Compliance Radar · Practitioner Spotlight · August 2026

Practitioner Spotlight
From policy to practice: making compliance controls work in daily operations
Maria Stahl, Director of Compliance at US Heart and Vascular, shares how healthcare leaders can turn compliance expectations into accountable, auditable work.
In this Practitioner Spotlight, Maria Stahl explains how healthcare organizations can translate compliance requirements into practical controls that hold up across teams, sites, and changing conditions.
“A policy establishes expectations, but a control makes those expectations operational through defined ownership, repeatable workflows, documented evidence, and ongoing monitoring.”
This conversation builds on August’s Compliance Radar, focused on the controls, handoffs, and documentation practices that make compliance durable in daily operations.
IN CONVERSATION
As Director of Compliance at US Heart and Vascular, you see how quickly a policy can lose force when it is not translated into a repeatable workflow. In a multi-site healthcare organization, what separates a policy that looks complete on paper from a control that is genuinely executable and auditable in daily operations?
A policy establishes expectations, but a control makes those expectations operational through defined ownership, repeatable workflows, documented evidence, and ongoing monitoring. In my role as Director of Compliance, I focus on translating regulatory requirements into practical controls that can be consistently executed across sites, measured through audits, and improved through corrective action when gaps are identified.
This execution often comes with collaboration with other organizational leaders to ensure policy requirements are embedded into daily processes rather than relying on single-perspective interpretation.
August’s Radar is about controls that fail at the handoff. Where do breakdowns most often occur between clinical teams, operations, revenue cycle, HR, legal, and leadership—and how do you make ownership, escalation, and documentation explicit without creating unnecessary bureaucracy?
We can acknowledge that breakdowns typically occur at handoff points where responsibility is assumed rather than assigned. We can also acknowledge that it is easy to interpret responsibility differently depending on the norms and expectations of any one department. However, this can be addressed by partnering with leadership across departments to establish clear process owners, escalation pathways, and documentation standards. This allows the organization to keep workflows practical and risk-based so that accountability is strengthened without adding unnecessary administrative burden.
The KGI settlement is a reminder that job requirements must be objective, job-related, and applied consistently. Drawing on your work in clinical documentation integrity and regulatory auditing, what can leaders learn about distinguishing a truly essential, evidence-based requirement from a legacy assumption?
My experience has reinforced that requirements should be supported by regulatory obligations, operational risk, or a measurable business need. Legacy assumptions often persist because "We've always done it that way," but effective leaders should routinely validate requirements against current regulations, data, and true job responsibilities.
The key question is whether the requirement can be clearly justified and consistently defended with evidence. If it cannot be linked to a legitimate operational, compliance, quality, or risk-management objective, it may be time to reassess whether it remains necessary.
Without stepping into legal advice, what documentation and cross-functional checkpoints help an organization make sensitive employment decisions—such as accommodation, reassignment, or recruiting decisions—consistently, timely, and with a clear record of the reasoning?
Effective organizations make sensitive employment decisions through a structured, well-documented process rather than individual judgment alone. From a compliance perspective, I would recommend key checkpoints: documenting the relevant facts, maintaining records of communications and interactive discussions, involving appropriate stakeholders such as HR, Legal, and operational leadership, evaluating available options consistently, and clearly recording the rationale for the final decision.
The goal is to create a process that is timely, objective, and consistently applied. Clear documentation, defined approval paths, and cross-functional review help ensure decisions are based on job-related requirements, organizational needs, and documented evidence, while creating an auditable record that supports transparency and accountability.
Your background spans healthcare administration, coding, revenue-cycle operations, audit leadership, and compliance. What is one practical habit a healthcare leader can introduce this quarter to help people see compliance as an operational enabler—not simply a gatekeeper?
I truly recommend incorporating a brief compliance and risk discussion into existing operational meetings. When healthcare leaders routinely review regulatory requirements, audit trends, process risks, and improvement opportunities alongside operational metrics, compliance becomes part of performance improvement and decision-making rather than a separate function that only appears when there is a problem.
PRACTICAL TAKEAWAYS
What leaders can put into practice
- Assign ownership at handoffs rather than assuming it.
- Test requirements against current regulation, operational risk, and real job responsibilities.
- Make compliance a routine operating conversation—not a separate function that appears only when something goes wrong.