Quality
Auditing, Corporate Compliance, Quality

The Cost of an Unchecked Policy

WHEN POLICY MEETS PRACTICE | A TWO-PART SERIES

How quality assurance and quality improvement audits keep policies alive and patients safe

Written by Robert Colon-Torres   

Every health system has policies. Far fewer can prove those policies are followed, or that they work. That gap is where preventable harm, financial penalties, and legal exposure live.

In nearly 25 years of healthcare compliance work, I have rarely investigated an adverse event where no policy existed. Far more often, the policy was there. It had been approved, posted, and acknowledged in an annual training. It simply was not what happened on the floor, and no one had checked.

This is the first of a two-part series on that gap between the policies health systems write and the care they actually deliver. My argument across both parts is straightforward: quality assurance (QA) and quality improvement (QI) audits are what turn a policy from a document into a practice, and compliance and CQI must operate as one team to make that happen. Part 1 examines what is at stake when the gap goes unchecked: for patients, for the organization's finances, and in front of regulators and courts. Part 2 explains why the gap opens and how to close it.

Harm is common, and much of it is preventable

The Institute of Medicine's To Err Is Human (1999) estimated that up to 98,000 hospitalized Americans die each year from preventable error.[1] Later estimates ranged far higher, including the widely cited 2016 claim that medical error is the third leading cause of death in the U.S.[2] Those higher figures have been sharply criticized on methodological grounds, and a 2020 meta-analysis put preventable inpatient deaths closer to 22,000 a year.[3][4] Compliance professionals should resist the temptation to lead with the most dramatic number; our credibility depends on precision.

But the debate over mortality obscures a point on which the evidence is consistent: harm itself is common. The HHS Office of Inspector General found that one in four hospitalized Medicare patients experienced harm, and that 43 percent of those events were preventable.[5] A 2023 New England Journal of Medicine study of eleven Massachusetts hospitals found adverse events in nearly one in four admissions, about a quarter of them preventable.[6] More than two decades after To Err Is Human, the problem has not been solved. In most of these cases, the evidence-based practice that would have prevented harm was already known.

Where policy and practice drift apart

Bar code medication administration (BCMA) shows how the drift happens. BCMA was designed to stop wrong-patient and wrong-dose errors, yet researchers documented fifteen distinct workarounds, including spare wristbands taped to carts and door frames, multiple patients' medications carried on one tray, and medications given first and scanned later.[7] None of this was sabotage. Each workaround was a rational response to workload, equipment placement, or a process that did not fit the real work.

Left alone, workarounds become what sociologist Diane Vaughan called the normalization of deviance: each shortcut that does not immediately cause harm makes the next one feel acceptable, until the unofficial procedure has replaced the official one.[8] By the time an adverse event exposes the gap, the deviation may have been routine for years. An audit is the only reliable way to see it sooner. A workaround is not just a staff behavior to correct; it is data showing exactly where the policy and the work have come apart.

Regulators now ask whether your program works

The compliance standard has shifted from “Do you have a policy?” to “Can you show that it works?” The HHS-OIG General Compliance Program Guidance (2023) treats auditing and monitoring as a core element of an effective program and expressly identifies quality and patient safety as compliance risks that boards should oversee.[9] The Department of Justice's Evaluation of Corporate Compliance Programs (updated 2024) asks prosecutors to judge not only whether a program is well designed, but whether it “works in practice,” including whether the organization tests its controls and learns from what it finds.[10]

The financial incentives point the same way. Since 2008, Medicare has declined to pay the added cost of certain hospital-acquired conditions, and the HAC Reduction Program reduces payments by one percent for the worst-performing quarter of hospitals.[11] Measurable medical errors were estimated to cost the U.S. economy $17.1 billion in a single year.[12] An unaudited policy is not a neutral gap. It is unpriced financial risk.

Your policies will be read in court

Courts in many states allow a health system's own policies to be admitted as evidence of the standard of care.[13] In Jutzi v. County of Los Angeles (1987), a county policy authorizing emergency physicians to treat orthopedic injuries helped establish that the hospital had met its standard of care.[14] In Heastie v. Roberts (2007), where a restrained patient was burned after the hospital's own contraband-search policy was not followed, the Illinois Supreme Court held that internal policies may be considered by the jury as evidence bearing on the standard of care, while a violation alone does not automatically establish negligence.[15]

The lesson for compliance is that a followed policy can protect you, and an unfollowed one can hurt you, sometimes more than having no policy at all. The only way to know which kind you have is to audit it.

A system problem, not a staff problem

When harm occurs, the instinct is to find the person who made the mistake. A just culture approach asks a better question: what in the system made the error likely?[16] Individuals remain accountable for reckless choices, but most errors and workarounds are system signals. Blaming the individual closes the file and leaves the conditions in place for the next event. QA and QI audits are how an organization turns systems thinking from a slogan into a practice.

About the Author

Robert Colon-Torres is a healthcare compliance executive with roughly 25 years of experience, most recently as a chief compliance officer for federally qualified health centers in California. He holds a degree in health law from Loyola University Chicago.


References

  1. Kohn LT, Corrigan JM, Donaldson MS, eds. To Err Is Human: Building a Safer Health System. Institute of Medicine; 2000.
  2. Makary MA, Daniel M. Medical error: the third leading cause of death in the US. BMJ. 2016;353:i2139.
  3. Shojania KG, Dixon-Woods M. Estimating deaths due to medical error: the ongoing controversy and why it matters. BMJ Qual Saf. 2017;26(5):423–428.
  4. Rodwin BA, et al. Rate of preventable mortality in hospitalized patients: a systematic review and meta-analysis. J Gen Intern Med. 2020;35(7):2099–2106.
  5. HHS Office of Inspector General. Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (OEI-06-18-00400). 2022.
  6. Bates DW, et al. The safety of inpatient health care. N Engl J Med. 2023;388(2):142–153.
  7. Koppel R, et al. Workarounds to barcode medication administration systems. J Am Med Inform Assoc. 2008;15(4):408–423.
  8. Banja J. The normalization of deviance in healthcare delivery. Bus Horiz. 2010;53(2):139–148.
  9. HHS Office of Inspector General. General Compliance Program Guidance. November 2023.
  10. U.S. Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs. Updated September 2024.
  11. Centers for Medicare & Medicaid Services. Hospital-Acquired Condition Reduction Program.
  12. Van Den Bos J, et al. The $17.1 billion problem: the annual cost of measurable medical errors. Health Aff. 2011;30(4):596–603.
  13. Bal BS. An introduction to medical malpractice in the United States. Clin Orthop Relat Res. 2009;467(2):339–347.
  14. Jutzi v. County of Los Angeles, 196 Cal. App. 3d 637 (1987).
  15. Heastie v. Roberts, 226 Ill. 2d 515 (2007).
  16. Marx D. Patient Safety and the “Just Culture”: A Primer for Health Care Executives. Columbia University; 2001.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Measuring Effectiveness of Your CDI Program

Mitigating Risk and Improving Quality of Care 

Co-authored by Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 

This paper outlines the basics related to key steps, metrics, and best practices for implementing an effective CDI audit program. The information below is for educational purposes only and not intended as consulting or legal advice.

Introduction

Clinical Documentation Improvement (CDI) is a vital process that ensures medical records are accurate, complete, and compliant, directly impacting patient care quality, severity-of-illness tracking, and reimbursement. As CDI departments mature, establishing a robust, routine auditing process—both internal and external—is essential to validate the accuracy of CDI staff queries, identify educational gaps for physicians, and ensure compliance with regulatory standards.

Effective CDI audits identify gaps in diagnostic specificity, medical necessity, and coding accuracy which must support documentation (like histories and exam findings), and appropriate, non-leading queries.

OIG Guidance and Regulatory Support for Your Audit

To control risk, your internal auditors will benefit from a clearer understanding of healthcare compliance guidance, statutory and regulatory provisions that are related to CMS reimbursement.   The HHS Office of Inspector General’s (OIG) General Compliance Program Guidance (2023) calls for a proactive approach that emphasizes preventing errors rather than relying on post-submission rationalizations. The OIG guidance implicates several key documentation safeguards:  documentation must accurately reflect the services provided; patient records must be unique to the specific clinical encounter documented; and an effective risk mitigation playbook should address systemic documentation errors before they lead to overpayment demands or other matters. 

Grounded in statutory frameworks, Title XVIII of the Social Security Act sets forth a principle of “no documentation, no payment.”  All diagnostic and therapeutic interventions must meet the “reasonable and necessary” standard.  Medical records that provide insufficient information to justify the conditions for CMS payment could result in claim denials or a subsequent recoupment of funds.

Checklist for Clinical Documentation Improvement Audits

A CDI audit is a structured review designed to measure the effectiveness of the CDI program in capturing the full clinical picture of a patient. It serves as a check-and-balance system, evaluating not only the accuracy of coding but also the appropriateness of queries sent to providers.  A CDI audit also ensures that the medical record reflects real-time clinical practices rather than functioning as a retrospective cost justification.

The process involves a continuous, four-stage cycle which should have a Lead Auditor to guide the team to: 1) Prepare and plan (set goals), 2) Execute – collect and analyze records, validate findings, 3) Report audit findings 4) Provide education to implement change, and re-audit to ensure changes are sustained.

1.  Preparing for the Audit
     Success in auditing requires careful planning and preparation.

  • Define Scope and Goals: Identify specific areas of focus, such as high-risk diagnoses (e.g., sepsis), high-volume, or high-cost areas.
  • Select Samples: Utilize a representative sample of records, including those with queries and those without, to assess both CDI activity and documentation gaps.
  • Determine Audit Frequency: Establish a regular schedule (e.g., monthly or quarterly).
  • Identify Reviewers: Use a mix of internal staff for ongoing monitoring and external auditors for unbiased, independent assessments.

2.  Execute the Audit
     An effective CDI audit follows a standard quality improvement cycle (Plan, Do, Study, Act):

  • Data Collection
    Use random sampling of patient records to get a representative view or targeted sampling for specific providers or types of documentation. Reviewers gather patient records, specifically examining:
    • Specificity to ensure documentation is accurate, thorough, and detailed.
    • Medical necessity - Confirm that the documentation justifies the care provided.
    • The principal diagnosis assigned.
    • Secondary diagnoses (comorbidities and complications).
    • Present on Admission (POA) indicators.
    • Query compliance, ensuring queries are evidence-based and not leading, with best practices focused on clarifying ambiguities in the medical record
  • Analysis and Validation 
    Auditors compare the documentation against evidence-based standards. Key questions include:
    • Did the documentation support the queried diagnosis through objective clinical indicators, e.g., vitals, labs, treatment?
    • Was the query necessary, or was the information already in the record?
    • Are there missed opportunities where documentation was insufficient?

3.  Reporting Audit Findings
     Audit findings should be reported through actionable metrics.

  • Query response rates and agreement percentages. Report if providers respond to queries and if those queries improve the record.
  • DRG shifts (change in Diagnosis Related Group).
  • Denial reduction rates.

4.  Provide Education to Implement Change
    The results are used to provide targeted feedback to clinicians and CDI staff.

  • Develop educational sessions based on recurring documentation gaps (e.g., chronic condition management).
  • Update templates and checklists for improved accuracy.
  • Re-audit to ensure improvements are sustained.

Key Metrics/Key Performance Indicators (KPIs) to Audit

To measure the success of a CDI program, organizations should track specific key performance indicators (KPIs):

CDI KPI

Conclusion 

Best practices for successful CDI audits involve the providers. After all – it is their documentation being audited! Ensure the CDI team creates processes that minimize administrative burden.

Leverage technology and streamline the audit process by using computer-assisted coding (CAC) and AI-powered analytics to scan for gaps and prioritize reviews. Ensure documentation is accurate across all patient encounters, not just for higher reimbursement.

Share feedback. Collaborate with the coding and billing departments to ensure documentation aligns with ICD-10/CPT guidelines. Create a closed feedback loop where findings are shared with clinicians and coders for ongoing training.

