CASE STUDY: Centene Corporation. Compliance 360 GRC Software Suite

Size: px
Start display at page:

Download "CASE STUDY: Centene Corporation. Compliance 360 GRC Software Suite"

Transcription

1 CASE STUDY: Centene Corporation Compliance 360 GRC Software Suite

2 2 CASE STUDY: Centene Corporation Background Centene Corporation is a leading multi-line healthcare enterprise that provides programs and related services to individuals receiving benefits under Medicaid, including Supplemental Security Income (SSI) and the State Children s Health Insurance Program (SCHIP). The Company operates Medicaid health plans in Georgia, Indiana, New Jersey, Ohio, South Carolina, Texas and Wisconsin. In addition, the Company contracts with other healthcare and commercial organizations to provide specialty services including behavioral health, life and health management, long-term care, managed vision, nurse triage, pharmacy benefits management and treatment compliance. Founded in 1984, this St. Louis based company went public in 2001, and has grown rapidly in recent years. Challenges With over $2.9 billion in annual revenues, Centene faces a complex regulatory environment. In addition to the department of insurance, its customers state Medicaid programs - are Centene s primary regulators. State Medicaid contracts With Compliance 360 GRC System Centene has: Eliminated sanctions for late filings and failures to notify Improved Wisconsin state policy and procedure compliance from 15% to 98% Improved compliance with Texas state requirements for complaint tracking from 15% non compliance to 100% compliance Reduced time spent managing policies and procedures by 95% Reduced time spent on corrective action plans by 70% Reduced time spent preparing annual regulatory reports by 75%

3 CASE STUDY: Centene Corporation 3 constitute the bulk of its regulatory requirements. Grounded in the Federal Medicaid Managed Care Regulations that were part of the Balanced Budget Act of 1997, these requirements are often more detailed than a commercial health plan s department of insurance regulations, and can vary from one state to the next, in terms of both the regulatory content and enforcement regimes. Furthermore, compliance with other federal and state regulations are often incorporated by reference in these contracts (i.e., the Health Insurance Portability Act and Deficit Reduction Act of 2005). Centene s regional and corporate offices face far more frequent and substantial reporting requirements than a comparable commercial health plan, and the consequences for failure to file or late filing can be significant. Non-compliance with reporting requirements carries the risk of administrative penalties and can also lead to the potential loss of the entire contract. This places a heavy burden on corporate risk administrators, who need to have a clear real-time assessment of regulatory risk while avoiding tying the hands of its regional compliance staff members. Objectives With SAI Global It was in this multi-state context of rapid growth and ornate state and federal regulatory requirements that Centene decided in 2005 to partner with SAI Global to help manage its compliance environment. The objectives behind this decision were to: 1. Strengthen the effectiveness of the compliance program; 2. Reduce overall risks and increase visibility to help ensure that regulatory requirements were being met; and 3. Reduce the cost of compliance through standardization and automation. According to Robert Miromonti, Vice President of Ethics and Compliance, Centene began using the Compliance 360 GRC System as a tool for automating the corporate code of conduct. While our people are the primary solution to the problem of regulatory risk, Compliance 360 is the tool they use. What s telling is that we haven t had a material compliance failure since we ve started using Compliance 360. Karen Fain Vice President of Internal Audit Training an ever growing employee base on an evolving code of conduct was an important yet time consuming task. Once that function was up and running, Centene turned to improving its compliance risk reporting. In Centene s Medicaid world, compliance with State contracts is the primary compliance risk and Miromonti wanted more transparency of subsidiary risk at the corporate level. Chasing paper at Centene s regional sites soaked up a lot of time and energy, with inconsistent results. Compliance 360 has enabled us to eliminate that paper chase and we now have the documentation to support compliance efforts at our fingertips. Other tasks for which Centene has used the Compliance 360 GRC System include the management of state contract compliance; corrective action plans; regulator, provider and consumer complaints; tracking regulatory reporting; maintaining policies and procedures; and

4 4 CASE STUDY: Centene Corporation tracking regulatory incidents. Yet, with all these critical needs addressed, Centene continues to broaden its use of Compliance 360. New applications are being found for the software, and the use of Compliance 360 is being expanded into new areas including accreditation and the management of quality improvement projects ( QIPs ). William Kruegel, Director, Compliance and Regulatory Affairs for Centene s New Jersey based University Health Plans (UHP), is particularly interested in unleashing the organizational power of Compliance 360 on the plan s quality improvement activities. These activities are currently managed based on a 45 page quality plan. Kruegel expects using Compliance 360 to track the various activities, which include highlighting operational components to meet HEDIS, NCQA and state contract requirements, will create significant operational efficiencies for the company. How Centene Reduces Its Compliance Risks When any healthcare organization looks at its compliance risk profile, it sees a variety of potential landmines. These risks are in some ways more substantial in the case of a Medicaid contractor like Centene: Like commercial health plans, Medicaid plans face risks of regulatory actions such as fines and other administrative penalties from health and insurance regulators. In Arizona, for example, under the state contract for acute care and long-term care services, the penalty for filing a report late is $5,000 for the first occurrence, and increases to $10,000 for the second late report, according to Nicole Larson, Director, Compliance, for Centene s Arizona based Bridgeway Health Solutions. With the state acting not only as regulator but also as the sole purchaser of Medicaid plans services, the plans run the additional risk of losing the contract entirely in the event of a pattern of non-compliance. Regulatory fines pale in comparison to this risk of a catastrophic loss of 100 percent of a plan s business in a state and the resulting damage to the organization s reputation. Karen Fain, Centene s Vice President, Internal Audit notes, If you meet or exceed state contract requirements, you have a good shot at renewal. If not, you can lose the entire deal. As a result of this risk, the top priority of Centene s compliance team, even above limiting the costs of its compliance programs, is the elimination of these risks of noncompliance. Ms. Fain, adds, Even if there were no cost savings, Compliance 360 would be worth it for the comfort level in knowing we re identifying and addressing non-compliance risks as they emerge. Kruegel came to the company in mid In his short tenure at UHP, he has become a power user of Compliance 360. A few of his comments about his experience go to the heart of the software s capacity to reduce the risk of non-compliance: We utilize Compliance 360 to assist us in tracking our compliance with the State Medicaid contract, which is over 250 pages long. The care management, prior authorization, network standards and other contract requirements are in most cases, more stringent than a commercial carrier would face, and the contract governs about 90% of our regulatory requirements. Compliance 360 is particularly helpful in identifying performance gaps and managing our remediation efforts to close those gaps. When I came on board, I saw several sanction letters from the state, often around failure to

