
Photo courtesy of the author
The Delaware Court of Chancery set the standard for compliance oversight in 1996, recognizing in In re Caremark a board-level obligation to make a good-faith effort to ensure that adequate information and reporting systems exist.[1] Healthcare boards have had nearly 30 years to build toward that standard, but for many, there is a gap between that standard and how they actually engage with their compliance programs.
Sure, if you ask healthcare board members whether their organizations have compliance programs they will almost certainly say yes – those are business fundamentals. But the answers will vary widely if you ask them what they expect to hear from their chief compliance officer, what details they expect, how it should be communicated, and how frequently. Multiple governmental authorities reinforce the requirement of a compliance program led by an executive with sufficient independence and authority, while acknowledging that one size does not fit all. That results in compliance programs that remain underdeveloped or operate episodically, with reporting filtered through management layers limiting the board’s ability to exercise the real oversight required of them. Regulators, governance authorities, and industry bodies have established baseline expectations for years, often with increasing specificity, but executives often still refer to them as business decisions (or risks). In reality, these are governance issues boards should settle.
The Department of Health and Human Services’ Office of the Inspector General (“OIG”) has long underscored the board’s central role here. Its Practical Guidance for Health Care Governing Boards on Compliance Oversight, developed with the Health Care Compliance Association, the American Health Lawyers Association, and the Association of Healthcare Internal Auditors, describes compliance oversight as an important component of a board’s fiduciary responsibilities and emphasizes that boards must act in good faith in carrying out that role.[2] The OIG’s General Compliance Program Guidance (“GCPG”) reinforces the point, designating “Compliance Leadership and Oversight” as the second of seven elements of an effective compliance program and specifying that boards must be knowledgeable about the program’s content and operation, while exercising reasonable oversight of the program’s effectiveness.[3]
The same requirements show up outside of healthcare as well. The U.S. Department of Justice’s (“DOJ”) 2024 update to its Evaluation of Corporate Compliance Programs added emphasis on emerging technology risk, whistleblower protections, and the compliance function’s access to data.[4] In March 2026, the DOJ issued its first department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy, which should push organizations toward stronger internal reporting and escalation.[5] In fact, we are already seeing its use in resolutions announced by the DOJ this year. In July 2026, the DOJ declined to prosecute Campus Eye Management Holdings LLC and its subsidiary, a New Jersey management services organization, after the companies voluntarily self-disclosed misconduct, cooperated with the investigation, remediated the conduct, and paid restitution.[6] Campus Eye is the third publicly announced corporate declination under the new policy. The same day, the DOJ announced a seven-count indictment of the founder and former chief executive, charging conspiracy to commit health care fraud, two substantive counts of health care fraud, conspiracy to offer and pay kickbacks in connection with illegal referrals, and three substantive counts of paying kickbacks.[7] The alleged conduct ran from 2015 through March 2023, continuing after the executive and outside investors formed Campus Eye entities in December 2021. For boards, the sequence is instructive: the company’s disclosure and remediation earned a declination, and that protection did not extend to the individual the government says directed the conduct. Whether an organization is positioned to find and disclose its own problems is an item for the board to oversee: program design.
Organizations like the National Association of Corporate Directors (“NACD”) are seeing this issue as well. NACD has reported that directors rank information-flow problems between the board and management among the leading barriers to a high-performing board.[8] In healthcare and other highly regulated industries, those issues can have outsized consequences.
The Chief Compliance Officer (“CCO”) role in healthcare emerged in the 1990s as a reactive function, built in response to enforcement actions, the U.S. Sentencing Guidelines of the time, and the OIG’s early hospital compliance guidance.[9] The original setup was defensive: build a program, train staff, stand up a hotline, and reduce exposure under the False Claims Act and the Anti-Kickback Statute.
The role has matured considerably since. Today’s CCO works as an enterprise risk leader, a culture steward, a regulatory horizon scanner, and a governance partner across three different audiences: the frontline employee population, executive management, and the board. The OIG’s GCPG reflects that evolution, recommending healthcare entities give the compliance officer independent access to the board along with the authority, stature, and resources to lead an effective program.[10]
Direct board engagement with CCOs has evolved more slowly. Many boards still approach compliance the way they did fifteen years ago, through episodic committee updates framed around incident reports, regulatory developments, and training completion rates. In discussions with peers and directors at other healthcare organizations, I have found that both groups continue to wrestle with understanding what good looks like in board or committee meetings, or even what should be shared between those meetings. When the CCO presents and the board simply receives the information, oversight becomes a one-way exchange. Some of the most productive board-compliance discussions I have participated in, or I have heard from peers or directors, have moved beyond the prepared agenda or board materials. They occur when directors probe the information presented, test their understanding, and ask what may be missing. Caremark expects that kind of active inquiry and informed engagement.
