Governance & boards
Oversight, accountability, independence and the practical mechanics that make governance work.
JD, MBA, CHC, CHRC, CCEP
I enjoy helping people connect the dots. My work has taken me through technology, law, teaching, and executive leadership. I draw on all of it to understand where someone is coming from, explain things plainly, and help them see how a decision fits into the bigger picture.

I spend a lot of time thinking about how people lead organizations: what they need to know, who gets to decide, and how to make sense of risk. These are a few of the subjects I write and speak about.
Oversight, accountability, independence and the practical mechanics that make governance work.
Risk appetite, assessment, escalation and connecting enterprise risk to actual decisions.
Program effectiveness, organizational behavior and the role of independent judgment.
Governance for technology that moves faster than the structures expected to oversee it.
Publications, keynote addresses, conference presentations, and conversations on healthcare, enterprise risk, board oversight, and the intersection of law and ethics.
HCCA Governance Manual
HCCA Complete Healthcare Compliance Manual
HCCA Compliance Perspectives · Guest conversation · 10 minutes
HCCA Board & Audit Committee Conference
HCCA Compliance Institute · Orlando
My introduction to the session · 1 min 16 sec
Connecting board oversight, clinical operations, compliance, and the practical work of building an ERM program.
HCCA Research Compliance Conference · Co-presented with my wife, Amy Stratton, MBA
Funding volatility, financial sustainability, and communicating research risk to executives and boards.
Kinsman Bioethics Conference
How healthcare lawyers approach ethical problems, with examples involving AI, privacy, apologies, and clinician safety.
Operations Technology Management Conference
Risk and opportunity, board oversight, organizational culture, and the assumptions that shape decisions.
At Vulcan, I worked on remarkable initiatives, including the Allen Institute for Brain Science. I enjoyed being part of that work, but my role in technology gave me a narrow view. I pursued a law degree and an MBA because I wanted to contribute to the bigger picture: to understand the business, help shape decisions, and take on broader responsibility.
That still motivates me. My career has included private practice, teaching, and leading legal, compliance, and enterprise risk work in healthcare. From 2012 to 2017, I taught as an adjunct professor at several local universities, nearly every quarter or semester. From 2017 to 2022, I taught exclusively at the University of Portland. Teaching was a regular part of my working life for a decade. I like helping leaders understand how their responsibilities fit together and what those responsibilities mean in practice. Sometimes a useful conversation changes how someone sees a problem.
I believe understanding something means being able to explain it simply. I also believe in being nice. You can disagree without being disagreeable, which matters a great deal in legal and compliance work. And a little humor helps.
In private practice, I advised public- and private-sector clients on business law, governance, contracts, and transactions. That included structuring a $10 million public-private venture capital fund and working on business valuations and asset and equity transactions.
At Northwest Permanente, I built enterprise risk management and internal audit programs from the beginning. My responsibilities grew to include compliance, policy systems, investigations, privacy, security and threat management, and legal advice. I also served as General Counsel and Chief Compliance Officer for Permanente Health Care Ventures.
Working within Kaiser Permanente gave me a view of healthcare that extended beyond the medical group to hospitals, system operations, and insurance. I worked with physician leaders, executives, and boards, including as administrative co-chair of the Board’s Enterprise Risk Management & Audit Committee.
More recently, my work has included predictive-model and AI governance.

There’s more to my life than work. Here are a few things I enjoy.

