How Exclusion And Ultimatums To Whistleblowers Support Charges Of Retaliation

A former Mayo Clinic research director, Traci Tamiko Eto, sued the health system and alleged she was demoted and fired after raising concerns about AI oversight on research projects. Eto had alleged discrimination and retaliation in an EEOC charge and received a right-to-sue letter prior to filing her lawsuit.

According to the allegations in the lawsuit, Eto identified "a series" of lapses in compliance with federal research standards at the health system. This included bypassing institutional review board review, mishandling patient data, and authorization of a cardiac surgical device procedure that had not gone through institutional review board.

Further, a 2024 study of MAYA, the digital assistant tool used by the health system, revealed the tool mischaracterized outcomes, deleted unfavorable results, and used unauthorized software.

Eto alleges researchers attempted to conceal a 67 percent MAYA error rate, and the study was ultimately approved, without inspections despite ten separate whistleblower reports.

Eto reported concerns to the health system's legal department, after which she was allegedly excluded from leadership meetings and later told she could resign on her own or face professional consequences. Eto was placed on a corrective action plan, which she challenged. She alleged there was no meaningful investigation of her report.

Further, Eto was allegedly demoted. In addition she requested Family and Medical Leave Act leave, which was initially denied, before ultimately being approved only after she retained an attorney. While on leave, Eto received a notification that her job was being eliminated. She was ultimately terminated after applying for several different internal positions. Eto alleges an internal "ghost file" at the health system flags former employees who raised concerns as "Not Eligible for Rehire".

Source: https://www.beckershospitalreview.com/healthcare-information-technology/ai/mayo-faces-lawsuit-over-ai-oversight-retaliation/

Commentary

The employee in the above case experienced exclusion, had her FMLA rights interfered with, and was ultimately terminated after reporting compliance concerns.

Healthcare employers should take care to ensure employees who report compliance or other concerns do not suffer from retaliation as a result of making a report.

To help mitigate the risks, consider the following:

· Prohibit any manager from unilaterally excluding an employee from recurring meetings, distribution lists, or decisions;

· Require human resources approval and written, documented business-related reasons for altering an employee's responsibilities or duties;

· Provide a reporting channel that is outside the reporter's managerial chain of command;

· Audit management conduct toward employees who have raised concerns or made reports; and

· Consult local legal counsel before making any employment decisions related to employees who have voiced concerns.

The final takeaway is that retaliation for reporting potential workplace wrongdoing can include exclusion, resignation ultimatums, denial of medical leave, and other adverse employment actions.

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

How Exclusion And Ultimatums To Whistleblowers Support Charges Of Retaliation

A health system is sued by an employee, who alleged she was excluded and given an ultimatum after reporting compliance concerns. We comment on the risks healthcare employers create when they isolate employees instead of conducting an investigation.

Poor Vendor Email Security Creates Huge Risk

An Atlanta children's charity suffers a $5 million loss after an attacker used a trusted vendor's email to request a payment information change. We discuss how vendor email compromise and poor internal controls can combine to create sizeable risks.

Malicious File Extensions: Inspect The Bytes, Not The Name

A new phishing campaign is delivering malware inside files that carry a font extension that is not actually a font. We examine how these campaigns bypass cybersecurity controls and what organizations need to know.

Do Your Due Diligence Before Hiring For Financial Positions

A Massachusetts man pled guilty to embezzling $7.8 million from two different medical practices using the same scheme. We discuss the importance of due diligence when hiring and how it can help avoid the fraud risks.

The Multiple Risks From "Boss Scams": More Than Just Lost Revenue

Executive impersonation is a common social engineering tactic used by cyber criminals. We comment on protecting the tricked employee from unfounded accusations while protecting the organization from loss.