The Day After You Close, the Compliance Bar Goes Up (with Baxter Lee)
Watch Now
Listen Now
Also Available On:
▶ Apple Podcasts
▶ Amazon Music
▶ Spotify
▶ YouTube
-
When a private equity firm closes a healthcare deal, the compliance and security bar rises the next morning, whether the new owner is ready or not. On this episode of The Compliance Advantage, host Ross Ronan talks with Baxter Lee, President of Clearwater, about why so many programs fall behind the moment growth speeds up. Baxter has spent his career on both sides of the table, in investment banking and private equity, then as an operator and CFO, and now leading Clearwater through its own growth from 30 to more than 270 people. He explains why a diligence report that sits on a shelf protects no one, and why compliance, privacy, and security only work when they run as one continuous program that is tested, not just documented. The conversation covers the real cost of waiting until a breach happens, the way an acquisition can quietly raise the bar with regulators like the Office for Civil Rights, and how an M&A playbook keeps a roll-up from outrunning its own controls. Ross and Baxter also dig into patient trust as an asset, the talent shortage in compliance and security leadership, and why building the foundation early is cheaper and more scalable than cleaning it up later. The throughline is simple. Done right, compliance and security are not a cost. They are how a growing healthcare company protects its value and earns the trust to keep growing.
-
Why is a compliance diligence report not enough on its own?
A diligence report only helps if the findings get built into the operating plan. Baxter Lee says programs fall short when the report becomes a static document that sits on a shelf and never gets actioned. Clearwater often reviews diligence done a year or two earlier and finds the same gaps still open. The point of diligence is to show you where to make adjustments, not to check a box.
What happens to compliance risk right after a private equity firm closes a deal?
The bar goes up the next day. Baxter Lee explains that what counted as reasonable and appropriate for a physician founder before a sale looks very different once institutional capital is behind the business, because regulators expect you to know better. The owner did nothing but close the transaction, and the standard already rose. If the program is not improving on day one, it is already behind.
Why should privacy, compliance, and security work as one program?
Because they overlap, and a gap in one becomes a gap in all three. Baxter Lee describes a Venn diagram where governance, risk management, and resiliency pull from all three areas. A common problem is a company that invests in a compliance officer but not a security officer, or the reverse. The strongest teams coordinate all three and test their controls continuously, rather than treating a single risk assessment or policy as the finish line.
What does a breach actually cost compared to preventing one?
Far more after the fact. Baxter Lee says cleanup tends to run orders of magnitude higher than upfront investment, and some clients pay Clearwater 10 times more on an ongoing basis after a breach than they would have spent to be ready. He points to Change Healthcare spending billions to rebuild after its incident. You do not want to test your incident response plan live for the first time during a real attack.
How does a healthcare company keep compliance from falling behind its growth?
Build the foundation early and resource an M&A playbook. Baxter Lee says doing it earlier is cheaper and more scalable than reverse engineering policies and systems a year or two into the roll-up. Even a fractional leader who owns the work lets a company move fast without outrunning its controls. He warns that some portfolio companies have had to pause acquisitions to let their programs catch up, which erodes the very enterprise value the growth was meant to build.
-
Ross Ronan (00:00)
Welcome to The Compliance Advantage. Today we have a very special guest, Baxter Lee, who's the president of Clearwater Security and Compliance. Thanks for joining us, Baxter. Appreciate it.
Baxter Lee (00:13)
Yeah, thanks for having me, Ross. Look forward to the conversation.
Ross Ronan (00:16)
Tell us a little bit about your background. I know you've been around the block in a lot of different areas and a lot of different things, which is amazing, because you don't see that very often. Investment banking, private equity, you've been CFO, and now you're president of Clearwater.
Kind of take us through that journey of where you came from and where you're at today.
Baxter Lee (00:37)
Yeah, I guess I've made it to the point in my career where I can be referred to as having been around the block, so.
Ross Ronan (00:44)
Yes.
Baxter Lee (00:45)
An accomplishment in and of itself. I started my career as a business major in college and started in finance, and went to work for Merrill Lynch Capital in their healthcare finance group. That's how I got brought into the healthcare industry.
