Compliance Deconstructed

Jessica Zeff, Lorie Davis, & Elvan Baker

Welcome to Compliance Deconstructed, a podcast dedicated to all things Healthcare Compliance.Hosted by Healthcare Compliance professionals Jessica Zeff, Lorie Davis, and Elvan Baker, each episode thoroughly breaks down the complex inner-workings of compliance in the healthcare industry.From the 7 Elements that make up Healthcare Compliance to AI's impact on the industry and everything in between, Compliance Deconstructed is your resource for information, strategy, and commentary to elevate your knowledge base. Click play and join us for an episode today!

  1. 12h ago

    California Medicaid Under The Microscope: What You Need To Know - Part 2

    California Medicaid, known as Medi-Cal, is one of the largest and most complex Medicaid programs in the United States, serving approximately 15 million members across diverse geographic and socioeconomic communities.  In this Part 2 episode of Compliance Deconstructed, Jessica Zeff, Elvan Baker, Lorie Davis, and special guest Marwan Kanafani continue to explore what makes California Medicaid unique, how its managed care model operates, and why organizations entering this market must understand both regulatory expectations and operational realities. The discussion examines how California has become a leader in developing innovative healthcare delivery models by addressing Social Drivers of Health alongside traditional medical services. The conversation highlights how federal waiver programs allow Medi-Cal to invest in interventions that improve long-term patient outcomes while helping healthcare organizations reduce avoidable utilization and improve the overall quality of care. Jessica, Elvan, Lorie, and Marwan also take a closer look at Enhanced Case Management (ECM) and the operational challenges that come with delivering high-touch, community-based care. From workforce development and documentation requirements to liability considerations and care coordination, the episode explains why implementing these programs requires thoughtful planning and collaboration across clinical, operational, and compliance teams. The conversation also explores what organizations should expect when entering the California Medicaid market, including rigorous regulatory oversight, vendor accountability, annual audits, and NCQA accreditation requirements. Whether you are a healthcare executive, compliance professional, managed care organization, or healthcare vendor, this episode provides practical insight into building sustainable operations while meeting the evolving expectations of California Medicaid. Key Takeaways California Medicaid serves approximately 15 million beneficiaries through one of the nation's largest and most complex managed care systemsSocial Drivers of Health continue to shape Medi-Cal's approach to improving patient outcomes through upstream, community-based interventionsEnhanced Case Management requires significant operational planning, workforce investment, and cross-functional coordination to deliver high-touch care effectivelyHealthcare vendors performing delegated functions are held to the same rigorous compliance expectations as the managed care organizations they supportAnnual audits, NCQA accreditation, and comprehensive documentation remain fundamental components of operating successfully within the California Medicaid environmentCounty-level differences, regional demographics, and local healthcare infrastructure all influence how organizations should approach expansion within California Medicaid Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    California Medicaid Under The Microscope: What You Need To Know - Part 2
  2. Jul 21

    California Medicaid Under The Microscope: What You Need To Know - Part 1

    California's Medicaid program, Medi-Cal, serves more than 14 million residents and continues to shape how managed care, compliance, and healthcare delivery evolve across the country.  In this episode of Compliance Deconstructed, Jessica Zeff, Elvan Baker, and special guest Marwan Kanafani explore how Medi-Cal operates, why California's regulatory environment is so complex, and what healthcare organizations need to understand to successfully navigate one of the nation's largest Medicaid programs. The conversation examines the role of the California Department of Health Care Services (DHCS), the state's managed care model, and the extensive oversight health plans experience through ongoing audits and regulatory reviews. The trio also dives into how federal waivers allow California Medicaid to test innovative care models while balancing accountability, operational demands, and patient access across a diverse population. Medi-Cal addresses social determinants of health by supporting initiatives that extend beyond traditional medical care, including housing stability, food security, environmental improvements, and transition planning for justice-involved populations. From a compliance standpoint, these programs require healthcare organizations, health plans, community partners, and government agencies to work together while demonstrating measurable outcomes that support continued funding and regulatory approval. Additionally, Jessica, Elvan, and Marwan also discuss the operational challenges created by carve-outs, data sharing, NCQA accreditation, and the continued integration of Medicare and Medi-Cal programs for dual-eligible populations. Whether you work in healthcare compliance, managed care, health plan operations, or provider leadership, this conversation offers practical insight into the regulatory expectations, implementation challenges, and collaborative strategies that help organizations succeed within California's evolving Medicaid landscape. Key Takeaways Medi-Cal's managed care structure delegates responsibility to private health plans while remaining under the oversight of the California Department of Health Care ServicesCalifornia health plans often operate in a continuous audit environment and how organizations prepare for overlapping regulatory reviewsMedicaid waivers allow California to develop innovative programs that address Social Determinants of Health and improve long-term patient outcomesHousing support, nutrition assistance, environmental interventions, and reentry programs contribute to better health while creating new compliance and operational considerationsHear practical recommendations for strengthening compliance through data-sharing agreements, outcome measurement, NCQA readiness, and planning for Medicare and Medi-Cal integration Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    California Medicaid Under The Microscope: What You Need To Know - Part 1
  3. Jul 7

    What Are The Most Important Compliance Concerns Regarding GLP1s?