Remember, auditing for CDI is a continuous cycle of improvement, moving beyond simply chasing revenue to establishing a sustainable, compliant, and accurate record-keeping process. By focusing on regular reviews, actionable metrics, and ongoing education, organizations can improve the quality of clinical documentation, leading to better patient care and optimal financial outcomes.

About the Authors

Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC, is a member of the AIHC Volunteer Education Committee. Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS, is the Chief Executive Officer at the American Institute of Healthcare Compliance.

References 

American Institute of Healthcare Compliance

National Library of Medicine

Office of Inspector General, U.S. Department of Health and Human Services. (2023). General Compliance Program Guidance.

Social Security Act § 1815(a), 42 U.S.C. § 1395g(a)

Social Security Act § 1862(a)(1)(A), 42 U.S.C. § 1395y(a)(1)(A)

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Auditing and Standard Deviation

The Importance of Statistical Significance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of standard deviation when Auditing for Compliance and quality standards. It is not intended as being comprehensive, legal or consulting advice. You may be interested in other auditing articles – click here. 

Introduction

In an increasingly data-driven corporate healthcare environment, auditing has moved beyond traditional spot-checking to advanced analytics. Standard deviation, a statistical measure of dispersion, has become an essential tool for auditors to assess risk and operational performance. By quantifying how data points, such as transaction amounts, process times, or product quality metrics deviate from the mean, auditors can identify anomalies, measure volatility, and evaluate the consistency of operational processes.

This paper explores how standard deviation helps audit financial risk by identifying outliers and market volatility, and how it improves operational efficiency by highlighting process variations.

Why Standard Deviation (SD) is Vital

In simpler terms, standard deviation measures the variation in the data. A higher variance requires a larger sample size to achieve statistical significance. It represents the average amount of variation or dispersion of data points from the mean.

Standard deviation is another measure of dispersion that complements variance. Standard deviation indicates how spread out the data points are in relation to the mean. Just like variance, standard deviation helps us understand the consistency and reliability of the data.

  • SD helps to identify outliers and anomalies. Auditors use standard deviation to pinpoint unusual data points that fall far from the mean to flag potential fraud, waste, billing errors, patient waiting times and quality measures.
  • SD is used to assess consistency. In auditing, a small standard deviation indicates consistent performance, while a high one suggests unreliable processes or high variability.
  • Calculating SD is vital when used in evaluating treatment/clinical variation. It helps determine if outcomes are consistent across a population. High standard deviation in medical data indicates inconsistent patient responses, which may signal a need for audits on clinical quality.

Understanding Risk and Performance

Financial risk management requires understanding volatility and uncertainty. Standard deviation serves as a proxy for this risk, helping auditors and financial analysts determine the potential for loss or unpredictability.

Auditors are tasked with providing assurance on financial statements and improving business processes. While averages (means) provide a central reference point, they often disguise underlying inconsistencies or high-risk outliers.

Standard deviation (SD) is essential because it measures the spread of data; a small standard deviation indicates consistency, while a high standard deviation indicates high variability. For auditors, this variability is synonymous with risk and potential inefficiency.

It is essential for auditing financial risk and operational efficiency because it permits auditors to see if "average" performance is due to uniform, acceptable results, or a mix of excellent and failing results.

Standard deviation is particularly useful for auditors due to its specific mathematical properties:

  • Sensitivity to Outliers: Because standard deviation squares the variance, it heavily impacts outliers, making it an effective tool for surfacing extreme cases.
  • Comparability (Scale Invariance): Auditors can directly compare the volatility of different datasets, even if they are in different units, allowing for comprehensive risk assessment across diverse business units.
  • The Normal Curve (Bell Curve): In a normal distribution, roughly 68% of data falls within one SD, 95% within two, and 99.7% within three. Auditors can use these intervals to define "normal" transactions and immediately identify the 5% that are outliers.

While powerful, standard deviation has limitations that auditors must recognize:

  • Assumes Normal Distribution: It works best with normal, bell-shaped curves. If data is heavily skewed or has fat tails, standard deviation might underestimate tail risk (rare but extreme events).
  • Backward-Looking: It is based on historical data, which may not repeat in the future.
  • Treats Volatility Equally: It treats positive and negative deviations equally, whereas auditors are primarily concerned with downside risk.

Steps to Calculate Sample Standard Deviation (SD)

Calculating standard deviation for a health care audit measures how much individual data points (e.g., patient wait times, billing errors) differ from the average, showing consistency in care. To calculate, find the average (mean), calculate each data point’s distance from the mean, square them, average those squares, and find the square root.

1.  Calculate the Mean

  • This is calculating the average by adding all audit data points and then dividing by the total number of items.

2.  Calculate Deviations

  • Subtract the mean from each individual data point.

3.  Square the Deviations

  • Square each result from step 2 to remove negative values.

4.  Sum of Squares

  • Add all squared values together.

5.  Calculate Variance

  • Divide the sum of squares (sample size minus one).

6.  Calculate Standard Deviation

  • Take the square root of the variance.
Square Root Formula

 σ is the standard deviation, xi is each individual data point in the set, µ is the mean, and N is the total number of data points. In the equation, xi, represents each individual data point. The results are then summed (symbolized as Σ), which is the numerator of the fraction from the equation.

Example: Audit of Patient Wait Times (Minutes)

Data (patient wait times): 10, 15, 20, 25, 30

Mean is 20:         (10 + 15 + 20 + 25 + 30) ÷ 5 = 100 ÷ 5 = 20

1.  Deviations:

  • 10 - 20 = -10
  • 15 - 20 = -5
  • 20 - 20 = 0
  • 25 - 20 = 5
  • 30 - 20 = 10

2.  Squared Deviations:

  • (-10)2 = 100
  • (-5)2 = 25
  • (0)2 = 0
  • (5)2 = 25
  • (10)2 = 100

3.  Sum of Squares: 100 + 25 + 0 + 25 + 100 = 250

4.  Variance: 250 ÷ (5 - 1) = 250 ÷ 4 = 62.5

5.  Standard Deviation: 62.5 ~ 7.90569 (round to 7.91)

6.  Audit Conclusion: The average wait time is 20 minutes with a standard deviation of 7.91 minutes

Conclusion

Understanding the significance of standard deviation is essential for modern auditing. It allows auditors to shift from a focus on the average to a focus on the variation. By providing a clear, quantified metric for variability, standard deviation allows auditors to quickly pinpoint financial risks and compliance issues that require investigation. Used alongside other audit tools, it ensures that companies can better manage risk, maintain control over processes, and optimize performance.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

National Library of Medicine

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

The Importance of Statistical Significance

Auditing for Compliance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of audit sampling used when Auditing for Compliance, specifically chart or billing audits. It is not intended as being comprehensive, legal, or consulting advice.

Introduction

A statistically significant chart audit in healthcare is a structured, randomized review of medical records designed to project findings onto an entire population of claims (the "universe") with measurable reliability.

The Office of Inspector General (OIG) states these audits be random, unbiased, and sufficiently large to be representative of the population. A common misconception is that a fixed percentage (e.g., 10%) of charts is always sufficient. The OIG does not set a fixed percentage. The sample size must be large enough to provide a reliable estimate of the universe's overpayment amount. A statistically significant chart audit, compliant with OIG guidelines, is a scientifically rigorous process.

In healthcare, audit sampling is crucial when auditing the entire population (100% of claims) is impractical due to high volume. A "statistically valid" sample differs from a simple "probe" or arbitrary sample (e.g., 10 charts) because it allows for the projection of error rates onto the larger population. A statistically valid sample is necessary for:

  • Provider Self-Disclosure Protocol: Submitting self-audits to the OIG.
  • Corporate Integrity Agreements (CIAs): Mandatory compliance for providers under investigation.
  • External Audits: Rebutting audits from Unified Program Integrity Contractors (UPICs) or Medicare Administrative Contractors (MACs).

Even your routine audits should be grounded as statistically significant, which is fundamental when auditing a healthcare organization for compliance. Taking this approach transforms subjective chart reviews into defensible, objective, and scalable evidence that can be used to prove compliance. government agencies.

Statistical significance provides the necessary confidence, typically 90% or higher, that findings from a small sample accurately represent the entire population, minimizing the risk of false positives. Experts often check if the auditor used an appropriate one-sided 90% confidence level, which is a common standard in these audits.

The confidence level defines how often the true population value (e.g., total overpayment) falls within the range calculated from the sample. The precision (Margin of Error) defines the range of accuracy around the point estimate (e.g., +/- $10,000). The trade-off is a higher confidence level (e.g., 99%) which usually requires a wider range of precision, or a significantly higher sample size to maintain precision.

Legal and Regulatory Defensibility

  • Mandatory for Extrapolation - Government contractors, such as Recovery Audit Contractors (RACs), Unified Program Integrity Contractors (UPICs) and Department of Health and Human Services (HHS) Office of Inspector General (OIG) Office of Audit Services, require statistical sampling for projecting overpayment amounts. If an audit lacks statistical significance, it cannot be legally extrapolated to the total claim population.
  • Rebuttal of Audit Findings - Organizations can use statistical expert testimony to challenge improper sampling methods used by auditors, as flawed sampling often leads to inflated repayment demands. Core areas challenged by experts are:
    • Improper Audit Universe/Frame: Auditors may fail to define the correct population of claims, including irrelevant claims or excluding relevant, paid-in-full claims that would balance the error rate.
    • Lack of Randomization/Bias: Experts look for patterns showing the sample was not truly random, such as a sample mean paid amount dramatically higher than the universe mean, indicating a biased selection.
    • Failure to Account for Underpayments: A common, frequently successfully challenged error is the failure of auditors to include underpayments, which skews the audit and "significantly" overstates the overpayment.
    • Imprecise Extrapolation: Even if a sample is random, it may be too small or produce a wide confidence interval (high imprecision), making the projection highly unreliable.
    • Failure to Replicate: Government auditors often fail to document their work sufficiently, making it impossible to reproduce the sample or calculations.
  • Lower Bound Calculation - Statistical methods (like Rat-Stats) calculate the lower limit of a 90% confidence interval, ensuring that recoupment amounts are statistically defensible and conservative.
    • OIG RAT-STATS is a free statistical software package created by the Office of Inspector General (OIG) that provides a "rock-solid," defensible foundation for auditing healthcare claims. It is used to generate random samples, determine sample sizes, and extrapolate error rates to entire populations. It is widely used by auditors, and often by providers in corporate integrity agreements.
    • While RAT-STATS is user-friendly, it requires a thorough understanding of statistics and the software itself to use it properly and to challenge, if necessary, the findings of an audit.

Ensuring Accuracy in Large Datasets

Statistical tools calculate the minimum required sample size (often at least 30 but higher depending on variance) to ensure that the audit has enough power to detect errors without wasting resources on excessive, manual review.

It is important to mitigate potential bias. Statistical sampling prevents "judgmental sampling," where auditors might only select high-dollar or potentially erroneous claims, which would falsely inflate the error rate. To achieve this, we need to address the confidence interval.

Key Components of an Audit Confidence Interval

We strive to reduce "false positives." A 95% confidence level indicates that there is only a 5% chance that observed deviations in documentation or billing were due to random chance, rather than a systematic compliance failure. Let’s dive a little deeper into the confidence level and margins of error.

  • A confidence level (e.g., 95%) is the reliability of the sampling method. A 95% confidence level means that if the audit were repeated 100 times, 95 of the resulting intervals would contain the true population value. Applying a 90% confidence level is a common requirement for CMS contractors to use as a basis for extrapolation.
  • Precision refers to the margin of error or the width of the interval. A tighter (narrower) interval means more precise results, often requiring a larger sample size. Larger samples shrink the confidence interval, providing higher precision. A higher confidence level (e.g., 99% instead of 95%) makes the interval wider (less precise) because you are trying to be more certain.
  • Upper/Lower Limits are the boundaries of the interval, providing the "best-case" and "worst-case" scenario for errors. In healthcare audits, particularly those involving billing compliance, overpayment extrapolation, and quality of care, upper and lower limits define the range of plausible values for a population parameter (such as total overpayment) with a set level of confidence (typically 90% or 95%).
    • Lower Limit (LL): The lowest expected value of the confidence interval. In many CMS audits, the lower limit of a one-sided 90% confidence interval is used to determine the minimum amount of overpayment to be recouped.
    • Upper Limit (UL): The highest expected value of the confidence interval. It represents the worst-case scenario for error rates.
    • Confidence Interval (CI): The full range between the Lower and Upper Limit. A narrower interval indicates higher precision.