Early days was underwriting transactions and debt facilities for hospitals, nursing homes, home health businesses. I really got to learn the healthcare ecosystem, reimbursement challenges, legislation that impacted healthcare providers at the time. We worked with organizations that were also going through bankruptcy and turnarounds, so I learned some of the challenges of operating in healthcare and what led to some of those situations. That was a good three and a half, four-year experience.
Then I spent two years with a lower middle market private equity fund, more of a generalist investor. But it did one healthcare transaction focused on the Medicaid dental space. Again, very regulatory and compliance-driven requirements when you're operating with children and in the Medicaid market and the dental space.
After that period of time, I realized I wanted to be more on the operator side of the table and not on the transactional side. I got to know these businesses really well. I got to know their executives and leadership teams well through the transactions. But I recognized I wanted to see something through a little more, and I really found myself intrigued with what made operators tick, what made them successful, how they overcame challenges.
So I started to think about a career shift and was recruited to move to Nashville about that time to work for Emdeon, which was the predecessor to Change Healthcare. It was a large, publicly traded platform at the time, with private equity support as well. I was able to do corporate development and M&A strategy, but more from an internal corporate development strategy perspective, and I was able to extend my reach into the healthcare IT side of healthcare through that platform, and learn a lot more, but do it from more of an operating perspective.
Then I transitioned to an internal divisional CFO role, and in 2015 spun out and went to an early-stage startup called Entrada Health. It was a mobile dictation platform for physicians that were struggling with productivity challenges of the early adoption of EMRs. We grew that business and sold it to NextGen Healthcare before I joined Clearwater as CFO.
After seven and a half years as the CFO of Clearwater, we went through a transaction with Sunstone Partners, and that gave me the opportunity to step up as president of the company. I've been with the company since we had 30 employees. We've grown it to over 270. So I've really been involved in a lot of the operational aspects of our growth over the last several years, and I'm excited to be leading the company as president and, through this transaction, interfacing with Sunstone.
Leadership Philosophy
Ross Ronan (03:57)
That's huge growth. As you went from CFO to president, from 30 to 270 employees, you had a lot of leadership responsibilities there. Is there any philosophy or any kind of mentor or book that you've put on your shelf? I always like to have this conversation because we talk about it with a lot of CEOs and board members.
I find it fascinating. I've got several books that I really like, and mentors that I have. Do you have anything out there you want to mention or plug?
Baxter Lee (04:32)
Yeah, I read a lot of books on management, journals, and other things. I'm not a big fiction reader, actually. I read a lot of business and, kind of boring, trends and books around how to grow businesses and build teams. I'd say, over the course of my career, I've collected what I've seen work with other leaders.
What inspired me to get into operations was seeing what made them successful, and really taking a transparent approach to leadership. Hopefully everybody on my team knows what I'm thinking, what the goals and objectives are in front of us.
I also try to lead with empathy. I want to make sure I truly understand what everybody's going through and what may be causing constraints or challenges, and not just assume that it's a skillset gap or things that are outside their control.
And then accountability as well: setting clear expectations and then holding people accountable to that. So transparency, empathy, accountability, and finally mutual respect, just making sure that regardless of what we're going through, everybody treats each other respectfully.
If we do those things together, we can overcome any challenges and come out on the other side stronger. That's the philosophy I've built over the course of my career.
Operating Under Pressure and Recovering From Mistakes
Ross Ronan (05:59)
It really is a great philosophy. I have this conversation with a lot of business owners and heads of companies. With Clearwater, with what we do, being in the cybersecurity and compliance space, it's a hard place to be when you're an employee working on stuff that can be really detrimental to an organization.
With cybersecurity, all it takes is one breach or one attempted breach that sends the whole company into a tailspin, and you've got a responsibility to protect against that. It's the same thing on the compliance side with fraud, waste, and abuse and the False Claims Act. Having that kind of mentality, where people can spin out of control pretty quickly because there's such high pressure, is really important.
Baxter Lee (06:50)
Absolutely. Fundamentally, we're all going to make mistakes. Whether you're operating a compliance or security program that's never going to be perfect, or just as individuals in our roles throughout your career, you're going to make mistakes. So it's how you react to those mistakes, learn from them, recover from them, and improve over time. I think that can be said for building your career successfully as well as running a successful compliance or security program.