For healthcare boards, effective Caremark oversight requires more than receiving compliance reports. It requires a deliberate and well-defined relationship with the CCO. Without that foundation, governance weaknesses often emerge at the moment they can do the greatest damage.
The relationship between the board and the CCO should be designed to promote transparency, independence, and accountability. Direct access to the audit, risk, or compliance committee helps ensure that compliance risks reach the board without being filtered through operational or legal channels. The GCPG provides the framework that boards should utilize.[11] Compliance reporting addresses forward-looking risk alongside historical incidents because boards need that horizon intelligence more than a rearview mirror. Boards and CCOs should share a common framework for what program effectiveness means, built on agreed indicators rather than activity counts. The CCO should participate in board-level strategic-risk discussions, particularly those involving new business lines, acquisitions, technology implementations, and payment model changes. Boards should also hold regular executive sessions with compliance, legal, internal audit, and quality leadership, without other members of management present. Although the practice can make executives uneasy, it preserves an unfiltered channel between directors and the control functions. In practice, it builds stronger relationships between directors and the CCO while reinforcing the authority and stature the GCPG describes.
The OIG encourages boards to stay active and appropriately skeptical, exercising independent judgment on information that reaches them through management.[12] That skepticism works best through direct questions: What compliance risks are you monitoring that have yet to reach our agenda? How would you describe our compliance culture right now, and what evidence backs that assessment? If a regulator walked in tomorrow, where would we be most exposed? When boards receive clear and candid answers to these questions, it is often evidence of a strong compliance oversight framework. Where the answers are less clear, a deeper conversation is usually appropriate. As a CCO, being asked those questions pushes me to maintain an effective program. It tells me the board members are engaged and interested in the program.
A few structural changes merit attention as the compliance function’s scope keeps expanding, a trend that is accelerating alongside AI adoption:
- Boards should assess whether their committee structure gives compliance oversight enough dedicated attention. The GCPG recommends that boards of large healthcare organizations consider separate board-level compliance and audit committees[13], and smaller organizations could find similar value in this framework. Committees staffed with directors who carry the deepest regulatory fluency can work directly with underlying risk data instead of summaries prepared for the full board, and they can move faster with fewer calendars to coordinate.
- Boards should assess whether their directors carry the compliance and governance fluency the current U.S. Sentencing Guidelines expect of a governing authority: knowledge of the compliance program’s content and operation, plus the capacity to exercise reasonable oversight of its effectiveness.[14] Compliance oversight depends as much on informed judgment as it does on formal governance processes. Gaps in either area can attract attention during government investigations, settlements, and other enforcement actions.
- Finally, boards should formalize CCO reporting expectations in a board-approved compliance oversight charter covering reporting frequency, content requirements, escalation thresholds, and the CCO’s direct access to board leadership.[15]
The OIG has been clear that the design and governance of a compliance program should reflect an organization’s size, complexity, and risk profile, and equally clear that boards carry real responsibility for making their oversight genuine.[16] The OIG is looking for boards to make a meaningful effort in their oversight, which means going beyond maintaining a compliance program on paper. Boards should be asking questions like those listed above to assess whether they and their CCO have created an oversight structure that supports effective compliance governance and fulfills their Caremark responsibilities. Creating that structure requires an ongoing partnership between the board and the CCO.
[1] In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 970 (Del. Ch. 1996).
[2] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., Ass’n of Healthcare Internal Auditors, Am. Health L. Ass’n & Health Care Compliance Ass’n, Practical Guidance for Health Care Governing Boards on Compliance Oversight 2–3 (Apr. 20, 2015).
[3] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 32, 37, 43–44 (Nov. 2023).
[4] U.S. Dep’t of Justice, Criminal Div., Evaluation of Corporate Compliance Programs (Sept. 2024).
[5] U.S. Dep’t of Justice, Corporate Enforcement and Voluntary Self-Disclosure Policy (Mar. 10, 2026).
