This post takes a closer look at the healthcare compliance annual work plan and its practical role in a compliance program. It draws on hands-on experience advising healthcare organizations on compliance structure and priorities. The goal is to explain why these plans are developed and how they support ongoing compliance efforts.
Executive Summary – Key Takeaways
- Annual work plans convert compliance programs into active risk management.
- Not legally required, yet operationally vital for sustained compliance.
- Seven-element planning clarifies ownership and demonstrates program effectiveness.
- Annual refreshes align policies, training, and audits with emerging risks.
Table of contents
- Healthcare Compliance Annual Work Plan Deserves Closer Attention
- Is a Healthcare Compliance Annual Work Plan Required?
- What should be covered in an Annual Work Plan?
- Other Elements of a Healthcare Compliance Annual Work Plan
- Keeping Annual Work Plans Fresh
- Frequently Asked Questions About The Healthcare Compliance Annual Work Plan
Healthcare Compliance Annual Work Plan Deserves Closer Attention
We have written at length about compliance programs for healthcare providers. We have covered the compliance functions and compliance resources required in, among others:
In all this material, we have usually mentioned the healthcare compliance annual work plan. But we have not described in any great detail what should be covered in such an annual plan or why it should be developed and implemented. Many Compliance Officers are drafting their annual work plans now, so here are some thoughts on why you should create and implement a healthcare compliance annual work plan.
Is a Healthcare Compliance Annual Work Plan Required?
The short answer is “No”. So far, skilled nursing facilities and accountable care organizations are the only healthcare organizations required by law and regulations to have compliance programs. And those regulations, which are pretty short, do not specify the requirements for an annual compliance work plan. The OIG General Compliance Program Guidance from the Federal Government does not explicitly recommend an annual work plan, either. So, with limited resources, why go to the effort of drafting, approving, and implementing an annual healthcare compliance work plan? Actually, there are good reasons.
Compliance programs are, at base, a type of risk management program. At implementation, you develop policies, evaluate risks, train staff, monitor activities for mistakes, and, when necessary, investigate errors or even misconduct. But these kinds of key initiatives can become stale; your efforts can lose momentum as other management imperatives arise to demand attention. Developing and implementing an annual work plan is one way to stave off loss of focus in this important area. It is also a way to assign responsibilities to staff throughout the organization for compliance program efforts.
One goal of a healthcare compliance program is to demonstrate its effectiveness during an investigation by government agencies. So it makes sense to organize your annual work plan along the same seven elements of your corporate compliance program.
What should be covered in an Annual Work Plan?
Here are some suggestions on the content of an annual work plan, organized around the seven elements of compliance programs.
| Policies and Procedures | The policies and procedures provide detailed guidance on compliance programs. They cover topics such as risk areas, oversight responsibilities, the role of the compliance officer, compliance committee composition and duties, and processes for investigating compliance issues. These activities may change over time, so an annual work plan should include a provision to review at least a portion of the policies and procedures each year. |
| Compliance Leadership and Oversight | The governing body, or Board of Directors, of healthcare organizations is ultimately responsible for the organization’s activities and services. Board members can’t fulfill these responsibilities without relevant and timely reports. So quarterly and annual reports should be part of an annual work plan. |
| Training and Education | Compliance training is another integral part of compliance programs. Staff members need to understand their personal responsibility to act ethically and legally, so training on the Code of Conduct is mandatory for all staff. Understanding how to report compliance concerns is another important subject of compliance training. Training in compliance laws like the False Claims Act and Anti-Kickback Statute is also essential. Compliance training as part of the initial employment process is required, as is periodic refresher training. Other special needs training to include in the annual work plan is targeted training for Board members and Medical Staff. All of this training can contribute to a healthy compliance culture in healthcare providers. The Compliance Committee must document completion of this training in its meeting minutes. |
| Effective Lines of Communication | The long list of the many healthcare organizations that have endured OIG investigations includes many where individuals attempted to report compliance concerns internally, but were not heard. So this element addresses that issue. A hotline providing for anonymous reporting is one strategy. Periodic articles on compliance and privacy in internal newsletters are another way to refresh the content staff members may see. An annual plan is the place to document the number and schedule for these communications. |