Beyond the “Bookshelf” Program: Static Reports vs. Living Programs
Ross Ronan (07:17)
Completely. All right, let's get into compliance and cybersecurity a little bit. You've sat on both sides, which is amazing: you're able to look at financing and deal structure when it comes to M&A, and then get into operations, whether it's a healthcare provider basis versus a tech or security basis.
Where do you see these healthcare executive boards maybe missing it a little bit? Or maybe the biggest misconception about what they're trying to get into, before they miss what they're really looking for?
Baxter Lee (08:00)
It's an evolution for sure. There are folks across the spectrum, those that take it more seriously than others, up and down the investment world. Where I see some of the shortfalls coming is taking a diligence report and then it becomes a static document that sits on a shelf somewhere, and it's not actioned into a part of the operating plan of the company.
It's like, well, we got advice from our lawyers, we got our diligence report, check. But then it doesn't become an operational part of the business. We see time and again where we come in and review prior diligence reports, or diligence that we did on an organization a year or two later, and a lot of those things just haven't been done.
I think that's the ultimate challenge: making sure it's prioritized effectively, and that they recognize the reason you do the diligence is to make sure you understand where you need to make adjustments, and not just check a box.
We see that across healthcare in general. There's a lot of static reporting and point-in-time assessments. What you really need to do to operate in today's environment is have a continuous, ongoing, proactive program that manages to your goals and objectives and aligns with regulations. We see various organizations do better with that than others.
Ross Ronan (09:41)
I see it across the board too. This common misconception is, I just did it, I checked the box, and therefore I'm protected. I agree with you. We call that a bookshelf compliance program, and you probably call it the same thing on the security side, where you're just like, here are all my policies, here's what we've done.
We've done a risk assessment, we've done an SRA, all these things, and now we put it on the shelf and go, check, we've done it, we're covered. And you're like, not quite. It's got to do something.
Baxter Lee (10:10)
Yeah.
Ross Ronan (10:11)
It's got to live, it's got to breathe, it has to morph, it has to enhance, it has to do all these things.
We often talk about being a proactive program versus a reactive program. I'm sure you see this at Clearwater all the time. You've got to be testing. You have to be out there making sure your fail-safes are working, as opposed to just saying, yeah, we've got a bunch of policies on the back shelf, and when something happens, we'll fix it.
Baxter Lee (10:38)
I think that's where we see the biggest opportunity in healthcare, that resiliency aspect. You have policies, you've got procedures, you've got things in place. Have you tested it? Have you determined if your controls are working effectively? Do your people know what they need to be doing, and what they should and shouldn't be doing?
Do you know how you're going to respond in an incident, and have you tested those procedures? I think there's a lot of room for maturity there. The industry's come a long way in the last several years if you look from a cybersecurity perspective, around implementing fundamental controls like multi-factor authentication and endpoint detection, things that didn't exist as frequently or as robustly two, three, four years ago as they do today.
Those controls are in place, and that's a big improvement over the last few years. But the threat actors are evolving as well. And if you're not testing your controls, making sure they're actually achieving the intended objective, and testing your own ability to respond and recover, then you still have a gap in your program.
Ross Ronan (11:44)
With technology improving, with AI out there, both of our worlds are constantly morphing because everybody's trying to attack, everybody's trying to get in, everybody's trying to figure out how to jump around the system in some way, shape, or form. It's pretty amazing at some point.
Sometimes I sit back and go, can we keep up? It's just amazing how much is out there.
Baxter Lee (12:06)
Not to mention the changing regulatory landscape, the different state requirements. It's a lot to keep up with. You're not only dealing with changing threat actors and more aggressive offensive capabilities, but also the defensive regulatory aspects that you need to keep up with.
If you don't resource this appropriately, you can find yourself falling behind pretty quickly. What we see in the private equity market is that these organizations are built to grow and scale, but their compliance and security programs don't always keep pace with that growth. So you're actually introducing more risk to the organization, or the risk profile is expanding as you're growing, because your program's not set up proactively to grow at the same pace.
