Spotlight on Women in GRC: What US healthcare compliance teaches us about modern GRC

Debbie Nemeth on managing healthcare compliance across 50 states, governing AI where the consequences can affect patient care, and reporting compliance in language business leaders will act on. In the latest Spotlight on Women in GRC podcast, host Lucy Montague speaks with Debbie, the series’ first American guest, about what US healthcare compliance can teach…

Lucy Montague Avatar

Debbie Nemeth on managing healthcare compliance across 50 states, governing AI where the consequences can affect patient care, and reporting compliance in language business leaders will act on.

In the latest Spotlight on Women in GRC podcast, host Lucy Montague speaks with Debbie, the series’ first American guest, about what US healthcare compliance can teach GRC leaders everywhere.

Debbie Nemeth, a Florida-based Deputy Compliance Officer has spent more than 20 years across ethics, risk and compliance, with experience spanning airlines, hospitality, pharmacy benefit management, manufacturing, pharmaceuticals, managed care and direct patient care.

In this conversation, Debbie shares:

  • Why serving patients in all 50 states creates a regulatory change challenge with lessons far beyond the US
  • Why AI in healthcare needs speed and innovation, but not at the expense of human oversight, healthcare data privacy or patient safety
  • Why compliance reporting has to move from operational activity to information leaders understand and care about
  • Why no mature compliance program ever gets to declare itself “finished”

50 states, one organization: How do you manage local compliance without creating silos?

North American healthcare organizations are expected to move quickly, control costs, protect highly sensitive information, keep pace with technology and navigate regulation that does not stop at the federal level.

Federal requirements matter, but so do the requirements of the jurisdictions in which the organization operates.

“Not only do we have federal rules that govern what we do, but when we are a service provider, which we are, that serves patients in all 50 states, we have to know and care about all of those 50 state regulatory agency rules as well.”

Debbie Nemeth, Deputy Compliance Officer

Debbie points to pharmacy ownership as one live example: a managed care organization may be able to own a pharmacy in many states, while the position differs elsewhere and continues to evolve. Her bigger concern is the constant monitoring required to know what has changed, what is coming next and what it means for the business.

“That’s one of the things that keeps us up at night as compliance leaders: do I know about all of these new regulations that have been passed or are coming down the pipeline to be passed? And then how can I prepare my business for them?”

Debbie Nemeth, Deputy Compliance Officer

The regulatory layering is real. HIPAA created national standards for the protection of certain health information, but state requirements can sit alongside the federal framework. A 50-state survey from Seyfarth Shaw maps state healthcare information privacy laws specifically because organizations cannot assume federal HIPAA requirements are the complete privacy picture.

But this is not really a 50-state problem just for US companies. It is a modern global GRC problem.

A company operating across European countries, US states, APAC markets, legal entities or regulated business units faces the same architectural tension: how do you preserve local governance without creating separate compliance silos everywhere you operate?

Centralizing everything is not automatically the answer. Local teams may need different regulatory obligations, workflows, controls, evidence, ownership structures and access rules. Some information should only be visible to defined users. The governance model needs to respect that.

The opposite extreme is just as problematic. If every region builds its own spreadsheet, database, taxonomy and reporting process, the enterprise loses the connected view it needs to understand aggregate exposure and report consistently.

Regulatory fragmentation does not have to mean fragmented GRC.

The technology supporting a multi-jurisdiction compliance program should be configurable enough to provide different environments, role-based permissions, local workflows and jurisdiction-specific requirements, while retaining common structures and enterprise reporting where that provides value. In other words: local governance without local silos.

That is where configurable risk and compliance software matters. The goal is not to force every jurisdiction into an identical program. It is to connect those programs intelligently enough that local accountability and enterprise visibility can coexist.

When healthcare gets AI wrong, the consequences are not hypothetical

If regulatory fragmentation demonstrates the complexity of US healthcare compliance, AI raises the stakes further. Healthcare organizations are under pressure to automate and reduce administrative burden, but the information and decisions involved may directly affect a person’s care.

“AI in healthcare, especially, is tricky because in healthcare, we are making decisions about people’s wellbeing, humans’ health. And so we have to be extra vigilant and direct and focused in making sure that we always have a human in the loop.”

Debbie Nemeth, Deputy Compliance Officer

AI adoption by US physicians is no longer theoretical. The American Medical Association’s 2026 survey of nearly 1,700 physicians found that 81% use AI professionally, more than double the use rate when the AMA first polled doctors in 2023. More than 75% said AI improves their ability to care for patients.

The opportunity is obvious. So is the governance challenge. In the AMA’s 2024 physician survey, based on 1,183 practicing physicians, 87% identified data privacy assurances as an important requirement for adoption, while increased oversight ranked as the top regulatory action needed to increase confidence and adoption.

Debbie describes a recent use case where AI takes a large amount of notes and information and creates a structured chart. The use case could go ahead, but the control mattered: a fully licensed and qualified person would review the AI-generated information against the underlying documents.

“We know that AI is not always perfect… we need to make sure that that information is correct.”

