Skip to Main Content
 
Thought Leadership

False Claims Act Insights—Boardroom FCA: Strategic Decisions That Create or Prevent False Claims Act Exposure

 
Podcast

     

Host Jonathan Porter welcomes Husch Blackwell partner Drew Canning to discuss False Claims Act risk from the boardroom perspective. While most FCA episodes focus on legal theories, enforcement trends, or specific cases, this conversation examines the strategic and operational decisions that boards and executives make every day—decisions that can either prevent FCA exposure or inadvertently create it. For board members, general counsels, and executives overseeing organizations that receive federal funds, this episode offers practical guidance on navigating FCA risk at the decision-making level.

We begin with strategic decision-making under uncertainty. Drew walks through a scenario many boards face: your company wants to acquire a business with questionable billing practices. How do you help the board decide whether to fix the problems post-acquisition or walk away entirely? We discuss the due diligence process, how to quantify FCA risk in acquisition modeling, and when regulatory uncertainty becomes too significant for a board to reasonably accept. This isn’t theoretical—these decisions happen regularly in healthcare, government contracting, and other industries where federal funds flow, and getting them wrong can mean inheriting someone else’s FCA liability.

Next, we examine operational decisions that create FCA exposure, often without anyone realizing it at the time. Drew explores where the line sits between reasonable cost-cutting and cutting compliance too thin. We discuss how budget decisions, staffing levels in compliance departments, and pressure to meet financial targets can quietly create the conditions for billing errors or certification failures that later become FCA cases. We also tackle a cutting-edge issue: what FCA risks do health systems face when deploying AI for coding and billing? As organizations increasingly adopt AI tools to improve efficiency, boards need to understand that these technologies can scale compliance failures just as easily as they scale legitimate operations.

Our conversation then turns to the compliance investment dilemma. How does a board know if it’s spending enough on compliance? Drew explains that there’s no magic formula or industry benchmark that works across the board, but there are warning signs when compliance resources are inadequate: high turnover in compliance roles, repeated billing errors, or compliance staff consistently raising concerns that get overruled by operations or finance. We discuss the concept of “good enough” compliance and when that mindset actually becomes a problem, particularly in industries where the government is a major payor and FCA exposure is always present.

We close by examining culture, incentives, and accountability. Drew discusses how boards should respond when a compliance failure comes to light—is termination always the answer, or are there situations where retraining and process improvement make more sense? We explore how boards can structure incentives that don’t inadvertently reward behavior that creates FCA risk, and how to ensure the board is getting the full picture from management rather than a sanitized version that downplays problems. Drew emphasizes that boards need to create an environment where compliance concerns can surface early, before they become government investigations.

Throughout the episode, we focus on practical, actionable guidance rather than abstract legal theory. The decisions boards make about acquisitions, cost structure, compliance investment, and organizational culture have direct FCA implications, and this episode equips listeners to recognize and manage those risks before they become enforcement actions.

Jonathan Porter | Full Biography

Jonathan focuses on white collar criminal defense, federal investigations brought under the False Claims Act, and litigation against the government and whistleblowers. He draws on his experience as a former federal prosecutor to guide clients in sensitive and enterprise-threatening litigation. At the Department of Justice, Jonathan earned a reputation as a top white-collar prosecutor and trial lawyer and was a key member of multiple international healthcare fraud takedowns and high-profile financial crime prosecution teams. He also teaches white-collar crime as an adjunct professor of law at Mercer University School of Law.

Drew Canning | Full Biography

Drew offers clients legal solutions alongside healthcare regulatory experience. He practices from Cincinnati, Ohio as a member of our virtual office, The Link. Drew regularly advises hospitals, health systems, payors, and providers on transactional and regulatory matters including health care affiliations, mergers, acquisitions and changes of control; licensure and certification; payor reimbursement; compliance with Stark Law and Anti-Kickback Statute; and state health boards oversight and enforcement. With firsthand knowledge of how quickly healthcare law changes and the challenges companies face in responding, Drew now brings this insight to clients from the other side of the table. He especially enjoys that, in healthcare matters, all parties are working toward the greater good of patient care.

