This is the first in a series examining each of the seven elements of an effective health care compliance program, as described in OIG's General Compliance Program Guidance. An overview of all seven is available in our earlier post on the essential elements of an effective health care compliance program.
Providers usually ask first whether any of this is required. The answer depends on who you are. For most providers, OIG frames its compliance program guidance as voluntary, and no general federal rule requires a physician practice to maintain a compliance program. For others it is mandatory and surveyable. Nursing facilities must maintain a compliance and ethics program under 42 C.F.R. § 483.85, with required elements scaled by organization size and training obligations under § 483.95(f), and surveyors have been able to cite failures since November 2019. Medicare Advantage organizations and Part D sponsors operate under their own CMS compliance program requirements.
The distinction matters less than it appears. Voluntary or not, the government's assessment of your conduct after something goes wrong will turn substantially on what your program looked like before. A provider without written policies has no way to show that the conduct at issue departed from anything.
The core set. Most providers, regardless of size, need a defined group of policies: a compliance program policy describing the program itself; a code of conduct; exclusion screening; licensure verification and tracking; claims submission and correction; refunds of overpayments to federal programs; copayment waivers; sliding scale and uninsured discounts; relationships with referral sources; HIPAA privacy and security; clinical documentation standards; and record retention.
That list is a floor. Scope varies with organization size, services offered, licensure type, and payer enrollment. A Medicare-certified provider carries additional obligations flowing from the applicable Conditions of Participation or Conditions for Coverage, and those conditions frequently require many specific written policies. An ambulatory surgery center, a home health agency, and a hospice each have distinct policy obligations that no off-the-shelf compliance plan fully covers.
The code of conduct is a separate instrument. It is the shorter, plainer statement of expectations that every workforce member reads and acknowledges, signed by the board and chief executive. Policies tell people how to do specific things. The code tells them what the organization expects when no policy is on point.
Compliance policies also reach further than the compliance department. Exclusion screening is a hiring and credentialing function. Non-retaliation is an employment policy with False Claims Act consequences. Training attendance is an HR record. Workplace safety obligations under OSHA sit alongside patient safety obligations. A full set of policies and procedures will depend on the provider type, size, geographic reach, and size of an organization.
Policies should be reviewed regularly and updated as needed. A policy referencing a superseded regulation, a discontinued service line, or with outdated contact information are tells that the policy has not been reviewed. Review on a defined cycle, date each version, and keep the prior versions.
Closing Thoughts
- Start from your actual risk profile, not a purchased manual. The services you furnish, your licensure, and your payer enrollments determine which policies you need; a generic set will be simultaneously too long and missing what matters to you.
- Keep the code of conduct separate from your policies, keep it short enough that people read it, and get a signed acknowledgment from every workforce member.
- Version and date everything, review on a fixed cycle, and retain superseded versions. In an investigation, the question is what your policy required on the date of the conduct.
Kaufman & Canoles' Health Care Practice Group represents health care providers in compliance, regulatory, and transactional matters, with experience working with all types of healthcare organizations. Please reach out to Colin McCarthy or any member of the Health Care Practice Group with any questions.
- Of Counsel
Colin McCarthy is a healthcare regulatory attorney with more than 15 years of experience advising healthcare providers on compliance, reimbursement, and operational matters. Based in Richmond, Virginia, he advises clients ...