In the podcast she lays out three P’s for investigation (and a few additional little “p’s” too):

Policies: Be sure to match up your policies, procedures and protocols with national standards of practice and regulatory requirements. Then make sure you are doing them in practice.

Paper: Documentation is critical.  Document your finding for the record and any corrective actions taken.

People: Get the right people involved in the investigation, and be sure to have a methodology for gathering them. Who will be on the team will vary depending o the type of investigation. And don’t forget to go back to the previous “P” and document your selection process.

Listen in to learn more about how to improve the effectiveness of your healthcare investigations, including how the investigatory process can and should be a part of the enterprise risk management and strategic plans.

View Details

Post By: Adam Turteltaub

While organizations have increasingly embraced cloud computing as a solution to their data management and other needs, they do so in an environment of heightened risks. Attacks on cloud providers are increasing, which makes it ever more important to ensure that the rewards outweigh the risks, including from a compliance perspective.

Chris Ford, Vice President Product, Threat Stack, advises organizations look to cloud service providers that have taken the step of becoming certified against standards such as ISO 27001 or SOC 2. He also recommends not stopping there and looking to certifications that align with specific risk areas such as IPAA, GDPR, CCPA or PCI.

That’s still not enough, though, he cautions in this podcast. Meet with the security team to discuss the organization’s practices and how it manages third party vendor risk. If their practices aren’t secure or the team is unwilling to meet with you that should be a very large red flag. So, too, is the approach to compliance:  stay away from vendors who take a check-the-box approach.

Other pieces of advice he offers:

Ask if they scan code in the build pipeline Determine if they do runtime monitoring of the infrastructure Find out what tools they use to ensure your date is secure Make sure they are constantly scanning for vulnerabilities

Finally, security is a “team sport” he notes. It’s important to maintain trust on an ongoing basis and look at this as a journey together. Be sure to learn from the failures of others, and, of course, make sure that you are just as vigilant of your internal IT security as you are of your vendor’s.

View Details

Post By: Adam Turteltaub With the Theranos trial in the news, we thought we would repost this podcast with former Theranos employee and whistleblower Tyler Shultz. Tyler Shultz, like many others, was entranced by the vision of Theranos and its charismatic founder Elizabeth Holmes. He would not remain so for long, ultimately sharing his concerns with her, his grandfather (a member of the board), and then becoming a source for a Wall Street Journal reporter, and a whistleblower, reporting to New York state’s public-health lab his concerns that the company’s proficiency tests had been manipulated.

On March 30, 2020 he will be sharing his experiences and insights at the 2020 Compliance Institute, and he was also kind enough to talk with us for the Compliance Perspectives podcast.

In a very frank discussion, he tells us how the culture of Theranos discouraged people from coming forward and raising issues. In fact, there were severe disincentives for doing so ranging from potential loss of a visa to litigation.

We also discuss what drew him to the company and why it was so hard to face the dark reality behind the enticing façade.

Finally, he addresses signs that compliance professionals should watch out for that could be symptomatic of a very dysfunctional culture, if not outright wrongdoing.

Listen in to hear what he has to say and then plan on hearing much more at the 2020 Compliance Institute.

View Details

Post By: Adam Turteltaub

“Dark data” sounds ominous, and as Peter Bauman (LinkedIn), Founder and CEO of ActiveNav explains in this podcast, it can lead to great risks for organizations.

Dard data is essentially data which organizations collect as a part of their business processes but don’t necessarily have a plan to use. It is also data that rarely gets thrown out, instead residing indefinitely on devices and services. It includes weblogs, tracking data, surveillance footage, email correspondence, chatroom conversations, presentations and old spreadsheets.

This data is typically unstructured, and often it is very opaque.

It also carries significant risks including the need to access it during litigation, and it even may create privacy issues.

How can you get a handle on this data? Shine a light on it. Determine where it is in your organization and start building a data inventory that classifies the data.

Next determine what is worth keeping and what needs to be destroyed. And, for the data worth keeping, take the trouble to classify it.

Most of all, treat this as an ongoing issue to manage. Data tends to collect itself, in many ways, and organizations need to be aware of what it has and what it’s for. That requires the creation of better policies for collecting and managing data.

Those policies need to be pragmatic, reflecting both business needs and the inevitable collection of ever more amounts of data.

Listen in to learn more about dark data and how you can start bringing it into the light.

View Details

Post By: Adam Turteltaub

You’re about to begin a complex investigation. What should you be thinking about? What should your first steps be?  And what tricks of the trade are there?

To find out we spoke with Tech Data’s Jannica Houben (LinkedIn), Vice President Global Legal Transformation and Katarzyna Golonka (LinkedIn), Vice President Global Compliance. The two of them will be leading the virtual session “Advanced Investigations in Multi-National Companies” at the 2021 SCCE Compliance & Ethics institute, which takes place September 19-22, 2021.

A good investigation, they explain, needs to be properly scoped and be staffed with qualified personnel. In thinking who those people would be for your organization, they advise remembering to consider both the obvious and the subtle issues such as the languages you need on the team. And, of course, be sure your interviewers are well trained, not just eager.

Other things to think about right at the start:

The legal expertise needed to understand reporting obligations, privacy and labor laws How enforcement authorities operate Whether there will be a need for IT and forensic resources Sector-specific knowledge Other expertise required such as in finance, sales, operations even SAP

One of the biggest decisions to make early is whether this is an investigation that is best handled using an internal or external team. Each has its own plusses and minuses. As they note in the podcast, an external team can bring in skillsets that you don’t have, including the often expensive and complex forensic resources. But, since an external team likely doesn’t know your culture as well as you do, they may miss the small things that an inside team wouldn’t.

They also discuss here the report that will come at the conclusion of an investigation. Documenting the steps you have taken is key, so much so that they believe if it isn’t documented it’s as if it never happened. It’s a part of demonstrating that the company took the issue serious and investigated thoroughly.

Make sure the report language is as concise and to the point as possible. The findings need to be reported objectively and accurately and, of course, state whether they allegations were substantiated or not.

Listen in to learn more and don’t miss their virtual session at the 2021 SCCE Compliance & Ethics institute.

View Details

Post By: Adam Turteltaub

Social media has now become a permanent fixture of our lives, but that doesn’t mean we’re altogether comfortable with it.  And for compliance professionals, there is  a constant and changing range of risks, reports Kortney Nordrum, Regulatory Counsel & Chief Compliance Officer for Deluxe.  She will be leading the session “Social Media:  Old Platforms, New Risks” at the 2021 SCCE Compliance & Ethics Institute.

To understand the risks, in this podcast we take a look at several different types, starting with the organization’s own social media activities.  She advises that, despite the informality of social media, companies need to think through their communications like they would advertising or PR: professionally.  That means using appropriate language, checking the hashtags to make sure that they aren’t being used elsewhere online where the meaning may be inappropriate, and having someone responsible for the activity.  It also means having a defined objective and a method for measuring if the social media is achieving what it is supposed to.

Organizations should also engage in what she calls “social listening”:  seeing what others are saying about you online.  Visit sites such as Facebook, Twitter, LinkedIn, Glassdoor, Yelp, Amazon and Google reviews.  Use them to understand how people are interacting with your organization and their experiences.

When it comes to looking at what employees are doing online, she cautions that the National Labor Relations Act covers a wide range of employee activities and protects them.  Generally speaking, the National Labor Relations Board has found that employees have the right to complain online about compensation and work conditions.

Also, exercise caution when reacting to that bikini-clad photo on Facebook.  There’s probably nothing you can or should do about it.

Be cautious, too, about the new platforms that have emerged.  Their data practices may be cause for concern.

Finally, she recommends using social media as a means for compliance teams to connect with the business people.  It provides opportunity to engage with them both in a formal professional way, as well as informally.

Listen in to learn more, and be sure to catch her session “Social Media:  Old Platforms, New Risks” at the 2021 SCCE Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

While the pandemic put many things on hold, it did not do the same for the False Claims Act (FCA). To find out what is happening in FCA activity we spoke with Patrick Hooper, Jordan Kearney and Alicia Macklin, partners at the law firm Hooper, Lundy & Bookman, PC and authors of the chapter Cutting Edge Topics in the FCA for the new HCCA book False Claims In Healthcare.

In this podcast they share that the opioid pandemic will still receive enforcement focus, particularly in areas such as treatment fraud. That’s likely to happen because of the increased number of people receiving medical coverage and the resurgence of the opioid epidemic during the pandemic.

They point to recent press releases and public comments by the FDA. The government also signaled it is looking at fraud related to electronic health records, which oven overlaps with opioid-related fraud.

We also discuss the now confusing area of subregulatory guidance. With the US Supreme Court decision in Azar v. Allina Health Services requiring more formal processes, and with a subsequent decision regarding local coverage decisions, many are wondering what to do.

Listen in to learn what to consider as you navigate these thorny, cutting edge FCA issues. And be sure to check out False Claims in Healthcare.

View Details

Post By: Adam Turteltaub

Third party anti-corruption due diligence didn’t stop during the pandemic, but it was different.  And, as the world begins to, hopefully, emerge from the pandemic Ashley Coselli, Senior Ethics and Compliance Counsel, Total American Services and Daniel Wendt, Member, Miller & Chevalier suggest in this podcast that companies should now go back to their files and see where there are holes

The two of them will be leading the session Managing the Most Difficult and Most Important Anti-Corruption Due Diligence Projects at the 2021 SCCE Compliance & Ethics Institute, which will be taking place September 19-22.

As you look through the due diligence files you are likely to find that one of the more important pieces missing is the face-to-face interaction that can be so important when gauging the risks posed by a third party. Once travel becomes safe and practical again, it’s important to get those relationship going, especially with high-risk relationships such as those with sales agents and joint venture partners.

Next, determine how effective their compliance programs are, and begin to triage based on the greatest risks. But, they advise, don’t try to do everything all at once. It can just be too much.

Also, invest the time to fill in the knowledge gaps about ownership structure to determine if anyone from the government, a former government official, or even a close family member of one has a stake in the organization.

As you fill in the blanks, make sure to document what you are doing and have done, including the business justification for using a third party. It can be dreadfully difficult during a government investigation five years from now answering why the company decided it needed a third party, how it made the selection and why there were gaps in the due diligence. But, if you have been documenting your actions all along, the challenge is much less significant.