Read the Transcript

This transcript has been auto generated

00;00;00;00 - 00;00;24;26

Jonthan Porter

Welcome to another episode of Husch Blackwell's False Claims Insights podcast. I'm your host, Jonathan Porter. Here's a question most board members never ask themselves. When did we decide to commit fraud? The answer, of course, is never. No board votes to violate the False Claims Act. But here's what they do. Vote on cutting compliance staff to hit margin targets.

00;00;24;27 - 00;00;51;21

Jonthan Porter

Approving AI tools that code faster but with less oversight. Greenlighting an acquisition even though due diligence flagged some questionable billing. Designing bonus structures that reward volume over accuracy. By the time the complaint gets unsealed, the fraud has a name, a relator, and a dollar figure. But it started years earlier in a conference room as a spreadsheet decision that seemed perfectly reasonable at the time.

00;00;51;23 - 00;01;17;29

Jonthan Porter

Today on the podcast, we're talking about the decisions that boards make every day, that create or prevent False Claims Act exposure. How do you know if you're spending enough on compliance, or if good enough has quietly become a problem? Where's the line between smart cost management and cutting compliance too thin? And when regulatory uncertainty is high, how does a board decide whether to fix a problem or walk away entirely?

00;01;18;01 - 00;01;38;12

Jonthan Porter

These aren't questions about fraud, they’re questions about governance. But in the world of the False Claims Act, that distinction doesn't matter nearly as much as boards think it does. Joining me to talk about governance is my law partner, Drew Canning. Drew and I sit on exact opposite ends of the enforcement spectrum. I'm who you call when you get a CID or a subpoena.

00;01;38;14 - 00;02;01;12

Jonthan Porter

Drew is who you call when your board or your C-suite is making decisions so that one day you don't get the CID or subpoena. Drew's a healthcare lawyer through and through helping clients make decisions that keep them on the right side of the compliance line. And so, Drew, welcome to the podcast. Thanks for joining us and telling our listeners a little bit about governance and how it relates to the False Claims Act.

00;02;01;15 - 00;02;17;17

Drew Canning

Thank you, Jonathan, and I'm happy to be here and especially to discuss this. I think your introduction is very apt. If I'm ever in a courtroom or taking a deposition, something's gone severely wrong. My goal is to not spend any part of my legal career in either situation.

00;02;17;24 - 00;02;39;01

Jonthan Porter

My goal is to not get in your lane either. So that's why we're teaming up so well here, Drew. So let's start by talking about the strategic decision making under FCA uncertainty. So when a company you're advising wants to say acquire a business with maybe say questionable billing practices, how do you help the board decide whether to fix it or to walk away?

00;02;39;03 - 00;03;07;09

Drew Canning

Yeah, it's not an easy decision. It's what we're paid for that counsel and advice to provide that insight. But I would like to take a step back and, you know, to provide some more context as to what the board should really be keeping in mind when they're weighing such decisions. I think in 2025 alone, the settlements and judgments under the False Claims Act exceeded 6.8 billion, and I think over 80% of that was tied to the health care industry.

00;03;07;11 - 00;03;37;20

Drew Canning

That same year, whistleblowers amounted to almost 1300 qui tam suits. I think that was record breaking, surpassing 2024. We know that the DOJ has put some added attention on this with its update to its compliance guidance, with its flagging of managed care risk practices and its heightened scrutiny of medical unnecessary care. I think that all just says that the False Claim Act isn't static, it's still well-worn, it's still being used.

00;03;37;20 - 00;04;00;05

Drew Canning

And I think it's something that boards cannot escape whenever they're making such decisions as who are we going to acquire? Who are we going to merge with, and how does that best serve our industry? So that said, I think the best starting point for a board is no longer post-closing problems to be dealt with. It's a pricing in a structural problem that has to be resolved before signing any agreements.

00;04;00;08 - 00;04;30;18

Drew Canning

As you know, the current DOJ doctrine, its successor liability is very much a concern and it's unavoidable for any buyer. I like to compartmentalize any issues that they would be finding with a target in any merger, acquisition as a cultural issue or an operational issue, if it's systemic from how the organization is operated, its people, its culture, that is going to be widespread and rampant, and it's going to necessitate added diligence.