5 CASE STUDY: Centene Corporation 5 notify, respond in a timely manner, or file regulatory reports. For example, in 2004, our plan had a fine and a corrective action plan ( CAP ) for the late filing of the New Jersey Department of Banking and Insurance Annual Supplement. In 2005, the company received a fine for failure to notify the Department of Human Services of a termination notice received from a network hospital. Since I arrived in 2006, however, and started using Compliance 360 to track these requirements, we haven t incurred a single administrative penalty of this type. Compliance 360 really is a helpful tool at audit time. When the regulators make a request for certain documents in the middle of an audit, I simply search on a key word or run an evidence room report, and all the documents I need to produce for the regulators are retrieved in seconds. So, not only can I produce these documents quickly, I can document the details of my response to the auditors while I am in the system. In a recent audit by our external quality review organization (EQRO), having Compliance 360 s capability to produce the correct versions of documents quickly and manage compliance activities was actually cited as a best practice by the auditors in their report. One significant risk to any regulated organization lies in its ability to respond to regulatory directives. Regulators are well known for looking more harshly on violations pointed out in previous examinations that haven t been fixed, compared to newly discovered problems. Therefore, when Texas insurance regulators told Centene s Texas affiliate, Superior Health Plan, that they believed Superior s complaint numbers were so low as to suggest poor complaint tracking, the company turned to Compliance 360 to make sure the corrective action plan was implemented quickly and effectively. Jamey Phillips, the Lead Complaint Coordinator for Superior, used Compliance 360 to assure that Superior had a comprehensive complaint system resulting in efficient logging, tracking, retention and resolution of complaints. The Compliance 360 GRC System enables the Complaint Unit to provide regulators and internal staff with periodic reports on those complaints. In the four months prior to implementation the tracking of consumer complaints, the average number of captured complaints identified was 36 per month; in the two months after implementation, the average number was 65, an 80 percent increase in Compliance 360 really is a helpful tool at audit time... In a recent audit by our external quality review organization (EQRO), having Compliance 360 s capability to produce the correct versions of documents quickly and manage compliance activities was actually cited as a best practice by the auditors in their report. William Kruegel, Director, Compliance and Regulatory Affairs for University Health Plans complaints. Similarly, the number of provider complaints captured per month tripled, from 4 to 12 complaints. Phillips reports that the use of Compliance 360 for complaint tracking not only has helped Superior respond to the regulators demand to centralize the complaint process, but also has improved compliance with the state s complaint record-keeping requirements. The 2007 state audit revealed a 15 percent rate of non-compliance with those requirements, while a recent re audit showed 100 percent compliance with the state record keeping rules. This is a perfect

6 6 CASE STUDY: Centene Corporation example of the flexibility of Compliance 360 to meet our compliance needs, states Miromonti. We identified a gap and were able to quickly configure the system to remediate it. Jan Larson, Director, Quality Improvement and Compliance for Managed Health Services, reports an even more dramatic improvement in compliance levels. Her estimate of policy and procedure compliance before the implementation of Compliance 360 at Managed Health Services - Wisconsin was as low as 15 percent. A recent audit revealed that this compliance level is now approximately 98 percent. When responding to regulators, the most significant risk comes up in the context of corrective action plans. Sara Neale, Centene s Director, Ethics and Compliance, described how Compliance 360 has helped: We had a routine administrative audit in Arizona that resulted in a corrective action plan. The state sent a Word document for us to use to track the action plan and report back to the state. The challenge for us was that there were simply too many supporting documents for us to do this effectively. With Compliance 360, we were able to organize and manage the volumes of documentation. To manage the internal process of implementing the CAP, we can sort and report by responsible parties and give each individual access to a report specific to him/her. Furthermore, we can provide instantaneous reporting and supporting documentation to the state whenever required. Now, Neale reports, three years later, when the company gets audited on these same requirements, it is easy to bring the reports up-to-date and respond quickly and thoroughly to the audit. A notable development in managed care in the past decade has been the increased use of contractors for the performance of delegated services. This has also expanded the management of risk, as the non-compliance of contractors with regulatory or contract requirements can be imputed to the health plan, particularly if there is inadequate delegation oversight. To address that risk, Kruegel says, we ve begun using Compliance 360 to monitor our contractor s reporting requirements and timeframes for deliverables. Through this oversight tracking mechanism, we now have a way to easily scorecard our contractors and ensure regulatory and contract compliance. The system made it amazingly easy for me to certify compliance to the federal regulators. Robert Miromonti Vice President of Ethics and Compliance As any state or federal health care contractor knows, there is an intimate relationship between some operational issues and contract compliance. When Centene experienced an operational break down at one of its subsidiaries, the Compliance 360 GRC System was used to assess performance and detect the root cause of the issue. Miromonti reports that when the corporate Compliance department got involved and looked at root causes, it became apparent that there was no adequate tracking mechanism. They worked with the subsidiary to develop a tracking mechanism that is now used company wide to reduce the risk of non compliance. Centene s experience shows that the risky world of whistle blowing can be made a bit less risky