One issue to consider that doesn’t involve the pandemic: Stop periodically to assess your current relationships. Sometimes a third party is brought on to handle one issue, and then over time the relationship expands greatly. Be sure to periodically ask: Is there the necessary due diligence for all the entity is doing, or just what it was initially hired to do?

Listen in to learn more about this very thorny risk area, and then join us virtually or in person at the 2021 SCCE Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

When the helpline rings, it’s a make or break opportunity. Get it right, and you could find out about potential wrongdoing and useful details. Get it wrong, and the caller may decide it’s not worth it, give perfunctory information, or, at worst, hang up.

Adam Balfour (LinkedIn), Vice President and General Counsel for Corporate Compliance and Latin America at Bridgestone Americas, Inc. strongly advocates in this podcast starting by asking yourself a question: Who is this helpline really meant to help? Is it simply there to collect information about issues or is it there to help employees? If an organization wants a speak-up culture, then the intake process can’t be an unpleasant, rote one. That will discourage employees from calling in.

Instead, he argues, it is better to embrace a process in which the organization demonstrates to callers that it hears them. That includes using a more empathetic approach, using language such as, “I’m sorry to hear that and it sounds like it was upsetting to you.” This can help encourage the employee to open up and share more.

Leading by addressing emotions can help open up people to sharing more facts, he has found.

To guide the conversation, a script is helpful, but it should not get in the way of the conversation. More important is to keep in mind the goal of getting information.

So, what do you do when setting up (or revising) the helpline with your vendor? He recommends laying out what processes and experiences you want for your workforce. Then, take a look at how they incentivize employees. If their goals are designed to get callers off the phone as quickly as possible, that could be sending exactly the wrong message.

Listen in to learn more about listening up.

View Details

Post By: Adam Turteltaub

Consistent discipline is difficult for organizations, especially when high performers are involved. It’s even more difficult for large organizations operating in dozens of countries around the world, navigating multiple cultures.

Yet, Dentsu International was not afraid to take on the challenge. In this podcast, and at their session at the 2021 SCCE Compliance & Ethics Institute, three Regional Ethics & Compliance Directors from the company -- Elaine Ong (APAC), Kalpana Kothari (EMEA) and Caveni Wong (Americas) – share what it took to put together consistent global disciplinary guidelines in a decentralized organization.

The goal of the project was to impose consequence and improve accountability around the globe. A first draft was created and reviewed by the regional compliance directors, legal, HR and internal audit. Then, approval was obtained from the Global CEO and Chairman before being presented to the board. The entire process took ten months.

And that was just the starting point. After that came the task of rolling it out.

Critical to the next phase was the support of senior management, the board, HR and business leaders. With their support the compliance team worked with local businesses to ensure that they understood the guidelines and how to apply them. Compliance also let the business know that it would not be alone. Compliance would be supporting them along the way.

Some of the other keys to success:

Develop a simplified framework that is easy to understand Create case-based training to provide opportunities to practice decision making Develop supporting collateral Review employee feedback

Listen in to learn more, and then plan on attending their virtual session at the 2021 SCCE Compliance & Ethics Institute

View Details

Post By: Adam Turteltaub

Ted Lasso has been a pandemic streaming success story. The show stars Jason Sudeikis as an American college football coach hired to lead a troubled English soccer (football) club.

Unlike the typically-portrayed coach, barking out orders and all about winning, Ted is an empathetic person, who wears his heart on his sleeve, looks for the best in people, and does his best to bring it out of everyone. That’s not always easy given the personalities that surround him. The team’s owner is engaged in a personal vendetta. One star player is self-obsessed, another is arguably the angriest person in the world.

The show has been a runaway success, with the public, critics and the press. It has earned 20 Emmy nominations, including Outstanding Comedy Series, Outstanding Lead Actor in a Comedy Series, and two nominations for Outstanding Writing for a Comedy Series.

For those of us working in compliance and ethics, the show is a great watch, not just for its entertainment value. It contains several lessons on creating the right organizational culture, and how to engage people in discussions of right and wrong.

In this podcast I sit down with Bill Wrubel, Executive Producer of the series who, not surprisingly for a show about working as a team, gives the credit to others including Brendan Hunt, Joe Kelly, Bill Lawrence, and, of course, Jason Sudeikis, who wanted the show to have meaning and be something beyond laughter. Fittingly, when Bill interviewed for the job, Sudeikis asked him if he had any mentors in his career and to tell him about them.

Sudeikis drew heavily from his own experiences in the entertainment industry, Bill shares. From his years working in improv he learned that success is the product of team work. You are as dependent upon what others are doing as what you are doing. From writing for SNL, under Tina Fey’s leadership, he had learned from her habit of listening to all the voices in the room, not just the loud ones, and to recognize that everyone had a contribution to make.

You can see that in the show, when Coach Lasso encourages the players to speak their mind, and also, notably, when he chooses to listen, not escalate confrontations, and be forgiving.

What may surprise many is that the writers regularly talked about and read books on leadership. They saw that not everything flows from the top and that great leadership comes from openness. “Be curious not judgmental” is an oft-quoted line from the show.

Listen in to the podcast, and then enjoy Ted Lasso. Then watch it one more time (if you haven’t watched it already) for the lessons about how to create a culture that encourages growth and openness. The setting is an English football club, but the lessons can apply to compliance and ethics program everywhere.

View Details

Post By: Adam Turteltaub

So much attention is paid to vetting third parties, it’s easy to forget that it is just the start of the process. Monitoring needs to be done on an ongoing basis as well.

Ronnie Kann, head of Global Ethics & Compliance at Energizer Holdings and Trent Sandifur, partner at Taft Law will be addressing that topic in their virtual session “What Does Third-Party Compliance Monitoring Look Like in Real Life?” at the 2021 SCCE Compliance & Ethics Institute.  In this podcast they caution that it’s advisable to think of monitoring not as something separate but as a part of a larger third-party due diligence program.

That program includes:

Keeping an eye on what’s going on with the third party Understanding what the risks are Thinking about how to monitor Making any improvements necessary to ensure the risk is effectively managed

How do you get the vendor on board for the monitoring process? They recommend beginning by ensuring that monitoring is included in the initial agreement. That helps both set and manage expectations. Also, work with the vendor to make sure that while getting the information you need you are not unnecessarily burdening them.

Be sure also to avoid overburdening your own business people, but, at the same, time, it’s essential that they recognize that they own the risk. This can help create a spirit of partnership that will help protect your organization and make the process go smoother.

Finally, they close the podcast with a discussion of what to think about as the pandemic ends and business starts catching up on all the due diligence that was done only partially when the pandemic made travel impossible. They recommend taking a risk-based approach to what you were unable to do.

Listen in to learn more, and be sure to join their session session “What Does Third-Party Compliance Monitoring Look Like in Real Life?” at the 2021 SCCE Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

Andy Powell is Chief Ethics & Compliance Officer, Senior Vice President and Deputy General Counsel at Flex, a global technology manufacturing company with approximately 160,000 employees in over 100 manufacturing and services sites spread out over 30 countries.

When he entered the compliance role there he realized that, realistically, the compliance team couldn’t be everywhere all the time.

He also sought to enhance the compliance and ethics culture.  To do so, he embarked on a strategy of normalizing compliance, making it a part of every manager’s job.  That, he knew, would require making managers both responsible and accountable.

His solution: create an integrated scorecard that leaders could manage against and would provide valuable insights to the compliance team.  As he explains in this podcast, you can’t expect managers to be accountable unless you can show them how they are doing.

The scorecard provides the hard numbers managers need.  To create it, he worked cross-functionally to gather data points from across the organization, including employee engagement surveys, helpline data, and even external benchmarking data.  The information is represented graphically along with insights from the compliance team.  Some of the data is macro.  Some give insights as finite as production lines.

How powerful is this tool?  Day to day it helps identify hot spots and generate improvements.  As importantly, the CEO typically asks each manager to show it to her whenever she travels around the company.

Listen is to learn more about the benefits from creating an integrated scorecard.

View Details

Post By: Adam Turteltaub

What does the SEC expect from an internal investigation?  It’s a topic that Nick Morgan, partner, Paul Hastings and Andy Dunbar, Chief Compliance Officer, Herbalife Nutrition tackle in this podcast and will be addressing at the 2021 SCCE Compliance & Ethics Institute.

So what makes for a good internal investigation?  It starts before the investigation even begins with a robust whistleblower program, speak-up culture and easily accessible reporting opportunities.

It also includes a disciplined investigation process.  That means someone need to be monitoring it to ensure that matters don’t fall through the cracks, that they get assigned efficiently, and that all investigations are moving forward.  In addition, someone has to be designated to review the final outcome of the investigations and determine if the right people were spoken to and the right documents examined.

And while the emphasis and effort will be placed on those tips that seem to have merit, It’s important to remember that the vast majority of them will not.  Yet, even for those that are unsubstantiated, take the time to document what was done and how conclusions were reached.

No matter if a claim does or doesn’t have merit, they advise ensuring that an adequate program is in place to protect whistleblowers from retaliation.  That includes a documented anti-retaliation policy and processes available for both employees to turn to and regulators to see.  Be sure also to let whistleblowers know that the same channels they used to report wrongdoing can be used to report retaliation as well.

It is also advisable for the compliance team to stay in contact with the whistleblower, even checking in a couple of months after an investigation concludes to make sure he/she is doing okay.  That can be very reassuring to the whistleblower and demonstrate that the compliance program is trustworthy.

Finally, they address what the compliance team can do, should the matter escalate to the point that the organization self-report, or if the SEC or DOJ comes knocking.  These include:

Reviewing hotline data to see if there were any early indications of the problem Amassing the data to demonstrate the effectiveness of the compliance program Preparing a plan to remediate

Listen in to learn more, and be sure to attend their session What the SEC Expects from Your Internal Investigation:  Former SEC Enforcement Attorneys Share Their Insights at the 2021 SCCE Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

HIPAA Section 1135 waivers are a tricky area, explains Courtney Blau (LinkedIn), Attorney, Risk Management and Compliance, Norman Regional Health System.

As she explains, Section 1135 Subsection B in the Social Security Act provides express authority to the HHS Secretary to waive a number of requirements, including the HIPAA privacy rule. In response to the pandemic, the Secretary was given additional authority to make amendments to HIPAA by program instruction or otherwise. These are no longer subject to public hearing or comment period.

However, a waiver is only effective for three days after implementation. As a results she advises not to adjust your organization’s processes. Instead continue to maintain normal operations.

