The Conference Everyone Will Be Talking About
Everything you need to plan your NEHIA/HFMA Joint: 2026 Compliance & Internal Audit Conference experience is right here. Explore registration information, conference details, speaker highlights, educational sessions, networking opportunities, and hotel accommodations as you prepare for the conference everyone will be talking about.
Registration
Registration for the NEHIA/HFMA Joint 2026 Compliance & Internal Audit Conference is now open! Use the registration link below to secure your attendance and take advantage of Early Bird savings while available.
Whether you're joining for the educational sessions, expert speakers, networking opportunities, or industry insights, this year's conference offers something for every healthcare compliance, privacy, audit, legal, and security professional.
$525
Full Conference Early Bird Registration: Available through October 30, 2026
$575
Full Conference Registration: After October 30, 2026
$300
Single Day Registration: December 2, 3, or 4
Hotel Accommodations
Stay Where the Action Is
Enhance your conference experience by staying at the official 2026 host hotel, the Mystic Marriott Hotel & Spa in Groton, CT. Take advantage of discounted conference rates, convenient access to all sessions and events, and additional opportunities to connect with speakers, sponsors, and fellow attendees throughout the conference.
Rooms in the conference block are limited and expected to sell out. Secure your accommodations early to guarantee availability and the special conference rate.
Book your room through the official conference block and stay at the center of the NEHIA/HFMA Joint: 2026 Compliance & Internal Audit Conference experience.
Explore the Agenda and Meet The Speakers
Wednesday, December 2
-
A continental breakfast will be available prior to the start of the conference.
-
Julie Hall
President
HFMA, Massachusetts-Rhode Island ChapterValerie Campbell
President
New England Healthcare Internal Auditors (NEHIA) -
Both Fraud and cyber-threats are persistent within the healthcare sector and are a priority for the FBI. Captioned presentation will provide an overview of emergent fraud trends identified across healthcare providers along with an recent cyber-threats targeting the healthcare sector to include best practices for response and law enforcement coordination.
Learning Objectives:Become familiar with emergent services subject to fraudulent billing.
Recognize current general, and sector-specific, cyber-threats and resulting response expectations.
Build trust and cooperation between the healthcare sector and the FBI / law enforcement.
-
Enjoy a 15-minute break between morning sessions to recharge, connect with colleagues, and prepare for the next discussion.
-
The 340B landscape is evolving faster than many compliance and audit teams can track manually — contract pharmacy restrictions, manufacturer rebate models, HRSA audit activity, and state-level 340B laws are all shifting at once. This session explores how compliance and internal audit functions are turning to AI-enabled tools to monitor regulatory change, flag diversion and duplicate discount risk, and prioritize audit testing more efficiently.
Learning Objectives:
Understand the basics and intermediate level of 340B compliance.
Understand the current 340B regulatory environment and how 340B and MFP intersect.
Providing insight into the role Internal Audit can have within the organization’s 340B program.
Speakers:
Katie Gonick
Manager
DeloitteLarry Katzman
Internal Audit Director
NYU Langone HealthCarsten Lachell
Manager
Deloitte -
Behavioral health is one of the fastest-growing, most heavily scrutinized segments of U.S. health care. Reimbursement expansion and telehealth services have attracted parallel attention from DOJ, HHS-OIG, state attorneys general, and the FTC. This panel brings together an operator’s and a defense lawyer’s perspective on where the risk is and how compliance programs need to evolve to keep pace with those risks.
Learning Objectives:
Identify the leading sources of behavioral health reimbursement opportunities and risks.
Understand current DOJ, OIG, and state enforcement priorities.
Evaluate telehealth, AI, and PE-related compliance concerns.
Develop practical strategies to reduce financial and regulatory exposure.
Speakers:
Maria Jackson
CEO
Bournewood Health SystemsEmma Spiro
Partner
Petrillo Klein + Boxer LLPTorrey Young
Partner
Seyfarth Shaw LLP -
Enjoy lunch in Mystic Salons A & D while continuing the conversation with fellow attendees.
