Burnout, Boundaries, and Compliance
Corporate Compliance, Leadership

Building Employee Engagement

Through Meaningful Healthcare Compliance Training

Written by Misty Kelly, OHCC, HPOC with contributions from Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS and Joy Rose, MSA, RHIA, CCS, CHA, CHPS   

This article was developed through collaboration with AIHC Education Volunteer Committee compliance professionals who shared practical experiences and lessons learned related to employee engagement and compliance education.

Several years ago, our organization deployed annual compliance training through a learning management system. Completion rates were acceptable; however, employees frequently waited until the deadline to complete their assignments, and retention of key concepts remained difficult to assess. The experience reinforced an important lesson: compliance training should not simply be focused on completion. It should focus on understanding and application. 

Training can satisfy a requirement without changing behavior. A completed module or passing quiz may document participation but does not necessarily demonstrate that an employee understands the expectation, recognizes when it applies, or can incorporate it into daily decision making. 

Begin With the “Why”

Organizations use a variety of methods to deliver compliance education, including annual LMS (learning management system) assignments, in-person presentations, newsletters, microlearning modules, department meetings, and one-on-one coaching. What resonates with one workforce member may not be as effective with another. Compliance professionals should remain flexible and willing to adjust their approach based on employee needs and organizational culture.

Nancie Cummins noted, “I have found individual training has helped the most. You can go through a format that meets Compliance plan criteria and have individuals interact to answer their specific needs. This way, you can address the compliance requirements while still allowing individuals to engage directly, ask questions, and receive guidance that is specific to their role and needs.”

While individualized training may not always be practical on a large scale, the underlying principle remains important: employees are more engaged when training is relevant to their role and allows opportunities for interaction, questions, and clarification. Even when one-on-one training is not feasible, larger sessions can incorporate opportunities for questions, discussion, and role-specific examples.

One Size Does Not Fit All

The challenge for compliance professionals is determining which methods will resonate most effectively with their workforce. There is no single correct approach. What works well in one organization may not work in another, and a method that was successful last year may be less effective today. Organizational cultures evolve, workforce demographics change, and training needs shift. Compliance professionals must remain attentive to those changes and be willing to adjust the format, timing, and level of interaction. 

The concept that compliance programs are not one-size-fits-all also applies to training platforms and methods. My overall goal with this article is to provide practical information to help guide new compliance professionals and offer new perspectives to seasoned professionals. 

Compliance education should not be limited to annual training. Whether education is delivered through a formal module, an ad hoc session, targeted remediation, or a Compliance & Ethics Week activity, employees should understand why the information matters. Whenever possible, connect the training to one or more of the following: 

  • Patient care and safety
  • The employee’s individual role
  • Organizational integrity
  • Operational effectiveness
  • Reputation and trust
  • Prevention of avoidable compliance problems
  • Other organizational-specific priorities

Employees are more likely to retain and apply information when they can see its relevance to their work. 

“Employees are frequently completing a checkbox without understanding the ‘why’ behind what they are doing.” – Joy Rose. Joy Rose’s observation reflects a common challenge. Employees are more likely to engage when expectations are connected to their daily responsibilities and the organization’s broader mission. Meaningful engagement requires a clear connection between the requirement, the employee’s role, and the consequence the requirement is intended to prevent. 

Choose Methods That Encourage Participation

LMS platforms can be effective tools for delivering and tracking education. However, even the most sophisticated platform will struggle to engage employees if content is repetitive, not role or industry-specific, or lacks practical relevance.

Compliance professionals should avoid designing education solely around their own preferred learning style. A format that feels clear and engaging to the person developing the training may not connect with every employee. Varying the delivery method can improve accessibility and help sustain attention, but variety should have a purpose. The selected method should support the learning objective, the complexity of the topic, and the needs of the intended audience. 

In recent years, I have focused on redesigning annual and targeted training to connect employees with organizational policies and reinforce applicable regulatory requirements. This required more than transferring existing content into a new format. We reconsidered how information was presented, where interaction could be added, and how employees could be directed back to the policies and procedures governing their work. Working with our information technology team, we used an AI-enabled platform to develop modules incorporating videos and interactive quizzes. Employee participation improved, and the experience reinforced an important point: strong content is essential, but presentation, relevance, and interaction influence whether employees remain engaged with that content. Technology did not replace the need for compliance oversight. It gave us another way to deliver information in a more engaging format.

For brief reinforcement

  • Microlearning and short refreshers
  • Short quizzes
  • Email, newsletter, or intranet reminders
  • Workflow posts explaining the purpose behind a task

For interaction and clarification

  • Live or department-specific sessions
  • One-on-one coaching when individualized support is needed
  • Department visits and informal question and answer sessions

For practical application 

  • Real-world scenarios
  • Role-specific instruction
  • Sample documents and guided exercises
  • Targeted education following audit or inspection findings

For engagement and visibility

  • Videos and visually engaging presentations
  • Gamification
  • Modest incentives, when appropriate

The method should never overshadow the message. Select the format based on what employees need to understand or do differently after the training.

Use Real-World Scenarios Responsibly

Employees in our organization have responded positively to real-world scenarios. In a post-training survey, 32% of respondents requested additional scenario-based education. Scenarios can help employees translate policy language into practical decisions and understand how a requirement applies in daily work. 

Compliance professionals must nevertheless use internal examples carefully. Remove or alter identifying details, avoid information that could permit re-identification, and focus on the scenario purpose or decision rather than the individuals involved. Not every internal matter is appropriate for broad education. When used responsibly, de-identified incidents, near-misses, and recurring questions can become valuable learning opportunities. 

Make Creativity Serve the Learning Objective

A well-chosen theme can also help create visibility and momentum around an annual campaign. Our organization has used travel, Olympic, superhero, and scavenger-hunt themes to refresh the employee experience. When feasible, simple décor, intranet content, photographs, and internal announcements can keep the campaign visible.

A theme, however, should support the learning objective rather than compete with it. Creative presentation may attract attention, but the content must remain relevant, accurate, accessible, and connected to employees’ responsibilities.

Leadership Sets the Tone

Training is less likely to influence daily behavior if leadership treats it as an annual assignment or does not reinforce expectations afterward. Leadership involvement should include visible support, sufficient employee time, operational follow-through, and reinforcement within departments. Leadership buy-in is often one of the most significant factors in influencing the success of a compliance program. 

In a recent post-training survey conducted within our organization, 36% of respondents identified leadership encouragement as a motivating factor in completing their assigned training. 

This year, our organization took a different approach by asking senior leaders to complete the training before it was deployed across the organization. As a result, leaders were able to provide feedback on the learner experience, answer employee questions based on firsthand knowledge, and reinforce the importance of the training from an informed perspective. Employees are more likely to engage when leaders demonstrate that compliance education is a priority rather than simply another assigned task.

Reinforce Learning Throughout the Year

Annual training alone cannot carry the entire compliance education program. There must be reinforcement and other trainings throughout the year. Employees may revert to prior habits when a workflow changes, particularly if the new process is not reinforced or if employees do not understand why the change occurred. Here are suggested reinforcement methods to consider:

  • Brief department touchpoints
  • Compliance newsletters or compliance content in the company newsletter
  • Periodic reminders via email or Teams messaging
  • Short quizzes
  • Leadership talking points
  • Workflow-specific coaching
  • New-hire reinforcement
  • Targeted education following audit or inspection findings

Measuring What Matters

Completion rates remain necessary for monitoring assigned education, but they answer only one question: Did the employee complete the training? They do not establish whether the employee understood the content, retained it, or applied it correctly. A more meaningful evaluation may include:

  • Knowledge checks that require application, not simple recall
  • Post-training surveys regarding relevance, clarity, and preferred formats
  • Targeted audits or observations of the affected process
  • Trends in repeat findings, recurring questions, and reported concerns
  • Discussions with department leaders about whether expectations are being followed

Follow-up education when results identify gaps

No single measure will provide a complete answer. Compliance professionals should consider multiple indicators and allow sufficient time for the expected behavior or process change to become observable. When results do not improve, the appropriate response may not be more training. The organization may need to examine the policy, workflow, available resources, competing priorities, or leadership reinforcement. 

Meaningful compliance training is not defined by completion certificates, attendance records, or annual deadlines. Those elements document activity, but effectiveness is demonstrated through understanding, application, and behavior. 

There is no universal formula for employee engagement. Each organization must consider its workforce, culture, risks, resources, and learning objectives. The most successful approach may combine formal training, practical scenarios, leadership reinforcement, ongoing communication, and opportunities for employees to ask questions and provide feedback. 

Our responsibility as compliance professionals is not simply to deliver information. It is to help employees recognize why the information matters and how it applies to the decisions they make every day. When employees understand the purpose behind an expectation and view Compliance as a trusted resource, training becomes more than a requirement. It becomes part of how the organization protects its patients, its workforce, and its integrity. 

About the Author

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management. She serves as a volunteer on the AIHC Education Committee. This article was written in collaboration with the following AIHC Education Committee Members: Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS and Joy Rose, MSA, RHIA, CCS, CHA, CHPS

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 


Read More
HIPAA Compliance
Corporate Compliance, HIPAA

The Hidden Risk in Multi Site Healthcare

When Visibility Fails, Compliance Follows 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

This article is for reference regarding risk management in healthcare, which is a complex topic and posted for educational purposes only. It is not intended as consulting or legal advice.

Introduction

Managing multiple healthcare facilities within a single organization has evolved from an operational responsibility to a complex enterprise risk function. As organizations expand across regions, states, and service lines, the ability to maintain consistent compliance, ensure patient safety, and protect financial performance becomes increasingly difficult without structured oversight.

For compliance and risk leaders, multi-site operations present a unique challenge. The risk is not limited to regulatory requirements or operational variability. The greatest risk is the loss of visibility. When leadership cannot clearly see what is occurring across sites in real time, issues are often identified only after they have already impacted patient care, compliance status, or revenue.

Recent federal guidance and national studies reinforce that multi-site risk is driven less by geographic dispersion and more by the absence of standardized oversight, integrated data, and structured accountability.¹ To manage multi-site healthcare environments effectively, organizations must move beyond decentralized oversight and adopt systems that promote accountability, visibility, and coordinated enterprise governance. Without these elements, growth introduces fragmentation rather than scalability.

The Risk Profile of Multi Site Healthcare Organizations

Multi-site healthcare organizations operate within a heightened risk environment driven by scale, variability, and complexity. While these risks are often described broadly, they consistently concentrate on specific operational and compliance areas that require targeted oversight. A primary risk is inconsistent application of regulatory requirements. Organizations governed by entities such as the Centers for Medicare & Medicaid Services and the Health Resources and Services Administration must ensure that standards related to documentation, billing, scope of services, and program integrity are applied uniformly across all locations. Variability in interpretation or execution increases the likelihood of audit findings, repayment exposure, and regulatory scrutiny.

Operational fragmentation is another critical concern. When sites operate with varying processes, undocumented workarounds, or informal practices, organizations lose the ability to ensure consistency and control. Over time, these inconsistencies evolve into systemic risk. Data fragmentation further compounds this issue. Without integrated systems, leadership lacks a reliable, centralized source of truth. This limits the organization’s ability to identify trends, monitor performance, and detect emerging risks before they escalate. Workforce variability also contributes to risk exposure. Differences in training, leadership capability, and staffing stability across sites directly affect compliance adherence, documentation quality, and patient safety outcomes.

Recent patient safety research demonstrates that breakdowns in communication, leadership engagement, and reporting culture are directly associated with lower safety performance and reduced incident reporting across healthcare organizations.²  In multi-site environments, these risks are amplified when leadership relies on inconsistent or anecdotal reporting rather than standardized enterprise data. Finally, delayed escalation of issues remains a persistent vulnerability. Without clear reporting structures and accountability, compliance concerns, incidents, and near misses may remain localized rather than addressed at the enterprise level.

High Risk Areas and Required Compliance Controls

Effective organizations do not manage multi-site risk at a high-level. They identify specific exposure areas and implement structured controls tied directly to those risks.

Documentation, Coding, and Billing Integrity - Variability in documentation and coding practices is one of the most significant sources of compliance exposure. Even with established policies, differences in provider behavior and oversight result in inconsistent application of requirements. Common risk patterns include insufficient documentation to support medical necessity, inconsistent use of modifiers, and failure to accurately capture services rendered. Across multiple sites, these inconsistencies increase audit vulnerability and repayment risk.

Administrative complexity and reliance on inconsistent workflows further increase risk and inefficiency across organizations. To mitigate this risk, organizations should implement centralized revenue integrity oversight, supported by routine pre and post billing audits. Documentation standards must be clearly defined and reinforced through targeted education tied directly to audit findings. Coding accuracy should be monitored through both random and focused audits, particularly in high-risk service lines. Transparent reporting of audit results reinforces accountability at both the provider and site level.

Sliding Fee Scale and Program Eligibility - For federally funded organizations, sliding fee scale compliance remains a critical risk area. Inconsistent eligibility determinations, failure to conduct required reevaluations, and inadequate documentation create exposure during audits and operational site visits. Organizations should implement standardized eligibility workflows supported by system controls that prevent incomplete processing. Routine audits should validate both documentation and application of discounts. Staff responsible for eligibility should receive structured training with defined competency expectations, and monitoring should include both process adherence and outcome accuracy.

Credentialing, Licensure, and Enrollment - Maintaining accurate credentialing and enrollment across multiple sites is operationally complex and highly regulated. Risks include expired licenses, services rendered prior to enrollment approval, and misalignment between credentialing records and payer systems. National credentialing standards emphasize ongoing monitoring, sanction checks, and oversight of delegated credentialing activities, particularly in multi-state environments.³

Centralized credentialing systems with automated alerts are essential. Organizations should maintain a single, validated source of provider data that is routinely reconciled with payer enrollment records. Pre-service verification processes should confirm that providers are eligible to render services. Routine audits should ensure alignment across credentialing, privileging, and enrollment data.

Patient Safety and Incident Reporting - Inconsistent reporting of incidents and near misses across sites creates significant patient safety and compliance risk. When reporting varies by location, organizations lose the ability to identify systemic issues. Recent studies highlight that organizations with stronger reporting cultures and leadership engagement demonstrate improved safety outcomes and increased event reporting.²

Centralized incident reporting systems should be implemented across all sites, with clearly defined expectations for reporting. Leadership must reinforce a culture that supports transparency and non-punitive reporting. Data should be trended at the enterprise level, and corrective actions should be tracked to completion. Regular leadership review ensures accountability and sustained improvement.

