6.4 Voluntary Self-Disclosure Protocols (OIG SDP, CMS SRDP) & Corporate Integrity Agreements (CIAs)

Key Takeaways

  • The OIG Health Care Fraud Self-Disclosure Protocol (SDP) allows healthcare providers to voluntarily report potential fraud, offering financial benefits (typically a 1.5x multiplier instead of 3x FCA treble damages) and a presumption against imposing a Corporate Integrity Agreement (CIA).
  • The CMS Self-Referral Disclosure Protocol (SRDP) is designed exclusively for disclosing actual or potential non-compliance with the Stark Law (Physician Self-Referral Law), allowing CMS to compromise overpayment liabilities.
  • Corporate Integrity Agreements (CIAs) are binding 5-year compliance contracts negotiated between the OIG and healthcare entities to resolve FCA investigations, mandating specific structural governance, operational policies, and confidential reporting channels.
  • CIAs mandate the engagement of an Independent Review Organization (IRO) to conduct annual objective Claims Reviews or Systems Reviews, with severe stipulated monetary penalties or program exclusion for non-compliance.
Last updated: July 2026

6.4 Voluntary Self-Disclosure Protocols (OIG SDP, CMS SRDP) & Corporate Integrity Agreements (CIAs)

When a healthcare compliance investigation reveals systemic non-compliance, intentional billing fraud, or physician financial relationships violating federal fraud and abuse laws, simply submitting a routine refund check to a Medicare Administrative Contractor (MAC) is legally insufficient. In such high-stakes matters, healthcare organizations must utilize formal federal self-disclosure protocols established by the HHS Office of Inspector General (OIG) or the Centers for Medicare & Medicaid Services (CMS). Voluntary self-disclosure provides structured mechanisms to resolve liabilities, avoid catastrophic False Claims Act (FCA) litigation, and prevent the imposition of mandatory Corporate Integrity Agreements (CIAs).


OIG Health Care Fraud Self-Disclosure Protocol (SDP)

First established in 1998 and revised in 2013 and 2021, the OIG Health Care Fraud Self-Disclosure Protocol (SDP) provides healthcare providers with a transparent, standardized pathway to voluntarily disclose and resolve potential fraud involving federal healthcare programs.

Scope and Eligibility

The OIG SDP is designed for matters involving potential violations of federal criminal, civil, or administrative law for which Civil Monetary Penalties (CMPL), Anti-Kickback Statute (AKS), or FCA liability may apply. To participate, the provider must:

  • Make a disclosure that is voluntary, complete, and in good faith.
  • Not be under active OIG or Department of Justice (DOJ) investigation for the same conduct.
  • Complete a full internal investigation and submit a comprehensive financial damage quantification within 90 days of initial submission.

Minimum Settlement Thresholds (2021 Updates)

Under the OIG's 2021 updated SDP guidance, mandatory minimum settlement amounts were increased:

  • Kickback Matters: Minimum $100,000 settlement threshold for self-disclosures involving potential Anti-Kickback Statute violations.
  • General Billing & Other Matters: Minimum $20,000 settlement threshold for general billing fraud or non-kickback disclosures.

Financial & Operational Benefits of OIG SDP

+-----------------------------------------------------------------------------------+
|                         OIG SDP ADVANTAGES VS. FCA LITIGATION                     |
+-----------------------------------------------------------------------------------+
| Feature                 | FCA Litigation / Subpoena   | OIG SDP Disclosure        |
| ----------------------- | --------------------------- | ------------------------- |
| Damages Multiplier      | 3x Treble Damages           | 1.5x Single Damages       |
| Per-Claim Penalties     | Mandatory ($13k - $27k/claim)| Generally Waived          |
| Corporate Integrity Agmt| High Likelihood (5-Yr CIA)  | Presumption AGAINST CIA   |
| Resolution Timeline     | 3 to 5 Years                | 12 to 18 Months           |
+-----------------------------------------------------------------------------------+

Key Benefit: The primary incentive for utilizing the OIG SDP is securing a reduced damages multiplier (typically 1.5 times single damages) and obtaining a release of OIG Civil Monetary Penalties authority without being subjected to an OIG-imposed Corporate Integrity Agreement.


CMS Self-Referral Disclosure Protocol (SRDP)

While the OIG SDP handles fraud and kickback matters, disclosures involving strictly technical or operational non-compliance with the Stark Law (Physician Self-Referral Law, 42 U.S.C. § 1395nn) must be submitted through the CMS Self-Referral Disclosure Protocol (SRDP).

Distinguishing OIG SDP from CMS SRDP

                               +----------------------------+
                               | COMPLIANCE DISCLOSURE PATH |
                               +----------------------------+
                                             |
       +-------------------------------------+-------------------------------------+ 
       |                                                                           |
+------------------------------+                                            +------------------------------+
|       OIG SDP DISCLOSURE     |                                            |      CMS SRDP DISCLOSURE     |
| • Anti-Kickback Statute (AKS)|                                            | • Stark Law STRICTLY         |
| • Intentional Billing Fraud  |                                            | • Missing/Expired Signatures |
| • Excluded Individual Billing|                                            | • Unwritten Lease/Doctor Agmt|
| • Requires 1.5x Multiplier   |                                            | • CMS Compromise Authority   |
+------------------------------+                                            +------------------------------+

CMS Settlement Compromise Authority

Because the Stark Law is a strict liability statute (meaning intent is irrelevant, and all claims billed during a period of non-compliance are tainted), total overpayment liabilities under Stark can reach tens of millions of dollars. Under the SRDP, CMS exercises statutory compromise authority under Section 6409 of the ACA to reduce financial settlements based on:

  1. Nature and extent of the technical non-compliance
  2. Timeliness of the self-disclosure
  3. Cooperation of the provider
  4. Efficacy of the entity's compliance program

Tolling the 60-Day Overpayment Rule

Submitting a formal disclosure under the CMS SRDP (or OIG SDP) tolls (pauses) the 60-day deadline under the ACA Overpayment Rule while CMS evaluates the disclosure, protecting the provider from Reverse False Claims Act liability during federal review.


