Compliance program
A compliance program is the formal system of written standards, oversight, training, communication, auditing, enforcement, and correction an organization uses to prevent, detect, and address violations of the law and of payer and program requirements. In health care, the HHS Office of Inspector General describes an effective compliance program in terms of seven elements and offers it as voluntary guidance rather than a mandate.
Updated
A compliance program is an organized set of internal controls — written standards and a code of conduct, designated oversight, training, channels to raise and report concerns, auditing and monitoring, consistent enforcement, and a process for responding to and correcting problems — that an organization maintains to prevent and detect violations of the law and of payer and program requirements.
In health care, the HHS Office of Inspector General (OIG) has published compliance program guidance describing the elements of an effective program. OIG frames these programs as voluntary and nonbinding — it uses the word "should" rather than "must" — while treating a program built around the seven elements as the standard against which an organization's conduct is measured.
In practice
For a billing operation, a compliance program is what turns scattered good habits — checking a claim before it goes out, keeping a HIPAA policy, training new hires — into a documented, defensible system. Its purpose is early detection: catching a coding error, an unsupported charge, or an improper arrangement while it is still a correction, before it becomes a repaid overpayment or an enforcement matter.
OIG says a program should be right-sized to the organization. A small practice can meet the same elements with a single compliance contact and scaled procedures rather than a dedicated department, and can begin with the components most likely to provide an identifiable benefit given its own history.
Commonly confused with
- Corporate integrity agreement: A corporate integrity agreement (CIA) is a set of compliance obligations OIG imposes on an organization as a condition of settling a fraud case. A compliance program is the voluntary system an organization builds on its own; a CIA is compulsory and externally monitored.
- The HIPAA rules: The HIPAA Privacy, Security, and Breach Notification Rules are specific legal requirements. A compliance program is the broader management system through which a practice meets those rules — and many others, including the fraud-and-abuse laws — rather than a rule in itself.