Data Integrity and Reporting - Reliable data is essential for effective oversight. In multi-site environments, inconsistent data definitions, delayed reporting, and lack of validation undermine decision making. Organizations should establish formal data governance structures that define standards, ownership, and validation processes. Standardized dashboards should be implemented across sites to ensure consistency in reporting. Data should be routinely reconciled across systems, and key risk indicators should be monitored consistently. Research indicates that dashboards are most effective when designed to drive action rather than simply display information.⁶

Workforce Competency and Training - Variability in workforce training directly impacts compliance and operational performance. Inconsistent onboarding, lack of role specific education, and high turnover create gaps in knowledge and execution. Standardized onboarding programs with defined competencies should be implemented across all sites. Ongoing training should be required and tracked, with reinforcement tied to identified risk areas. Competency should be validated through assessments and audit results to ensure effective application.

Vendor and Third-Party Oversight - Reliance on third party vendors introduces additional compliance and operational risk. Lack of visibility into vendor practices and misalignment with regulatory requirements can create exposure. Organizations should implement formal vendor risk management programs that include due diligence, clear contractual expectations, and ongoing performance monitoring. Vendors should be evaluated against defined compliance standards and subject to periodic audits. Contracts should clearly define accountability and regulatory obligations.

Enterprise Visibility and Remote Oversight

The most significant risk in multi-site operations is not complexity but lack of visibility. In organizations where leadership is remote or geographically dispersed, reliance on informal updates creates delayed awareness of risk. Federal compliance guidance emphasizes structured oversight, including risk assessments, auditing, monitoring, and board level reporting.¹ Organizations should establish a single enterprise view of risk that includes credentialing status, billing trends, patient safety events, training compliance, and corrective action tracking. Visibility must be standardized, real time, and actionable.

Accountability as an Enterprise Expectation - Accountability must be clearly defined and embedded at every level of the organization. Each site should have designated leadership responsible for compliance, quality, and operational performance, with measurable expectations aligned to enterprise standards. Research demonstrates that leadership structure and accountability directly influence safety culture, communication, and organizational performance. ⁵ Performance management should incorporate compliance metrics alongside operational goals. Enterprise leadership must maintain oversight through routine review of site performance, clear escalation pathways, and enforcement of corrective actions.

Systems, Monitoring, and Enterprise Oversight - Systems function as the infrastructure that supports compliance and risk management across multiple sites. Centralized platforms for audit tracking, incident reporting, credentialing, and performance monitoring provide the foundation for effective oversight. Monitoring should be continuous and risk based. Routine audits, data validation, and trend analysis allow organizations to identify patterns across sites and intervene proactively. Early warning indicators should be established to trigger action before risks escalate. Effective oversight requires translating data into action through structured governance and consistent follow through.

Addressing Blind Spots Through Validation and Culture

Blind spots represent one of the most significant risks in multi-site environments. These include underreported incidents, undocumented workarounds, and gaps in training that are not captured through standard reporting. Organizations must validate reported data through independent audits, direct observation, and cross site comparison. Identifying outliers often reveals underlying risk. Equally important is fostering a culture of transparency. Staff must feel supported in reporting concerns, and leadership must respond consistently to reinforce trust in reporting mechanisms.

Supporting Organizational Growth While Managing Risk

Growth must be supported by infrastructure and oversight. Research suggests that organizations that standardize core processes before expansion achieve more sustainable outcomes. ⁷ Organizations should ensure that systems, processes, and staffing models are scalable prior to expansion. Centralized governance should remain intact while allowing for controlled local execution. Data driven decision making should guide expansion, resource allocation, and performance improvement.

Conclusion

Managing multiple healthcare facilities requires a structured and deliberate approach to risk, compliance, and operational oversight. Multi-site environments introduce significant exposure across regulatory, clinical, operational, and financial domains. Across federal guidance and recent healthcare research, a consistent theme emerges. Multi-site success is driven by standardized visibility, structured accountability, integrated compliance controls, and proactive monitoring.¹ ² ³

Organizations that succeed invest in visibility, enforce accountability, and implement integrated systems that allow leadership to monitor performance in real time. By identifying specific risk areas and implementing targeted controls, organizations can reduce compliance exposure, strengthen patient safety, and support sustainable growth. In multi-site healthcare operations, risk is not created by scale alone. It is created by the absence of structure. Visibility, accountability, and systems remain the foundation of effective governance and long-term success.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Ms. Bertholette Pardieu, MPH, CCEP, OHCC is an accomplished compliance and risk leader with over a decade of experience developing and strengthening enterprise-wide compliance, governance, and risk programs across highly regulated healthcare sectors, including FQHCs, PBMs, and Medicare/Medicaid organizations. She currently serves as the Director of Risk Management & Corporate Compliance Officer for Broward Community & Family Health Centers, Inc. (the largest Federally Qualified Health Center in Broward County), overseeing risk, compliance and governance for a $16.4M multi-site FQHC system serving more than 13,000 patients. Previously, she led enterprise compliance risk initiatives at Convey Health Solutions, where she built the company’s first compliance risk program, directed effectiveness audits, and enhanced vendor oversight for national health plans.

A trusted advisor to executives and boards, Ms. Pardieu is known for her strategic mindset, collaborative leadership, and ability to embed compliance into organizational culture to protect against regulatory and operational risk. She holds a Master of Public Health from Florida International University and a Bachelor of Science from Barry University. Ms. Pardieu is a Certified Healthcare Compliance Officer (OHCC), with additional credentials including certifications in Corporate Compliance & Ethics and Healthcare Risk Management; and is a recent graduate of the Women’s Executive Leadership Accelerator Program through the Inclusion Learning Lab.

References

1. U.S. Department of Health and Human Services, Office of Inspector General
    General Compliance Program Guidance (2023)
    * Direct PDF (Full Guidance):
      
https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf
    * Official OIG Overview Page:
      
https://oig.hhs.gov/compliance/general-compliance-program-guidance/
2. Agency for Healthcare Research and Quality (AHRQ)
    Patient Safety Culture and Workforce Safety
    * 
https://psnet.ahrq.gov/perspective/ensuring-patient-and-workforce-safety-culture-healthcare
3. National Committee for Quality Assurance (NCQA)
    Credentialing Standards
    * 
https://www.ncqa.org/programs/health-plans/credentialing/benefits-support/standards/
4. Council for Affordable Quality Healthcare (CAQH)
    2023 CAQH Index Report
    * 
https://www.caqh.org/hubfs/43908627/drupal/2024-01/2023_CAQH_Index_Report.pdf
5. National Library of Medicine (PubMed)
    Leadership and Patient Safety Culture Systematic Review
    * 
https://pubmed.ncbi.nlm.nih.gov/41507881/
6. Journal of the American Medical Informatics Association (JAMIA Open)
    Healthcare Dashboard Effectiveness Study
    * 
https://academic.oup.com/jamiaopen/article/8/4/ooaf078/8214040
7. National Institutes of Health (PubMed Central)
    Healthcare Leadership Complexity and System Growth
    * 
https://pmc.ncbi.nlm.nih.gov/articles/PMC11223336/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Burnout, Boundaries, and Compliance
Leadership

Beyond Burnout

Workforce Ethics as Enterprise Risk and the Compliance Cost of Moral Injury 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

Introduction 

Workforce ethics, moral injury, and sustainability have emerged as critical compliance, governance, and patient safety concerns across the healthcare industry. Persistent staffing shortages, increased demand for services, and constrained resources have shifted workforce wellbeing from a human resources issue to an enterprise risk with direct implications for regulatory compliance, quality of care, and organizational stability.

For healthcare compliance and ethics leaders, understanding the relationship between workforce ethics and system performance is essential. Ethical strain within the workforce undermines reporting mechanisms, weakens compliance controls, and increases the likelihood of patient safety events. Addressing these challenges requires structured, organization-wide strategies that are deliberately integrated into governance, ethics, and risk management frameworks rather than addressed through isolated or informal efforts.

The Ongoing Workforce Crisis in Healthcare

Healthcare professionals across clinical and administrative roles continue to face escalating pressures. Chronic staffing shortages, burnout, high turnover, and increasing productivity expectations have become widespread across healthcare settings. These pressures are often accompanied by ethical conflicts that arise when professionals are unable to provide the level of care they believe patients require due to systemic constraints such as limited staffing, time pressures, or resource scarcity.

When healthcare workers repeatedly encounter situations where organizational limitations conflict with professional values, moral distress develops. If unaddressed, moral distress can progress into moral injury, which manifests as emotional exhaustion, disengagement, loss of trust in leadership, and withdrawal from organizational values. These outcomes directly affect workforce stability and compromise compliance processes, quality oversight, and patient safety initiatives.

Why Workforce Ethics Matters to Compliance and Risk

From a compliance and risk management perspective, workforce instability creates cascading organizational risk. Burnout and disengagement increase the likelihood of patient safety events, documentation errors, incomplete reporting, and breakdowns in adherence to policies and procedures. A workforce under sustained ethical strain is also less likely to participate meaningfully in compliance training, reporting mechanisms, and quality improvement activities.

Regulators and accrediting bodies increasingly assess organizational culture, leadership responsiveness, and staff engagement as part of broader evaluations of compliance effectiveness. As a result, compliance programs that fail to account for workforce ethics risk overlooking a key driver of regulatory exposure and patient harm.

To address this risk, compliance leaders should formally incorporate workforce ethics and moral injury into compliance risk assessments. Indicators such as turnover trends, vacancy duration, overtime utilization, safety event patterns, and ethics reporting activity provide valuable insight into ethical strain and emerging compliance vulnerabilities. Presenting these risks to executive leadership and boards alongside traditional compliance risks reinforces accountability and ensures appropriate mitigation strategies are implemented.

Workforce Sustainability as an Enterprise Risk

Workforce sustainability reflects an organization’s ability to maintain a stable, engaged, and ethically supported workforce over time. It extends beyond recruitment and retention efforts and encompasses leadership accountability, governance oversight, and organizational culture. Persistent workforce instability leads to diminished productivity, loss of institutional knowledge, increased reliance on temporary staffing, and escalating recruitment and onboarding costs. These challenges create financial strain and operational disruption, reinforcing the need to integrate workforce sustainability into enterprise risk management and governance structures.

Treating workforce ethics as an enterprise risk enables organizations to assign risk ownership, monitor trends over time, and implement corrective actions before issues escalate into regulatory or patient safety events.

Ethical Obligations and Moral Injury in Healthcare Compliance

Healthcare compliance programs are grounded in ethical principles that emphasize integrity, accountability, transparency, and patient-centered care. Moral injury represents a significant ethical risk because it undermines the ability of healthcare professionals to uphold these principles consistently. Compliance and ethics leaders have an obligation to recognize moral injury as an organizational issue rather than an individual failing. Ethical standards and regulatory expectations require healthcare organizations to foster environments where ethical concerns can be raised without fear of retaliation and where leadership responds meaningfully to those concerns. When ethical distress is ignored or minimized, trust in reporting mechanisms erodes, weakening compliance effectiveness and increasing organizational risk.

To strengthen ethical oversight, compliance leaders should establish clear ethics escalation pathways that are distinct from human resources or disciplinary processes. Providing staff with trusted avenues to raise ethical concerns outside of traditional human resources channels reinforces psychological safety and supports early identification of systemic issues that may impact compliance and patient care.

Ethical Support Structures That Strengthen Compliance

Healthcare organizations are increasingly implementing structured mechanisms to address workforce ethics and moral injury. When designed intentionally, these supports function as preventive and detective controls within compliance and quality frameworks. Moral distress rounds provide facilitated opportunities for staff to discuss ethically challenging situations in psychologically safe settings. When formalized through policy, documented appropriately, and reviewed at an aggregate level, these sessions help identify systemic challenges, promote consistent and ethical decision making, and inform leadership responses aligned with organizational values and regulatory expectations.

Ethics consultation services support staff and leadership in navigating complex ethical dilemmas related to patient care, resource allocation, or conflicting obligations. These services promote thoughtful decision making, consistent documentation, and alignment with ethical and regulatory standards. Wellbeing and resilience initiatives also contribute to workforce sustainability when they are integrated with ethics, compliance, and quality efforts. Effective programs address structural drivers of distress such as workload, staffing models, and leadership support rather than placing responsibility solely on individual coping strategies.

The Role of Compliance and Ethics Leadership

Compliance and ethics leaders play a critical role in elevating workforce ethics and moral injury from individual experiences to enterprise risk indicators. This includes integrating workforce ethics into compliance risk assessments, monitoring trends related to turnover, reporting activity, and safety events, and embedding ethical workforce considerations into auditing and monitoring activities. By doing so, compliance programs can identify early warning signs of ethical strain before they result in patient harm or regulatory exposure.

Leadership accountability is essential to sustaining ethical workforce support. Compliance leaders should partner closely with human resources, clinical leadership, quality, and safety teams to ensure workforce ethics risks are addressed through coordinated and sustainable interventions rather than isolated initiatives. This collaboration supports alignment between operational realities and ethical expectations.

In addition, compliance and ethics leaders should ensure workforce ethics risks are elevated through formal governance channels. Regular reporting to executive leadership and boards should include workforce-related risk trends, mitigation efforts, and outcomes. Providing leadership with clear, actionable data reinforces accountability and supports informed decision making. By reinforcing non-retaliation protections, promoting psychological safety, and modeling transparency, compliance leaders help sustain trust in reporting mechanisms and ensure workforce ethics remains an organizational priority.

Ethical Workforce Wellbeing and Safer Patient Care

Ethical workforce wellbeing is a critical driver of patient safety and compliance effectiveness. When healthcare professionals feel supported in navigating ethical challenges, they are more likely to report concerns, document accurately, and adhere to policies. Sustained ethical strain increases the risk of errors, underreporting, disengagement, and regulatory exposure.

Compliance leaders should treat ethical workforce wellbeing as an enterprise risk rather than an individual resilience issue.

Integrating workforce ethics indicators into compliance and patient safety monitoring allows organizations to identify systemic drivers of risk. Trusted reporting mechanisms, leadership accountability, and alignment of wellbeing initiatives with compliance and patient safety objectives ensure ethical workforce wellbeing functions as a protective control that supports safer patient care and long-term organizational sustainability.

