RHTP Roadmap: “Compliance as the Operating System for Transformation”

Aerial view of a rural community with location markers representing rural healthcare access and RHTP implementation

In PYA’s video series, RHTP Roadmap: From Award to Outcome, the third episode,“Compliance as the Operating System for Transformation,” explores how rural healthcare organizations can use compliance as a framework to guide successful implementation of Rural Health Transformation Program (RHTP) initiatives. Shannon Sumner, Principal, Chief Privacy Officer, and leader of PYA’s regulatory compliance services, explains that compliance should not be viewed as a final checkpoint or regulatory obligation. Instead, it should be integrated into planning and implementation from the beginning to help organizations convert funding into sustainable outcomes.

Sumner emphasizes that receiving RHTP funding is only the first step. Rural providers must also establish governance structures, financial stewardship practices, privacy and cybersecurity safeguards, and oversight mechanisms that ensure funds are used effectively and that outcomes can be demonstrated over time. According to Sumner, the most successful initiatives will

  • govern the award
  • protect funding and data
  • prove that intended results were achieved

The episode explains how organizations can strengthen existing compliance programs to support funded workstreams, manage implementation risks, maintain accountability, and create a sustainable foundation for transformation. Leaders will learn practical steps for building controls, monitoring progress, documenting evidence, and connecting project activities to measurable outcomes.

The episode encourages organizations to:

  • Embed compliance from Day 1
  • Establish governance, accountability, and decision authority
  • Link expenditures to requirements, approvals, and outcomes
  • Strengthen oversight of cybersecurity, privacy, vendors, and workforce initiatives
  • Use dashboards to track spending, risks, outcomes, and corrective actions
  • Define ownership for controls, reviews, and escalation
  • Integrate compliance into existing governance structures
  • Create a 90-day roadmap for sustainable transformation

Contact PYA’s Rural Health Transformation team for assistance with RHTP planning, implementation, compliance, governance, and performance monitoring.

Stay informed:


Video Summary

RHTP implementation creates accountability obligations alongside the opportunity to transform rural care. Rural providers need governance, financial stewardship, data protection, oversight, and evidence structures that move with implementation rather than being added after decisions are made.

In this episode of PYA’s RHTP Roadmap: From Award to Outcome, Shannon Sumner explains how an existing compliance program can serve as an operating framework for implementation. The discussion connects award commitments to ownership, controls, monitoring, vendor oversight, board reporting, corrective action, and a practical first-90-day roadmap.

Key Takeaways

  • Compliance should be designed into RHTP implementation from day one rather than used only as a final review.
  • The video organizes RHTP oversight around governing the award, protecting funds, protecting data, and proving outcomes.
  • RHTP workstreams should connect to the organization’s existing compliance infrastructure rather than creating a separate compliance program.
  • Key risk domains discussed include financial stewardship, cybersecurity and privacy, workforce expansion, innovative care models, and third-party oversight.
  • Each material expenditure should have an evidence trail connecting the award or budget line, business purpose, approval, procurement, payment support, and related milestone or deliverable.
  • Leadership and board reporting should be concise and decision-ready, bringing together spending, milestones, quality, cybersecurity, workforce, vendor performance, and remediation.
  • The first 90 days should establish accountable owners, operational obligations, vendor and data inventories, policies, delegated authority, baseline measures, testing, reporting, and remediation.

Frequently Asked Questions

Why should compliance be part of RHTP implementation from day one?

The video explains that compliance is most useful when it is built into implementation before decisions are finalized. Doing so helps connect award commitments to owners, controls, measures, evidence requirements, escalation paths, and corrective action.

Should organizations create a separate compliance program for RHTP?

No separate program is recommended in the video. Instead, RHTP-funded workstreams should connect to and strengthen the organization’s existing compliance system so governance, training, communication, auditing, monitoring, enforcement, and corrective action support implementation.

What risk areas should an RHTP compliance framework address?

The presentation identifies five risk domains that should have clear ownership: financial stewardship, cybersecurity and privacy, workforce expansion, innovative care models, and third-party oversight.

What documentation should support material RHTP expenditures?

The video recommends an evidence trail that connects the applicable award term or budget line, business purpose, approval and authority, procurement decision, invoice and payment support, and the related milestone or deliverable.

When should compliance become involved with technology vendors?

The video recommends moving compliance upstream, before a vendor is selected and before a contract is signed. The review should address data flows, access, security diligence, HIPAA obligations, business associate requirements when applicable, uptime and recovery expectations, incident notification, audit rights, subcontractors, and exit rights.

