How Much Compliance Is Enough? The Five Levels of Compliance

More compliance isn't always better. There, I said it.
I've spent much of my career building, fixing and running healthcare compliance programs. And I've come to believe that organizations tend to operate at one of five levels of compliance maturity. The interesting question isn't whether every organization should reach Level 5. It's figuring out what level is right for yours.
Level 1: We're Fine
There really isn't a compliance program. Maybe there is a dusty compliance plan somewhere, some annual training, and someone whose job description includes the word "compliance." But little is actually happening. For a healthcare organization of any meaningful size or complexity, this isn't much of a strategy. It's hope.
Level 2: The Basics
Now we have something. Policies. Training. A reporting mechanism. Some oversight. Perhaps periodic auditing. The basic elements of a compliance program exist, although much of the activity remains reactive. Something happens, compliance responds. This may be enough for a very small or relatively simple organization with limited risk.
Level 3: Trusted Partner
This is where things get interesting. Compliance isn't just called after something goes wrong. Operations, finance and clinical leadership begin bringing compliance into issues earlier. The Compliance Officer understands the business. The business trusts the Compliance Officer. Problems are identified before they become crises. Business opportunities are evaluated with compliance in the room rather than compliance being asked to bless them afterward. For many organizations, Level 3 may be perfectly good compliance.
Level 4: Embedded Compliance
At Level 4, compliance becomes part of how the organization operates. Risks are systematically identified. Auditing and monitoring are active. Data is used. Clinic or business-unit performance can be measured. Findings are reported back to leadership. Corrective actions are tracked.
Most importantly, compliance isn't sitting off to the side. It is integrated into operations. For a growing healthcare MSO, including many private equity-backed organizations, Level 4 may be the sweet spot: meaningful risk reduction and operational value without unnecessary infrastructure.
Level 5: Strategic Compliance
This is the pinnacle. At Level 5, senior leadership doesn't merely tolerate compliance. It values the Compliance Officer's perspective.The Compliance Officer has become a trusted source of information about the organization — its risks, people, culture and operations. Leadership wants compliance in the room before consequential decisions are made. At this level, compliance can contribute to much more than avoiding enforcement. It can identify operational weaknesses, improve processes, protect revenue, strengthen culture, facilitate growth and help prepare an organization for sophisticated buyer due diligence. Compliance has become a business asset.
But Do You Need Level 5?
Maybe not. That's especially important for private equity sponsors and their healthcare portfolio companies. Investment horizons matter. Resources matter. Risk tolerance matters. The regulatory complexity of the business matters. A five-location physician group doesn't necessarily need the compliance infrastructure of a 150-location multistate MSO. And building compliance infrastructure simply because somebody's checklist says you should isn't strategic compliance. It's overhead.
The better question is:
What is the right amount of compliance for this organization, at this point in its life cycle, given its actual risks?
That answer may be Level 3.
It may be Level 4.
And sometimes there is substantial value in reaching Level 5.
Fractional Can Fit
There is also no rule that says an organization needs to hire a full-time Chief Compliance Officer and build a large department to develop a meaningful compliance function. A fractional Compliance Officer can provide senior-level experience, independence and continuity while allowing the organization to scale its compliance investment to its actual needs. I've seen this model work particularly well with growing healthcare businesses. Start with an assessment. Identify the important risks. Build what matters. Integrate it into operations. Increase sophistication as the organization grows. And, when size and complexity eventually justify it, transition to a dedicated internal Compliance Officer.
The objective isn't to have the biggest compliance program.
It's to have the right one.
So, what level are you?
Reid Pearlman, JD, CCEP is Principal/Consultant at True Compliance Consulting, LLC in Atlanta. He can be reached at Reid@MyComplianceOfficer.net.

































Comments