[6] U.S. Dep’t of Justice, National Fraud Enforcement Division, Declination Letter to Campus Eye Management Holdings LLC and Campus Eye Management LLC (July 29, 2026).
[7] U.S. Att’y’s Office, Dist. Of N.J., Press Release No. 26-166, Founder and Former CEO of New Jersey Based Eye Care Group Charged with Health Care Fraud Conspiracy and Paying Illegal Kickbacks, (July 29, 2026).
[8] Scott Engler & Evan Grossman, 10 Steps to a Better Board Partnership, NACD Directorship (Sept. 13, 2022).
[9] U.S. Sent’g Comm’n, Guidelines Manual ch. 8 (1991); Compliance Program Guidance for Hospitals, 63 Fed. Reg. 8,987 (Feb. 23, 1998).
[10] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 37 (Nov. 2023).
[11] Id. at 37–38.
[12] Gregory Demske, Chief Counsel, Office of Inspector Gen., U.S. Dep’t of Health & Human Servs., Guidance for Health Care Boards (podcast, Mar. 27, 2013).
[13] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 73–74 (Nov. 2023).
[14] U.S. Sent’g Guidelines Manual § 8B2.1(b)(2)(A) (2025).
[15] Practical Guidance for Health Care Governing Boards on Compliance Oversight, supra note 2, at 11–13; U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 43–44, 73–74 (Nov. 2023).
[16] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 43–45, 65–74 (Nov. 2023); Practical Guidance for Health Care Governing Boards on Compliance Oversight, supra note 2, at 3–5.
Andrew B. Heineman is Chief Compliance Officer at Honest Health. This post is based on his article, “Compliance as a Governance Function: What Boards Should Expect from Their CCO,” published in the August 2026 issue of Compliance Today. ©2026 Society of Corporate Compliance and Ethics (SCCE) & Health Care Compliance Association (HCCA). Adapted with permission.
The views, opinions and positions expressed within all posts are those of the author(s) alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author(s) and any liability with regards to infringement of intellectual property rights remains with the author(s).

Photo courtesy of the author
The Delaware Court of Chancery set the standard for compliance oversight in 1996, recognizing in In re Caremark a board-level obligation to make a good-faith effort to ensure that adequate information and reporting systems exist.[1] Healthcare boards have had nearly 30 years to build toward that standard, but for many, there is a gap between that standard and how they actually engage with their compliance programs.
Sure, if you ask healthcare board members whether their organizations have compliance programs they will almost certainly say yes – those are business fundamentals. But the answers will vary widely if you ask them what they expect to hear from their chief compliance officer, what details they expect, how it should be communicated, and how frequently. Multiple governmental authorities reinforce the requirement of a compliance program led by an executive with sufficient independence and authority, while acknowledging that one size does not fit all. That results in compliance programs that remain underdeveloped or operate episodically, with reporting filtered through management layers limiting the board’s ability to exercise the real oversight required of them. Regulators, governance authorities, and industry bodies have established baseline expectations for years, often with increasing specificity, but executives often still refer to them as business decisions (or risks). In reality, these are governance issues boards should settle.
The Department of Health and Human Services’ Office of the Inspector General (“OIG”) has long underscored the board’s central role here. Its Practical Guidance for Health Care Governing Boards on Compliance Oversight, developed with the Health Care Compliance Association, the American Health Lawyers Association, and the Association of Healthcare Internal Auditors, describes compliance oversight as an important component of a board’s fiduciary responsibilities and emphasizes that boards must act in good faith in carrying out that role.[2] The OIG’s General Compliance Program Guidance (“GCPG”) reinforces the point, designating “Compliance Leadership and Oversight” as the second of seven elements of an effective compliance program and specifying that boards must be knowledgeable about the program’s content and operation, while exercising reasonable oversight of the program’s effectiveness.[3]
The same requirements show up outside of healthcare as well. The U.S. Department of Justice’s (“DOJ”) 2024 update to its Evaluation of Corporate Compliance Programs added emphasis on emerging technology risk, whistleblower protections, and the compliance function’s access to data.[4] In March 2026, the DOJ issued its first department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy, which should push organizations toward stronger internal reporting and escalation.[5] In fact, we are already seeing its use in resolutions announced by the DOJ this year. In July 2026, the DOJ declined to prosecute Campus Eye Management Holdings LLC and its subsidiary, a New Jersey management services organization, after the companies voluntarily self-disclosed misconduct, cooperated with the investigation, remediated the conduct, and paid restitution.[6] Campus Eye is the third publicly announced corporate declination under the new policy. The same day, the DOJ announced a seven-count indictment of the founder and former chief executive, charging conspiracy to commit health care fraud, two substantive counts of health care fraud, conspiracy to offer and pay kickbacks in connection with illegal referrals, and three substantive counts of paying kickbacks.[7] The alleged conduct ran from 2015 through March 2023, continuing after the executive and outside investors formed Campus Eye entities in December 2021. For boards, the sequence is instructive: the company’s disclosure and remediation earned a declination, and that protection did not extend to the individual the government says directed the conduct. Whether an organization is positioned to find and disclose its own problems is an item for the board to oversee: program design.