Conclusion

Workforce ethics, moral injury, and sustainability represent one of the most significant risk areas facing healthcare organizations today. Staffing shortages, burnout, and ethical conflict threaten compliance effectiveness, patient safety, and financial performance. By integrating workforce ethics into compliance risk assessments, governance structures, and ethical support mechanisms, healthcare organizations can proactively address moral injury, support their workforce, protect patients, and strengthen long-term organizational resilience.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Bertholette Pardieu, MPH, CCEP, OHCC is the Director of Risk Management and Corporate Compliance Officer at Broward Community and Family Health Centers, Inc., the largest Federally Qualified Health Center in Broward County. She has over a decade of experience leading enterprise-wide healthcare compliance, risk management, privacy, and governance programs across highly regulated environments, including FQHCs and Medicare and Medicaid systems. Her work focuses on integrating ethics, workforce sustainability, and patient safety into compliance and enterprise risk management frameworks. She regularly advises executive leadership and boards on regulatory strategy, organizational risk, and ethical governance. Bertholette earned her Office of Healthcare Compliance, Certified (OHCC) through the American Institute of Healthcare Compliance, a licensing/certification partner w/CMS.

References

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Nurse Staffing as National Performance Goal 12

Executive Oversight, Patient Safety, and Compliance Risk in 2026

Written by: Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE 

Abstract 

Effective January 1, 2026, the Joint Commission elevated nurse staffing to National Performance Goal (NPG) 12, establishing staffing adequacy as a measurable accreditation and patient safety requirement. This article provides an executive- and auditor-facing analysis of NPG 12, examining regulatory intent, alignment with CMS Conditions of Participation, leadership accountability, and compliance risk. Practical guidance is offered to assist governing boards, executive leaders, and compliance professionals in operationalizing staffing oversight within enterprise risk, quality, and accreditation frameworks.

Introduction

Healthcare organizations entering 2026 face intensified scrutiny related to workforce adequacy, patient safety, and leadership accountability. Persistent staffing shortages, clinician burnout, and adverse patient outcomes have driven regulators and accrediting bodies to elevate staffing oversight as a core compliance priority. The Joint Commission’s designation of nurse staffing as National Performance Goal 12 represents a formal shift from treating staffing as an operational concern to recognizing it as a governance and accreditation imperative.

This shift requires healthcare leaders to reevaluate staffing policies, oversight structures, and performance measurement methodologies to ensure alignment with accreditation standards and federal regulatory expectations.

Regulatory Evolution and Rationale for NPG 12

Historically, nurse staffing requirements were embedded across leadership, human resources, and patient care standards and often evaluated indirectly through quality outcomes or adverse event investigations. However, evidence consistently demonstrates a direct relationship between inadequate nurse staffing and increased mortality, preventable harm, staff turnover, and regulatory findings.

By establishing staffing as NPG 12, the Joint Commission underscores the necessity of proactive oversight, data-driven decision-making, and executive accountability in maintaining safe staffing levels.

Scope and Applicability of NPG 12

NPG 12 applies broadly across hospital settings and clinical departments. Requirements extend beyond bedside nursing to include interdisciplinary clinical support essential to patient care. Key expectations include 24/7 registered nurse coverage, designated nurse executive oversight, and staffing models responsive to patient acuity, complexity, and care demands.

Organizations must demonstrate that staffing decisions are grounded in clinical need rather than solely financial or administrative considerations.

Executive and Governing Body Accountability

A defining feature of NPG 12 is its explicit emphasis on leadership oversight. Executive leaders and governing boards are expected to actively monitor staffing metrics, understand staffing-related risks, and ensure appropriate resource allocation. Surveyors may evaluate whether leadership receives regular staffing reports, responds to trends, and integrates staffing considerations into strategic planning.

Failure to demonstrate leadership engagement may result in accreditation findings related to leadership and governance standards, even in the absence of sentinel events.

Ethical and Professional Practice Implications

Beyond regulatory compliance, NPG 12 reinforces ethical obligations embedded in nursing professional standards and organizational duty of care. Chronic understaffing places nurses in ethically untenable positions, increasing moral distress and undermining professional judgment. Accrediting bodies increasingly assess whether organizations acknowledge and mitigate moral injury and burnout as patient safety risks.

Labor, Workforce, and Employment Law Intersections

NPG 12 intersects with labor law, whistleblower protections, and occupational safety standards. Inadequate staffing has been cited in retaliation claims, union grievances, and OSHA-related complaints alleging unsafe working conditions. Documentation demonstrating proactive staffing oversight may mitigate regulatory and legal exposure.

Alignment with CMS Conditions of Participation

NPG 12 closely aligns with CMS Conditions of Participation related to nursing services, patient rights, and quality assessment and performance improvement. Deficiencies may result in immediate jeopardy findings, amplifying compliance risk when accreditation and CMS enforcement converge.

Data-Driven Staffing Models and Performance Metrics

Compliance with NPG 12 requires data-driven staffing methodologies beyond static ratios. Surveyors may assess acuity-based tools, staffing variance analysis, and correlations between staffing levels and quality indicators. Organizations must demonstrate how staffing data informs corrective actions and continuous improvement.

Compliance with NPG 12 requires data-driven staffing methodologies beyond static nurse-to-patient ratios. Consistent with NPG.12.06.01 EPs 1–4, surveyors assess whether staffing adequacy is evaluated when undesirable patterns, trends, or variations in quality or safety are identified and whether findings are escalated through performance improvement and governance structures.

Real-world, setting-specific examples

Critical Access and Rural Hospitals:

A rural critical access hospital identified repeated patient flow delays and increased transfer times during seasonal surges. Although staffing numbers met minimum coverage requirements, leadership incorporated staffing effectiveness indicators into QAPI reviews, revealing gaps in skill mix during high-acuity presentations.

Corrective actions included cross-training nursing staff and implementing an escalation protocol requiring nurse executive review when acuity thresholds were exceeded. Findings and actions were documented and reported to governance, consistent with NPG.12.06.01 EP 3–4.

Psychiatric and Behavioral Health Settings:

In an inpatient psychiatric unit, analysis of restraint and seclusion events revealed correlations with staffing shortages during overnight shifts. Leadership included staffing adequacy in the root cause analysis, adjusted staffing models to ensure appropriate competency and coverage, and monitored outcomes through ongoing performance improvement activities. Annual staffing analysis results were provided to the patient safety program and governing body, aligning with NPG.12.06.01 EP 1–2.

Emergency and Mixed-Acuity Rural Facilities:

A rural emergency department experiencing increased left-without-being-seen rates evaluated staffing data alongside throughput and acuity metrics. Leadership implemented targeted staffing adjustments during peak hours and tracked improvements through QAPI dashboards. Staffing analyses and corrective actions were formally reviewed by executive leadership and incorporated into governance reports, demonstrating compliance with NPG.12.06.01 EP requirements.

These examples illustrate that staffing data must be actively analyzed, escalated, and integrated into performance improvement activities. Surveyors may evaluate whether leaders can articulate how staffing analyses influence corrective actions and how results are communicated to the hospital wide patient safety program and governing body.

Documentation, Evidence, and Surveyor Expectations

Surveyors may request evidence of leadership review, board discussion, action plans, and integration of staffing metrics into QAPI activities. Absence of such documentation may result in findings even when staffing ratios appear acceptable.

Compliance, Legal, and Operational Risk

Inadequate staffing presents compounded risk across accreditation, regulatory, legal, and operational domains. NPG 12 codifies staffing adequacy as an enterprise compliance risk requiring sustained mitigation strategies.

Survey Readiness and Best Practices

Survey readiness under NPG 12 requires staffing-focused mock surveys, compliance dashboards, and leadership preparedness to articulate how staffing decisions support patient safety and quality outcomes.

Conclusion

The elevation of nurse staffing to National Performance Goal 12 reflects a deliberate regulatory shift toward recognizing workforce adequacy as a foundational patient safety requirement rather than an operational afterthought. By formally linking staffing oversight to accreditation, performance improvement, and governance accountability, the Joint Commission has clarified expectations that safe staffing is inseparable from leadership responsibility and organizational culture.

Healthcare organizations entering 2026 must demonstrate that staffing adequacy is actively monitored, analyzed, and escalated through established quality and compliance structures. Static staffing policies and retrospective justification are no longer sufficient. Instead, leaders are expected to use data-driven methodologies, integrate staffing considerations into QAPI activities, and ensure governing bodies receive meaningful, actionable information related to staffing risk and performance.

Organizations that proactively embed staffing oversight into enterprise risk management, accreditation readiness, and strategic planning will be best positioned to mitigate regulatory exposure, support workforce sustainability, and achieve measurable improvements in patient safety outcomes. In this evolving regulatory environment, effective nurse staffing oversight is not only a compliance obligation—it is a defining indicator of organizational resilience, leadership effectiveness, and commitment to high-quality care in 2026 and beyond.

Appendix A: NPG 12 Compliance Crosswalk (Effective January 2026)

The following table maps National Performance Goal 12 Elements of Performance to corresponding sections of this article using Joint Commission survey-oriented language to support accreditation readiness.

NPG / EP

Joint Commission Expectation

Article Section(s)

Survey-Ready Language

NPG 12.01.01

Leadership ensures adequate number and mix of qualified staff based on patient needs.

Leadership ensures adequate number and mix of qualified staff based on patient needs.

Staffing decisions are based on patient acuity, complexity, and clinical demand rather than solely financial considerations.

NPG 12.02.01 EP 1–2

Nurse executive directs staffing plans and participates in governance decision-making.

Nurse executive directs staffing plans and participates in governance decision-making.

The nurse executive maintains authority and accountability for nursing staffing models in collaboration with senior leadership.

NPG 12.02.01 EP 4–5

Registered nursing oversight is available 24/7.

Registered nursing oversight is available 24/7.

Registered nursing services are available 24 hours per day, seven days per week, consistent with deemed-status requirements.

NPG 12.04.01

Staff practice within scope of licensure and competency requirements.

Staff practice within scope of licensure and competency requirements.

Staffing adequacy includes verification of licensure, scope of practice, supervision, and competency.

NPG 12.05.01

Staff receive education, training, and competency evaluation

Ethical and Professional Practice Implications

Workforce education and competency are treated as patient safety safeguards.

NPG 12.06.01 EP 1–4

Staffing is evaluated during QAPI and reported to leadership and governance.

Data-Driven Staffing Models; Documentation and Surveyor Expectations

Staffing adequacy is incorporated into performance improvement analyses and reported to executive leadership and governing bodies.


About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • American Institute of Healthcare Compliance. (2026). January 2026 compliance newsletter.
  • The Joint Commission. (2025). National performance goals effective January 1, 2026: Hospital program.
  • Centers for Medicare & Medicaid Services. (2025). Medicare conditions of participation.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Burnout, Boundaries, and Compliance
Leadership

Burnout, Boundaries, and Compliance

Why Staff Wellness Is a Risk Management Issue 

Written By Dr. Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

This article, grounded in findings from the recent AIHC webinar presentation 'Burnout, Boundaries, and Compliance: Why Staff Wellness Is a Risk Management Issue,' explores how staff wellness programs can be embedded into organizational quality plans and compliance frameworks to proactively address workforce fatigue and prevent downstream risks.

In today’s healthcare environment, the intersection of staff wellness, regulatory compliance, and organizational quality has become impossible to ignore. As staff burnout reaches unprecedented levels, it is increasingly clear that wellness is not just a human resources concern, but a compliance and risk management imperative.

Understanding the Compliance Implications of Burnout

Burnout, defined by the World Health Organization as a syndrome resulting from chronic workplace stress that has not been successfully managed, presents real compliance risks. These risks include errors in clinical documentation, lapses in ethical judgment, and regulatory breaches. Healthcare organizations must recognize that failing to address burnout contributes to higher turnover, lower morale, increased patient safety incidents, and diminished organizational performance. These outcomes directly impact quality metrics and compliance reporting.

Embedding Staff Wellness into Quality Initiatives

A critical finding from Dr. Atkins presentation coupled with additional research identified the value of early detection—integrating wellness strategies at the onset of program design. Staff wellness plans must be embedded as part of quality improvement frameworks, not as optional extras. Organizations that build wellness into policy, practice, and compliance audits are more likely to see measurable improvements in documentation accuracy, patient satisfaction, and employee retention. Proactive wellness programs signal to staff that their well-being is prioritized and monitored, just like infection control or safety metrics.

Early Detection Is Essential

Early detection refers to the strategic implementation of burnout prevention strategies during the formative stages of a healthcare program or system process. Rather than responding to burnout reactively, early detection builds organizational resilience by identifying risk factors—such as understaffing, inadequate training, or high patient acuity—before they lead to harm. Embedding wellness at this early stage empowers staff and creates a feedback loop where staff input shapes policies, reducing the burden of moral distress and compassion fatigue.

Building a Compliance Culture That Prioritizes Wellness

Healthcare compliance leaders are in a unique position to advocate for systemic change. A culture of compliance that integrates wellness must address:

  1. clear policies on mental health support,
  2. confidential self-reporting pathways for burnout,
  3. regular staff wellness assessments, and
  4. accountability structures that enforce reasonable workloads and boundaries.

Wellness champions and wellness subcommittees can play a pivotal role in fostering peer support and resilience among teams.

Practical Steps for Implementation

To effectively embed wellness into compliance strategy, healthcare organizations should:

  • Incorporate staff wellness indicators into internal audits
  • Require burnout screening as part of risk assessments
  • Develop cross-functional wellness committees
  • Use anonymous staff feedback to refine wellness interventions
  • Align wellness initiatives with accreditation and CMS quality metrics

Conclusion

Burnout is a multifaceted risk that affects every level of a healthcare organization. By embedding wellness into compliance and quality frameworks from the start, organizations can create safer, more effective systems of care. Early detection, policy integration, and leadership advocacy are essential for ensuring that wellness is viewed not just as a benefit, but as a compliance requirement. The time for healthcare systems to act is now—staff wellness must be recognized as a foundational element of quality and risk management strategy.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Agency for Healthcare Research and Quality. (2022). Patient Safety Primer: Burnout and Resilience. Retrieved from https://psnet.ahrq.gov
  • National Academy of Medicine. (2019). Taking Action Against Clinician Burnout: A Systems Approach to Professional Well-Being. The National Academies Press.
  • Shanafelt, T. D., & Noseworthy, J. H. (2017). Executive leadership and physician well-being: Nine organizational strategies to promote engagement and reduce burnout. Mayo Clinic Proceedings, 92(1), 129-146.
  • World Health Organization. (2019). Burn-out an “occupational phenomenon”: International Classification of Diseases. Retrieved from https://www.who.int

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 3

Part 3: When Unscrupulous Managers Turn Auditors Against Their Coworkers or Teams   

Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

  

We Recommend Reading Part 1:  When Audit Managers Knowingly Skew Audit Results and Part 2: When Criminal Behavior Infiltrates Your Audit Program. This final article in the Fraud Indicators & Red Flags series addresses potential outcomes when lead audit managers sabotage the audit process due to being insecure or due to the need to secure power in their position.