00;04;30;18 - 00;05;00;05

Drew Canning

And truly, the board needs to weigh is that something that they can even correct or modify post-close. If it's an operational issue, it's quantifiable and it is more an issue of neglect or ignorance. There's a clear path to resolving it and addressing it either in the purchase price, the valuation, escrow terms, indemnification structures. All that's to say is that strategic decision making has to be informed by appropriate and prudent at diligence.

00;05;00;08 - 00;05;24;08

Drew Canning

The DOJ's own compliance evaluation framework gives the board a concrete diagnostic to consider. You know, they're going to look at whether the acquires completed pre acquisition due diligence. They're going to look whether misconduct or its risk was identified during that diligence. And who conducted the risk review. They're going to analyze whether the compliance function was integrated into the merger and acquisition and post transaction process.

00;05;24;08 - 00;05;42;20

Drew Canning

You know, are we updating our policies? Are we changing the personnel that are overseeing it? Are we implementing that organizational changes that should be identified? And that's why, again, that distinction between operational versus cultural, is it a known, quantifiable, correctable problem or is it an unknown structural cultural one?

00;05;42;23 - 00;06;02;04

Jonthan Porter

Yeah. Drew, I'm with you there. And you'd be surprised how often that does come up in investigations where there have been acquisitions or mergers and the question is, what exactly did you know when you were acquiring this other company? Unless in some asset purchase agreement you're acquiring their liabilities. And what did you do? What did you know? Should you have figured out more?

00;06;02;04 - 00;06;23;03

Jonthan Porter

That comes up a lot, because health care now there's a lot of M&A practices booming in health care. And there's this added M&A angle that's making FCA very, very interesting. And so Drew, there's a lot of regulatory uncertainty in health care. I know it comes up in deals all the time. Standard governance decisions all the time. There's a lot of regulatory uncertainty in health care.

00;06;23;06 - 00;06;30;14

Jonthan Porter

How much regular regulatory uncertainty is too much for a board to accept. How do you walk boards through that issue?

00;06;30;15 - 00;06;57;05

Drew Canning

Yeah, uncertainty itself as ground that raises the bar for what boards need before they can even calibrate the risk. You look at the recent court decisions like Wisconsin Bell and Zafirov, where we've seen that any amount of federal government reimbursement can can tie to the claim and the whole mechanism of a qui tam action. I think all that just tells a board that this is an ever present issue and it's not going away.

00;06;57;07 - 00;07;31;00

Drew Canning

On the enforcement posture side, I think the uncertainty is compounding. We know that the DOJ is actively pursuing investigations of pharma practices and price fixing, price inflation, copay assistance programs, stuff like that. You know, we know that HHS has again, continued to partner with DOJ in their working groups, and they've committed to cross-agency coordination. At the same time, if you look back in 2025, the DOJ has also increased its use of dismissing its authority.

00;07;31;00 - 00;07;55;24

Drew Canning

And so I think the framework there is that the DOJ continues to have more attention, resources and robust interest in this. At the same time, they're being more prudent about the types of cases and investigations that they're performing. Again, it lends itself to the uncertainty that the boards have to weigh. At the end of the day, the DOJ’s own framework starts by asking whether the company understood its risk profile and better the appropriate resources for that.

00;07;55;27 - 00;08;15;19

Drew Canning

That's going to be a shifting approach depending on the type of industry, the type of acquisition, the type of conduct that's involved. At the end of the day, the board needs to stay as informed as possible and ensure that it has the tools and resources that are actually providing it accurate and actionable information.

00;08;15;21 - 00;08;39;09

Jonthan Porter

Thanks, Drew. Those are great points. One thing that I think our listeners would value hearing is about operational decisions that create False Claims Act exposure. A lot of times when you have a merger or acquisition, there's a lot of questions about, well, how is this acquired company doing things? Is there a way for us to streamline things, cut some costs and therefore do better as a business?

00;08;39;12 - 00;08;49;09

Jonthan Porter

But there's risk there. So Drew, when your accounts and clients, where's the line between reasonable cost cutting and then cutting compliance too thin? What do you tell clients about that issue?

00;08;49;11 - 00;09;08;11

Drew Canning

I think we'd start with looking at where this is coming from. The DOJ prosecutors are instructed to ask whether the compliance program is adequately resourced and empowered to function effectively. They're not just looking for something that exists on paper. And this includes whether the company has ever denied resources requested from a compliance and control functions, and on what grounds.

