7.7 The Organizational Compliance Plan and Workforce Compliance
Key Takeaways
- An effective compliance program has seven elements: written policies and standards of conduct, a designated compliance officer and committee, training and education, effective lines of communication including an anonymous hotline and non-retaliation, internal monitoring and auditing, consistently enforced disciplinary standards, and prompt response with corrective action.
- The elements derive from the Federal Sentencing Guidelines and OIG compliance program guidance, most recently the General Compliance Program Guidance issued in November 2023, with the monthly-updated OIG Work Plan as a planning input.
- Exclusion screening against the OIG List of Excluded Individuals/Entities and SAM must occur at hire and periodically thereafter, because no federal health care program payment may be made for items or services furnished, ordered, or prescribed by an excluded person.
- Identified overpayments must be reported and returned within 60 days of identification; the OIG Self-Disclosure Protocol carries minimum settlement amounts of $100,000 for kickback-related matters and $20,000 for other matters, while Stark-only issues go to the CMS Voluntary Self-Referral Disclosure Protocol.
- Compliance, risk management, quality, internal audit, legal, and privacy are distinct functions with overlapping data; the risk manager collaborates on the compliance plan but does not own it, and the compliance officer's independence and direct board access are structurally protected.
What This Task Actually Asks
Domain 3 asks the risk manager to collaborate in the development of the organization's regulatory compliance plan so the workforce complies with applicable accreditation standards. Read the verb again: collaborate. The compliance plan is not the risk manager's document. It belongs to the compliance officer and, ultimately, to the governing body. The exam repeatedly tests whether you know the difference between contributing risk intelligence to a compliance program and taking it over.
This section covers the structure of a compliance program. The substantive fraud and abuse statutes - the physician self-referral law, the anti-kickback statute, and the False Claims Act - are taught separately; here they matter only as the risks the program exists to control.
The Seven Elements of an Effective Compliance Program
The seven elements originate in the United States Sentencing Commission's Federal Sentencing Guidelines for organizations, where an effective program can reduce a convicted organization's culpability score and therefore its fine, and were carried into healthcare through the Department of Health and Human Services Office of Inspector General (OIG) compliance program guidance - the 1998 hospital guidance, the 2005 supplemental guidance, and the General Compliance Program Guidance (GCPG) the OIG issued in November 2023 for all segments of the industry, followed by industry-segment-specific guidance.
| # | Element | Healthcare implementation example | Risk manager's contribution |
|---|---|---|---|
| 1 | Written policies, procedures, and standards of conduct | Code of conduct signed at hire and annually; policies on coding and documentation, gifts and vendor interactions, conflicts of interest, and referral arrangements | Supplies event and claims data showing where policy is ambiguous or ignored; aligns clinical risk policies with the code |
| 2 | A designated compliance officer and compliance committee | Compliance officer with independent, direct access to the board's audit and compliance committee | Serves as a committee member bringing the loss and exposure view; does not chair or absorb the function |
| 3 | Effective training and education | Role-specific annual training with completion tracking and competency validation, not just attendance | Contributes case-based content from real events and closed claims; measures whether behavior changed |
| 4 | Effective lines of communication | Anonymous hotline and web portal, open-door access to the compliance officer, and a documented, enforced non-retaliation policy | Ensures the hotline and the event-reporting system route correctly so clinical harm reports reach patient safety |
| 5 | Internal monitoring and auditing | An annual compliance risk assessment driving an audit work plan covering coding, billing, credentialing, and financial arrangements | Shares loss runs, event trends, and near-miss themes as audit targets; consumes audit findings as claim signals |
| 6 | Well-publicized disciplinary standards, enforced consistently | One accountability framework applied to executives, employed physicians, and frontline staff alike | Reconciles the disciplinary framework with the just-culture algorithm so identical conduct is treated identically |
| 7 | Prompt response to detected offenses and corrective action | Documented investigation, corrective action plan, repayment where owed, and a reasoned self-disclosure decision | Coordinates evidence preservation, notifies carriers where a claim may follow, tracks corrective actions to closure |
Two elements draw the most exam attention. Consistent enforcement is where programs fail in practice: a hospital that terminates a coder for the same conduct it tolerates in a high-admitting surgeon has a paper program, and regulators read the disciplinary record, not the policy. Prompt response is where the risk manager is most visible, because a detected offense is simultaneously a compliance matter, a potential overpayment, a possible claim, and an evidence-preservation problem.