What should an organization do during the first 90 days of RHTP implementation?

The roadmap in the video calls for naming accountable owners, translating award terms into operational obligations, inventorying vendors and data flows, identifying evidence requirements, approving policies and authority, training teams, launching monitoring, establishing baselines, testing controls, reporting status, resolving gaps, and confirming sustainability and oversight expectations.

“Compliance as the Operating System for Transformation,” presented by PYA Principal Shannon Sumner.

This transcript was generated with AI and may contain errors or omissions. Please refer to the video recording for the most accurate version.

00:06

Welcome and thank you for joining me today. Today we’re going to explore how effective compliance programs can help rural providers make the best possible use of their rural health transformation program dollars. Our focus is not simply on protecting the funding; it is on using compliance as a practical framework to turn an award into sustainable operational and opportunity outcomes.

00:35

So today, we’re going to explore a topic that is often overlooked during large transformation initiatives: the role of compliance in ensuring rural health transformation program investments achieve their intended outcomes. Rural providers have an extraordinary opportunity to expand access, modernize technology, strengthen the workforce, and improve care delivery. But receiving the dollars is only the beginning.

01:03

Providers must also establish the governance, financial stewardship, data protection, and oversight structures needed to use those dollars effectively and sustain what they build.

01:17

So the premise of today’s discussion is simple: compliance should not be something that reviews implementation after the fact. Compliance should be designed into implementation from day one, and when that happens, the compliance program becomes a practical tool for helping the organization move from award to outcome.

01:40

So, a little bit about myself. I am Shannon Sumner. I lead PYA’s regulatory compliance service line. I’m also serving as the firm’s privacy officer, but my prior experience includes serving health systems in the internal audit and compliance functions. So today, when I speak about compliance, I recognize that smaller rural organizations may not have that one person serving as a compliance officer. In fact, in many cases, they wear multiple hats, from risk manager to quality and maybe compliance. So, for today’s session, compliance can be defined as that person or persons involved, including a compliance committee, a quality committee, a risk committee, in overseeing regulatory compliance for your facility. It is a process, it’s a program, but not necessarily an individual.

02:39

So, if there’s one key takeaway from today’s presentation, it’s this: compliance is the operating system for transformation. The most successful RHTP initiatives will not be the ones that simply spend their funds or launch the greatest number of projects. They will be the ones that govern the award, protect the funds, protect the data, and prove the outcomes are achieved.

03:06

First and foremost, govern the award, make decision-making authority, those escalation paths, and accountability for those paths visible from the start.

03:19

Second, protecting the funds, tie approvals, procurement, and documentation directly to the award terms and those approved activities.

03:31

And third, you’ve got to protect the data, building those privacy frameworks, cybersecurity, and also third-party vendor controls into technology and care delivery before implementation, and fourth, you’ve got to prove that outcome. Monitor your milestones, your quality measures, measure your spending, and corrective actions together, so the organization can demonstrate not only what it purchased, but what the investment actually accomplished. So that’s the key to receiving these dollars.

04:05

And you know, while compliance is sometimes characterized as a function that slows things down,

04:11

in this context, it should do the exact opposite. A well-designed compliance framework enables leaders to make those decisions with greater confidence, because expectations, controls, and escalation processes are already in place.

04:30

So, when a provider accepts transformation funding, it also accepts a series of commitments: every goal, every milestone, every budget item, and performance measure creates an accountability obligation, and that obligation expands beyond actually doing the work. The organization must be able to demonstrate appropriate stewardship, operational resilience, and evidence of those results. Those are key.

05:01

stewardship means showing that federal funds were used for approved purposes, and that decisions and expenditures can be traced. You will be audited for this.

05:13

Resilience means protecting care delivery, the workforce, data again, and technology as operating models are going to be constantly changing. A new program is not truly transformational if it cannot be maintained, secured, or integrated into ongoing operations. And evidence means documenting that activities occurred, milestones were achieved, and outcomes aligned with the intent of the award,

05:43

and this is why compliance should be embedded in implementation meetings and work streams rather than added after those decisions have been made. Compliance truly helps translate each promise in the award to an owner, a control, a measure, and an evidence requirement,

06:02

innovation earns trust when governance controls and evidence move with

06:09

  1. And one of the biggest mistakes that we’ve seen that organizations can make is treating the RHTP implementation as separate from the compliance program. Instead, the funded workstreams, so all those that you’ve already cataloged, should activate and strengthen the seven elements of an effective compliance program.

