Signs Your Hospital Compliance Program is Ineffective

Healthcare organizations often assume their compliance programs are effective because nothing has gone wrong. In our experience working with hospitals, health systems, and…

Read More

Jim Hook, MPH

By Jim Hook, MPH | June 24, 2026

Iceberg showing hidden risk beneath the surface, representing signs of an ineffective hospital compliance program.

Healthcare organizations often assume their compliance programs are effective because nothing has gone wrong. In our experience working with hospitals, health systems, and other provider organizations, that assumption is one of the most common and most dangerous signals of underlying risk.

When Everything Seems Fine—Until It Isn’t

You may be cruising along, comfortable with how your healthcare compliance program is being managed. You are not hearing from any government agencies, and no government investigations are in the offing. You aren’t receiving letters from attorneys representing alleged whistleblowers.

The Board of Directors seems satisfied with the reports from the Compliance Officer, even if they are sometimes a little behind. No one is coming forward with complaints about all of the HIPAA and compliance training that takes up staff time.

Senior management and the governing bodies of several hospitals and other healthcare providers probably felt the same way, right up until the proverbial other shoe landed in their collective laps.

Suddenly, there was an urgent need to take a good look at their compliance program. They had to ask whether they really have an effective compliance program.

Why don’t we take a look at potential warning signs that you may have compliance issues waiting to bite you where it hurts—in the bank account.

There are many potential sources of compliance failures. To make this manageable, let’s look at them through the lens of the seven elements of a compliance program.

1. Effective Compliance Policies and Procedures

A lack of up-to-date, relevant documentation for your compliance program can lead to ineffective compliance practices. Policies and procedures are the tools healthcare organizations use to keep compliance efforts organized and focused. Changes in state or federal laws and regulations need to be reflected in compliance policies and procedures as soon as they are effective.

2. Effective Compliance Leadership and Oversight 

The Board’s Role in Compliance Oversight

Compliance leadership starts with the governing body or Board of Directors. The role of the Board is firmly established in compliance guidance. In many instances, when a report of potential issues related to investigations begins to arise, a common question is: “Where was the Board of Directors?”

Boards have responsibilities to both inquire about investigations and other compliance risk issues, and to keep themselves educated on healthcare compliance issues. Incomplete reports and the Board’s disinterest in education aimed at keeping them informed on their roles and responsibilities are signs of ineffective compliance leadership.

The Compliance Officer Function

The Compliance Officer is the key person in all compliance efforts. We have seen instances where the role of Compliance Officer was a collateral duty of another management or staff position. When push came to shove, the compliance duties took a back seat.

In other circumstances, a new Compliance Officer overstated compliance requirements involving claims to federal healthcare programs. The Board was receiving the impression the Medicare program would soon be asking for return of most the payments the hospital had received in the past year. In both cases, Hospital management replaced the compliance officer with an outsourced program post-haste

The Role of the Compliance Committee

Compliance committees can also be a source of reduced effectiveness of compliance efforts. Most compliance committees consist of senior managers of the operations, financial management, billing, and human resources professionals in an organization. This can be useful when potential issues need management intervention.

Signs of ineffectiveness include issues that go unresolved for months or meetings that are poorly attended. An active and responsive compliance committee is another key lynch pin of an effective compliance program.

3. Compliance Training and Education

It’s fair to say that many, if not most, compliance training programs are not edge-of-the-seat productions. Nevertheless, they are an important element of an effective program. One test of the effectiveness of your training program is the number of employees who say they never heard of the training they underwent with respect to compliance issues when an investigation is in progress. This is also a frequent response to HIPAA training, too. Lack of reports from employees about activities or policies they consider questionable is a sign your training program is not getting the job done.

4. Effective Lines of Communication

Many healthcare organizations maintain anonymous methods of reporting compliance concerns, like hotlines. These can be an effective method of receiving information about a host of issues, including patient safety, patient privacy, and quality care, in addition to compliance concerns. So a lack of reporting of any issues may indicate this reporting tool needs new emphasis or retooling altogether. We should all keep in mind that many of the largest investigations and settlements pursued by the Office of the Inspector General (OIG) were preceded by internal reports of potential wrongdoing. Those reports were often ignored or suppressed.

5. Enforcing Standards

Enforcing standards is another area where ineffectiveness can creep in. One key to enforcing standards is to do it fairly and proportionately. At-risk behavior, as opposed to mistakes due to ignorance, should be treated similarly across an institution. Employees will eventually find out about disciplinary actions taken against their fellow staff members. Try not to make such actions too different for similar offenses. And HIPAA violations are another area where consistency of sanctions is important. In our experience, employee compliance violations are infrequent. Employee HIPAA violations can be a weekly occurrence.

6. Risk Assessment, Auditing, and Monitoring

Important elements of a compliance program that may change over time include compliance risks. For instance, when healthcare providers begin a new service, it is highly advisable to add the service to the list of services that are subject to internal audit during the first year of the service or program. This helps healthcare entities ensure they are documenting clinical information properly and completing billing records with correct coding. 

Other specific risk areas for healthcare organizations that are “designated health services,” as defined in the Stark Rules, include physician contracts and other medical staff relationships. The risks in this area may morph over time as relationships change.

For instance, converting physicians from independent contractors to employees requires careful planning to avoid running afoul of Stark and the Anti-Kickback Statute.

An annual compliance work plan that rarely changes is another potential source of red flags. While many factors influencing compliance risks are the same year in and year out, new regulations, operations, and even legal action are sources of updates for risk areas. Lack of updates to this area can easily lead to a program that lacks relevance and integrity.

Auditing and monitoring are often what people think about when they think about compliance. And audits are an important part of the guidance from the OIG. Audits that do not assess the most significant compliance risks can be a sign of an ineffective program.

Accurate financial data is crucial to any system seeking to protect itself from financial consequences of non-compliance, and other consequences like reputational harm. Just ask the healthcare systems that are subject to Corporate Integrity Agreements or even legal action to exclude them from federal healthcare programs!

7. Responding to Detected Offenses and Developing Corrective Action Initiatives

Finally, we get to investigations and corrective action plans. In our experience, willful misconduct or fraudulent behavior has been rare. But investigations and corrective action plans are also needed when the mistakes are unintentional or not motivated by private interests. Recurring compliance failures to observe healthcare regulations requiring frequent investigations are a sure sign of an ineffective compliance program.

We have written previously about a “Culture of Compliance” in healthcare organizations. Leadership at all levels is needed to convince staff members across all departments that the organization values the principle of “Do the right thing, always”. Living by that principle can go a long way to avoiding compliance failures and catastrophes.