Attorney · Executive · Writer · Teacher

Robert B.
Stratton

JD, MBA, CHC, CHRC, CCEP

I enjoy helping people connect the dots. My work has taken me through technology, law, teaching, and executive leadership. I draw on all of it to understand where someone is coming from, explain things plainly, and help them see how a decision fits into the bigger picture.

GovernanceEnterprise RiskCompliance & EthicsHealthcareAI Governance
Welcome. You’ll find some of my writing and work here, along with a little about the person behind it.
Robert B. Stratton
What I think about

Questions I keep coming back to.

I spend a lot of time thinking about how people lead organizations: what they need to know, who gets to decide, and how to make sense of risk. These are a few of the subjects I write and speak about.

01

Governance & boards

Oversight, accountability, independence and the practical mechanics that make governance work.

02

Enterprise risk

Risk appetite, assessment, escalation and connecting enterprise risk to actual decisions.

03

Compliance & ethics

Program effectiveness, organizational behavior and the role of independent judgment.

04

AI & emerging risk

Governance for technology that moves faster than the structures expected to oversee it.

Selected work

Writing, speaking & conversations.

Publications, keynote addresses, conference presentations, and conversations on healthcare, enterprise risk, board oversight, and the intersection of law and ethics.

Publication

Enterprise Risk Management in Healthcare

HCCA Governance Manual

2025
Publication

ERM in Healthcare · Updated Chapter

HCCA Complete Healthcare Compliance Manual

Publication announcement
HCCA announcement naming me as a contributing author of chapter 3.14, Enterprise Risk Management in Healthcare
Original HCCA promotional material · 2026
2026
Podcast

Healthcare Enterprise Risk Assessments

HCCA Compliance Perspectives · Guest conversation · 10 minutes

Keynote

Enterprise Risk Governance

HCCA Board & Audit Committee Conference

2023
Speaking

Architecting the Aligned Ecosystem: A Blueprint for Healthcare Enterprise Risk Management

HCCA Compliance Institute · Orlando

Conference announcement
HCCA Compliance Institute speaker card for my April 30, 2026, ERM in Healthcare session in Orlando
Original HCCA promotional material · 2026

My introduction to the session · 1 min 16 sec

Connecting board oversight, clinical operations, compliance, and the practical work of building an ERM program.

2026
Speaking

The Board Will See You Now: When Research Risk Goes Enterprise

HCCA Research Compliance Conference · Co-presented with my wife, Amy Stratton, MBA

Conference announcement
HCCA Research Compliance Conference speaker card for June 7–9, 2026, in San Antonio
Original HCCA promotional material · 2026

Funding volatility, financial sustainability, and communicating research risk to executives and boards.

2026
Faculty speaker

Legal Solutions to Ethical Problems

Kinsman Bioethics Conference

How healthcare lawyers approach ethical problems, with examples involving AI, privacy, apologies, and clinician safety.

2025
Speaking

Strategic Risk Management and Risk Governance

Operations Technology Management Conference

Risk and opportunity, board oversight, organizational culture, and the assumptions that shape decisions.

2020
A little about me

How I got here.

At Vulcan, I worked on remarkable initiatives, including the Allen Institute for Brain Science. I enjoyed being part of that work, but my role in technology gave me a narrow view. I pursued a law degree and an MBA because I wanted to contribute to the bigger picture: to understand the business, help shape decisions, and take on broader responsibility.

That still motivates me. My career has included private practice, teaching, and leading legal, compliance, and enterprise risk work in healthcare. From 2012 to 2017, I taught as an adjunct professor at several local universities, nearly every quarter or semester. From 2017 to 2022, I taught exclusively at the University of Portland. Teaching was a regular part of my working life for a decade. I like helping leaders understand how their responsibilities fit together and what those responsibilities mean in practice. Sometimes a useful conversation changes how someone sees a problem.

I believe understanding something means being able to explain it simply. I also believe in being nice. You can disagree without being disagreeable, which matters a great deal in legal and compliance work. And a little humor helps.

In private practice, I advised public- and private-sector clients on business law, governance, contracts, and transactions. That included structuring a $10 million public-private venture capital fund and working on business valuations and asset and equity transactions.