    GLP-1 medications continue to reshape healthcare delivery, creating new opportunities for patient care while introducing significant compliance responsibilities for providers, telehealth organizations, pharmacies, and health plans.  In this episode of Compliance Deconstructed, Jessica Zeff is joined by co-hosts Elvan Baker and Lorie Davis to examine the regulatory and operational challenges surrounding GLP-1 prescribing, including telehealth evaluations, compounded medications, fraud, waste, and abuse risks, prior authorization requirements, and practical compliance oversight. The reality is that organizations often focus on patient demand without fully evaluating how their operational processes support compliant prescribing practices. Jessica, Elvan, and Lorie discuss why synchronous telehealth visits, thorough clinical documentation, provider licensure verification, and informed patient conversations all play an important role in reducing regulatory risk while supporting appropriate access to care. From a compliance standpoint, GLP-1 oversight extends well beyond the prescription itself. The conversation explores FDA scrutiny surrounding compounded GLP-1 medications, the role of pharmacy benefit managers, documentation expectations for medical necessity, and how financial incentives, prescribing trends, and marketing practices can create fraud, waste, and abuse concerns when organizations fail to implement appropriate safeguards. In practice, compliance requires ongoing monitoring rather than one-time policy development. Jessica, Elvan, and Lorie share practical strategies for incorporating GLP-1 medications into annual compliance risk assessments through documentation audits, claims monitoring, pharmacy verification, marketing reviews, and cross-functional collaboration that helps organizations balance regulatory expectations with sustainable patient care. Key takeaways: Understand how synchronous and asynchronous telehealth models create different compliance obligations for patient evaluation, informed consent, documentation, and provider accountability.Review GLP-1 prescribing workflows to verify provider licensure, patient identity, clinical necessity, and complete medical documentation before prescriptions are issued.Evaluate how your organization manages compounded GLP-1 medications, including pharmacy sourcing, FDA marketing requirements, and communications regarding product equivalency.Monitor prior authorization processes, diagnosis coding, and supporting documentation to reduce compliance risks associated with medical necessity and reimbursement.Assess fraud, waste, and abuse risk by reviewing prescribing patterns, refill activity, provider compensation structures, refund policies, and potential kickback concerns.Incorporate GLP-1 medications into your compliance audit program with regular risk assessments, claims reviews, marketing audits, and collaboration across compliance, operations, clinical, legal, and pharmacy teams. Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    What Are The Most Important Compliance Concerns Regarding GLP1s?
  4. Jun 23

    The Best Ways to Manage Compliance In a Critical Access Hospital w/ Denise Lord

    In this episode of Compliance Deconstructed, Jessica Zeff and Elvan Baker sit down with Denise Lord to explore the realities of managing healthcare compliance in a critical access hospital. Denise shares firsthand insights into balancing multiple responsibilities, building effective compliance programs with limited resources, and creating sustainable processes that support both regulatory requirements and patient care. This in-depth conversation examines the unique structure of critical access hospitals, where compliance leaders often oversee quality, risk management, infection prevention, patient experience, and privacy responsibilities simultaneously. Denise explains how this broad oversight can provide valuable visibility into organizational operations, helping healthcare leaders identify trends, address risks proactively, and strengthen collaboration across departments. Jessica, Elvan, and Denise also discuss the importance of fostering a culture of shared ownership for compliance. They highlight the role of executive leadership, compliance committees, department managers, and frontline staff in creating an environment where ethical decision-making, regulatory adherence, and patient safety become part of everyday operations rather than isolated compliance activities. Key Takeaways: • Critical access hospital compliance leaders often oversee multiple functions, creating opportunities to identify risks and trends across the organization. • Strong compliance programs depend on collaboration between leadership, clinical teams, operations, legal counsel, information technology, and frontline staff. • Compliance committees become more effective when members actively participate in discussions and help identify organizational priorities. • A just culture approach helps organizations address incidents fairly while encouraging staff to report concerns and potential compliance issues. • Privacy and HIPAA training become more meaningful when employees understand how compliance directly impacts patients, families, and their local communities. • Successful compliance management requires flexibility, strategic prioritization, strong communication with leadership, and a willingness to adapt when unexpected challenges arise. Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    The Best Ways to Manage Compliance In a Critical Access Hospital w/ Denise Lord
  5. Jun 9