As a kid, I lived just south of Cape Canaveral. Our school took us outside to watch Challenger launch, and I saw it explode live. I’ve been fascinated with space ever since, and fascinated with risk.
The official investigation and report are still part of my speaking and risk work. One example I use is the way the flight data was framed: looking only at flights with O-ring damage obscured the relationship with temperature. Including flights without damage made the pattern clearer.
That example stays with me because the choice of what to include in the analysis changed what people could see. It’s a reason to ask what information is missing before relying on a conclusion.
I love science fiction. Space battles are part of the appeal, but so are the questions about people: how we live together, what we value, and what we might become. I especially enjoy stories that imagine an optimistic future.
I read around 50 books a year, mostly science fiction. My dad found an author-signed copy of Dune in Port Townsend. He likes telling that story, so I’ll leave the telling to him.
Attorney and senior executive with experience spanning healthcare law, compliance, enterprise risk, board governance, internal audit, and technology. Built enterprise programs, advised boards and executive leaders, served as General Counsel and Chief Compliance Officer for a healthcare venture subsidiary, and taught graduate business students.
Download executive profile ↓ PDFSenior General Counsel; Corporate Compliance Official; Executive Director, Enterprise Risk Management & Security
Built the ERM and internal audit infrastructure; led compliance and advised on healthcare regulation, investigations, privacy, physician arrangements, telehealth, and AI governance. Served as administrative co-chair of the Board’s Enterprise Risk Management & Audit Committee. Scope included two hospitals and approximately 40 clinics.
General Counsel & Chief Compliance Officer
Founding executive supporting innovative healthcare initiatives. Designed governance and compliance structures and advised on partnerships, inter-entity arrangements, technology agreements, and regulatory risk.
Attorney & Principal
Advised public- and private-sector clients on corporate law, governance, contracting, restructuring, valuation, and transactions. Structured a $10 million public-private venture capital fund.
Former Adjunct Professor
Taught nearly every quarter or semester at several local universities from 2012 to 2017, then exclusively at the University of Portland from 2017 to 2022. Courses included finance, economics, enterprise risk management, corporate governance and compliance, valuation, and business technology.
IT Manager
Led technology operations supporting biomedical research and aviation initiatives, including the Allen Institute for Brain Science.

I like examples that give people something to think about. These are a few I use to start a conversation.

A familiar world can look surprisingly unfamiliar when south is at the top.
I use south-up maps in my talks because they make people pause. Australia and Antarctica are at the top, and it takes a moment to find your bearings. We get so used to north being at the top that we forget it’s a choice.
I use that moment to ask what other assumptions we’ve stopped noticing. A different frame can change how we understand the same information.

It’s a useful place to begin a conversation about risk and opportunity.
My risk governance presentation starts with gambling. It gives us a familiar way to talk about what we stand to gain, what we could lose, and how much we’re willing to put at stake.
Organizations face those questions too. A useful risk conversation starts with the opportunity we’re pursuing and the uncertainty we’re willing to accept. That makes risk appetite something people can discuss in the context of an actual decision.

