Compliance Deconstructed

Jessica Zeff, Lorie Davis, & Elvan Baker

Welcome to Compliance Deconstructed, a podcast dedicated to all things Healthcare Compliance.Hosted by Healthcare Compliance professionals Jessica Zeff, Lorie Davis, and Elvan Baker, each episode thoroughly breaks down the complex inner-workings of compliance in the healthcare industry.From the 7 Elements that make up Healthcare Compliance to AI's impact on the industry and everything in between, Compliance Deconstructed is your resource for information, strategy, and commentary to elevate your knowledge base. Click play and join us for an episode today!

  1. 6d ago

    The Biggest Reasons Your Compliance & Legal Teams Need to Be On the Same Page

    Healthcare compliance and legal teams often work in the same areas, but knowing when an issue belongs with compliance, when legal counsel should be involved, and when both teams need to work together can create confusion.  In Episode 33 of Compliance Deconstructed, Jessica Zeff, Lorie Davis, Elvan Baker, and special guest Gabby Morella, Managing Partner at Morella & Associates, explore the relationship between healthcare compliance and legal counsel and explain why collaboration between these functions matters when organizations face regulatory, contractual, operational, and legal issues. The conversation begins by breaking down the different forms of compliance that healthcare organizations encounter, including contract compliance and operational compliance. The group also discusses how compliance professionals help organizations monitor whether policies, procedures, agreements, and regulatory requirements actually work in practice, while legal professionals bring specialized knowledge to contractual interpretation, regulatory interpretation, liability, and legal risk. Another major focus is attorney-client privilege and the misconceptions that often surround it. Gabby explains that the client holds the privilege, that privilege does not automatically apply to every conversation with an attorney, and that involving additional people in certain communications can affect whether privilege applies.  This in-depth episode also emphasizes that organizations should understand the limits of attorney-client privilege and should not treat it as a blanket protection for decisions or conduct that may create legal or regulatory problems. Key Takeaways From Episode 33: Compliance covers ongoing risk management, auditing, policies, contracts, and regulatory requirementsInvolve legal early when an issue could create significant liability, contractual, regulatory, or reporting riskCompliance oversees implementation and day-to-day adherence, while legal provides legal advice and risk guidanceThe level of legal involvement should reflect the organization, situation, and potential riskAttorney-client privilege has specific boundaries and can be affected by who is included in communicationsStrong collaboration between compliance, legal, and operations supports better decisions and stronger compliance outcomesConnect with Gabby on her website Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    The Biggest Reasons Your Compliance & Legal Teams Need to Be On the Same Page
  2. Sep 1

    Medical Billing & Coding: The Challenges Facing Today's Healthcare Professional

    Medical billing and coding is one of the most complex operational areas in healthcare, with providers and billing organizations required to navigate hundreds of codes, modifiers, reimbursement rules, payer requirements, and changing regulations.  In Episode 32 of Compliance Deconstructed, Jessica Zeff, Lorie Davis, and special guest Nancy Worthy of Worthy Billing and Consulting discuss the medical billing and coding challenges that can create compliance risks, reimbursement problems, claim denials, and audit exposure for healthcare organizations. Nancy draws on more than 35 years of medical billing experience to explain how seemingly small details can affect whether a claim gets paid correctly, including time-based codes, telehealth place of service codes, modifiers, units, provider credentialing, and payer-specific requirements.  The discussion highlights how frequently billing and coding rules can change and why healthcare providers need processes that help them monitor those changes and apply the correct requirements to each claim, particularly in areas such as mental health and telehealth. Medical records and prior authorizations also play an important role in supporting accurate healthcare billing, because the services represented on a claim need appropriate documentation and required approvals.  This episode provides practical insight into how billing teams, compliance professionals, healthcare providers, and health plans can work together to identify billing errors, correct claims, monitor recurring issues, and build processes that reduce unnecessary risk while supporting accurate reimbursement. Key Takeaways From This Episode: Medical billing and coding requires ongoing attention because codes, modifiers, reimbursement rates, payer requirements, and billing rules can change throughout the yearTime-based billing requires accurate documentation, including the appropriate amount of service time and, when required, start and stop times that support the code billedTelehealth billing can create additional complexity because place of service codes and modifiers depend on where the patient receives the service and payer requirements can change over timeIncident-to billing, supervision billing, and billing for interns or pre-licensed providers have specific requirements, and healthcare organizations should verify the rules for each applicable payer before submitting claimsHealthcare providers serving Medicaid patients in Pennsylvania may need to consider county-specific managed care arrangements and verify that the provider participates with the appropriate plan before billingAccurate medical records, prior authorizations, credentialing, claim forms, codes, modifiers, and reimbursement rates all contribute to billing compliance, making collaboration between billing, compliance, clinical, operational, and leadership teams essential Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    Medical Billing & Coding: The Challenges Facing Today's Healthcare Professional
  3. Aug 18