7 CASE STUDY: Centene Corporation 7 with Compliance 360. Recently, according to Miromonti, an employee brought an allegation that Centene was not compliant with a state contract requirement. Rather than having to plow through reams of paper or rely on he said/she said debates, the compliance assessment capacity of Compliance 360 allowed a relatively easy resolution of the complaint. The health plan had documented the company s compliance with the provisions that were the subject of the dispute, corroborating Centene s claim that it was in full compliance with the provisions. All we needed to do was review the evidence documented in Compliance 360 and validate that we were following the established procedures said Miromonti. The speed of the resolution helped Centene prevent a potential regulatory sanction and proactively send a clear message of status in control to regulators. The real value of Compliance 360 to Centene in reducing regulatory risk was noted succinctly by Karen Fain, Centene s Vice President of Internal Audit; While our people are the primary solution to the problem of regulatory risk, Compliance 360 is the tool they use. What s telling is that we haven t had a material compliance failure since we ve started using Compliance 360 to manage state contract compliance. How Centene Proactively Identifies Compliance Issues Too often, regulators are the first to discover a company s compliance problems. At that point, it can be too late for the regulated company to do anything to avoid sanctions. The federal sentencing guidelines note that an effective compliance program has the ability to seek out and find areas of non-compliance within the company. While Centene had an internal audit process in place, Miromonti decided that it would be important to augment that process with a compliance dashboard that allowed him to see - in real-time - where each of the subsidiaries were in terms of compliance with the state contracts. Miromonti turned to the Compliance 360 GRC System for this capability. Bridgeway s Nicole Larson noted that the risk management dashboard system allows senior staff to check compliance levels at any time. The system does much more than track levels of compliance, though. Compliance 360 allows us to assign tasks, set up projects, and track deliverables such as reports we provide to the state, Larson noted. Miromonti reports that the reporting features afforded by the risk management dashboard are a lifesaver. The dashboard consolidates all the data, all the reports, he notes. When we went live with Compliance 360, we went to instantaneous report-running. Now we have unlimited access to the data and can drill down as deep as we need - there s no longer a need to chase paper at the subsidiaries, because we now have immediate access to the issues and supporting documentation. We can run reports by new risks identified, open risks and risk categories. Prior to Compliance 360, we spent a significant amount of time tracking and consolidating reports. What would take the department a day or two each month to complete now is instantaneous. We now spend that time working with the subsidiaries on remediation efforts. As Centene proactively develops new dimensions to its compliance dashboard, it continues to uncover and address new compliance risks. An example of this occurred as Neale worked with the claims department on its dashboard. In developing the dashboard, Sara noticed that the claims department had inadvertently set internal standards that were lower than those required by the state. As a result of catching this error early, Centene was able to align its internal

8 8 CASE STUDY: Centene Corporation standards with the state s requirements and avert a potential regulatory problem. How Centene Reduces Compliance Overhead Costs Compliance executives at Centene report an ever-expanding set of uses for Compliance 360. One of the early adopters in the company was Kruegel, who says he uses the software to track anything and everything. He uses Compliance 360 not only to manage policies and procedures, as do most of his colleagues in the other regions, but also to track all correspondence with any regulatory agency. Kruegel records each regulatory letter received, schedules any follow-up tasks that flow from the correspondence, what the required information is for the response, the due date, the person responsible for the response, and the date the actual response was submitted. Thus, Kruegel notes, he can monitor on a daily basis, the status of any response. He finds this particularly helpful when multiple departments are responsible for generating a response. Without Compliance 360, this task would be very difficult and time consuming, with a significant risk of disconnects and missed steps. This is not a small portion of his work - by the end of July, Kruegel s department alone had received over 620 communications in 2008 from state regulators. Kruegel estimates that using Compliance 360 eliminates 75 percent of the staff time this task would consume. Kruegel finds even more dramatic savings in the time it takes to manage the other functions under his responsibility. He reports savings of roughly: 95 percent of the time required to manage his company s policies and procedures; 70 percent of the time required to work on corrective action plans; 75 percent of the time required to plan each year s regulatory reports. Centene uses the Compliance 360 GRC System to assess its current status and its readiness to assume new business. Miromonti had previously completed HIPAA compliance assessments using a generic tool, a project that took three to four months from assessment to final report generation. He estimates that this task consumes less than a week when done on Compliance 360, a time savings of over 95 percent. In addition, Compliance 360 s reporting capabilities allow him to provide daily reports on the assessment if needed. Bridgeway s Nicole Larson routinely uses the system to assess Bridgeway s readiness for new contract amendments, assigning projects and due dates for those projects. One of the interesting things to note about using Compliance 360 on corrective action plans ( CAPs ) is that it allows the compliance department to involve colleagues in the functional units of the company in the execution of the CAP. Kruegel notes that before we started using Compliance 360, I was much more involved in the nitty-gritty of implementing the CAPs. Now, with Compliance 360 s superior tracking and communication capabilities, I can entrust implementation to the people in the various departments who should be doing it and still keep the implementation rolling along at the proper pace. As mentioned, above, managing regulatory reporting is another source of significant savings gained through the use of Compliance 360. Kruegel reports that the New Jersey plan alone must file 15 quarterly reports, 10 semiannual reports, and 54 annual reports, one of which involves the input of more than 20 people because it is a compilation of data across multiple

9 CASE STUDY: Centene Corporation 9 departments. His Arizona counterpart, Nicole Larson, estimates that she spends about 8 hours per month on regulatory reporting with Compliance 360, compared to her estimated 2-3 FTEs that were required without the software, a savings of roughly 98 percent for this task. The Compliance 360 GRC System has helped Centene manage its rapid growth across 17 states over the last few years. Rhonda Galaske, Centene s Manager, Operational Policy, reports that the number of Centene s policies and procedures, company-wide, have nearly tripled, from 1,543 in 2005 to 4,073 in Yet, even with that explosive growth, Galaske uses Compliance 360 to eliminate one month of an employee s time per quarter in the task of managing and reporting on their policies and procedures. Prior to the implementation of Compliance 360 all polices required a physical signature to approve the document. The original copy was kept at the subsidiary and a copy was sent to the corporate office for tracking purposes. Jan Larson, Director, Quality Improvement and Compliance for Centene s Wisconsin plan, Managed Health Services, reports that the easy reporting of the status of policies and procedures that Compliance 360 provides is good for reminding policy owners. Galaske reports that this element of the system has allowed Centene to turn the ownership of managing policies back over to the business units. This creates a sense of ownership and accountability with the people who actually use the policies on a day-to-day basis. This staff savings from the use of Compliance 360 extends to the regional plans, as well. Bridgeway s Nicole Larson spends less than 1 percent of her time managing the plan s 160 policies, and noted that it would take between one and two FTEs to do the same job without the help of Compliance 360. Regulators and external auditors periodically require organizations to submit attestations regarding corporate training. Historically, this has been a time-consuming and error-prone process for organizations like Centene. A couple of examples of Centene s use of Compliance 360 Accountability is increased by encouraging the development of a culture of timely updates to the compliance assessment system and transparency regarding the compliance challenges subsidiaries face. Robert Miromonti Vice President of Ethics and Compliance highlight the software s usefulness in performing this function: Code of Conduct. Centene must annually survey its employees (now numbering about 3,400) regarding its Code of Conduct. Employees must attest that they have read the code and disclose any compliance issues or potential conflicts of interest. The Compliance Department must verify that each employee has responded, and investigate any of the disclosed issues or conflicts. Compliance 360 provides the attestation verification automatically and employees that have issues requiring further investigation can be instantaneously identified through reporting. This process saves the Compliance Department two man-months per year by reducing the administrative process of tracking paper documents.

