A speak-up culture is earned. Invest time with colleagues across your healthcare organization. Develop open lines of communication for effective compliance.
Continue readingTrust in healthcare compliance programs
Four ways to build a healthy culture of compliance. Help your clinical and operational colleagues see compliance as foundational to your healthcare organization
Continue readingCompliance officer effectiveness takes a special blend of skills
Highly effective board committees know their oversight responsibilities. After a four-year investigation, Caremark pled guilty to felony mail fraud and entered into numerous settlement agreements. The primary allegation was that the board failed to make reasonable inquiries and take appropriate action to prevent certain systemic compliance failures.
Continue readingHealthcare compliance culture means doing the right thing at all levels
Healthcare compliance culture is strategic. Defining compliance culture in the context of overall healthcare priorities. Measure it.
Continue readingFour Power Skills for Influence
Compliance helps healthcare organizations mitigate risk by building strong relationships and leading through influence for effective regulatory change management
Continue reading12 key metrics for compliance officers looking to move their culture forward
Culturally impactful metrics emphasize getting healthcare compliance officers in the right rooms – ahead of regulatory change or organizational growth.
Continue readingYes, worker fatigue is a Compliance concern
How does worker fatigue affect a healthcare organization’ s level of regulatory compliance?
It turns out, employees who are not getting enough rest have a higher chance of making mistakes or performing their work at a sub-standard level. And in healthcare, this can mean increased non-compliance with facility policies and adverse effects on patient care.
Worker fatigue during a pandemic
Healthcare workers have always been at risk of fatigue, particularly with the traditionally long shifts for residents and the high stakes of patient care. The pandemic adds the unknowns of treatment, grief over lost patients, fear of catching the virus and missing family and routine. Unfortunately, this dual fatigue- at work and at home – increases the risk for errors around patient care and other highly regulated elements of healthcare.
Worker fatigue and increased mistakes
Workers who are fatigued may not have the same ability to focus on their tasks. For example, when sending a fax from the hospital to a primary care office on behalf of a patient, a nurse might type in the wrong fax number, thus sending protected health information (PHI) to the wrong person. Or worse, an employee may click on a link embedded in an email that is associated with malware and cause a breach. These are just two examples of how worker fatigue could cause compliance concerns.
Worker fatigue and decreased quality of work
Similarly, when people are fatigued or burned out, the quality of their work and judgment can decrease. For example:
- A usually conscientious employee may cut corners and not ensure a signature is obtained on a patient consent for surgery.
- A contract manager may upload a new contract but forget to obtain a required business associate agreement (BAA) form.
- A compliance audit may show that a Human Resources employee delayed scheduling flu vaccines and tuberculosis test for a group of new employees.
- A nurse may leave confidential patient information showing on a computer screen at the nurses’ station when called away to answer a nurse call light.
How Compliance can help
Helping staff stay well rested doesn’t fall just to the Compliance team, of course. But Compliance is a stakeholder and can partner with Human Resources to make sure the organization prioritizes reducing worker fatigue and supporting employees’ wellbeing.
- Compliance professionals can identify regulatory risks and help prioritize issues and develop materials for staff meetings to reinforce the need for adequate rest. Check out these CDC guides for material:
- Human Resources can create and offer support such as include peer support programs, supporting mental health paid time off, and referrals to the organization’s employee assistance (EAP) program. (An EAP is a work-based intervention program – like counseling – designed to assist employees in resolving personal problems that may adversely affect their performance.)
- Hospital administration can work with department heads to make sure shifts are scheduled in a way that allows for adequate rest.
The issue of worker fatigue is rooted in every aspect of a healthcare organization’s operation. People are passionate about their work and want to care for their team and their patients. Managers are doing their best to schedule people appropriately, but COVID has made existing staff shortages worse. A reminder from the Compliance team may help everyone in the organization take better care of themselves to ultimately deliver better care.
Keep on top of regulations affecting your organization and make sure those regulations are translated into policies and procedures that affect patient care. YouCompli customers have access to notifications about changes to regulations, resources to inform policy and procedure updates, and tools to track compliance. Contact us today to learn more.