    How Important Is Information Security In Healthcare Compliance w/ Joe Wynn

    Information security plays a critical role in healthcare compliance, risk management, and organizational resilience. In this episode of Compliance Deconstructed, Jessica Zeff, Lorie Davis, and special guest Joe Wynn, Founder & CEO of Seiso, break down the foundational elements of an effective information security program and explain why protecting sensitive data requires a structured approach that extends beyond technology solutions. This in-depth conversation explores the importance of conducting comprehensive risk assessments to identify vulnerabilities, evaluate threats, and prioritize security efforts based on potential impact. The hosts also discuss practical safeguards such as multi-factor authentication, data backups, software patching, access controls, and employee training that help healthcare organizations strengthen their security posture and reduce exposure to cybersecurity risks. Jessica, Lorie, and Joe also address common misconceptions surrounding HIPAA compliance, SOC 2 reports, and security attestations while highlighting emerging concerns related to website tracking technologies and third-party data sharing. After consuming this episode, you’ll gain actionable insights into building a sustainable information security strategy that supports regulatory compliance, protects patient information, and promotes long-term organizational success. Key Takeaways: • Risk assessments provide the foundation for identifying security gaps, evaluating threats, and prioritizing remediation efforts across the organization. • Multi-factor authentication, secure backups, regular software updates, access management, and employee education remain essential components of a strong security program. • Healthcare organizations should understand that there is no official HIPAA certification and that compliance requires ongoing oversight and accountability. • SOC 2 reports evaluate security controls and can support broader compliance initiatives when paired with regulatory assessments. • Website cookies, tracking scripts, and third-party marketing tools can create privacy and compliance risks when organizations do not fully understand how data is collected and shared. • Information security requires continuous evaluation, process improvement, and cross-functional collaboration to protect sensitive information and maintain regulatory compliance. Connect with Joe Wynn Website | LinkedIn Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    How Important Is Information Security In Healthcare Compliance w/ Joe Wynn
  6. May 26

    A Comprehensive Breakdown of Medicaid In Healthcare Compliance

    In this episode of Compliance Deconstructed, Jessica Zeff joins co-hosts Elvan Baker and Lorie Davis to unpack one of the most operationally complex areas of healthcare compliance: Medicaid and the realities of navigating state-specific healthcare programs. The reality is Medicaid is not a single national program with standardized rules, and organizations often underestimate how much variation exists between states when it comes to eligibility, benefits, managed care structures, provider enrollment, and compliance obligations. Jessica, Elvan, and Lorie explore how Medicaid differs from Medicare and private insurance while discussing why compliance professionals, providers, and health plans cannot rely on assumptions when entering new Medicaid markets. From a compliance standpoint, this becomes especially important when organizations expand across state lines and discover that processes tied to credentialing, appeals, grievances, staffing, reporting, and oversight may look completely different depending on the state administering the program. The conversation also examines the balance between federal oversight from the Centers for Medicare & Medicaid Services and the flexibility states have to design their own Medicaid programs through waivers, managed care arrangements, and operational structures. On paper, this may sound straightforward. But operationally, this becomes challenging when organizations attempt to align compliance, legal, IT, clinical operations, and leadership teams around requirements that are often layered across contracts, appendices, policy manuals, and state guidance documents. Jessica, Elvan, and Lorie also share practical strategies for approaching Medicaid compliance in a structured and sustainable way, including conducting detailed gap analyses, building operational playbooks, mapping information flow, and training teams on state-specific requirements. A lot of organizations struggle with treating Medicaid compliance like a one-time implementation project, when in practice it requires ongoing monitoring, collaboration, and operational adaptability to manage risk effectively while supporting patient access and organizational stability. Key takeaways from this episode: Medicaid programs vary significantly from state to state, including eligibility rules, covered services, managed care structures, and provider participation requirements.Compliance professionals should avoid assuming that experience in one Medicaid program automatically translates to another state’s program.CMS provides federal oversight, but states maintain substantial flexibility through waiver programs, managed care models, and operational design decisions.Provider enrollment, credentialing, appeals and grievances, staffing requirements, and reporting obligations often differ substantially across states.Conducting a detailed gap analysis helps organizations identify operational, compliance, staffing, and technology requirements before entering a Medicaid market.Successful Medicaid compliance requires collaboration across compliance, operations, legal, clinical, IT, and leadership teams to ensure policies translate into day-to-day operational execution. Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    A Comprehensive Breakdown of Medicaid In Healthcare Compliance
  7. May 12