-
Clinical trial billing compliance requires far more than a coverage analysis—it depends on coordinated, accountable processes across physicians, study teams, research finance, pharmacy, laboratory services, revenue cycle, and compliance functions. This session explores how organizations can build an integrated, audit-ready clinical research billing ecosystem that embeds compliance into operational workflows and distributes responsibilities across stakeholders. Participants will examine common risk areas, including communication breakdowns between departments, inconsistent coverage analysis implementation, investigational product billing challenges, laboratory charge routing, order set design, and physician billing oversight. Through interactive case-based exercises, attendees will map coverage analysis requirements to real-world ordering and billing workflows to identify points of risk and opportunities for improvement. The session will highlight practical tools, standardized templates, accountability frameworks, and governance strategies that help institutions strengthen compliance, improve billing accuracy, enhance audit readiness, and support sustainable clinical research operations.
Learning Objectives:
Designing a model focused on distributing compliance responsibilities across study teams and ancillary services with clear accountability and escalation pathways.
Analyzing how inter-departmental workflows intersect with coverage analysis requirements and identify risk points that lead to hospital and physician billing non-compliance.
Applying structured tools to build standardized, audit-ready processes for clinical trials.
Speaker:
Lynn D. Blake
Director, Clinical Research Compliance & Privacy
Stony Brook Medicine -
This session explores the real-world operational challenges of hospital price transparency and CMS monitoring, with a focus on the practical steps compliance, data integrity, pricing, and internal audit teams can take today. Through real-world scenarios, from developing compliant machine-readable files and maintaining ongoing compliance to responding to CMS warning letters and adapting to evolving regulations, attendees will gain insight into how cross-functional teams can effectively coordinate to meet regulatory requirements.
Learning Objectives:
Describe the current regulatory landscape for hospital price transparency and CMS monitoring, including emerging legislative proposals and their practical implications for hospitals.
Identify common operational challenges in creating and maintaining compliant machine-readable files, responding to CMS letters/violation notices, and interpreting regulatory updates.
Apply real-world scenarios and case examples to define concrete steps attendees can take back to their organizations to improve compliance processes and communication.
Speakers:
Heather Dubois
Director of Revenue Integrity
Brown University HealthBryan Gordon
Senior Regional Account Executive
Cleverley + Associates -
Take a moment to recharge and reflect before the afternoon sessions begin.
-
This session will examine physician compliance risk areas that continue to drive regulatory scrutiny: documentation integrity, billing accuracy, and supervision requirements. These topics are especially important as healthcare organizations rely heavily on EMR documentation and increasingly complex care delivery models. Presenters will focus on practical risks and monitoring strategies compliance teams can apply.
Learning Objectives:
Recognize high-risk areas in physician billing and supervision.
Evaluate documentation practices for compliance with CMS guidelines.
Develop monitoring and auditing approaches tailored to physician compliance.
Apply lessons learned from enforcement trends to everyday operations.
Speakers:
Chuck Mazer
Clinical Compliance Officer
Weill Cornell MedicineMaria Joseph
Chief Compliance & Privacy Officer
Weill Cornell Medicine -
Join us as we recap the day’s insights, celebrate new connections, and look ahead to tomorrow’s sessions.
Thursday, December 3
-
Fuel up for another full day of learning, networking, and engagement with a buffet breakfast.
-
Kick off Day 2 with opening remarks, conference updates, and a preview of the day's sessions.
-
Durable medical equipment fraud is one of the most detrimental frauds in the healthcare industry, costing federal and private insurance carriers, particularly Medicare, billions of dollars annually. This case presentation showcases real case examples of a fraudulent telemedicine company and the steps that they took to circumvent law enforcement scrutiny. The presentation will cover new billing methods used to give the appearance of a genuine doctor/patient relationship, sham contracts used to conceal the illegal online sale of signed DME doctor’s orders, and the use of artificial intelligence to create fictitious medical consult audio recordings. Presenters will share their use of covert investigative techniques to gather critical evidence leading to the conviction of the company owner.