An organization has a signed code of conduct, a designated compliance officer with board access, annual role-based training, a documented audit work plan, and a written disciplinary policy. Employees who suspect wrongdoing are instructed to report it to their immediate supervisor, and several have said they fear being identified. Which element of an effective compliance program is deficient?
Planning Inputs, Screening, and the Cost of Getting It Wrong
The OIG Work Plan and published guidance
The OIG's Work Plan, updated monthly, lists the audits and evaluations the OIG intends to conduct - the closest thing to advance notice of federal enforcement attention. The General Compliance Program Guidance supplies the current framework expectations. A compliance work plan that does not visibly react to the OIG Work Plan and to the organization's own risk assessment is a defensible-sounding document that will not hold up under scrutiny.
Exclusion screening
Individuals and entities excluded from federal health care programs appear on the OIG's List of Excluded Individuals/Entities (LEIE) and in the System for Award Management (SAM) exclusion records. Screening obligations to know cold:
- Screen before hire or contracting, and periodically thereafter; the LEIE is updated monthly and the OIG's guidance points organizations toward monthly checking.
- Screen everyone in the payment chain: employees, medical staff members, temporary and agency staff, volunteers with patient contact, vendors, billing companies, and contractors.
- No federal health care program payment may be made for any item or service furnished, ordered, or prescribed by an excluded person - including administrative and management services, and including situations where the excluded person never submits a claim personally.
- Consequences of employing an excluded person include repayment of amounts received, civil monetary penalties per item or service claimed (statutory amounts are adjusted for inflation) plus treble damages, and potential False Claims Act exposure for retaining the money.
Self-disclosure and the 60-day rule
When an internal investigation finds that the organization received money it was not entitled to, the 60-day overpayment rule - Section 1128J(d) of the Social Security Act, added by the Affordable Care Act - requires the overpayment to be reported and returned within 60 days of identification, or by the date any corresponding cost report is due, whichever is later. An identified overpayment that is not returned becomes an "obligation" and can support reverse false claims liability. "Identified" requires quantification through reasonable diligence, so a prompt, documented investigation is part of complying with the rule rather than a delay of it, and the CMS rule applies a six-year lookback.
Two disclosure pathways exist, and choosing between them is a legal decision made with counsel:
| Pathway | Use it for | Notable features |
|---|---|---|
| OIG Health Care Fraud Self-Disclosure Protocol (SDP) | Conduct potentially violating federal criminal, civil, or administrative laws for which civil monetary penalties are authorized, including kickback-related conduct | Minimum settlement amounts of $100,000 for kickback-related matters and $20,000 for all other matters; generally results in a lower damages multiplier and reduced likelihood of a Corporate Integrity Agreement |
| CMS Voluntary Self-Referral Disclosure Protocol (SRDP) | Actual or potential violations of the physician self-referral law only | CMS retains settlement authority; not available for conduct that also implicates the anti-kickback statute |
| Refund to the contractor | Ordinary billing errors with no fraud indicia | Return through the Medicare Administrative Contractor's overpayment process within the 60-day window |
The 60-day return deadline is suspended once the OIG acknowledges receipt of an SDP submission or CMS acknowledges an SRDP submission - a practical reason the disclosure decision must be made deliberately and documented, not deferred.
During a routine re-screening, the compliance department discovers that a per-diem respiratory therapist hired eight months ago appears on the OIG List of Excluded Individuals/Entities. She does not submit claims herself; her services are billed as part of the hospital's inpatient rate. What is the correct characterization of the organization's exposure?