Debbie Nemeth, Deputy Compliance Officer

That requirement matters in an environment where privacy exposure is already substantial. The US Department of Health and Human Services Office for Civil Rights publishes breaches of unsecured protected health information affecting 500 or more individuals, and current reporting based on its portal lists 772 such healthcare breaches reported for 2025, affecting approximately 139.7 million individuals.

So the answer cannot simply be “move fast” or “ban it.” The stronger question is: what governance is proportionate to the consequence if this AI output is wrong?

“The AI said so” is not an acceptable control.

In Debbie’s multi-billion dollar healthcare organization, proposed AI initiatives go through governance oversight involving compliance and collaboration with legal, privacy and information security. That is a useful model beyond healthcare. High-consequence AI use cases need clear accountability, controlled access to sensitive data, validation and appropriate human decision-making.

Compliance can still enable innovation. In fact, good governance should make responsible innovation easier. Debbie’s team is also exploring AI for compliance work itself, but she offers an important warning:

“You can ask ChatGPT to write a policy for you, and it might come out looking really great, but it might be absolutely wrong for your business.”

Debbie Nemeth, Deputy Compliance Officer

The job is not to automate because we can. It is to identify where technology removes low-value process and where human judgment remains a control, particularly when patient safety, confidentiality or regulatory obligations are at stake.

Compliance has a reporting problem: Are we measuring activity or value?

Healthcare compliance teams can monitor regulatory change and build sophisticated governance around AI, but there is still another hurdle: getting the wider business to understand why any of it matters.

“Reporting is tricky, I think. You have to do it in the language that your business leaders speak. And your business leaders, they like metrics, they like numbers, they like to see dollars saved.”

Debbie Nemeth, Deputy Compliance Officer

That pressure is understandable in a $5.3 trillion US healthcare system. Hospital expenditures alone reached $1.63 trillion in 2024, while physician and clinical services reached $1.11 trillion. Business leaders operate in numbers, and compliance cannot retreat into a different language.

But compliance value is not always a clean dollar amount. A privacy incident that did not occur, an inappropriate business model that was changed early, or a regulatory issue identified before launch can be commercially significant without fitting neatly into a single KPI.

Debbie chairs quarterly compliance committee meetings with around 20 operational leaders and includes the privacy team to provide updates on confidentiality issues, trends and notices the business needs to understand. She stresses that compliance cannot be run by one leader or one team. It requires business-wide buy-in.

“Sometimes with GRC, with compliance risk ethics, you’re not getting an exact dollar amount or an exact metric. You can find some metrics. And so we try to pull out those metrics that make sense and are applicable.”

Debbie Nemeth, Deputy Compliance Officer

This aligns with the US Department of Health and Human Services Office of Inspector General’s General Compliance Program Guidance. The guidance sets out 7 elements of compliance program infrastructure and emphasizes oversight, auditing and monitoring, education, communication and response as parts of an effective program.

The challenge is to stop mistaking volume for value. A dashboard full of completed assessments, policy reviews and training percentages may be administratively accurate, but does it tell a leader what exposure is changing, where repeated issues indicate a systemic weakness, whether remediation is working, or what decision needs to be taken next?

If your compliance dashboard only proves how busy the compliance team is, you are measuring activity, not value.

Good healthcare compliance reporting should translate the program into decision-useful insight. That does not mean abandoning operational metrics. It means connecting them to risk, outcomes, business priorities and action.

As CoreStream GRC’s GRC Strategy Director, Paul Cadwallader explains in a recent webinar:

“We don’t manage compliance by counting controls, we manage it by how fast we close the gap between a risk being found and the risk being fixed.” 

Paul Cadwallader, GRC Strategy Director, CoreStream GRC 

The same principle applies to the technology underneath the report. If teams spend the reporting cycle manually reconciling siloed data, they have less time to interpret it. Connected GRC data should make it easier to surface trends, compare jurisdictions or business areas and show leadership where attention is actually required.

The future of US healthcare compliance is not more process for process’s sake

Across all 3 challenges, the temptation is to respond to complexity with more: more spreadsheets for every state, more controls around every new technology and more metrics on every dashboard.

Debbie’s experience points to a better answer. GRC needs to be local where regulation and access differ, connected where enterprise visibility matters, human where judgment matters, and measurable where leaders need to make decisions.

“No company has a GRC or compliance or risk program that works 100% of the time, because we are all run by humans in industries and business and operations that are constantly changing. And so that’s why we are here to constantly learn and do more.”

Debbie Nemeth, Deputy Compliance Officer

That learning mindset has shaped Debbie’s own career. After around 12 years in compliance, she returned to higher education for a master’s degree in law, including a healthcare track covering healthcare law, healthcare compliance and third-party oversight. Her lesson is not that every compliance professional needs another degree. It is that experience should never become an excuse to stop learning.

Regulations, technology and business models change. The organizations that treat compliance as a finished implementation will always be chasing the next problem.

And ultimately, Debbie’s definition of the job is refreshingly simple:

“We’re not in this job for anything other than we want to help our businesses do the right thing.”

Debbie Nemeth

For healthcare compliance leaders, doing the right thing increasingly means designing governance that can keep pace with the business without losing control of what matters most.