In addition, compliance teams need to remember that many states have laws that are even stricter HIPAA. As a result, the waiver may not be applicable to providers in those states.

Listen in to learn more about this complex topic.

View Details

Post By: Adam Turteltaub

Mergers and acquisitions can be filled with landmines.  To find out what compliance teams can do to help manage the risk, and help ensure a successful transaction for the business unit, we spoke on this podcast with Fernanda Beraldi, Senior Director, Ethics and Compliance at Cummins Inc. and Ed Broecker, Partner, Foster Brown Todd.  The two of them will be leading the session Compliance Diligence in M&A:  Best Practices from LOI to Integration at the 2021 SCCE Compliance & Ethics Institute, which will be taking place in-person and virtually September 19-22, 2021.

Since the earlier compliance is brought into the M&A process the better, they advise developing a close relationship with the business. The goal is to have compliance involved starting with the initial discussions, even before there is a letter of intent.

When doing a compliance assessment, they recommend conducting a risk-based approach, to a point. Looking at legal and regulatory risk areas are important, but as important is looking at the corporate culture. Get a handle on whether the compliance program simply exists on paper or is woven into the way the company does business. Take the time to interview the compliance team at the target company and ask specific questions about culture, training, and receptiveness to compliance.

Be alert also to one red flag that is often missed: the absence of helpline calls and cases.  While it is hard not to miss the red flag of a lot of calls from a facility or a large number of investigations, it can be easy not to notice when there are far too few calls, or none at all. That may be the very troubling sign of a culture that makes it difficult, if not impossible, for employees to raise their hands when they see something wrong.

After the acquisition, they advocate for the creation of a compliance champions or ambassadors program. Having people in other departments who can be the eyes, ears, arms and legs for the compliance program can be invaluable both for what is happening and for communicating compliance messages.

Listen in to learn more, and to gain even more of their expertise, be sure to join us in Las Vegas at the 2021 SCCE Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

How do you get people to come forward and report issues? Ronnie Feldman (LinkedIn), President and Founder of Learnings & Entertainment, has an unconventional suggestion:  Learn from improv groups.

As he explains in this Compliance Perspectives podcast, improv performances only work because the members of the cast know that they have unconditional support from their castmates. They embrace the concept of “yes and”, looking to embellish what each other did and move it forward.  That gives them the ability to take risks.

Improv artists also practice their listening skills to make sure that they understand what each other is saying.

This creates a psychologically safe environment where people can bring ideas forward without fear. Harvard Professor Amy Edmondson, argues that the best organizations do the same thing, he explains.

How does an organization get to that place of psychological safety where people can feel come forward and say what’s on their mind safely? By constantly reminding people that it is okay to point out what is wrong. And a good compliance program, he explains, is one that creates this environment.

How can a program get there? For one, he argues that compliance training needs to be improved. Taking the trouble to do it right both engages employees and shows the company is committed. Stories of incidents that happened at the organization can be particularly impactful.

Then think more like an advertising agency and seek to get the message in front of people as many times as possible and as creatively as possible. And, as you do so, be entertaining and interesting. He argues that this will help put compliance in a more positive light.

Listen in to hear more provocative ideas for encouraging more employees to come forward.

View Details

Post By: Adam Turteltaub

What do the current times and the times to come mean for corporate values?

To answer that question we turn in this podcast to Marjorie Doyle, Principal, Marjorie Doyle & Associates, and Art Weiss, Principal, Strategic Compliance and Ethics Advisors, SCCE & HCCA President and Chief Compliance and Ethics officer at TAMKO Building Products. These two compliance veterans, and members of the SCCE Basic Compliance & Ethics Academies faculty, will be addressing the topic in their session “Polish Your Brand! Make Your Values Apply to Current Issues” on September 19th at the 2021 SCCE Compliance & Ethics Institute.

When faced with such monumental changes as we are today they advise sticking to your values but looking to see if it is time to evolve the definitions. As an example they point to the value of safety, which now should likely reflect not just preventing injuries from things such as falls, but also from COVID-19.

Likewise, they argue that with remote work values remain just as important, but organizations need to recognize that the application of those values is different. Studies have long shown that company values tend to be stronger for employees in the corporate headquarters than they are for those farther away. With so many workers no longer in the office, organizations will need to work harder to keep their values front and center and a driver of corporate culture.

And how can organizations bridge the very different experiences of workers who come into the office and those who don’t? They advise regular communications from leadership filled with examples that reinforce the organizational culture. Those communications, and others, should also explain how the organization’s values are being applied to meet the changing environment.

Listen in to learn more, and be sure to join us at the 2021 SCCE Compliance & Ethics Institute.

View Details

Post By: Adam Turteltaub

On July 1, 2021 the US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), FBI, and UK National Cyber Security Centre (NCSC) released an advisory reporting on “malicious cyber activities by Russian military intelligence against U.S. and global organizations…”

The advisory shared that “brute force” is being used to “penetrate government and private sector victim networks.”

To understand what this means for organizations and what they should do we talked with Mark Lanterman (LinkedIn), Chief Technology Officer at ComputerForensic Services. He explains in this podcast that it’s not just the brute force attacks that should cause concerns. It is these efforts combined with the use of “known vulnerabilities” to access data undetected.

What should organizations do to protect themselves? He advises following the recommendations in the advisory. For one adopt multi-factor authentication along with time out and lockout features. Other steps to take include network segmentation and closely monitoring access controls.

He also suggests that organizations review existing protocols to ensure that they are actually being followed. Just because a policy is documented, he warns, doesn’t mean it is being applied.

If your organization is using a cloud provider, he recommends take the time to revisit its value as a tool, what protections are in place, what data is stored and where it is stored. Ask your cloud provider about the infrastructure it uses, how it is protected, and what are the backup and protection policies. Trusting any third party with your data, including a cloud provider, is not something that should be done lightly.

Inside your organization, he argues for rethinking the approach to data security, changing it from something you train on once a year to an entire culture. There can’t be a set it and forget it mentality. A much more dynamic approach is required.

Listen in to learn more about how you can better protect your organization against brute force and more subtle attacks.

View Details

Post By: Adam Turteltaub

Liverpool-based Jenny Radcliffe, who leads Human Factor Security, is not your typical hacker, clad in a black hoodie and working out of basement. Rather than spending her time hunched over a keyboard, she seeks to hack people.

What does that mean? As she explains in this podcast, she uses persuasion, psychology and influence methods to make her way into systems, and even into physical premises. She is often hired to break alarms and see if she can talk her way into a building.

She does it by capitalizing on the all-too-human aspects of our personalities, and from her experiences she has learned how phishing emails and other techniques also capitalize on human weaknesses to enable hackers to breach computer systems.

What’s both terrifying and fascinating, is how hackers take advantage of our weaknesses, tailoring their attacks, knowing that different scams work for different people and cultures. In fact, she explains that the organization culture you have, is the hack you invite. In a hierarchical organization the hacker will likely use authority principles. In a younger, less rules-driven culture attackers may use registration for a social activity as a way to steal passwords and IDs.

Hackers also take advantage of human emotions and stress. As she memorably says, “Emotion kicks logic off the cliff.” That’s why techniques such as promising a prize or threatening the release of embarrassing information can be so successful in getting people to click where they shouldn’t.

She advises companies create “cognitive firewalls” within their organization, helping employees to watch for red flags such as:

Any approach via email, call or social media that makes the recipient emotional The mentioning of money The request to act, especially if asked to act quickly

How else can you protect your organization? By making it safe for people to come forward when they make a digital mistake. The more comfortable they are coming forward, the faster they will and the sooner the breach is remediated.

And how do you find the internal bad actor? That, she says, falls on the shoulders of line managers, who need to be on the lookout for changes of behavior that may indicate stress.

Listen in to learn more, including the risks that can come as employees return to the workplace.

View Details

Post By: Adam Turteltaub

Legacy data is any data that your organization has lying around in obsolete formats that isn’t accessed regularly but is, instead, held for regulatory purposes. While that may sound innocuous enough, it can be an enormous problem for healthcare providers, says Bridget Group (LinkedIn), Corporate Counsel of Harmony Healthcare IT.

Typically the data is held in systems which are long out of date and lack the security features that are prudent for the current environment. The hardware is equally problematic, tending to be unstable with long downtimes and high maintenance costs. That can make it hard to meet the requirements of HIPAA and the 21st Century Cures Act.

So what should healthcare providers do to manage this challenge?

First, she recommends setting up a registry of all the systems across the enterprise to get a handle on what data is available and where it is. The IT department and health information management team can both be helpful.

Take the time to understand the retention requirements for the data under both Federal and State laws, the latter of which can be the more restrictive.

Then, if you don’t have one already, set up a data governance board, with the charge to identify health information captured across the organization, understand the purpose of the data, who can access it and how long it must be kept for. The board can and should create policies for retention, destruction and access.

Be sure also to train the workforce so it understands its obligations.

Finally, she advises moving data into an archiving solution, the cloud or a data warehouse and off of those legacy systems.

Listen in to learn more about how to keep legacy data from damaging your organization’s legacy.

View Details

Post By: Adam Turteltaub

Preventing data breaches is a critical task for all businesses these days, but it’s especially so in healthcare. No one wants to see health information disclosed, and the risks of a ransomware attack are enormous, literally putting lives at stake. And, of course, there are significant consequences under HIPAA.

Nick Culbertson, CEO and co-Founder of Protenus, reports that there were well over 700 breaches in healthcare in 2020. Over 40 million records were affected. It’s a staggering number, and one such breach exposed over 3 million records.

Breaches occurred in 49 of 50 states and Puerto Rico. In sum, nowhere is safe.

What can healthcare organizations -- and others, too, for that matter -- do to protect themselves? He recommends taking a layered approach. That includes security measures such as strong firewalls but also extensive training of employees, penetration testing and audit log monitoring. In sum, embrace multiple layers of defense that can protect against a wide range of possible mishaps.

In addition, as he explains in this podcast, it is important to take a broad view of the human risk elements. These range from snooping into records to find out if someone does or does not have COVID, to failing to dispose of paper records properly, to bad actors offering furloughed employees cash for their passwords and IDs.

One other area to protect against: breaches through business associates. With increased integration of providers and their suppliers comes dramatically increased risk. The largest incident in 2020 was the result of one such breach.

The bottom line, he reports, is that organizations need to invest more in their cybersecurity, but compliance and privacy teams also need to stay on the alert for simple, human failings.

Listen in to learn more about how to protect your organization.

