Governance & boards
Oversight, accountability, independence and the practical mechanics that make governance work.
JD, MBA, CHC, CHRC, CCEP
I enjoy helping people connect the dots. My work has taken me through technology, law, teaching, and executive leadership. I draw on all of it to understand where someone is coming from, explain things plainly, and help them see how a decision fits into the bigger picture.

I spend a lot of time thinking about how people lead organizations: what they need to know, who gets to decide, and how to make sense of risk. These are a few of the subjects I write and speak about.
Oversight, accountability, independence and the practical mechanics that make governance work.
Risk appetite, assessment, escalation and connecting enterprise risk to actual decisions.
Program effectiveness, organizational behavior and the role of independent judgment.
Governance for technology that moves faster than the structures expected to oversee it.
Publications, keynote addresses, conference presentations, and conversations on healthcare, enterprise risk, board oversight, and the intersection of law and ethics.
HCCA Governance Manual
HCCA Complete Healthcare Compliance Manual
HCCA Compliance Perspectives · Guest conversation · 10 minutes
HCCA Board & Audit Committee Conference
HCCA Compliance Institute · Orlando
My introduction to the session · 1 min 16 sec
Connecting board oversight, clinical operations, compliance, and the practical work of building an ERM program.
HCCA Research Compliance Conference · Co-presented with my wife, Amy Stratton, MBA
Funding volatility, financial sustainability, and communicating research risk to executives and boards.
Kinsman Bioethics Conference
How healthcare lawyers approach ethical problems, with examples involving AI, privacy, apologies, and clinician safety.
Operations Technology Management Conference
Risk and opportunity, board oversight, organizational culture, and the assumptions that shape decisions.
At Vulcan, I worked on remarkable initiatives, including the Allen Institute for Brain Science. I enjoyed being part of that work, but my role in technology gave me a narrow view. I pursued a law degree and an MBA because I wanted to contribute to the bigger picture: to understand the business, help shape decisions, and take on broader responsibility.
That still motivates me. My career has included private practice, teaching, and leading legal, compliance, and enterprise risk work in healthcare. From 2012 to 2017, I taught as an adjunct professor at several local universities, nearly every quarter or semester. From 2017 to 2022, I taught exclusively at the University of Portland. Teaching was a regular part of my working life for a decade. I like helping leaders understand how their responsibilities fit together and what those responsibilities mean in practice. Sometimes a useful conversation changes how someone sees a problem.
I believe understanding something means being able to explain it simply. I also believe in being nice. You can disagree without being disagreeable, which matters a great deal in legal and compliance work. And a little humor helps.
In private practice, I advised public- and private-sector clients on business law, governance, contracts, and transactions. That included structuring a $10 million public-private venture capital fund and working on business valuations and asset and equity transactions.
At Northwest Permanente, I built enterprise risk management and internal audit programs from the beginning. My responsibilities grew to include compliance, policy systems, investigations, privacy, security and threat management, and legal advice. I also served as General Counsel and Chief Compliance Officer for Permanente Health Care Ventures.
Working within Kaiser Permanente gave me a view of healthcare that extended beyond the medical group to hospitals, system operations, and insurance. I worked with physician leaders, executives, and boards, including as administrative co-chair of the Board’s Enterprise Risk Management & Audit Committee.
More recently, my work has included predictive-model and AI governance.

There’s more to my life than work. Here are a few things I enjoy.

