The Healthcare Compliance Step-By-Step Podcast

EPICompliance

We understand that compliance can feel overwhelming, but it doesn't have to be. Our weekly podcast breaks down one key aspect of healthcare compliance at a time, making it easier to stay informed and take actionable steps. These episodes aren't just for physicians; they're valuable for anyone involved in a healthcare-related business. Each week, we feature interviews with leading voices in the field, including healthcare executives, compliance experts, and innovators who share real-world insights and practical guidance.

  1. 2d ago

    #154 - Medicare Advantage Fraud: Understanding Out-of-Network DME Risks

    Medicare Advantage Fraud: Understanding Out-of-Network DME Risks examines growing compliance concerns surrounding out-of-network Durable Medical Equipment, Prosthetics, Orthotics, and Supplies (DMEPOS) suppliers. In this session, Ray Walters (EPICompliance), and Mr. Jose Delgado (Taino Consultants) discuss recent HHS-OIG findings and what healthcare organizations should understand about supplier verification, Medicare enrollment, documentation, referral risks, and fraud prevention. Key Topics: Out-of-network DMEPOS fraud risks.Supplier verification, Medicare enrollment, and documentation.Due diligence, staff training, vendor oversight, and internal auditing.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: October 6, 2026.

  2. Sep 30

    #153 - Before You Deploy AI in Healthcare: Risks, Responsibilities & Opportunities

    Before You Deploy AI in Healthcare: Risks, Responsibilities & Opportunities examines what healthcare organizations should consider before introducing Artificial Intelligence into clinical, administrative, and compliance workflows. In this session, Ray Walters (EPICompliance), Mr. Jose Delgado (Taino Consultants), and special guest, Dr. Jose Delgado (CEO of EPICompliance) discuss how AI is being used in healthcare and the privacy, security, compliance, and operational risks organizations should evaluate before implementation. Key Topics: AI use in healthcare operations.HIPAA and Security Risk Analysis considerations.Policies, staff training, and responsible implementation.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 29, 2026.

  3. Sep 23

    #152 - Health Plan Exits: Compliance Risks When Coverage Changes

    Health Plan Exits: Compliance Risks When Coverage Changes examines the compliance risks healthcare organizations may face when major insurers leave a market, networks change, or patients are forced to transition to new coverage. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the impact of Cigna and UnitedHealthcare leaving Georgia's ACA marketplace after 2026 and the compliance responsibilities that can arise when patients experience coverage changes, higher costs, or disruptions in care. Key Topics: Health plan exits and coverage changes.Patient notification and communication.Documentation and internal auditing.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 22, 2026.

  4. Sep 16

    #151 - Rural Healthcare Transformation: Managing Compliance During Operational Change

    Rural Healthcare Transformation: Managing Compliance During Operational Change examines the compliance risks rural healthcare organizations may face when restructuring services, changing staffing models, adopting new technology, or introducing new care models. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the $50 billion Rural Health Transformation Program and the importance of patient access, continuity of care, staffing oversight, documentation, funding, accountability, and measurable outcomes. Key Topics: Rural hospital restructuring and service reductions.Patient access and continuity of care.Funding accountability and measurable outcomes.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 15, 2026.

  5. Sep 9

    #150 - Medicare Advantage Quality Payments: Compliance Behind the Star Ratings

    Medicare Advantage Quality Payments: Compliance Behind the Stat Ratings examines the compliance risks connected to Medicare Advantage quality measurements, Star Ratings, and the financial incentives tied to quality bonus payments. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss why accurate reporting, reliable quality data, proper documentation, patient outreach, vendor oversight, and internal auditing are increasingly important as Medicare Advantage quality bonus payments are expected to exceed $13 billion in 2026. The discussion focuses on an important compliance principle: a higher Star Rating is only valuable if the organization can support how that rating was achieved. Healthcare organizations should be able to trace quality results back to reliable source documentation, validate reported data, monitor third-party vendors, document patient outreach, and take corrective action when errors are identified. Key Topics: Patient outreach and the risks of financial pressure influencing care decisions.Vendor oversight and third-party accountability.Internal auditing and corrective action.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 8, 2026.

