The Day After You Close, the Compliance Bar Goes Up: Baxter Lee on Healthcare M&A, Compliance, and Security
When a private equity firm closes a healthcare deal, the compliance and security bar rises the next morning, whether the new owner is ready or not. On this episode of The Compliance Advantage, host Ross Ronan talks with Baxter Lee, President of Clearwater, about why so many programs fall behind the moment growth speeds up. Baxter has spent his career on both sides of the table, in investment banking and private equity, then as an operator and CFO, and now leading Clearwater through its own growth from 30 to more than 270 people. He explains why a diligence report that sits on a shelf protects no one, and why compliance, privacy, and security only work when they run as one continuous program that is tested, not just documented.
What you will hear in this episode
- Why a diligence report on a shelf protects no one, and what an actioned program looks like instead.
- How closing a deal raises the compliance bar overnight in the eyes of the Office for Civil Rights.
- Why privacy, compliance, and security have to run as one continuous, tested program.
- What a breach really costs compared to investing in prevention up front.
- How an M&A playbook keeps a roll-up from outgrowing its own controls.
- Why patient trust is an asset that drives where people take their care.
The bar rises overnight, whether you're ready or not
Closing a healthcare deal doesn't come with a grace period. Regulators, including the Office for Civil Rights, expect the acquired organization to meet a higher standard starting the day after signing, regardless of what the compliance program looked like the day before. Baxter has watched this play out from both sides of the table: first structuring deals in investment banking and private equity, then living with the consequences as an operator and CFO growing Clearwater from 30 employees to more than 270.
That dual perspective is what shapes his warning to growing healthcare companies: the pace of a roll-up or growth strategy will always outrun a compliance program that isn't built to scale with it.
Diligence doesn't end at close
A due diligence report is only useful if someone acts on it. Too often, it gets filed away once the deal closes, and the findings never turn into a working program. Baxter argues that an actioned program, one that takes diligence findings and implements them, tests them, and revisits them, is what actually protects the organization. The report itself protects no one sitting in a drawer.
A diligence report that sits on a shelf protects no one. Baxter Lee, President, Clearwater
One continuous, tested program
Compliance, privacy, and security are frequently managed as three separate workstreams, each with its own owner and its own timeline. Baxter makes the case that this separation is exactly where risk hides. When the three run as one continuous program, tested rather than simply documented, gaps close and leadership gets one accurate picture of where the organization actually stands.
What breach costs compared to prevention
Ross and Baxter dig into the real math of waiting. The cost of a breach isn't limited to the incident response bill. It includes the damage to the deal's value, the operational disruption, and the harder-to-reverse erosion of patient trust. Building the foundation early, before the deal closes and before growth accelerates, is consistently cheaper than cleaning it up after the fact.
Patient trust is an asset, and a growth engine
For a growing healthcare company, especially one built through a series of acquisitions, an M&A playbook that scales compliance and security alongside the deal pipeline is what keeps the roll-up from outgrowing its own controls. Done right, Baxter says, compliance and security aren't a cost center. They're how a growing healthcare company protects its value and earns the trust that keeps patients, and growth, coming.
Done right, compliance and security are not a cost. They are how a growing healthcare company protects its value and earns the trust to keep growing. Baxter Lee, President, Clearwater
About Baxter Lee
Baxter Lee is President of Clearwater, a healthcare cybersecurity and compliance firm. He came up through investment banking and private equity before moving to the operator side, and has helped grow Clearwater from 30 employees to more than 270, stepping into the president role after serving as CFO.
Healthcare M&A compliance questions this episode answers
Why does the compliance bar rise the moment a healthcare deal closes?
The moment a private equity firm closes a healthcare deal, the Office for Civil Rights and other regulators expect the new owner to be operating at a higher standard immediately, regardless of whether the organization is actually ready. Growth accelerates faster than most compliance programs can keep pace.
What happens to due diligence reports after a healthcare deal closes?
Too often, the diligence report gets filed away once the deal is done. A report that sits on a shelf protects no one. It only creates value when its findings are actioned into a real program that is implemented and tested after close, not simply documented before it.
Why should compliance, privacy, and security run as one program?
When compliance, privacy, and security are managed as separate, siloed efforts, gaps form in the space between them. Running them as one continuous, tested program closes those gaps and gives leadership a single accurate picture of risk as the organization grows.
What does a healthcare data breach cost compared to investing in security up front?
Waiting until a breach happens is far more expensive than building the foundation early. Beyond direct incident costs, a breach damages the acquired company's value and the trust that drives patients to keep seeking care there, costs that are much harder to reverse than to prevent.
Why is patient trust considered a business asset in healthcare M&A?
Patients choose where to receive care partly based on whether they trust an organization to protect their data. In a roll-up strategy, an M&A playbook that keeps compliance and security scaling alongside growth protects that trust, turning it into an asset that supports continued expansion rather than a liability that undermines it.
Growing through acquisition? Don't outgrow your controls.
Clearwater helps healthcare organizations build compliance and security programs that scale with growth, not behind it. Get out of the storm and into Clearwater.
Talk with our consultants