Corporate Integrity Agreements (CIAs)

When a healthcare organization resolves a major government fraud investigation or False Claims Act enforcement action with the DOJ and OIG without self-disclosing, the OIG typically requires the entity to enter into a Corporate Integrity Agreement (CIA) as a condition of avoiding exclusion from Medicare and Medicaid.

Definition and Scope

A Corporate Integrity Agreement (CIA) is a binding, enforceable compliance contract between the OIG and a healthcare entity. CIAs typically last 5 years and impose strict operational, monitoring, and reporting obligations.

Mandatory Core Elements of a CIA

  1. Compliance Infrastructure: Appointment of a dedicated Compliance Officer and Compliance Committee with direct, unmediated access to the Board of Directors.
  2. Written Standards: Promulgation of a comprehensive Code of Conduct and specific operational compliance policies.
  3. Mandatory Training: Annual general and role-specific compliance training for all covered persons, requiring 100% completion tracking and signed attestations.
  4. Confidential Disclosure Log: Maintaining an anonymous hotline and formal disclosure log documenting all reported compliance concerns and investigations.
  5. Exclusion Screening: Mandatory monthly screening of all employees and contractors against the OIG List of Excluded Individuals/Entities (LEIE) and SAM.gov.
  6. Reportable Events: Mandatory written notification to the OIG within 30 days of identifying any "reportable event" (such as a substantial overpayment or government investigation).

Independent Review Organizations (IROs) & Compliance Reporting Obligations

A central component of every Corporate Integrity Agreement is the requirement to engage an independent third party to perform objective audits.

Role of the Independent Review Organization (IRO)

An Independent Review Organization (IRO) is an accounting, auditing, or consulting firm retained by the healthcare provider but approved by the OIG. The IRO must be completely independent of the healthcare organization.

+-----------------------------------------------------------------------------------+
|                             CORE TYPES OF IRO REVIEWS                             |
+-----------------------------------------------------------------------------------+
| 1. Claims Reviews:     Annual statistical sampling of paid Medicare/Medicaid      |
|                        claims to evaluate billing accuracy and calculate error    |
|                        rates.                                                     |
| 2. Systems Reviews:    Detailed operational reviews evaluating governance,        |
|                        Stark/AKS arrangements databases, or executive compensation|
|                        tracking systems.                                          |
+-----------------------------------------------------------------------------------+

Annual Reporting & Stipulated Penalties

  • Implementation Report: Submitted to the OIG within 90 to 120 days of CIA execution, detailing the setup of all mandatory compliance elements.
  • Annual Reports: Submitted every 12 months, incorporating full IRO audit findings, training logs, hotline summaries, and executive certifications.
  • Stipulated Penalties: Monetary fines ($1,000 to $2,500+ per day) automatically assessed by the OIG for failing to submit reports on time, failing to implement IRO recommendations, or breaching CIA provisions.
  • Material Breach & Exclusion: Continued or egregious failure to comply with CIA terms constitutes a material breach, triggering OIG's Notice of Intent to Exclude the provider from all federal healthcare programs.

Real-World Healthcare Compliance Scenario

Case Study: Stark Law Technical Non-Compliance & CMS SRDP Resolution

Context: During an internal compliance audit of physician contracts at a community hospital, the compliance team discovers that 8 medical director agreements with local specialists had expired 14 months prior. The physicians continued providing medical director services and receiving monthly stipends ($5,000/month) without signed contract renewals, creating a technical Stark Law violation.

Strategic Resolution Path:

  1. Option Evaluation:
    • MAC Refund: Inappropriate; does not resolve underlying Stark Law strict liability.
    • OIG SDP: Inappropriate; there is no evidence of Anti-Kickback Statute intent or criminal fraud.
    • CMS SRDP: Selected. Designed specifically for Stark Law non-compliance.
  2. Execution & Tolling: Counsel prepares a full SRDP submission establishing that stipends reflected Fair Market Value (FMV) and services were actually performed. Submission tolls the 60-day overpayment clock.
  3. Settlement Compromise: Rather than demanding repayment of all $18 million in downstream Medicare claims billed by the 8 specialists during the 14-month gap, CMS exercises compromise authority and settles the matter for $65,000.
  4. Outcome: The hospital resolves all Stark liability, avoids FCA litigation, and avoids an OIG Corporate Integrity Agreement.
Test Your Knowledge

What is the primary financial incentive for a healthcare organization to voluntarily disclose billing fraud or Anti-Kickback Statute violations through the OIG Health Care Fraud Self-Disclosure Protocol (SDP) rather than waiting for a government subpoena?

A
B
C
D
Test Your Knowledge

A hospital discovers that it made stipend payments to community physicians under medical director agreements that had expired 12 months prior without written extensions. The payments reflected fair market value, but lacked signed contracts. Which self-disclosure pathway is specifically designed to resolve this matter?

A
B
C
D
Test Your Knowledge

Under a 5-year OIG Corporate Integrity Agreement (CIA), what is the primary role of an Independent Review Organization (IRO)?

A
B
C
D
Test Your Knowledge

What is the consequence if a healthcare entity under a Corporate Integrity Agreement (CIA) fails to submit its required Annual Report to the OIG by the designated deadline?

A
B
C
D