Introduction

In the first two articles over mid-level fraud indicators, we covered signs and solutions to the problem individuals. In this article we cover signs and methods to address auditors who have been “turned” into internal threats or “moles”; informing on their coworkers and/or teammates.

When unscrupulous managers or audit leads act alone or in a conspiracy to maintain their position, they will employ many short-term tactics. Because they have to constantly defend their activities, they will not think in terms of strategies except in some form of escape plan (covered in part 2). Managers or lead auditors who target subordinates to become informants stands alone, both in severity and damage to good employees and ultimately the organization: mid-level leaders targeting individual subordinates they have found to be malleable, weak, or easily intimidated/worn down. This is especially damaging to teams as cohesiveness and trust are critical to their work.

How Employees Are Turned

Retaliation

According to the U.S. Equal Employment Opportunity Commission (EEOC), “The most frequently alleged bases of discrimination were retaliation (39.2%), sex (35%), disability (34.3%), and race (16.8%). At the end of FY 2023, the EEOC had 227 merits cases on its active district court docket, of which 95 (41.8%) were class or systemic cases. Mar 27, 2024”. In the realm of equal opportunity, we tend to think of discrimination in its most well-known forms: employment discrimination because of your race, color, religion, sex (including pregnancy, transgender status, and sexual orientation), national origin, disability, age (age 40 or older), or genetic information. However, many cases have been litigated where an employee was retaliated against by a superior for voicing concerns, ethical complaints and maltreatment because of their job functions. To "discriminate" against someone means to treat that individual differently, or less favorably, for some reason.

While close timing between the allegation of retaliation and the manger's action can display retaliatory motive, there have been cases in which years have passed and other evidence established that the employee's prior activities set off the manager's action. Even minus close proximity timing, other relevant facts may include verbal or written statements; comparative evidence that a similarly situated employee was treated differently; falsity of the employer's ostensible reason for the adverse action or uncovered plausible deniability; or any other evidence from which an inference of retaliatory intent could be assessed. From the EEOC’s perspective, retaliation can take numerous forms: reprimand the employee or give a performance evaluation that is lower than it should be; engage in verbal or physical abuse; increase scrutiny; make the person's work more difficult; to name a few.

Managers find ways to retaliate against subordinates for bringing forward worries about fraud or questionable conduct. Rather than listening to the employee, who is normally an expert, many employers instead resort to various forms of blaming the messenger, and good employees are often fired, moved, or blackballed/driven from the healthcare arena for their willingness to speak up.

As in the parts 1 and 2, information is limited how mid-level administrators target individuals: but there are a number of recurring behaviors and types of bad actors who seek to isolate and “turn” auditors against their coworkers and teams.

Decentralization and Isolation

These arise from the same flaw(s) in any system but are used differently by the fraudster in a leadership capacity. The managers in question exploit the trust and lack of supervision of their activities: what controls may exist can be overridden (technology) or deflected (manipulating reports, meeting statements, etc.). Information asymmetry is used to manipulate technological data and remove negative information from reports, information the auditor will never see. If or when inquiries arise plausible deniability is used and the lack of oversight fully exploited.

There are two environments managers or audit leads use to isolate subordinates they wish to control: the office setting and the remote workforce.

In the office, if an auditor voices concerns or acts in a manner the manager sees as threatening or the manager has found to be easily influenced the manager may move the auditor away from coworkers or teammates or vice versa; move the team to other offices. The auditor now has no one they trust or can communicate with easily, directly and, critically, confidentially. Movements are harshly scrutinized and timeframes are strictly set to further control movement and communications. This isolation can be further abused by either the manager promising to put the team back together if the auditor “behaves”: or, the auditor is now so isolated maltreatment can be carried out at the manager’s will and the auditor turned to report what the manager wishes to hear when the audit team meets and works. Either way the team has been effectively infiltrated.

In the remote environment the manager already exploits information asymmetry but now, since the audit team cannot see each other at any point (in my experience Zoom and visual-virtual meetings do not fill the void of direct interaction), pressure can be put on individuals in turn and cracks either caused or taken advantage of. When conspiring managers work together and keep unrelenting pressure through implied or real threats (as viewed by the targeted auditor) and they force the auditors to only communicate with them individuals can feel lost and without options.

Bullying and Disrespectful Behavior:

Unfortunately, these behaviors have no direct legal protection: unscrupulous managers know this. They use both a combination of Game Theory and perverse incentives against individuals and together bullying and disrespectful behavior can wear an auditor down making them more malleable to turn against their team. Because of scarcity of information and similarities in definitions, bullying in this article is synonymous with disrespectful behavior, as they are virtually identical in practice.

An August 11, 2020 article in Forbes magazine titled The Differences Between Workplace Bullying And A “Hostile Work Environment” put the problem of protection against bullying as follows: “What then separates, on the one hand, a workplace that is miserable due to a boss who is a jerk to the entire staff and, on the other hand, a Title VII hostile work environment claim? The key is that the abusive conduct must be related to the employee’s race, sex, religion, etc. (otherwise known as a protected characteristic) in order for the mistreatment to be unlawful under Title VII and related laws. For example, if a manager has everyone walking on eggshells because they yell constantly and set unattainable goals/deadlines—but this abuse is directed to all employees—then this is not illegal under Title VII. If, however, the supervisor treated only female employees this way, then these women could pursue a hostile work environment claim if the inequity is based on their sex.”

For disrespectful behavior I direct the reader to a 2017 article published by The National Institute of Health: Disrespectful Behavior in Health Care-Its Impact, Why It Arises and Persists, And How to Address It—Part 2 by Matthew Grissinger: “Health care organizations have fed the problem of disrespectful behavior for years by ignoring it, thereby tacitly accepting such behaviors.  The health care culture has permitted a certain degree of disrespect while considering this a normal style of communication. Studies have shown that disrespectful behaviors are tolerated most often in unfavorable work environments, but it is unclear whether poor working conditions create an environment where the behaviors are tolerated or if the dis respectful behaviors create the unfavorable environment.

Organizations have largely failed to address disrespectful behavior for a variety of reasons. First, the behavior typically occurs daily but often goes unreported due to fear of retaliation and the stigma associated with “whistle blowing.” Disrespectful behaviors are difficult to measure, so without robust systems of environmental scanning to uncover the behavior, concerned leaders may be ignorant of the problem.  Leaders may also be unaware of the behavior if managers shield them from this information because they view it as a personal failure. If disrespectful behaviors are known, leaders may be reluctant to confront individuals if they are powerful or high-revenue producers, or they may not know how to handle the problem. It’s not a topic taught in training programs, so leaders may hesitate to take on a problem for which there is no obvious solution.”

The Workplace Bullying Institute (WBI), established in 1997 tackles the issues of prevention and protection against bullying. Since their institute began they have been “advocates for anti-workplace bullying legislation in the U.S. having introduced the Healthy Workplace Bill in California in 2003 and 31 other states and two territories since, WBI, in collaboration with David C. Yamada, Professor of Law, Suffolk University Law School, Boston, now brings forward an alternative model bill the Workplace Bullying Accountability Act (WBAA).”

The WBI has the most widely adopted definition of workplace bullying: “Workplace bullying is defined as an “abusive work environment” characterized by: repeated verbal abuse; conduct that is threatening, intimidating or humiliating; defamation of one’s reputation; work sabotage, undermining performance; and/or orchestrated ostracism.”

The WBI identifies multiple types of bullies:

  • The Constant Critic: “This one draws its targets behind closed doors. There they can threaten and intimidate without witnesses. Most shocking is that they target the most competent, veteran, go-to worker and claim that that target is incompetent. The stunning big lie freezes the target. If they are ever reported, they deny what they said and did. To HR, it becomes a she said/she said unsolvable problem. Their favorite tactic is to manufacture a false performance appraisal.”

We immediately see use of plausible deniability. If the manager is investigated they have a story ready-made, which can neither be proven nor disproven. No matter who gets involved the manager can always fall on “That’s not what I meant”; and so on. Because so much work is done remotely today this bully can plan and plot, and “test the waters” to find who the best targets are.

This bully will also take full advantage of information asymmetry. They make themselves, or them and a conspirator, the sole reporting avenues for all work, reports and performance evaluations. With decentralization and lack of robust controls documents will be manipulated, changed or deleted and the target sees no options. The bully may also have the ability to remove or corrupt auditor files. They cover two bases by verbally ordering the team to never report concerns or problems to each other or their supervisor: they strangle open communications. Their second layer of concealment is that the team will recognize the statement as an order and any attempt to circumvent or jump over them will result in accusations of insubordination. Since the manager controls upward information flow they can report what they choose, in what manner they choose. This creates and sustains an adversarial relationship between the manager(s) and the team and initiates the isolation stage of their scheme.

  • The Two-Headed Snake: “One moment your lunch buddy and a hugger. Right after, they stab you in the back. They are intent on controlling your reputation. To destroy it, they either start, or fail stop, rumors about you. This critter is very difficult to catch unless someone tells you what the snake has said about you.” This type includes the manager who either is friendly/polite, or says nothing: then months later you get a call from a superior informing you they were approached by the manager and a complaint lodged.

The two-headed snake also heavily exploits plausible deniability. This bully will do two things simultaneously: negatively/falsely report the auditor’s performance to their superior(s) and to the executives and omit reports and concerns voiced by the auditor completely: and be professional to the superiors they report to but harsh and untruthful to the auditor.

  • The Gatekeeper: “The Constant Critic and Two-Headed Snake do things to people. They commit acts of omission. Gatekeepers bully by withholding resources you need to succeed. Their dirty tricks are acts of omission. What do you need? Time to do the job? It’s denied by an impossible deadline. Information? You are blocked from using computers and search services. Furthermore, your colleagues have been ordered to not help you with anything. New job and you need training. No training for you. No budget. Though the department party is paid for. Need light duty coming back from surgery as the doctor ordered? No way. Management knows best and if you don’t return immediately to full duty, you will be fired.”

The auditor victimized by this type of bully actually may have immediate options to “return fire”. In parts 1 and 2 we covered fraud red flags and indicators of managers: and behaviors recognized by both the DoD IG and The State of New York Comptroller were withholding information. If the auditor feels there is no other starting point this can be immediately reported and investigated.

The WBI also has a position statement which encompasses, to a large extent, traits discussed in parts 1 and 2: “We believe a majority of bullies adopt the tactics of bluster and bravado as a cover, a mask, for some underlying deficiency. In other words, bullying is a compensatory set of behaviors meant to overcome something lacking — technical competence, empathy, or even fraud and theft.” This statement highlights another recognized red flag: Indications that key personnel are not competent in the performance of their assigned responsibilities.

If you as an auditor feel bullied, you are not alone. In an online survey conducted by the WBI some concerning numbers appeared:

  • falsely accused someone of “errors” not actually made (71%)
  • stared, glared, was nonverbally intimidating and was clearly showing hostility (68%)
  • discounted the person’s thoughts or feelings (“oh, that’s silly”) in meetings (64%)
  • used the “silent treatment” to “ice out” & separate from others (64%)
  • exhibited presumably uncontrollable mood swings in front of the group (61%)
  • made up own rules on the fly that even she/he did not follow (61%)
  • disregarded satisfactory or exemplary quality of completed work despite evidence (58%)
  • harshly and constantly criticized having a different ‘standard’ for the Target (57%)
  • started, or failed to stop, destructive rumors or gossip about the person (56%)
  • encouraged people to turn against the person being tormented (55%)

The last bullet point is exceptionally worrisome in the context of this article.

Being Selectively Unreachable:

When auditors are in the middle of their work, they often need rapid response from leadership to assist in problems, questions or the usual suspect, the “speed bump”. Especially in the remote environment managers will use these two ways: first they will be unreachable-period. And they will force the auditor to only approach them. Or they could call the auditor and demean them over the phone for their lack of knowledge knowing even if the behavior is reported likely no one will accept a phone call alone as evidence. But the manager will be faster than lightning to reprimand the same person. A chokehold has been put on communication but only to the individual. This causes tremendous stress and increases uncertainty because the auditor knows what awaits if he/she asks peers or an immediate supervisor for help and it gets discovered.

How to Spot the Informant

The auditor who bad actors have turned has several elements: was the auditor a good productive team member or was he/she already sarcastic, pessimistic or argumentive? On top of that, is the employee in an office setting or remote?

The Good Employee/The Unwilling Informant:

This is the majority of informants. In the office this may be visible early such as the example of the manager moving the team out or moving the auditor far away from the team. The remote environment is much more complicated for the team and much easier for the bad manager. The team does not see each other: as we have discussed communications have been forced to only the toxic manager so interactions between team members is tightly controlled: when an auditor has been targeted and pressure repeatedly put on the one auditor what communications take place do not allow the team to see potential effects. As discussed earlier even if the individual attempted to communicate directly with an immediate supervisor (but below the manager’s level) and the supervisor approached the manager, a plausibly deniable statement was ready.

The Not-so-Good or Easily Turned Employee:

There was already some real or perceived wrong by the individual and the manager’s insertion to further their “game” was not entirely unwelcome. In the office setting this might be dealt with by the meetings called by the bad actor(s): they want the team to feel their power and, not uncommonly, keep the team off balance and perhaps even maintain a certain amount of fear. The team will see the individual and either by statements made, favoritism shown by the bad actor toward the individual or other observed actions the team can as a collective element see a problem on the horizon. If the disgruntled auditor is separated from the team withholding information can go both ways and damage minimized. If the auditor remains with the team the team can collectively watch for signs such as excessive complaining and arguing, even over small points; complaining about being uninformed by the team; undermining team efforts to improve work, conditions or reporting functions; and disengagement from the team (good auditors can act this way as well: remember they do not want to be controlled and this may be an attempt to clue in the team).

With good and bad auditors, the remote environment complicates things-a LOT. Now the team does not know when the manager contacts the informant auditor, or about what. Meetings are remote and again the team cannot see each other (these managers do not use visual-virtual media for their meetings: it is another means to isolate individuals). The individual can even go so far as to start and maintain low level conflicts between her/himself and other members (as the bad managers do by initiating and maintaining disputes and adversarial relationships with the team).

An important behavior to look for is territorial behavior. Remember this individual was not unreceptive to the manager’s insertion into their work environment: they will do what they can to ensure no other team member discovers the alliance.