00;09;08;17 - 00;09;40;15

Drew Canning

With regards to cost cutting, it's got to be vetted, whether it touches on compliance staffing, audit frequency, hotline investigation capacity. That's the exact kind of decision the DOJ will reconstruct after the fact. I think there's a difference between cutting a redundant vendor contract versus not providing the resources to fully staff a compliance program. And I think any of our organizations that are accepting federal reimbursement, Medicare or Medicaid, Tricare causes more material risk.

00;09;40;17 - 00;10;14;10

Drew Canning

And so, again, for an adequate compliance program, I think the board needs to evaluate where are we seeing reimbursement, what is in line for us to actually carry out the required rules around that? And I draw the line cost kind of becomes an issue when the moment it impacts detection capability rather than administrative overhead. So if we lose hotline investigation staff or delaying scheduled risk assessments, those change affect whether the organization could find its own problems before the government does.

00;10;14;13 - 00;10;33;05

Drew Canning

I know it's probably not an easy decision for the board to get to that level. But, you know, like any good lawyers, we're not going to give you a specific response. It's going to be tailored towards the entity to meet it where it's at. And I think getting that information to the board, whether it impacts detection capability, will inform that decision.

00;10;33;08 - 00;10;54;17

Jonthan Porter

Thanks. Sure. Yeah, I think that's the right way to view it. And that's why again, I'm glad you're giving our clients this advice on the front end and not me because that's excellent advice. Speaking of cost cutting, one of the big ways that people are going to cut costs in the future is through. I, I know that you talk a lot about AI in your practice and in speeches and everything, so I want to make sure we talk about AI here for a second.

00;10;54;19 - 00;11;11;06

Jonthan Porter

What risks do you see in, say, health systems using AI for coding and billing and let me just say, Drew, you're welcome to talk as long as you want on this. But we could probably do a standalone podcast on this one. So why don't you just give our listeners just the highlights of using AI for coding and billing?

00;11;11;06 - 00;11;36;20

Drew Canning

Yeah, absolutely. And earlier this year, Rob Gerberry from HLA and I presented the Ohio Hospital Association just on this one topic, and it was truly advising the board and management and C-suite on how are you adequately addressing AI within your organization? And I think the key takeaway there is making a distinction between front end and back in office, making a distinction between clinical decision making and administrative.

00;11;36;22 - 00;12;00;15

Drew Canning

If we're talking about an AI system that helps with scheduling, that's one thing. If we're talking about another that's in charge of coding reimbursement and assessing any patients, that's a different issue. I think you treat it up, really. We can go on forever about this topic, but it's one of the fastest moving areas right now. And we already know that the DOJ is actively monitoring AI for potential violation of the False Claims Act.

00;12;00;15 - 00;12;32;09

Drew Canning

I believe there's a recent issue with University of Colorado Health, where an unexamined AI protocol was automatically reevaluated and CPT codes and changed them to the highest level of care. And I think there is a multimillion dollar settlement that came out of that. We already know just from the DOJ AI own use case inventory that, you know, I think in 2025 it was up to over 300 entries, and they're going to continue to find ways to use it on their side, which means that our clients and organizations and our systems

00;12;32;12 - 00;13;02;01

Drew Canning

they need to be using it on their side, too. I think how boards appropriately oversee the implementation of AI within their organization matters. I think three specific patterns worth naming is a set it and forget it approach. And that's kind of what we saw in the University of Colorado situation. And that's one size fits all. And something where there isn't a human in the loop in oversight as to what's been documented and created, especially if it's being used for reimbursement and clinical decision making.

00;13;02;03 - 00;13;25;25

Drew Canning

I think, you know, there's the generative AI drafting code where stuff is hallucinating, where diagnoses are being made up, and the paper trail is inaccurate. I think the last is any black box vendor algorithms. That's to say an entity can't hide behind its vendor contracts. They can't hide behind the algorithm or the code. At the end of the day, it's responsible for the submission of claims.

00;13;25;25 - 00;13;46;29

Drew Canning

It's responsible for the care that's provided, and they have to own that. You know, I would also say that the DOJ's own evaluation of corporate compliance programs explicitly now asks whether a company is assessing the impact of AI on the ability to comply with the law, and they're going to vet whether AI risk is integrated into the enterprise risk management framework.