Organizations like the National Association of Corporate Directors (“NACD”) are seeing this issue as well. NACD has reported that directors rank information-flow problems between the board and management among the leading barriers to a high-performing board.[8] In healthcare and other highly regulated industries, those issues can have outsized consequences.
The Chief Compliance Officer (“CCO”) role in healthcare emerged in the 1990s as a reactive function, built in response to enforcement actions, the U.S. Sentencing Guidelines of the time, and the OIG’s early hospital compliance guidance.[9] The original setup was defensive: build a program, train staff, stand up a hotline, and reduce exposure under the False Claims Act and the Anti-Kickback Statute.
The role has matured considerably since. Today’s CCO works as an enterprise risk leader, a culture steward, a regulatory horizon scanner, and a governance partner across three different audiences: the frontline employee population, executive management, and the board. The OIG’s GCPG reflects that evolution, recommending healthcare entities give the compliance officer independent access to the board along with the authority, stature, and resources to lead an effective program.[10]
Direct board engagement with CCOs has evolved more slowly. Many boards still approach compliance the way they did fifteen years ago, through episodic committee updates framed around incident reports, regulatory developments, and training completion rates. In discussions with peers and directors at other healthcare organizations, I have found that both groups continue to wrestle with understanding what good looks like in board or committee meetings, or even what should be shared between those meetings. When the CCO presents and the board simply receives the information, oversight becomes a one-way exchange. Some of the most productive board-compliance discussions I have participated in, or I have heard from peers or directors, have moved beyond the prepared agenda or board materials. They occur when directors probe the information presented, test their understanding, and ask what may be missing. Caremark expects that kind of active inquiry and informed engagement.
For healthcare boards, effective Caremark oversight requires more than receiving compliance reports. It requires a deliberate and well-defined relationship with the CCO. Without that foundation, governance weaknesses often emerge at the moment they can do the greatest damage.
The relationship between the board and the CCO should be designed to promote transparency, independence, and accountability. Direct access to the audit, risk, or compliance committee helps ensure that compliance risks reach the board without being filtered through operational or legal channels. The GCPG provides the framework that boards should utilize.[11] Compliance reporting addresses forward-looking risk alongside historical incidents because boards need that horizon intelligence more than a rearview mirror. Boards and CCOs should share a common framework for what program effectiveness means, built on agreed indicators rather than activity counts. The CCO should participate in board-level strategic-risk discussions, particularly those involving new business lines, acquisitions, technology implementations, and payment model changes. Boards should also hold regular executive sessions with compliance, legal, internal audit, and quality leadership, without other members of management present. Although the practice can make executives uneasy, it preserves an unfiltered channel between directors and the control functions. In practice, it builds stronger relationships between directors and the CCO while reinforcing the authority and stature the GCPG describes.
The OIG encourages boards to stay active and appropriately skeptical, exercising independent judgment on information that reaches them through management.[12] That skepticism works best through direct questions: What compliance risks are you monitoring that have yet to reach our agenda? How would you describe our compliance culture right now, and what evidence backs that assessment? If a regulator walked in tomorrow, where would we be most exposed? When boards receive clear and candid answers to these questions, it is often evidence of a strong compliance oversight framework. Where the answers are less clear, a deeper conversation is usually appropriate. As a CCO, being asked those questions pushes me to maintain an effective program. It tells me the board members are engaged and interested in the program.