View Details

Post By: Adam Turteltaub

HIPAA?  HITRUST?  One you have to follow (or else), the other it may be time to pursue.

In this podcast Justin Beals, CEO & Co-Founder of Strike Graph provides a primer on HITRUST and what companies thinking about pursuing certification need to consider.

HIPAA, he explains, is a legal requirement providing rules for how healthcare data must be handled, and penalties for when it is mishandled.  HITRUST is not a legal requirement but a standard.  An organization can get assessed against it and even certified.

Why should you pursue it? There are many reasons, but, likely the most compelling is that healthcare providers require HITRUST certification from their vendors.  With approximately 70% of data breaches traceable to third parties, organizations are demanding that their suppliers take strong steps to ensure the security of their systems.

Pursuing HITRUST certification can be a long process, Justin explains.  As a result, one key to success is starting early and avoiding the temptation to go too fast.  It’s not supposed to be fast and easy.  Plus, it requires the collection of significant data.

A second key to success:  recognizing that this represents a culture change.  Attitudes toward security will likely need to evolve, and data protection is now more important than ever, bringing with it a host of changes that need to be implemented.

A concerted communications and education effort will be needed to achieve success.  With so many breaches beginning with human errors, the workforce has to know what to watch out for, what to avoid, and why cybersecurity must be taken so much more seriously.

Listen in to learn more about HITRUST and the challenges and rewards in implementing it in your organization.

View Details

Post By: Adam Turteltaub

Brooke Nelson (LinkedIn), Executive Director, Worldwide Compliance and Business Ethics at Amgen had a unique and broad perspective on managing compliance during the pandemic.

In this podcast she shares what she has seen, including a drop in incidents in many areas.  Part of that, she believes, is likely due to the fact that people were disconnected.  With sales reps less able to make calls on medical practices there were less interactions and less opportunities for things to go awry.

When it comes to investigations the adjustment to the pandemic has gone better than might be expected.  As she notes, global organizations have always had to rely on some remote methods in the past when conducting investigations since you didn’t necessarily have compliance staff in every location.  During this era, though effective investigation practices in distant locations have likely grown more effective.

However, there remains a strong case for conducting at least some aspects of the investigation in person.  An in-person meeting can give a clearer read of the individual.  In addition, the presence of an investigation team may lead other individuals on site to share information that they might not have.  An investigations team physically present also offers another benefit:  it demonstrates the company takes investigations seriously.

With the US and other regions hopefully soon reopening, she does warn that compliance teams should be prepared, if they aren’t already, for change.  It is time, for example, to reiterate the need for the workforce to reach out and report their concerns through the helpline and other channels.

Compliance should also look out across the organization to better understand what is happening on a country-by-country basis, both for the business units and for the compliance team, itself.  There are likely significant disparities and a need to adjust efforts and expectations accordingly.

And, of course, the way we all work has changed, perhaps permanently.

Listen in to learn more about our recent past and what to consider moving forward.

View Details

Post By: Adam Turteltaub

A Systems Improvement Agreement (SIA) comes at a time of crisis for a healthcare organization, one in which it may even risk being terminated by CMS. As Suzanne Gellner (LinkedIn), Principal, The Gellner Group explains, an SIA involves a lot of work that must be done quickly, typically within just 12 months.

For organizations undergoing an SIA she recommends creating an oversight committee made up of C-Suite leaders and others with oversight of the service areas under the SIA. This will help make sure that these same service areas are accountable.

The committee would ideally have each group meet with them monthly and provide status updates.

Leadership support is critical, but so too is the support of middle managers. They are going to be the major change against, she explains, who understand what is happening on the front lines, and what leadership wants to see happen. They are also the individuals who will be coaching the staff into how to meet the goals of the SIA.

To help the managers, take the time to learn what their likely pain points are, what their day-to-day work life looks like and what challenges they perceive. With that knowledge you can better demonstrate how the SIA initiatives will help them in their work. Done right, it can turn them into ambassadors for the changes the SIA requires.

Suzanne also recommends taking a unit-by-unit approach rather than a system-wide approach to the SIA. Each service area is going to be different. The challenges and people will vary. As a result, it’s essential to understand where they are and how the program will benefit them the best.

In addition, once there is success in one unit, the others will likely notice, recognize the benefits and be more eager to implement the SIA.

Listen in to learn more about how to successfully navigate an SIA in your organization.

View Details

Post By: Adam Turteltaub

“Government ethics” is not an oxymoron. In fact, according to Jabu Sengova, Ethics officer for the City of Atlanta, government ethics programs are very real.

In this podcast she provides an overview of how Atlanta’s works. She shares that when it comes to ethics in the public sector there are several areas of focus including conflicts of interest and the misuse of public assets such as credit cards and cars.

Managing conflicts of interest has been a particular problem during the pandemic. With employees working from home there has been a noted increase of incidents revolving around second jobs and operating a business on the side. It is a problem likely facing the private sector as well.

And, of course, there are the ongoing challenges involving gifts and gratuities, especially for those city employees who work regularly with contractors and vendors.

Meeting these challenges isn’t easy for the ethics team. They serve a large 8,000 person employee base  with very limited resources. In addition, until recently there was a strong preference for in-person training. Atlanta is only now moving into elearning.

Yet, despite lagging in some areas, there is much, Jabu argues, that corporate compliance programs could learn from government ones, including resiliency. She notes that in her time there she has worked for three different mayors.

Business could also learn about doing more with less, she believes. For much of her time in Atlanta, there were only two or three members of the ethics team.

Listen in to learn more about government ethics programs and what everyone can learn from them.

View Details

Post By: Adam Turteltaub Jim Passey, Vice President, Chief Audit & Compliance Officer at Honor Health sat down with us to record three podcasts focused on compliance career development:

Setting Career Goals Moving Your Career Forward Making it to the Top

It isn’t enough just to set your eyes on the goal of chief compliance officer. Nor is it probably advisable to walk into the CEO’s office and make your pitch should the job become open.

In this podcast Jim Passey, who has been a Chief Compliance Officer for six years and at two organizations, share his advice for crossing the threshold from staff to leadership.

He advises that you start the process long before the job opens up. Be visible and make yourself known in meetings and on key projects as an active participant, not just another body in the room. Let people see you as an agent for positive change and a key voice at the table. That will both help your career, and help others take the compliance program more seriously.

Let your supervisor know you are eager to advance. Couch it in terms such as “I want to take on more responsibility” or “I’m eager to add value.” An emotionally intelligent manager shouldn’t take that as a threat, but instead take it as an opportunity to help you grow. Plus, if you don’t make your intentions clear, you may be passed up for someone else who has.

When the top job does open up, it’s important to remember that the CEO, board, or whoever else is doing the actual hiring probably has never worked in compliance and lacks a full understanding of the job. You will need to bridge that knowledge gap.

You will also need to remember that, at the top level, technical skills, such as expertise in specialized areas of law, are likely to be less important than personality characteristics and fit. Leadership wants someone who is going to be able to partner with them.

It’s also important to remember that the interview is a two-way street. Be prepared to ask questions that will you determine if the job (especially at an unfamiliar company) is right for you. Consider questions in your head such as: Does this conform to my perception of an environment I want to work with? What kind of support will I get? Are the leaders a strong, compliant type of a group, or are they just trying to fill the role?

Listen in to learn more about how you can improve your chances of making it to the top of the compliance profession.

View Details

Post By: Adam Turteltaub

NAVEX Global recently released its 2021 Risk & Compliance Incident Management Benchmark Report.  It is a document rich in data about what’s going on with helplines and incident management.

To understand lessons learned from the data we invited Carrie Penman, Chief Risk & Compliance Officer from NAVEX, to join us.

She reports that there is finally an answer to a question many have wondered: what has the pandemic’s impact been on helpline call volume. Interestingly, Carrie reports that overall call volume declined. April and May 2020 saw the steepest drops, not surprisingly since that was the time when businesses were closing quickly and employees were adjusting. But, she points out, it was not just a two-month phenomenon. Even at the end of 2020 volume had not returned to pre-pandemic levels.

Drilling down into the data there were significant variations by industry, with differences caused by whether organizations had switched to a work-from-home mode or had large number of essential workers still on the job site.

But what about the quality of the calls? Carrie reports that the substantiation rate of 42% was in line with previous years.

There was one exception, though: environmental health & safety. Substantiation rates were lower, and the number of reports increased substantially, likely due to COVID-19 related concerns.

Interestingly, 76% of EH&S reports were anonymous vs. just 54% of business integrity claims, most likely not out of fear but because complaints about things like not wearing a mask where a call back was not likely necessary.

The report also includes news that the median days between incident observed and reported increased from 21 to 28 days. That’s troubling for investigators given that memories fade over time.

Finally, we discuss the perennial concern about whether anonymous reports can be trusted. The data showed that anonymous reports were substantiated at a much lower rate: just 35% vs. 50% of reports with a name attached

Listen in to learn more, including some potentially troubling numbers about retaliation.

View Details

Post By: Adam Turteltaub Jim Passey, Vice President, Chief Audit & Compliance Officer at Honor Health sat down with us to record three podcasts focused on compliance career development:

Setting Career Goals Moving Your Career Forward Making it to the Top

You’ve set your career goals. You’ve mapped out the interim steps. Now, how do you keep moving along the path you have made for yourself?

The first step that Jim Passey outlines in this podcast is to do your homework. Compliance, he explains, is about giving good advice. As a result, nothing can destroy your credibility (and prospects) faster than giving bad advice.

To avoid that trap he advises investing the time to understand the government’s expectations. That begins, of course, with the Federal Sentencing Guidelines, but it doesn’t stop there. Stay on top of what is going on in enforcement. Focus on what the enforcement community is focusing on. Also, have a strong grasp of your organization’s business so you know to implement your program effectively within its culture. That includes understanding the structure and political flow of decision making, including who has formal and informal authority.

That’s only the beginning. As we all know, compliance isn’t just about knowing what the law and regulations requires. In many ways that is the easy part. The more difficult challenge is getting people to comply. Success is guiding behavior comes from persuasion, collaboration, motivation and inspiration.

So, to ensure success for your compliance program and your career, it is essential to develop strong communication skills, and even know a bit about salesmanship.

Negotiation skills are also a necessity. There are lots of grey areas in compliance where the laws and regulations aren’t perfectly clear, or a new business idea doesn’t fall neatly within existing frameworks. Having the ability to navigate the grey and find a potential solution is an invaluable skill.