10 10 CASE STUDY: Centene Corporation HLOGA and LDA. Centene s Government Relations department needed to address a federal requirement to conduct widespread training on the Honest Leadership and Open Government Act of 2007 (HLOGA) and the Lobbying Disclosure Act (LDA). Miromonti and his staff used Compliance 360 s Survey Module to rollout training and test employee understanding of the requirements. The organization was able to educate 90 percent of the nearly 3,400 employees within a month. The system made it amazingly easy for me to certify compliance to the federal regulators, reports Miromonti. Furthermore, I was able to use the system to distribute and track subcertifications from all employees directly involved in lobbying activities. A theme that is consistent across all of Centene s executives is the value of Compliance 360 s real-time reporting. Centene s executives report substantial savings from this capability. The real-time reporting function of Compliance 360 is excellent, notes Jamey Phillips of Superior Health Plan, Instead of having to go through a spreadsheet and calculate data, the software generates a full report with virtually no effort. The system is very efficient, especially for monthly reports. Before Compliance 360 came into use, it took 15 hours to report both member and provider complaints; after Compliance 360, it takes only two hours. Beyond the staff time savings, Nicole Larson reports a heightened accountability that results from real-time, comprehensive reporting provided by Compliance 360. Everybody knows who is responsible for what tasks, and when those tasks are due, she notes. Miromonti sees this increased accountability at the corporate level, too, as the company-wide reporting rolls up to a monthly corporate executive report. Accountability is increased by encouraging the development of a culture of timely updates to the compliance assessment system and transparency regarding the compliance challenges subsidiaries face, he concludes.

11 USA Europe Australia Asia Plainsboro, NJ T: +1 (877) 470-SAIG [7244] F: Warwickshire, UK T: +44 (0) F: +44 (0) Sydney T: F: Jakarta T: Waltham, MA T: F: Melbourne T: F: Alpharetta, GA T: F: Perth T: F: Houston, TX T: F: About SAI Global Compliance SAI Global Compliance is the world leader in providing organizations with a wide range of governance, risk and compliance (GRC) products, services and technology that help build organizational integrity and effectively manage compliance risk. Our global staff includes professionals and subject matter specialists in advisory services; program design, management and implementation; instructional design; and software development. Our focus is to help establish and enhance compliance effectiveness. With well over a thousand organizations as clients and tens of millions of satisfied users around the world, we work with clients to integrate a flexible suite of solutions and services specifically tailored for a business and industry. Our products include the world s largest library of compliance and ethics learning, Code of Conduct advisory services and training, and the Compliance 360 GRC Software Suite to manage compliance, policy, incident and audit management. Our Cintellate EH&S Software addresses key issues in operational environmental health and safety management. For more information, please call us at the full service location nearest you or visit 2012 SAI Global Ltd. The SAI Global name and logo, the Cintellate name and ListenUp name are trademarks of SAI Global Ltd. Compliance 360 and Virtual Evidence Room are registered trademarks of Compliance 360, Inc., an SAI Global company. All Rights Reserved. CSCCBR1210a

Enterprise Risk Management in Compliance 360

Enterprise Risk Management in Compliance 360 Enterprise Risk Management in Compliance 360 2 Enterprise Risk Management in Compliance 360 Effective risk management involves identifying and understanding the risks the organization is faced with, analyzing

More information

Policy Management Compliance 360 GRC Software Suite

Policy Management Compliance 360 GRC Software Suite Policy Management Compliance 360 GRC Software Suite 2 Compliance 360 Software Suite: Policy Management Introduction Policies and procedures are the underpinning of any governance, risk and compliance (GRC)

More information

CASE STUDY: St. Joseph Medical Center. Compliance 360 GRC Software Suite

CASE STUDY: St. Joseph Medical Center. Compliance 360 GRC Software Suite CASE STUDY: St. Joseph Medical Center Compliance 360 GRC Software Suite 2 CASE STUDY: St. Joseph Medical Center Background Since June 1, 1887, when the doors opened at Houston s first hospital, St. Joseph

More information

Managing EHS Incidents Using Integrated Managment Systems. By Matt Noth

Managing EHS Incidents Using Integrated Managment Systems. By Matt Noth Managing EHS Incidents Using Integrated Managment Systems By Matt Noth 2 Managing EHS Incidents Using Integrated Managment Systems Introduction Most organizations have been managing safety and environment-related

More information

CASE STUDY: EMQ FamiliesFirst. Compliance 360 GRC Software Suite

CASE STUDY: EMQ FamiliesFirst. Compliance 360 GRC Software Suite CASE STUDY: EMQ FamiliesFirst Compliance 360 GRC Software Suite 2 Case Study: EMQ FamiliesFirst EMQ FamiliesFirst Saving Grace for California s Children and Families in Need EMQ FamiliesFirst (www.emqff.org/about/index.shtml)

More information

Safe and Healthy Workplace Environments using Effective Industrial Hygiene Management Systems. By Matt Noth

Safe and Healthy Workplace Environments using Effective Industrial Hygiene Management Systems. By Matt Noth Safe and Healthy Workplace Environments using Effective Industrial Hygiene Management Systems By Matt Noth 2 Safe and Healthy Workplace Environments Using Effective Industrial Hygiene Management Systems

More information

EHS Management Software Making the right choice for your business

EHS Management Software Making the right choice for your business EHS Management Software Making the right choice for your business Practical steps for choosing the right software solution to manage your EHS performance & compliance 2 Practical steps for choosing the

More information

Emptoris Contract Management Solution for Healthcare Providers

Emptoris Contract Management Solution for Healthcare Providers Emptoris Contract Management Solution for Healthcare Providers An Emptoris White Paper Emptoris, an IBM Company www.emptoris.com CMS-HP-4/12 Emptoris Contract Management Solution for Healthcare Providers