Key Statistical Concepts for Auditors

Confidence Levels: The percentage of times (e.g., 90% or 95%) that the true value of an error is expected to fall within the calculated confidence interval.

Null Hypothesis (H0): The assumption that there is no meaningful difference between the audited sample and the expected (compliant) standard.

P-Value: The probability that results were produced by chance. A low p-value (typically $p<0.05$) allows the auditor to reject the null hypothesis and conclude a real, significant error pattern exists.

Randomized & Unbiased: Every claim in the universe must have an equal chance of selection.

Representative: The sample must reflect the characteristics of the entire population.

Standard Deviation: Measures the variation in the data; higher variance in claims requires a larger sample size to achieve statistical significance.

Statistically Valid & Replicable: Another auditor using the same methodology should arrive at similar results.

Universe Definition: The specific time period, the provider, and types of claims being audited (CPT code range 99212-99215 from Jan-Dec 2025).

Limitations to Consider

  • Not Always Meaningful: A statistically significant result (due to a large sample size) does not always mean the error is clinically or financially important.
  • Small Populations: When auditing small departments, high variation may lead to non-significant results, even if errors are present.
  • Requires Expertise: Misapplication of statistical formulas can create misleading conclusions; statistical literacy is crucial for compliance officers.

General Rules of Thumb - When full statistical calculation is not possible, industry guidelines offer the following benchmarks:

  • Small Populations (<100): Audit all records (100% sampling).
  • Large Populations: 10% of the total eligible charts, up to a maximum of 1000, is often sufficient.
  • Rapid Cycle Sampling: Small, consecutive samples (e.g., 5-10 charts) can be used to track changes over time in quality improvement projects and for monitoring purposes.

Conclusion

It’s all about measuring the effectiveness of your compliance program

The effectiveness of the compliance program must identify high-risk patterns. Organizations use statistical significance to track if voluntary changes to coding or billing procedures resulted in significant, measurable reductions in error rates. Taking this approach allows the organization to determine if corrective actions, such as training, efforts to correct Electronic Health Record systems, conducting pre-billing targeted audits, etc. are making the expected improvements required for compliance.

Statistical techniques allow internal auditors to identify trends in data, such as high-frequency billing of complex codes, which indicate potential risk for future external audits.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

CDC

National Library of Medicine

Strategic Management Services

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Measuring Audit Results

Why Statistical Literacy is Crucial for Auditors 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of common statistical terminology used when Auditing for Compliance and not intended as being comprehensive, legal or consulting advice.  Please consult a professional for more information regarding the importance of using statistical measures for your healthcare organization. 

Why Is This Important When Software Generates the Statistics?

It is essential for chart auditors to understand statistical terms even when software generates the statistics because automated tools cannot interpret context, detect hidden biases, or make judgment calls regarding data quality.

While software speeds up the analysis of large datasets, an auditor's understanding of statistics is required to validate that the results are meaningful, accurate, and truly answer the audit's objective rather than just identifying coincidental correlations.

Advantages of Using AI - Artificial intelligence (AI) and software tools are transforming medical chart audits from infrequent, retrospective sampling into continuous, comprehensive, and automated processes. These tools primarily utilize Natural Language Processing (NLP) and Machine Learning (ML). AI integrates with electronic health records (EHRs) to analyze 100% of patient records continuously, rather than relying on limited retrospective samples, providing the ability to identify documentation gaps (such as missing signatures, late entries, unsupported coding), coding errors, and compliance risks in real-time.

Advanced, AI-enabled health information systems can now analyze raw, disparate data from Electronic Health Records (EHR)—including clinical notes, lab results, and patient-reported metrics—to automatically calculate complex health scores like Metabolic Equivalents (METs) and identify declining kidney function.

AI-driven tools identify patterns of documentation errors, allowing auditors to proactively manage risks related to payer audits and recoupments or situations which can trigger investigative external audits.

Human Review is Necessary

Statistical software works on the principle "garbage in, garbage out" (GIGO). Auditors must know if the data was collected properly, if there are missing values, and if the data is skewed, as automated tools may process flawed data without flagging it.

Auditors ensure data integrity – that the data accurately reflects the patient encounter or financial transaction before software analyzes it. Understanding statistical distribution helps auditors know when a simple "average" is misleading and when they need to look at the median or standard deviation.

Then there is the importance of contextual interpretation. Human auditors are better at interpreting the context and intent of a clinical note, such as differentiating "CTA" (clear to auscultation) from "CTA" (CT-angiogram) based on the surrounding narrative. Also, auditors can integrate information not explicitly written together in a single section. It is important to insert the human factor because auditors can spot subtle indicators or nuance not easily quantifiable by algorithms.

Risk Oversight - Ethical and Regulatory Accountability

Human oversight is crucial to prevent the "black box" problem where AI makes decisions without transparency, mitigating potential bias in automated audit systems. It prevents algorithmic bias and "automation complacency" where humans over-rely on AI.

By keeping human judgment in the loop, especially when auditing complex datasets or making critical decisions, the integrated process ensures the logic behind a decision is interpretable, transparent, and legally sound.

Importance of Statistical Literacy

Compliance should be the focus of all your audit functions. Measuring where you are now and improvements achieved is accomplished by applying statistics to understand data collected during the baseline audit and subsequent audits over time.

In healthcare chart audits, statistics are primarily used to summarize coding, billing and documentation compliance as well as clinical performance, identify variations in care, and determine if quality improvement (QI) initiatives are successful. These audits rely on both basic descriptive measures and more specialized tools for monitoring trends.

Auditors use descriptive statistics to summarize data and describe the basic features of a set of patient records. Instead of reading hundreds of individual charts, auditors use these "snapshots" to see the big picture—like how well a clinic is following safety rules or what the "typical" patient looks like. Common techniques include frequency distribution, percentages, and proportions to assess compliance with rules, regulations and reimbursement standards. Visual tools such as bar charts, histograms, and run charts analyze trends over time, providing a visual illustration of the data.

Key Statistical Measures Auditors Should Know

Statistics provide a "snapshot" of performance, helping to identify areas for improvement in clinical care, documentation accuracy, and compliance without making broad generalizations about the entire population. Here are the most common descriptive statistics used in healthcare audits explained in simple terms:

Finding the Middle or Central Tendency (the “typical”)

Used to find the average or typical value in audit data. Auditors use these to identify the most common or "average" value in a group of charts. These statistics help identify the center or "middle" of the data set. Terminology associated with central tendency are:

  • Mean (average): The average value, calculated by adding all values and dividing by the total count. The sum of all values divided by the number of cases. It helps identify the average performance, such as the average length of stay.
  • Median (middle value): The middle value, often used to avoid skewing data with extreme outliers, especially in run charts. For instance, let’s say you have 5 patients waiting 10, 15, 20, 25, and 100 minutes to see the provider. The mean is 34 ((10+15+20+25+100)/5), but the median is 20. The median is better for spotting typical patient experience when a few outliers (like the 100-minute patient) skew the average.
  • Mode (most common value in the data set): The most frequently occurring data point. The mode helps auditors identify anomalies. If a provider's billing pattern shows a "mode" that differs significantly from peers (e.g., almost all visits are coded as complex), it serves as a red flag for review.

Measures of Dispersion (Variability or Spread)

Measures of Dispersion (also known as variability or spread) in a chart audit tell you how consistent or scattered your data is. While the average (mean) tells you where the center of the data is, the dispersion tells you if most records are close to that average or wildly different.

In a chart audit, high dispersion often means high variability in clinical practice, which might suggest a need for better standardization (e.g., in documentation, timing of care, or drug dosages).

  • Standard Deviation (SD): Measures the spread of data; a small standard deviation indicates data is tightly clustered around the mean. – An example – if the average audit score was 90% with an SD of 5% means most charts fall between 85% and 95%. SD is the most common, precise measure, but best used when data is roughly bell-shaped (normally distributed).
    • Low SD = Data is consistent (most nurses/doctors documenting similarly).
    • High SD = Data is inconsistent (wide variation in practice).
  • Range & Interquartile Range (IQR): Identifies the highest/lowest values and the spread of the middle 50% of the data. Excellent for skewed data or when you have outliers, as it ignores the extreme top and bottom, focusing on the "typical" records. It is a robust method identify the "normal" range of data while excluding extreme outliers that might skew results.

In a chart audit, high dispersion often means high variability in clinical practice, which might suggest a need for better standardization (e.g., in documentation, timing of care, or drug dosages). In summary, dispersion tells you if your performance is reliable (low spread) or unreliable (high spread).

Frequency & Proportions

Frequency and Proportions are the two primary, simple statistics used to turn raw medical record data into actionable information. Frequency measures how often a specific event, behavior, or error occurs in a set of charts. It is a simple raw number or count. Proportions (often presented as percentages) measure the frequency relative to the whole. It tells you what part of the total population or sample had the characteristic, rather than just the raw count.

  • Frequency Distribution (Raw Count): Illustrates how often specific criteria are met. Frequency is simply counting how many times something happened. It tells you the total volume.
    • Example: You audit 50 charts to see if doctors signed their notes. You find that 40 charts have signatures. The frequency? 40.
  • Proportion (Percentages): Used to define compliance rates (e.g., % of charts with documented allergies). Proportion puts that count into context by comparing it to the total. It tells you the "score" or the rate of success.
    • The Formula: (Number of times it happened) ÷ (Total number of charts checked). Example: Using the same 50 charts, you take the frequency (40) and divide it by the total (50). The Proportion? 0.80 or 80%.
  • Why use both?
    • Frequency is great for understanding workload (e.g., "We had 100 falls this month").
    • Proportion is better for measuring quality (e.g., "Only 2% of our patients had falls").

If you check 10 charts and find 5 errors, the frequency is low (only 5), but the proportion can be horrifying (50%).

Conclusion

Compliance auditors must understand audit statistics to ensure their findings are defensible, accurate, and scalable. A firm grasp of statistical concepts allows auditors to identify high-risk patterns of non-conformance while minimizing the risk of "false positives".

Furthermore, when regulatory bodies like CMS or the OIG perform audits, they often use extrapolation to project error rates into massive financial recoupments; an auditor who understands the underlying math can effectively validate or challenge these high-stakes calculations

For more information, consider enrolling in the Auditing for Compliance online course. Tuition includes online, proctored certification to earn your Certified Healthcare Auditor (CHASM) credential.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with  Officer of the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor and investigator in the healthcare field.

References

American Institute of Healthcare Compliance

National Library of Medicine – Descriptive Statistics

Purdue University – Descriptive Statistics

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Is it an Audit, Gap Analysis or Risk Assessment?

For Auditors and Compliance Officers 

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

New to Compliance & Auditing for Compliance?  This short article is #3 in a three-part series addressing various areas of auditing and monitoring healthcare providers for compliance.  You may want to read Article #1 – Importance of Compliance Audits and Article #2 Auditing for Anti-Kickback Statute Violations.

Introduction

A healthcare compliance audit checks adherence to laws (such as HIPAA, Stark, Anit-Kickback Statue, coding, billing rules) and includes reviewing written policies, assessing internal controls, verifying staff training, monitoring data security, examining processes, interviewing staff, and ensuring a robust reporting/corrective action process is in place.  This is all aimed at risk reduction and better patient care.

The focus of this article is to discuss the difference between a Gap Analysis and Risk Assessment when conducting an audit.

Conducting an Audit can be Complex

To audit, gap analyze, and risk assess healthcare compliance, an organization systematically identifies standards, gathers data, evaluates compliance gaps and threats, prioritizes issues, then create corrective plans.  This is followed by conducting monitoring audits and review to find and fix deficiencies before they become major problems. It is a continuous process.