Denise Atwood, RN, JD, CPHRM
District Medical Group (DMG), Inc., Chief Risk Officer and Denise Atwood, PLLC
Disclaimer: The opinions expressed in this article or blog are the author’s and do not represent the opinions of DMG.

Denise Atwood, RN, JD, CPHRM has over 30 years of healthcare experience in compliance, risk management, quality, and clinical areas. She is also a published author and educator on risk, compliance, medical-legal and ethics issues. She is currently the Chief Risk Officer and Associate General Counsel at a nonprofit, multispecialty provider group in Phoenix, Arizona and Vice President of the company’s self-insurance captive.

Communicating Compliance Terms in Plain English…
If you have ever been new to a particular field of the workforce, such as healthcare compliance, you know all too well that the language used by coworkers can sound foreign, like gibberish, or “alphabet soup.” As we continue to work in the field though, we too, start speaking the language. However, while that may be ok for conversing in the compliance department, it still be confusing if we are trying to communicate with, or to educate, other functional areas of the healthcare organization. Without knowing the terminology, the message we are trying to convey is unlikely to be understood when received.
Alphabet Soup
Take a look at an example of terminology just starting with the letter “A” from the Office of the Inspector General Work Plan (reference below):
- ADAP AIDS Drug Assistance Program (note this one includes an abbreviation in the definition);
- AI/AN American Indians and Alaska Natives (I, for one, was unfamiliar with this abbreviation);
- AIDS acquired immunodeficiency syndrome;
- ALF assisted living facility;
- ALJ administrative law judge;
- AMD age‐related macular degeneration (while I have heard of macular degeneration, I did not know this was a standard abbreviation);
- AMP average manufacturer price;
- ASC ambulatory surgical center;
- ASP average sales price; and
- AWP average wholesale price.
Say I am talking to another seasoned compliance professional in front of a new employee. Using the above “A” acronyms only, the conversation may sound something like this,
“Based on the billing audit, I see we are not receiving contracted AWP reimbursement under our AI/AN contract for ALF patients with AMD.”
As you can imagine, a new employee might be confused by the acronyms and terms communicated instead of using common business English. Sometimes just saying the entire word instead of the abbreviation is a good place to start, so instead of saying AWP say average wholesale price.
Repetitive Communication
In order to improve communication between seasoned compliance professionals and other members of the organization, it is important to use repetitive teaching strategies. In addition to saying the entire compliance term and the abbreviation, be repetitive and write out the compliance term in addition to the abbreviation in written communications. That way staff become more familiar with compliance terminology and it becomes a part of their daily vocabulary.
Knowledge in Practice
When it comes to any industry, including healthcare, it is easy to throw around acronyms and jargon that is familiar and efficient. However, it is important to be aware of who you are talking to, and therefore make sure they clearly understand whatever it is you are communicating. Translate and reword industry terminology in emails, policies and teaching materials where necessary in order to improve communication and understanding. Better compliance will ultimately be the result.
PRACTICE TIP:
- Regularly evaluate training and orientation materials to ensure industry specific terminology is defined and understandable.
- Utilize the youCompli system as a centralized hub for new and existing compliance processes and utilize the included model procedures throughout the various areas of your organization.
RESOURCES:
Health Care Compliance Association (HCCA) Compliance Dictionary found at https://www.hcca-info.org/publications/compliance-dictionary
Health and Human Services (HHS), Office of the Inspector General (OIG), Work Plan Appendix B: Acronyms and Abbreviations found at https://oig.hhs.gov/publications/workplan/2011/wp09-appx_b_acronyms.pdf
Denise Atwood, RN, JD, CPHRM
District Medical Group (DMG), Inc., Chief Risk Officer and Denise Atwood, PLLC
Disclaimer: The opinions expressed in this article or blog are the author’s and do not represent the opinions of DMG.

Denise Atwood, RN, JD, CPHRM has over 30 years of healthcare experience in compliance, risk management, quality, and clinical areas. She is also a published author and educator on risk, compliance, medical-legal and ethics issues. She is currently the Chief Risk Officer and Associate General Counsel at a nonprofit, multispecialty provider group in Phoenix, Arizona and Vice President of the company’s self-insurance captive.