Other Elements of a Healthcare Compliance Annual Work Plan
| Enforcing Standards and Disciplinary Action | Enforcing standards and administering discipline are by their very nature ad hoc activities. But that does not mean they should be ignored in compliance programs’ annual work plans. Decisions about disciplinary actions are the responsibility of management, but reporting how disciplinary policies are enforced to the Compliance Committee can help keep penalties for similar behavior somewhat uniform. |
| Risk Assessment, Monitoring, and Auditing | Much like periodic review of policies and procedures is an element of an annual work plan, so too is continuous assessment of the compliance risks of a health care organization. For example, new risk areas may emerge as new services are implemented or new relationships with health care professionals are initiated. The annual OIG Work Plan may also point you to an audit topic if the OIG is auditing similar programs as part of its audit projects. |
New regulations may require new audit priorities to monitor progress in compliance with the latest standards. And since most healthcare providers submit claims to government healthcare programs, auditing of patients’ medical records and associated billing records will always be part of an annual work plan. Other reports of routine rules, like checking the OIG exclusion list of prospective new employees or verifying suspension of user credentials of departing employees, can also be part of the annual auditing and monitoring process. Reporting these activities to the Compliance Committee can help the organization track progress throughout the year.
| Responding to Detected Offenses and Developing Corrective Action Initiatives | Investigations into detected or reported offenses is another ad hoc activity. But the annual work plan should at least discuss the possibility of this aspect of compliance programs and establish timelines for the timely reporting of incidents. |
Keeping Annual Work Plans Fresh
For many healthcare organizations, elements of an annual work plan will be the same from year to year. Some aspects that may require new projects in any given year include:
- New policies for new regulations or other new circumstances;
- New training based on new laws; and
- New audits to address new services or previous violations of rules on billing and coding.
Whether things in your part of the healthcare industry have changed a little or a lot from year to year, it is vital to keep up with changes that should influence your next annual work plan.
In our 10+ years of experience providing compliance officer services to several hospitals and other healthcare organizations, we have drafted numerous compliance programs and annual work plans. Sometimes we are asked if one or another element “is really necessary”. For better or worse, the answer is usually “yes, you have to do this to protect your organization”. It was not always embraced with enthusiasm, but professional standards and ethics required nothing less!
Frequently Asked Questions About The Healthcare Compliance Annual Work Plan
No single federal rule requires every healthcare organization to maintain a standalone annual compliance work plan.
Certain organizations have related mandatory obligations. Skilled nursing facilities must maintain a compliance and ethics program and review it annually. Medicare Shared Savings Program ACOs must maintain and periodically update a compliance plan. For other organizations, OIG guidance is voluntary, but it recommends annual risk assessments and development of a risk-based compliance work plan.
Work-plan priorities should follow a documented risk assessment rather than a recycled checklist or the OIG Work Plan alone.
Organizations should evaluate internal information such as audit findings, claims denials, hotline reports, investigations, and service changes. External inputs may include regulatory developments, enforcement actions, and relevant OIG projects. The highest-priority risks should receive defined auditing, monitoring, training, policy, or corrective-action activities based on available resources.
The compliance officer should coordinate the plan, while the Compliance Committee and governing body provide structured oversight.
OIG recommends that the Compliance Committee help conduct the risk assessment, prioritize resources, and develop the work plan with the compliance officer. The governing body should receive regular reports, evaluate whether compliance has sufficient authority and resources, and meet with the compliance officer at least quarterly.
The work plan should be formally reassessed annually and revised whenever a material new risk emerges.
Midyear changes may be warranted after new regulations, enforcement actions, audits, investigations, acquisitions, service launches, or significant operational changes. OIG’s own Work Plan changes as projects and priorities evolve, reinforcing that an organizational compliance work plan should remain responsive rather than fixed for twelve months.
Each work-plan item should identify the risk, responsible owner, planned action, timeline, reporting path, and evidence of completion.
Documentation should also capture findings, corrective actions, follow-up testing, and resulting policy, training, or control changes. This creates a traceable record showing not only that activities occurred, but whether controls worked, identified problems were remediated, and lessons learned were incorporated into the compliance program.