More information

ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES

ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES THOMSON REUTERS ACCELUS ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES PROACTIVE. CONNECTED. INFORMED. THOMSON REUTERS ACCELUS Compliance management Solutions Introduction The advent of new and pending

More information

White Paper: The Seven Elements of an Effective Compliance and Ethics Program

White Paper: The Seven Elements of an Effective Compliance and Ethics Program White Paper: The Seven Elements of an Effective Compliance and Ethics Program Executive Summary Recently, the United States Sentencing Commission voted to modify the Federal Sentencing Guidelines, including

More information

Automated IT Asset Management Maximize organizational value using BMC Track-It! WHITE PAPER

Automated IT Asset Management Maximize organizational value using BMC Track-It! WHITE PAPER Automated IT Asset Management Maximize organizational value using BMC Track-It! WHITE PAPER CONTENTS ADAPTING TO THE CONSTANTLY CHANGING ENVIRONMENT....................... 1 THE FOUR KEY BENEFITS OF AUTOMATION..................................

More information

WHITE PAPER. Automated IT Asset Management Maximize Organizational Value Using Numara Track-It! p: 813.227.4900 f: 813.227.4501 www.numarasoftware.

WHITE PAPER. Automated IT Asset Management Maximize Organizational Value Using Numara Track-It! p: 813.227.4900 f: 813.227.4501 www.numarasoftware. WHITE PAPER By Tony Thomas Senior Network Engineer and Product Manager Numara TM Software Inc. ADAPTING TO THE CONSTANTLY CHANGING IT ENVIRONMENT The challenge in controlling the corporate IT infrastructure

More information

Self-Service SOX Auditing With S3 Control

Self-Service SOX Auditing With S3 Control Self-Service SOX Auditing With S3 Control The Sarbanes-Oxley Act (SOX), passed by the US Congress in 2002, represents a fundamental shift in corporate governance norms. As corporations come to terms with

More information

UMDNJ COMPLIANCE PLAN

UMDNJ COMPLIANCE PLAN UMDNJ COMPLIANCE PLAN INTRODUCTION...2 COMPLIANCE OVERSIGHT 3 COMPLIANCE COMMITTEE STRUCTURE...4 CHIEF COMPLIANCE OFFICER S RESPONSIBILITIES...5 RESEARCH COMPLIANCE.5 UNIT IMPLEMENTATION.6 COMPLIANCE POLICIES

More information

Case Study Success with a. into a Corporate Integrity Agreement (CIA)

Case Study Success with a. into a Corporate Integrity Agreement (CIA) Case Study Success with a Corporate Integrity Agreement (CIA) More than 100 affiliated physician practices and healthcare facilities Operations in multiple states More than 2,000 Covered Persons under

More information

Demonstrating the ROI for SIEM: Tales from the Trenches

Demonstrating the ROI for SIEM: Tales from the Trenches Whitepaper Demonstrating the ROI for SIEM: Tales from the Trenches Research 018-101409-01 ArcSight, Inc. 5 Results Way, Cupertino, CA 95014, USA www.arcsight.com [email protected] Corporate Headquarters:

More information

Compliance Requirements for Healthcare Carriers

Compliance Requirements for Healthcare Carriers INFORMATION DRIVES SOUND ANALYSIS, INSIGHT REGULATORY COMPLIANCE ADVISORY Compliance Requirements for Healthcare Carriers Introduction With the introduction of the new healthcare exchanges in January 2014

More information

AlienVault for Regulatory Compliance

AlienVault for Regulatory Compliance AlienVault for Regulatory Compliance Overview of Regulatory Compliance in Information Security As computers and networks have become more important in society they and the information they contain have

More information

Aegon Global Compliance

Aegon Global Compliance Aegon Global Compliance GLOBAL Charter COMPLIANCE CHARTER aegon.com The Hague, June 1, 2013 Information sheet Target audience: All employees and management of Aegon companies Issued by: Aegon N.V. Group

More information

Customer Data and Reputational Risk in the Pharmaceutical Industry

Customer Data and Reputational Risk in the Pharmaceutical Industry 1 Customer Data and Reputational Risk in the Pharmaceutical Industry Sensitive Data: A Chain of Trust Organizations of all types, from banks to government agencies to healthcare providers, are taking steps

More information

Sarbanes-Oxley: Beyond. Using compliance requirements to boost business performance. An RIS White Paper Sponsored by:

Sarbanes-Oxley: Beyond. Using compliance requirements to boost business performance. An RIS White Paper Sponsored by: Beyond Sarbanes-Oxley: Using compliance requirements to boost business performance The business regulatory environment in the United States has changed. Public companies have new obligations to report

More information

GUIDANCE FOR MANAGING THIRD-PARTY RISK

GUIDANCE FOR MANAGING THIRD-PARTY RISK GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,

More information

438 ADMINISTRATIVE SERVICES SUBCONTRACTOR EVALUATION

438 ADMINISTRATIVE SERVICES SUBCONTRACTOR EVALUATION 438 ADMINISTRATIVE SERVICES SUBCONTRACTOR EVALUATION EFFECTIVE DATE: 10/01/14, 06/01/15,07/01/16 REVISION DATE: 05/07/15, 02/04/16 STAFF RESPONSIBLE FOR POLICY: DHCM OPERATIONS I. PURPOSE This Policy applies

More information

IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP

IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP IT Audit Perspective on Continuous Auditing/Continuous Monitoring INTRODUCTION New demands from the board, senior organizational

More information

Compliance. TODAY June 2012. Meet Lanny A. Breuer. Assistant Attorney General, Criminal Division, U.S. Department of Justice.