Other ways bad managers isolate good auditors have been discussed: but as they are more than likely indicators of fraud, they have more immediate avenues for elimination. They include Excessive control/micromanagement and forcing all control into the hands of 1-2 individuals; unclear expectations/vague “guidance” (withholding official or clear guidance they do not want known or applied).

Solutions

First and always at any sign of trouble even if only suspected document, document, document and wherever possible make bullet points tying complaints to a specific noncompliance, such as carrying on continuous disputes with the auditor and give official links to the guidances you used or attach them as Exhibits. Try to keep date-time groups as accurate as possible; and who said what when. Document what routes were attempted and what results were.

Most managers and lead auditors are ethical, hardworking and care deeply for their subordinates and the organization. The bad actors are the minority. When concerns arise about managers behaving fraudulently or antagonistically toward an auditor and their supervisor or the team another manager must be found who can address the situation and stay the course of reporting with an individual and/or the entire team. When the bad actors show themselves go to the good people and seek pathways to resolution. These people should be sought out by the team early and included in meetings if possible: or at the very least independently communicated with by a trusted teammate. This way communications are open, honest and in all likelihood big problems can be averted if the direct reporting mechanisms fail. A manager who is willing to isolate and turn an employee is not on the job for the right reasons: so, we can infer some form of fraud is taking place: financial, position protection or something else. It must be addressed quickly.

Even if a team member is believed/known to be an informant I still recommend sequestered team meetings. These are two-edged swords: the informant can report information the team shares which they rather the bad manager not be privy to: at the same time meetings can include “project assignments” or additional duties assigned to each member-the supervisor will likely be the lead for this. The supervisor can then contact each auditor individually with specifics added to their assignments. After a time, consistencies will appear because the manager(s) will micromanage everything and the informant will have shown her/his hand somewhere. In the office setting the team will need to look for more visible signs, as listed above.

The supervisor or first line leader can work directly with the informant. An unwilling participant in any fraudulent enterprise will likely want their position betrayed: they respect their team and want no part of whatever the manager is up to. Reporting safety nets and protections must be offered: confidentiality must be strictly adhered to: and the promise made of rapid action must at all costs be kept.

No solution has value unless there is a structure in place to proceed with it. Most big organizations have a hotline: whether via telephone or email the hotline must be reviewed regularly and every concern addressed. Unlike most systems if an auditor has been unwillingly turned against their team and the supervisor is assisting in the reporting process there should be an avenue for immediate supervisor/trusted individual input. Secondhand information may not be ideal but likely the auditor-informant (called a relator) is scared, stressed and afraid of retaliation, possibly including against their team. If first line leaders have enough tenure, they will likely know a peer in compliance or risk evaluation and rather than indirect communications, they can expedite the relator meeting directly with a party who has the authority to kickstart the resolution pathways. If possible, a direct internal line of reporting is advised. If the organization is big enough there may be an Ombudsman’s office to help pave the way.

Compliance and human resources cannot sit on their hands: but many departments either failed to believe the relator, initiate a serious investigation, or adhere to strictest confidentiality. Because these fraudsters know and game the system they will know as long as they refrain from certain behaviors and statements, civil rights type arguments will find little traction. The relators know this also: and if they are willing to come forward, they must have airtight guarantees of confidentiality-of the case they have reported and their identity and work environment.

Fraudster managers will “lock up” as many avenues of communication as they can internally and depending on their current tenure other sections, perhaps even compliance has been duped or kept so inaccurately informed they trust the manager(s) too much (again, information asymmetry and plausible deniability).

It is also recommended external avenues be established such as an attorney’s office, the contracting organization if the entity is a government contractor, or even an Arbitrator who can direct concerns efficiently and timely to the correct people. These are not recommended as first paths. However, if a relator has any doubt about their safety, then external measures should be established. Therefore, the team, again perhaps the Lead or supervisor should establish an external compliance “escape route”.

Now the deep dive: if any breach of process is suspected or prior attempts at resolution have failed. This is not recommended but may be necessary if the people reported to do not behave in a manner fitting the complaint. The relator has attempted internal controls and found them ineffective, even with as clear documentation and reporting as possible. This action comes with serious risk, there is no doubt: but resolution was honestly attempted and failed. Advise the addressees the relator is willing to take the case as high as necessary, even to the federal level.

My recommendation would be to word it as an advisory: “I have told you what I know, I expect proof of response within X# of days. If I hear nothing, or I receive any indications my confidentiality has been breached I reserve the right in accordance with (company, contractor) policy to report this to all authorities concerned with this matter. I am making a final attempt to resolve this problem locally and it is hoped at this point my concerns will be taken seriously. But if not, when reported to federal authorities the matter is out of our hands.” This statement will be taken seriously as intended: you have an argument and we need to address it, and you consider it very important. Or they could view it as a threat. Officially reporting the manager should be enough and the receiver(s) of the report should not need an advisory statement like this: you reserve this powerful addition to inform the receivers that you will see the matter through until a conclusion is reached and closed. So, it is up to the relator and any ally he/she may have to determine where in the process this goes-but have it ready. The relator has reported it at the lowest possible level: he or she must now commit to reaching as high as necessary to ensure all parties are dealt with and corrective changes made.

Conclusion

The vast majority of mid-level leaders are ethical and know their success relies on the true, realized accomplishment of the audit team below them. Attempting to turn a good or bad employee will never cross their minds because they hold themselves to a higher standard; and know deep inside that open communication delivered concurrently to all team members will achieve the highest rates of success.

Even where fraudulent managers exist these ethical managers will be as intolerant of their antics as the auditors. They will likely be an effective early avenue of reporting even if others who should be directly involved have failed.

Unfortunately, the damage mid-level fraudsters cause far exceeds the number working in the healthcare arena. Systems, processes and departments (i.e. Compliance) exist only to be disregarded and outmaneuvered: and individuals are expendable at any point so their illegal enterprise will survive. Elimination will only be achieved by teams and individuals willing to report them and defend their peers, and team cohesiveness strong enough to let each member know they are trusted and the team as a unit will support and if necessary, defend them.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 2

Part 2: When Criminal Behavior Infiltrates Your Audit Program 


Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)   

We Recommend Reading Part 1 Fraud Indicators and Red Flags – When Audit Managers Knowingly Skew Audit Results as this article is Part 2, “the rest of the story.”

Subsequent to Part 1 - Fraud Indicators and Red Flags, this article stresses the need for early detection of that rare, but dangerous potential fraud committed by the Lead Auditor or Audit Manager.  Members of the audit team realize that detecting a non-conformance often means there is likely much that has gone undetected. If you see something, say something, right?  But what if it is your boss managing the audit?

Introduction

In this article, the term Audit Manager and Lead Auditor is used interchangeably, even though there may be variances between these two titles.  Audits are conducted as part of the organization’s compliance program for the purpose of detecting non-conformances in order to take corrective action to improve compliance to applicable rules and regulations. 

The assumption is made that most organizations have internal controls, checks and balances and accountability built into their compliance program.  When those controls fail, the audit process can be jeopardized, skewing audit results with a potential devastating impact on the risk management process.

Organizations, regardless of size, should require the following elements within an audit: Plan, Execute, Report, Corrective action (P-E-R-C).  Smaller healthcare organizations may only have one internal auditor, while mid-size and larger organizations have a team of auditors. Someone needs to manage or lead the audit, even if it is a team of only one auditor.  If your organization doesn’t engage with an independent third-party contractor to periodically inspect the management of the audit team, you should.  Typically, your Lead Auditor is the most skillful within our organization.  For an effective program, engaging an unbiased audit expert to review and “audit” the management of how audits are conducted is a sound risk management decision. 

Let’s review why auditing your audit program is so important.

Below the Surface: Detecting What You Don’t See

If your organization detects a problem, it is likely just the tip of the iceberg.  What you don’t or can’t see is likely to be a much bigger risk factor that what you do see. 

The assumption is made that most organizations have internal controls, checks and balances and accountability built into their compliance program.  Hopefully, this article describes several ways to detect areas of potential fraud within your audit processes.

It is not uncommon for C-suite Executives to delegate the responsibility of establishing and maintaining an effective internal compliance control system to mid-level management, such as the Lead Auditor, who must implement such controls at a reasonable cost. This could conflict with the Lead Auditor’s goals of improving coding, documentation, billing accuracy and other business systems.

It is the Lead Auditor’s primary responsibility to provide assurance that reviews are conducted to detect compliance non-conformance and to lead the audit team through the P-E-R-C proves.  For an audit program to be effective, audits must be conducted and reported in a manner free from material bias, conflict of interest and performed in an objective manner.  We must admit, auditing is not guaranteed to catch every instance of fraud, waste and/or abuse.  If a problem goes undetected, does this reflect poorly on the audit team?  It could, and it could result in tarnishing the team’s reputation.

But what happens when audit results are consistently exceptional?  Repeated scores of, let’s say 96%, 97%, 98% accuracy where the target performance goal is at least 95% accuracy?  Are these results “real” or should they be questioned?  Can Auditor Managers and Lead Auditors sway audit results to improve their own performance? Is it possible that the compliance infrastructure is unintentionally designed to encourage willful misrepresentation resulting in false positive outcomes?

These are important questions to ask to ensure the appropriate checks and balances are in place.  In-other-words, who is auditing the Lead Auditor? 

When Information is Withheld or Altered

Most organizations have effective audit programs led by experienced certified healthcare auditors.  Audit Managers and Lead Auditors are skilled at giving leaders independent, objective assurance that something is true. And auditors are experts when it comes to internal controls expected during an audit; unless that information is withheld or altered. Lead auditors, through training and experience, should be able to detect fraud indicators and when these indicators involve claims, then financial fraud may also be considered triggering an internal investigation. But having this much power, can it open opportunity for willful misrepresentation?

Let’s look at the government auditing standards for a moment.  In the 2018 Revision of Government Auditing Standards, the US Government Accountability Office it states (page 175, Section 8.73): “Fraud involves obtaining something of value through willful misrepresentation. Whether an act is, in fact, fraud is determined through the judicial or other adjudicative system and is beyond auditors’ professional responsibility.” 

Section 8.74 states: “Auditors may obtain information through discussion with officials of the audited entity or through other means to determine the susceptibility of a program to fraud, the extent to which the audited entity has implemented leading practices to manage fraud risks, the status of internal controls the audited entity has established to prevent and detect fraud, or the risk that officials of the audited entity could override internal control. An attitude of professional skepticism in assessing the risk of fraud assists auditors in assessing which factors or risks could significantly affect the audit objectives.”

Is Manipulating the Audit Environment a Sign of Malicious Activity?

Manipulating any part of the audit process requires investigation. This can involve acts of self-preservation on the Lead Auditor’s part, perhaps to the extent they want to drive out the more experienced auditors on the team who can uncover and report true findings and irregularities.

It is likely that experienced auditors on the team they manage may observe and question “why” something has navigated away from protocol. A red flag is when the Audit Manager’s motivations are questioned, the question is deflected or goes unanswered.

In my experience, opportunities exploited and behavior often found in those who are committing fraud, waste or abuse are those listed below, in addition to the typical collusion and conspiracy which are better known:

Weak Internal Controls – The manager is not monitored

The manager knows if concerns are voiced, the controls are so weak that little will come of complaint(s)-the manager also already has a script in place based on plausible deniability. Hyper-compartmentalization is exploited: departments are territorial and do not share information, i.e. Compliance does not oversee or meet with the auditing department. This causes a black hole between critical control components. There is no guarantee of confidentiality or protection. This too is exploited.

Moral hazard

A moral hazard occurs when one party in a transaction has the opportunity to assume additional risks that negatively affect the other party. The decision is based not on what is considered right but on what provides the highest level of benefit, hence the reference to morality.  In my experience, one of the more common is the moral hazard of rationalization.

Rationalizations are the excuses people give themselves for failing to live up to their own ethical standards. "Moral hazard of rationalization" refers to the psychological phenomenon where individuals use reasoning and justifications to convince themselves that their unethical behavior is acceptable, essentially allowing them to engage in immoral actions while maintaining a positive self-image, thus creating a "moral hazard" by reducing the perceived negative consequences of their actions; it's essentially using logic to excuse morally questionable behavior.1

Thorough knowledge of the systems and/or programs/Information Asymmetry

This is a serious element because the fraudster will have superior knowledge and/or access to electronic programs and processes.  When the Lead Auditor or Audit Manager has unlimited power through technology to manipulate data, routine monitoring is recommended of how this power is employed.  This is all part of strengthening internal controls through an objective expert.

The Payoff Matrix

According to an article in the National Library of Medicine published September 2023, in the context of healthcare fraud: "The Payoff Matrix refers to a conceptual framework that analyzes the potential outcomes (rewards and penalties) for different actors involved in fraudulent activities within the healthcare system, considering the choices they make between committing fraud or acting honestly, essentially illustrating the potential gains or losses depending on their decision and the actions of other parties involved, like patients, providers, and insurers; it helps visualize the incentives and disincentives that could influence their behavior towards fraudulent practices.”2

This is difficult for the vast number of honest managers to understand because they care deeply for their processes, employers, and, most importantly, people. To the fraudster it is a game; there are winners, there are losers; there are moves and counter-moves. They see the auditors as expendable players rather than victims: and they see superiors and leaders as opposing players who will be beaten and outmaneuvered. In the context of this article, they secure their positions and remain champions of the game, to continue with little thought to their own possible loss.

Detect the Tip of the Iceberg?

Actions to Mitigate Risk

The compliance department must be active, in place and independent in authority and action. If the reader will indulge a few analogies, I will show how critical this section of any organization is. About the iceberg analogy used in this article – the Titanic, the mighty, “unsinkable” ship, cutting edge in every way in its time.  We know on April 14, 1912 the Titanic hit an iceberg and sank igniting one of the most remembered tragedies in history.

Experts disagree on why the ship struck the iceberg but there are recurring theories: poor watch crew alertness and/or training; no binoculars; and they just didn’t see it in time. Things they do agree on: the ship was sailing too fast in known iceberg waters and there were not enough lifeboats.

Your compliance department is like the watch crew - They must look for hazards (watch): search for hazards in the future (binoculars): and have the authority to order the captain to alter course no matter how inconvenient. A compliance department that has become complacent or does not monitor internal controls is ignoring speed: things in healthcare move quickly. Having an ineffective compliance department is like having these lookouts not just make the ship hit the iceberg; they back the ship up and make it hit the iceberg again. Compliance must also be the lifeboats. They need to listen to and address every concern raised and treat all parties equally-no one stands alone because of title or position and the corollary; no one is above scrutiny for the same reasons. And compliance must be trusted to maintain strictest confidentiality. Every individual who reports concerns must feel they will be protected and safe.