As a kid, I lived just south of Cape Canaveral. Our school took us outside to watch Challenger launch, and I saw it explode live. I’ve been fascinated with space ever since, and fascinated with risk.
The official investigation and report are still part of my speaking and risk work. One example I use is the way the flight data was framed: looking only at flights with O-ring damage obscured the relationship with temperature. Including flights without damage made the pattern clearer.
That example stays with me because the choice of what to include in the analysis changed what people could see. It’s a reason to ask what information is missing before relying on a conclusion.
I love science fiction. Space battles are part of the appeal, but so are the questions about people: how we live together, what we value, and what we might become. I especially enjoy stories that imagine an optimistic future.
I read around 50 books a year, mostly science fiction. My dad found an author-signed copy of Dune in Port Townsend. He likes telling that story, so I’ll leave the telling to him.
Attorney and senior executive with experience spanning healthcare law, compliance, enterprise risk, board governance, internal audit, and technology. Built enterprise programs, advised boards and executive leaders, served as General Counsel and Chief Compliance Officer for a healthcare venture subsidiary, and taught graduate business students.
Download executive profile ↓ PDFSenior General Counsel; Corporate Compliance Official; Executive Director, Enterprise Risk Management & Security
Built the ERM and internal audit infrastructure; led compliance and advised on healthcare regulation, investigations, privacy, physician arrangements, telehealth, and AI governance. Served as administrative co-chair of the Board’s Enterprise Risk Management & Audit Committee. Scope included two hospitals and approximately 40 clinics.
General Counsel & Chief Compliance Officer
Founding executive supporting innovative healthcare initiatives. Designed governance and compliance structures and advised on partnerships, inter-entity arrangements, technology agreements, and regulatory risk.
Attorney & Principal
Advised public- and private-sector clients on corporate law, governance, contracting, restructuring, valuation, and transactions. Structured a $10 million public-private venture capital fund.
Former Adjunct Professor
Taught nearly every quarter or semester at several local universities from 2012 to 2017, then exclusively at the University of Portland from 2017 to 2022. Courses included finance, economics, enterprise risk management, corporate governance and compliance, valuation, and business technology.
IT Manager
Led technology operations supporting biomedical research and aviation initiatives, including the Allen Institute for Brain Science.

I like examples that give people something to think about. These are a few I use to start a conversation.

A different view can interrupt familiar thinking and give us a chance to check our assumptions.
I use south-up maps in my talks because they make people pause. Australia and Antarctica are at the top, and it takes a moment to find your bearings. North at the top is a convention. The map is still showing the same world.
That moment is a consciousness raiser. It breaks the habit of looking at something in the way we always have. I think of the courtroom oath to tell “the truth, the whole truth, and nothing but the truth” in a similar way. Taking that oath asks a witness to pause and consider their answers carefully. “The whole truth” is especially relevant: what we leave out can change someone’s understanding just as much as what we say. The approximations and shortcuts we use in ordinary conversation deserve more attention when someone is relying on our testimony.
In governance, legal, compliance, and risk work, I use effective challenge to create that deliberate pause. It means checking the group’s reasoning, asking what we have assumed, and examining whether the evidence supports the decision. It also means making room for people to say what they actually think.
In my MBA program, we would ask, “Are we going to Abilene?” Jerry B. Harvey’s The Abilene Paradox: The Management of Agreement describes a family taking an unpleasant trip because each person thinks the others want to go. Afterward, they discover that everyone would have preferred to stay home. The apparent agreement concealed their shared reservations.
That question has stayed with me. Before acting on a consensus, I want to know whether people support the decision or are going along because they believe everyone else does.
Challenger adds another dimension. I watched the launch as a child, and the investigation remains part of my risk work. The decision involved technical uncertainty, organizational failures, and substantial schedule pressure within NASA. The Commission investigated claims of outside intervention and found no evidence of it. The circumstances deserve more care than a simple label like groupthink.
One analytical failure is especially useful in my talks. Managers compared launch temperatures for flights that had O-ring damage. Damage appeared across a range of temperatures, which obscured the relationship with cold. When the Commission included flights without damage, the pattern changed: all four flights at 63°F or below had O-ring distress, compared with three of twenty at 66°F or above.
Engineers had raised objections to launching in the cold. My point is that the decision process failed to adequately test and resolve the reasoning used to dismiss that concern. Asking, “Why are we excluding flights without damage?” could have exposed a serious weakness in the comparison. The selected data did not establish that cold was safe.
Pressure to deliver is part of organizational life. A deadline, an important commitment, or an influential person’s expectations can make it harder to pause. Those circumstances make effective challenge more valuable.
I want people to be able to ask: What are we leaving out? Does this comparison answer the question? What do we each actually think? A useful challenge gives the group a chance to reconsider while there is still time to make a different decision.
The map is a simple way to start that conversation. Once we notice how readily a familiar orientation shapes our thinking, we can look more carefully at the assumptions behind decisions that matter.
Read Jerry B. Harvey’s Abilene article (1988 reprint) ↗
Challenger Commission: temperature analysis ↗
Challenger Commission: pressures on the system ↗

It’s a useful place to begin a conversation about risk and opportunity.
My risk governance presentation starts with gambling. It gives us a familiar way to talk about what we stand to gain, what we could lose, and how much we’re willing to put at stake.
Organizations face those questions too. A useful risk conversation starts with the opportunity we’re pursuing and the uncertainty we’re willing to accept. That makes risk appetite something people can discuss in the context of an actual decision.