Compliance. TODAY June 2012. Meet Lanny A. Breuer. Assistant Attorney General, Criminal Division, U.S. Department of Justice. Compliance TODAY June 2012 a publication of the health care compliance association www.hcca-info.org Meet Lanny A. Breuer Assistant Attorney General, Criminal Division, U.S. Department of Justice See page

More information

Safety Management Program

Safety Management Program Corrective Action Plan (CAP) Safety Management Program Submitted by TransCanada PipeLines Limited and its National Energy Board Regulated Subsidiaries to address non-compliant findings in the National

More information

Managing data security and privacy risk of third-party vendors

Managing data security and privacy risk of third-party vendors Managing data security and privacy risk of third-party vendors The use of third-party vendors for key business functions is here to stay. Routine sharing of critical information assets, including protected

More information

NEW PERSPECTIVES. Professional Fee Coding Audit: The Basics. Learn how to do these invaluable audits page 16

NEW PERSPECTIVES. Professional Fee Coding Audit: The Basics. Learn how to do these invaluable audits page 16 NEW PERSPECTIVES on Healthcare Risk Management, Control and Governance www.ahia.org Journal of the Association of Heathcare Internal Auditors Vol. 32, No. 3, Fall, 2013 Professional Fee Coding Audit: The

More information

Faster, Smarter, More Secure: IT Services Geared for the Health Care Industry A White Paper by CMIT Solutions

Faster, Smarter, More Secure: IT Services Geared for the Health Care Industry A White Paper by CMIT Solutions Faster, Smarter, More Secure: IT Services Geared for the Health Care Industry A White Paper by CMIT Solutions Table of Contents Introduction... 3 1. Data Backup: The Most Critical Part of any IT Strategy...

More information

DEMONSTRATING THE ROI FOR SIEM

DEMONSTRATING THE ROI FOR SIEM DEMONSTRATING THE ROI FOR SIEM Tales from the Trenches HP Enterprise Security Business Whitepaper Introduction Security professionals sometimes struggle to demonstrate the return on investment for new

More information

Seven Rules of Thumb for Post-Trade Compliance

Seven Rules of Thumb for Post-Trade Compliance A Confluence Whitepaper Seven Rules of Thumb for Post-Trade Compliance What Fund Administrators Need to Know A growing body of regulations governing investment portfolio management has expanded both the

More information

RSA ARCHER OPERATIONAL RISK MANAGEMENT

RSA ARCHER OPERATIONAL RISK MANAGEMENT RSA ARCHER OPERATIONAL RISK MANAGEMENT 87% of organizations surveyed have seen the volume and complexity of risks increase over the past five years. Another 20% of these organizations have seen the volume

More information

General HIPAA Implementation FAQ

General HIPAA Implementation FAQ General HIPAA Implementation FAQ What is HIPAA? Signed into law in August 1996, the Health Insurance Portability and Accountability Act ( HIPAA ) was created to provide better access to health insurance,

More information

February 2015. Audit committee performance evaluation

February 2015. Audit committee performance evaluation February 2015 Audit committee performance evaluation Audit committee performance evaluation The following questionnaire is based on emerging and leading practices to assist in the self-assessment of an

More information

solution brief NEC Remote Managed Services Prevent Costly Communications Downtime with Proactive Network Monitoring and Management from NEC

solution brief NEC Remote Managed Services Prevent Costly Communications Downtime with Proactive Network Monitoring and Management from NEC NEC Remote Managed Services Prevent Costly Communications Downtime with Proactive Network Monitoring and Management from NEC NEC Remote Managed Services: Removing the Complexities of Communications Network

More information

Meeting the HIPAA Training and Business Associate Requirements Questions and Answers, with HIPAA Security Expert Mike Semel

Meeting the HIPAA Training and Business Associate Requirements Questions and Answers, with HIPAA Security Expert Mike Semel Meeting the HIPAA Training and Business Associate Requirements Questions and Answers, with HIPAA Security Expert Mike Semel Questions Answers 1 Is a Business Associate (BA) responsible for assuming a Covered

More information

STATE STANDARDS FOR ACCESS TO CARE IN MEDICAID MANAGED CARE

STATE STANDARDS FOR ACCESS TO CARE IN MEDICAID MANAGED CARE Department of Health and Human Services OFFICE OF INSPECTOR GENERAL STATE STANDARDS FOR ACCESS TO CARE IN MEDICAID MANAGED CARE Suzanne Murrin Deputy Inspector General for Evaluation and Inspections September

More information

SPECIAL REPORT: KYC AND AML POLICY IMPLEMENTING BEST PRACTICE IN AN EVER-CHANGING REGULATORY ENVIRONMENT

SPECIAL REPORT: KYC AND AML POLICY IMPLEMENTING BEST PRACTICE IN AN EVER-CHANGING REGULATORY ENVIRONMENT SPECIAL REPORT: KYC AND AML POLICY IMPLEMENTING BEST PRACTICE IN AN EVER-CHANGING REGULATORY ENVIRONMENT INTRODUCTION Heightened expectations from regulators have created an ever-more demanding regulatory

More information

WHY CONTRACTORS AUTOMATE TIME AND ATTENDANCE

WHY CONTRACTORS AUTOMATE TIME AND ATTENDANCE WHY CONTRACTORS AUTOMATE TIME AND ATTENDANCE FROM A LEADER IN WORKFORCE MANAGEMENT SOLUTIONS www.mitcsoftware.com INTRODUCTION Labor costs are the largest controllable expense for most contractors. Contractors

More information

Protecting Business Information With A SharePoint Data Governance Model. TITUS White Paper

Protecting Business Information With A SharePoint Data Governance Model. TITUS White Paper Protecting Business Information With A SharePoint Data Governance Model TITUS White Paper Information in this document is subject to change without notice. Complying with all applicable copyright laws

More information

Establishing a Mature Identity and Access Management Program for a Financial Services Provider

Establishing a Mature Identity and Access Management Program for a Financial Services Provider Customer Success Stories TEKsystems Global Services Establishing a Mature Identity and Access Management Program for a Financial Services Provider FINANCIAL SERVICES NETWORK INFRASTRUCTURE SERVICES INFORMATION

More information

Securing Patient Portals. What You Need to Know to Comply With HIPAA Omnibus and Meaningful Use

Securing Patient Portals. What You Need to Know to Comply With HIPAA Omnibus and Meaningful Use Securing Patient Portals What You Need to Know to Comply With HIPAA Omnibus and Meaningful Use September 2013 Table of Contents Abstract... 3 The Carrot and the Stick: Incentives and Penalties for Securing

More information

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS As a world leader in electronic commerce and payment services, First Data Corporation and its subsidiaries ( First Data entity or entities ),