Turning Compliance and Security Into Enterprise Value
Ross Ronan (12:55)
You dovetail that into my next topic, which is the growth of your compliance and security programs as these companies are growing. The whole point, and I see this a lot with private equity, we work with the majority of private equity groups and healthcare investors, is that they want to grow this business not necessarily for profits or money. It's to expand network capabilities, expand the provider base, and be able to provide healthcare to a lot of different people in a lot of different cost-effective ways.
A lot of people don't feel that way, but it's true, and at least the ones we deal with are on that standpoint. So we're always talking about growth. Now, this is The Compliance Advantage, and one of the things we talk about is how you change your privacy, security, and healthcare compliance programs from, like you said, a cost center that just sits over here and isn't able to grow and scale, to something that's more of an advantage.
They use it for sales, they use it for partnerships, they use it for patient satisfaction. How do you see that, or how do you talk to healthcare providers, to say this is how it creates enterprise value?
Baxter Lee (14:11)
I think you and I probably talk about it very similarly. Compliance and security can be a liability to your business, and if done correctly, it can be an advantage. Being proactive pays dividends over the long term, avoiding negative events or mitigating the impact of those potential events, and also positioning your business to grow and scale.
We think that starts early, particularly using those diligence reports right at the transaction and building it into all the plans you have in place for M&A and growth and operations. Compliance and security should be right there with it, so you're implementing that foundation and it's positioned to grow with your business.
You have a playbook for M&A, you have a playbook for growth, you're training your employees effectively along the way. Everyone understands what achieving certain milestones means for the business. If you take HIPAA, for instance, a lot of the rules and regulations around HIPAA have what I'll call obscure applications in terms of the reasonable and appropriate language.
What is reasonable and appropriate for your business? That is up for interpretation. So if you're buying a physician founder-run business, what was reasonable and appropriate for them pre-transaction in the eyes of OCR or the federal government is a lot different the day after you close, when you have institutional capital behind it and you should know better. The bar just went up, and you didn't do anything other than close the transaction. So if you're not improving day one, you're already behind.
Then with the growth and scale of the business through M&A or organic initiatives, de novo office expansion or things like that, you're falling behind. That's where organizations really struggle: building that foundation early in a way that actually allows you to achieve those goals and objectives. I can tell you, we've worked with portfolio companies that have had to go to the board and say, we have to stop doing M&A because we have to catch up.
That's probably a terrible position to be in, in year two or three of an investment, when you're telling the investors to stop investing and stop growing because your IT, security, and compliance can't keep up with the pace of growth. To your point on creating enterprise value, that's clearly eroding value if you can't execute your growth strategy as a result of not having that foundation in place.
Ross Ronan (17:05)
Or even worse, doing it without regard to the red flags that are out there, and now you find yourself in a bind. In one of my previous lifetimes, we had a number of different corporate integrity agreements that came from acquisitions done seven, eight, ten years before that, that truly didn't have good diligence on them, or anything that we were supposed to be responsible for.
We're doing a great job today, but historically it was just a problem. I feel like that's where it slips through the cracks a little bit. You have this, but now you have to make sure your compliance and your security systems are growing with your entities.
And by the way, integration's huge. You're going to integrate all of these different things. You guys more so than us, but all these IT integrations can really change your EMR. How many times have you come across someone changing their EMR, just sitting back here on a server, and no one's protected it?
Baxter Lee (18:09)
Yep. On the positive side, I think we've seen that come a long way. If you go back to pre-COVID, the M&A and roll-up strategy in the PPM space, what we heard and saw a lot was, we don't want to disrupt the provider workflow. We're going to take the IT infrastructure as it comes. And then two, three years in, they would hire some poor CIO to bring it all together, and that was a nightmare.
I do think we see more standardization on the front end now, and private equity firms recognizing the need to pick a platform and a tech stack and tell the doctors up front, it's going to be a short pain, but we're going to move you here, and then we're going to get scalability and efficiency, and it's going to be better for the enterprise long term.
That comes with compliance and security advantages as well, because you're dealing with a less fragmented infrastructure that you have to manage. So I do think there's been an evolution over the last five, six years toward an IT approach that makes the business more scalable and more secure. One set of policies and procedures that can now be applied across the infrastructure.
