The Board of Visitors’ Audit, Compliance and Risk Committee convened Friday morning to hold a discussion on institutional compliance and U.Va. Health Compliance and Privacy Program reports.
The committee is tasked with overseeing internal audit, compliance and enterprise risk management for the academic and medical center divisions of the University, and it is responsible for assessing performance, accounting controls and reviewing the University’s risk governance framework. It consists of 10 members, including a faculty consulting member.
Written reports were provided to Board members for Friday’s meeting, detailing the status of various action plans, oversight of major initiatives, administrative statuses, reports on compliance programs and key auditing projects in FY2026.
The meeting commenced with opening remarks and a meeting overview by Owen Griffin, Committee chair, Commerce Class of 1994 and Darden Class of 1999 alumnus. The Committee also welcomed Steven Weber, new director of Health System Audits.
Following Griffin’s remarks, Gary Nimax, assistant vice president for compliance and College Class of 1987 alumnus, gave a report on the Committee’s Institutional Compliance program.
Nimax said that he works directly with many University compliance teams, composed of subject-matter experts from the University’s compliance areas to ensure that the University complies with federal, state and other regulatory compliance requirements. These areas include Athletics, Youth Protection, Enrollment Management, Environmental Health & Safety, Equal Opportunity & Civil Rights and Finance, among others.
Nimax also explained the seven elements of an effective compliance program, as defined by the U.S. Federal Sentencing Guidelines, which he said are considered to be the best practices for how an organization ensures their compliance program is effective. He cited elements two and seven as the Board’s focus for this meeting — oversight by high-level personnel, with periodic reporting to the Board from individuals with operational responsibility, and taking reasonable steps to respond to and prevent further similar offences.
One way to set these effective compliance expectations is the compliance helpline, according to Nimax, which consists of a web intake form and a phone hotline monitored by an independent third party. Reports from these two avenues get funneled into the SafeGrounds management system.
SafeGrounds is a platform used to monitor safety-related incidents reported across Grounds by compliance officers across the departments of Human Resources, the Office for Equal Opportunity and Civil Rights, the Office of Youth Protection, the Office of Threat Assessment and the Division of Student Affairs and the Honor and Judiciary committees.
“It allows us to track profiles for people who are involved in cases, and we get a more complete picture of that individual or of a specific area of the University,” Nimax said.
According to Nimax, out of 9,863 reports in the SafeGrounds system in the 2025-26 fiscal year, 44 percent of cases were HR related, including both academic and medical. Student affairs cases account for 29 percent of all cases, including but not limited to roommate disputes, academic deficiencies and students in need of mental health services.
Additionally, 30 percent of cases were reported anonymously, and 57 percent of cases were either fully or partially substantiated — referring to the amount of evidence presented or found in the following investigation to support the allegation.
“It’s really critical that we receive [even unsubstantiated] reports,” Nimax said. “Some organizations fall into the trap of thinking that no reports means there are no problems, and that’s not the case. We think that if an organization doesn’t receive reports like this, that it’s indicative of either a lack of awareness of the Compliance Helpline, a fear of retaliation if you report something or just a poor culture of compliance.”
Looking ahead, Nimax said he plans to monitor the Federal Office of Management and Budget’s proposed revisions to the Uniform Guidance. The Uniform Guidance is a set of federal guidelines that govern how universities must manage federal grants and other financial assistance. The Office of Management and Budget proposed changes to overhaul the Uniform Guidance in May 2026, intended to “improve transparency, accountability, and oversight for Federal awards across the Federal Government.”
He also referenced a potential change of requirements for Section 117 of the Higher Education Act, which mandates reporting any foreign gifts or contracts that universities receive, as well as the evolving use of artificial intelligence and AI strategy across the University. The U.S. Education Department’s proposed changes of requirements for Section 117 include public release of all foreign source names, employee compliance certifications and collection of donor identities, among others.
Annette Norton, director of Corporate Compliance and Privacy at U.Va. Health, then gave committee members a report on U.Va. Health’s compliance program.
The U.Va. Health Compliance system had 1330 cases logged through the SafeGrounds system, with almost 60 percent of reports coming in categorized as HIPAA Privacy compliance issues. This is about a 30 percent increase from the number of total compliance reports in FY25, but Norton said that this increase is positive because it means that the University community both utilizes and trusts the Office of Compliance.
Norton said that 66 percent of total cases were substantiated and 10 percent of cases were partially substantiated. She also discussed additional compliance-conducted monitoring activities, including HIPAA site audits, random snooping tests, Break the Glass audits and billing reviews. In total, 627 of these audits and tests were conducted in the 2025-26 fiscal year.
The Audit, Compliance and Risk Committee will convene again during the next scheduled Board meeting Dec. 2-4.

Charlotte Gabriel is a second-year Commerce and College student, and she serves as a staff writer on the news desk.