The rest of the iceberg

In this image, note the long flat tabletop just below the surface. Managers who commit fraud, especially for their benefit at the cost of everyone else’s, will form some sort of escape route.

They are willing to “take some heat” as long as their fraudulent enterprise survives. The compliance department has to destroy this STAT. If the managers are spoken to but nothing substantial really is done, then they have taken the ship, backed it up, repaired it (so they think) and sent the ship right back into the iceberg.

Invest in Infrastructure & Developing a Culture of Compliance

Your workforce must feel “safe” to report concerns and observations of potential fraud, waste and/or abuse.  This only happens when a top-down culture of compliance has been instilled within the organization and demonstrated by the items listed below.

Responding to complaints must be rapid and effective - Compliance must be several critical things, just like the military: it must be forward yet visible (Air Force). We know they are active and they are watching beyond their office desks. We see them. They also must be agile: able to respond to indications or complaints quickly.  Employees at every level must know these people are there, always gathering information even when unseen and are there to defend them if necessary.

Compliance must also be the Army and Marines - Employees (relators) must know how to report concerns to the compliance department in a safe manner and undetected by the Lead Auditor when the Lead Auditor is of concern. Confidentiality must be the operative philosophy. Like all the major services, they must be able to act independently with the backing of the highest levels of authority. Above all, compliance must dedicate itself to an overarching creed: never let the relator feel scared, threatened, harassed or intimidated. Any form of retaliation will not be tolerated.

Establish a Confidential Network - The Audit Team needs to find an avenue to escalate complaints, confidentially, to those tasked with compliance and especially whistleblower protections. This should be between each auditor and the compliance officer or someone within the Compliance Committee. There really is power in numbers and just like plausible deniability, there will be force in consistency of fact. Because the auditors are external to the auditees, and in the remote environment external to the Audit Managers, information and concerns can be shared and options discussed without fear of harassment, reprisal or retaliation. Facts can be shared and supported by other auditors’ experiences.

This element differs from strengthening internal controls in that the point of contact for concerns need not absolutely be someone tasked with receiving them by policy.

Strengthen Internal Controls - There is no cookie-cutter template for succeeding in this. Whether through complacency, old school ways of thinking or the bureaucracy-wide need for self-preservation and avoidance of “bad news,” weak internal controls have devolved into weakness for a reason. Following right on the heels of getting these people to listen may be getting the auditors to trust them. Our attempts at reporting have failed: why should we trust you now? This is a legitimate question which must be answered before real progress can be made.

Documentation – Over time facts and details can become unclear.  Documenting observations, gathering “evidence” and making record in a timely manner can help determine if the person altering data has made a material falsification requiring a more formal internal (or external) investigation.

Conclusion

The vast majority of healthcare managers are ethical, hard-working people who care about their organization both downward and upward. They are as outraged by fraud or someone on their team manipulating information.  In my experience, the majority of published reporting of mid-level fraud regards financial motivation. If any healthcare organization takes firm and consistent steps to maintain strong internal controls, the type of fraud in this article will never see light and be mitigated before any significant damage can be realized.

Although we have covered quite a number of subjects, the solution will be driven by the establishment of a superstructure founded on ferreting out truth from plausible deniability and weak internal controls. Without these other efforts will yield little.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS. 

References

  1. McCombs School of Business – Ethics Unwrapped https://ethicsunwrapped.utexas.edu/glossary/rationalizations
  2. National Library of Medicine – Study on the Path of Governance in Health Insurance Fraud Considering Moral Hazard https://pmc.ncbi.nlm.nih.gov/articles/PMC10543491/#:~:text=Combating%20health%20insurance%20fraud%20is,toward%20a%20non%2Dfraudulent%20state

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 1

Part 1:  When Audit Managers Knowingly Skew Audit Results  


Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Fraud cannot be eliminated. No system is completely fraud-proof, as any system can be bypassed or manipulated. However, it can be detected early by paying greater attention to common fraud indicators. This article follows a road less-traveled by discussing the potential of audit managers knowingly skewing audit results causing unintended consequences within what appears to be a well-functioning compliance program.

Introduction & Defining Terms

The Office of Inspector General (OIG) provides compliance guidance documents for healthcare provider use.  There are also self-reporting mechanisms in place to report overpayments on the OIG website (Self-Disclosure) and Self-Referral Disclosure for voluntary self-reporting of overpayments on the Centers for Medicare and Medicaid Services’ (CMS’) website.  Detecting these errors resulting in potential overpayments is typically accomplished through efficient auditing and monitoring programs coordinated under the direction of the organization’s Compliance Officer or Compliance Department.  But is the oversight of the audits manipulated to achieve particular performance goals? Could it result in the “cobra effect” (explained further below). Is anyone monitoring the integrity of the Audit Managers?

Tons of information can be found on the Internet, books, articles, etc. on fraud detection and prevention in healthcare.  Typical publications and investigative reports illustrate involvement of providers, executives and even lower-level employees. 

But there is nowhere near the focus on mid-level managers; those who are the go-betweens of the C-Suites and Internal Auditors and their immediate supervisors. Because the monetary variance with the executives/owners is so different, they are left out.

In my experience, it appears that the mid-level fraud aspect is recognized primarily by two government entities, one federal and one state, which will be referenced throughout this article. The list of terms and definitions used throughout are below for reference.

Cobra Effect- a situation where an attempted solution to a problem inadvertently makes the problem worse due to unintended consequences. 

Conspiracy- Britannica defines conspiracy as “in common law, an agreement between two or more persons to commit an unlawful act or to accomplish a lawful end by unlawful means.” The Law Dictionary defines Criminal Conspiracy as “A combination or confederacy between two or more persons formed for the purpose of committing, by their joint efforts, some unlawful or criminal act, or some act which is innocent in itself, but becomes unlawful when done by the concerted action of the conspirators, or for the purpose of using criminal or unlawful means to the commission of an act not in itself unlawful.”

Indicators and Red Flags- For the purpose of this article the two terms are used synonymously: Signs of deception or suspicious aspects of behavior or misrepresentations that can lead to illegal payments or claims. 

Perverse Incentive(s)- An incentive (reward or motivation) that unintentionally leads to negative or undesirable outcomes.

Plausible Deniability- Although this can be found in dictionaries there is no official, or even strictly legal definition. An explanation is far more effective. By far the best is the updated July 17th, 2022 article in The Law Dictionary2. It is not nearly as neat as one would expect; but the article displays how fraudsters who game the system apply this in their daily activities:

“Plausible deniability is defined by the dictionary. But it’s not technically a legal term or defined in any legal documents. Which makes it a much looser term than it sounds. On top of that, plausible doesn’t mean trustworthy, possible, or even likely. Plausible means you could conclude that something might or might not be possible. But usually theoretically, superficially, or suspiciously. It doesn’t necessarily have to be a “reasonable” conclusion, either. In its broadest sense, the term usually points to a lack of proof. After all, innocent until proven guilty is the backbone of our legal system. So, if there’s no proof, it’s plausible they could deny it.”  The definition continues to state “Essentially anything illegal or unethical that can be explained away under an innocent and probable guise – true or otherwise – falls under plausible deniability. Even if the plausibility of the denial is suspicious. However, in the ‘60s, the CIA took the term and expanded on what plausible deniability means to them. And the CIA’s version is the one that became popularized.  To the CIA, it’s the act of withholding information from senior officials to protect their higher-ups in the event the information becomes public. Whether the information was actually withheld or not matters little in court if there’s no proof to the contrary.”  The Law Dictionary Article goes further and indirectly shows us the dangers posed by managers who use it:

“While it might seem like a minor tweak, the CIA’s definition puts blame on subordinates. This blame swap alleviates pressure on more senior officials. Which you may or may not frown upon.  And I get that. Most people expect superiors to be held accountable for the actions of the subordinates. But if they have plausible deniability, the senior officials can’t be held accountable. This is true even if the actions clearly only benefit the superior who “wasn’t” in the know.  It also applies if an implication was made that spurred on illegal or unethical actions. An example would be a sinister comment in a suspicious tone followed by an equally suspicious exaggerated wink. That is, providing the superior can write it off as a misunderstanding.  However, in cases where someone genuinely didn’t know something was happening, they can’t reasonably be held accountable for the other person’s actions. Regardless of management practices and chains of command, if someone really doesn’t want you to know something, they’re really just not going to tell you. Famously, Ollie North (Lt. Col. Oliver L. North from the Iran-Contra scandal) called this situation “absolute deniability.” Ollie’s argument was if you’re genuinely not aware of or did not do something, that’s not plausibility – it’s just not a thing.

This seemingly convenient loophole is meant to uphold the burden of proof. And – before you cry outrage – the burden of proof is for your benefit as well. So, it’s kind of important if you care about your rights. However, that’s not typically how we think of plausible deniability. And that’s certainly not how we’ve seen it pan out in the political or corporate arena. Real-world plausible deniability can (and does!) encompass things like thinly veiled threats, false advertisements, sexual harassment, stalking, discrimination against legally protected characteristics like race, age, gender, and sexual orientation, as well as a slew of other instances.”

Why Focus on Mid-Level Audit Managers?
The Data Speaks for Itself!

The Association of Certified Fraud Examiners (ACFE)1 conducts biannual surveys of its members and one of the questions is what effect the perpetrator’s position has on fraud. ACFE graciously has given me permission to use their surveys and data for this publication.

Since the surveys began in 1996, questions on the survey focused on fraud committed by position. Three positions were given by respondents:

  1. Executives/owners;
  2. Employees; and
  3. Managers.

A recurring trend emerged. The trend breaks down generally (but consistently):

  • Executives/owners account for the least number of cases but the most losses in money.
  • The employees by contrast account for the greatest number of cases but the least amount of monetary losses.

But the surprising result, given the relative scarcity of information, was on managers.

  • In every survey conducted, the ACFE found managers account for fewer cases than employees; but 250%-300% monetary losses.

The Data Speaks

Data gathered in 2018 was a sign of things to come. The ACFE survey found most perpetrators were either employees (41.2%/median loss of $50.000.00) or managers (39.5%). But the median loss due to managers was $150,000.00: 3 times that caused by employee fraud.

In the ACFE’s 2020 survey employees accounted for median loss of $60,000.00 and managers, $150,000.00 or 2.5 times that of lower-level employees.

Forward to 2022 and employees accounted for median loss of $50,000.00. Managers again took a far larger proportion of median losses, totaling $125,000.00 2.5 times that of employees. In the 2022 survey the ACFE also stated “Frauds committed by higher-level perpetrators also typically take longer to detect.” “One of the challenges of dealing with fraud committed by high-level perpetrators is that these individuals often have the ability to evade or override controls that would otherwise detect fraud. Additionally, fraudsters in positions of authority might bully or intimidate employees below them, which can deter those employees from reporting or investigating suspected wrongdoing. Both of these factors might contribute to the longer duration of frauds committed by high-level employees.”

The ACFE has completed its 2024 survey, with the following results:

  • Employee fraud caused a median $60,000.00 loss; whereas
  • Managers caused a massive $184,000.00 median loss.

In addition, the ACFE reported based on the surveys and monitoring over time, “Similarly, fraud cases perpetrated by individuals at higher levels of authority took longer to detect. The median duration of frauds perpetrated by employees was only 8 months…while frauds committed by mid-level managers had a median duration of 18 months….” (All figures and quotes used with permission of the Association of Certified Fraud Examiners).

NOTE: There are two reasons to retro back to 2018. One was to show the timespan and consistency of results. But the second is to show that the data was consistent even during the pandemic and afterwards. This opens an area gaining scrutiny: fraud committed in the remote workplace.

In the case of healthcare coding and documentation auditors, the primary directive is to ensure documentation is true and accurate: and that claims submitted reflect the work that was in fact accomplished and specific codes are correct for encounters. When claims become involved, there will always be a financial element.  However, performance and upward mobility within the organization becomes a component for dishonesty within mid-level audit management. Although most motivation to commit fraud is financial, coding and documentation audit manager performance is often based on coordinating information down for improved accuracy and upward to demonstrate the audit program is working.

A bigger issue is that red flags were unreported or intentionally misrepresented at a level beyond the auditors. This is where the mid-level leadership can be most dangerous as they form the “solid floor” to the corporate officers for upward transmission of information, and ostensibly a “Communications ceiling” for the auditors and their supervisors, ensuring information goes down to the respective components.

Guidance from the Department of Defense Inspector General (DoD IG)

In its current guidance Fraud Detection Resources for Auditors3, there is a subsection titled Management Related Fraud Indicators. This is interesting because of the mass availability of information singling out executives and employees but little recognizing mid-level involvement. The DoD IG opens the subsection with a key statement:

“Management sets the tone of an organization through its control environment. An organization’s control environment is the foundation of all other internal control components. An organization’s control environment includes integrity and ethical values, management philosophy, organizational structure, and self-governance. For a DoD contractor, active participation in a compliance program, integrity reporting, and the DoD Voluntary Disclosure Program are key parts of its control environment. The control environment provides both discipline and structure to the organization; therefore, auditors must consider management characteristics and influence over the control environment not only as fraud risk factors but also as fraud indicators along with the general and audit specific fraud indicators.”

Several of the sixteen indicators are reviewed below.

Fraud Indicators listed by the DoD IG4

Detect an inappropriate or unreasonable argumentative attitude?

  • Failure to display and communicate an appropriate attitude regarding the importance of internal control, including a lack of internal control policies and procedures; ethics program; codes of conduct; self-governance activities; and oversight of significant controls

This can be noticed by something as easily overlooked as never mentioning them. More importantly managers have oversight and execution authority of those internal controls. They have the ability to withhold and interpret the controls to their benefit at the cost or suppression of the auditors they are tasked to oversee. They may withhold compliance training, guidance, manuals or conferences on the controls and processes reporting or proliferate “training” of their own to such an extent the auditors become separated from compliance knowledge or reporting routes.

  • Displaying through words or actions that senior management is subject to less stringent rules, regulations, or internal controls than other employees.

At meetings managers will not mention who they answer to, or how. They stay silent on their responsibilities for compliance.

  • Hostile relationship between management and internal and/or external auditors. This would include domineering behavior towards the auditor, failure to provide information, and limiting access to employees of the organization.

In some ways this is a continuation of the indicator above: but is an escalation as now the manager is forcing an adversarial relationship, hoping to bring it to a confrontational level and the manager will feel justified in disciplining the auditor for insubordination or drive the auditor out of the organization completely.

