The Healthcare Compliance Step-By-Step Podcast

EPICompliance

We understand that compliance can feel overwhelming, but it doesn't have to be. Our weekly podcast breaks down one key aspect of healthcare compliance at a time, making it easier to stay informed and take actionable steps. These episodes aren't just for physicians; they're valuable for anyone involved in a healthcare-related business. Each week, we feature interviews with leading voices in the field, including healthcare executives, compliance experts, and innovators who share real-world insights and practical guidance.

  1. 3d ago

    #153 - Before You Deploy AI in Healthcare: Risks, Responsibilities & Opportunities

    Before You Deploy AI in Healthcare: Risks, Responsibilities & Opportunities examines what healthcare organizations should consider before introducing Artificial Intelligence into clinical, administrative, and compliance workflows. In this session, Ray Walters (EPICompliance), Mr. Jose Delgado (Taino Consultants), and special guest, Dr. Jose Delgado (CEO of EPICompliance) discuss how AI is being used in healthcare and the privacy, security, compliance, and operational risks organizations should evaluate before implementation. Key Topics: AI use in healthcare operations.HIPAA and Security Risk Analysis considerations.Policies, staff training, and responsible implementation.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 29, 2026.

  2. Sep 23

    #152 - Health Plan Exits: Compliance Risks When Coverage Changes

    Health Plan Exits: Compliance Risks When Coverage Changes examines the compliance risks healthcare organizations may face when major insurers leave a market, networks change, or patients are forced to transition to new coverage. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the impact of Cigna and UnitedHealthcare leaving Georgia's ACA marketplace after 2026 and the compliance responsibilities that can arise when patients experience coverage changes, higher costs, or disruptions in care. Key Topics: Health plan exits and coverage changes.Patient notification and communication.Documentation and internal auditing.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 22, 2026.

  3. Sep 16

    #151 - Rural Healthcare Transformation: Managing Compliance During Operational Change

    Rural Healthcare Transformation: Managing Compliance During Operational Change examines the compliance risks rural healthcare organizations may face when restructuring services, changing staffing models, adopting new technology, or introducing new care models. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the $50 billion Rural Health Transformation Program and the importance of patient access, continuity of care, staffing oversight, documentation, funding, accountability, and measurable outcomes. Key Topics: Rural hospital restructuring and service reductions.Patient access and continuity of care.Funding accountability and measurable outcomes.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 15, 2026.

  4. Sep 9

    #150 - Medicare Advantage Quality Payments: Compliance Behind the Star Ratings

    Medicare Advantage Quality Payments: Compliance Behind the Stat Ratings examines the compliance risks connected to Medicare Advantage quality measurements, Star Ratings, and the financial incentives tied to quality bonus payments. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss why accurate reporting, reliable quality data, proper documentation, patient outreach, vendor oversight, and internal auditing are increasingly important as Medicare Advantage quality bonus payments are expected to exceed $13 billion in 2026. The discussion focuses on an important compliance principle: a higher Star Rating is only valuable if the organization can support how that rating was achieved. Healthcare organizations should be able to trace quality results back to reliable source documentation, validate reported data, monitor third-party vendors, document patient outreach, and take corrective action when errors are identified. Key Topics: Patient outreach and the risks of financial pressure influencing care decisions.Vendor oversight and third-party accountability.Internal auditing and corrective action.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 8, 2026.

  5. Sep 2

    #149 - The Cost of a Healthcare Data Breach: Prevention, Response, and Legal Exposure

    The Cost of a Healthcare Data Breach: Prevention, Response, and Legal Exposure examines the financial, operational, and legal consequences healthcare organizations may face after a cybersecurity incident. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the Watson Clinic data breach and the resulting $10 million settlement related to a 2024 cybersecurity incident that reportedly affected approximately 280,000 individuals. The discussion focuses on an important compliance principle: the cost of a data breach extends far beyond restoring systems and recovering data. Healthcare organizations may also face litigation, patient notification expenses, credit or identity monitoring, forensic investigations, regulatory scrutiny, reputational damage, corrective action, and long-term legal costs. Key Topics: The Watson Clinic data breach and resulting $10 million settlement.The financial and legal exposure associated with healthcare data breaches.Why healthcare organizations should establish a breach-response plan before an incident occurs.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 1, 2026.