Conclusion: Complexity is not an excuse for more complexity in compliance

The pressure on healthcare compliance is not slowing down. In FY2025, healthcare-related False Claims Act recoveries reached $5.72 billion, representing 83% of all FCA recoveries.

Debbie’s experience shows why responding with more process is not enough. Across regulatory change, AI and reporting, the common requirement is GRC that can adapt without losing control or creating more complexity for the business.

That lesson extends far beyond US healthcare. Wherever organizations are balancing different regulations, emerging technology and growing expectations from leadership, modern GRC needs to connect the right information, controls and people so the business can make better decisions.

Complexity may be unavoidable, complex GRC doesn’t have to be.

About Debbie Nemeth

Debbie Nemeth is a US-based ethics, risk and compliance professional with more than 20 years of experience across industries including transportation, hospitality, pharmacy benefit management, manufacturing, pharmaceuticals, managed care and direct patient care. Based in Florida, she currently serves as a Deputy Compliance Officer supporting an infusion and specialty pharmacy operation for a multi-billion-dollar healthcare company. Debbie holds a master’s degree in law with a healthcare focus and is the founder of CommPly Consulting, where she provides training and resources for compliance professionals.

As a special offer for Spotlight on Women in GRC listeners, Debbie is providing complimentary access to her Compliance Influence Blueprint. Simply use the code GRC Women to access it.

About Spotlight on Women in GRC

Spotlight on Women in GRC is a podcast series created to continue the conversation sparked by the Women in GRC Awards 2026 and carry those insights beyond the event. Backed by key sponsor CoreStream GRC and hosted by Lucy Montague, the series shines a light on women shaping governance, risk and compliance, exploring their backgrounds, experiences and perspectives on what is changing across the industry.

Frequently asked questions about US healthcare compliance

What is healthcare compliance in the United States?

US healthcare compliance is the process of identifying and meeting the laws, regulations, guidance, contractual obligations and internal standards relevant to healthcare organizations and their activities. Depending on the organization, this can include federal requirements, state requirements, privacy and security obligations, fraud and abuse controls, healthcare program rules and industry-specific requirements. HHS-OIG publishes General Compliance Program Guidance covering federal laws and seven elements of compliance program infrastructure.

Does HIPAA apply in all 50 states?

HIPAA is a federal framework that establishes national standards for protecting certain health information for organizations subject to the rules. But HIPAA is not the complete compliance picture. State healthcare privacy requirements may also apply, which is why multi-state organizations need to understand both federal and jurisdiction-specific obligations.

Why can healthcare compliance requirements differ between states?

The United States has both federal and state lawmaking and regulatory authority. Healthcare organizations operating across states can therefore face state-specific privacy, licensing, pharmacy and other requirements alongside federal rules. Debbie’s experience serving patients across all 50 states illustrates why regulatory change management needs both local detail and enterprise oversight.

How can GRC software help manage healthcare compliance across multiple states or regions?

Configurable GRC software can help organizations maintain jurisdiction-specific workflows, controls, permissions, evidence and ownership while connecting information into a common enterprise view. The objective should be local governance without local silos, with access controls protecting sensitive information while leadership retains appropriate oversight.

How should healthcare organizations govern AI?

AI governance should be proportionate to the risk and consequence of the use case. In healthcare, that can mean privacy and security review, defined accountability, validation, appropriate controls over data access and qualified human oversight where outputs could influence patient care. AMA research found 81% of surveyed physicians used AI professionally in 2026, making AI governance a current operational issue rather than a future one.

What should a healthcare compliance dashboard measure?

A useful compliance dashboard should go beyond counts of activity. It should help leaders understand material trends, changes in exposure, recurring issues, remediation progress, jurisdictional differences and decisions that require attention. Operational metrics still matter, but the test is whether the information supports better governance and action.

  • Spotlight on Women in GRC: What US healthcare compliance teaches us about modern GRC

    Spotlight on Women in GRC: What US healthcare compliance teaches us about modern GRC

    Debbie Nemeth on managing healthcare compliance across 50 states, governing AI where the consequences can affect patient care, and reporting compliance in language business leaders will act on. In the latest Spotlight on Women in GRC podcast, host Lucy Montague speaks with Debbie, the series’ first American guest, about what US healthcare compliance can teach…

  • CoreStream GRC 3.7 Release Notes

    CoreStream GRC 3.7 Release Notes

    1.0      Document purpose This document provides a summary of the highlights of the CoreStream GRC Release 3.7. Major Platform releases are finalized every 2-3 months depending on client and strategic priorities. These release notes are part of CoreStream GRC’s approach to keeping clients and partners informed of the improvements we are delivering. This document summarizes…

  • Enterprise Risk Management software RFP template: questions and scoring  

    Enterprise Risk Management software RFP template: questions and scoring  

    Enter your details and we’ll email you the Enterprise Risk RFP template: Why do organizations invest in Enterprise Risk Management software?  Despite increasing regulatory pressure and growing organizational complexity, many businesses still rely on manual processes to manage enterprise risk.  Sticking to manual processes, often results in:  A risk register isn’t a risk strategy.  Modern…