A few structural changes merit attention as the compliance function’s scope keeps expanding, a trend that is accelerating alongside AI adoption:
- Boards should assess whether their committee structure gives compliance oversight enough dedicated attention. The GCPG recommends that boards of large healthcare organizations consider separate board-level compliance and audit committees[13], and smaller organizations could find similar value in this framework. Committees staffed with directors who carry the deepest regulatory fluency can work directly with underlying risk data instead of summaries prepared for the full board, and they can move faster with fewer calendars to coordinate.
- Boards should assess whether their directors carry the compliance and governance fluency the current U.S. Sentencing Guidelines expect of a governing authority: knowledge of the compliance program’s content and operation, plus the capacity to exercise reasonable oversight of its effectiveness.[14] Compliance oversight depends as much on informed judgment as it does on formal governance processes. Gaps in either area can attract attention during government investigations, settlements, and other enforcement actions.
- Finally, boards should formalize CCO reporting expectations in a board-approved compliance oversight charter covering reporting frequency, content requirements, escalation thresholds, and the CCO’s direct access to board leadership.[15]
The OIG has been clear that the design and governance of a compliance program should reflect an organization’s size, complexity, and risk profile, and equally clear that boards carry real responsibility for making their oversight genuine.[16] The OIG is looking for boards to make a meaningful effort in their oversight, which means going beyond maintaining a compliance program on paper. Boards should be asking questions like those listed above to assess whether they and their CCO have created an oversight structure that supports effective compliance governance and fulfills their Caremark responsibilities. Creating that structure requires an ongoing partnership between the board and the CCO.
[1] In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 970 (Del. Ch. 1996).
[2] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., Ass’n of Healthcare Internal Auditors, Am. Health L. Ass’n & Health Care Compliance Ass’n, Practical Guidance for Health Care Governing Boards on Compliance Oversight 2–3 (Apr. 20, 2015).
[3] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 32, 37, 43–44 (Nov. 2023).
[4] U.S. Dep’t of Justice, Criminal Div., Evaluation of Corporate Compliance Programs (Sept. 2024).
[5] U.S. Dep’t of Justice, Corporate Enforcement and Voluntary Self-Disclosure Policy (Mar. 10, 2026).
[6] U.S. Dep’t of Justice, National Fraud Enforcement Division, Declination Letter to Campus Eye Management Holdings LLC and Campus Eye Management LLC (July 29, 2026).
[7] U.S. Att’y’s Office, Dist. Of N.J., Press Release No. 26-166, Founder and Former CEO of New Jersey Based Eye Care Group Charged with Health Care Fraud Conspiracy and Paying Illegal Kickbacks, (July 29, 2026).
[8] Scott Engler & Evan Grossman, 10 Steps to a Better Board Partnership, NACD Directorship (Sept. 13, 2022).
[9] U.S. Sent’g Comm’n, Guidelines Manual ch. 8 (1991); Compliance Program Guidance for Hospitals, 63 Fed. Reg. 8,987 (Feb. 23, 1998).
[10] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 37 (Nov. 2023).
[11] Id. at 37–38.
[12] Gregory Demske, Chief Counsel, Office of Inspector Gen., U.S. Dep’t of Health & Human Servs., Guidance for Health Care Boards (podcast, Mar. 27, 2013).
[13] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 73–74 (Nov. 2023).
[14] U.S. Sent’g Guidelines Manual § 8B2.1(b)(2)(A) (2025).
[15] Practical Guidance for Health Care Governing Boards on Compliance Oversight, supra note 2, at 11–13; U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 43–44, 73–74 (Nov. 2023).
[16] U.S. Dep’t of Health & Human Servs., Office of Inspector Gen., General Compliance Program Guidance 43–45, 65–74 (Nov. 2023); Practical Guidance for Health Care Governing Boards on Compliance Oversight, supra note 2, at 3–5.
Andrew B. Heineman is Chief Compliance Officer at Honest Health. This post is based on his article, “Compliance as a Governance Function: What Boards Should Expect from Their CCO,” published in the August 2026 issue of Compliance Today. ©2026 Society of Corporate Compliance and Ethics (SCCE) & Health Care Compliance Association (HCCA). Adapted with permission.
The views, opinions and positions expressed within all posts are those of the author(s) alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author(s) and any liability with regards to infringement of intellectual property rights remains with the author(s).