At Northwest Permanente, I built enterprise risk management and internal audit programs from the beginning. My responsibilities grew to include compliance, policy systems, investigations, privacy, security and threat management, and legal advice. I also served as General Counsel and Chief Compliance Officer for Permanente Health Care Ventures.

Working within Kaiser Permanente gave me a view of healthcare that extended beyond the medical group to hospitals, system operations, and insurance. I worked with physician leaders, executives, and boards, including as administrative co-chair of the Board’s Enterprise Risk Management & Audit Committee.

More recently, my work has included predictive-model and AI governance.

Education, certifications & admissions
Juris Doctor (JD) · Master of Business Administration (MBA)
  • Certified in Healthcare Compliance (CHC)
  • Certified in Healthcare Research Compliance (CHRC)
  • Certified Compliance & Ethics Professional (CCEP)
Attorney licensed in Oregon and Washington
Me smiling outdoors in a blue vest
Outside work

A few other things about me.

There’s more to my life than work. Here are a few things I enjoy.

My moon-and-rocket logo

Space

As a kid, I lived just south of Cape Canaveral. Our school took us outside to watch Challenger launch, and I saw it explode live. I’ve been fascinated with space ever since, and fascinated with risk.

Why I still use the Challenger report

The official investigation and report are still part of my speaking and risk work. One example I use is the way the flight data was framed: looking only at flights with O-ring damage obscured the relationship with temperature. Including flights without damage made the pattern clearer.

That example stays with me because the choice of what to include in the analysis changed what people could see. It’s a reason to ask what information is missing before relying on a conclusion.

Challenger Commission report: the two graphs ↗

What I read

I love science fiction. Space battles are part of the appeal, but so are the questions about people: how we live together, what we value, and what we might become. I especially enjoy stories that imagine an optimistic future.

I read around 50 books a year, mostly science fiction. My dad found an author-signed copy of Dune in Port Townsend. He likes telling that story, so I’ll leave the telling to him.

Technology, at home and on the road

I travel a lot, and I like being prepared. A GL.iNet travel router is part of my kit, along with the other technology that lets me work and stay connected while I’m away. I enjoy getting it all set up. Ideally, the adventure is in the trip rather than in getting my devices to cooperate.

That interest extends to projects at home: electric vehicles, e-bikes, solar and battery systems, networking, and my QNAP server. I also experiment with scripting and AI agents. There’s usually something to configure, improve, or figure out.

Me enjoying a drink on a rooftop terrace

Whiskey

I’m interested in whiskey: how it’s made, how distillation affects the result, and why one tastes different from another. The Multnomah Whiskey Library is a place I’m interested in exploring.

People, dogs, and getting away

My wife, Amy, and I have three kids. I enjoy traveling with her and spending time on the water. Dogs are part of everyday life, too. Anyone who has spent time on a video call with me may have met a few of them.

My wife, Amy, and me while travelingMy wife, Amy, and me smiling on a ship with the ocean behind us
Me relaxing with our brown dogMe relaxing with our white dog
Executive profile

My experience at a glance.

Attorney and senior executive with experience spanning healthcare law, compliance, enterprise risk, board governance, internal audit, and technology. Built enterprise programs, advised boards and executive leaders, served as General Counsel and Chief Compliance Officer for a healthcare venture subsidiary, and taught graduate business students.

Download executive profile ↓ PDF

Northwest Permanente, P.C. | Kaiser Permanente

Senior General Counsel; Corporate Compliance Official; Executive Director, Enterprise Risk Management & Security

Built the ERM and internal audit infrastructure; led compliance and advised on healthcare regulation, investigations, privacy, physician arrangements, telehealth, and AI governance. Served as administrative co-chair of the Board’s Enterprise Risk Management & Audit Committee. Scope included two hospitals and approximately 40 clinics.

Permanente Health Care Ventures, P.C.

General Counsel & Chief Compliance Officer

Founding executive supporting innovative healthcare initiatives. Designed governance and compliance structures and advised on partnerships, inter-entity arrangements, technology agreements, and regulatory risk.

RBS Law LLC | 2011-2019

Attorney & Principal

Advised public- and private-sector clients on corporate law, governance, contracting, restructuring, valuation, and transactions. Structured a $10 million public-private venture capital fund.