And then having that M&A playbook of, okay, when we acquire something, we're going to move things over quickly onto this new tech stack and not maintain these legacy applications and servers that can create a lot of liability for the business. We've seen that evolve a lot, but it varies across the spectrum. The bigger, more upstream firms have those playbooks built, and I think the middle market and lower middle market are still working through that today.
Diligence at the Last Minute, and the M&A Playbook
Ross Ronan (19:53)
I completely agree. I also feel like there are some middle market investment firms that have a little bit more maturity when it comes to doing a healthcare deal. Either they've been burned in the past, or they've done something they had to go unravel, so they get it. And then there are some where you get tapped on the shoulder at the last part of the diligence cycle.
They say, hey, we're closing in 30 days, I need a compliance assessment, I need a security assessment, I need these things done real quick, can you do it real fast? And the answer is yeah, but you're going to have a laundry list of things you've got to do thereafter.
Baxter Lee (20:31)
Yeah, and you see those firms being more reactive than proactive. And it's not just private equity. We've worked with health systems that do M&A. One large health system came to us and their IT department was overwhelmed every time they would do an acquisition.
They'd have to put down everything they were doing and go do due diligence. And they're like, we don't know how to do due diligence, we're not set up for that. All we have is staff to do operational IT work. They wanted us to come in and help them build a playbook for due diligence and integration of their acquisitions.
So it's across the spectrum, but if you're in the business of M&A and that's part of your growth strategy, you need to build a playbook that's resourced appropriately, so you can tackle those challenges through the transaction, understand what you're acquiring, what the legacy liabilities might be as a result of what you're acquiring, and have a playbook for how you're going to integrate them and what the timeline is.
You've seen it in mergers before. If you go back to the Starwood-Marriott merger, it was publicly announced that they were going to consolidate platforms, and guess what happened? They stopped investing in one of the two platforms, and the attackers realized that, and they got access to the Starwood databases during that integration process.
That can happen in M&A. The press releases, the things people put out when they want to tell their growth story to the market, also advertise to the attackers that there's this disruption happening here, and you're now a target as a result.
Ross Ronan (22:16)
That's really good insight. I don't know that I've had a guest really put it out in that manner, because I feel like that's a really important message to get out there: don't just say you're doing it, you've got to do it. Because if you don't have your protections in place, you've just told everybody you're going through a transaction or an integration.
And I think the government's looking too, on our side of it, with fraud, waste, and abuse and False Claims Act issues. They go, okay, you're in this process of integration, you need to fix it.
Privacy, Compliance, and Security as One Integrated Program
Ross Ronan (22:16)
You've talked a little bit about this, and I love the idea where cybersecurity, compliance, privacy, and technology all work together to make sure everybody is protected. I've always talked about this too, because we don't do what you do. We don't do security work, we don't do HIPAA security, we don't do SRAs and all the other things associated with it. Part of my thinking is, you guys are the experts in this industry, I'm not.
Could we hire a bunch of people and probably do it? Yeah. As well as you guys? No. I would like our clients to have the best resources known to man, and those are people who are experts in their industry, like you guys. So when you think about cybersecurity, privacy, and security all coming together, it's not a single functionality. It's not your job, it's not my job, it's all of our jobs. How do you see that as an integrated program, and what does that look like to make it actually work?
Baxter Lee (23:59)
I think the integration is critically important. Privacy, compliance, and security all intersect. If you had a Venn diagram, there are definitely elements that all interrelate. Through your governance, your policies, and your risk management structure, your organization should have constituents from all three built into your operating plan.
Going back to one of your earlier questions, another challenge we see is under-investment in one of the three, or two of the three. They may have a compliance officer, but they don't have a security officer, or vice versa. I can't tell you how many times I've talked to investors where they're like, well, we have a really good management team that's been in healthcare a long time, so they know what they need to do. I'm like, well, how do you know they're doing the things that need to be done? They may or may not be.
Unfortunately, the most proactive leadership teams we work with are the ones that have been through a situation in the past. They've been through an OIG investigation, a HIPAA investigation, a cybersecurity breach, or something, and they've learned from that experience and they bring that to the table. Not everyone's been through those situations. So if you haven't been tested, you may think good is good enough, when you really need to be doing more, and you may have gaps.