    A Comprehensive Guide to Understanding MIPS

    Healthcare providers continue to face growing pressure to improve patient outcomes while meeting evolving regulatory expectations, and this episode of Compliance Deconstructed breaks down how the Merit-based Incentive Payment System (MIPS) shapes modern healthcare compliance and quality reporting. Jessica Zeff, Lorie Davis, and Elvan Baker explain how MIPS creates measurable standards for quality care and why healthcare organizations need a practical strategy for managing performance across multiple reporting categories. The conversation explores the four pillars of MIPS, including Quality, Cost, Improvement Activities, and Promoting Interoperability, while providing real-world examples of how these metrics impact healthcare providers on a daily basis. The hosts discuss how quality measures influence patient care workflows, how cost tracking affects reimbursement, and why interoperability continues to play a growing role in coordinated healthcare delivery. Once you press play, you’ll gain actionable insights into how healthcare organizations can build stronger compliance processes by integrating MIPS requirements directly into clinical operations and electronic health record systems. This episode also highlights the importance of monitoring performance data consistently, engaging in ongoing improvement activities, and understanding the reasoning behind quality measures instead of approaching reporting as a checkbox exercise. Jessica, Lorie, and Elvan bring an approachable perspective to a topic that often feels overwhelming for healthcare professionals navigating compliance obligations and government reporting programs. Their discussion provides healthcare leaders, administrators, and compliance professionals with a clearer understanding of how MIPS participation can support operational efficiency, strengthen patient outcomes, and position organizations for long-term success in value-based care environments. Key takeaways from this episode: MIPS was created to measure and incentivize quality healthcare delivery across the Medicare system.The Quality category evaluates providers using detailed performance measures tied to patient outcomes and treatment standards.Cost measures examine healthcare spending patterns and help identify opportunities for more efficient care delivery.Improvement Activities encourage providers to invest in continuous education, workflow enhancements, and patient-centered initiatives.Promoting Interoperability focuses on secure electronic health record communication and coordinated care between providers.Successful MIPS participation requires proactive workflow integration, consistent performance monitoring, and a strong understanding of reporting requirements. Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    A Comprehensive Guide to Understanding MIPS
  8. Apr 28

    Your HEDIS Action Plan: Tips & Strategies to Help Your Practices

    HEDIS measures, developed by the National Committee for Quality Assurance, provide a standardized framework for evaluating healthcare quality across health plans and provider organizations. In Episode 24 of Compliance Deconstructed, Jessica Zeff and Lorie Davis break down how the Healthcare Effectiveness Data and Information Set (HEDIS) supports consistent performance measurement and drives improved patient outcomes. Today’s conversation explores how HEDIS measures track key areas such as preventative care, chronic disease management, behavioral health, access to care, and patient experience. These categories help healthcare organizations identify whether patients are receiving evidence-based services, while also highlighting opportunities to improve engagement and care delivery. Jessica and Lorie explain the HEDIS data collection process, including the use of claims data, chart chase efforts, and medical record abstraction to validate performance. This process ensures that healthcare organizations capture accurate and complete data, which is essential for reporting, regulatory compliance, and quality improvement initiatives. The episode also emphasizes the importance of identifying and closing care gaps, along with the critical role compliance plays in maintaining data integrity, privacy, and adherence to regulations. By integrating compliance into every stage of HEDIS planning and execution, healthcare organizations can reduce risk, support accreditation efforts, and strengthen overall performance. Key Takeaways: HEDIS measures provide a standardized system for evaluating healthcare quality and performance across organizationsThe framework tracks essential areas including preventative care, chronic disease management, and patient experienceAccurate data collection relies on claims data, chart chases, and detailed medical record abstractionCare gaps identify missed healthcare services and create opportunities for targeted patient outreachCompliance ensures regulatory adherence, data security, and ethical handling of patient informationA proactive, year-round HEDIS strategy supports improved outcomes, stronger reporting, and organizational success Don't miss this year's HCCA Conference in Pittsburgh! Click here for all the info. Learn more about Healthcare Compliance and discover how Simply Compliance can help your company at simplycomplianceconsulting.com.

    Your HEDIS Action Plan: Tips & Strategies to Help Your Practices

Ratings & Reviews

About

Welcome to Compliance Deconstructed, a podcast dedicated to all things Healthcare Compliance.Hosted by Healthcare Compliance professionals Jessica Zeff, Lorie Davis, and Elvan Baker, each episode thoroughly breaks down the complex inner-workings of compliance in the healthcare industry.From the 7 Elements that make up Healthcare Compliance to AI's impact on the industry and everything in between, Compliance Deconstructed is your resource for information, strategy, and commentary to elevate your knowledge base. Click play and join us for an episode today!