Adjunct teaching | 2012–2022

Former Adjunct Professor

Taught nearly every quarter or semester at several local universities from 2012 to 2017, then exclusively at the University of Portland from 2017 to 2022. Courses included finance, economics, enterprise risk management, corporate governance and compliance, valuation, and business technology.

Vulcan Inc. | 2000-2007

IT Manager

Led technology operations supporting biomedical research and aviation initiatives, including the Allen Institute for Brain Science.

Portrait of me in a jacket

A few examples from my talks

I like examples that give people something to think about. These are a few I use to start a conversation.

South-up world map

Which way is up?

A familiar world can look surprisingly unfamiliar when south is at the top.

Read the example

I use south-up maps in my talks because they make people pause. Australia and Antarctica are at the top, and it takes a moment to find your bearings. We get so used to north being at the top that we forget it’s a choice.

I use that moment to ask what other assumptions we’ve stopped noticing. A different frame can change how we understand the same information.

Against the Gods by Peter L. Bernstein, shown in my risk presentation

Why talk about gambling?

It’s a useful place to begin a conversation about risk and opportunity.

Read the example

My risk governance presentation starts with gambling. It gives us a familiar way to talk about what we stand to gain, what we could lose, and how much we’re willing to put at stake.

Organizations face those questions too. A useful risk conversation starts with the opportunity we’re pursuing and the uncertainty we’re willing to accept. That makes risk appetite something people can discuss in the context of an actual decision.

Chinese Room illustration from my risk governance presentation

The Chinese Room: who understands the whole process?

How individual expertise connects to the purpose, risks, and opportunities of an organization.

Read the example

Philosopher John Searle introduced the Chinese Room thought experiment in 1980. Imagine a person who cannot understand Chinese sitting inside a room. People outside pass in written questions in Chinese. Using an elaborate instruction book, the person manipulates the symbols and sends back answers convincing enough that those outside believe they are communicating with someone who understands the language. Inside the room, the person understands neither the questions nor the answers. Chinese is simply the unfamiliar language in this example; another language unknown to the participant would serve the same purpose.

Searle’s argument is that following rules for manipulating symbols does not, by itself, establish understanding. I used to call this the “Siri problem” to give audiences a more familiar reference. Today, large language models make the question even more immediate. Applied to an LLM, Searle’s argument would challenge whether its sophisticated computational processes produce understanding, even when its responses appear knowledgeable. That remains a contested philosophical question.

How it connects to my work

In a complex organization, each department or each step in a process may perform its assigned work without understanding the bigger picture. People know what comes in, what they are supposed to do, and what gets passed along. They may have little visibility into the ultimate purpose, the risks created across the process, or the opportunity the organization is pursuing.

One objection to Searle is that understanding might belong to the whole system, even if the person inside the room lacks it. I find that especially useful when thinking about organizations. No individual needs to know everything. But the organization needs some way to connect what people know, examine the assumptions between steps, and make decisions with a view of the whole. That is a central concern in my risk and governance work.

Why it matters

A process can produce the expected output at every step while leaving important questions unanswered. Who understands what the organization is trying to accomplish? Who can recognize a risk that crosses departmental boundaries, or an opportunity that falls outside anyone’s assigned responsibility?

The Chinese Room gives us a way to ask whether our processes connect individual expertise into organizational understanding. Completing each step tells us something about execution. We still need to ask who can see what it all means.

Who gets
to decide?

Who gets to choose the directors?

Clarifying who decides can change how someone understands their responsibility.

Read the example

A shareholder elections committee chair once wanted to impose rules limiting who could run for the board. I explained that the shareholders get to decide who they want as directors.

That was a light-bulb moment for her. It clarified how she understood her fiduciary responsibility. I like those conversations, where connecting a decision to the bigger picture helps someone see their role more clearly.

Safe to
speak up?

Transparency: when speaking up makes you look worse

What the first risk register reveals about candor, psychological safety, and leadership.

Read the example

Ethical decision making and speak-up culture depend on how clearly an organization communicates its objectives, goals, and risk appetites. People need to understand what they are trying to accomplish, what tradeoffs they can make, and when a concern needs to reach someone else.