So it's knowing your blind spots, making sure you've got appropriate people tapped for privacy, compliance, and security, and that they're working in a coordinated way to map to all the rules, regulations, and best practices for your industry and your business.
We look at it from a programmatic perspective, starting with governance, through risk management, and then technical testing of your environment and your controls from a security perspective. And then resiliency, as I mentioned earlier. How well is all that in place, and have you tested it? You think you're doing these things, but can they be exploited? How well can you recover? Have you done a tabletop exercise with your leadership team? Do they even know who they would call if they had a cyber attack or a breach?
It's a continuous process, and I think that's the challenge. It's not, I did a risk assessment, or I wrote a policy, or I did a pen test. It's that you learn from those things, you put improvements in place, and then you retest, and you do that over and over again continuously. You're never complete. It's never over. The threat actors are changing, the regulations are changing, so you're never fully compliant or fully secure. And if you don't have that program in place to do that continuous process, that's where you end up with gaps.
Ross Ronan (26:58)
It's funny, because I tell a lot of people I mentor, if you think you're going to wait until your work is done, your work will never be done. I can guarantee you'll have peaks and valleys, peaks and valleys, but your work will never be done. And that's a good sign of a compliance and a security program.
It always gives me pause when I've got a leader who says, you know what, I've got Joe who can do security and privacy and compliance and all these things because he's got all this experience. It's really about a money-saving issue, as opposed to investing in your company and your programs.
I'm not opposed to one person being responsible for all those, as long as they're using the right people to help them, whether it's you guys or somebody else, to come in and say, I need support, I need help, I need something here. It all becomes different facets, whether you include different departments or you have one person with different kinds of expertise underneath them. That's still a department of multiple different expertises.
Baxter Lee (28:16)
Yeah, we see that a lot. If there's a founder-run business, the main doctor, I've seen situations where the wife was a practicing attorney, and so now she's operating as the compliance officer and she's learning compliance as they go.
Ross Ronan (28:35)
And general counsel and employment counsel and...
Baxter Lee (28:39)
Yeah. Or you have other executives where, okay, we're going to appoint them as the compliance officer or the security officer, and they don't really have the experience to do that. To your point, it's a bit of a money-saving exercise, and it makes people feel good that you've got somebody wearing that hat, but they don't have the background experience or the bandwidth to really do it effectively.
People ask us all the time, when should I hire a security officer, when should I hire a compliance officer? It's, how important is it to your business? There's no perfect answer, but if you're waiting until you get to a certain point, you're clearly missing that opportunity to build the foundation and build it up.
Frankly, I think it's cheaper and more scalable when you do it earlier in the process than waiting a year or two in, when you've got to reverse engineer IT and policies and different things to meet your current operating environment and close those gaps, than if you would've invested earlier and built it up to scale.
Even if it was on a fractional basis, having someone to own that, so that you could then hire somebody into that role who can hit the ground running, as opposed to coming in and cleaning up gaps and a lack of investment from the prior periods.
The Cost of Waiting: Prevention vs. Cleanup
Ross Ronan (30:02)
That's the same advice we give to other leaders and CEOs: don't wait until something happens, because it will happen.
Baxter Lee (30:13)
Yeah.
Ross Ronan (30:14)
It will happen. I've been around for 20-plus years doing this, and I've never seen it not happen. It will happen. If it didn't, we wouldn't exist. From the standpoint of, in your experience, how much does it cost to un-ring a breach bell versus what it would take to invest up front before something even happens?
One's a few hundred thousand dollars maybe, and the other one's a couple million. It's just crazy.
Baxter Lee (30:50)
Yeah, if you're talking about a breach or a cyber incident, it tends to be orders of magnitude more expensive to clean it up after the fact. You don't want to be testing your incident response plans live for the first time during an incident.
That's a big challenge. We have clients that'll pay us 10X on an ongoing basis after a breach to do the things we'd said they could have done before, than they would've spent prior. And that's not even to deal with the remediation efforts. That's actually operationally getting it to par for where they should've been before the breach.