Core Components of a Healthcare Compliance Audit often include:

Risk Assessment & Scope

  • Identifying high-risk areas (e.g., billing, privacy, patient safety) and defining what the audit will cover.

Performing a Documentation Review

  • Checking written policies, procedures, training records, consent forms, and compliance plans for completeness and accuracy.

Testing Internal Controls

  • Evaluating safeguards for data (EHR, access), billing, and operations to prevent fraud and errors.

Workforce Competency

  • Verifying that employees understand and follow policies through training logs and interviews.

Conducting Interviews & Observation

  • Talking to staff and watching workflows to see if policies are truly followed in practice.

HIPAA Compliance

  • Data Security & Privacy auditing to determine HIPAA/HITECH compliance, access controls, and breach protocols.

Billing & Coding Accuracy

  • Performing pre-billing and post-billing audits to ensure claims are correctly coded and comply with payer rules.

Reporting & Investigation

  • Assessing the effectiveness of hotlines, whistleblower protections, and how reported issues are handled.

Corrective Action Plan (CAP)

  • Developing and tracking steps to fix any identified compliance gaps.

Gap Analysis

The distance between where you are where you need to be

Conducting an audit often requires performing a gap analysis.  A gap analysis identifies the difference between your current state and desired compliance levels.   Simply put, it starts by defining the compliance goal, assesses current performance (what your organization is actually doing) and pinpointing exactly where the organization is falling short.

In healthcare compliance, a Gap Analysis finds what you're missing compared to a standard (e.g., Coding or HIPAA rules), showing the "what's missing" and "how far" from compliance, while a Risk Assessment identifies why you're vulnerable, evaluating the likelihood and impact of threats (like breaches) to determine what controls are truly needed to mitigate risk, forming two complementary steps to achieve full, effective compliance, not replacements for each other.

Key Steps for Risk Mitigation Gap Analysis:

1. First, start with defining the scope and objective.

  • Clearly state what you're analyzing (processes, compliance, performance) and the desired outcome or standard (e.g., regulatory compliance, industry best practice).

2. Next, define benchmarks, goals that need to be met.

  • Define the desired state. Establish benchmarks, goals, and ideal performance levels, often based on regulations, standards, or strategic objectives.
  • Create list of items being measured and evaluated.

3. Conduct an Evaluation to Assess Current State.

  • Document existing performance, processes, policies, and controls, gathering data through audits, interviews, and metrics.

4. Identify & Analyze Gaps.

  • Compare current vs. desired states to find discrepancies.
  • Use tools like SWOT or process mapping to visualize inefficiencies, as taught by AIHC in the Auditing for Compliance online course which addresses gap analysis.

5. Conduct Root Cause Analysis (RCA).

  • Dig deep to understand why gaps exist (e.g., outdated policies, lack of training, resource issues).

6. Prioritize or Rank by Severity.

  • Rank gaps by severity, impact, and risk level (e.g., using an impact/effort matrix) to focus on the most critical issues first.

7. Develop Action Plan (Remediation).

  • Create detailed plans with specific actions, assigned owners, resources, timelines, and success metrics to close each prioritized gap.

8. Implement & Execute.

  • The organization must act and ensure necessary resources and support are in place.

9. Monitor & Review.

  • Continuously track progress, measure results against KPIs, and make adjustments to ensure effective risk reduction.

10. Communicate & Report.

  • Share findings and progress with stakeholders to maintain transparency and buy-in.

Risk Assessment – The “Why” and “How Bad”

After identifying what's missing (the gaps), the risk assessment quantifies how bad those gaps are. The risk assessment evaluates potential threats to compliance and patient safety.  This process explains why gaps matter and dictates what to fix to manage risk effectively.  It includes an impact analysis, evaluating controls and calculate residual risk.

Difference between Gap Analysis & Risk Assessment:

Gap Analysis = Current vs. Standard

Risk Assessment = Threats/Vulnerabilities vs. Assets

Key steps for a risk assessment following a gap analysis:

1. Identify Risks from Gaps.
  • Take the identified gaps (e.g., lack of security training, outdated software) and pinpoint the specific threats or vulnerabilities they create (e.g., phishing, data breach, system failure).

2. Analyze Risk (Likelihood & Impact). For each identified risk, determine.

  • Likelihood: How probable is it that this risk will occur?
  • Impact/Severity: How bad would the consequences be (financial, operational, reputational) if it did happen?

3. Evaluate & Prioritize Risks.

  • Combine likelihood and impact to score each risk (e.g., High, Medium, Low) and prioritize them. Focus on high-impact, high-likelihood risks first.

4. Develop Mitigation (Control) Strategies.

  • For prioritized risks, design actions to eliminate, reduce, or transfer the risk. These are your control measures (e.g., implementing training, upgrading systems).

5. Record Findings & Controls.

  • Document the entire process, including identified risks, analysis, chosen controls, and responsibilities. This is often a legal requirement.

6. Implement Controls.

  • Put the planned actions into practice.  

7. Monitor & Review.

  • Don’t stop short, complete the cycle by regularly checking if controls are working and update the assessment as the environment, threats, or business needs change.

Auditing for Compliance

Even if you have some audit experience, taking an online course and certifying can fill-in knowledge gaps and provide essential skills to lead an audit team.

To become a lead auditor, many organizations will require you to complete a training course that covers auditing principles, management systems, and leadership skills, followed by passing an exam and gaining auditing experience, such as offered by the American Institute of Healthcare Compliance (AIHC), recognized as a Licensing/Certifying partner with the Centers for Medicare & Medicaid Services (CMS).

Resources to Stay Informed

Lead Auditors and Compliance Officers need to stay informed.  Subscribing to government notifications is one way.  You may also want to review current educational articles (free) published by the American Institute of Healthcare Compliance (AIHC)– click here for the Auditing category, and view all articles or by additional categories. 

Videos can be a helpful way to stay informed.  We recommend the following which may be of interest for you or members of your audit and compliance team!

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

  • Auditing for Compliance online training course by the American Institute of Healthcare Compliance.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing, Corporate Compliance

Auditing for Anti-Kickback Statute Violations

Written by the AIHC Education Department 

About the AKS 

The Anti-Kickback Statute [42 U.S.C. § 1320a-7b(b)] 

The AKS is a criminal law that prohibits the knowing and willful payment of "remuneration" to induce or reward patient referrals or the generation of business involving any item or service payable by the Federal health care programs (e.g., drugs, supplies, or health care services for Medicare or Medicaid patients). Remuneration includes anything of value and can take many forms besides cash, such as free rent, expensive hotel stays and meals, and excessive compensation for medical directorships or consultancies.

In some industries, it is acceptable to reward those who refer business to you or your organization. However, in the Federal health care programs, paying for referrals is a crime.  

The statute covers the payers of kickbacks, those who offer or pay remuneration, as well as the recipients of kickbacks. Yes, the law applies to those who solicit or receive remuneration. Each party's intent is a key element of their liability under the AKS.

The Department of Justice (DOJ), the Department of Health and Human Services Office of Inspector General (OIG), and the Centers for Medicaid and Medicare Services (CMS) are all charged with enforcing these laws. Filing claims to any Federal healthcare program related to an AKS violation may also violate the False Claims Act (FCA). From there, it just gets more complicated because kickbacks in health care can lead to:

  • Overutilization
  • Increased program costs
  • Corruption of medical decision making
  • Patient steering
  • Unfair competition

The kickback prohibition applies to all sources of referrals, even patients. For example, where the Medicare and Medicaid programs require patients to pay copays for services, you are generally required to collect that money from your patients. Routinely waiving these copays could implicate the AKS and you may not advertise that you will forgive copayments. It can be used to induce patients to choose a specific provider's services or to prescribe their products instead of cheaper alternatives. However, you are free to waive a copayment if you make an individual determination that the patient cannot afford to pay or if your reasonable collection efforts fail. It is also legal to provide free or discounted services to uninsured people.

The Government does not need to prove patient harm or financial loss to the programs to show that a physician violated the AKS. A physician can be guilty of violating the AKS even if the physician actually rendered the service and the service was medically necessary. Taking money or gifts from a drug or device company or a durable medical equipment (DME) supplier is not justified by the argument that you would have prescribed that drug or ordered that wheelchair even without a kickback.

Consequences for Violating the AKS

AKS Criminal penalties and administrative sanctions for violating the AKS include fines, jail terms, and exclusion from participation in the Federal health care programs as follows:

  • Civil penalties: The CMPL allows the Office of Inspector General (OIG) to impose civil penalties for violations of the Anti-Kickback Statute. These penalties include a fine of up to $50,000 per violation plus three times the value of the illegal kickback (treble damages).
  • Criminal penalties: Violating the Anti-Kickback Statute is a felony and can also lead to criminal penalties, including fines of up to $100,000 and imprisonment for up to 10 years.
  • Other consequences: In addition to financial and criminal penalties, individuals found guilty of kickback violations can be excluded from participation in federal health care programs. The Office of Inspector General (OIG) has the authority to exclude both individuals and entities. Claims that include items or services resulting from a violation are not payable and may constitute false or fraudulent claims under the False Claims Act.

Criminals Target Healthcare Providers

Physicians make an attractive target for kickback schemes because you can be a source of referrals for fellow physicians or other health care providers and suppliers. As a provider, you decide what drugs your patients use, which specialists they see, and what health care services and supplies they receive. And criminals count on providers not understanding the law. This point stresses the need to audit for potential AKS violations and to have a healthcare attorney familiar with the AKS to review any agreements in advance to avoid an unlawful situation.

There are still handshake deals made, where there is no written agreement, where remuneration is made in exchange for some form of kickback. Even these “unwritten” arrangements should be audited for potential issues.

Auditors are typically not attorneys, but an internal auditor can receive training to review for potential violations, then refer questionable situations to the Compliance Officer who will forward to outside legal counsel for further investigation and corrective action.  Why outside legal counsel? In-house legal counsel is likely to have reviewed or written the agreement in question, creating a conflict of interest in being involved in any aspect of the audit process.

Common targeting methods

  • Payments disguised as legitimate compensation:
    • Paying providers for patient referrals disguised as "bonuses" or "referral fees".
    • Offering or paying for patient information that is used to market to potential enrollees.
    • Paying providers for "consulting," "advising," or "research" when the primary purpose is to secure referrals.
    • Overpaying doctors for speaking engagements.
    • Payments for office space, phlebotomy, or other services that are inflated or not legitimate, intended to be a form of compensation for referrals.
  • In-kind or indirect benefits:
    • Providing free or below-market rent, equipment, supplies, or staff.
    • Offering gifts or tokens of appreciation that could be perceived as a reward for referrals.
    • Giving practice subsidies or covering expenses that are not otherwise required.
    • Free or discounted office space or supplies.
    • Gifts, meals, or tickets to events.
  • Compensation based on referral volume or status:
    • Offering payments or bonuses that are based on the number of patients a provider refers to a particular plan or service.
    • Providing remuneration that is contingent on the health status or demographics of the patients referred.
  • Exploiting "safe harbors":
    • Structuring arrangements that appear to be compliant (e.g., professional courtesy programs or recruitment benefits) but have the primary purpose of inducing referrals.

Safe Harbor Considerations

Safe harbors are specific, pre-approved exceptions to the AKS that provide immunity from prosecution if followed precisely. They are voluntary, and not all financial arrangements have a safe harbor. An arrangement must meet all conditions of a specific safe harbor to be protected; partial compliance is not enough.

To be protected by a safe harbor, an arrangement must fit squarely in the safe harbor and satisfy all of its requirements. Some safe harbors address personal services and rental agreements, investments in ambulatory surgical centers, and payments to bona fide employees.

Congress set forth a number of factors to consider when developing safe harbors; while not binding with respect to any assessment of an arrangement that implicates the Federal anti-kickback statute (other than in the establishment or modification of safe harbors (see section 1128D(a)(2) of the Act, 42 U.S.C. 1320a–7d(a)(2)), they are instructive for assessing risk under the Federal anti-kickback statute.