How individual expertise connects to the purpose, risks, and opportunities of an organization.
Philosopher John Searle introduced the Chinese Room thought experiment in 1980. Imagine a person who cannot understand Chinese sitting inside a room. People outside pass in written questions in Chinese. Using an elaborate instruction book, the person manipulates the symbols and sends back answers convincing enough that those outside believe they are communicating with someone who understands the language. Inside the room, the person understands neither the questions nor the answers. Chinese is simply the unfamiliar language in this example; another language unknown to the participant would serve the same purpose.
Searle’s argument is that following rules for manipulating symbols does not, by itself, establish understanding. I used to call this the “Siri problem” to give audiences a more familiar reference. Today, large language models make the question even more immediate. Applied to an LLM, Searle’s argument would challenge whether its sophisticated computational processes produce understanding, even when its responses appear knowledgeable. That remains a contested philosophical question.
In a complex organization, each department or each step in a process may perform its assigned work without understanding the bigger picture. People know what comes in, what they are supposed to do, and what gets passed along. They may have little visibility into the ultimate purpose, the risks created across the process, or the opportunity the organization is pursuing.
One objection to Searle is that understanding might belong to the whole system, even if the person inside the room lacks it. I find that especially useful when thinking about organizations. No individual needs to know everything. But the organization needs some way to connect what people know, examine the assumptions between steps, and make decisions with a view of the whole. That is a central concern in my risk and governance work.
A process can produce the expected output at every step while leaving important questions unanswered. Who understands what the organization is trying to accomplish? Who can recognize a risk that crosses departmental boundaries, or an opportunity that falls outside anyone’s assigned responsibility?
The Chinese Room gives us a way to ask whether our processes connect individual expertise into organizational understanding. Completing each step tells us something about execution. We still need to ask who can see what it all means.
How authority, sound decision processes, and active risk oversight come together in corporate governance.
I once worked with a shareholder elections committee chair who wanted to impose additional limits on who could run for the board. The conversation changed when I explained that the shareholders get to decide whom they want as directors. Her responsibility was to administer a fair election within the company’s governing rules. That distinction helped her see her role differently.
I come back to that question often in corporate governance. Who has the authority to make a decision? Whose interests are they serving? What process should they follow?
Shareholders own the company. Directors and officers are entrusted with authority to act on behalf of the corporation and its shareholders. Understanding that responsibility means paying attention to how decisions are made, as well as what those decisions produce.
Corporate governance is an area where process and outcome both matter. Leaders need reasonable information, a clear understanding of their authority, and judgment unclouded by personal conflicts. They also need systems that bring important concerns to their attention and a process for following up.
The business judgment rule recognizes that even a sound decision can produce a bad outcome. Courts generally give considerable deference to informed, good-faith decisions made by leaders without disqualifying conflicts. Those leaders had their boots on the ground. Hindsight does not reproduce everything they knew or faced at the time.
Caremark brings oversight into that picture. Its expansion, particularly beginning with the Blue Bell decision in 2019, made the responsibility for monitoring critical risks much more concrete. Directors need to make a good-faith effort to establish risk reporting and monitoring systems and actively monitor through them. That includes reviewing the information, responding to red flags, and following up. The 2023 McDonald’s decision expressly recognized officers’ oversight duties within their areas of responsibility. Serious oversight failures can expose directors and officers personally.
These responsibilities have consequences beyond the company. Blue Bell’s listeria outbreak killed three people. Food safety was fundamental to its business, yet the allegations described a failure to establish a board-level system for monitoring it. Healthcare, food, and construction are heavily regulated because failures can harm patients, customers, workers, and the public. That public interest belongs in the governance conversation.
I work with physicians who bring extraordinary attention to detail and outcomes to their board roles. In surgery or the care of a critically ill patient, that attention is essential. In corporate governance, it can sometimes draw them too far into an individual decision and away from the process surrounding it.
I have often said, “No one is dying in the boardroom.”
It is a reminder to pause. The board usually has time to ask who should make the decision, what information is needed, and how the organization will monitor the result. The systematic mistakes deserve particular attention: important information repeatedly failing to reach decision makers, conflicts going unaddressed, concerns being suppressed, or nobody following up.
Failures in the boardroom can still affect people’s lives outside it. That is why getting the process right matters.
When something goes wrong, I want to understand the result and how the organization arrived there. Was the decision reasonable based on what people knew? Was important information available but never brought forward? Did someone raise a concern that went unanswered? Is the same weakness affecting other decisions?