If you look at Change Healthcare, they spent billions rebuilding the platforms and the infrastructure. So clearly an ounce of prevention done the right way could have been significant in terms of saving that organization a lot of public reputational harm as well as financial harm. It is significant, if you haven't invested appropriately on the front end, what you end up spending after an event happens.
Ross Ronan (32:07)
You hit a really good point, and I want to make sure we've covered this. One, the Change event, and obviously the downward effect it had for all the providers that use Change and everybody else. I had several clients who were wrapped up in that. I'm sure you did as well.
The one thing you said that I think is really important is, on a cybersecurity event, anything HIPAA related, you'll see huge settlements, nine hundred and ninety-nine million dollar, billion dollar settlements. We've seen that in the False Claims arena. But the reputational harm you see with any kind of breach, with Change or anybody else, people just... One of our pillars of compliance as an advantage is patient trust equity. Patients want to trust exactly what you're doing as a provider, and if they don't think my PHI, my PII, my financial information, my healthcare security is safe with you, I am not going to go to you.
Baxter Lee (33:19)
Yeah, the industry's shifting too. Everything is about giving consumers more choice in healthcare. There are more retail options, more technology-driven options. So you're absolutely right, the reputational harm now plays into that.
If they can't trust you, not just with their outcomes and what you're trying to achieve from a health perspective, but with their data, I think that definitely has an impact on where they're going to take their care, if they have that choice. Obviously, if you're in a critical emergency situation, you need access to the best hospital in the region, you're going to go to the hospital regardless. But as we try to engineer a system that lowers costs and drives consumer behaviors and value-based care, there's a lot more opportunity where patients do have choice, and reputational harm can be significant in this industry now.
Ross Ronan (34:22)
Lowering the cost of healthcare doesn't come in the form of stopping the things that put controls into your organization so you don't have any issues, right?
Baxter Lee (34:32)
That's not the area to save.
Ross Ronan (34:35)
Not quite the same as saving money. You guys just got private equity backing. You said Sunstone backed you, and you're now president from the CFO position. What's it like for Clearwater now? How are you building out your compliance infrastructure and leadership, and what are you doing there?
Clearwater's Growth Strategy and the Healthcare Ecosystem
Baxter Lee (34:53)
We see a lot of opportunity in the space, across the ecosystem of healthcare, and we really do look at it as an ecosystem. You have health plans and large hospitals. You've got your ambulatory providers, and then all the vendors, digital health companies, and others that sell into healthcare.
On the whole, healthcare's been slow to adopt technology, and slow to invest in security around the technology we have adopted. There's been a big push for the last twenty years for electronic medical records and digitization, and now all the sharing of that data that was engineered through the HITECH Act.
We're getting the results we wanted, but that's creating a lot of fragmentation, which creates a lot of vulnerabilities. The more we share data, the more access points there are between constituents. And we're creating data at a greater volume as well. That just creates more vulnerabilities for the industry and for the ecosystem as a whole.
So we're working across the ecosystem, working with large health systems on their operational security and HIPAA compliance programs. We work with the ambulatory providers, particularly the institutional-backed roll-ups, and also value-based care platforms that are trying to grow very aggressively and may not have the internal resources, day one or throughout, to put the infrastructure in place.
We come in and build those programs out, operationalize them, and run them for them. And then at some point they may try to bring it back in-house, or they realize it's still more cost-effective and better for them if we keep running it, and they focus on their core mission of executing their strategy, and don't have to worry about managing all the challenges of cybersecurity and compliance with employee turnover and changing regulations and all the challenges that go along with it.
We see a lot of partners that we've grown significantly with, and they just keep wanting us to do it for them. So it's a big opportunity across healthcare. And then the last piece is vendors. There's a huge market in the vendor space, and more of them are bringing on data or interfacing with technology platforms of their counterparties.
They want to sell to a hospital, or they want to sell to a health plan. They need access to data and technology. Vendor risk for those health plans and providers is the fastest-growing risk. So they're putting more pressure on the vendors to demonstrate security and compliance effectively in order to get that contract in place.