For example, OIG’s advisory opinions frequently consider factors such as overutilization, increased costs to Federal health care programs, corruption of medical decision making, patient steering, and unfair competition.

One of OIG’s Compliance Program Guidance documents reiterates these factors by highlighting the following questions to help guide an assessment of any problematic arrangements or practices identified as a red flag:

  • Does the arrangement or practice have the potential to interfere with, or skew, clinical decision making?
  • Does the arrangement or practice have the potential to increase costs to Federal health care programs or beneficiaries?
  • Does the arrangement or practice have the potential to increase the risk of overutilization or inappropriate utilization?
  • Does the arrangement or practice raise patient safety or quality of care concerns?
  • Does the arrangement or practice raise concerns related to steering patients or providers to a particular item or service?

The health care community and its partners must be mindful of these types of factors and question arrangements that implicate the Federal anti-kickback statute. An affirmative answer to one or more of these questions is a red flag signaling an arrangement or practice may be particularly susceptible to the harm caused by fraud and abuse.

AKS Audit Checklist

To audit for Anti-Kickback Statute (AKS) violations, create a comprehensive inventory of financial relationships, assess existing contracts against AKS safe harbors, conduct internal reviews of transactions and billing, and implement a robust compliance program that includes regular monitoring and staff training. Key steps include analyzing payments to ensure they are for fair market value, are not tied to referrals, and that arrangements are documented properly with signed agreements and legal review.

  • Build an inventory of all financial relationships 
    • List all transactions -
      • Document all financial relationships and transactions with potential AKS implications, including those with physicians, vendors, and other healthcare entities.
    • Categorize relationships –
      • Group arrangements by type, such as physician recruitment, medical directorships, lease agreements, and professional service agreements.
    • Work with legal counsel –
      • Involve legal counsel to ensure no relevant relationships with government health care programs are missed.
  • Review and assess existing arrangements 
    • Check against safe harbors –
      • Compare each financial arrangement against the requirements of relevant AKS safe harbors. For example, safe harbor requirements often include a written agreement, specifies the services, is for at least one year, and compensation is at fair market value and not tied to the volume or value of referrals.
    • Verify compensation –
      • Ensure compensation is set in advance and is not changed retroactively, especially within the first year of a new contract. Compensation should not be based on referrals or revenue generated from referrals.
    • Examine billing practices –
      • Review billing and payment practices to confirm they align with contractual terms and are at fair market value.
  • Conduct data analysis and transaction-level audits 
    • Obtain relevant data –
      • Gather data from general ledgers, vendor files, payroll, and payment records.
    • Select a sample –
      • Randomly select a sample of payments for a detailed audit.
    • Validate transactions –
      • Cross-reference payments against supporting documentation, such as invoices, timesheets, and contracts.
    • Use data analytics –
      • Employ data analytics to identify patterns and trends that might indicate improper conduct. This is an area where implementing Artificial Intelligence programs can provide speed and accuracy.
  • Audit Results Can Strengthen the Compliance Program 
    • Implement policies –
      • Audit results can help the Compliance Department establish written policies and procedures for compliance with the AKS.
    • Provide training –
      • Regularly train staff and key stakeholders on the AKS and how to identify and report potential violations. This includes discussion with all providers during on-boarding and at least annually as part of compliance training.
    • Ensure due diligence –
      • Conduct due diligence on new and existing business partners and perform background checks, such as checking the OIG's exclusion list.
    • Monitor and report –
      • Create a system for ongoing monitoring and auditing and establish a confidential way for employees to report suspected violations.

Conclusion

Audits proactively uncover compliance gaps and vulnerabilities before they become a problem, allowing for corrective action to be taken.

Auditing for AKS (Anti-Kickback Statute) compliance is crucial for mitigating risk because it identifies and addresses vulnerabilities that could lead to severe legal penalties, financial fines, and reputational damage. Regular audits help ensure adherence to laws and regulations, protect company assets, and maintain the trust of stakeholders by demonstrating a commitment to ethical practices.

Monitoring for AKS violations helps to prove a commitment to ethical and legal conduct. These types of audits help maintain a positive brand image and public trust.

Remember, regular auditing fosters a company-wide culture of accountability and continuous improvement, where employees are more aware of and committed to compliance requirements.

About the AIHC Education Department

The American Institute of Healthcare Compliance (AIHC) Education Department provides classroom and web-based training and certification for healthcare administrators and professionals. It includes an enrollment department that processes registrations, and a research and development arm focused on creating new educational products. Learn more about short course and certification offerings in addition to free and low-priced Continuing Education Unit (CEU) certification renewal single short courses or CEU packages. Visit our website https://dev-main.aihc-assn.org/

References

  • Centers for Medicare and Medicaid Services - WPS Government Services on Waivers of Deductibles and Co-Insurance
  • Department of Justice Enforcement Activities
  • Office of Inspector General Fraud & Abuse Laws, Physician Roadmap
  • American Institute of Healthcare Compliance, Healthcare Compliance certification program

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing, Corporate Compliance

Importance of Compliance Audits

What Compliance Officers & Lead Auditors Should Know

Written by the AIHC Education Department 

Introduction

Audits Must be Independent, Transparent and Objective - No one enjoys having their department reviewed; however, audits are a necessary and important part of your organization’s compliance program. When a review or audit is conducted, you want to know that the auditors are objective with no hidden agendas. We want to be confident that the audit is being conducted fairly and objectively. Which leads us to the next important topic - who does the Auditor and Compliance Officer report to?

How to Establish Fairness

Bias, whether conscious or unconscious, can lead to improper influence, inaccurate evaluations, and legal repercussions, so auditors must have the ability to recuse themselves to ensure objective decision-making and to maintain the organization’s trust.

The reporting structure is critical to maintain fairness and impartiality. The Lead Auditor, as well as the Compliance Officer, must be outside the line of management to ensure independence and avoid conflicts of interest. This separation allows them to effectively monitor operations, identify risks, and hold the organization accountable without fear of reprisal, which is essential for maintaining an effective compliance program and protecting the organization from legal and financial penalties.

A few important key reasons for separation from management are:

Independence and unbiased assessment - Being outside the direct management structure ensures an objective and unbiased evaluation of the organization's operations, free from internal pressures. Lead auditors and Certified Healthcare Auditors know that the best compliment received is that the audit was fair. 

This means auditors must avoid participating in a review where bias can be construed.

  • Auditors must avoid taking a position that isn't objective due to personal convictions, which can impact everything from audit scope to reporting.
  • Auditors never create the audit criteria.
    • Evaluate compliance based on objective factors and documented data, such as implemented policies and procedures as your audit criteria.

Avoidance of conflicts of interest – Your organization is wise to follow advice from the Office of the Inspector General (OIG) general compliance guidance which emphasizes that the Compliance Officer should not lead or report to the legal or financial departments to prevent conflicts of interest. For example, the legal department's role is to defend the organization, which can conflict with the Compliance Officer's role of identifying and reporting risks. This is important because the audit team generally reports to the Compliance Officer or Compliance Department.

Direct reporting structure is necessary: A direct reporting relationship to the CEO or board of directors allows compliance and audit officers to bypass management interference when necessary. This ensures complete transparency and empowers them to raise concerns between all levels of management and act on findings without fear of reprisal.

Enabling effective "checks and balances" - Separation from the reporting structure creates a system of checks and balances, a vision promoted by the OIG, which is crucial for achieving the goals of a compliance program and identifying issues before they become costly problems.

Audit Results Must be Reproducible - Audit results must be reproducible to ensure objectivity, reliability, and transparency. Reproducibility allows independent verification of findings, catching mistakes and biases, and building trust in the results. It is crucial for validating the audit process, supporting long-term research, and meeting professional standards.

Maintaining professional obligations - Keeping the compliance function separate from operational departments upholds the professional obligations of the role, which include risk identification and mitigation, which must be separate from those who may be responsible for operational outcomes.

Exceed OIG Audit & Compliance Objectives

OIG is the acronym for Office of Inspector General (OIG), which is a division within a government agency responsible for oversight, audits, and investigations to prevent waste, fraud, and abuse. These offices conduct independent reviews of an agency's programs and operations to ensure efficiency, effectiveness, and financial health, and they often operate with a degree of independence to better serve their oversight function.

Compliance Officers should have structured training in auditing and monitoring not only to understand and support the Lead Auditor, but also to perform their own essential functions effectively, proactively manage risks, and foster an organization-wide culture of compliance and accountability. Acquiring expertise in auditing and monitoring enhances a compliance officer's professional value and opens up career advancement opportunities within the organization or as an independent consultant.

  • Training equips compliance officers with the skills to identify, assess, and mitigate potential compliance risks and vulnerabilities before they escalate into serious issues or legal violations. This proactive approach helps the organization avoid costly penalties and legal repercussions.

The Compliance Officer also is required to understand the principles of auditing and monitoring to ensure reviews have been conducted according to appropriate, acceptable standards and in compliance with applicable rules and regulations. Specialized training transforms a compliance officer from a simple "rule-checker" into a strategic asset who actively contributes to the organization's resilience and long-term success. Obtaining certification in both compliance and auditing is recommended (choose a non-profit organization which is a licensing/certification partner with CMS, such as the American Institute of Healthcare Compliance.

Ensure All Audits are in Alignment with Organizational Objectives

An effective audit program should assist with the ongoing evaluation of the organization’s compliance program and demonstrate the level of risk for mitigation purposes. Ideally, an organization would regularly complete a risk assessment that helps define the work plan for the audits or monitoring. Without a work plan, an organization might not demonstrate it’s aware of the risks impacting it and focus attention on lower-risk areas.

To audit where your organization is on the OIG risk spectrum, you should review your compliance program's effectiveness by auditing its seven core elements and assessing your exposure to risks like fraud, waste, and abuse. The seven elements recommended by the OIG are:

  1. Written Policies and Procedures
  2. Compliance Leadership and Oversight
  3. Training and Education
  4. Effective Lines of Communication
  5. Enforcing Standards: Consequences and Incentives
  6. Risk Assessment, Auditing, and Monitoring
  7. Responding to Detected Offenses and Developing Corrective Action Initiatives

Start by evaluating your internal controls and policies, checking for potential violations, and using risk assessment tools that consider both the likelihood and impact of risks. These audits help identify areas for improvement and ensure you are not on a path that could lead to severe consequences such as OIG exclusion or a Corporate Integrity Agreement.

Audit for Quality Assurance to Improve Patient Care

The Centers for Medicare & Medicaid Services (CMS) Quality Assurance and Performance Improvement (QAPI) is a data-driven, proactive approach that combines Quality Assurance (QA) and Performance Improvement (PI) to maintain and improve care standards in healthcare facilities like nursing homes.

QA ensures that care meets established standards, while PI focuses on continuously enhancing processes to prevent issues and improve outcomes and resident quality of life. A key framework for QAPI includes five core elements: Design and Scope, Governance and Leadership, Feedback/Data Systems/Monitoring, Performance Improvement Projects, and Systematic Analysis and Action.

Element 1: Design and Scope

A QAPI program must be ongoing and comprehensive, dealing with the full range of services offered by the facility, including the full range of departments. When fully implemented, the QAPI program should address all systems of care and management practices, and should always include clinical care, quality of life, and resident choice. It aims for safety and high quality with all clinical interventions while emphasizing autonomy and choice in daily life for residents (or resident’s agents). It utilizes the best available evidence to define and measure goals. Nursing homes will have in place a written QAPI plan adhering to these principles.

Element 2: Governance and Leadership

The governing body and/or administration of the nursing home develops a culture that involves leadership seeking input from facility staff, residents, and their families and/or representatives. The governing body assures adequate resources exist to conduct QAPI efforts. This includes designating one or more people to be accountable for QAPI; developing leadership and facility-wide training on QAPI; and ensuring staff time, equipment, and technical training as needed.