See YouCompli in Action
Easier, faster, more effective compliance is possible
Collaboration Between Compliance and Risk: What is Permissible?
Compliance departments, generally speaking, guide staff and boards of directors to comply with the requirements, laws and regulations that govern the organization’s business. They also monitor for compliance via internal audits. Risk departments, on the other hand, address ways to mitigate risk to an organization through such activities as the evaluation and purchase of insurance policies. Given the broad nature of the scope of these two departments within the organization, when is compliance and risk collaboration permissible?
Possible collaborations
- Strategic planning: Collaboration here should include not only compliance and risk but the entire organization and the board of directors, if applicable.
- Disaster response and business continuity: As with strategic planning, disaster response and business continuity planning should also involve input and collaboration from all departments in the organization.
- General security and privacy : Here the compliance/privacy officer, information technology/security officer, and risk management director should all be included in the planning.
- Known security threat and/or breach incident: Compliance, information technology (IT), and risk management would all participate in mitigating a security threat or breach incident on the organization. Each would provide input and guidance on their respective areas of knowledge.
- Risk assessments, gap analysis and mitigation plans: Again, the development of these plans should include leaders from the entire organization; moreover, compliance and risk would specifically collaborate on the assessment, analysis and mitigation activities.
- General policy development: Compliance and risk staff can collaborate and provide feedback and input for all organization policies.
- Record and document retention schedule: Here compliance and risk can collaborate with legal counsel to ensure record and document retention policies comply with state and federal laws.
- Staff education: This is an area where compliance and risk can collaborate to provide training, whether it is done in person, virtually, by email or via online course.
Collaborations to vet and evaluate permissibility
- Security breach: As noted above, compliance, IT, and risk will work together once a security breach has been identified. It is important to ensure compliance addresses HIPAA related information and potential reporting requirements; IT evaluates the technical aspects of the breach; and risk focuses on reporting to the insurance carrier and mitigation strategies in conjunction with compliance and IT. These collaborative activities will usually take place under a breach coach or law firm to protect the confidential nature of the breach.
- Shared work areas: Depending on the confidential nature of discussions, say a lawsuit against the organization, it may or may not be appropriate for compliance staff to be privy to such information. So shared work areas should be closely evaluated.
- Shared staff: As with shared work areas, if a staff member such as a registered nurse (RN) is shared between the compliance and risk department, both leaders and the RN must remain in the scope of the job role in which they are working at the time.
- Reporting to the board: Typically, compliance reports to the organization’s leader (such as a CEO) but also has direct or dotted line reporting to the board of directors. Make sure any collaborations with other departments do not create potential conflicts of interest with reporting up this chain of command.
- Committee membership: As with the analysis discussed above, make sure to vet compliance staff member membership on the risk committee and vice versa to avoid any actual or potential conflicts of interest.
Goal
All organizations should work to develop a culture where permissible collaborations between compliance and risk occur. They should also make certain that staff feel comfortable calling the compliance or risk department with potential concerns while ensuring the staff not crossing any lines when it comes to compliance or risk department confidential matters or conflicts of interest.
PRACTICE TIP:
- Evaluate opportunities for the compliance department to collaborate with the risk management team, as noted above.
- Access youCompli to find resources which address required document and record retention requirements.
Denise Atwood, RN, JD, CPHRM
District Medical Group (DMG), Inc., Chief Risk Officer and Denise Atwood, PLLC
Disclaimer: The opinions expressed in this article or blog are the author’s and do not represent the opinions of DMG.

Denise Atwood, RN, JD, CPHRM has over 30 years of healthcare experience in compliance, risk management, quality, and clinical areas. She is also a published author and educator on risk, compliance, medical-legal and ethics issues. She is currently the Chief Risk Officer and Associate General Counsel at a nonprofit, multispecialty provider group in Phoenix, Arizona and Vice President of the company’s self-insurance captive.
Sign-up to never miss a compliance related article!
Manage your healthcare regulatory change process effectively and efficiently
YouCompli enables the compliance officers to assign ownership and oversight of tasks to different department heads, functional leaders, or specialists. The solution prompts users to accept, reject, or reassign the task by a stated deadline. Manage the rollout and accountability of new requirements with the best workflow in the business.








