2.3 Written Standards, Code of Conduct & Operational Policies and Procedures

Key Takeaways

  • The Code of Conduct serves as the foundational ethical standard for the entire organization and must be distributed to 100% of employees, board members, medical staff, and contractors.
  • Written attestations confirming receipt, reading, and agreement to comply with the Code of Conduct must be collected upon hire/onboarding and annually thereafter.
  • Operational policies and procedures translate high-level compliance principles into specific, actionable steps for high-risk areas such as Stark/AKS financial relationships, billing accuracy, non-retaliation, and HIPAA privacy.
  • Compliance policies require a structured review cycle (typically annual) and mandatory revision whenever relevant federal laws, OIG guidance, or internal audit findings change.
Last updated: July 2026

Written Standards, Code of Conduct & Operational Policies and Procedures

Executive Summary: Written standards form the structural backbone of an effective compliance program. An organization's Code of Conduct articulates its foundational ethical commitments, while operational policies and procedures translate statutory requirements into concrete, day-to-day operational workflows. To ensure efficacy, healthcare entities must mandate 100% workforce distribution and annual attestation, maintain a centralized electronic policy management system, and enforce strict version control and review cycles.


The Code of Conduct: Foundational Standard of Conduct

The Code of Conduct (also referred to as the Code of Ethics or Standards of Conduct) is the premier governance document of a healthcare organization. It establishes the institutional tone, articulates ethical principles, and outlines mandatory behavior for all individuals associated with the entity.

Scope and Distribution Mandates

Under OIG General Compliance Program Guidance (GCPG), the Code of Conduct cannot be limited to full-time administrative staff. It must apply universally to 100% of workforce members, including:

  • Executive officers and administrative managers.
  • Members of the Board of Directors.
  • Full-time, part-time, and PRN clinical employees.
  • Physicians, mid-level providers, and allied health professionals on the medical staff.
  • Independent contractors, temporary staffing personnel, consultants, and commercial vendors.

Essential Components of a Healthcare Code of Conduct

+-------------------------------------------------------------------+
|                     CORE CODE OF CONDUCT ELEMENTS                 |
+-------------------------------------------------------------------+
| 1. Organizational Mission, Values & Ethical Commitment            |
| 2. Commitment to Full Compliance with Federal/State Laws          |
| 3. Mandatory Duty to Report Misconduct & Compliance Hotline Info   |
| 4. Absolute Non-Retaliation & Whistleblower Protection Policy      |
| 5. Rules on Conflicts of Interest, Gifts & Vendor Interactions    |
| 6. Standards for Accurate Billing, Coding & Medical Records       |
| 7. Protection of Patient Privacy (HIPAA) & Asset Security         |
| 8. Disciplinary Consequences for Compliance Violations            |
+-------------------------------------------------------------------+

Attestation Protocols & Tracking Systems

Distributing the Code of Conduct is legally insufficient unless the organization verifies and documents that each individual has read, understood, and agreed to abide by its terms.

Mandatory Attestation Workflow

  1. Initial Onboarding Attestation: Collected from all new employees, board members, and contractors prior to or on their first day of service.
  2. Annual Re-Attestation: Collected from 100% of existing personnel during a designated annual compliance attestation window.
  3. Electronic Tracking & Audit Trails: Compliance management software or Learning Management Systems (LMS) record timestamped electronic signatures, IP addresses, and document version IDs to establish an unalterable audit trail.

Enforcement for Non-Responders

Organizations must establish a zero-tolerance policy for non-completion of annual attestations. Personnel who fail to complete attestations within prescribed deadlines should face escalating administrative consequences, including system access revocation, suspension of clinical privileges, or administrative leave without pay until compliant.


Operationalizing Compliance: Specific Policies & Procedures

While the Code of Conduct outlines overarching ethical principles, operational Policies and Procedures (P&Ps) provide detailed, step-by-step instructions for managing specific operational risk areas.

Hierarchy of Governance Documentation

Document LevelDocument TypeScope & PurposeTarget Audience
Level 1Code of ConductHigh-level ethical principles, mission, universal reporting duties, non-retaliation.Entire workforce, board, medical staff, vendors.
Level 2Operational Compliance PoliciesDetailed rules governing specific regulatory risk domains (Stark, AKS, HIPAA, Billing).Specific functional departments (e.g., Billing, HIM, Contracting).
Level 3Standard Operating Procedures (SOPs)Granular, step-by-step procedural workflows and task instructions.Operational line staff, coders, intake specialists.