The Governing Body should foster a culture where QAPI is a priority by ensuring that policies are developed to sustain QAPI despite changes in personnel and turnover. Their responsibilities include, setting expectations around safety, quality, rights, choice, and respect by balancing safety with resident-centered rights and choice. The governing body ensures staff accountability, while creating an atmosphere where staff is comfortable identifying and reporting quality problems as well as opportunities for improvement.

Element 3: Feedback, Data Systems and Monitoring

The facility puts systems in place to monitor care and services, drawing data from multiple sources. Feedback systems actively incorporate input from staff, residents, families, and others as appropriate. This element includes using Performance Indicators to monitor a wide range of care processes and outcomes and reviewing findings against benchmarks and/or targets the facility has established for performance. It also includes tracking, investigating, and monitoring Adverse Events that must be investigated every time they occur, and action plans implemented to prevent recurrences.

Element 4: Performance Improvement Projects (PIPs)

A Performance Improvement Project (PIP) is a concentrated effort on a particular problem in one area of the facility or facility wide; it involves gathering information systematically to clarify issues or problems and intervening for improvements. The facility conducts PIPs to examine and improve care or services in areas that the facility identifies as needing attention. Areas that need attention will vary depending on the type of facility and the unique scope of services they provide.

Element 5: Systematic Analysis and Systemic Action

The facility uses a systematic approach to determine when in-depth analysis is needed to fully understand the problem, its causes, and implications of a change. The facility uses a thorough and highly organized/structured approach to determine whether and how identified problems may be caused or exacerbated by the way care and services are organized or delivered.

  • Additionally, facilities will be expected to develop policies and procedures and demonstrate proficiency in the use of Root Cause Analysis.
  • Systemic Actions look comprehensively across all involved systems to prevent future events and promote sustained improvement. This element includes a focus on continual learning and continuous improvement.

QAPI amounts to much more than a provision in Federal statute or regulation; it represents an ongoing, organized method of doing business to achieve optimum results, involving all levels of an organization.

Conclusion

The OIG recommends an organization develop a set of monitors or warning indicators to alert it to risks that require mitigation. This may be in the form of data mining or reported concerns from employees or patients. These indicators can assist in identifying a risk when it occurs instead of years after the incident.

Adherence to OIG guidance is considered a basic best practice. An effective compliance program, which includes risk assessments and audits, help meet requirements of the Federal Sentencing Guidelines and is viewed favorably by enforcement authorities like the Department of Justice (DOJ).

About the AIHC Education Department

The American Institute of Healthcare Compliance (AIHC) Education Department provides classroom and web-based training and certification for healthcare administrators and professionals. It includes an enrollment department that processes registrations, and a research and development arm focused on creating new educational products. Learn more about short course and certification offerings in addition to free and low-priced Continuing Education Unit (CEU) certification renewal single short courses or CEU packages. Visit our website https://dev-main.aihc-assn.org/

References

  • Auditing for Compliance certification course with the American Institute of Healthcare Compliance
  • Exclusions Program with the Office of Inspector General
  • Fraud Risk and Heightened Scrutiny with the Office of Inspector General
  • Quality Assurance and Performance Improvement (QAPI) with the Centers for Medicare & Medicaid Services

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 3

Part 3: When Unscrupulous Managers Turn Auditors Against Their Coworkers or Teams   

Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

  

We Recommend Reading Part 1:  When Audit Managers Knowingly Skew Audit Results and Part 2: When Criminal Behavior Infiltrates Your Audit Program. This final article in the Fraud Indicators & Red Flags series addresses potential outcomes when lead audit managers sabotage the audit process due to being insecure or due to the need to secure power in their position.

Introduction

In the first two articles over mid-level fraud indicators, we covered signs and solutions to the problem individuals. In this article we cover signs and methods to address auditors who have been “turned” into internal threats or “moles”; informing on their coworkers and/or teammates.

When unscrupulous managers or audit leads act alone or in a conspiracy to maintain their position, they will employ many short-term tactics. Because they have to constantly defend their activities, they will not think in terms of strategies except in some form of escape plan (covered in part 2). Managers or lead auditors who target subordinates to become informants stands alone, both in severity and damage to good employees and ultimately the organization: mid-level leaders targeting individual subordinates they have found to be malleable, weak, or easily intimidated/worn down. This is especially damaging to teams as cohesiveness and trust are critical to their work.

How Employees Are Turned

Retaliation

According to the U.S. Equal Employment Opportunity Commission (EEOC), “The most frequently alleged bases of discrimination were retaliation (39.2%), sex (35%), disability (34.3%), and race (16.8%). At the end of FY 2023, the EEOC had 227 merits cases on its active district court docket, of which 95 (41.8%) were class or systemic cases. Mar 27, 2024”. In the realm of equal opportunity, we tend to think of discrimination in its most well-known forms: employment discrimination because of your race, color, religion, sex (including pregnancy, transgender status, and sexual orientation), national origin, disability, age (age 40 or older), or genetic information. However, many cases have been litigated where an employee was retaliated against by a superior for voicing concerns, ethical complaints and maltreatment because of their job functions. To "discriminate" against someone means to treat that individual differently, or less favorably, for some reason.

While close timing between the allegation of retaliation and the manger's action can display retaliatory motive, there have been cases in which years have passed and other evidence established that the employee's prior activities set off the manager's action. Even minus close proximity timing, other relevant facts may include verbal or written statements; comparative evidence that a similarly situated employee was treated differently; falsity of the employer's ostensible reason for the adverse action or uncovered plausible deniability; or any other evidence from which an inference of retaliatory intent could be assessed. From the EEOC’s perspective, retaliation can take numerous forms: reprimand the employee or give a performance evaluation that is lower than it should be; engage in verbal or physical abuse; increase scrutiny; make the person's work more difficult; to name a few.

Managers find ways to retaliate against subordinates for bringing forward worries about fraud or questionable conduct. Rather than listening to the employee, who is normally an expert, many employers instead resort to various forms of blaming the messenger, and good employees are often fired, moved, or blackballed/driven from the healthcare arena for their willingness to speak up.

As in the parts 1 and 2, information is limited how mid-level administrators target individuals: but there are a number of recurring behaviors and types of bad actors who seek to isolate and “turn” auditors against their coworkers and teams.

Decentralization and Isolation

These arise from the same flaw(s) in any system but are used differently by the fraudster in a leadership capacity. The managers in question exploit the trust and lack of supervision of their activities: what controls may exist can be overridden (technology) or deflected (manipulating reports, meeting statements, etc.). Information asymmetry is used to manipulate technological data and remove negative information from reports, information the auditor will never see. If or when inquiries arise plausible deniability is used and the lack of oversight fully exploited.

There are two environments managers or audit leads use to isolate subordinates they wish to control: the office setting and the remote workforce.

In the office, if an auditor voices concerns or acts in a manner the manager sees as threatening or the manager has found to be easily influenced the manager may move the auditor away from coworkers or teammates or vice versa; move the team to other offices. The auditor now has no one they trust or can communicate with easily, directly and, critically, confidentially. Movements are harshly scrutinized and timeframes are strictly set to further control movement and communications. This isolation can be further abused by either the manager promising to put the team back together if the auditor “behaves”: or, the auditor is now so isolated maltreatment can be carried out at the manager’s will and the auditor turned to report what the manager wishes to hear when the audit team meets and works. Either way the team has been effectively infiltrated.

In the remote environment the manager already exploits information asymmetry but now, since the audit team cannot see each other at any point (in my experience Zoom and visual-virtual meetings do not fill the void of direct interaction), pressure can be put on individuals in turn and cracks either caused or taken advantage of. When conspiring managers work together and keep unrelenting pressure through implied or real threats (as viewed by the targeted auditor) and they force the auditors to only communicate with them individuals can feel lost and without options.

Bullying and Disrespectful Behavior:

Unfortunately, these behaviors have no direct legal protection: unscrupulous managers know this. They use both a combination of Game Theory and perverse incentives against individuals and together bullying and disrespectful behavior can wear an auditor down making them more malleable to turn against their team. Because of scarcity of information and similarities in definitions, bullying in this article is synonymous with disrespectful behavior, as they are virtually identical in practice.

An August 11, 2020 article in Forbes magazine titled The Differences Between Workplace Bullying And A “Hostile Work Environment” put the problem of protection against bullying as follows: “What then separates, on the one hand, a workplace that is miserable due to a boss who is a jerk to the entire staff and, on the other hand, a Title VII hostile work environment claim? The key is that the abusive conduct must be related to the employee’s race, sex, religion, etc. (otherwise known as a protected characteristic) in order for the mistreatment to be unlawful under Title VII and related laws. For example, if a manager has everyone walking on eggshells because they yell constantly and set unattainable goals/deadlines—but this abuse is directed to all employees—then this is not illegal under Title VII. If, however, the supervisor treated only female employees this way, then these women could pursue a hostile work environment claim if the inequity is based on their sex.”

For disrespectful behavior I direct the reader to a 2017 article published by The National Institute of Health: Disrespectful Behavior in Health Care-Its Impact, Why It Arises and Persists, And How to Address It—Part 2 by Matthew Grissinger: “Health care organizations have fed the problem of disrespectful behavior for years by ignoring it, thereby tacitly accepting such behaviors.  The health care culture has permitted a certain degree of disrespect while considering this a normal style of communication. Studies have shown that disrespectful behaviors are tolerated most often in unfavorable work environments, but it is unclear whether poor working conditions create an environment where the behaviors are tolerated or if the dis respectful behaviors create the unfavorable environment.

Organizations have largely failed to address disrespectful behavior for a variety of reasons. First, the behavior typically occurs daily but often goes unreported due to fear of retaliation and the stigma associated with “whistle blowing.” Disrespectful behaviors are difficult to measure, so without robust systems of environmental scanning to uncover the behavior, concerned leaders may be ignorant of the problem.  Leaders may also be unaware of the behavior if managers shield them from this information because they view it as a personal failure. If disrespectful behaviors are known, leaders may be reluctant to confront individuals if they are powerful or high-revenue producers, or they may not know how to handle the problem. It’s not a topic taught in training programs, so leaders may hesitate to take on a problem for which there is no obvious solution.”

The Workplace Bullying Institute (WBI), established in 1997 tackles the issues of prevention and protection against bullying. Since their institute began they have been “advocates for anti-workplace bullying legislation in the U.S. having introduced the Healthy Workplace Bill in California in 2003 and 31 other states and two territories since, WBI, in collaboration with David C. Yamada, Professor of Law, Suffolk University Law School, Boston, now brings forward an alternative model bill the Workplace Bullying Accountability Act (WBAA).”

The WBI has the most widely adopted definition of workplace bullying: “Workplace bullying is defined as an “abusive work environment” characterized by: repeated verbal abuse; conduct that is threatening, intimidating or humiliating; defamation of one’s reputation; work sabotage, undermining performance; and/or orchestrated ostracism.”

The WBI identifies multiple types of bullies:

  • The Constant Critic: “This one draws its targets behind closed doors. There they can threaten and intimidate without witnesses. Most shocking is that they target the most competent, veteran, go-to worker and claim that that target is incompetent. The stunning big lie freezes the target. If they are ever reported, they deny what they said and did. To HR, it becomes a she said/she said unsolvable problem. Their favorite tactic is to manufacture a false performance appraisal.”

We immediately see use of plausible deniability. If the manager is investigated they have a story ready-made, which can neither be proven nor disproven. No matter who gets involved the manager can always fall on “That’s not what I meant”; and so on. Because so much work is done remotely today this bully can plan and plot, and “test the waters” to find who the best targets are.

This bully will also take full advantage of information asymmetry. They make themselves, or them and a conspirator, the sole reporting avenues for all work, reports and performance evaluations. With decentralization and lack of robust controls documents will be manipulated, changed or deleted and the target sees no options. The bully may also have the ability to remove or corrupt auditor files. They cover two bases by verbally ordering the team to never report concerns or problems to each other or their supervisor: they strangle open communications. Their second layer of concealment is that the team will recognize the statement as an order and any attempt to circumvent or jump over them will result in accusations of insubordination. Since the manager controls upward information flow they can report what they choose, in what manner they choose. This creates and sustains an adversarial relationship between the manager(s) and the team and initiates the isolation stage of their scheme.