00;13;46;29 - 00;14;23;05

Drew Canning

And I think when we saw the updated compliance program protocols, boards have to monitor whether AI trustworthiness and reliability is actually being monitored. And I think a few practical mitigation techniques to ensure that there's IT representation on the board meetings, establishing a dedicated subcommittee that's monitoring this. I think the changing environment of AI could easily lend itself to monthly updates, but that would be overwhelming for a board, and certainly that would pull the board more into the daily administrative task and the management task.

00;14;23;05 - 00;14;46;16

Drew Canning

And again, that's should be left to your C-suite folks. I think the other practical mitigation tips is keeping the human in the loop and ensuring that the right algorithms are being tested, and building contract guardrails with those vendors so that truly, the board knows the purpose, the intent, the case argument as to why these vendor contracts and agreements are being adopted and pursued to begin with.

00;14;46;18 - 00;15;12;19

Drew Canning

Don't just take on these AI contracts without having a use case scenario of what it's trying to solve for. And a lot of that's going to be informed by your front end personnel, your staff saying, we need this, this will help, and this is what it's supposed to address. Following up and then monitoring whether those AI contracts and software and services are actually addressing that use case scenario that it was originally proposition for, is the realm of the board to ensure that they're monitoring that.

00;15;12;22 - 00;15;33;15

Jonthan Porter

Thanks, Drew. Yeah. So I think I've said I think I've said it on this podcast. I know I've said it in conferences and to clients. If you're using AI to replace things that humans would have caught, DOJ is not going to look at that favorably. Courts aren't either. Juries certainly aren't. And so AI is great. I love AI, I use AI that is not going to be a good defense for you is I'm sorry.

00;15;33;15 - 00;15;53;13

Jonthan Porter

The AI told me to do the thing that ended up being wrong. So Drew, thanks for that. I think another thing that clients struggle with is the exact levels of investments in their compliance programs. I know that I got a call last year from someone saying, hey, like on average, what portion of the budget should go towards compliance?

00;15;53;13 - 00;16;09;16

Jonthan Porter

I said, I have no idea. That's really outside of my wheelhouse, but clients are looking for benchmarks or norms, so let's talk about that. So how does a board know if it's spending enough on diligence? I guess both in time and in attention. Yeah.

00;16;09;16 - 00;16;39;19

Drew Canning

And you know, I'd say there's no fixed percentage of revenue rule, but I think there's a few points that boards can actually use and know first is pure benchmarking. What is everybody else doing in the same or similar situation. Second, the structural sufficiency rather than a dollar amount. And third, reporting cadence as a proxy for engagement. So you're looking at peer benchmarking, consult the industry standard ranges and know whether your sized entity is within line.

00;16;39;21 - 00;17;01;22

Drew Canning

I don't think there's a sitting on the shelf answer for are we spending enough? Are we monitor and do we have a good compliance program. And then with the structural insufficiency again, the DOJ is going to specifically ask whether the compliance funding requests have ever been denied and on what grounds, and whether the compliance staffing is sufficient to audit, document, analyze and act on the findings.

00;17;01;22 - 00;17;20;00

Drew Canning

And I guess, you know, you had raised this kind of in the merger and acquisition context. I'm thinking of a more just a holistic approach. You have your risk management personnel, you have your compliance program, whether they're being tasked to a merger and acquisition situation or whether they're just being tasked with day to day operations. I think it's the same result.

00;17;20;00 - 00;17;48;22

Drew Canning

And that's just truly whether there's a mechanism to measure the results of the audits and act on the findings. You know, you bring this up, and I guess we've been talking a lot about the board level, and I think we're ignoring the fact that there's a structural blind spot as to what's actually being reported to the board. And regardless of budget size and regardless of what's being put into practice, what the board hears is largely what management decides to share.

00;17;48;25 - 00;18;23;04

Drew Canning

And it's a balance of avoiding information overload and ensuring that the board members aren't overwhelmed. I think at the end of day, a well-funded compliance program that only reports upward through management isn't actually giving the board what it needs to judge. Sufficiency. And that's why I always like to see a separation of reporting or mechanism, or a way that those board members can individually interact with those risk management personnel to ensure that they're getting the full story, or at least that the information in a way that best serves the board.