How individual expertise connects to the purpose, risks, and opportunities of an organization.
Philosopher John Searle introduced the Chinese Room thought experiment in 1980. Imagine a person who cannot understand Chinese sitting inside a room. People outside pass in written questions in Chinese. Using an elaborate instruction book, the person manipulates the symbols and sends back answers convincing enough that those outside believe they are communicating with someone who understands the language. Inside the room, the person understands neither the questions nor the answers. Chinese is simply the unfamiliar language in this example; another language unknown to the participant would serve the same purpose.
Searle’s argument is that following rules for manipulating symbols does not, by itself, establish understanding. I used to call this the “Siri problem” to give audiences a more familiar reference. Today, large language models make the question even more immediate. Applied to an LLM, Searle’s argument would challenge whether its sophisticated computational processes produce understanding, even when its responses appear knowledgeable. That remains a contested philosophical question.
In a complex organization, each department or each step in a process may perform its assigned work without understanding the bigger picture. People know what comes in, what they are supposed to do, and what gets passed along. They may have little visibility into the ultimate purpose, the risks created across the process, or the opportunity the organization is pursuing.
One objection to Searle is that understanding might belong to the whole system, even if the person inside the room lacks it. I find that especially useful when thinking about organizations. No individual needs to know everything. But the organization needs some way to connect what people know, examine the assumptions between steps, and make decisions with a view of the whole. That is a central concern in my risk and governance work.
A process can produce the expected output at every step while leaving important questions unanswered. Who understands what the organization is trying to accomplish? Who can recognize a risk that crosses departmental boundaries, or an opportunity that falls outside anyone’s assigned responsibility?
The Chinese Room gives us a way to ask whether our processes connect individual expertise into organizational understanding. Completing each step tells us something about execution. We still need to ask who can see what it all means.
Clarifying who decides can change how someone understands their responsibility.
A shareholder elections committee chair once wanted to impose rules limiting who could run for the board. I explained that the shareholders get to decide who they want as directors.
That was a light-bulb moment for her. It clarified how she understood her fiduciary responsibility. I like those conversations, where connecting a decision to the bigger picture helps someone see their role more clearly.
What the first risk register reveals about candor, psychological safety, and leadership.
Ethical decision making and speak-up culture depend on how clearly an organization communicates its objectives, goals, and risk appetites. People need to understand what they are trying to accomplish, what tradeoffs they can make, and when a concern needs to reach someone else.
They also need psychological safety: confidence that they can ask a question, acknowledge uncertainty, challenge an assumption, or report a problem without humiliation or retaliation. Clear expectations help people exercise judgment. Psychological safety helps them speak when that judgment tells them something needs attention.
An organization’s first risk assessment illustrates how easily those conditions can break down.
Some leaders openly identify risks, explain weaknesses, and describe what could go wrong. Others share little or hide concerns. The resulting risk register may make the most forthcoming leaders appear to have the most troubled departments. Less transparent leaders can appear to have everything under control.
The register then reflects differences in candor as well as differences in risk. If leadership treats it as a performance ranking, the organization gets an inaccurate picture and penalizes the people who helped make that picture clearer.
I use risk-based governance to connect organizational objectives to the decisions people make throughout the business. Clear risk appetites and escalation expectations help people understand where they can exercise discretion, what requires further discussion, and how to explain their reasoning.
That framework also establishes how leaders should use information about risk. Identifying a concern begins a conversation about its significance and what to do about it. The number of risks a leader reports says little, by itself, about how well that person leads.
When reviewing an initial assessment, I want to understand how the information entered the register. Are departments using similar thresholds? Do people understand the questions? Do they trust the process? Does a short list reflect limited exposure, limited awareness, or reluctance to disclose?
Psychological safety matters here because people take an interpersonal risk when they reveal a weakness or disagree with someone influential. Leaders need to demonstrate that candor receives a fair hearing. Accountability remains essential, including accountability for concealing a concern. A fair review considers what someone knew, the choices available, and how they acted.
I also consider organizational structure. Employee-owned companies, privately held businesses, public companies, benefit companies, and nonprofits distribute authority and accountability differently. Those arrangements can influence whose interests leaders prioritize, how they respond to good and bad news, and how comfortable employees feel challenging a decision. Structure provides part of the context; leadership’s behavior determines whether openness feels credible.
People notice what happens to colleagues who speak candidly. If reporting a risk brings blame, the next assessment may look better because people have learned to share less.
I want governance to give people a clear basis for making wise decisions and confidence that reasonable judgment will receive fair consideration. That requires transparency about objectives and acceptable risk, psychological safety to raise concerns, and a consistent response from leadership.
A useful risk register depends on people being willing to tell the organization what it needs to know. How leaders respond to that information shapes the quality of the next decision, the next assessment, and the culture people work in every day.
How cognitive biases affect information and decisions across a complex organization.
Geoffrey Miller and Gerald Rosenfeld introduced “intellectual hazard” in a 2009 working paper, published in the Harvard Journal of Law & Public Policy in 2010. They examined how behavioral biases interfere with the way complex organizations acquire, analyze, communicate, and act on information. Their analysis focused on the 2008 financial crisis, with connections to failures in space exploration and surgery.
The concept draws attention to what happens to information as it moves through an organization. Important evidence may receive too little attention, lose context between departments, or fail to reach someone who can act on it.
I work with a lot of smart people, including physicians and lawyers. Their expertise is essential, but expertise does not make anyone immune to cognitive bias. A familiar explanation can become an assumption we stop testing. Information that supports our judgment can seem more persuasive than information that challenges it.
Intellectual hazard helps me examine how those tendencies affect the organization. Whose judgment carries weight? Can someone question an established view? Does information retain its meaning as it moves from a specialist to management and then to the board?
Those questions matter because decisions often depend on several people’s expertise. Each person may understand their part well, while the organization struggles to connect what they know.
Qualified people, extensive data, and formal reporting processes can coexist with serious gaps in understanding. In my risk and governance work, I look for ways to make those gaps visible and give people room to challenge a conclusion.
I want someone to be able to ask, “What would make us reconsider?” without others hearing it as an attack on their competence. That question can help an organization recognize a risk, revisit an assumption, or see an opportunity it has overlooked.
If something here interests you, I’d enjoy hearing from you. I’m happy to talk about leadership, a question you’re working through, speaking opportunities, or working together.
Start a conversation ↗For independent legal and consulting work: Officer and the Board ↗