  • The Two-Headed Snake: “One moment your lunch buddy and a hugger. Right after, they stab you in the back. They are intent on controlling your reputation. To destroy it, they either start, or fail stop, rumors about you. This critter is very difficult to catch unless someone tells you what the snake has said about you.” This type includes the manager who either is friendly/polite, or says nothing: then months later you get a call from a superior informing you they were approached by the manager and a complaint lodged.

The two-headed snake also heavily exploits plausible deniability. This bully will do two things simultaneously: negatively/falsely report the auditor’s performance to their superior(s) and to the executives and omit reports and concerns voiced by the auditor completely: and be professional to the superiors they report to but harsh and untruthful to the auditor.

  • The Gatekeeper: “The Constant Critic and Two-Headed Snake do things to people. They commit acts of omission. Gatekeepers bully by withholding resources you need to succeed. Their dirty tricks are acts of omission. What do you need? Time to do the job? It’s denied by an impossible deadline. Information? You are blocked from using computers and search services. Furthermore, your colleagues have been ordered to not help you with anything. New job and you need training. No training for you. No budget. Though the department party is paid for. Need light duty coming back from surgery as the doctor ordered? No way. Management knows best and if you don’t return immediately to full duty, you will be fired.”

The auditor victimized by this type of bully actually may have immediate options to “return fire”. In parts 1 and 2 we covered fraud red flags and indicators of managers: and behaviors recognized by both the DoD IG and The State of New York Comptroller were withholding information. If the auditor feels there is no other starting point this can be immediately reported and investigated.

The WBI also has a position statement which encompasses, to a large extent, traits discussed in parts 1 and 2: “We believe a majority of bullies adopt the tactics of bluster and bravado as a cover, a mask, for some underlying deficiency. In other words, bullying is a compensatory set of behaviors meant to overcome something lacking — technical competence, empathy, or even fraud and theft.” This statement highlights another recognized red flag: Indications that key personnel are not competent in the performance of their assigned responsibilities.

If you as an auditor feel bullied, you are not alone. In an online survey conducted by the WBI some concerning numbers appeared:

  • falsely accused someone of “errors” not actually made (71%)
  • stared, glared, was nonverbally intimidating and was clearly showing hostility (68%)
  • discounted the person’s thoughts or feelings (“oh, that’s silly”) in meetings (64%)
  • used the “silent treatment” to “ice out” & separate from others (64%)
  • exhibited presumably uncontrollable mood swings in front of the group (61%)
  • made up own rules on the fly that even she/he did not follow (61%)
  • disregarded satisfactory or exemplary quality of completed work despite evidence (58%)
  • harshly and constantly criticized having a different ‘standard’ for the Target (57%)
  • started, or failed to stop, destructive rumors or gossip about the person (56%)
  • encouraged people to turn against the person being tormented (55%)

The last bullet point is exceptionally worrisome in the context of this article.

Being Selectively Unreachable:

When auditors are in the middle of their work, they often need rapid response from leadership to assist in problems, questions or the usual suspect, the “speed bump”. Especially in the remote environment managers will use these two ways: first they will be unreachable-period. And they will force the auditor to only approach them. Or they could call the auditor and demean them over the phone for their lack of knowledge knowing even if the behavior is reported likely no one will accept a phone call alone as evidence. But the manager will be faster than lightning to reprimand the same person. A chokehold has been put on communication but only to the individual. This causes tremendous stress and increases uncertainty because the auditor knows what awaits if he/she asks peers or an immediate supervisor for help and it gets discovered.

How to Spot the Informant

The auditor who bad actors have turned has several elements: was the auditor a good productive team member or was he/she already sarcastic, pessimistic or argumentive? On top of that, is the employee in an office setting or remote?

The Good Employee/The Unwilling Informant:

This is the majority of informants. In the office this may be visible early such as the example of the manager moving the team out or moving the auditor far away from the team. The remote environment is much more complicated for the team and much easier for the bad manager. The team does not see each other: as we have discussed communications have been forced to only the toxic manager so interactions between team members is tightly controlled: when an auditor has been targeted and pressure repeatedly put on the one auditor what communications take place do not allow the team to see potential effects. As discussed earlier even if the individual attempted to communicate directly with an immediate supervisor (but below the manager’s level) and the supervisor approached the manager, a plausibly deniable statement was ready.

The Not-so-Good or Easily Turned Employee:

There was already some real or perceived wrong by the individual and the manager’s insertion to further their “game” was not entirely unwelcome. In the office setting this might be dealt with by the meetings called by the bad actor(s): they want the team to feel their power and, not uncommonly, keep the team off balance and perhaps even maintain a certain amount of fear. The team will see the individual and either by statements made, favoritism shown by the bad actor toward the individual or other observed actions the team can as a collective element see a problem on the horizon. If the disgruntled auditor is separated from the team withholding information can go both ways and damage minimized. If the auditor remains with the team the team can collectively watch for signs such as excessive complaining and arguing, even over small points; complaining about being uninformed by the team; undermining team efforts to improve work, conditions or reporting functions; and disengagement from the team (good auditors can act this way as well: remember they do not want to be controlled and this may be an attempt to clue in the team).

With good and bad auditors, the remote environment complicates things-a LOT. Now the team does not know when the manager contacts the informant auditor, or about what. Meetings are remote and again the team cannot see each other (these managers do not use visual-virtual media for their meetings: it is another means to isolate individuals). The individual can even go so far as to start and maintain low level conflicts between her/himself and other members (as the bad managers do by initiating and maintaining disputes and adversarial relationships with the team).

An important behavior to look for is territorial behavior. Remember this individual was not unreceptive to the manager’s insertion into their work environment: they will do what they can to ensure no other team member discovers the alliance.

Other ways bad managers isolate good auditors have been discussed: but as they are more than likely indicators of fraud, they have more immediate avenues for elimination. They include Excessive control/micromanagement and forcing all control into the hands of 1-2 individuals; unclear expectations/vague “guidance” (withholding official or clear guidance they do not want known or applied).

Solutions

First and always at any sign of trouble even if only suspected document, document, document and wherever possible make bullet points tying complaints to a specific noncompliance, such as carrying on continuous disputes with the auditor and give official links to the guidances you used or attach them as Exhibits. Try to keep date-time groups as accurate as possible; and who said what when. Document what routes were attempted and what results were.

Most managers and lead auditors are ethical, hardworking and care deeply for their subordinates and the organization. The bad actors are the minority. When concerns arise about managers behaving fraudulently or antagonistically toward an auditor and their supervisor or the team another manager must be found who can address the situation and stay the course of reporting with an individual and/or the entire team. When the bad actors show themselves go to the good people and seek pathways to resolution. These people should be sought out by the team early and included in meetings if possible: or at the very least independently communicated with by a trusted teammate. This way communications are open, honest and in all likelihood big problems can be averted if the direct reporting mechanisms fail. A manager who is willing to isolate and turn an employee is not on the job for the right reasons: so, we can infer some form of fraud is taking place: financial, position protection or something else. It must be addressed quickly.

Even if a team member is believed/known to be an informant I still recommend sequestered team meetings. These are two-edged swords: the informant can report information the team shares which they rather the bad manager not be privy to: at the same time meetings can include “project assignments” or additional duties assigned to each member-the supervisor will likely be the lead for this. The supervisor can then contact each auditor individually with specifics added to their assignments. After a time, consistencies will appear because the manager(s) will micromanage everything and the informant will have shown her/his hand somewhere. In the office setting the team will need to look for more visible signs, as listed above.

The supervisor or first line leader can work directly with the informant. An unwilling participant in any fraudulent enterprise will likely want their position betrayed: they respect their team and want no part of whatever the manager is up to. Reporting safety nets and protections must be offered: confidentiality must be strictly adhered to: and the promise made of rapid action must at all costs be kept.

No solution has value unless there is a structure in place to proceed with it. Most big organizations have a hotline: whether via telephone or email the hotline must be reviewed regularly and every concern addressed. Unlike most systems if an auditor has been unwillingly turned against their team and the supervisor is assisting in the reporting process there should be an avenue for immediate supervisor/trusted individual input. Secondhand information may not be ideal but likely the auditor-informant (called a relator) is scared, stressed and afraid of retaliation, possibly including against their team. If first line leaders have enough tenure, they will likely know a peer in compliance or risk evaluation and rather than indirect communications, they can expedite the relator meeting directly with a party who has the authority to kickstart the resolution pathways. If possible, a direct internal line of reporting is advised. If the organization is big enough there may be an Ombudsman’s office to help pave the way.

Compliance and human resources cannot sit on their hands: but many departments either failed to believe the relator, initiate a serious investigation, or adhere to strictest confidentiality. Because these fraudsters know and game the system they will know as long as they refrain from certain behaviors and statements, civil rights type arguments will find little traction. The relators know this also: and if they are willing to come forward, they must have airtight guarantees of confidentiality-of the case they have reported and their identity and work environment.

Fraudster managers will “lock up” as many avenues of communication as they can internally and depending on their current tenure other sections, perhaps even compliance has been duped or kept so inaccurately informed they trust the manager(s) too much (again, information asymmetry and plausible deniability).

It is also recommended external avenues be established such as an attorney’s office, the contracting organization if the entity is a government contractor, or even an Arbitrator who can direct concerns efficiently and timely to the correct people. These are not recommended as first paths. However, if a relator has any doubt about their safety, then external measures should be established. Therefore, the team, again perhaps the Lead or supervisor should establish an external compliance “escape route”.

Now the deep dive: if any breach of process is suspected or prior attempts at resolution have failed. This is not recommended but may be necessary if the people reported to do not behave in a manner fitting the complaint. The relator has attempted internal controls and found them ineffective, even with as clear documentation and reporting as possible. This action comes with serious risk, there is no doubt: but resolution was honestly attempted and failed. Advise the addressees the relator is willing to take the case as high as necessary, even to the federal level.

My recommendation would be to word it as an advisory: “I have told you what I know, I expect proof of response within X# of days. If I hear nothing, or I receive any indications my confidentiality has been breached I reserve the right in accordance with (company, contractor) policy to report this to all authorities concerned with this matter. I am making a final attempt to resolve this problem locally and it is hoped at this point my concerns will be taken seriously. But if not, when reported to federal authorities the matter is out of our hands.” This statement will be taken seriously as intended: you have an argument and we need to address it, and you consider it very important. Or they could view it as a threat. Officially reporting the manager should be enough and the receiver(s) of the report should not need an advisory statement like this: you reserve this powerful addition to inform the receivers that you will see the matter through until a conclusion is reached and closed. So, it is up to the relator and any ally he/she may have to determine where in the process this goes-but have it ready. The relator has reported it at the lowest possible level: he or she must now commit to reaching as high as necessary to ensure all parties are dealt with and corrective changes made.

Conclusion

The vast majority of mid-level leaders are ethical and know their success relies on the true, realized accomplishment of the audit team below them. Attempting to turn a good or bad employee will never cross their minds because they hold themselves to a higher standard; and know deep inside that open communication delivered concurrently to all team members will achieve the highest rates of success.

Even where fraudulent managers exist these ethical managers will be as intolerant of their antics as the auditors. They will likely be an effective early avenue of reporting even if others who should be directly involved have failed.

Unfortunately, the damage mid-level fraudsters cause far exceeds the number working in the healthcare arena. Systems, processes and departments (i.e. Compliance) exist only to be disregarded and outmaneuvered: and individuals are expendable at any point so their illegal enterprise will survive. Elimination will only be achieved by teams and individuals willing to report them and defend their peers, and team cohesiveness strong enough to let each member know they are trusted and the team as a unit will support and if necessary, defend them.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 2

Part 2: When Criminal Behavior Infiltrates Your Audit Program 


Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)   

We Recommend Reading Part 1 Fraud Indicators and Red Flags – When Audit Managers Knowingly Skew Audit Results as this article is Part 2, “the rest of the story.”