More information

2016 OCR AUDIT E-BOOK

2016 OCR AUDIT E-BOOK !! 2016 OCR AUDIT E-BOOK About BlueOrange Compliance: We specialize in healthcare information privacy and security solutions. We understand that each organization is busy running its business and that

More information

How to choose a financial planner

How to choose a financial planner How to choose a financial planner And get the most out of the relationship Page 1 Choosing a financial planner can often seem the hardest step in getting professional financial advice. Consumer research

More information

CHARTER FOR THE THE REGULATORY, COMPLIANCE & GOVERNMENT AFFAIRS COMMITTEE CHARTER THE BOARD OF DIRECTORS

CHARTER FOR THE THE REGULATORY, COMPLIANCE & GOVERNMENT AFFAIRS COMMITTEE CHARTER THE BOARD OF DIRECTORS CHARTER FOR THE THE REGULATORY, COMPLIANCE & GOVERNMENT AFFAIRS COMMITTEE CHARTER OF THE BOARD OF DIRECTORS OF Copyright/permission to reproduce Materials in this document were produced or compiled by

More information

POLICY SUBJECT: EFFECTIVE DATE: 5/31/2013. To be reviewed at least annually by the Ethics & Compliance Committee COMPLIANCE PLAN OVERVIEW

POLICY SUBJECT: EFFECTIVE DATE: 5/31/2013. To be reviewed at least annually by the Ethics & Compliance Committee COMPLIANCE PLAN OVERVIEW Compliance Policy Number 1 POLICY SUBJECT: EFFECTIVE DATE: 5/31/2013 Compliance Plan To be reviewed at least annually by the Ethics & Compliance Committee COMPLIANCE PLAN OVERVIEW Sound Inpatient Physicians,

More information

INSPECTOR GENERAL STATEMENT ON THE FEDERAL COMMUNICATIONS COMMISSION S MAJOR MANAGEMENT CHALLENGES FISCAL YEAR 2005

INSPECTOR GENERAL STATEMENT ON THE FEDERAL COMMUNICATIONS COMMISSION S MAJOR MANAGEMENT CHALLENGES FISCAL YEAR 2005 INSPECTOR GENERAL STATEMENT ON THE FEDERAL COMMUNICATIONS COMMISSION S MAJOR MANAGEMENT CHALLENGES FISCAL YEAR 2005 05-AUD-04-08 November 15, 2005 Office of Inspector General ******* Federal Communications

More information

Understanding the HIPAA standard transactions: The HIPAA Transactions and Code Set rule

Understanding the HIPAA standard transactions: The HIPAA Transactions and Code Set rule Understanding the HIPAA standard transactions: The HIPAA Transactions and Code Set rule Many physician practices recognize the Health Information Portability and Accountability Act (HIPAA) as both a patient

More information

Accountable Care Organization. Medicare Shared Savings Program. Compliance Plan

Accountable Care Organization. Medicare Shared Savings Program. Compliance Plan Accountable Care Organization Participating In The Medicare Shared Savings Program Compliance Plan 2014 Corporate Location: 3190 Fairview Park Drive Falls Church, VA 22042 ARTICLE I INTRODUCTION This Compliance

More information

Compliance Program and HIPAA Training For First Tier, Downstream and Related Entities

Compliance Program and HIPAA Training For First Tier, Downstream and Related Entities Compliance Program and HIPAA Training For First Tier, Downstream and Related Entities 09/2011 Training Goals In this training you will gain an understanding of: Our Compliance Program elements Pertinent

More information

Addressing common challenges in the record-to-report process. kpmg.com

Addressing common challenges in the record-to-report process. kpmg.com Addressing common challenges in the record-to-report process kpmg.com Addressing common challenges in the record-to-report process Laeeq Ahmed, managing director, KPMG Meilani Hendrawidjaja, director,

More information

2012 HIPAA Privacy and Security Audits

2012 HIPAA Privacy and Security Audits Office of the Secretary Office for Civil Rights (OCR) 2012 HIPAA Privacy and Security Audits Linda Sanches OCR Senior Advisor, Health Information Privacy Lead, HIPAA Compliance Audits OCR 1 Agenda Background

More information

SUBJECT: FRAUD AND ABUSE POLICY: CP 6018

SUBJECT: FRAUD AND ABUSE POLICY: CP 6018 SUBJECT: FRAUD AND ABUSE POLICY: Department of Origin: Compliance & Audit Responsible Position: Vice President of Compliance and Audit Date(s) of Review and Revision: 07/10; 04/11; 11/11; 02/12; 6/12;

More information

Health Sciences Compliance Plan

Health Sciences Compliance Plan INDIANA UNIVERSITY Health Sciences Compliance Plan 12.18.2014 approved by University Clinical Affairs Council Table of Contents Health Sciences Compliance Plan I. INTRODUCTION... 2 II. SCOPE... 2 III.

More information

2/9/2012. 2012 HIPAA Privacy and Security Audit Readiness. Table of contents

2/9/2012. 2012 HIPAA Privacy and Security Audit Readiness. Table of contents 2012 HIPAA Privacy and Security Audit Readiness Mark M. Johnson National HIPAA Services Director Table of contents Page Background 2 Regulatory Background and HITECH Impacts 3 Office of Civil Rights (OCR)

More information

6/8/2016 OVERVIEW. Page 1 of 9

6/8/2016 OVERVIEW. Page 1 of 9 OVERVIEW Attachment Supervisory Guidance for Assessing Risk Management at Supervised Institutions with Total Consolidated Assets Less than $50 Billion [Fotnote1 6/8/2016 Managing risks is fundamental to

More information

Department of Health and Human Services. Centers for Medicare & Medicaid Services. Medicaid Integrity Program

Department of Health and Human Services. Centers for Medicare & Medicaid Services. Medicaid Integrity Program Department of Health and Human Services Centers for Medicare & Medicaid Services Medicaid Integrity Program North Carolina Comprehensive Program Integrity Review Final Report Reviewers: Mark Rogers, Review

More information

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes.

