Matt is a founding member of Protiviti and serves as Protiviti’s Healthcare Internal Audit Practice Leader as part of Protiviti’s Healthcare Center of Excellence. He has more than 25 years of experience providing operational, technology, and regulatory consulting and internal audit services to a wide range of healthcare organizations. He is a frequent speaker on internal audit, compliance, and information technology improvement initiatives.  He has also published related pieces for national publications as well as various additional healthcare thought leadership resources.

Major Projects

  • Served as the lead for numerous Internal Audit reviews executed as part of both full outsourcing and co-sourcing arrangements across all sectors of the healthcare industry (with an emphasis on provider and payer organizations). The scope of these audits has included the full suite of Protiviti’s capabilities.  As limited examples, audits have include areas such as artificial intelligence governance, application pre/post implementation, EHR risk management, digital transformation, medical device life cycle management, security administration, penetration testing and vulnerability assessments, change management, data backup and recovery, data processing and interface utilization, business continuity / disaster recovery / resiliency, patient/consumer experience, IT Governance, Sarbanes-Oxley assistance, HIPAA compliance, workplace violence, revenue integrity and operations, executive compensation, payroll practices, charge capture, risk management, physician arrangements, regulatory compliance, claims system optimization, and construction program practices.
  • Facilitated the end-to-end enterprise-wide risk assessment and internal audit plan development process across a wide range of healthcare organizations.
  • Facilitated the assessment and/or establishment of various Enterprise Risk Management (ERM) functions at large healthcare organizations. Efforts covered the full spectrum of ERM from initial strategy development and program implementation through ongoing maintenance and monitoring processes.
  • Led various information security / cybersecurity program assessments for a variety of healthcare organizations in order to evaluate current-state against industry leading practices, industry leading frameworks, regulatory guidance, experience at other organizations, etc.
  • Conducted numerous reviews focused on evaluating the sufficiency of programs and practices in place for promoting, monitoring, and enforcing compliance with the safeguarding of Protected Health Information (including ePHI), as required by HIPAA.
  • Assisted various healthcare organizations across a wide range of digital initiatives including overarching strategy development, Robotic Process Automation governance/deployment, advanced analytics adoption, emerging technology governance/deployment, consumer engagement, regulatory/privacy/security implications, etc.
  • Led numerous efforts focused on evaluating and/or executing processes to satisfy the risk analysis requirement in §164.308(a)(1)(ii)(A) in order to perform an evaluation of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of applicable ePHI.

Areas of Expertise

  • Internal Audit
  • Technology Consulting
  • Security and Privacy
  • Regulatory Compliance

Industry Expertise

  • Healthcare

Education

  • BS – Management Information Systems
  • BS – Business Management

Professional Memberships and Certifications

  • Certified Healthcare Internal Audit Professional (CHIAP)
  • Project Management Professional (PMP)
  • Microsoft Certified: AI Business Professional
  • Association of Healthcare Internal Auditors (AHIA)
  • Institute of Internal Auditors (IIA)
  • Healthcare Information and Management Systems Society (HIMSS)
  • Project Management Institute (PMI)
Loading...