OIG Compliance Program Guidance and Annual Work Plans

Key Takeaways

  • The Office of Inspector General (OIG) established Seven Core Elements of an effective compliance program that serve as the industry standard for healthcare risk management and auditing.
  • OIG Compliance Program Guidance (CPG) documents provide voluntary, tailored frameworks for specific healthcare industry sectors including physician practices, hospitals, and billing companies.
  • The OIG Work Plan is updated monthly and details active and prospective audit, evaluation, and investigative targets that medical auditors must integrate into internal risk assessments.
  • Corporate Integrity Agreements (CIAs) are mandatory compliance obligations imposed by the OIG on providers settling fraud investigations, requiring independent review organization (IRO) audits.
Last updated: July 2026

OIG Compliance Program Guidance and Annual Work Plans

The Office of Inspector General (OIG) of the U.S. Department of Health and Human Services (HHS) plays a pivotal role in establishing compliance standards and conducting oversight of federal healthcare programs. For Certified Professional Medical Auditors (CPMAs), OIG guidance documents and publications provide the benchmark for designing internal audit scopes, evaluating compliance effectiveness, and identifying high-risk coding and billing areas. This section examines the OIG's foundational Seven Core Elements of an effective compliance program, sector-specific Compliance Program Guidance (CPG) documents, the dynamic monthly OIG Work Plan, and Corporate Integrity Agreements (CIAs).


1. The Seven Core Elements of an Effective Compliance Program

In 1991, the United States Sentencing Commission established the Federal Sentencing Guidelines for Organizations, which provided sentencing mitigation for corporations that maintained effective compliance programs. Drawing from these guidelines, the OIG synthesized Seven Core Elements that serve as the universal standard for healthcare compliance and auditing programs regardless of organization size.

Detailed Breakdown of the Seven Core Elements:

  1. Implementing Written Policies, Procedures, and Standards of Conduct:

    • The foundation of compliance. Includes a formal Code of Conduct establishing organizational commitment to ethical standards and federal healthcare laws.
    • Requires detailed written operational policies covering CPT/HCPCS/ICD-10 coding accuracy, documentation integrity, claim submission protocols, and overpayment processing.
  2. Designating a Compliance Officer and Compliance Committee:

    • The Compliance Officer (CO) must possess direct authority and an independent reporting line to the Board of Directors or Chief Executive Officer, operating independently of legal counsel and financial billing management to avoid conflicts of interest.
    • The Compliance Committee assists the CO in advising management, assessing operational risk, and allocating resources.
  3. Conducting Effective Training and Education:

    • Mandates initial compliance training upon hire and mandatory annual refresher training for all employees, clinical staff, and contractors.
    • Requires specialized training tailored to job roles, such as documentation and coding rules for providers and medical coders.
  4. Developing Effective Lines of Communication (Hotline):

    • Requires accessible, confidential, and anonymous reporting mechanisms (such as a 24/7 compliance hotline) for employees to report suspected non-compliance or fraud.
    • Enforces a strict, written non-retaliation and non-retribution policy protecting whistleblowers who report concerns in good faith.
  5. Conducting Internal Monitoring and Auditing:

    • Mandates ongoing risk assessments, baseline audits, and periodic retrospective/prospective coding and documentation audits.
    • Medical auditors use objective data analytics and random sampling to evaluate claim accuracy, coding compliance, and medical necessity.
  6. Enforcing Standards Through Well-Publicized Disciplinary Guidelines:

    • Ensures consistent, fair, and documented disciplinary consequences for compliance violations, ranging from retraining and written warnings to suspension or employment termination.
    • Applies disciplinary standards uniformly across all organizational levels, regardless of clinical revenue generation.
  7. Responding Promptly to Detected Offenses and Developing Corrective Action Plans:

    • When auditing or monitoring identifies potential non-compliance, the organization must immediately initiate an internal investigation.
    • Requires root cause analysis, implementation of corrective action plans (CAPs), retraining, policy revisions, and reporting and returning identified overpayments within the statutory 60-day window.

2. OIG Compliance Program Guidance (CPG) Documents

Beginning in 1998, the OIG developed sector-specific Compliance Program Guidance (CPG) documents to assist healthcare entities in tailoring the Seven Core Elements to their operational structures.