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. TECHNOLOGY BRIEF: REDUCING COST AND COMPLEXITY WITH GLOBAL GOVERNANCE CONTROLS CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. Table of Contents Executive

More information

Security Information Lifecycle

Security Information Lifecycle Security Information Lifecycle By Eric Ogren Security Analyst, April 2006 Copyright 2006. The, Inc. All Rights Reserved. Table of Contents Executive Summary...2 Figure 1... 2 The Compliance Climate...4

More information

COMPLIANCE PROGRAM GUIDANCE FOR MEDICARE FEE-FOR-SERVICE CONTRACTORS

COMPLIANCE PROGRAM GUIDANCE FOR MEDICARE FEE-FOR-SERVICE CONTRACTORS Department of Health and Human Services CENTERS FOR MEDICARE & MEDICAID SERVICES COMPLIANCE PROGRAM GUIDANCE FOR MEDICARE FEE-FOR-SERVICE CONTRACTORS March 2005 TABLE OF CONTENTS INTRODUCTION...3 ELEMENTS

More information

ID THEFT RESOLUTION PROGRAM Program Description for CIGNA Life, Accident and Disability Customers

ID THEFT RESOLUTION PROGRAM Program Description for CIGNA Life, Accident and Disability Customers ID THEFT RESOLUTION PROGRAM Program Description for CIGNA Life, Accident and Disability Customers What is Identity Theft? Identity Theft occurs when someone uses your personal identifying information,

More information

STATEMENT FROM THE CHAIRMAN

STATEMENT FROM THE CHAIRMAN STATEMENT FROM THE CHAIRMAN In an ever-changing global marketplace, it is important for all of us to have an understanding of the responsibilities each of have in carrying out day-to-day business decisions

More information

Compliance Management, made easy

Compliance Management, made easy Compliance Management, made easy LOGPOINT SECURING BUSINESS ASSETS SECURING BUSINESS ASSETS LogPoint 5.1: Protecting your data, intellectual property and your company Log and Compliance Management in one

More information

PROTECTION OF PERSONAL INFORMATION

PROTECTION OF PERSONAL INFORMATION PROTECTION OF PERSONAL INFORMATION Definitions Privacy Officer - The person within the Goderich Community Credit Union Limited (GCCU) who is responsible for ensuring compliance with privacy obligations,

More information

Audit and Risk Committee Charter. 1. Membership of the Committee. 2. Administrative matters

Audit and Risk Committee Charter. 1. Membership of the Committee. 2. Administrative matters Audit and Risk Committee Charter The Audit and Risk Committee (the Committee ) is a Committee of the Board established with the specific powers delegated to it under Clause 8.15 of the Company s Constitution

More information

Metrics by design A practical approach to measuring internal audit performance

Metrics by design A practical approach to measuring internal audit performance Metrics by design A practical approach to measuring internal audit performance September 2014 At a glance Expectations of Internal Audit are rising. Regulatory pressure is increasing. Budgets are tightening.

More information

Leveraging a Maturity Model to Achieve Proactive Compliance

Leveraging a Maturity Model to Achieve Proactive Compliance Leveraging a Maturity Model to Achieve Proactive Compliance White Paper: Proactive Compliance Leveraging a Maturity Model to Achieve Proactive Compliance Contents Introduction............................................................................................

More information

PCI DSS READINESS AND RESPONSE

PCI DSS READINESS AND RESPONSE PCI DSS READINESS AND RESPONSE EMC Consulting Services offers a lifecycle approach to holistic, proactive PCI program management ESSENTIALS Partner with EMC Consulting for your PCI program management and

More information

A Best Practice Guide

A Best Practice Guide A Best Practice Guide Contents Introduction [2] The Benefits of Implementing a Privacy Management Programme [3] Developing a Comprehensive Privacy Management Programme [3] Part A Baseline Fundamentals

More information

RSA ARCHER AUDIT MANAGEMENT

RSA ARCHER AUDIT MANAGEMENT RSA ARCHER AUDIT MANAGEMENT Solution Overview INRODUCTION AT A GLANCE Align audit plans with your organization s risk profile and business objectives Manage audit planning, prioritization, staffing, procedures

More information

Corporate Compliance and Ethics

Corporate Compliance and Ethics Corporate Compliance and Ethics Title: Corporate Compliance and Ethics Course Code: EL-CCE-COMP-0 Course Outline Section 1: Introduction A. Course Contributors B. About This Course C. Learning Objectives

More information

Top Seven Risks to Consider When Selecting a Life Science LMS

Top Seven Risks to Consider When Selecting a Life Science LMS Top Seven s to Consider When Selecting a Life Science LMS THE UNINTENDED CONSEQUENCES OF UNINFORMED DECISIONS IN THIS PAPER: Identifying and avoiding gaps in LMS functionality that may lead to critical

More information

Privacy by Design Setting a new standard for privacy certification

Privacy by Design Setting a new standard for privacy certification Privacy by Design Setting a new standard for privacy certification Privacy by Design is a framework based on proactively embedding privacy into the design and operation of IT systems, networked infrastructure,

More information

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

WHITE PAPER. PCI Basics: What it Takes to Be Compliant WHITE PAPER PCI Basics: What it Takes to Be Compliant Introduction A long-running worldwide advertising campaign by Visa states that the card is accepted everywhere you want to be. Unfortunately, and through

More information

Sarbanes-Oxley Control Transformation Through Automation

Sarbanes-Oxley Control Transformation Through Automation Sarbanes-Oxley Control Transformation Through Automation An Executive White Paper By BLUE LANCE, Inc. Where have we been? Where are we going? BLUE LANCE INC. www.bluelance.com 713.255.4800 [email protected]

More information

Standards of. Conduct. Important Phone Number for Reporting Violations

Standards of. Conduct. Important Phone Number for Reporting Violations Standards of Conduct It is the policy of Security Health Plan that all its business be conducted honestly, ethically, and with integrity. Security Health Plan s relationships with members, hospitals, clinics,

More information

Case Studies Mobility Management

Case Studies Mobility Management Case Studies Mobility Management A window into real-world customer applications for Calero solutions CASE STUDY Managing Mobile and Fixed Communications Expenses ABOUT CALERO CALERO PROVIDES ENTERPRISE

More information

Building Trust and Confidence in Healthcare Information. How TrustNet Helps

Building Trust and Confidence in Healthcare Information. How TrustNet Helps Building Trust and Confidence in Healthcare Information The management of healthcare information in the United States is regulated under the HIPAA (Health Insurance Portability and Accountability Act)

More information