Subsequent to Part 1 - Fraud Indicators and Red Flags, this article stresses the need for early detection of that rare, but dangerous potential fraud committed by the Lead Auditor or Audit Manager.  Members of the audit team realize that detecting a non-conformance often means there is likely much that has gone undetected. If you see something, say something, right?  But what if it is your boss managing the audit?

Introduction

In this article, the term Audit Manager and Lead Auditor is used interchangeably, even though there may be variances between these two titles.  Audits are conducted as part of the organization’s compliance program for the purpose of detecting non-conformances in order to take corrective action to improve compliance to applicable rules and regulations. 

The assumption is made that most organizations have internal controls, checks and balances and accountability built into their compliance program.  When those controls fail, the audit process can be jeopardized, skewing audit results with a potential devastating impact on the risk management process.

Organizations, regardless of size, should require the following elements within an audit: Plan, Execute, Report, Corrective action (P-E-R-C).  Smaller healthcare organizations may only have one internal auditor, while mid-size and larger organizations have a team of auditors. Someone needs to manage or lead the audit, even if it is a team of only one auditor.  If your organization doesn’t engage with an independent third-party contractor to periodically inspect the management of the audit team, you should.  Typically, your Lead Auditor is the most skillful within our organization.  For an effective program, engaging an unbiased audit expert to review and “audit” the management of how audits are conducted is a sound risk management decision. 

Let’s review why auditing your audit program is so important.

Below the Surface: Detecting What You Don’t See

If your organization detects a problem, it is likely just the tip of the iceberg.  What you don’t or can’t see is likely to be a much bigger risk factor that what you do see. 

The assumption is made that most organizations have internal controls, checks and balances and accountability built into their compliance program.  Hopefully, this article describes several ways to detect areas of potential fraud within your audit processes.

It is not uncommon for C-suite Executives to delegate the responsibility of establishing and maintaining an effective internal compliance control system to mid-level management, such as the Lead Auditor, who must implement such controls at a reasonable cost. This could conflict with the Lead Auditor’s goals of improving coding, documentation, billing accuracy and other business systems.

It is the Lead Auditor’s primary responsibility to provide assurance that reviews are conducted to detect compliance non-conformance and to lead the audit team through the P-E-R-C proves.  For an audit program to be effective, audits must be conducted and reported in a manner free from material bias, conflict of interest and performed in an objective manner.  We must admit, auditing is not guaranteed to catch every instance of fraud, waste and/or abuse.  If a problem goes undetected, does this reflect poorly on the audit team?  It could, and it could result in tarnishing the team’s reputation.

But what happens when audit results are consistently exceptional?  Repeated scores of, let’s say 96%, 97%, 98% accuracy where the target performance goal is at least 95% accuracy?  Are these results “real” or should they be questioned?  Can Auditor Managers and Lead Auditors sway audit results to improve their own performance? Is it possible that the compliance infrastructure is unintentionally designed to encourage willful misrepresentation resulting in false positive outcomes?

These are important questions to ask to ensure the appropriate checks and balances are in place.  In-other-words, who is auditing the Lead Auditor? 

When Information is Withheld or Altered

Most organizations have effective audit programs led by experienced certified healthcare auditors.  Audit Managers and Lead Auditors are skilled at giving leaders independent, objective assurance that something is true. And auditors are experts when it comes to internal controls expected during an audit; unless that information is withheld or altered. Lead auditors, through training and experience, should be able to detect fraud indicators and when these indicators involve claims, then financial fraud may also be considered triggering an internal investigation. But having this much power, can it open opportunity for willful misrepresentation?

Let’s look at the government auditing standards for a moment.  In the 2018 Revision of Government Auditing Standards, the US Government Accountability Office it states (page 175, Section 8.73): “Fraud involves obtaining something of value through willful misrepresentation. Whether an act is, in fact, fraud is determined through the judicial or other adjudicative system and is beyond auditors’ professional responsibility.” 

Section 8.74 states: “Auditors may obtain information through discussion with officials of the audited entity or through other means to determine the susceptibility of a program to fraud, the extent to which the audited entity has implemented leading practices to manage fraud risks, the status of internal controls the audited entity has established to prevent and detect fraud, or the risk that officials of the audited entity could override internal control. An attitude of professional skepticism in assessing the risk of fraud assists auditors in assessing which factors or risks could significantly affect the audit objectives.”

Is Manipulating the Audit Environment a Sign of Malicious Activity?

Manipulating any part of the audit process requires investigation. This can involve acts of self-preservation on the Lead Auditor’s part, perhaps to the extent they want to drive out the more experienced auditors on the team who can uncover and report true findings and irregularities.

It is likely that experienced auditors on the team they manage may observe and question “why” something has navigated away from protocol. A red flag is when the Audit Manager’s motivations are questioned, the question is deflected or goes unanswered.

In my experience, opportunities exploited and behavior often found in those who are committing fraud, waste or abuse are those listed below, in addition to the typical collusion and conspiracy which are better known:

Weak Internal Controls – The manager is not monitored

The manager knows if concerns are voiced, the controls are so weak that little will come of complaint(s)-the manager also already has a script in place based on plausible deniability. Hyper-compartmentalization is exploited: departments are territorial and do not share information, i.e. Compliance does not oversee or meet with the auditing department. This causes a black hole between critical control components. There is no guarantee of confidentiality or protection. This too is exploited.

Moral hazard

A moral hazard occurs when one party in a transaction has the opportunity to assume additional risks that negatively affect the other party. The decision is based not on what is considered right but on what provides the highest level of benefit, hence the reference to morality.  In my experience, one of the more common is the moral hazard of rationalization.

Rationalizations are the excuses people give themselves for failing to live up to their own ethical standards. "Moral hazard of rationalization" refers to the psychological phenomenon where individuals use reasoning and justifications to convince themselves that their unethical behavior is acceptable, essentially allowing them to engage in immoral actions while maintaining a positive self-image, thus creating a "moral hazard" by reducing the perceived negative consequences of their actions; it's essentially using logic to excuse morally questionable behavior.1

Thorough knowledge of the systems and/or programs/Information Asymmetry

This is a serious element because the fraudster will have superior knowledge and/or access to electronic programs and processes.  When the Lead Auditor or Audit Manager has unlimited power through technology to manipulate data, routine monitoring is recommended of how this power is employed.  This is all part of strengthening internal controls through an objective expert.

The Payoff Matrix

According to an article in the National Library of Medicine published September 2023, in the context of healthcare fraud: "The Payoff Matrix refers to a conceptual framework that analyzes the potential outcomes (rewards and penalties) for different actors involved in fraudulent activities within the healthcare system, considering the choices they make between committing fraud or acting honestly, essentially illustrating the potential gains or losses depending on their decision and the actions of other parties involved, like patients, providers, and insurers; it helps visualize the incentives and disincentives that could influence their behavior towards fraudulent practices.”2

This is difficult for the vast number of honest managers to understand because they care deeply for their processes, employers, and, most importantly, people. To the fraudster it is a game; there are winners, there are losers; there are moves and counter-moves. They see the auditors as expendable players rather than victims: and they see superiors and leaders as opposing players who will be beaten and outmaneuvered. In the context of this article, they secure their positions and remain champions of the game, to continue with little thought to their own possible loss.

Detect the Tip of the Iceberg?

Actions to Mitigate Risk

The compliance department must be active, in place and independent in authority and action. If the reader will indulge a few analogies, I will show how critical this section of any organization is. About the iceberg analogy used in this article – the Titanic, the mighty, “unsinkable” ship, cutting edge in every way in its time.  We know on April 14, 1912 the Titanic hit an iceberg and sank igniting one of the most remembered tragedies in history.

Experts disagree on why the ship struck the iceberg but there are recurring theories: poor watch crew alertness and/or training; no binoculars; and they just didn’t see it in time. Things they do agree on: the ship was sailing too fast in known iceberg waters and there were not enough lifeboats.

Your compliance department is like the watch crew - They must look for hazards (watch): search for hazards in the future (binoculars): and have the authority to order the captain to alter course no matter how inconvenient. A compliance department that has become complacent or does not monitor internal controls is ignoring speed: things in healthcare move quickly. Having an ineffective compliance department is like having these lookouts not just make the ship hit the iceberg; they back the ship up and make it hit the iceberg again. Compliance must also be the lifeboats. They need to listen to and address every concern raised and treat all parties equally-no one stands alone because of title or position and the corollary; no one is above scrutiny for the same reasons. And compliance must be trusted to maintain strictest confidentiality. Every individual who reports concerns must feel they will be protected and safe.

The rest of the iceberg

In this image, note the long flat tabletop just below the surface. Managers who commit fraud, especially for their benefit at the cost of everyone else’s, will form some sort of escape route.

They are willing to “take some heat” as long as their fraudulent enterprise survives. The compliance department has to destroy this STAT. If the managers are spoken to but nothing substantial really is done, then they have taken the ship, backed it up, repaired it (so they think) and sent the ship right back into the iceberg.

Invest in Infrastructure & Developing a Culture of Compliance

Your workforce must feel “safe” to report concerns and observations of potential fraud, waste and/or abuse.  This only happens when a top-down culture of compliance has been instilled within the organization and demonstrated by the items listed below.

Responding to complaints must be rapid and effective - Compliance must be several critical things, just like the military: it must be forward yet visible (Air Force). We know they are active and they are watching beyond their office desks. We see them. They also must be agile: able to respond to indications or complaints quickly.  Employees at every level must know these people are there, always gathering information even when unseen and are there to defend them if necessary.

Compliance must also be the Army and Marines - Employees (relators) must know how to report concerns to the compliance department in a safe manner and undetected by the Lead Auditor when the Lead Auditor is of concern. Confidentiality must be the operative philosophy. Like all the major services, they must be able to act independently with the backing of the highest levels of authority. Above all, compliance must dedicate itself to an overarching creed: never let the relator feel scared, threatened, harassed or intimidated. Any form of retaliation will not be tolerated.

Establish a Confidential Network - The Audit Team needs to find an avenue to escalate complaints, confidentially, to those tasked with compliance and especially whistleblower protections. This should be between each auditor and the compliance officer or someone within the Compliance Committee. There really is power in numbers and just like plausible deniability, there will be force in consistency of fact. Because the auditors are external to the auditees, and in the remote environment external to the Audit Managers, information and concerns can be shared and options discussed without fear of harassment, reprisal or retaliation. Facts can be shared and supported by other auditors’ experiences.

This element differs from strengthening internal controls in that the point of contact for concerns need not absolutely be someone tasked with receiving them by policy.

Strengthen Internal Controls - There is no cookie-cutter template for succeeding in this. Whether through complacency, old school ways of thinking or the bureaucracy-wide need for self-preservation and avoidance of “bad news,” weak internal controls have devolved into weakness for a reason. Following right on the heels of getting these people to listen may be getting the auditors to trust them. Our attempts at reporting have failed: why should we trust you now? This is a legitimate question which must be answered before real progress can be made.

Documentation – Over time facts and details can become unclear.  Documenting observations, gathering “evidence” and making record in a timely manner can help determine if the person altering data has made a material falsification requiring a more formal internal (or external) investigation.

Conclusion

The vast majority of healthcare managers are ethical, hard-working people who care about their organization both downward and upward. They are as outraged by fraud or someone on their team manipulating information.  In my experience, the majority of published reporting of mid-level fraud regards financial motivation. If any healthcare organization takes firm and consistent steps to maintain strong internal controls, the type of fraud in this article will never see light and be mitigated before any significant damage can be realized.

Although we have covered quite a number of subjects, the solution will be driven by the establishment of a superstructure founded on ferreting out truth from plausible deniability and weak internal controls. Without these other efforts will yield little.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS. 

References

  1. McCombs School of Business – Ethics Unwrapped https://ethicsunwrapped.utexas.edu/glossary/rationalizations
  2. National Library of Medicine – Study on the Path of Governance in Health Insurance Fraud Considering Moral Hazard https://pmc.ncbi.nlm.nih.gov/articles/PMC10543491/#:~:text=Combating%20health%20insurance%20fraud%20is,toward%20a%20non%2Dfraudulent%20state

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More