00;18;23;06 - 00;18;56;26

Jonthan Porter

Yeah, and that's certainly a structural problem that DOJ is aware of is when the compliance function is allowed to have roadblocks. I remember sitting in a DOJ conference room talking about how if only you'd had a dotted line up to the board, then this could have been resolved. I remember having those conversations. That's a very real thing. And of the few things that DOJ actually knows about well-functioning compliance programs, I can tell you that is one, is that you can't have something that is designed to avoid the board finding out about the bad things.

00;18;56;29 - 00;19;11;16

Jonthan Porter

I don't know a lot about this is why I call you Drew, but that is one thing I am sure of, is you need the dotted line up to the board, because you can't have a situation where the board just doesn't find out about the bad things. Drew, when does a good enough compliance actually become a problem? Tell us about that.

00;19;11;23 - 00;19;41;17

Drew Canning

I mean, I think the line falls exactly when the paper program stops being a functioning one. The guidance distinguishes sharply between the compliance program that exists on paper and one that is implemented, resourced, reviewed, revised in an effective manner. And importantly, the mere fact that misconduct occurs doesn't automatically mean that the program wasn't effective. You can't stop criminal activity of employees, and I think on that level, I only use the terms that I, you know, management personnel should give themselves grace.

00;19;41;17 - 00;20;04;02

Drew Canning

But we're not here to prevent at 100% everything that occurs because certain situations will occur no matter what, under any well funded resource program. And what does good enough look like? I think what matters is whether the program had a track record of detecting the issue, and whether the organization did the honest root cause work afterward. I think that refrains good enough in a useful way.

00;20;04;07 - 00;20;27;05

Drew Canning

The test isn't zero incidents, it's whether the program catches its own problems and then effectively evolved after the fact. If the same situations keep occurring. And I think that's really telling. If we can't even detect anything to begin with, we don't have an effective program. And furthermore, whatever exists on paper, I feel like, again, we had started this whole discussion on the mergers and acquisitions side of things.

00;20;27;05 - 00;20;46;04

Drew Canning

And in that due diligence, we're requesting tons and tons of information. And after so many transactions, you kind of start to realize, oh, that's great that this is all exist on paper, what's actually put in practice, and rarely is it ever 100% what's on paper is actually being carried out. And again, that's kind of where we pointed back to those cultural issues.

00;20;46;06 - 00;21;14;17

Drew Canning

And operational humans like stories. They like repetition. They're like habits and then habits become practice. And then because the five people before me did it this way, I'm going to do it that way. And that's informing the issues that kind of begin to start systematically bubbling up. And again, a working good enough compliance program should identify those. And then it would require the board to then act on it.

00;21;14;19 - 00;21;28;17

Drew Canning

Good enough becomes inactive. Specifically when it substitutes documentation for our detection. Checking every box on that OIG seven elements is good, but it needs to be put into practice.

00;21;28;19 - 00;21;48;02

Jonthan Porter

Thanks, Drew. And yeah, and I think what you're saying here ties back to how we sort of started our conversation. It's about culture. It's about the culture of the organization. I think sometimes the culture is driven by how boards act when the bad things come to light. And so let's spend a few minutes talking about what happens when compliance things get reported up to the boards.

00;21;48;05 - 00;22;02;09

Jonthan Porter

When you're advising boards that have these important compliance problems come to them, how should a board actually handle it when those compliance problems come to light? Termination? Retraining? Something else? Tell us about those conversations that you have with your clients boards.

00;22;02;12 - 00;22;32;11

Drew Canning

I think the response has to match the root cause and the root cause. Analysis has to come before the remedy is chosen, not after. Boards and management often default to policy revisions or structural realignment, rather than addressing an individual performance directly. Throughout this, hard conversations are going to have to be had either weighing the investment, addressing the behavior of personnel, or at the end of the day, whatever did go wrong was the responsible party and oversight of someone, and some people slide.

00;22;32;15 - 00;23;02;29

Drew Canning

The board is in the position to own that, take care of it and force change. And again, that response has to match the issue that was detected or that occurred. And the DOJ’s own framework gives the board a structured way to think about it proportionately, rather than defaulting to either extreme. They look at whether disciplinary measures and consequences have been fairly and consistently applied across the organization, and whether similar instances of misconduct were treated disparately.