What else does he recommend? Be dependable. Take initiative. Be the voice of solutions not problems. Work well with others. Build your network. Get involved in the compliance community, and take advantage of what SCCE and HCCA have to offer. You can even start with this podcast.  Listen in.

View Details

Post By: Adam Turteltaub

Cataloguing everything your compliance program does isn’t easy, but Susan Roberts (LinkedIn), who recently retired from full-time corporate life after serving as Chief Compliance Officer at three different companies, did just that. And in this podcast she advocates for doing the same for your compliance program.

She made it a habit to create what she and her team referred to as, simply, “the book.” It is designed to be a comprehensive resource should the government (or even management) want to know whether the company has an effective compliance and ethics program.

To make your book both useful and complete, she advocates breaking the book into several sections including:

An introduction Background Executive Summary Relevant expectations for compliance programs from government, industry groups and elsewhere (US Sentencing Guidelines, DOJ Fraud Section compliance program guidance, FCPA Resource Guide, and so on) A description of the compliance program including sections on:

Program oversight Tone at the top Risk assessment Monitoring and auditing Standards, policies and procedures Training, communication and awareness Confidential reporting systems Investigations Corrective actions Discipline and incentives Employee and other screening Third-party management Continuous improvement

In sum, it should provide a full and rich picture of the compliance program including screen shots of training, the code of conduct and helpline posters.

Having all that data in one place has paid off twice in very significant ways for Susan and the companies she worked for. In one case it helped convince the Department of Justice that a monitor would not be needed after trouble was discovered at a recently acquired business unit. The book helped demonstrate that the company was already doing everything listed in the Corporate Integrity Agreement. In another case, it helped an acquiring company have faith that there truly was an effective compliance program already in place.

The book can also provide insight into where the program needs to improve, acting as something of a self-assessment tool. If you have much less to say in one section, it may be a sign of a program gap.

List in to learn more about creating a book of your own, including how often to update it.

View Details

Post By: Adam Turteltaub Jim Passey, Vice President, Chief Audit & Compliance Officer at Honor Health sat down with us to record three podcasts focused on compliance career development:

Setting Career Goals Moving Your Career Forward Making it to the Top

In this podcast, the first in the series, he encourages individuals who are still early in their compliance career to take the time to gain a broad view of the industry they work in. For him, that is healthcare, and while many of the examples he cites in this podcast are healthcare-specific, they are equally applicable to other industries.

As you gain an understanding of your industry, he recommends thinking about whether you want to make compliance a career or a stop along the way. If you think it is a potential career for you, he advises you ask yourself whether you are comfortable with conflict and being the bearer of bad news. Both are, for better or worse, an essential part of a being an effective compliance officer, and many are not comfortable in that role.

Also, take the time also to assess what you aspire to do within compliance. Do you want to be the chief compliance officer or are you more comfortable at another level? Do you want to be a compliance generalist or focus on specific areas? To help find the answer pursue projects in a number of different compliance niches.

One important consideration when setting career goals is geography. If you are committed to staying in one region, your prospects may be limited. There may be just one top compliance job in your industry in a given city. If that’s the case, you may need either to set your sights a little lower or be willing to look in other cities and states or industries. As he observes: the fast way to move up the ladder is to move to where the jobs are.

Once you determine your career objectives take the time as well to identify intermediate steps along the way. This will help you set a path and measure your progress. Check regularly to see how you are doing, especially when major events take place, such as a new initiative that interests. It may encourage an adjustment in your plans.

Listen in to learn more about setting your career on the right track.

View Details

Post By: Adam Turteltaub

While most of the work in compliance is selfless, there needs to be a bit of self-interest when it comes to career.  Even if a compliance officer doesn’t want to make it to the top, he or she likely would, at some point, want to move up.

How best to do that?  In this podcast we talk with long-time compliance veteran and executive coach Amii Barnard-Bahn about promotability.  She has developed a Promotability Index and is author of the book The PI Guidebook.

Amii reports that from her analysis there are five key elements of promotability:

Self-awareness External awareness Strategic thinking Executive presence, and Thought leadership

External awareness is worth special attention and centers around how your behaviors impact others and how others perceive you.  The latter is particularly important since that perception becomes their reality when working with you.

Notably absent from the list is technical expertise.  It is a requirement, to be sure, but above a certain level technical acumen starts to be less important than the ability to manage people and affect change through others.

When it comes to seeking a promotion she advises to avoid having discussions with supervisors about the topic during the annual evaluation.  That conversation is more about compensation, and it is better to separate the two.  Also, it is ill-timed for another reason:  typically succession planning conversations by management and HR are held months earlier.  Better to raise the topic about six months before the annual review cycle.

If you do approach your manager about moving up, make sure she or he knows it is safe to give you candid feedback.  In addition, be sure to understand the power structure and culture of your company to know the likelihood of whether you are a candidate to move up the ladder.  Ask questions such as:  “How am I seen?”  “Am I working on the things I should be?”  “Are there perceptions that block me?”

Finally, she counsels individuals that the days of just working harder to get ahead are gone.  Instead, build around your strengths and remove bad habits.  Focus on areas such as the ability to influence and working with and through others.

Listen in to learn more about how you may be able to improve your own promotability index.

View Details

Post By: Adam Turteltaub

When a data breach occurs, one step is often overlooked in the rush to remediate:  preserving as much of the data logs and backups as possible  That’s a mistake, say Debra Geroux, Shareholder at Butzel Long and Scott Wrobel, Co-Owner, N1 Discovery, because that data illuminates what happened, how it happened, and what data was taken.

In this podcast they also advise hiring cyber counsel immediately to obtain guidance through the legal and regulatory issues.  They may also be able to help you conduct the subsequent investigation under privilege.  Counsel can also help identify outside resources, deal with law enforcement, and help healthcare organizations determine if the breach is a reportable one.

In addition to outside counsel, Geroux and Wrobel argue strongly for leveraging the organization’s communication team.  Managing messaging is critical.  The communication targets—victims, employees, the board, public, media -- have to be identified and given the information they need.  But, be judicious.  Limit your communications to essential information to reduce the opportunity to spin the story.

Most importantly, they advise, make the effort to understand what the root cause of the incident was.  Often, that’s not as evident as it may seem.  Sometimes the first suspected point of breach is not the actual one.

To reduce the risk of future incidents, they recommend adopting two-factor authentication.  Workforce training is also essential since so often employee errors (and vulnerability to sophisticated phishing efforts) are a factor.

Hiring a third-party security company to conduct an internal and external vulnerability assessment can also be helpful.  It should identify every device and piece of software on or connected to your network, their vulnerabilities and how to remediate them.

That assessment should also address any cloud-based solutions your organization is using.  While, generally speaking. those solutions are secure, if your organization leaves the default settings in place, it could leave you exposed to bad actors.

Listen in to learn more about how to protect your organization, including the need to take a second look at your cyber insurance policy.

View Details

Post By: Adam Turteltaub

America’s data is under attack. Solar Winds and other recent headline-grabbing stories have demonstrated that foreign adversaries are eager to hack into computer systems for a wide range of purposes.

The US Department of Defense has had its supply chain hit hard, and to help protect both the chain and the nation’s assets has pursued the Cybersecurity Maturity Model Certification (CMMC), with a multi-level approach requiring outside certification, not the self-certification as in the past.  Although only for defense contractors, it is a model worth watching since it may eventually expand, in one form or another, to additional areas of government contracting.

In this podcast Tony Buenger, Cyber Security Consultant and Instructor, and Marti Arvin, Executive Advisor, both of CynergisTek explain some of the complexities of CMMC and its many levels. Level 1 covers basic hygiene and is primarily focused on technical security controls. Level 3 is a certification that requires maturity in terms of documented policies and procedures that have been institutionalized. Level 5, the highest level, is focused on persistent threats.

Notably CMMC focuses not just on technology, but also on processes and people, even looking to ensure that the process are built into the organization’s governance. As a result, it’s not a standard for just the CISO or CIO to handle. CMMC is a commitment that needs to be institutionalized, takes time, and requires both trust and ongoing verification.

In sum, it very much requires the maturity that is a part of its name.

Listen in to learn more about CMMC and what your organization needs to do now, and possibly in the future.

View Details

Post By: Adam Turteltaub

So what happened to ethics and compliance programs during the pandemic? Did companies throw out their commitment to doing the right thing and values in their quest to survive the upheaval? Or did they embrace them?

The data is looking very encouraging, reports Susan Divers, Senior Advisor at LRN. As she shares in this podcast their 2021 Program Effectiveness Report found that the commitment to ethics and values actually increased during this period. Ethics and compliance were front and center, helping organizations to cope with the crisis as they emphasized values over rules.

There were stress points, however. Many organizations didn’t pivot quickly enough to meet the demands of the new reality. For example, the majority did not move their training to mobile platforms, at least initially.

In addition, the report found concerns about the future, including:

Pressure to cut compliance staff and budgets Workers lacking the checks in their behavior that come from when colleagues are nearby, and not located remotely, Pressures to circumvent controls as business resumes

Listen in to learn more about the research findings and also some interesting data on the gaps between business leaders and middle management.

View Details

Post By: Adam Turteltaub

Cheryl Curbeam (LinkedIn), Vice President, Chief Risk and Compliance Officer at Corteva Agriscience has had a very interesting and unusual path to the compliance professional. She studied and began her career in mechanical engineering before moving into operations leadership. It turned out to be a great background for compliance, teaching her how to think about what is and isn’t in scope and how to solve tough problems.

From there she went into sales, spending about 80% of her time on the road. It gave her great insight into the mind of salespeople, including the fact that their focus is on customers. Corporate work, including compliance training, is squeezed in when they can find time. As a result, sales teams want compliance to deliver clear and easy-to-find guidance.

That experience helped her when she went to develop an app to support the compliance program for this new company, which was created in June 2019 after Dow and DuPont merged and spun Corteva off. Despite the long compliance history of both of the original organizations, the new enterprise needed to create a compliance program of its own. It launched, not too long before the pandemic and all the changes that came with it, including having even more of its workforce operating remotely.

As she explains in this podcast and will also address at the SCCE Technology and Compliance Conference on June 24th, the company needed to train employees remotely and enable them to report concerns. An app turned out to be an ideal tool. The mobile solution housed training, the code of conduct and other assets such as quick learning topics.  It also provided a vehicle for accessing the helpline.