Compliance Is Not Risk Management: The Boundary the Exam Probes
Compliance, risk management, quality, internal audit, legal, and privacy all consume overlapping data and often sit in the same weekly meeting. The exam wants you to know they are distinct functions with distinct accountability.
| Function | The question it answers | Primary source of authority |
|---|---|---|
| Compliance | Are we following the rules that govern payment and program participation? | Federal Sentencing Guidelines, OIG guidance, settlement obligations |
| Risk management | What could cause loss, and how do we prevent, finance, and defend it? | Governing body charter, insurer and captive requirements |
| Quality and performance improvement | Are our processes and outcomes meeting the standard we set? | CMS quality Conditions of Participation, accreditor standards |
| Internal audit | Do the controls actually operate as designed? | Board audit committee |
| Legal | What is our legal position, and what is privileged? | Counsel's professional obligations |
| Privacy and security | Is protected health information appropriately used, disclosed, and safeguarded? | HIPAA Privacy and Security Rules |
Independence is structural, not personal. OIG guidance is explicit that the compliance officer should have direct access to the governing body and the chief executive, and should not be subordinate to the general counsel or the chief financial officer - the functions whose work compliance may need to question. A compliance officer who reports to risk management, or a risk manager who "owns" the compliance plan, breaks the same principle. When a stem offers a reporting-structure change that folds compliance under another department, the risk manager's role is to flag the independence problem to leadership and the board, not to accept the expanded territory.
The consequence of program failure: Corporate Integrity Agreements. A Corporate Integrity Agreement (CIA) is what the OIG typically requires in exchange for not excluding an organization when resolving fraud allegations. CIAs commonly run five years and impose obligations far beyond the seven elements: a designated compliance officer and committee, annual board resolutions certifying that the board reviewed program effectiveness, executive certifications, mandatory training hours, an Independent Review Organization (IRO) performing claims and arrangements reviews, disclosure of reportable events, and stipulated penalties for breach with exclusion available for material breach. The exam framing is simple: a CIA is what a voluntary program turns into after it fails, and it costs vastly more.
Scenario
An internal audit finds that one employed physician's evaluation and management coding has been two levels above peer benchmarks for three years, with documentation that does not support the level billed. Estimated exposure approaches several hundred thousand dollars. The chief executive asks the risk manager to "handle it quietly."
The defensible sequence: the compliance officer leads the investigation, with counsel engaged early so the investigation can be structured for privilege where available; the risk manager preserves records and stops any routine destruction affecting the relevant period; the audit is expanded to determine whether the pattern is individual or systemic; the overpayment is quantified through reasonable diligence, which starts the 60-day analysis; the disclosure pathway is chosen with counsel; corrective action includes documentation education, prospective auditing, and consistent application of the disciplinary framework through the proper medical staff and human resources channels; and the matter is reported to the board's compliance committee. "Handling it quietly" - repaying nothing, disciplining no one, and telling no one - converts a billing error into potential False Claims Act exposure and personal exposure for the executives who buried it. Escalating over the chief executive's preference, in that circumstance, is the correct answer.
Exam Traps
- Risk management owning the compliance plan. Collaborate, contribute data, sit on the committee, and educate - do not take the function.
- Reciting six elements. Candidates most often drop consistent disciplinary enforcement or effective communication.
- Screening only at hire. Exclusion screening is periodic, and the LEIE updates monthly.
- Assuming an excluded person is harmless if they do not bill. The prohibition covers items and services furnished, ordered, or prescribed.
- Treating the 60-day clock as starting at suspicion. It starts at identification, which requires reasonable diligence and quantification - but diligence must be prompt and documented.
- Choosing the disclosure protocol alone. The SDP-versus-SRDP-versus-refund decision is made with counsel, not by the risk manager.
- Believing a hotline equals a program. Without non-retaliation, tracked resolution, and consistent discipline, a hotline is decoration.
Following a reorganization, the chief executive proposes that the compliance officer report to the risk manager and that the risk management department own and maintain the organizational compliance plan, reasoning that both functions review the same events. What is the risk manager's most appropriate response?