They also need psychological safety: confidence that they can ask a question, acknowledge uncertainty, challenge an assumption, or report a problem without humiliation or retaliation. Clear expectations help people exercise judgment. Psychological safety helps them speak when that judgment tells them something needs attention.

An organization’s first risk assessment illustrates how easily those conditions can break down.

Some leaders openly identify risks, explain weaknesses, and describe what could go wrong. Others share little or hide concerns. The resulting risk register may make the most forthcoming leaders appear to have the most troubled departments. Less transparent leaders can appear to have everything under control.

The register then reflects differences in candor as well as differences in risk. If leadership treats it as a performance ranking, the organization gets an inaccurate picture and penalizes the people who helped make that picture clearer.

How it connects to my work

I use risk-based governance to connect organizational objectives to the decisions people make throughout the business. Clear risk appetites and escalation expectations help people understand where they can exercise discretion, what requires further discussion, and how to explain their reasoning.

That framework also establishes how leaders should use information about risk. Identifying a concern begins a conversation about its significance and what to do about it. The number of risks a leader reports says little, by itself, about how well that person leads.

When reviewing an initial assessment, I want to understand how the information entered the register. Are departments using similar thresholds? Do people understand the questions? Do they trust the process? Does a short list reflect limited exposure, limited awareness, or reluctance to disclose?

Psychological safety matters here because people take an interpersonal risk when they reveal a weakness or disagree with someone influential. Leaders need to demonstrate that candor receives a fair hearing. Accountability remains essential, including accountability for concealing a concern. A fair review considers what someone knew, the choices available, and how they acted.

I also consider organizational structure. Employee-owned companies, privately held businesses, public companies, benefit companies, and nonprofits distribute authority and accountability differently. Those arrangements can influence whose interests leaders prioritize, how they respond to good and bad news, and how comfortable employees feel challenging a decision. Structure provides part of the context; leadership’s behavior determines whether openness feels credible.

Why it matters

People notice what happens to colleagues who speak candidly. If reporting a risk brings blame, the next assessment may look better because people have learned to share less.

I want governance to give people a clear basis for making wise decisions and confidence that reasonable judgment will receive fair consideration. That requires transparency about objectives and acceptable risk, psychological safety to raise concerns, and a consistent response from leadership.

A useful risk register depends on people being willing to tell the organization what it needs to know. How leaders respond to that information shapes the quality of the next decision, the next assessment, and the culture people work in every day.

What would
make us
reconsider?

Intellectual hazard: how capable organizations miss important risks

How cognitive biases affect information and decisions across a complex organization.

Read the example

Geoffrey Miller and Gerald Rosenfeld introduced “intellectual hazard” in a 2009 working paper, published in the Harvard Journal of Law & Public Policy in 2010. They examined how behavioral biases interfere with the way complex organizations acquire, analyze, communicate, and act on information. Their analysis focused on the 2008 financial crisis, with connections to failures in space exploration and surgery.

The concept draws attention to what happens to information as it moves through an organization. Important evidence may receive too little attention, lose context between departments, or fail to reach someone who can act on it.

How it connects to my work

I work with a lot of smart people, including physicians and lawyers. Their expertise is essential, but expertise does not make anyone immune to cognitive bias. A familiar explanation can become an assumption we stop testing. Information that supports our judgment can seem more persuasive than information that challenges it.

Intellectual hazard helps me examine how those tendencies affect the organization. Whose judgment carries weight? Can someone question an established view? Does information retain its meaning as it moves from a specialist to management and then to the board?

Those questions matter because decisions often depend on several people’s expertise. Each person may understand their part well, while the organization struggles to connect what they know.

Why it matters

Qualified people, extensive data, and formal reporting processes can coexist with serious gaps in understanding. In my risk and governance work, I look for ways to make those gaps visible and give people room to challenge a conclusion.

I want someone to be able to ask, “What would make us reconsider?” without others hearing it as an attack on their competence. That question can help an organization recognize a risk, revisit an assumption, or see an opportunity it has overlooked.

Read Miller and Rosenfeld’s paper ↗

Next conversations

Let’s talk.

If something here interests you, I’d enjoy hearing from you. I’m happy to talk about leadership, a question you’re working through, speaking opportunities, or working together.

Start a conversation ↗

For independent legal and consulting work: Officer and the Board ↗