What’s her advice to others considering developing an app? First, find a vendor that can support all phases of app development. Second, be sure to have a strong project manager internally to deal with the complexity inside your company. Third, know what content you need to deliver. Fourth, gain the support of your IT department. And finally, have a strong communications plan to ensure that the workforce understands the value the app provides.

Listen in to learn more and be sure to join us June 24th for the SCCE Technology and Compliance Conference.

View Details

Post By: Adam Turteltaub

Corporate anti-corruption efforts are a constant struggle, with compliance teams always searching for new approaches that can mitigate this very dangerous risk.

Jonathan Rusch, an Adjunct Professor at Georgetown University Law Center and American University Washington College of Law, sees an opportunity in technology. He is the author of the Coalition for Integrity’s guidance document Using Machine Learning for Anti-Corruption Risk and Compliance.

In this podcast he shares that in other areas, such as fraud and anti-money laundering (AML), some kind of Artificial Intelligence (AI), whether rules written by programmers or machine learning, has proven productive. The Coalition for Integrity wanted to know if a similar solution could work for anti-corruption efforts.

In his and their research three successful implementations were found: AB InBev, Microsoft and Alexion Pharmaceuticals.

When embarking on an effort in this area, he recommends first assessing what approach makes the most sense. For a smaller organization, a simpler, rules-based approach to automation is likely more appropriate.

For larger organizations, he suggests building a business case that encompasses what needs to be done, the costs, the ongoing staffing requirements and the overall anticipated ROI.

If machine-based learning could be worthwhile for your organization, he advises creating a clear definition of what you want the solution to address. From there it’s time to build your data set, work with the data and train the machine learning model. And, importantly, it’s also time to make sure the model is generating predictions that are accurate and reliable.  Often at the first stages it does not.

When it comes to the data set, he notes that there may be more data within the enterprise than is initially thought. Data to consider incorporating into the effort could include spending, sales, accounts receivable, third-party contracts and third-party transactions.

Intrigued?  Listen in to expand your learning about machine learning.

View Details

Post By: Adam Turteltaub

The Environmental, Social and Governance (ESG) movement has been around for a long time, but over the last year it has hit a tipping point. In fact, according to Roy Snell, former SCCE & HCCA CEO and now advisor to Osprey ESG Software, it has hit several tipping points.

In this podcast he and Alison Taylor, Executive Director of Ethical Systems, outline how strong the ESG movement has become and how important it is for compliance professionals to embrace it. They will also be addressing this topic at the SCCE ESG and Compliance Conference on June 17, 2021.

As they share here, recently the EU announced it was looking to create regulations monitoring the truthfulness of ESG claims, particularly for investment firms. The US Securities & Exchange Commission (SEC) has set up an enforcement working group of its own. Standards bodies are emerging and setting some very high bars, and many organizations have committed to various ESG goals.

One of the difficulties of ESG is that there is a mix, Alison notes, of hard and soft obligations. In the area of modern slavery, for example, many countries already have requirements in place for, at a minimum, reporting what the company is doing to managing the risk. And in environmental arena there are already a host of laws and regulations. But, in many other areas that fall under ESG there are not yet laws. Nevertheless, a corporate commitment should be taken just as seriously and with great rigor.

In sum, ESG has come of age, and with it has come the risk that organizations will start fudging the numbers to meet their proclaimed and required ESG goals. That leads to an opportunity and need for compliance teams to get involved. As in other areas, compliance should not necessarily be directly involved in the initiatives since it can create a conflict of interest. Instead, they advise, compliance should, as it traditionally has, ensure the integrity of the organization’s work by creating control processes and procedures and investigating claims of potential wrongdoing.

For the compliance team to be effective they recommend working with related units in the organization: ESG, corporate social responsibility, sustainability and investor relations. Increasingly investors are demanding that organizations report on their ESG efforts, and that has caught the attention of leadership and the board.

Listen in to learn more, and then join us at the SCCE ESG and Compliance Conference.

View Details

Post By: Adam Turteltaub

We all face ethics issues in our lives and work. Yet, while there is so much these days people feel comfortable speaking about, ethics is often not one of them.

To better understand why, we sat down with Bettina Palazzo (LinkedIn), of Switzerland-based Palazzo Ethics Advisory.

As she explains, ethics is a systematic way of thinking about what is good and bad, how we should live together and what makes for a good life. These are all questions people have to answer for themselves. Yet, people hesitate to talk ethics because there is often not a clear cut or easy answer. That creates ambiguity and feelings of uncertainty that make people uncomfortable, and that discomfort is more acute in a business setting where quick, certain decisions are prized.

To encourage more discussions of ethics issues, Dr.Palazzo advises better marketing. Safe spaces for discussing ethics have to be created, and ethics talks need to be packaged attractively and focused on real-life experiences that people are likely to encounter in the workplace.

She also encourages ethics teams to be mindful of the perspective of the workforce.  They are adults, and if ethics training comes across as parenting – with the employee as the child – it can shut down any learning.

The conversation concludes with a provocative discussion of leadership and ethics and how intertwined they are. Leadership, she argues, is inherently an exercise in ethics because leadership comes with power over people, and leaders must think about how that power will be used.

Listen in to learn more, including how best to set the right ethical tone throughout the organization.

View Details

Post By: Adam Turteltaub

Self-disclosures and returns of overpayments are a fact of life for healthcare providers in the US, but that doesn’t mean that what to do in every situation is always perfectly clear or easy.

Elliott Coward, Associate at Morris, Manning & Martin and author of the chapter “Self-Disclosure and Return of Overpayments” for the Complete Healthcare Compliance Manual provides an excellent overview of the self-disclosure and repayment obligations this podcast.

She explains that obligations to self-disclose and return overpayments fall into two buckets. There is a “concrete bucket” such as Medicare’s 60-Day Rule. It requires providers provide accurate bills for payment, and if any non-compliance is found to refund the overpayments.

The second bucket is less concrete and contains carrots and sticks from the regulators. These provide incentives for self-reporting and penalties for failure to do so.

Whatever bucket the issue you encounter falls into, she recommends coming to the government well-prepared. Make sure the audit is done thoroughly and well. Have in hand the exact amount that can be tied to a specific claim or a statistically strong extrapolation. And, be sure to have your story straight: understand what the problem was, what caused it, and what your organization’s remediation plan is.

In addition, and especially if the self-disclosure was caused by a very significant problem, be sure to also demonstrate that the root cause has been identified and proactive steps have been taken to correct it.

For simpler disclosures and repayments, she cautions against taking them too lightly.  Follow the instructions for repayment to a tee. Don’t skip any steps and follow all the instructions carefully. A short cut can easily trigger an inquiry and all the additional burden that comes with it.

Listen in as she also explains some of the nuances such as the difference between a simple error, when there are indications of potential fraud, and when a Stark Law violation has occurred.

View Details

Post By: Adam Turteltaub

“How should my compliance program be designed?”

It’s a question many are now asking in the wake of the pandemic, and it’s a question Donna Abbondandolo, Chief Compliance Officer of Bon Secours Mercy Health asked even before it.

In her case the compliance team was divided functionally. One team was focused on revenue cycle. The other for general compliance.

While that likely made sense at one point, it no longer did, and, adding to the need for a change was the fact that compliance was moving out from enterprise risk management and was about to report to the CEO and the audit & compliance committee of the board.

Bottom line: it was time for something new.

When setting goals for redesigning your program she recommends first understand the strategy of your organization, where it is going and how you can align compliance best to support the strategy.

Also, be sure to have a good handle on the risk profile. What are the high-risk areas? How do you identify what is high risk? How do you support leadership in managing risks? The latter can be a very difficult question in a geographically- dispersed organizations.

Even with these considerations in mind and the best intentions, she warns that there will be bumps along the way. That’s when it’s important to have already cultivated relationships with operational leaders to help smooth things over, dispel the notion that compliance is a roadblock, and build trust.

In terms of structure, she took a functional approach to the redesigned program as a way to address compliance concerns both by function and across the enterprise. She developed key leads for various areas to help support the operating units.

Within the compliance team, she met with staff, took the time to understand their skillsets and then leveraged their strengths to help create a strong, functional model. She also worked with HR to leverage the organization redesign principles they had, including developing a purpose statement for the compliance team.

Listen in to benefit from her experience. It could help you when it’s time to redesign your compliance program, or just to kick the tires a bit on your current one.

View Details

Post By: Adam Turteltaub

Emmelyn Kim is AVP, Research Compliance & Privacy officer of Northwell Health in Lake Success, New York. She is also the authors of the chapters Clinical Research:  Financial Conflicts of Interest and Clinical Research: Human Research Protections for the new HCCA Complete Healthcare Compliance Manual.

Like the chapters themselves, the conversation in this podcast ventured well outside of the lab into some of the broader issues affecting research, the pandemic and both vaccine distribution and use patterns.

We began with a discussion of the Environmental, Social & Governance (ESG) movement that has grown quickly from an ideal to actual compliance requirements already in many countries. Europe leads in this movement for now, but with so much money at stake it’s increasingly like that businesses in the US, including those in healthcare, will be measured on ESG metrics. At that point, ESG may become a compliance requirement.

Accelerating the trend, arguably, is the overlap in interests between ESG, diversity, equity and inclusion efforts, #MeToo, the Black Lives Matter movement and more recently efforts to stem anti-Asian hate crimes.

In addition, health equity is increasingly seeing scrutiny and concern, with the pandemic having different impacts when assessed by race.

She sees compliance playing a central role in the organizational response to these issues, serving as eyes and ears. Plus, compliance is best suited to spot ethical lapses and respond to them.

Listen in to learn more in this provocative podcast.

View Details

Post By: Adam Turteltaub

During the second half of 2020 Gartner Research evaluated the compliance spending of 117 organizations, and the company recently released the interesting findings. Brian Lee, Managing Vice President in the Gartner Legal and Compliance Practice explains in this podcast that their research showed that after three years of strong increases spending plateaued in 2020, no doubt due to the pandemic and ensuing budget freezes and reevaluations.

Of course, he points out, the risks didn’t freeze. In fact, the pandemic created additional risks and came with new requirements in areas like privacy and data security, which led to greater internal collaboration.

Looking deeper into the numbers Gartner found that companies made a shift in how they allocated their budgets. Personnel expenses were roughly the same but companies invested heavily in outsourced solutions, with a 15% increase in spending on technology and a 13% increase on communication and training vendors.

