7.3 Compliance Audits, OIG Work Plan, & Fraud Enforcement
Key Takeaways
- Internal audits are proactive checks within an organization, while external audits are conducted by third parties like RACs.
- The OIG Work Plan outlines the areas the Office of Inspector General intends to audit based on high risk for fraud and abuse.
- The False Claims Act (FCA) imposes liability on persons who knowingly submit false claims to Medicare or Medicaid.
- The Anti-Kickback Statute (AKS) criminalizes offering or receiving anything of value to induce referrals for federal healthcare programs.
Compliance Audits, OIG Work Plan, & Fraud Enforcement
Healthcare organizations must implement robust compliance programs to prevent and detect billing errors, fraud, and abuse. A core component of these programs is auditing. When organizations fail to comply, federal agencies step in to enforce laws designed to protect the integrity of government healthcare programs, primarily Medicare and Medicaid.
Internal vs. External Audits
Auditing is the systematic review of documentation and coding to ensure accuracy and compliance with rules. It is a critical defense mechanism for healthcare organizations.
- Internal Audits: Conducted by the organization's own staff, such as compliance officers or internal auditors (or hired consultants acting internally). These audits are proactive. They help identify weaknesses in coding, documentation, or billing processes before external entities find them. The results are used for provider education, process improvement, and internal corrective action plans.
- External Audits: Conducted by outside entities, often government contractors or commercial payers. Examples include RACs, MACs, and UPICs. The goal of external audits is typically to recover improper payments, enforce regulations, and identify potential fraud.
Government Audit Programs
The Centers for Medicare & Medicaid Services (CMS) employs several types of contractors to protect the Medicare Trust Fund:
- RACs (Recovery Audit Contractors): Their primary mission is to identify and correct improper Medicare payments—both overpayments and underpayments. They review claims on a post-payment basis. Notably, RACs are paid on a contingency fee basis, meaning they keep a percentage of what they successfully recover, which incentivizes aggressive auditing.
- UPICs (Unified Program Integrity Contractors): These contractors focus specifically on identifying and investigating suspected fraud and abuse across Medicare and Medicaid. If a UPIC finds evidence of fraud, they refer the case to the Office of Inspector General (OIG) or the Department of Justice (DOJ) for prosecution.
- CERT (Comprehensive Error Rate Testing): The CERT program is designed to measure improper payments in the Medicare fee-for-service program. It doesn't target specific providers for fraud but reviews a random, statistically valid sample of claims to calculate a national error rate. CMS uses this data to identify trends and target future educational efforts.
The OIG Work Plan
The Office of Inspector General (OIG) is the enforcement arm of the Department of Health and Human Services (HHS). Its mandate is to fight waste, fraud, and abuse in Medicare, Medicaid, and other HHS programs.
The OIG Work Plan is a crucial, publicly available document that is updated monthly. It outlines the specific areas, services, and provider types the OIG intends to investigate or audit in the coming year based on perceived high risk for fraud and abuse.
- Why it matters: Compliance departments closely review the Work Plan to identify risks applicable to their organization. If the OIG announces they are auditing high-level Evaluation and Management (E/M) visits in the emergency department, a hospital should proactively audit their own ED coding to ensure compliance before an official OIG audit occurs. It acts as a roadmap of the government's enforcement priorities.
Fraud and Abuse Laws
Understanding the difference between fraud and abuse is key, as the penalties vary significantly:
- Abuse: Involves payment for items or services when there is no legal entitlement to that payment, but the provider did not knowingly or intentionally misrepresent the facts. Examples include billing for a service that was not medically necessary due to a misunderstanding of the rules, or charging excessively for services.
- Fraud: The intentional deception or misrepresentation made by a person with the knowledge that the deception could result in some unauthorized benefit to themselves or another person. Examples include billing for services that were never provided, or intentionally altering medical records to justify higher payment.
Three major federal laws govern healthcare fraud:
1. The False Claims Act (FCA)
The False Claims Act is one of the most powerful tools the government has to combat healthcare fraud. The FCA makes it illegal to submit claims for payment to Medicare or Medicaid that you know or should know are false or fraudulent.
- "Knowing" standard: This is critical. It doesn't just mean deliberate, malicious intent. It includes acting in "reckless disregard" or "deliberate ignorance" of the truth. Failing to check if your billing practices comply with the rules, or ignoring warnings from compliance staff, can violate the FCA.
- Whistleblowers: The FCA contains a unique qui tam provision. This allows private citizens (often employees or former employees, known as whistleblowers) to file lawsuits on behalf of the government regarding false claims. If the suit is successful, the whistleblower receives a significant portion (usually 15-30%) of any recovered damages.
2. The Anti-Kickback Statute (AKS)
The AKS is a criminal law that prohibits the knowing and willful payment, offer, or solicitation of "remuneration" to induce or reward patient referrals or the generation of business involving any item or service payable by Federal health care programs.
- Remuneration: This means anything of value. It could be cash, free rent, expensive hotel stays, extravagant meals, tickets to sporting events, or excessive compensation for a medical directorship.
- Example: A laboratory offering a physician $50 for every blood test sent their way violates the AKS. The law is designed to ensure that medical decisions are based on the patient's best interest, not the physician's financial gain.
3. The Stark Law (Physician Self-Referral Law)
The Stark Law is a strict liability statute. This means that unlike the AKS, intent does not matter; if you violate the rule, you are liable, even if it was an innocent mistake.
The Stark Law prohibits a physician from referring Medicare/Medicaid patients for specific "designated health services" (DHS) to an entity with which the physician (or an immediate family member) has a financial relationship, unless a specific, legally defined exception applies.
- Designated Health Services (DHS) include: Clinical laboratory services, physical therapy, occupational therapy, radiology and certain other imaging services, and durable medical equipment (DME), among others.
- Example: A physician owns a physical therapy clinic. They cannot refer their Medicare patients to that specific clinic unless their financial arrangement fits perfectly into a Stark Law exception. The purpose is to prevent physicians from ordering unnecessary services simply to profit from their ownership interest.
Which federal law specifically prohibits offering, paying, soliciting, or receiving anything of value to induce referrals of services covered by Medicare or Medicaid?
Which government contractor is paid on a contingency fee basis and is primarily tasked with identifying and correcting improper Medicare payments, both overpayments and underpayments?