    A Comprehensive Look at New OIG Guidance In Medicare

    The Office of Inspector General’s new Medicare Advantage Industry Segment-Specific Compliance Program Guidance (ICPG) provides healthcare organizations with a more focused framework for identifying and managing compliance risks within the Medicare Advantage sector.  In this episode, Jessica Zeff, Elvan Baker, and special guest Brian Burton of Healthicity discuss how the new guidance fits alongside the OIG’s General Compliance Program Guidance and the seven elements that form the foundation of an effective healthcare compliance program. While the Medicare Advantage ICPG does not carry the force of a regulation, the guidance provides a blueprint for the compliance activities the OIG expects organizations to consider, particularly when evaluating enforcement matters and Corporate Integrity Agreements. The discussion examines why Medicare Advantage has received increased attention, including its growth to more than half of all Medicare enrollment in 2025 and the significant number of beneficiaries now receiving coverage through Medicare Advantage plans. The conversation also explores the organizations and individuals who may need to understand the Medicare Advantage compliance guidance, including Medicare Advantage organizations, healthcare providers, vendors, first-tier downstream and related entities, brokers, marketers, and investors.  Jessica, Elvan, and Brian also examine specific areas of compliance risk identified by the OIG, including risk adjustment and data integrity, utilization management and prior authorization, marketing and enrollment, network adequacy, claims and payment integrity, quality of care, and vertically integrated or financially motivated ownership structures. Key Takeaways: The Medicare Advantage ICPG works alongside the OIG’s General Compliance Program Guidance and provides sector-specific direction for organizations operating within the Medicare Advantage environmentMedicare Advantage compliance guidance addresses a broad range of participants, including health plans, providers, vendors, first-tier downstream and related entities, brokers, marketers, and investorsRisk adjustment and data integrity require close attention to diagnosis coding, documentation, health risk assessments, and potential overpayments, making ongoing monitoring an important part of Medicare Advantage complianceUtilization management, prior authorization, and artificial intelligence create compliance considerations involving medical necessity, access to care, claims decisions, and the appropriate use of technology in clinical and reimbursement processesMarketing and enrollment, network adequacy, provider directories, claims and payment integrity, quality of care, and financially motivated ownership structures represent additional risks identified within the Medicare Advantage ICPG Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    A Comprehensive Look at New OIG Guidance In Medicare
  4. Aug 4

    California Medicaid Under The Microscope: What You Need To Know - Part 2

    California Medicaid, known as Medi-Cal, is one of the largest and most complex Medicaid programs in the United States, serving approximately 15 million members across diverse geographic and socioeconomic communities.  In this Part 2 episode of Compliance Deconstructed, Jessica Zeff, Elvan Baker, Lorie Davis, and special guest Marwan Kanafani continue to explore what makes California Medicaid unique, how its managed care model operates, and why organizations entering this market must understand both regulatory expectations and operational realities. The discussion examines how California has become a leader in developing innovative healthcare delivery models by addressing Social Drivers of Health alongside traditional medical services. The conversation highlights how federal waiver programs allow Medi-Cal to invest in interventions that improve long-term patient outcomes while helping healthcare organizations reduce avoidable utilization and improve the overall quality of care. Jessica, Elvan, Lorie, and Marwan also take a closer look at Enhanced Case Management (ECM) and the operational challenges that come with delivering high-touch, community-based care. From workforce development and documentation requirements to liability considerations and care coordination, the episode explains why implementing these programs requires thoughtful planning and collaboration across clinical, operational, and compliance teams. The conversation also explores what organizations should expect when entering the California Medicaid market, including rigorous regulatory oversight, vendor accountability, annual audits, and NCQA accreditation requirements. Whether you are a healthcare executive, compliance professional, managed care organization, or healthcare vendor, this episode provides practical insight into building sustainable operations while meeting the evolving expectations of California Medicaid. Key Takeaways California Medicaid serves approximately 15 million beneficiaries through one of the nation's largest and most complex managed care systemsSocial Drivers of Health continue to shape Medi-Cal's approach to improving patient outcomes through upstream, community-based interventionsEnhanced Case Management requires significant operational planning, workforce investment, and cross-functional coordination to deliver high-touch care effectivelyHealthcare vendors performing delegated functions are held to the same rigorous compliance expectations as the managed care organizations they supportAnnual audits, NCQA accreditation, and comprehensive documentation remain fundamental components of operating successfully within the California Medicaid environmentCounty-level differences, regional demographics, and local healthcare infrastructure all influence how organizations should approach expansion within California Medicaid Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    California Medicaid Under The Microscope: What You Need To Know - Part 2
  5. Jul 21