00;23;03;01 - 00;23;26;13

Drew Canning

You know, I think we're seeing more and more where the DOJ has pursued settlement payments directly from individual executives because of this as an outcrop of this. And it certainly we're seeing that in cases of kickback schemes, telehealth billing and inflated risk adjustment coding. Again, you know, we'd kind of come to this talking about culture and what do you do when you find a problem?

00;23;26;16 - 00;23;40;07

Drew Canning

I think a board that treats a serious compliance failure is purely a corporate problem. To be resolved with a settlement check is out of step range from where the enforcement is actually heading. That's not what you want to see.

00;23;40;09 - 00;23;54;15

Jonthan Porter

Yeah, that's not what you see. Drew agree with you there. So Drew, final question for you. How does a board make sure it's getting the full picture, not just what it wants to see? Finish that thought. Tell us about that and close this out on that point.

00;23;54;17 - 00;24;14;27

Drew Canning

Yeah I think we kind of discussed a little bit of this earlier and kind of mentioned some of that just information asynchrony that just naturally occurs. I think one concrete low cost mechanism is private executive sessions between the board or the board committee and senior leadership, whether it be the chief compliance officer, the CFO or the general counsel.

00;24;15;04 - 00;24;40;29

Drew Canning

And that's separate and apart from an open board meeting. I think that lends itself to candor, clarity in those board meetings, senior leaders don't always speak up, kind of diminishing, maybe some concerns or additional insight that they might have to offer that the board can act on. Again, I think when we're evaluating the compliance activity, we got to ask whether the board or the audit committee has held those private sessions.

00;24;40;29 - 00;25;02;03

Drew Canning

And I think it shows that the board is concerned about it. Their attempting to get at the right information and to act upon it. It's not just good practice, it's specific factor that can be weighed after the fact. A second lever to ensure that we're getting the full picture is trend data rather than incident reports. How have we performed over the last year?

00;25;02;03 - 00;25;36;08

Drew Canning

What are we seeing? And it kind of paints a better picture as to where the organization is going. Again, asking whether the compliance function has full access to reporting and investigative information is an element that the DOJ would want to see. And then whether the organization tracks and analyzes that data for patterns, rather than just reporting on one off incidences and giving a little one off report at this board meetings. A third, I'd say maybe the most direct answer is the board members need to ask themselves, am I only getting what management wants me to see?

00;25;36;10 - 00;25;58;08

Drew Canning

And they need to stay curious. They need to understand, okay, you told me this and maybe just, you know, repeating back what they're being informed about and to ensure that they know what they're saying. I know in healthcare there's plenty of acronyms, there's plenty of mind numbing reports. And I think acknowledging that the information that they are receiving is supposed to serve a purpose and they need to question it

00;25;58;08 - 00;26;13;11

Drew Canning

just goes a long way of making sure that it's an active conversation as opposed to a passive, rote experience. Again, kind of the fear that it only exists on paper and it's not actually being considered and operationalized.

00;26;13;14 - 00;26;28;28

Jonthan Porter

Thanks, Drew. Those are excellent points. I want to thank you for coming on the podcast. We talk a lot about investigations here, but when I hear from listeners that we do the proactive governance conversations, they value those a lot. So, Drew, thanks for coming on the podcast. I think our listeners are going to get a lot out of this.

00;26;28;28 - 00;26;30;16

Jonthan Porter

So thanks for joining us.

00;26;30;16 - 00;26;34;05

Drew Canning

Thank you so much, Jonathan. Happy to come back on the next topic.

00;26;34;08 - 00;26;56;19

Jonthan Porter

To close, there will be more next topics. There's so much happening in health care and government contracting and everything. And so we're going to continue to bring on smart people from the farm and elsewhere to talk about all things that can lead to False Claims Act enforcement, where we talk about the big cutting issues, like the Zafirov case where the 11th Circuit decided that qui tams are, in fact, constitutional.

00;26;56;22 - 00;27;08;03

Jonthan Porter

And so we're going to talk about all those things and more on the podcast. And so, Drew, thanks again for coming. And to our listeners, we appreciate you. And we'll see you next time.

Professionals:

Drew A. Canning

Partner