  • Failure to establish procedures to ensure compliance with laws and regulations and prevention of illegal acts.

One of two things, or both, will occur: the managers will make themselves the only contacts to raise concerns or even ideas. The DoD IG, DHHS OIG and government contractors have complaint and whistleblower processes in place but if they are not enforced, investigated and confidentiality strictly adhered to, the auditor’s chances of a peaceful resolution are slim to none. Fraudulent managers know and exploit this and it is another tool in their scheme to silence a problematic voice in their environment.

  • Indications that key personnel are not competent in the performance of their assigned responsibilities.

This is one of the more common non-financially driven fraud motives; an audit manager will not have the training, experience or credentials of auditors they oversee. The manager cannot ask the right questions but feels their position is threatened by superior knowledge which can result in closing lines and compliance avenues of communication.

When the manager is incompetent to fill the role, every red flag is fair game. 

In addition, they justify their actions by telling themselves only they deserve the position: not even necessarily that they earned it. In one of the cases below, two managers are conspiring against the audit team.  The two managers involved did not even have certified auditing credentials, such as the Certified Healthcare Auditor (CHA) offered by AIHC.

In one case, the company had been in trouble with CMS several times. A current manager with no auditing credentials was emplaced to oversee random audits of Medicare claims: but audits quickly discovered that same manager was responsible for 84% of the continuing errors and retrospective audits showed the same manager was responsible for much of the trouble uncovered by CMS auditors previously.

  • The manager attempted to redirect the audits but the audit supervisor did have auditing training and defended the auditor and had already hammered out a solid audit plan and methodology, which the company’s compliance director and CMS approved; and she checked every item audited as a check-and-balance.
  • Soon the auditor and supervisor learned the company began getting serious inquiries from CMS about the managers’ lag time submitting the compliance audits and eventually they “had to downsize” right when another sanction appeared looming.

In total 9 people were downsized in the space of a week and in the middle of the “pack” or team were the auditor and supervisor. This experience exposes two glaring problems with manager fraud.

  1. The manager was untrained and did not know how the audit was built and demanded items with a certain ID (hers) be left out of all audits. Random means random-you cannot pick and choose which items you audit or report. It skews results and becomes a targeted audit: a type no recognized auditing organization allows when a statistically representative general sample is demanded.
  2. The manager did not understand what a universe or statistically significant sample was, or simple formulas for calculating them. The manager also did not understand the old axiom “numbers don’t lie”. The manager constantly attempted to reword, reinterpret or omit fact of the audits when the audits had to be reported to the executives. During a meeting the supervisor and auditor attempted to explain how CMS and the DHHS OIG used their statistical auditing system, called RAT-STATS. The outcome was no response and orders to continue with targeted audits.

Just as widespread, but carrying much higher risk: a manager can never be allowed to oversee and influence an audit where they have a direct stake in the audit outcome. No audit will be trusted. This goes back to the indicator about managers creating a hostile environment: they will have results altered by bullying, threatening or confounding the auditor or do it themselves and through use of plausible deniability draw suspicion on the auditor.

If there is conspiracy between the manager and the reporting executive or body, the damage goes from probable/possibly mitigated to unacceptably high risk. In this company there was conspiracy but CMS uncovered it later. I do not know what happened to the two collaborators but I do know the Compliance Officer, who saved the company multiple times from CMS prosecution, was let go not long after the auditor and the supervisor.

  • Undue interest and micromanagement. We live in the information age, where information travels almost as fast as thought (or at least as fast as typing skills). Managers who demand inclusion on all Emails, regardless of topic are suspect, especially when a seemingly unrelated Email is sent only to a coworker and a harsh Email from the manager is the result. The danger signs are clear. The Email never went to the manager-how did he or she intercept it? The Email was unrelated to any sensible matter the manager would be involved in-let’s say in this case I asked a teammate for a copy of a pdf document because in my thousands of emails and e-files I couldn’t find it. Then, why was I criticized?
  • A manager that claims disinterest or having no knowledge about a sensitive or high-profile issue in which you would expect management involvement. An auditor informs the manager the electronic system that pulls visits for audit has been only pulling specific dates or codes (remember, depending on the data, the system may be running its own targeted audit). The manager tells you offhandedly to “just do the audit”. Or you tell the manager coders are assigning codes specifically prohibited (let’s say they’re CMS-only codes) on commercial claims. The manager doesn’t even say thanks: just like “I’ll look into it if I have time”.
  • Failure to effectively follow-up on recommendations resulting from external reviews or questions about financial results. Failure to follow up on any serious concerns or recommendations from the audit team. This couples with the hostile work environment: rather than follow up professionally the managers criticize the auditors.

Thomas P. DiNapoli, State of New York Comptroller Red Flags for Fraud5

Several of these management level indicators were further detailed in a guidance recently released by the State of New York Comptroller in his fraud guidance Red Flags for Fraud, under Management Red Flags. Mr. DiNapoli states the problem slightly differently:

  • Managers engage in frequent disputes with auditors.

This can be read differently than the DoD IGs indicator in that here the manager instigates and maintains irritating, false or adversarial confrontations to bait the auditor into a situation which the manager can accuse the auditor of being insubordinate, or keep the auditor confused or confounded about what the manager “wants”. This can flow into appeals if the manager oversees challenges to the auditor’s findings. The manager will overturn the auditor’s error and use such vague or meaningless rationale that the auditor is forced to contact the manager and is sharply rebuked (again, the manager has avoided dealing with the auditor and supervisor). This tends to make the auditor continue contact, attempting to get a clear answer. Each time the manager increases the inflammatory rhetoric or vague verbiage and a cycle has begun. This is the entrance of a behavior/methodology addressed below - plausible deniability.

The Comptroller’s report also specifies a red flag related to indicators in the DoD IG guidance:

  • “Management decisions are dominated by an individual or small group”.

Managers who are willing to retaliate without cause yet staunchly refuse to discuss their perceived “problems” with the auditor and the supervisor and never forward concerns through the chain of command are dangerous: they keep vital information from the executives and compliance/fraud investigators above or laterally while oppressing their subordinates and keeping them uninformed. In scenarios I present later I cover operations where managers are in a conspiracy: if concerns or perceived negative information is communicated the managers meet with each other and no one else.

Mr. DiNapoli also saw the red flag he made independent of others:

  • “Manager reluctance or refusal to provide information to auditors and their supervisors”.

This links directly to multiple red flags in several ways. As mentioned appeals results will be intentionally confounding to the auditor which puts the entire power of the outcome in the hands of the manager. The problem escalates when the manager(s) are the first and highest reporting entity who receive audit reports. I have seen cases where information and/or data in an audit report was manipulated or deleted and conspiring managers made claims the auditor was remiss: which went into their records for future “disciplinary actions”. In one example even if the auditor keeps the reports in her or his e-files after a short amount of time the reports are deleted. The file is there in name but can neither be opened nor retrieved. This can tie in to the hostile work environment: the manager chastises an auditor for “errors”: but either never provides specific, official guidance or provides “guidance” of the manager’s making (a guidance was talked about at a meeting but never entered in an official manual).

Inconsistent, vague or implausible responses arising from inquiries or analytical procedures.

Mr. DiNapoli’s red flag above shows us officials do recognize the use of plausible deniability. In the manager’s sphere of influence this needs to be closely scrutinized by the executives and auditors: but especially compliance.

A red flag, actually two, were further noted by Mr. DiNapoli but are closely related:

  • There is a weak internal control environment; and
  • Decentralization without adequate monitoring.

This may be the most important red flag there is: every other indicator or red flag can be built from it. The managers scrutinize the auditors-but who is scrutinizing the managers? This gives fraudulent managers 2 key openings.

First: when not monitored consistently managers can manipulate almost anything: documents, conversation records, even information that goes up and/or down the leadership structure. Many boards and even civil courts will not allow mobile phone records because they can easily be manipulated.

Second, they can target any perceived threat or opposition without question or investigation. This is where auditors who attempted to resolve problems locally become whistleblowers. They attempt to use the reporting systems in place but because the managers failed to forward concerns to the reporting body above them the concerns never go up. In addition, with decentralization the higher authority often incorrectly trusts the manager because the “information” sent to them never covered complaints. Even worse, if the higher authority was part of the hiring process they have motivation to hide a potential hiring error.

Last in this group is a red flag usually associated with embezzlement, and often with employees: but it can happen in any setting, at any level where an individual wants absolute restricted control of information. This red flag is refusing vacations or promotions for fear of detection. Let’s expand an example from above:

  • The manager demands inclusion on all Emails and intercepts irrelevant Emails and rebukes the auditor.
  • Now let’s add that the manager is on vacation: and the Emails are still being intercepted whether relevant or not. The outcome is the same: criticism of the auditor for asking a question. Is the manager embezzling?

As auditors we cannot know that. So how is this a red flag? Because the manager still has a chokehold on information flow. Let’s extend this: the manager is on vacation and your team is informed to contact her or his peer, another manager in the same position. You do as instructed, and either the manager on vacation answers your Email: the other manager answers your Email but states he or she will meet with the other “to discuss”; and no one else. Or worse the manager on vacation calls you and the conversation becomes adversarial.

Another red flag: the use of plausible deniability

Some may think this is a term straight out of Hollywood but it is still very real whether the fraud is primarily to protect a position or financially motivated. No matter which red flag or indicator we cover, plausible deniability is guaranteed. A case I know of is a manager, contacting only an auditor who has raised several concerns, stating “your insubordination will not be tolerated. Any further complaints will result in your discipline and we will make sure you get written up”. The supervisor hears of it and speaks to the manager. The manager replies with “I never said that. I simply stated I needed more detail in the concerns your auditor was voicing”. It is believable (as far as it goes): but is a fabrication of what was said, actually saying nothing, and again is cutting off lines of communication. Another example is the Email intercepts I mentioned. A question gets asked. And the manager states “I was on PTO. I wasn’t even in the office”. The auditor has the response from the intercepted Email but the manager followed up with a phone call-the auditor’s word against a higher level authority. Or, the manager was careful but knew full well the adversarial position regularly taken against the auditor. The response Email will be vaguely worded or gray enough where “That’s not what I meant” could be viewed as a reasonable answer. A manager who uses plausible deniability regularly will have their own dictionary of denials at the ready.

Manager Red Flags in the Remote Environment

The pandemic forced remote work on many organizations; and many continue to use this scenario as they are taking second looks at potential savings. For the cost of X number of computers for remote workers, and evaluating in-person or in-office time now from a part-time view organizations are seeing potential cost savings in everything from previously assumed overhead such as electricity to space lease or rental and parking.

What would we term this relatively new motivation for fraud? I would say we call it decentralization. And because of this decentralization, the incentive to commit fraud increases; and involves every red flag and indicator we have discussed. In the office environment an auditor could find someone, even if a peer to relate problems to. Remote work by its nature separates people. Or, as the managers see it, isolates them. And some preliminary information I have seen this isolation is making employees at almost every level suffer. But how will a manager use this, and remote work in general to keep their position unquestioned.

This case encompasses both incompetent managers and remote fraud: but there are more angles to the remote aspect so I will put it here. Two managers had been hired recently: neither had certified auditing or compliance training, and the reason they were hired was never made clear. “New” processes were initiated but were not released to the audit team until significantly later with no feedback allowance; what CMS would term a “comment period”. Concerns were voiced but harshly rebuked; and auditors were singled out for disciplinary Emails only to them, sometimes also to the supervisor. Meetings with them, the supervisor and auditor were refused. When an auditor voiced concerns again the managers waited 6 months: then complained to an external manager and demand without cause the auditor be disciplined.

The two managers made it clear no auditee was to receive ≥ 10 errors: and if the auditor stood their ground and the audit went to appeal, or the auditee complained to them directly, the auditor would be disciplined and errors in the report overturned in favor of the auditee. This causes a serious compliance problem: the auditee does not dictate the rules, or any aspect, of an audit. This is a red flag not found easily but applies universally: the auditee cannot, under any circumstances be allowed to dictate the rules of the audit.

The overarching rule here is covered by every recognized auditing body I know of and simply put, an audit is governed by rules, regulations and laws-not the auditee. This is a point strongly made during my Certified Healthcare Auditor training.  If an auditee is allowed to determine parameters of an audit the audit becomes immediately suspect and the auditors vulnerable to fraud investigations against them. In this case conspiracy extends beyond the two cooperating managers: they have now allied with the auditees, who will likely not “turn on them” as a quid pro quo.

Concerns had been voiced for several months audit results were being skewed: the conspiring managers told the auditors they had no choice. But a record was kept of a random sampling of several months’ audits in a specialty area: and of 100 total visits, 90 were of a type with such limited codes it was nearly impossible to make mistakes. A third of those were postsurgical visits where not only the procedure codes were limited (to 1 only); the diagnosis codes were also severely limited to 1-2 codes only. And this is regardless of the documentation. For practical purposes it is almost impossible to arrive at 90 single-type visits with such mandatory restraints on code choice. Targeted audits have a place: after random audits have been completed, aberrations found and concentration needs to be more focused. But if an organization’s policy is random audits only, the manager has much to answer for.

This case fits in several categories and could be covered deeper in each: but now the managers’ game has an added dimension mentioned previously. When the managers knowingly skew the results of the audits, and the audits are government, meaning they will be compiled and presented to Congress, the managers have added collusion to their list of illegal behaviors.

Conclusion

By their nature auditors (and their oversight bodies) are adversarial. The auditors need to find errors to improve accuracy and reporting-and the auditees want to look the best because their throats are on the line when budget cuts come. Using plausible deniability the managers claim “We’re remote: we have no influence on the auditees, and we have records of reports filed. If anyone is acting maliciously it is the auditors.” Because of the remote workspace, decentralization and lack of strong internal controls the managers have avoided a problematic scenario.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.

References

  1. Association of Certified Fraud Examiners: https://www.acfe.com/fraud-resources/report-to-the-nations-archive
  2. Plausible Deniability Definition, Examples, & Laws, Powered by Black’s Law Dictionary, Free 2nd ed., and The Law Dictionary: https://thelawdictionary.org/article/plausible-deniability/
  3. DoD IG Fraud Detection Resources for Auditors: https://www.dodig.mil/Resources/Fraud-Detection-Resources/Fraud-Scenarios/
  4. DoD IG Comprehensive List of Fraud Indicators: https://www.dodig.mil>Audit>Indicators Only
  5. Thomas P. DiNapoli, State of New York Office of the State Comptroller-Red Flags for Fraud: https://www.osc.ny.gov/files/local-government/publications/pdf/red_flags_fraud.pdf

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Culture of Safety is based on Prevention, not Punishment

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS  

This article emphasizes the need of healthcare institutions to focus on building a culture of safety through Root Cause Analysis (RCA) to Manage Clinical Risk is an important management tool.  Read Part 1: Building a Culture of Patient Safety Starts with Reducing Staff Burnout posted December 3, 2024 and Part 2:  An Approach to Reduce Patient and Workforce Harm.