My work is to help organizations establish and use a governance process that answers those questions before a crisis. People should understand their authority, have the information they need, and know what requires further attention.
A good process gives leaders room to exercise judgment. It also gives the organization a basis for learning from a bad outcome without treating every disappointing result as proof that someone made an improper decision.
What the first risk register reveals about candor, psychological safety, and leadership.
Ethical decision making and speak-up culture depend on how clearly an organization communicates its objectives, goals, and risk appetites. People need to understand what they are trying to accomplish, what tradeoffs they can make, and when a concern needs to reach someone else.
They also need psychological safety: confidence that they can ask a question, acknowledge uncertainty, challenge an assumption, or report a problem without humiliation or retaliation. Clear expectations help people exercise judgment. Psychological safety helps them speak when that judgment tells them something needs attention.
An organization’s first risk assessment illustrates how easily those conditions can break down.
Some leaders openly identify risks, explain weaknesses, and describe what could go wrong. Others share little or hide concerns. The resulting risk register may make the most forthcoming leaders appear to have the most troubled departments. Less transparent leaders can appear to have everything under control.
The register then reflects differences in candor as well as differences in risk. If leadership treats it as a performance ranking, the organization gets an inaccurate picture and penalizes the people who helped make that picture clearer.
I use risk-based governance to connect organizational objectives to the decisions people make throughout the business. Clear risk appetites and escalation expectations help people understand where they can exercise discretion, what requires further discussion, and how to explain their reasoning.
That framework also establishes how leaders should use information about risk. Identifying a concern begins a conversation about its significance and what to do about it. The number of risks a leader reports says little, by itself, about how well that person leads.
When reviewing an initial assessment, I want to understand how the information entered the register. Are departments using similar thresholds? Do people understand the questions? Do they trust the process? Does a short list reflect limited exposure, limited awareness, or reluctance to disclose?
Psychological safety matters here because people take an interpersonal risk when they reveal a weakness or disagree with someone influential. Leaders need to demonstrate that candor receives a fair hearing. Accountability remains essential, including accountability for concealing a concern. A fair review considers what someone knew, the choices available, and how they acted.
I also consider organizational structure. Employee-owned companies, privately held businesses, public companies, benefit companies, and nonprofits distribute authority and accountability differently. Those arrangements can influence whose interests leaders prioritize, how they respond to good and bad news, and how comfortable employees feel challenging a decision. Structure provides part of the context; leadership’s behavior determines whether openness feels credible.
People notice what happens to colleagues who speak candidly. If reporting a risk brings blame, the next assessment may look better because people have learned to share less.
I want governance to give people a clear basis for making wise decisions and confidence that reasonable judgment will receive fair consideration. That requires transparency about objectives and acceptable risk, psychological safety to raise concerns, and a consistent response from leadership.
A useful risk register depends on people being willing to tell the organization what it needs to know. How leaders respond to that information shapes the quality of the next decision, the next assessment, and the culture people work in every day.
How cognitive biases affect information and decisions across a complex organization.
Geoffrey Miller and Gerald Rosenfeld introduced “intellectual hazard” in a 2009 working paper, published in the Harvard Journal of Law & Public Policy in 2010. They examined how behavioral biases interfere with the way complex organizations acquire, analyze, communicate, and act on information. Their analysis focused on the 2008 financial crisis, with connections to failures in space exploration and surgery.
The concept draws attention to what happens to information as it moves through an organization. Important evidence may receive too little attention, lose context between departments, or fail to reach someone who can act on it.
I work with a lot of smart people, including physicians and lawyers. Their expertise is essential, but expertise does not make anyone immune to cognitive bias. A familiar explanation can become an assumption we stop testing. Information that supports our judgment can seem more persuasive than information that challenges it.
Intellectual hazard helps me examine how those tendencies affect the organization. Whose judgment carries weight? Can someone question an established view? Does information retain its meaning as it moves from a specialist to management and then to the board?
Those questions matter because decisions often depend on several people’s expertise. Each person may understand their part well, while the organization struggles to connect what they know.
Qualified people, extensive data, and formal reporting processes can coexist with serious gaps in understanding. In my risk and governance work, I look for ways to make those gaps visible and give people room to challenge a conclusion.
I want someone to be able to ask, “What would make us reconsider?” without others hearing it as an attack on their competence. That question can help an organization recognize a risk, revisit an assumption, or see an opportunity it has overlooked.
If something here interests you, I’d enjoy hearing from you. I’m happy to talk about leadership, a question you’re working through, speaking opportunities, or working together.
Start a conversation ↗For independent legal and consulting work: Officer and the Board ↗