The security reviews are more intense. The questions are longer than they've ever been. So it's important for the vendors to invest in their security. Talking about a competitive advantage: if you can go into those conversations proactively and say, we take security and compliance seriously, here's our playbook, here's everything we're doing, you can trust us as a partner, you can get through that security review faster and win those contracts. You can grow and achieve your revenue goals faster than if you're reacting to those and then scrambling to put those answers in place.
So we think there's a big opportunity to be proactive in the vendor landscape, to grow that market and for vendors in that space to grow more effectively. We're investing across all three end markets. We see a lot of opportunity, the same services applied differently in those different markets.
Ross Ronan (38:32)
I love what you're doing. I think your growth strategy is right on the money. For me, the reason we started this business is, we just want to help. We want to bring expertise across multiple lines to people who might not be able to have that or hire for it.
That's a struggle a lot of people have seen in healthcare across the board. So I commend what you guys are doing, and I feel like your growth strategy is pretty amazing in that whole structure.
Baxter Lee (39:05)
Yeah, appreciate that. We're a very mission-driven organization. Our employees care very much about the mission of protecting the healthcare ecosystem. Our mission statement is, we want to help our clients be more secure, compliant, and resilient, so they can achieve their missions.
This is not rocket science, but it's also not easy. Part of it is this changing landscape we've talked about, and there are not enough CISOs and compliance officers to go around at every organization, so there's a shortage of talent as well.
We play in the space of, you're doing something today, but you really need to be up here. So what's that gap? We want to close that gap for you, so you can achieve your goals and objectives from a business perspective, protect your patients, and protect their data. We're just trying to help close the gap. I think that's ultimately what we're all about, and our employees really wake up every day taking it very seriously. It's an important mission to be behind.
Taking Care of Yourself: Health Span vs. Lifespan
Ross Ronan (40:12)
That is well said. Last question, and I really appreciate your time today. I always ask this because we believe in healthcare you should always take care of yourself, your own health as well. What do you do to take care of yourself, to keep your motivation, your energy, and your physicality going?
Baxter Lee (40:27)
Yeah, I'm always striving to do better, I can tell you that. With three kids 16 and under, and work, there's not a lot of time, but it's definitely been an area I'm investing a lot more in, making sure I carve out more time for myself. Exercise, trying to take my boys out to play golf a little bit, just to unwind and connect with them in a different way that I haven't been able to do since they were younger.
So just being intentional about creating more personal time for me and my family. It's hard to balance it all. But it's about trying to be intentional and making sure that, you're right, you can't push yourself to the limits, because ultimately you've got to reinvest in yourself a little bit and give yourself the support to be able to achieve your goals.
Ross Ronan (41:19)
I love the discussion between lifespan and health span, really focusing on your health span versus your lifespan, and honestly investing in yourself. It's the same concept we've been talking about for the last forty-five minutes. Being proactive versus reactive in your health life is the same conversation.
Do you want to have a heart attack and then all of a sudden be reactive to that? Or do you want to be proactive, where you can live that health span that goes a lot longer than maybe most people do?
Baxter Lee (41:50)
Yeah, it's a great point and a reminder for myself to take more of a proactive approach as well.
Ross Ronan (41:57)
Well, Baxter, thank you so much for today. Great conversation. I know the listeners are going to love this. If anybody wants to check out Clearwater, go ahead and check them out. Baxter is the head of that, and we really appreciate your time today, so thank you so much.
Baxter Lee (42:13)
Thanks so much, Ross. Really enjoyed the conversation.
Ross Ronan (42:15)
Absolutely.
-
Baxter Lee is President of Clearwater, a healthcare cybersecurity and compliance firm.
He came up through investment banking and private equity before moving to the operator side, and he has helped grow Clearwater from 30 employees to more than 270, stepping into the president role after serving as CFO.
In this episode he and Ross break down how compliance, privacy, and security become a growth advantage when they scale with a healthcare company instead of trailing behind it..
LinkedIn →
“Don’t wait until something happens, because it will happen. I’ve been around for 20-plus years doing this, and I’ve never seen it not happen.”
Clearwater President Baxter Lee joins Ross Ronan on The Compliance Advantage to explain why compliance and security must scale with healthcare M&A growth. A diligence report on a shelf is not protection. Learn how to build a program that drives enterprise value.