Learning Objectives:
Learn about the various techniques being utilized by fraudsters to execute nationwide DME and telemedicine fraud schemes.
Attendees will gain exposure to the use of artificial intelligence in purported call center and telemedicine consultation recordings, and the investigative steps used to successfully dismantle the criminal network.
Highlight the continued importance of claim data analysis in conjunction with collaboration between law enforcement and SIUs as a key to investigative success.
Speakers:
Anna Ferreira-Pandolfi
HHS-OIG Special Agent / Criminal Investigator
FBIAlbert Tenuta
Special Agent
FBIDhara Satija
Director, Life Sciences and Healthcare Consulting Group
Paul Hastings -
Take a mid-morning pause to recharge, connect with colleagues, and continue the conversation.
-
Join us for an insightful discussion with two Chief Information Security Officers as we explore the evolving cybersecurity landscape and the critical role of collaboration between compliance, privacy, and information security leaders. This session will highlight practical examples of effective partnership models that strengthen organizational resilience and support regulatory compliance. Panelists will discuss today's most significant cyber risks, including emerging threats associated with artificial intelligence and the growing importance of AI governance frameworks. The conversation will also cover key risk management practices such as vendor due diligence, third-party oversight, and data mapping strategies that help organizations understand and protect sensitive information. In addition, attendees will gain perspectives on the proposed updates to the HIPAA Security Rule and the potential implications for healthcare organizations. Participants will leave with actionable insights and best practices for building stronger cross-functional partnerships to address cybersecurity, privacy, and compliance challenges in an increasingly complex environment.
Learning Objectives:
Identify effective strategies for collaboration between Compliance, Privacy, and Information Security leaders to strengthen organizational risk management and regulatory compliance.
Evaluate emerging cybersecurity risks, including AI-related threats, vendor and third-party risks, and the role of data mapping in protecting sensitive information.
Assess the impact of proposed HIPAA Security Rule updates and apply practical approaches to enhance cybersecurity and governance programs within healthcare organizations.
Speakers:
Rachel Kurzweil
Of Counsel, Litigation
Paul HastingsKaitlin McCarthy
Associate Deputy Compliance Officer
Beth Israel Lahey HealthMatt Shaw
Chief Information Security Officer
Southcoast HealthBruce M. Forman
Chief Information Security Officer
UMass Memorial Health -
Disaster Recovery and Protection of Staff - Where Does Compliance and Internal Audit Fit In? Crisis management, executive protection, physical security, and disaster recovery/downtime procedures should be woven together into the risk assessment for Compliance and Internal Audit Plans in Healthcare.
Learning Objectives:
Understanding what situations would be considered "disaster recovery" and needing staff personal protections.
Understanding how Compliance and Internal Audit can play a role in the above.
Understanding where law enforcement such as the FBI can assist in the above.
Speakers:
Jay Greenberg
Managing Director
EYDonna Schneider
Vice President, Corporate Compliance and Internal Audit
Brown University Health -
Enjoy lunch and meaningful conversation with fellow attendees before we reconvene for the afternoon program.
-
Healthcare organizations are facing increasing pressure to interpret and implement annual coding, documentation, and reimbursement changes while managing heightened scrutiny from payers, auditors, and regulators. This session provides a practical review of key 2027 coding and regulatory updates that present compliance, operational, and financial risk. Through real-world audit findings, case examples, and lessons learned from compliance and coding reviews, attendees will gain insight into common documentation and billing vulnerabilities and emerging areas of payer focus. More importantly, participants will leave with actionable strategies, audit tools, monitoring approaches, and provider education techniques that can be implemented immediately to improve documentation integrity, strengthen compliance oversight, enhance audit readiness, and reduce organizational risk. This session is designed to provide practical takeaways that attendees can apply within their organizations as soon as they return to the office.
Learning Objectives:
Identify key 2027 coding and regulatory updates that may increase compliance risk.
