Hospitals operate within some of the most complex regulatory environments in healthcare. Each department, staff role, and process is subject to oversight that touches billing, coding, patient safety, and federal program integrity. This post explains how an independent third-party review can strengthen a hospital’s compliance program, bring objectivity, reveal blind spots, and align internal efforts.
Table of contents
- The Case for an Independent Compliance Review
- Corporate Compliance Program Documentation
- Compliance Program Leadership and Oversight
- Training and Education
- Effective Lines of Communication
- Enforcing Standards
- Risk Assessment, Auditing, and Monitoring
- Responding to Detected Offenses
- The Value of an Independent Compliance Review
- A Few Parting Words
The Case for an Independent Compliance Review
From many perspectives, hospitals are among the most involved institutions in the healthcare system. They have a myriad of employee and staff member duties and classifications, many of whom have requirements set by state licensing authorities. Hospitals have extensive facilities, with a great deal of specialized equipment, and utilize many, many types of specialized supplies. They are subject to many complicated provisions of law and regulatory compliance related to billing, coding, and federal healthcare compliance considerations. Hospitals also have a unique group of professionals who enjoy elements of self-government within the institution—the Medical Staff.
It follows then that hospital compliance programs are more complex than those of other healthcare organizations. Now, there are tools a compliance officer managing a hospital compliance program can use to determine whether the institution has an effective program. But it’s also true that we sometimes grade ourselves on a curve, especially when a long-term issue has resisted resolution. This is where a third-party compliance review can help address persistent compliance concerns.
What would a third-party compliance review of an effective hospital compliance program look like? Let’s look at it from the perspective of the seven elements of compliance programs. These are outlined in the Office of Inspector General (OIG) General Compliance Program Guidance issued in 2023.
Corporate Compliance Program Documentation
The foundation of any substantial management system is the written documentation. Policies and procedures, and similar documentation, describing the program’s activities and providing guidance for staff members. High-level compliance program policies and procedures should include:
Compliance Program Leadership and Oversight
OIG settlements with multiple healthcare providers, including hospitals, have consistently emphasized the roles and responsibilities of compliance program leadership and governance. The Compliance Officer should report directly to the CEO and to the organization’s governing body or Board of Directors. The Compliance Officer is the primary person responsible for investigating compliance issues reported from anywhere in the organization. He or she is also responsible for developing, implementing, and managing a custom-tailored compliance program for the institution.
Reports from the Compliance Officer and Compliance Committee should be regular and detailed. They must help the Board understand program activities, findings, and recommendations from monitoring and investigations.
Together, the elements of Board of Directors oversight, CEO interest and direction, and Compliance Officer expertise go a long way to implementing a culture of compliance in the organization.
Training and Education
Engaging training and education are the way a hospital can make a subject like corporate compliance seem at least modestly interesting. And of course, they are an expectation of the OIG in its compliance guidance. Many healthcare organizations make use of third-party training courses covering subjects such as fraud and abuse, corporate compliance, and HIPAA. These programs can do a good job with the generic elements of compliance programs and privacy regulations. They must also include specific information, such as how to report compliance issues and the expectations in the organization’s Code of Conduct.
Beyond the general education provided to all employees, there should be specific training for staff involved in medical coding and billing. Additional training should cover Medicare, Medicaid, and Tricare healthcare programs. The Board should receive periodic education about the compliance obligations of the institution and the methods for meeting those obligations.
From experience, we know managers and supervisors are very busy. They must work hard to keep employees informed about their duties and hospital policies. It is also true that staff members usually pay the most attention to the issues their direct supervisors emphasize. So, reinforcing the existence of a hospital Compliance Program and expectations for employee cooperation is also an integral part of training.
Effective Lines of Communication
Many institutions have implemented hotlines that provide for anonymous reporting of compliance concerns. Hotlines and other reporting systems must be monitored, and follow-up on reports is mandatory. Organizations must also continuously remind staff members about compliance policies, their reporting responsibilities/opportunities, and policies on non-retaliation against reporters.
Enforcing Standards
Enforcing standards sometimes seems straightforward when they relate to conduct on the job, such as harassment or absenteeism. But it can be challenging when mistakes or even misconduct threaten the hospital’s reputation or financial health.
A hospital’s disciplinary policies and Code of Conduct should clearly allow disciplinary action when someone repeats mistakes or worsens problems in identified compliance risk areas. And the policy of non-retaliation should not protect a staff member from the consequences of their own mistakes or misconduct. It certainly will not protect a staff member from a government investigation when potential fraud or false claims are involved!
Risk Assessment, Auditing, and Monitoring
Risk assessment, auditing, and monitoring are some of the most critical activities in an effective hospital Compliance Program. Auditing and monitoring must first focus on the compliance risks identified in the hospital’s Compliance Program. A second source of potential auditing topics is the list of OIG audits in process at all times. Any hospital with a patient service under audit by the OIG should review its own program. It must ensure compliance with regulatory requirements for thorough documentation and accurate billing.
An audit program must have sufficient resources to complete the auditing activities in the annual Compliance Work plan. Some audits may require outside resources like a coding consultant. Others may be completed by Compliance staff or even the department managing the service.
Auditing activities can be divided into two groups: targeted audits and routine monitoring. Targeted audits may focus on previously identified weaknesses. These can include audits of medical necessity and billing accuracy for specific services or conditions. Routine monitoring includes activities like screening new employees, including those with independent contractor relationships, and vendors against the OIG exclusion lists. Another example is ensuring the information system credentials of terminated employees are revoked in a timely manner.
There are also technical issues to address in developing and implementing comprehensive auditing activities. Pay attention to the sample size so that audit results can be extrapolated to the entire universe of the same services. This can be very important when considering requests for recoupment fines.
The progress and completion of audits or routine monitoring should be tracked during Compliance Committee meetings. Results should then be reported to the Board of Directors. And of course, the progress of completing corrective action to address deficiencies should also be reported to the Compliance Committee. Corrective action plans should be specific about the steps, guidelines, and short-term monitoring to ensure the issue is addressed.
Responding to Detected Offenses
A second very important element of an effective hospital compliance program is responding to detected offenses. As anyone who has dealt with Office of Inspector General staff members conducting an investigation, this is when things get real, real fast. While most hospitals will never face such an investigation, it is wise to act as though an OIG attorney may review every action in the future.
Policies should specify the steps to take when an issue rises to the level of an official compliance investigation.
The Value of an Independent Compliance Review
A third-party compliance program review helps leadership understand where the program stands today and what to do next. It validates what is working and isolates gaps that carry the most operational or regulatory risk.
Benefits Include …
| Objectivity and credibility | Independent findings carry weight with boards, executives, and regulators. |
| Focused risk reduction | Reviews translate broad requirements into prioritized, practical fixes. |
| Operational clarity | Clear recommendations help assign ownership, timelines, and measures of success. |
| Better use of resources | Programs stay current with OIG expectations and industry practice. |
| Regulatory alignment | Programs stay current with OIG expectations and industry practice. |
A concise report, an achievable work plan, and follow-up checks give the organization a clear path forward. The goal is a program that works in day-to-day operations and holds up under scrutiny.
A Few Parting Words
At The Fox Group, we help hospitals develop and implement corporate compliance risk mitigation strategies, with over ten years of experience in this area. We routinely conduct effectiveness audits of our clients’ compliance programs to ensure we stay up to date with the latest compliance standards. Most of what I have described above stems from our own experience, including government investigations that required careful responses.
Hospitals can implement comprehensive compliance programs independently. However, having someone experienced who has managed the process many times in different settings can be a great advantage! Think about it if you are considering a third-party compliance review.
