Developing, implementing, and continuing an effective compliance program over the long term can be daunting for healthcare organizations. Small hospitals and individual physician practices usually have their hands full, focusing on quality clinical care and financial management in turbulent environments. Larger healthcare providers sometimes suffer from organizational inertia; they start fast but struggle to maintain the intensity of effort over the long term. And, of course, they have their own turbulent environments to deal with.
The insights that follow aren’t just theoretical — they’re drawn from years of hands-on experience helping hospitals and other healthcare organizations build and sustain real-world compliance programs.
Table of contents
The Office of Inspector General (OIG) of the Department of Health and Human Services (HHS) issued its General Compliance Program Guidance in November 2023. This compliance guidance consolidated the OIG’s guidance issued over several years, beginning in 1992. The compliance guidance is comprehensive, which means that, like many other issues, some things are emphasized more than others from organization to organization.
Let’s take a look at what our experience tells us about parts of a compliance and ethics program that sometimes get overlooked. It may be rare that entire compliance program elements are overlooked, so we will focus on issues that come up within each of the seven elements of an effective compliance program.
Written Compliance Policies and Procedures – The Code of Conduct
One of the compliance challenges that many healthcare entities face when they try to write and implement a Code of Conduct is the issue of gifts and business courtesies from vendors and even patients.
- Some patients want to recognize the efforts of individual members of the patient care team with gifts, such as gift cards or even cash. Organizations of healthcare professionals typically adopt policies that strongly discourage their members from accepting individual gifts from patients or family members. Of course, gifts like food or candy that can be shared with other staff members may be acceptable. Even for these gifts, limits on the value of such gifts, e.g., not exceeding $50, should be considered.
- Business courtesies include items such as free or discounted services, meals, travel, or entertainment that might bias decision-making or create the appearance of favoritism toward a supplier, vendor, or other business associate. Healthcare entities should consider policies that limit business courtesies to such things as working meals, typically during work hours and a courtesy that does not exceed a specific limit per person.
- There are gifts and business courtesies that should be considered for a list of unacceptable gifts/business courtesies:
- Cash and cash equivalents such as gift certificates or gift cards.
- Funding to support parties, celebrations, or similar non-business-related functions;
- ANYTHING, no matter how minimal in value, offered with the expectation that the person offering the gift will receive favorable treatment in return and
- Accommodation or travel of any value unless offered in conjunction with the performance of the organization’s business and approved by management.
- Effectively implemented policies and procedures relating to gifts and business courtesies also help a healthcare entity manage the risk of allegations of kickbacks or even Stark violations in the case of the 10 designated health services.
Compliance Program Leadership and Oversight
Reports to the Governing Body
The OIG guidance on compliance programs emphasizes the need for the Compliance Officer to have direct access to the Governing Body, typically the Board of Directors. Since Boards usually have the ultimate responsibility for the organization’s performance, including the effectiveness of the healthcare compliance program, they must have unfiltered reporting on compliance programs and investigations.
Many, if not most, Boards are risk averse. Like most of us, they prefer to receive bad news and reliable information on the causes and cures from a trusted source. In our experience as Compliance Officer for a number of clients, we often presented findings about billing and other mistakes that cost the institution significant funds to repay federal healthcare programs. Over time, we established an environment of trust with the Board, chief executive officer, and senior leadership that we maintained for years. No one likes their mistakes reported to the Board, but a compliance officer can be your friend when it’s time to develop corrective action initiatives.
The focus of the Compliance Officer
In larger organizations, having a dedicated compliance professional and support staff for functions like internal audits and internal monitoring is feasible. In smaller organizations, the role of Compliance Officer may be a collateral duty of another manager or director. In these instances, it is important to both make enough time for the compliance activities and ensure the individual is well-equipped to manage the Compliance efforts. Organizations such as the Health Care Compliance Association offer excellent educational resources for someone learning on the job.
Compliance Training and Education: General Training vs. Company-specific
These days, there are many excellent sources for training staff members on the general principles of a compliance and ethics program. Training can be completed online, reducing the need to schedule large groups of personnel simultaneously in the same place.
However, this type of training usually does not include specifics about the company’s compliance program.
These and many more pieces of information must also be conveyed to staff members as part of initial orientation – and repeated periodically over time! Many hospitals have adopted huddles as a way of informally reminding staff about proper procedures, especially in the area of patient safety. Adding issues like completing medical records documentation timely or acting to protect patient health information can go a long way towards helping maintain compliance with other applicable laws and regulatory requirements, as well.
Enforcing Standards
Consequences
Most of us are not anxious to face the consequences of our actions, and this is true of healthcare organizations as well. However, between staff members who feel loyalty towards their fellow staff members and managers who are worried about losing staff for disciplinary reasons, there can be a reluctance to bring compliance concerns to a compliance professional in the organization. It is important to remind everyone that your organization is dedicated to doing the right thing – in all aspects of healthcare operations.
And don’t overlook the need for retraining as part of a disciplinary process for compliance violations. If push comes to shove, and you must separate a staff member from the organization, especially for a repeat offense, you want to make sure you can tell the unemployment judge the staff member was well aware of their duties.
Incentives
Incentives are also important to healthcare facilities implementing ongoing compliance programs. Recognizing efforts to prioritize compliance in both formal employee recognition programs and in informal settings sends a message that the organization values these types of efforts by staff members.
Risk Assessments
Risk assessments are designed to identify the specific business risks of healthcare organizations. At their most basic level, healthcare compliance programs are risk management programs. The goal is to avoid or at least mitigate the numerous risks for your organization in the healthcare industry.
One of these compliance risks is employing staff members excluded from state or federally funded healthcare programs. The OIG maintains a searchable database of persons who have been excluded from federally funded healthcare programs, and many states also maintain such databases. Several services will perform these searches and notify you if the new hire you are considering is excluded from Medicare or Medicaid. And these services are not too expensive, even for smaller organizations. Of course, if you utilize a service, pay attention to their reports on new hires and existing employees.
Even with service and careful monitoring, people can slip through. One of our hospital clients was waiting for the arrival of a new Chief Operating Officer the next day. A person in the community saw the announcement in the newspaper and called the hospital to warn them the individual had been excluded elsewhere. Although the hospital screened the individual, it turned out he had more than one social security number. Needless to say, they dodged a big bullet!
Final Thoughts
These are really just a few of the overlooked parts of hospital compliance programs we have witnessed in the past ten years. No matter how organized you start out when implementing written compliance programs, it will be challenging to pay attention to all aspects over a period of time. Here is a guide to measuring the effectiveness of your compliance program from year to year. Good luck!