Recognize common audit risk areas associated with coding, billing, and documentation.
Implement strategies to improve audit readiness and strengthen compliance oversight.
Speaker:
Pam D’Apuzzo
Managing Director
VMG Health -
Drug diversion remains a significant compliance, operational, and financial risk for healthcare organizations, but it is often only one symptom of broader weaknesses within pharmacy oversight and fraud, waste and abuse (FWA) control environments. Drawing on real-world assessments of health systems, pharmacies, and controlled substance monitoring programs, this session explores common diversion issues, emerging pharmacy-related FWA risks, and practical strategies for strengthening internal controls. Attendees will gain insights into governance, analytics, investigations, and monitoring techniques that help organizations identify vulnerabilities before they become bigger issues. The session will provide actionable leading practices that internal audit, compliance and operational leaders can apply immediately within their organizations.
Learning Objectives:
Identify common drug diversion and pharmacy-related FWA risk indicators.
Discuss key controls across controlled substance management and monitoring processes.
Apply leading practices for auditing, investigating, and monitoring pharmacy risks.
Speakers:
Brittany Ferguson
Manager, Forensic and Integrity Services
EYEmily Huebener
CPA Partner, Forensic and Integrity Services
EY -
Take a moment to connect with exhibitors, colleagues, and conference resources before the program resumes.
-
After the presentation the audience will have an enhanced understanding of internal audit trends and leading practices across the internal audit lifecycle that can be used to reset your strategy for the next 2-3 years. Presentation will highlight changing trends related to Internal audit mandates, operating models, risk assessment processes, technology, AI and ways of working, reporting and metrics and KPI's.
Learning Objectives:
Better understanding of leading internal audit trends in 2026.
Understanding how to refresh your Internal Audit strategy for the future.
Overview of technology and trends in the profession.
Speaker:
John Ackerman
Partner / Principal
EY -
Healthcare coding and billing continue to evolve amid changing regulatory expectations, increased enforcement activity, technological innovation, and ongoing operational pressures. This session will provide an update on emerging issues affecting providers, including recent and proposed regulatory developments, government enforcement priorities, documentation and coding risks, the growing use of artificial intelligence and automation within revenue cycle functions, and practical considerations for governance and oversight. Presenters will discuss how compliance and internal audit functions can proactively identify risk, evaluate emerging technologies, strengthen monitoring activities, and partner with operational leaders to support compliant, efficient billing practices. The discussion will also highlight lessons learned from recent experiences, common pitfalls, and practical strategies organizations can implement to enhance coding integrity while preparing for future regulatory and technological changes.
Learning Objectives:
Describe emerging coding and billing risks arising from evolving regulatory requirements, enforcement priorities, and operational changes impacting healthcare providers.
Evaluate opportunities and risks associated with the use of artificial intelligence and automation within coding, billing, documentation review, and revenue cycle processes, including key governance considerations.
Apply practical strategies to strengthen compliance and internal audit oversight through risk-based monitoring, auditing, and collaboration with operational stakeholders.
Speakers:
Kelly Sauders
Partner, Health Care Counseling
Deloitte & Touche, LLPStephen Gillis
Director, Compliance Coding, Billing & Audit
Mass General BrighamHeather Hagan
Principal
Health Care Counseling -
Join us as we wrap up another engaging day and look ahead to tomorrow's sessions.
-
The day's learning doesn't end when the sessions conclude. Join us for an evening networking reception to continue conversations, exchange insights, and build meaningful connections with fellow attendees and industry professionals.
Friday, December 4
-
Join us for breakfast as we kick off the final day of learning, collaboration, and connection.
-
Begin the day with conference updates, key announcements, and a preview of the insightful sessions still to come.
-
This panel presentation will focus on practical AI use cases for Compliance and Privacy professionals.
Learning Objectives:
Understand Compliance best practices for AI with respect to AI for compliance monitoring, Privacy risks and use cases, including shadow AI, third-party risk, and proactive use of agents.
Developing an AI policy (key terms, launching & training).
