Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

Understanding the Seven Core Elements of an Effective Healthcare Compliance Program

Client Alert

The Patient Protection and Affordable Care Act (“ACA”) mandates that medical providers, as a condition of enrollment in Medicare, Medicaid, and the Children’s Health Insurance Program (“CHIP”), establish a compliance program.[1] The ACA also stipulates that the Department of Health and Human Services (“HHS”) and the Office of Inspector General (“OIG”) shall establish the core elements of a required compliance program.

There are seven main elements of an effective compliance program laid out by the HHS and OIG in the General Compliance Program Guidance (“GCPG”).

1. Written Policies and Procedures

Compliance requires all employees to understand their roles and responsibilities within the practice. Having written policies, such as a code of conduct, documentation requirements, and the processes to maintain compliance with Federal and State laws, allows expectations to be clearly communicated.    

The OIG recommends that written policies be easily accessible and comprehensible for individuals to refer to. In addition, policies should be kept up-to-date and revised when applicable laws change. Procedures on billing, coding, sales and marketing, quality of care, patient incentives, and arrangements with other healthcare providers should be included within written policies.      

2. Compliance Leadership and Oversight

The OIG states that “boards and senior leadership are vital to effective compliance programs,” especially when working to create a culture of compliance within a company.

Best practices for creating effective compliance oversight are appointing a compliance officer who has the authority and resources to ensure the success of a compliance program, as well as a compliance committee that supports the compliance officer.

3. Training and Education

Entities should have education and training programs for compliance, focusing on risk areas for the company or any issues discovered in an audit. These areas can range from billing and coding to interactions with other physicians.

Some topics the OIG recommends for employee training are the commitment to complying with Federal and State laws, the identity and role of the compliance officer, the importance of open communication with the compliance officer, and the various ways individuals can raise compliance questions and concerns with the compliance officer.

4. Effective Lines of Communication with the Compliance Officer and Disclosure Programs

Effective compliance programs encourage communication between employees, the board, and the compliance officer.

Best practices for creating effective lines of communication are informing staff about how and when the compliance officer can be reached directly and encouraging staff to bring any compliance questions to the compliance officer as soon as possible.  

In addition to making communication a priority, entities should create confidentiality and non-retaliation policies and implement an anonymous reporting option to encourage quick reporting. The OIG recommends logging all communication surrounding disclosure of compliance concerns or violations.    

5. Enforcing Standards: Consequences and Incentives

Both consequences and incentives are important for compliance program enforcement. Consequences for non-compliance can either be educational when a staff member was neglectful or can include sanctions if a staff member intentionally committed a compliance violation.

The OIG recommends that incentives be given for excellent compliance performance or contribution to the compliance program. Incentives can include additional compensation, significant recognition, or forms of encouragement.  

6. Risk Assessment, Auditing, and Monitoring

Risk assessments and audits allow for an entity to understand its compliance risk. Creating a plan for a risk assessment, conducting an internal audit, and utilizing data analytics allows for compliance efforts to be directed at areas where a company is most vulnerable to violations.

The OIG recommends that in addition to risk assessments, entities should monitor legal and regulatory changes to determine new areas of compliance risk. In addition, entities should maintain routine monitoring of ongoing risks, such as regular screening of State licensure certification databases.

7. Responding to Detected Offenses and Developing Corrective Initiatives

Compliance programs are designed to encourage compliance and detect areas of improvement. When areas of improvement are identified or a violation occurs, it is vital that entities have policies in place to respond to the concerns and take corrective action.  

Best practices are investigating all violations to determine what type of reporting or corrective action is required. In addition, the OIG recommends evaluating whether to engage outside counsel during the investigation. Counsel can help determine what reporting measures to take and what corrective action is needed. A thorough record of every violation investigation should be maintained.        

Implementing OIG Guidance

While the OIG considers the seven core components as essential for an effective compliance program, the OIG also recognizes that not every healthcare practice is the same. Entities may take different measures to accomplish each of the core elements. In addition, compliance programs may be adapted to fit a practice’s specific needs and can be adjusted based on the size of the practice. As such, the OIG also discusses compliance program adaptations for small and large entities in the GCPG and has published separate guidance for individual and small group physician practices.    

Developing or updating a compliance plan that mitigates risk for your practice is vital. We recommend engaging an attorney to draft or review your compliance program to ensure that it satisfies the OIG guidance and aligns with complex and changing healthcare regulations.

To learn more about the HHS-OIG General Compliance Program Guidance and how to develop a compliance plan for your practice, please contact BMD Health Law Group Member Jeana Singleton at jmsingleton@bmdllc.com or 330-253-2001.     

[1] Patient Protection and Affordable Care Act, Section 6401(a)(7).  


FinCEN Residential Real Estate Reporting Rule Now in Effect

FinCEN’s new Residential Real Estate Reporting Rule, effective March 1, 2026, requires certain real estate transfers to be reported to combat financial crimes. Transfers of residential property to entities or trusts without financing may require a Real Estate Report.

Department of Education Proposes Redefinition of “Professional Degree,” Excluding Nursing and Limiting Graduate Loan Borrowing

The U.S. Department of Education has issued a Notice of Proposed Rulemaking that would redefine “professional degree” programs under the One Big Beautiful Bill Act. The proposal excludes nursing from the recognized list and would impose new borrowing limits for graduate students while eliminating the Grad PLUS program. Public comments are due by March 2, 2026.

First-of-Its-Kind Federal Ruling Finds Use of Consumer AI Tool May Destroy Attorney-Client Privilege

On February 10, 2026, Judge Jed Rakoff of the U.S. District Court for the Southern District of New York issued a first-of-its-kind ruling finding that documents generated by a criminal defendant using a consumer AI platform were not protected by attorney-client privilege after being shared with counsel. The court treated the AI tool as a third party, concluding that entering sensitive information into a publicly available platform may waive confidentiality. The ruling also suggests that the work product doctrine may not apply where AI-generated materials are created independently by a client rather than at counsel’s direction. The decision signals that parties should exercise caution when using consumer AI tools in connection with legal matters.

Your Golden Chance for H-1B Lottery Registration - March 2026

USCIS H-1B registration opens March 4–19, 2026. U.S.-based employees on valid nonimmigrant status are exempt from the $100,000 fee for change of status petitions. The new weighted lottery favors higher-skilled and higher-paid employees, improving odds for advanced degree holders and Wage Level 3 or 4 workers.

Invisible Algorithms: The Hidden Role of Artificial Intelligence in USCIS Immigration Processing

The Department of Homeland Security has confirmed that artificial intelligence and machine learning tools are now integrated into numerous operational functions within U.S. Citizenship and Immigration Services (USCIS). These tools are described as mechanisms to improve efficiency, reduce backlogs, and assist officers in managing an unprecedented volume of applications. DHS emphasizes that human adjudicators retain decision-making authority and that AI systems do not independently grant or deny immigration benefits. Find out how AI affects the U.S. immigration process.