What else has Gartner found? Listen in as we discuss:

An increased focus on supplier continuity and increased third-party due diligence An increase in the use of liaisons to supplement the compliance team Privacy spending increasing, and the relationship between privacy and compliance changing

New opportunities for compliance to affect and lead corporate culture.

View Details

Post By: Adam Turteltaub

Corporate Integrity Agreements (CIAs) and Integrity Agreements (IAs) are recurring features on the healthcare compliance landscape. To help sort them out and provide a bit of a primer on the topic we spoke with Veronica Xu, Chief Compliance Officer, Sabre Healthcare Group. Veronica is also co-author with Dr. Cornelia Dorfschmid and Nicole Caucci of the article “Government Settlements:  Corporate Integrity Agreements and Integrity Agreements” in the Complete Healthcare Compliance Manual.

A typical CIA has the following requirements, she explains:

A compliance officer A compliance committee Policies and procedures An education program Disclosure mechanism/hotline Independent review Reporting obligations

In each case these elements of the CIA are customized to the organization and the incident that led to the CIA.

An IA differs in several ways. First IAs are more likely to be called for with smaller, simpler organizations. The length of the term is typically shorter (3 years vs. 5 for CIAs), and the level of monitoring and frequency of review are markedly different.

The relationship with the monitor, regardless of the type and scope of the agreement, is extremely important. The monitor’s job is, as the name says clearly, to monitor the organization’s efforts to the meet the requirements of the agreement. They also review reportable events and other notifications mandated by the agreement.

The level of involvement by the monitor differs widely. In some cases, it may be just a monthly call.  In other cases, the monitor may be much more active, not just monitoring but also providing feedback and pushing the organization to improve its efforts.

The key to a successful relationship with the monitor, Veronica explains, is to be open minded, collaborative, receptive, respectful and transparent. Take a constructive, positive approach and the monitorship can be much easier and leave the compliance program and the organization as a whole in a much stronger place.

To avoid backsliding after the monitorship ends, she advices continuing the relevant practices in the CIA or IA, but don’t keep them static. Make sure they continue to evolve as your risk profile and compliance programs do.

Listen in to learn more, including the importance of celebrating.

View Details

Post By: Adam Turteltaub

The playing field for anticorruption never stops changing, with new laws and new risks constantly arising. To help sort things out, and to gain his insight into other compliance challenges, we sat down with Gary Kalman, Director of the US office of Transparency International.

One of the biggest changes in the landscape, he explains is the enactment of a new law in the US, effective January 1, 2021, which implemented a new ultimate beneficial owner (UBO) regime designed to make it harder for individuals to hide behind holding companies.  That law will have three key impacts, he reports:

It will increase the ability of organizations to understand who they are dealing with in their supply chain Aid law enforcement, particularly in the areas of pirated and counterfeit goods Make it more difficult for fraudsters to make artificially low bids on government contracts that they have no real plan to fulfill, thereby squeezing out legitimate businesses

He also sees new legislation in Congress that he believes is likely to pass and have an impact on anticorruption efforts. The Foreign Extortion Prevention Act, if passed, will extend anti-bribery prohibitions to the demand side of the equation. The FCPA, of course, is focused on the supply side. The CROOK Act, which stands for Countering Russian and Other Overseas Kleptocracies, would create a fund to help foreign states fight public corruption and develop structures designed to promote the rule of law.

This proposed legislation comes at a time in which corruption has increased as a result of the pandemic. A dramatic rise in government spending has led to an increased number of public tenders globally, with the consequent increase in opportunities for both fraud and corruption.

In sum, it’s a challenging time, and there are reasons for optimism and pessimism. Listen in to see to which side you lean and how you should prepare for what may come next.

View Details

Post By: Adam Turteltaub

While the CARES Act provided much needed funding, it wasn’t a handout for healthcare providers. There are strings attached, explains Stephen Shaver, an attorney with Wachler & Associates and author of the Chapter “Revenue Cycle: CARES Act Relief Funds” in the new HCCA Complete Healthcare Compliance Manual.

There are key restrictions under the Provider Relief Fund (PRF) on how the dollars may be used: only to prevent, prepare for and respond to coronavirus. Healthcare providers also may not use any PRF payments for an expense that another funding source has already reimbursed or is required to reimburse.

The risks don’t stop there, Stephen explains. Poor documentation and comingling of the funds can cause compliance issues. To mitigate the risk, he recommends having an adequate paper trail and for compliance team to coordinate their activities with accounting and finance to ensure that there are adequate internal controls in place.

Healthcare providers should also take the time to read the terms and conditions. They are rather specific and contain elements that might not be expected, such as on the use of chimpanzees.

Finally, he warns not to shrug off the power of enforcement authorities. There is potential liability under the False Claims Act and the US Government has vowed aggressive response to misuse of the funding. In addition to the Office of Inspector General at Health and Human Services and the US Department of Justice, Congress created a Special Inspector General for Provider Relief.

Listen in to learn more, and be sure to read the Chapter “Revenue Cycle:  CARES Act Relief Funds” in the new HCCA Complete Healthcare Compliance Manual.

View Details

Post By: Adam Turteltaub

The Agencie Francaise Anticorruption, popularly known as the AFA, recently recorded a podcast with us to give insights into its work.

Maria Lancri, a partner at the Paris law firm of Squair joins us in this podcast to provide further light on the activities of the AFA.

As she explains the recently released guidelines reflect both the AFA’s learning and a great deal of input from the private sector. They represent a substantial evolution from the first guidelines, moving from a more theoretical document to one significantly more practical in its approach. The elements of a compliance program have been organized into three pillars:

Commitment of senior management Using risk mapping Management of the identified risks

Based on her reading of the guidelines and AFA actions there are several key takeaways that she shares. First is the importance of commitment by senior management. There must be involvement in the program, the board must be overseeing it, and the budget must be meaningful.

Second, the AFA is willing to recognize that a program can be deemed sufficient and worthy of recognition, even if it does not follow the guidelines precisely.

Third, multiple levels of controls are essentials. The AFA even provides a list of potential controls for an organization to consider.

Listen in to learn more of her insights into the expectations and actions of the AFA.

View Details

Post By: Adam Turteltaub

As we move ever forward in compliance, sometimes it’s good to stop, look back, and understand the history of compliance programs.

Seth Whitelaw, President and CEO of Whitelaw Compliance Group knows the roots of compliance programs well.  He covers them in this podcast an in the chapter “Healthcare Compliance Programs: From Murky Beginnings to Established Expectation” in the new HCCA Complete Healthcare Compliance Manual.

In our conversation, we start at the beginning for compliance with the birth of the Defense Industry Initiative (DII), which was formed in the wake of the procurement scandals of the 1980s. Today’s commonplace tools such as codes of conducts and helplines can all trace their lineage back to the DII.

Compliance has evolved considerably over the years, and yet resistance remains. As Seth points out some resist because compliance is perceived as being too expensive to do well.  Others resist because they think they are compliant and ethical.

Anyone in the profession knows that even the best companies still face challenges sooner or later. So, too, does the government.

Through the years the government has helped make that point and strengthened the case for investing in compliance. The Sentencing Guidelines laid out an outline for compliance that does not have to be expensive to be effective. The Office of Inspector General at Health and Human Services has fleshed out the Guidelines for healthcare compliance programs, giving much needed direction for this industry. The evaluation criteria from the US Department of Justice has pushed compliance teams to ask fundamental questions of compliance programs and to see if they truly work.

Looking to the future, provocatively Seth sees two potential trends. First is the shift of compliance to a more independent function, potentially one that is outside of the company. The second will be increased used of data, combined with Artificial Intelligence, to automate many of the manual compliance tasks.

Listen in to learn more about where compliance was, where it is now, and where it may be going.  And be sure to check out the new Complete Healthcare Compliance Manual.

View Details

Post By: Adam Turteltaub

Few areas of compliance change as rapidly as export controls. People, companies and even countries move on and off the sanctions list. Adding to the complexity, as Matt Silverman, Senior Manager, Compliance & Export Control at ASML explains, is the challenge that an export control violation isn’t about simply shipping goods to someone or somewhere you shouldn’t. Even a conversation, plant tour or the wrong hire can be a violation.

So, how do you stay on top of this issue?

For one, you need a good source of data on who and what entities are on the sanctions list. There are multiple sources that need to be checked regularly includes the Department of Commerce Bureau of Industry and Security (BIS) and Department of State. Plus you will likely need a good vendor with a database of prohibited persons, along with subscriptions to several email lists. And, it doesn’t hurt, as he has done, to join a network of export compliance pros who share the latest information.

Second, it’s critical to work with the business unit to help them understand both the complexities and the need to proceed with caution. At the same time the compliance team needs to stay involved and utilize creative problem-solving skills.

One other discipline, he explains, has to be involved in managing this risk: HR. Hiring a non-US person to work in the company in a sensitive position may be a deemed export and a violation of law. At the same time, though, the company has to be mindful of anti-discrimination laws.

Listen in to learn more about how to manage this complex, ever-evolving risk area.

View Details

Post By: Adam Turteltaub

After this podcast, I will never look at a doctor’s office the same way again, and if you are responsible for Stark Law Compliance, your perspective may well change as well.

Goran Musinovic is Vice President of the Realty Trust Group in Knoxville and co-author with Michael Honeycutt and Gregory Gheen of the Chapter “Contracts with Referral Sources:  Real Estate Compliance” in the new HCCA Complete Healthcare Compliance Manual.

Medical office space rentals can trigger Stark Law issues quite easily, he explains. To ensure that it doesn’t, the lease must adequately describe the property; be at least for a year; the premises size may not exceed what is legitimate, reasonable and necessary; space must be used exclusively the lessee, the rent must be fair market value; and it may not take into consideration any referrals between the lessee and lessor.

And that’s just the start.

In addition, compliance teams need to watch for allowances for improvements that do not make sense economically, who is paying for phone, internet and the removal of medical waste, whether the rent is actually being collected, and, if the space is time-shared, whether it is being shared as agreed.

In sum, there is a lot to track. Listen in to learn more, and be sure to check out the new edition of the HCCA Complete Healthcare Compliance Manual.

View Details

Post By: Adam Turteltaub

We all want honesty in our lives, and in our workplaces. It can make for all the difference on both a personal and professional level.