Conducting better/faster regulatory research with AI.
Governance to evaluate vendors.
Using AI to create tools to manage conflicts of interest.
Speakers:
Garrett Gillespie
Chief Compliance Officer
Tufts MedicineGrace Jodhan
Privacy Officer
Luminis HealthMichael Lozzi
Conflict of Interest Officer
Boston Children's HospitalLori Dutcher
Chief Compliance Officer
Beth Israel Lahey Health -
As healthcare organizations navigate increasing regulatory complexity and operational and technological challenges, Internal Audit, Compliance, and Privacy leaders must work together to provide effective oversight while maintaining distinct responsibilities. Join leaders representing these three lines from UMass Memorial Health, Rochester Regional Health, and Hospital for Special Surgery as they share practical approaches to risk assessment, emerging challenges, technology adoption, and building trusted partnerships and communication lines across the enterprise. Attendees will gain actionable insights on coordinating risk activities, reducing duplication, enhancing collaboration and advancing integrated risk management programs.
Learning Objectives:
Differentiate the unique responsibilities and perspectives of Internal Audit, Compliance, and Privacy functions within healthcare organizations.
Explore practical approaches for coordinating enterprise risk assessments and prioritizing emerging risks across multiple oversight functions.
Understand how Internal Audit, Compliance, and Privacy leaders are evaluating and leveraging AI and other emerging technologies.
Identify leadership strategies for building influence, developing strong relationships, and advancing careers across governance, risk, and compliance functions.
Speakers:
Robert Cournoyer
Vice President, Internal Audit
UMass Memorial HealthK. Ellen Gallagher
Senior Vice President, Chief Audit, Compliance & Privacy Officer
Rochester Regional HealthIrene Ma
Senior Director
Hospital for Special SurgeryWendy Chartrand
Chief Compliance and Privacy Officer
UMass Memorial Health - HealthAlliance-Clinton Hospital -
Enjoy a brief break before we reconvene for the remaining sessions and conference highlights.
-
Successful compliance officers do more than interpret regulations. They influence behavior, build trust, and drive meaningful organizational change. This engaging session is designed for compliance professionals seeking to strengthen their impact without relying on authority, title, or regulatory requirements alone. Participants will learn practical strategies to build credibility, gain stakeholder buy-in, navigate organizational politics, and hold others accountable while preserving strong relationships. Through real-world case studies, discussion, and actionable tools, attendees will explore how to adapt to different styles, manage resistance, lead difficult conversations, and create partnerships that advance compliance goals. The session challenges compliance professionals to move beyond email-driven communication and become catalysts for engagement, understanding, and sustainable change. Attendees will leave with practical tools and confidence to influence outcomes, foster accountability, and achieve compliance success across complex organizations.
Learning Objectives:
Participants will be able to strengthen influence without authority.
Build Credibility, trust, and accountability.
Adapt their communication to different styles and stakeholders.
Speaker:
Danielle Fagan
Vice President, Adult Psychiatry & Rehabilitation
Brown University Health -
In this presentation, we will provide an overview of recent policy changes targeted at the establishment and billing practices of hospital off-campus provider-based departments (HOPDs), with a particular focus on new attestation and NPI requirements for HOPDs by January 1, 2028. We will review recent trends observed related to existing and new HOPD sites, then discuss what hospitals need to be doing to comply with the new requirements by 2028. We will close by answering questions and opening the discussion to conference attendees to share how their organizations are responding.
Learning Objectives:
Regulatory requirements to establish an HOPD.
New requirements applicable to HOPD’s in 2028.
Review of billing implications of HOPD status.
Speaker:
Conor Duffy
Partner and Co-Chair of the Health Care Practice Group
Robinson & Cole, LLP -
As we bring the 2026 conference to a close, join us for final reflections on the ideas, challenges, and opportunities explored throughout the conference. We'll celebrate the connections made, the knowledge shared, and the collective efforts driving the future of healthcare compliance, privacy, audit, legal, and security.