Mandatory Healthcare Compliance Policies

A comprehensive healthcare compliance program must maintain explicit policies covering high-risk regulatory areas:

  • Non-Retaliation Policy: Absolute protection for employees reporting suspected compliance breaches in good faith.
  • Conflict of Interest (COI) Policy: Disclosure and management protocols for financial, professional, or personal conflicts involving employees, executives, or physicians.
  • Physician Financial Relationships Policy: Governs arrangements under the Stark Law and Anti-Kickback Statute, requiring advance written contracts, documented Fair Market Value (FMV) compensation, commercial reasonableness, and centralized contract tracking.
  • Billing Integrity & Overpayment Refund Policy: Dictates accurate coding standards and mandates prompt refunding of identified overpayments under the 60-Day Overpayment Rule (Social Security Act § 1128J(d)).
  • Sanction Screening Policy: Mandates monthly checking of all employees and vendors against the OIG LEIE and GSA SAM.gov exclusion databases.
  • HIPAA Privacy & Security Policies: Outlines breach notification workflows, minimum necessary data access, physical security, and electronic record safeguards.

Policy Review Cadence, Version Control & Accessibility

Static, unmaintained policies fail to satisfy federal effectiveness standards. Policies must evolve alongside changing laws and operational practices.

Policy Review Schedules

  • Routine Annual Review: Every compliance policy must undergo formal review at least annually by designated policy owners and the Compliance Committee.
  • Triggered Out-of-Cycle Reviews: Immediate policy revisions are required when:
    • Congress or state legislatures enact new healthcare statutes.
    • Federal agencies (CMS, OIG, OCR) publish revised regulations or General Compliance Program Guidance updates.
    • Internal or external audits reveal operational compliance gaps or ambiguous guidelines.
    • Settlements or Corporate Integrity Agreements (CIAs) dictate new standard operating requirements.

Centralized Accessibility and Version Control

Healthcare institutions must maintain a single, centralized electronic policy repository on an intranet portal accessible 24/7/365 to all staff. Physical paper policy binders should be phased out, as they encourage the use of obsolete procedures.

Version Control Metadata Standards

Every policy document must display standardized metadata header controls:

  • Document ID & Title: Unique identifier and official descriptive title.
  • Effective Date & Current Version Number: Date the current version took effect.
  • Historical Revision Log: Summary of past revisions, approval dates, and retired version numbers.
  • Owner & Approval Authority: Designated department owner (e.g., CCO) and approving body (Compliance Committee / Board).
  • Archive Maintenance: Retired policy versions must be securely archived for a minimum of 6 to 10 years (matching False Claims Act statute of limitations) to defend historical operational practices during government audits or litigation.

Real-World Healthcare Compliance Scenario

The Outdated Policy Defense Failure

Background: A regional home health agency was subjected to a targeted audit by a Medicare Administrative Contractor (MAC) regarding skilled nursing home visits. The audit revealed systematic overbilling totaling $3.4 million due to incorrect billing codes applied to routine custodial care.

Investigation Findings: Federal investigators discovered that billing clerks were following a printed paper manual dating from 2018 that resided in the billing department manager's office. CMS had published updated billing rules in 2021 that restricted those specific code combinations. However, the agency had failed to perform annual policy reviews, had no electronic policy portal, and had never updated the physical manual. Furthermore, 35% of the billing staff had failed to complete their annual Code of Conduct attestations over the preceding two years.

Legal Outcome: The DOJ rejected the agency's assertion of "unintentional administrative mistake." Federal prosecutors established that operating with outdated policies and failing to enforce mandatory annual attestations demonstrated reckless disregard under the False Claims Act. The agency settled the matter for $8.5 million and entered into a strict 5-year Corporate Integrity Agreement requiring centralized electronic policy management with mandatory quarterly audit trails.

Test Your Knowledge

To whom must an effective healthcare organization's Code of Conduct be distributed and applied?

A
B
C
D
Test Your Knowledge

What is the primary operational objective of establishing a strict version control and archiving process for compliance policies and procedures?

A
B
C
D
Test Your Knowledge

Which event should immediately trigger an out-of-cycle review and potential update of an operational compliance policy?

A
B
C
D