Healthcare Compliance Auditing and Monitoring Strategies

Healthcare compliance auditing and monitoring are essential components of an effective compliance program, but they are often misunderstood or treated as interchangeable functions….

Read More

Jim Hook, MPH

By Jim Hook, MPH | September 4, 2026

Healthcare compliance and auditing workspace with operational dashboards, policy documentation, and governance reporting in a modern healthcare administrative environment.

Healthcare compliance auditing and monitoring are essential components of an effective compliance program, but they are often misunderstood or treated as interchangeable functions. Drawing on years of experience supporting hospitals and healthcare organizations with compliance, privacy, and operational oversight, this article examines how auditing and monitoring serve different purposes. It also explores where each is most effective and how organizations can apply both to reduce regulatory and operational risk.

Understanding the Role of Auditing and Monitoring in Healthcare Compliance

When the topic of a healthcare compliance program comes up in healthcare organizations, many people often think about healthcare compliance audits. They may view auditing as the sum and substance of a healthcare compliance program. Of course, ongoing compliance auditing is an important component of an effective healthcare compliance program. However, it is by no means the full extent of a program based on the seven elements espoused by the Office of Inspector General (OIG) in the U.S. Department of Health and Human Services (HHS).

Nevertheless, auditing and its first cousin, Monitoring, are important elements, along with the identification of risk areas. These activities play an important role in evaluating whether processes are functioning properly, identifying areas of non-compliance, and reducing operational and regulatory risk across healthcare organizations.

So what do these activities contribute to the effectiveness of a compliance program, and how do these principles apply across other functions in a complex healthcare organization?

Auditing vs. Monitoring

Auditing and monitoring are similar, but with significant differences:

  • Auditing can be defined as …
    • A formal, typically retrospective, review process used to determine whether a specific process is working properly and effectively. It may be undertaken internally within a department or conducted by an outside evaluator.
    • Results are reported to senior management and to the organization’s Compliance Committee. Follow-up may include corrective action plans, repayments to government or private payors, and disciplinary actions for staff members.
  • Monitoring can be defined as …
    • A concurrent, or nearly concurrent, review of an important process to ensure there are no mistakes or variations from expected outcomes. Monitoring processes may be carried out within a department or business unit.
    • Reporting may be directed to more senior managers and, for certain processes, to the organization’s Compliance Committee. Lack of compliance may be addressed through corrective action plans and disciplinary actions.

So, when should organizations spend the time and organizational energy on continuous monitoring processes vs. retrospective audits? One approach is to evaluate the activities identified during the risk assessment portion of the compliance program. Organizations should also consider how quickly subpar performance in a specific risk area could create operational or regulatory consequences.

Compliance Program Risk Areas to Audit

Claims to government healthcare programs

Most healthcare organizations provide services to patients or clients who are covered by federal and/or state healthcare programs such as Medicare, Medicaid, and Tricare. Billing for these services is a significant compliance risk for healthcare organizations. These activities are governed by extensive regulatory requirements for documentation, diagnosis coding, and procedure coding.

Auditing for these claims may include medical record documentation review, diagnosis coding review, and procedure coding review. While accuracy from the start of the billing process is highly desirable, mistakes in coding and billing can still occur. Healthcare organizations can mitigate these risks by resubmitting claims with mistakes as soon as they are identified.

Other risk areas

Other risks that are related to claims to government healthcare programs include: duplicate billing, unbundling charges, billing for services not rendered, and submitting false claims. Compliance audits of claims can provide insights into other areas subject to various regulatory requirements.

  • For instance, hospitals with financial arrangements with referring physicians may want to incorporate an auditing process for payments to those physicians. This can help ensure payments are being made in accordance with the signed contract covering the services and compensation.
  • Home Health agencies may want to audit for documentation of face-to-face visits between patients and physicians.
  • Hospice programs may want to audit for refunds for cases exceeding the inpatient and outpatient caps on reimbursement.
  • Hospitals may want to audit patient status with respect to the 2-midnight rule on reimbursement, and the issuance of Advance Beneficiary Notices to Medicare patients. Other risk areas include Good Faith Estimates, No Surprises Billing, and Financial Assistance Policy implementation.

Compliance Program Risk Areas to Monitor

There are several types of review activities that should be covered by ongoing monitoring programs that are also governed by regulatory requirements. These include:

  • Screening of staff members against the OIG List of Excluded Individuals and Entities. Ongoing monitoring is indicated because the penalties for employing an excluded individual or an excluded entity are severe. And this type of monitoring can be integrated into the onboarding process for new staff members and the contracting process for vendors.
  • Contracts with physicians providing services to any of the ten designated health services, as defined in the Stark Laws. Again, because of the severe penalties for Stark Law violations, careful monitoring of contracts is important. Monitoring can help ensure all required elements are present. This helps establish an exception to the prohibitions on financial arrangements with physicians.
  • Employee access to Electronic Health Records. The processes for adding new users and revoking access for users who no longer need access to EHR systems are another example of an important monitoring program. These processes are particularly important for organizations that maintain EHR systems. There are many examples of HIPAA breaches involving staff members who were no longer with a healthcare organization, but still had access to an EHR system. Such breaches can leave organizations open to penalties and audits by the Office for Civil Rights (OCR).
  • Staff member training in HIPAA and Compliance Programs. Staff member training is a requirement in the HIPAA Privacy and HIPAA Security Rules, as well as one of the seven elements of an effective Compliance Program. Scheduling training for new staff members and annual refresher training for existing staff members is an ongoing process. It is also a challenge for healthcare organizations across the industry. But it is a source of non-compliance for many organizations when the OCR comes for an audit. So, including it in routine monitoring programs reporting to the Compliance Committee can help management keep it visible.

Building an Effective Healthcare Compliance Program

After over ten years of providing the services of a compliance officer and privacy officer, we have seen many different approaches to compliance programs and privacy programs. This experience has included work with multiple hospitals and other healthcare industry organizations. The most effective programs consistently enjoyed the support of senior management, who set the tone for auditing and monitoring, training, ethical standards, and accountability.

Auditing and monitoring can sometimes seem onerous and troublesome. However, healthcare organizations operate in an environment with significant regulatory standards and penalties for violations. In that environment, ongoing auditing and continuous monitoring are small burdens to bear to avoid monetary penalties and soiled reputations.

These same principles can also be applied across other organizational functions to support accountability, operational consistency, and continuous improvement.