  6. Sep 2

    #149 - The Cost of a Healthcare Data Breach: Prevention, Response, and Legal Exposure

    The Cost of a Healthcare Data Breach: Prevention, Response, and Legal Exposure examines the financial, operational, and legal consequences healthcare organizations may face after a cybersecurity incident. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the Watson Clinic data breach and the resulting $10 million settlement related to a 2024 cybersecurity incident that reportedly affected approximately 280,000 individuals. The discussion focuses on an important compliance principle: the cost of a data breach extends far beyond restoring systems and recovering data. Healthcare organizations may also face litigation, patient notification expenses, credit or identity monitoring, forensic investigations, regulatory scrutiny, reputational damage, corrective action, and long-term legal costs. Key Topics: The Watson Clinic data breach and resulting $10 million settlement.The financial and legal exposure associated with healthcare data breaches.Why healthcare organizations should establish a breach-response plan before an incident occurs.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: September 1, 2026.

  7. Aug 26

    #148 - The Trusted User Threat: Social Engineering, Contractors, and Healthcare Cybersecurity

    The Trusted User Threat: Social Engineering, Contractors, and Healthcare Cybersecurity examines how trusted access can become a major security vulnerability when employees, contractors, vendors, or business associates are targeted by attackers. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) discuss the 2026 AdaptHealth cybersecurity incident and other recent healthcare-related breaches involving DentaQuest, Medtronic, and Amazon-owned One Medical Senior Health. The discussion focuses on a central compliance principle: trusted access does not mean risk-free access. An attacker may not need to defeat sophisticated security controls if they can manipulate a legitimate user, contractor, or help-desk process and gain access through valid credentials or an active session. Ray and Jose discuss how healthcare organizations can strengthen cybersecurity by reviewing contractor access, multifactor authentication, password security, session management, phishing and vishing awareness, cloud application controls, access termination, incident detection, Business Associate Agreements (BAAs), and third-party security monitoring. Key Topics: Social engineering, phishing, vishing, credential theft, and MFA manipulation.Contractor and third-party access, cloud applications, password security, and session management.Recent breach examples involving AdaptHealth, DentaQuest, Medtronic, and One Medical Senior Health, along with the growing use of social engineering and identity-based attacks.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: August 25, 2026.

  8. Aug 20

    #147 - Remote Patient Monitoring: Managing Vendors, Billing, and Medical Necessity

    Remote Patient Monitoring: Managing Vendors, Billing, and Medical Necessity examines the compliance responsibilities healthcare organizations should understand when using remote patient monitoring programs and third-party vendors. In this session, Ray Walters (EPICompliance) and Mr. Jose Delgado (Taino Consultants) are joined by featured guest and CEO of EPICompliance, Dr. Jose Delgado, to discuss how medical necessity, patient consent, device delivery, billing documentation, staffing capacity, vendor oversight, and privacy and security responsibilities all work together in a compliant RPM program. The discussion focuses on a central compliance principle: Remote Patient Monitoring is a clinical service supported by technology, and outsourcing technology or operational support does not eliminate the billing provider's clinical, billing, privacy, or oversight responsibilities. Ray, Jose, and Dr. Delgado discuss how healthcare organizations can strengthen RPM compliance by confirming individualized medical necessity, documenting informed consent, validating devices and data transmission, reconciling vendor records with the medical record and claims, reviewing staffing capacity, monitoring billing patterns, and conducting meaningful vendor due diligence. Key Topics: Medical necessity, patient consent, device delivery, and proper documentation of RPM services.Billing requirements, staffing capacity, and the responsibilities of employees, clinical staff, and third-party vendors.Vendor oversight, HIPAA privacy and security, and identifying billing or operational warning signs before they lead to audits or enforcement.Resources: Learn more about healthcare compliance systems: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Explore healthcare compliance training and weekly webinars: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠epicompliance.com/training-in...⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Originally Recorded: August 18, 2026.

About

We understand that compliance can feel overwhelming, but it doesn't have to be. Our weekly podcast breaks down one key aspect of healthcare compliance at a time, making it easier to stay informed and take actionable steps. These episodes aren't just for physicians; they're valuable for anyone involved in a healthcare-related business. Each week, we feature interviews with leading voices in the field, including healthcare executives, compliance experts, and innovators who share real-world insights and practical guidance.