    California Medicaid Under The Microscope: What You Need To Know - Part 1

    California's Medicaid program, Medi-Cal, serves more than 14 million residents and continues to shape how managed care, compliance, and healthcare delivery evolve across the country.  In this episode of Compliance Deconstructed, Jessica Zeff, Elvan Baker, and special guest Marwan Kanafani explore how Medi-Cal operates, why California's regulatory environment is so complex, and what healthcare organizations need to understand to successfully navigate one of the nation's largest Medicaid programs. The conversation examines the role of the California Department of Health Care Services (DHCS), the state's managed care model, and the extensive oversight health plans experience through ongoing audits and regulatory reviews. The trio also dives into how federal waivers allow California Medicaid to test innovative care models while balancing accountability, operational demands, and patient access across a diverse population. Medi-Cal addresses social determinants of health by supporting initiatives that extend beyond traditional medical care, including housing stability, food security, environmental improvements, and transition planning for justice-involved populations. From a compliance standpoint, these programs require healthcare organizations, health plans, community partners, and government agencies to work together while demonstrating measurable outcomes that support continued funding and regulatory approval. Additionally, Jessica, Elvan, and Marwan also discuss the operational challenges created by carve-outs, data sharing, NCQA accreditation, and the continued integration of Medicare and Medi-Cal programs for dual-eligible populations. Whether you work in healthcare compliance, managed care, health plan operations, or provider leadership, this conversation offers practical insight into the regulatory expectations, implementation challenges, and collaborative strategies that help organizations succeed within California's evolving Medicaid landscape. Key Takeaways Medi-Cal's managed care structure delegates responsibility to private health plans while remaining under the oversight of the California Department of Health Care ServicesCalifornia health plans often operate in a continuous audit environment and how organizations prepare for overlapping regulatory reviewsMedicaid waivers allow California to develop innovative programs that address Social Determinants of Health and improve long-term patient outcomesHousing support, nutrition assistance, environmental interventions, and reentry programs contribute to better health while creating new compliance and operational considerationsHear practical recommendations for strengthening compliance through data-sharing agreements, outcome measurement, NCQA readiness, and planning for Medicare and Medi-Cal integration Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    California Medicaid Under The Microscope: What You Need To Know - Part 1
  6. Jul 7

    What Are The Most Important Compliance Concerns Regarding GLP1s?

    GLP-1 medications continue to reshape healthcare delivery, creating new opportunities for patient care while introducing significant compliance responsibilities for providers, telehealth organizations, pharmacies, and health plans.  In this episode of Compliance Deconstructed, Jessica Zeff is joined by co-hosts Elvan Baker and Lorie Davis to examine the regulatory and operational challenges surrounding GLP-1 prescribing, including telehealth evaluations, compounded medications, fraud, waste, and abuse risks, prior authorization requirements, and practical compliance oversight. The reality is that organizations often focus on patient demand without fully evaluating how their operational processes support compliant prescribing practices. Jessica, Elvan, and Lorie discuss why synchronous telehealth visits, thorough clinical documentation, provider licensure verification, and informed patient conversations all play an important role in reducing regulatory risk while supporting appropriate access to care. From a compliance standpoint, GLP-1 oversight extends well beyond the prescription itself. The conversation explores FDA scrutiny surrounding compounded GLP-1 medications, the role of pharmacy benefit managers, documentation expectations for medical necessity, and how financial incentives, prescribing trends, and marketing practices can create fraud, waste, and abuse concerns when organizations fail to implement appropriate safeguards. In practice, compliance requires ongoing monitoring rather than one-time policy development. Jessica, Elvan, and Lorie share practical strategies for incorporating GLP-1 medications into annual compliance risk assessments through documentation audits, claims monitoring, pharmacy verification, marketing reviews, and cross-functional collaboration that helps organizations balance regulatory expectations with sustainable patient care. Key takeaways: Understand how synchronous and asynchronous telehealth models create different compliance obligations for patient evaluation, informed consent, documentation, and provider accountability.Review GLP-1 prescribing workflows to verify provider licensure, patient identity, clinical necessity, and complete medical documentation before prescriptions are issued.Evaluate how your organization manages compounded GLP-1 medications, including pharmacy sourcing, FDA marketing requirements, and communications regarding product equivalency.Monitor prior authorization processes, diagnosis coding, and supporting documentation to reduce compliance risks associated with medical necessity and reimbursement.Assess fraud, waste, and abuse risk by reviewing prescribing patterns, refill activity, provider compensation structures, refund policies, and potential kickback concerns.Incorporate GLP-1 medications into your compliance audit program with regular risk assessments, claims reviews, marketing audits, and collaboration across compliance, operations, clinical, legal, and pharmacy teams. Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    What Are The Most Important Compliance Concerns Regarding GLP1s?
  7. Jun 23