Key CPG Industry Sectors:

  • Individual and Small Group Physician Practices (2000)
  • Third-Party Medical Billing Companies (1998)
  • Hospitals (1998) and Supplemental Hospital Guidance (2005)
  • Clinical Laboratories (1998)
  • Nursing Facilities (2000) and Supplemental Guidance (2008)
  • Home Health Agencies (1999)
  • General Compliance Program Guidance (GCPG - Issued November 2023)

Guidance for Individual and Small Group Physician Practices

The OIG recognized that small physician practices lack the resources of large hospital networks. Consequently, the Physician CPG emphasizes a flexible, step-by-step approach focused on four primary risk areas:

  1. Improper Coding and Billing: Upcoding, unbundling, billing for services not rendered, double billing, and improper use of modifiers (especially Modifier -25 and Modifier -59).
  2. Reasonable and Necessary Services: Billing for services that fail to meet Medicare coverage criteria or lack documented medical necessity.
  3. Documentation Standards: Inadequate, incomplete, or illegible clinical documentation; copy-paste cloned documentation in EHR systems.
  4. Improper Financial Relationships: Anti-Kickback Statute and Stark Law violations involving medical directorships, equipment leases, or free services.

3. The OIG Work Plan and Its Role in Audit Planning

The OIG Work Plan details the active, prospective, and recently completed audit, evaluation, and investigative projects conducted by the OIG's Office of Audit Services and Office of Evaluation and Inspections.

Evolution to Monthly Web Updates

Historically published as a static annual book every October, the OIG transitioned in 2017 to a dynamic monthly web update model. New audit projects are added throughout the year as emerging risk areas are identified, while completed reports are posted continuously.

Utilizing the Work Plan in Medical Auditing

Medical auditors must review the OIG Work Plan monthly to align internal risk assessments and annual audit schedules with federal oversight priorities. Common Work Plan audit targets include:

  • Modifier -25 Usage: Evaluation and Management (E/M) services billed on the same day as a minor surgical procedure.
  • Telehealth Services: Documentation and billing compliance for remote patient monitoring and audio-only visits under Medicare Part B.
  • Split/Shared E/M Visits: Evaluation of billing rules for services performed jointly by physicians and Non-Physician Practitioners (NPPs) in facility settings.
  • Inpatient vs. Outpatient Status: Compliance with the Medicare Two-Midnight Rule for short-stay hospital admissions.
  • High-Risk Medical Equipment & Therapy: Hyperbaric oxygen therapy, custom orthotics, and specialty DME claims.

Auditor Workflow: When the OIG adds a new topic to the Work Plan (e.g., "Audit of Medicare Part B Claims for High-Risk E/M Services"), the medical auditor should immediately pull internal billing data for those CPT codes, assess organizational utilization rates against national benchmarks, and conduct a targeted probe audit.


4. Corporate Integrity Agreements (CIAs) and IRO Reviews

When a healthcare provider settles a civil fraud investigation under the False Claims Act, the OIG typically requires the provider to enter into a Corporate Integrity Agreement (CIA) in exchange for not exercising administrative exclusion authority.

Key Features of a CIA:

  • Duration: Typically five years.
  • Mandates: Requires establishing a formal compliance program adhering to strict OIG standards, designating a Compliance Officer, conducting mandatory employee training, establishing a hotline, and submitting annual compliance reports to the OIG.
  • Independent Review Organization (IRO): The provider must retain an independent external auditing entity—known as an Independent Review Organization (IRO)—to perform annual independent reviews.

Role of the Medical Auditor as an IRO

When acting as or working for an IRO under a CIA, the CPMA performs two main types of reviews:

  1. Claims Reviews: Involves statistical sampling (often unweighted random sampling via RAT-STAT) of submitted claims to determine coding, documentation, and medical necessity error rates. If the error rate exceeds a specified threshold (e.g., 5%), expanded sampling and financial overpayment extrapolation may be triggered under the CIA terms.
  2. System Reviews: Evaluates operational processes, billing software rules, and compliance controls governing specific risk areas.
Test Your Knowledge

An internal medical auditor is establishing a baseline audit plan for a 15-physician multispecialty group. Which operational activity directly fulfills Element 5 (Internal Monitoring and Auditing) of the OIG Seven Core Elements?

A
B
C
D
Test Your Knowledge

A CPMA reviews the latest monthly update of the OIG Work Plan and notes a new focus on Medicare Part B payments for split/shared Evaluation and Management (E/M) visits in hospital outpatient departments. What is the auditor's most appropriate immediate action?

A
B
C
D
Test Your Knowledge

A regional medical center entered into a 5-year Corporate Integrity Agreement (CIA) with the HHS-OIG following a civil False Claims Act settlement. The hospital hires an independent CPMA firm to serve as its Independent Review Organization (IRO). What is a primary statutory responsibility of the IRO during the CIA term?

A
B
C
D
Test Your Knowledge

A clinical staff member reports to the compliance officer that a surgeon is routinely cloning EHR progress notes across multiple patient encounters. The compliance officer records the complaint but takes no action to investigate, audit, or correct the billing. Which element of the OIG compliance framework was breached?

A
B
C
D