For Ron Carucci, Co-Founder and Managing Partner at Navalent, discovering what led people to tell the truth and behave fairly became a mission. He analyzed over 3200 interviews that took place over fifteen years using Artificial Intelligence and identified four factors that correlated to whether people would behave honestly, which he defines as saying the right thing, doing the right thing and doing the right thing for the right reason.  The four factors he found are:

Clear identity Meeting the inherent promise of the values statement of the organization and ensuring actions don’t belie those words Accountability Too often accountability has become a negative: scoring people against the wrong measures and putting them through an odious review process, which leads them to dishonest acts to avoid being penalized Governance Here he means not board governance but organizational governance: how we make decisions, allocate resource and set priorities. It needs to be done in a transparent way with reliable data Cross-Functional Relationships When the organization becomes fragmented and there are soon competing truths, conflicts go unresolved. The relationships need to be solid.

According to his research, get these four factors right and the organization is 16 times more likely to have people be honest.

Listen in to learn more a new way to think about creating a more honest organization.

View Details

Post By: Adam Turteltaub

The Paycheck Protection Program (PPP) stimulus effort has led to many publicized cases of fraud.  As Neil Getnick, managing partner at the law firm Getnick & Getnick explains in this podcast, it’s not just grifters who are taking advantage of this program. Legitimate businesses can find themselves on the wrong side of the line.

As organizations sought funds many engaged in outright fraudulent activity such as creating fictitious employees, applying despite being on the Treasury Department’s do not pay list, even hiding the fact that they were in bankruptcy.

But there are subtler ways companies can go astray. A technically accurate but misleading answer in the questionnaire is one trap. Another is questionable documentation. There are very specific document requirements, he explains, and if an organization makes a redaction it must be spelled out quite clearly.

But perhaps most importantly organizations need to ensure that their attestation to this sentence is truthful: “Current economic uncertainty makes this loan request necessary to support the ongoing operations of the applicant."

With a new stimulus being discussed in Washington, organizations need to ensure that any funds are applied for properly. And if they err in doing so, they need to be very careful in how they correct the matter.

View Details

Post By: Adam Turteltaub

Dubai-based compliance veteran Cynthia Khumalo (LinkedIn) is heavily focused on third party due diligence.  It’s a difficult task for companies in normal times, but it’s all the more difficult these days.

In this podcast she recommends starting by having a good sense of the requirements that the third party is expected to fulfill and how it will enable the business.  That means understanding what the company is missing in its own capabilities and what will be required of the supplier.  Looking to see if the vendor has the technical capabilities and can operate within legal parameters is an essential first step.

It’s only the start of the process, though.  She advises taking the time to understand the organization’s risk appetite, parameters of the third-party’s engagement, and what can be done internally to assess the provider.

When assessing the vendor, it’s important to look at the traditional elements such as ownership.  But it’s also important to go beyond desktop research, when possible and prudent, and check the things only an in-person visit can reveal.

Due diligence doesn’t end when the contract is signed.  On an ongoing basis there’s a need to know what may have changed that can prove problematic, which is why audit rights can be crucial.  But a softer approach can also be helpful, demonstrating that compliance isn’t there to catch the vendor doing something wrong but instead to make sure that things continue in a way that doesn’t run astray of legal and regulatory (as well as contractual) requirements.

Listen in to learn more about third party risks and management.

View Details

Post By: Adam Turteltaub

It’s not an easy time for compliance budgets. Never exactly padded, they are under pressure as organizations try to control costs during the pandemic era.

While management may feel as if compliance should be included in an across-the-board cut, not everyone agrees that is a good idea, including the US Department of Justice.

So how do you make the case to management not to reduce compliance investments?  Long-time compliance professional Patrick Wellens suggests reminding them that regulators expect adequate staffing of the compliance team, in good times and bad. In addition, the proliferation of digital and social platforms and collection of so much data may be increasing risks.  Outsourcing and the proliferation of new suppliers adds third-party complexity. And at the same time, various stakeholders are demanding more out of business, not less.

If all of that doesn’t work, and you do have to cut the budget, he advises to cut strategically. Determine what isn’t adding sufficient value and can be suspended.

To get more out of the budget, look at what activities can be shared with other departments and where shared services can help. Building common ground with other departments is a technique that is useful not just for this period but also for the long term.

Look, too, at the training budget. Some of it may not be relevant for the current time.  Also, look to inexpensive and effective alternatives, such as as sharing stories of incidents that occurred at the company. Also, consider regular nudges and ethical dilemmas to consider.

Then, looking to the future, when budgets begin to grow again, he advises not simply restoring what you had cut. Instead, he counsels beginning with investments that can improve effectiveness and address key risk areas.  In the second stage, look for efficiencies where you can optimize controls.

Listen in to learn more about how to do more with less.

View Details

Post By: Adam Turteltaub

The need to Know Your Customer (KYC) is not, contrary to popular belief, an issue limited to financial institutions.  A wide range of industries are affected. In fact, in 2020 of the 15 companies penalized by the Office of Foreign Assets Control (OFAC), just two were financial services firms, reports Tracy Manning, Director of Financial Crime Compliance at LexisNexis Risk Solutions.

In this podcast she explains that, despite the diversity of affected firms, there are common challenges during this time of pandemic, including difficulty accessing sources for KYC due diligence information and delayed onboarding of new accounts.

So great and persistent is the challenge that almost 80% of survey respondents saw this problematic environment remaining for the next 18-24 months.

To navigate through these difficulties it’s important to understand the convergence of factors that combined with a pandemic to make KYC so hard. These include a mass shift by consumers to digital interactions, and with it rising expectations for business. Worse, bad actors have followed business online, changing their tactics to capitalize on the new reality, including preying on those working from home.

Compliance teams need to rethink their strategies for the new normal, she argues. For example, instead of relying on manual look-back processes geared towards physical identities, they need to explore the digital identity data consumers are leaving their wake.

KYC is yet another challenge for a challenging time. Listen in to learn more about KYC and protecting your business.

View Details

Post By: Adam Turteltaub

With the 25th annual HCCA Compliance Institute about to take place we have been collecting some rememberances of the last 25 years from various members of the compliance community.

In this podcast, SCCE & HCCA board member, and the association’s next president Robert Bond shares his history in compliance. Robert, who is Senior Counsel and Notary Public at the London firm of Bristows actually has roots that dig even. About 35 years ago he was living in the Midlands of the UK and had a neighbor who was developing (loudly) a video game, often at all hours of the night.

As Robert and the neighbor talked, it became clear that the programmer needed some legal help, which led Robert eventually to move fully into the then emerging field of video game law. Even at that time, he reports, gaming firms were collecting vast troves of data with often insufficient understanding  of both the opportunities and risks it posed.

By the time of the first Compliance Institute he had moved to London and was leading a small firm’s multimedia practice. Notably by the 1990s privacy, which Robert specializes in, was already becoming a concern. As he shares in the podcast, with the birth of the web, more data was collected and increased focus was being paid to the ethical side and the need to be careful with what was fast becoming the new oil.

His advice when it comes to data; don’t think about a privacy compliance program. Think about a compliance program and how data protection and privacy fit in.

Listen in to learn more about his fascinating career, the evolution of compliance, and what he sees as a C-suite future for privacy officers. And plan on joining us for the 2021 Compliance Institute.

View Details

Post By: Adam Turteltaub

In-person compliance training can have an impact like no other. But it has to be done right, which isn’t easy especially during the pandemic. Richard Bistrong, who specializes in delivering in-person compliance training, advises compliance teams to approach live training from a reverse engineering perspective: start with your goals and examine how they drive what you offer education on and how you do it.

That includes looking at how your risk profile has changed. Chances are they have evolved and that travel and entertainment training isn’t as important as it once was.

To make the training work effectively, realize that you can’t just move an in-person session over to Zoom. You need to understand what works in the digital environment. Participants tend to be more passive, making it even more important to be clear as to what is in it for them.

Also, relook at the use of slides. They can make the training feel less personal. It may be better to keep the video focused on the presenter and send additional materials later. It also may be better to have as a goal getting people talking and curious to learn more.

For more advice, he highly recommends reading Can You Hear Me by Nick Morgan.

One other thing to begin thinking about: hybrid meetings. Once workers begin returning to the office there may be times where people are being trained in person with colleagues dialing in. When that happens you need to avoid proximity bias: tailoring the message for and answering the questions of those in the room and losing track of those accessing the program remotely.

Listen in to learn more about how to make live training work in a remote world.

View Details

Post By: Adam Turteltaub

Brexit is done, sort of. As Andre Bywater, partner at Cordery Compliance explains, the deal the United Kingdom struck with the European Union applies primarily to goods, not services. While the trade is free from tariffs, it’s not free from paperwork. In addition, while there is a temporary agreement in place on data transfers, an adequacy decisions is still needed for the long term.

So what does this mean for compliance teams? A great deal. For one, it’s dangerous to assume that what applies to the EU also applies to the UK, and vice versa. Shipments of goods through the UK will likely be impacted, and plans should be made in case data flows are interrupted.

Global companies should also anticipate even more complexity in all the already challenging risk area of sanctions. The UK will likely want to continue to make it mark in this arena and also in the oft-related issue of modern slavery.

Business also needs to plan for more complex labor issues. Moving staff between the UK and EU will be significantly more complex with visa issues needing to be navigated.

Listen in to learn more about what Brexit means today, and what your compliance program needs to do for the post-Brexit future.

View Details

Post By: Adam Turteltaub

It’s not everyday that a Chief Constable joins the Society of Corporate Compliance and Ethics, let alone one who is the United Kingdom’s police national lead for ethics. So when Richard Lewis signed up we invited him to sit down for a podcast, and he graciously said yes.

In this conversation he explains the structure of policing in the UK and its ethics function. Each of the 43 police agencies, he told me, has its own ethics committee. Above them are four regional committees, and above them the National ethics Committee which he chairs and meets quarterly. To make the discussion robust and not an “echo chamber” the National Ethics Committee includes police but also individuals from business and academia.

Their mission is not to enforce ethics but to determine best practices that can be applied. In addition, they explore the ethics issues facing the police including the Black Lives Matter movement, #MeToo, abuse of authority and, as he put it both what they can and can’t do as well as what they should and shouldn’t do.

Another area of discussion is digital ethics. Technology such as facial recognition software and AI are evolving faster than the ethical frameworks.

In this conversation we also explore managing stress in these difficult jobs. One important strategy for maintain mental health: having an adequate work-life balance. It’s a goal that has grown more difficult to achieve in this always-connected world, made worse by the fact that so many people can’t escape an office that is now in a corner of their home.