    The Best Ways to Manage Compliance In a Critical Access Hospital w/ Denise Lord

    In this episode of Compliance Deconstructed, Jessica Zeff and Elvan Baker sit down with Denise Lord to explore the realities of managing healthcare compliance in a critical access hospital. Denise shares firsthand insights into balancing multiple responsibilities, building effective compliance programs with limited resources, and creating sustainable processes that support both regulatory requirements and patient care. This in-depth conversation examines the unique structure of critical access hospitals, where compliance leaders often oversee quality, risk management, infection prevention, patient experience, and privacy responsibilities simultaneously. Denise explains how this broad oversight can provide valuable visibility into organizational operations, helping healthcare leaders identify trends, address risks proactively, and strengthen collaboration across departments. Jessica, Elvan, and Denise also discuss the importance of fostering a culture of shared ownership for compliance. They highlight the role of executive leadership, compliance committees, department managers, and frontline staff in creating an environment where ethical decision-making, regulatory adherence, and patient safety become part of everyday operations rather than isolated compliance activities. Key Takeaways: • Critical access hospital compliance leaders often oversee multiple functions, creating opportunities to identify risks and trends across the organization. • Strong compliance programs depend on collaboration between leadership, clinical teams, operations, legal counsel, information technology, and frontline staff. • Compliance committees become more effective when members actively participate in discussions and help identify organizational priorities. • A just culture approach helps organizations address incidents fairly while encouraging staff to report concerns and potential compliance issues. • Privacy and HIPAA training become more meaningful when employees understand how compliance directly impacts patients, families, and their local communities. • Successful compliance management requires flexibility, strategic prioritization, strong communication with leadership, and a willingness to adapt when unexpected challenges arise. Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    The Best Ways to Manage Compliance In a Critical Access Hospital w/ Denise Lord
  8. Jun 9

    How Important Is Information Security In Healthcare Compliance w/ Joe Wynn

    Information security plays a critical role in healthcare compliance, risk management, and organizational resilience. In this episode of Compliance Deconstructed, Jessica Zeff, Lorie Davis, and special guest Joe Wynn, Founder & CEO of Seiso, break down the foundational elements of an effective information security program and explain why protecting sensitive data requires a structured approach that extends beyond technology solutions. This in-depth conversation explores the importance of conducting comprehensive risk assessments to identify vulnerabilities, evaluate threats, and prioritize security efforts based on potential impact. The hosts also discuss practical safeguards such as multi-factor authentication, data backups, software patching, access controls, and employee training that help healthcare organizations strengthen their security posture and reduce exposure to cybersecurity risks. Jessica, Lorie, and Joe also address common misconceptions surrounding HIPAA compliance, SOC 2 reports, and security attestations while highlighting emerging concerns related to website tracking technologies and third-party data sharing. After consuming this episode, you’ll gain actionable insights into building a sustainable information security strategy that supports regulatory compliance, protects patient information, and promotes long-term organizational success. Key Takeaways: • Risk assessments provide the foundation for identifying security gaps, evaluating threats, and prioritizing remediation efforts across the organization. • Multi-factor authentication, secure backups, regular software updates, access management, and employee education remain essential components of a strong security program. • Healthcare organizations should understand that there is no official HIPAA certification and that compliance requires ongoing oversight and accountability. • SOC 2 reports evaluate security controls and can support broader compliance initiatives when paired with regulatory assessments. • Website cookies, tracking scripts, and third-party marketing tools can create privacy and compliance risks when organizations do not fully understand how data is collected and shared. • Information security requires continuous evaluation, process improvement, and cross-functional collaboration to protect sensitive information and maintain regulatory compliance. Connect with Joe Wynn Website | LinkedIn Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    How Important Is Information Security In Healthcare Compliance w/ Joe Wynn

Ratings & Reviews

About

Welcome to Compliance Deconstructed, a podcast dedicated to all things Healthcare Compliance.Hosted by Healthcare Compliance professionals Jessica Zeff, Lorie Davis, and Elvan Baker, each episode thoroughly breaks down the complex inner-workings of compliance in the healthcare industry.From the 7 Elements that make up Healthcare Compliance to AI's impact on the industry and everything in between, Compliance Deconstructed is your resource for information, strategy, and commentary to elevate your knowledge base. Click play and join us for an episode today!