06:31

Written policy should address project governance,

06:35

spending authority,

06:37

procurement, that third party and that vendor oversight, data use,

06:44

documentation, and also reporting,

06:48

compliance leadership, or if you’re wearing multiple hats, compliance roles should have defined roles in implementation, governance, and a clear path for escalating concerns.

07:01

Education and training should equip project leaders, finance teams, clinicians, and operational staff to understand allowable activities, approval requirements, privacy obligations, performance measures, and record retention expectations.

07:20

Open communication should make it easy for employees and partners to ask questions or raise concerns before a problem grows,

07:27

and then auditing and monitoring should be tailored to the actual RHTP workstreams, including the spending, the milestones,

07:35

vendor performance, workforce requirements, privacy, and obviously quality.

07:43

Consistent enforcement that reinforces requirements apply across all departments and to those third parties. And finally, response and corrective action should identify any root causes, assign owners, establish due dates, and verify that issues are fully resolved.

08:02

The goal is not to create a separate RHTP compliance program.

08:07

The goal is to use one connected to your already existing compliance system to support the funded work and increase the likelihood that the dollars produce those sustainable results.

08:21

And this slide actually highlights those five risk domains that should have a clearly designated owner before implementation begins. So take note of these particular elements. First of all, year one risk grows wherever responsibility, documentation, or that oversight is unclear. So the first domain is financial stewardship, allowing that accountability, approvals, procurement, spending, and your supporting evidence. The second is cybersecurity and privacy, including technology selection, contracting,

08:58

access controls, incident response, and ongoing monitoring, and the third is that workforce expansion. Providers may be recruiting clinicians using new staffing models or extending services across settings, and that creates credentialing, enrollment, supervision, labor, and scope of practice considerations.

09:19

The fourth is innovative care models, telehealth, mobile care, community partnerships, integrated behavioral health, and other new models may create those fraud and abuse, payer billing, and state law considerations that should be evaluated before launch. And the fifth is that third-party oversight. Vendors and partners require due diligence, appropriate contracts and business associate agreements, conflicts of interest reviews, and ongoing performance monitoring.

09:50

Compliance can help the organization build a practical ownership matrix that identifies who performs each control, who reviews it, what evidence is retained.

10:00

And when an issue must be escalated, so really put every critical control in the work plan and not in that binder after go

10:11

live. And for many rural providers, this may be the most important slide in this presentation.

10:16

It’s not enough to spend those transformation dollars appropriately. The organization must be able to tell the complete story of each material expenditure,

10:27

and that story should connect the award term or budget line item, the business purpose, the approval and authority,

10:35

the procurement decision, the invoice and payment support, and the related milestone or deliverable, and I often encourage organizations to ask a simple question: If an auditor reviewed this expenditure three years from now, would someone unfamiliar with the project understand exactly why it occurred, who authorized it, and how did it advance the program?

11:00

Compliance helps the organization answer yes by establishing approval thresholds, delegated authority, standard documentation, and retention expectations before that first obligation is made.

11:16

The organization should then reconcile activity monthly, compare actual spending to award restrictions, approved budgets, milestones, and forecasts, and investigate variances quickly. Document those decisions and track any remediation to closure.

11:36

This does more than prepare the organization for an audit. It helps leaders identify underspending, misalignment, delays, or unanticipated costs early enough to redirect resources and protect the intended outcome. A clean evidence trail turns stewardship into a repeatable operating discipline.

12:00

A significant portion of RHTP funding may be directed toward that technology-enabled care, including telehealth, remote monitoring, analytics, interoperability, cybersecurity, and those population health tools. But these investments can expand access, but they also expand operational, those privacy those cyber and those vendor risks.

12:25

Compliance must therefore move upstream. It should be involved before a vendor is selected and before a contract is signed.

12:34

So before selection or signature, define the data flows and who will have access. Complete security due diligence. Can’t overstate that. Confirm those HIPAA obligations and whether a business associate is required.

12:49

Establish uptime, backup, recovery, and incident notification expectations, and assign implementation ownership.

12:59

Define monitoring, audit, subcontractor, and your exit rights.

13:05

And during selection, score your functionality, the security, the interoperability, the support required, and sustainability-not just on your price alone.

13:17

So during contracting, place privacy, security, those incident response or service levels, any audit rights and subcontractor expectations specifically in the agreement.

13:28

And after implementation, be sure that you’re monitoring performance, the system access, those incidents, and corrective actions on a defined cadence,

13:38

because the compliance program adds value by making these decisions consistent and visible, no critical vendor risk decisions should depend on one person’s inbox or institutional memory.