  6. Aug 26

    #148 - The Trusted User Threat: Social Engineering, Contractors, and Healthcare Cybersecurity

    The Trusted User Threat: Social Engineering, Contractors, and Healthcare Cybersecurity examines how trusted access can become a major security vulnerability when employees, contractors, vendors, or business associates are targeted by attackers. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the 2026 AdaptHealth cybersecurity incident and other recent healthcare-related breaches involving DentaQuest, Medtronic, and Amazon-owned One Medical Senior Health. The discussion focuses on a central compliance principle: trusted access does not mean risk-free access. An attacker may not need to defeat sophisticated security controls if they can manipulate a legitimate user, contractor, or help-desk process and gain access through valid credentials or an active session. Ray and Jose discuss how healthcare organizations can strengthen cybersecurity by reviewing contractor access, multifactor authentication, password security, session management, phishing and vishing awareness, cloud application controls, access termination, incident detection, Business Associate Agreements (BAAs), and third-party security monitoring. Key Topics: Social engineering, phishing, vishing, credential theft, and MFA manipulation.Contractor and third-party access, cloud applications, password security, and session management.Recent breach examples involving AdaptHealth, DentaQuest, Medtronic, and One Medical Senior Health, along with the growing use of social engineering and identity-based attacks.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: August 25, 2026.

  7. Aug 20

    #147 - Remote Patient Monitoring: Managing Vendors, Billing, and Medical Necessity

    Remote Patient Monitoring: Managing Vendors, Billing, and Medical Necessity examines the compliance responsibilities healthcare organizations should understand when using remote patient monitoring programs and third-party vendors. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) are joined by featured guest and CEO of EPICompliance, Dr. Jose Delgado, to discuss how medical necessity, patient consent, device delivery, billing documentation, staffing capacity, vendor oversight, and privacy and security responsibilities all work together in a compliant RPM program. The discussion focuses on a central compliance principle: Remote Patient Monitoring is a clinical service supported by technology, and outsourcing technology or operational support does not eliminate the billing provider's clinical, billing, privacy, or oversight responsibilities. Ray, Jose, and Dr. Delgado discuss how healthcare organizations can strengthen RPM compliance by confirming individualized medical necessity, documenting informed consent, validating devices and data transmission, reconciling vendor records with the medical record and claims, reviewing staffing capacity, monitoring billing patterns, and conducting meaningful vendor due diligence. Key Topics: Medical necessity, patient consent, device delivery, and proper documentation of RPM services.Billing requirements, staffing capacity, and the responsibilities of employees, clinical staff, and third-party vendors.Vendor oversight, HIPAA privacy and security, and identifying billing or operational warning signs before they lead to audits or enforcement.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: August 18, 2026.

  8. Aug 12

    #146 - Medical Device Sales Compliance: Preventing Fraud, Conflicts, and Vendor Abuse

    Medical Device Sales Compliance: Preventing Fraud, Conflicts, and Vendor Abuse examines the warning signs healthcare organizations should recognize when working with medical device companies, sales representatives, distributors, and other vendors. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss how weak purchasing controls, inadequate vendor oversight, conflicts of interest, poor inventory management, and inappropriate financial relationships can expose healthcare organizations to fraud, inflated costs, kickbacks, false documentation, and patient safety risks. The conversation also examines the Jacksonville medical device fraud case involving sales representative Scott Michael Weller. According to reporting, Baptist Health alleged that excessive medical device ordering and weaknesses in purchasing and inventory controls contributed to significant losses. The case highlights the importance of comparing purchasing activity with actual clinical utilization, inventory, staffing, and operational needs. Ray and Jose also discuss how healthcare organizations can strengthen vendor screening, competitive purchasing, conflict-of-interest disclosures, invoice verification, inventory controls, contract monitoring, employee reporting responsibilities, exclusion screening, and responses to suspected fraud. Key Topics: Medical device purchasing and utilization warning signs.Invoice verification, inventory controls, competitive purchasing, and contract oversight.Employee reporting responsibilities and investigating suspicious vendor activity.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: August 11, 2026.

About

We understand that compliance can feel overwhelming, but it doesn't have to be. Our weekly podcast breaks down one key aspect of healthcare compliance at a time, making it easier to stay informed and take actionable steps. These episodes aren't just for physicians; they're valuable for anyone involved in a healthcare-related business. Each week, we feature interviews with leading voices in the field, including healthcare executives, compliance experts, and innovators who share real-world insights and practical guidance.

You Might Also Like