Introduction

Keeping patients safe requires an organizational culture of safety based on the commitment from Directors and C-Suite Executives.  Creating a patient safety environment includes complex interventions that involve the need for variations in individual work routines and healing processes as well as behavioral changes to be made on the part of the team or the individual for maximum acceptance from others.

Patient safety is a framework of organized activities that creates cultures, processes, procedures, behaviors, technologies and environments in health care that consistently and sustainably lower risks, reduce the occurrence of avoidable harm, make error less likely and reduce its impact when it does occur.

Every point in the process of care-giving contains a certain degree of inherent unsafety.

Clear policies, organizational leadership capacity, data to drive safety improvements, skilled health care professionals and effective involvement of patients and families in the care process, are all needed to ensure sustainable and significant improvements in the safety of health care.

Root Cause Analysis & Patient Safety

Most healthcare organizations use RCA as a tool to find out what happened, why it happened, and how to prevent it from happening again. The process is a tool for identifying prevention strategies. It is a process that is part of the effort to build a culture of safety and move beyond the culture of blame.

In a Root Cause Analysis Program, basic and contributing causes are discovered in a process similar to diagnosis of disease - with the goal always in mind of preventing recurrence.  The following information breaks this complex process down into basic bullet points and serves as an introduction to this topic only. 

What the RCA process is:

  • An inter-disciplinary, involving experts from the frontline services;
  • Successful when you involve those who are the most familiar with the situation;
  • A process which requires diligence - continually digging deeper by asking why, why, why at each level of cause and effect;
  • A process that requires your organization to identify changes that need to be made to systems; and
  • A process that must be performed with objectivity and as impartial as possible.

What RCA Should Encompass:

  • Determination of:
    • human and other factors;
    • Related processes and systems
    • potential improvement in processes or systems
  • Analysis of underlying cause and effect systems through a series of why questions
  • Identification of risks and their potential contributions

For Your Program to be Credible, an RCA must:

  • Adopt a top-down approach
    • Include participation by the leadership of the organization and those most closely involved in the processes and systems
  • Be internally consistent
  • Include consideration of relevant literature

The Safety Assessment Code (SAC)

The Safety Assessment Code (SAC) can be used to determine whether or not an RCA must be conducted, based on the severity of a specific incident and its probability of occurrence.  It is a method for determining whether any further definitive action is required concerning a particular incident based on the severity of the incident and its probability of occurrence.

A "SAC score" is also of value for incidents that did not result in an adverse event but may also lead to an RCA; i.e., a close call. Close calls occur far more frequently than adverse events and can provide an exceptional opportunity for learning. Close calls afford the chance to develop preventive strategies and actions before a patient may be harmed.

The SAC Matrix is a tool for combining severity and probability. While either the severity or probability of occurrence could be determined first, it is usually more productive to assess the severity first.

When you pair a severity category with a probability category for either an actual event or close call, you will get a ranked matrix score.  These ranks, or Safety Assessment Codes (SAC), can then be used for doing comparative analysis.  There are various SAC matrix tables available, the one below uses 3 severity and 4 probability categories. 

SAC Decision Making Matrix

While either the severity or probability of occurrence could be determined first, it is usually more productive to assess the severity first. This is true since until one has determined the severity of an incident it would be difficult if not impossible to assess an appropriate probability level.  Intersect the 2 categories to determine the SAC score.  For example, if the probability of the adverse event happening if frequent and it is determined by the team that it ranks a severity of “3”, then result would be mapped in the table below.

3 = highest risk

2 =  intermediate risk

1 =  lowest risk

probability severity

The utility of the SAC is at the start of the process so that resources are applied where they have the greatest opportunity to improve the level of safety from a systems perspective.

Root Cause Analysis (RCA) Versus Healthcare Failure Mode & Effects Analysis (HFMEA™)

HFMEA™ is a technique that is usually performed on a system to assess and prioritize the risks associated with that system in the hopes of reducing the risks through re-design as a proactive measure.  Both Root Cause Analysis (RCA) and Healthcare Failure Mode and Effects Analysis (HFMEA™) possess the following elements:

  • Both are non-statistical methods of analysis
  • The goal of both is to reduce patient harm
  • Both involve identifying conditions that lead to harm
  • Both are team activities

Many people confuse these terms and believe that they compete against each other when in fact neither of these two techniques can accomplish what the other can. They are complementary to each other.  A “root cause” is the most fundamental reason for a failure or situation where performance does not meet expectations.

  • Root cause analysis is routinely conducted reactively – to probe the reason for a poor or unexpected outcome or failure which has already occurred.
  • A recent use of root cause is to conduct such analysis as part of a proactive risk reduction effort using Healthcare Failure Mode and Effects Analysis (HFMEA™).

The table below provides a side-by-side comparison of these two analytical tools used in health care.



RCA

Required by Joint Commission after a sentinel event

HFMEA™

Proactive approach to prevent system-related failures

Similarities

  • Non-statistical methods of analysis;
  • Goal is to reduce possibility of harm to patients in the future;
  • Involves identifying conditions that lead to harm;
  • Requires experienced and trained quality managers to lead analysis efforts; and
  • Activity which requires people, time, materials and upper-level management support.

Differences

                            RCA                                                             HFMEA™

Reactive

Proactive

Focuses on an event

Focuses on entire process

Hindsight bias

Unbiased

Fear, resistance

Openness

Asks: “Why?”

Asks: “What if?”

Summary

Organizational culture refers to the shared beliefs, values, and behaviors within a healthcare organization. A lack of emphasis on patient safety in organizational culture can hinder initiatives that aim to ensure patient safety. It may manifest itself as a lack of commitment, inadequate support, or insufficient prioritization of safety measures by the hospital's leadership and staff. This can result in a higher likelihood of medical errors and adverse events occurring. A weak organizational culture can also discourage staff from reporting incidents or speaking out about potential safety concerns further compromising patient safety.

Building a culture of safety starts with educating your Board of Directors, a C-Suite Executives.  The Compliance Department should oversee internal audits that not only include typical compliance risks related to fraud, waste and abuse, but measuring compliance to safety standards as well.  Producing reports to present to high-level executives can help support the budget needed to mitigate patient risk of an adverse event.

To learn more about RCA, I recommend registering for the Certified Healthcare Auditor online certification training program which includes not only auditing, but using RCA for corrective action after the audit.  To learn more about training as a healthcare Compliance Officer, I highly recommend the online Corporate Compliance certification program. 

About the Author and AIHC

The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair and overseeing the AIHC Volunteer Education Committee. She is also a volunteer hospice nurse, hospice hands-on-care volunteer and End of Life Doula.

The American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS. Please visit our online store listing current training and certification offerings.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Leadership, Quality

Building a Culture of Patient Safety Starts with Reducing Staff Burnout

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS

Patient safety directly relates to reducing mistakes. Increased job-related stress contributes to workforce burnout, a major contributing factor to unsafe practices. Unfortunately, our healthcare workforce faces unprecedented challenges: incidence of violence in the workplace, accelerated rates of burnout, and exposure to dangerous hazards.  This article emphasizes the need to improve patient safety and outcomes through reducing staff burnout.

Introduction

Providing a safe environment instills confidence not only to the patients we serve, but for our workforce as well.  According to the National Institutes of Health, a strong link exists between workforce wellness and patient safety.  When healthcare workers are physically and mentally well, they are more likely to have the ability to focus and deliver safe and quality patient care.  Therefore, we can conclude that a healthy workforce is necessary for a safe patient environment. 

A positive patient and workforce safety culture has been shown to significantly improve a number of patient outcomes, including lower rates of surgical site infections, falls, and medication errors, according to the Patient Safety Network. In addition to specific health outcomes, patients report having better experiences with their care when the culture of patient safety is strong.

Although most healthcare organizations agree on the importance of safety culture, research this year focused heavily on the psychological factors surrounding culture, such as psychological safety, how to support healthcare workforce staff after an adverse event, and burnout. This is a challenge in today’s world.

Work Overload as a Contributing Factor

Causes of work overload in healthcare include time constraints; alert or alarm fatigue; new and hard-to-use technology, including EHRs; and cognitive strain, which, according to the American Medical Association (AMA), directly or indirectly causes 87.1% of medical errors—even though most safety interventions focus on training clinicians, whose knowledge and skill is responsible for only 12.8% of medical errors.

Assaults, Violence Contribute to Burnout

The passion most healthcare workers have can be overridden by the threat of on-the-job violence. And this doesn’t even account for the threats encountered getting to and from work!

According to the Bureau of Labor Statistics, there is a 63% increase in the rate of injuries from violent attacks against medical professionals from 2011 to 2018. And, according to a report by the Centers for Disease Control (CDC) and the Bureau of Labor Statistics (BLS), it is reported that:

  • In 2020, health care and social assistance workers overall had an incidence rate of 10.3 (out of 10,000 full-time workers) for injuries resulting from assaults and violent acts by other persons.
  • The rate for nursing and personal care facility workers was 21.8 per 10,000 full time workers for injuries caused by assaults and violent acts by others.
    • This means that for every 10,000 full-time employees in nursing and personal care facilities, there were an average of 21.8 reported incidents of workplace violence.
  • Data obtained from nurses (RNs/LPNs) in a major population-based study showed a rate of physical assaults at 13.2 per 100 nurses per year and at a rate of 38.8 per 100 nurses per year for non-physical violent events (threat, sexual harassment, verbal abuse).

As you can see, it is difficult to work your best under these circumstances.  And even though some institutions may have a proper formal incident reporting system, there are still many incidents, especially in the forms of bullying, verbal abuse, and harassment that are never reported.

Most Vulnerable Workforce

The most vulnerable healthcare workers victimized are staff at emergency departments, especially nurses and paramedics, and staff directly involved with in-patient care.

What Patient Safety Is

When discussing “patient safety” in the context of this article, it may be helpful to quote definitions, examples and descriptions of what a safety culture is. 

According to the American Nurses Association, a culture of safety describes the core values and behaviors that come about when there is collective and continuous commitment by organizational leadership, managers, and healthcare workers to emphasize safety over competing goals.   The Joint Commission defines Safety Culture as the sum of what an organization is and does in the pursuit of safety.

From a global perspective, the World Health Organization states that patient safety is defined as “the absence of preventable harm to a patient and reduction of risk of unnecessary harm associated with health care to an acceptable minimum." Within the broader health system context, it is “a framework of organized activities that creates cultures, processes, procedures, behaviors, technologies and environments in health care that consistently and sustainably lower risks, reduce the occurrence of avoidable harm, make error less likely and reduce impact of harm when it does occur."

Is Burnout a Still Problem Now that COVID-19 is Behind Us?

The COVID pandemic is a major contributing factor to the overall burnout of health care workers. And, COVID continues to be a current infectious disease stressor to the healthcare workforce.  According to the Centers for Disease Control (CDC), “Health worker jobs in the U.S. involve demanding and sometimes dangerous duties, including exposure to infectious diseases and violence from patients and their families. The COVID-19 pandemic presented even more stressors. These included a surge of patients, longer working hours, and shortages of supplies and protective equipment. Health workers are reporting feeling fatigue, loss, and grief at levels higher than before the pandemic.”  The CDC reports:

Individuals who choose to work in healthcare often make personal sacrifices for their work. While the work can be rich with purpose and meaning, the demands on time and attention can be relentless to the point of being unhealthy for the healthcare worker.  Leadership’s approach and commitment to patient safety has a significant impact on your organization’s culture. If leaders do not prioritize or actively foster a culture of safety, it can negatively affect staff engagement and commitment to patient safety practices. Strong and supportive leadership is crucial for implementing and maintaining a culture that prioritizes patient safety.  Lack of support from upper management contributes to clinical staff burnout.

Burnout related to work stress is mainly seen as emotional exhaustion, depersonalization, and diminished sense of accomplishment.  This manifests itself with mental and physical exhaustion and is demonstrated as a lack of commitment, inadequate support, or insufficient prioritization of safety measures by leadership and staff. This can result in a higher likelihood of medical errors and adverse events occurring.

In healthcare organizations, patient and workforce safety culture are founded on how well teams work together, how supportive leadership and managers are of patient and workforce safety, how staff report events and near misses, and how teams and leaders respond to events. A weak organizational culture can also discourage staff from reporting incidents or speaking out about potential safety concerns further compromising patient safety.

Focusing efforts on a sound and sustained safety culture will lead to and support better outcomes in patient healthcare and safer working conditions for healthcare workers.

Address Patient Safety and Volunteer Staff Burnout

Don’t overlook the important role of your volunteers! Volunteers have a potential negative impact on patient care when these important members of your team experience high levels of burnout.  This can lead to decreased attention to detail, potential errors, and compromised quality of care due to exhaustion and reduced motivation. Although they are unpaid staff, they still require orientation and training.  When their importance is overlooked and minimized, it can contribute to burnout, making them more prone to mistakes, overlook important details, or have reduced responsiveness, potentially affecting patient safety.  Factors like unclear expectations, excessive workload, lack of support from leadership, inadequate training, and feeling undervalued can contribute to volunteer burnout. 

Emotional exhaustion, decreased engagement, increased absenteeism, irritability, and feeling overwhelmed are common signs of volunteer burnout. Implement systems to identify early signs of burnout in volunteers and provide necessary support or adjustments to their roles. Routine skills testing, annual HIPAA and compliance training should be included in your volunteer program.

Conclusion

The purpose of patient safety is to reduce risks, errors and harm that can occur to patients while receiving medical care, which is part of the huge patient quality emphasis currently stressed in the United States and globally. As the world faces evolving and new challenges, it can be difficult to provide an infrastructure to respond with consistent, effective practices deployed by a workforce that is properly equipped, financially and emotionally supported.

The most effective approach to envision the promotion of a patient safety culture is a multifaceted approach of interventions established at the top.  Additional reading and resources to review are:

About the Author and AIHC

The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair and overseeing the AIHC Volunteer Education Committee.  She is also a volunteer hospice nurse, hospice hands-on-care volunteer and End of Life Doula. 

American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS.  Please visit our online store listing current training and certification offerings.


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved


Read More