13:52

And RHTP initiatives require active oversight by executive leadership and the governing board, but effective oversight does not require hundreds of pages of reporting. Boards need a concise, decision-ready view on a predictable cadence.

14:09

A dashboard should bring together your budget performance, meeting those project milestones, quality measures, cybersecurity,

14:19

workforce initiatives, vendor performance, and remediation.

14:23

The stoplight approach shown in the slide can make the information immediately understandable.

14:28

Green, of course, means the work is on plan and controlled. Yellow means management intervention may be needed, and red means a decision, an escalation, or prompt corrective action is required. And your compliance function can help establish objective thresholds, so status is not based only on project optimism. It can also ensure that issues are reported consistently across those work streams, because every review should close with four things:

15:00

Decisions made, and by whom,

15:03

the risks accepted or escalated, the owners and due dates, and the corrective actions and evidence required for closure.

15:13

This creates a record of active oversight and connects mission, public accountability, and regulatory expectations.

15:22

More importantly, it gives leadership the information needed to intervene while there is still time to predict and protect the investment and the outcome.

15:35

Now, this slide provides that practical roadmap for integrating compliance with implementation during the first 90 days,

15:44

the key is to build the control environment in parallel with delivery and not as a separate project. During days zero through 30, name your accountable owners, translate the award terms into operational obligations,

16:00

and inventory your vendors, your data flows, and any high-risk decisions.

16:05

This is also the time to identify what evidence will be needed and where it will be retained.

16:12

During days 31 through 60, approve policies and delegated authority, train the teams, launch monitoring, and capture baseline measures, because without a baseline, it may be difficult to show whether access, quality, your workforce capacity, or operational performance even improved. And during day 61 through 90, test the evidence trail and those key controls. Report status to leadership, resolve identified gaps, and confirm sustainability and oversight expectations. The goal is not more bureaucracy. The goal is an operating rhythm in which governance, controls, monitoring, and remediation support implementation rather than trail behind it. And by day 90, leaders should be able to see how dollars, the activities, the risks, and intended outcomes connect.

17:09

Now, if you’re wondering where to begin, this slide identifies four actions that can start immediately. First, put compliance at the table. Include compliance, finance,

17:21

Security, legal, quality, and those operational leaders and workstream governance now, while those decisions are still being shaped. Second, build one obligations list. Consolidate your award terms, your deadlines, the controls, measures,

17:39

vendors, and evidence requirements into a single usable inventory, because this becomes the common source of truth for implementation and oversight.

17:50

Third, assign control owners. For each critical control, identify who performs it, who reviews it, who documents it, and who escalates those concerns and who verifies closure.

18:03

Fourth, schedule the first review. Use one standing dashboard to assess spending, your milestones, your risks, your outcomes, and corrective actions together. Do not wait until the first formal report is due. And these four actions make accountability operational immediately. They also allow the organization to use its existing compliance infrastructure to remove uncertainty, surface any barriers, and improve the likelihood that RHTP dollars achieve their intended impact.

18:37

As we conclude, I want to return to the central message of this presentation:

18:42

The success of rural health transformation program investments will be ultimately measured not by the dollars awarded, or even the dollars spent, but by sustainable improvements in healthcare access, quality, workforce capacity, technology capabilities,

19:01

Operational resilience and community outcomes. The sources on this slide provide the broader program and compliance context, including the CMS RHT overview,

19:14

HHS program materials,

19:16

the funding opportunity,

19:18

state award materials,

19:21

HHS OIG compliance guidance and the DOJ’s compliance program evaluation framework. Those sources support the framework, but the organization’s current award documents and state guidance should control implementation decisions.

19:37

But an effective compliance program helps rural providers convert the award into outcomes by creating governance structures, protecting funds and data,

19:48

monitoring performance, and ensuring that corrective action occurs when implementation does not proceed as planned.

19:56

My challenge to rural providers is this: Do not treat compliance as a regulatory expense or a final review. Treat it as a strategic asset and a force multiplier, because when compliance is integrated from day one, the organization is better positioned to use every RHTP dollar effectively, demonstrate the value created, and sustain transformation for the communities it serves, thank you for joining me, and thank you for the important work that you do in rural healthcare.

20:30

So now that you have carefully considered and implemented a compliance roadmap, the next step is to monitor your activities. Join PYA for the next installment, episode four, dashboarding and Demonstrating Your Achievements. Thank you.

PYA

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.