Compliance in Healthcare
Corporate Compliance

Creating a Culture of Compliance: Beyond Policies and Procedures

Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

Avoid sanctions, civil monetary penalties and other consequences resulting from lack of developing an ethical culture of compliance throughout all layers of your organization.  This article addresses basic steps to create an effective culture of compliance in a healthcare organization.

Introduction

In today’s evolving healthcare landscape, compliance is not merely about adhering to rules—it's about fostering an organizational mindset grounded in ethics, accountability, and patient-centered care. While policies and procedures are essential, they only work when consistently upheld by a culture that values transparency, collaboration, and integrity.

This article explores the foundations of a compliance-driven culture, offering real-world examples and practical strategies to help healthcare organizations embed compliance into the fabric of daily operations.

Why Policies Alone Are Not Enough

Healthcare organizations often implement robust compliance policies to meet federal and state requirements. However, documented policies without cultural reinforcement can lead to significant risk. In 2022, for example, Sutter Health paid $13 million to resolve allegations that it submitted inaccurate information to Medicare Advantage plans, partly due to documentation practices that didn't align with federal compliance expectations (U.S. Department of Justice, 2022).

This case, like many others, highlights how written policies must be supported by ethical behavior, staff engagement, and a culture where employees understand—and believe in—why compliance matters.

Key Elements of a Compliance-Driven Culture

1. Leadership Accountability 
Compliance starts at the top. Leaders must consistently model ethical decision-making, engage in open dialogue, and take visible ownership of compliance goals. In a 2023 survey by the Health Care Compliance Association (HCCA), 81% of compliance professionals stated that strong executive support is the most critical factor in building a successful compliance culture (HCCA, 2023).

2. Psychological Safety 
Organizations must create environments where employees feel safe reporting concerns. The Office of Inspector General (OIG) stresses that effective compliance programs include confidential reporting mechanisms and non-retaliation policies (OIG, 2023).

A real-world example comes from the University of Miami Health System, which updated its compliance hotline protocol after an internal review revealed staff hesitancy to report incidents anonymously, fearing disciplinary action (Becker’s Hospital Review, 2021).

3. Role-Relevant Training 
Generic training can result in disengagement and minimal knowledge retention. Instead, organizations should provide interactive, role-specific education that integrates real scenarios. For example, front-desk staff may need HIPAA training focused on verbal disclosures, while clinicians require deeper insight into documentation and informed consent.

4. Compliance Champions 
Designating compliance ambassadors within organizations helps reinforce policies through peer modeling and encourages early identification of concerns. Champions can attend monthly briefings, facilitate team discussions, and elevate issues in real time.

The Role of Multidisciplinary Teams

Every discipline within healthcare interacts with compliance differently. A registered nurse may encounter issues with medication documentation, a billing specialist may question coding irregularities, and a social worker may balance confidentiality with mandated reporting.

When these roles operate in silos, important compliance insights can be missed. Organizations like Kaiser Permanente have implemented interdisciplinary compliance councils to bridge communication gaps, share observations, and build mutual understanding across roles (Kaiser Permanente, 2020).

Embedding Compliance in Daily Practice

To make compliance part of daily operations, consider the following:

  • Routine Huddles: Use brief team meetings to explore ethical concerns or clarify unclear procedures.
  • Visual Dashboards: Display progress on compliance goals or audit outcomes to reinforce accountability.
  • Feedback Loops: Encourage staff to anonymously share observations or suggest improvements.
  • Ethical Storytelling: Share lessons from real incidents (redacted) to show the practical impact of compliance success—or failure.

Common Barriers and Solutions

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Burnout and compassion fatigue

Integrate wellness and compliance initiatives. Emphasize that well-rested staff are more alert and compliant.

Fear of retaliation

Publicly reinforce non-retaliation policies. Offer leadership training on how to handle reports respectfully.

Check-the-box mentality

Break trainings into micro-learning modules with real examples. Make them interactive.

Siloed communication

Establish interdepartmental compliance committees or shared reporting tools.

Measuring a Healthy Compliance Culture

A balanced approach includes both measurable data and lived experiences. Indicators include:

  • Quantitative: Hotline usage trends, audit compliance scores, time-to-resolution metrics for reported issues.
  • Qualitative: Team members openly discuss compliance, seek clarification without hesitation, and share real-time feedback with leadership.

For example, Johns Hopkins Medicine publishes an internal compliance scorecard and encourages departments to review and discuss the results in staff meetings (Johns Hopkins Compliance Office, 2023).

Conclusion

An effective compliance program is more than documentation—it’s a culture shaped by people, reinforced through daily actions, and supported by intentional leadership. As healthcare systems face increasing regulatory scrutiny and public accountability, building a compliance culture is no longer optional. It’s a strategic imperative that protects both patients and providers.

Organizations that succeed in this space do so not by fear or formality, but by fostering an environment where doing the right thing is encouraged, expected, and consistently practiced across all disciplines.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Understanding Whistleblower Protections in Healthcare

Legal Obligations and Compliance Implications  


Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

The government’s new whistleblower complaint portal launched in April 2025 emphasizes the importance of complying with regulations related to qui tam suits, OCR investigations and protecting the rights of employees submitting a tip or complaint internally or to authorities. This article illustrates how certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation.

Introduction

Healthcare compliance professionals are often the first line of defense when systems break down. Understanding the interplay between legal protections and organizational ethics is vital—not only to ensure legal compliance, but also to foster environments where staff feel empowered and safe to report misconduct.

Whistleblowers are critical to protecting the integrity of healthcare delivery. When individuals report unsafe care, fraudulent billing, privacy violations, or ethical concerns, they help ensure accountability, uphold regulatory compliance, and safeguard patient welfare. For compliance professionals—particularly those working in environments regulated by Medicare, Medicaid, HIPAA, and federal contracts—it is essential to understand the scope and implications of whistleblower protections under current U.S. law.

This article explores the legal framework that underpins whistleblower protections, including the False Claims Act (FCA), HIPAA Privacy Rule exceptions, and National Defense Authorization Act (NDAA) provisions. It also highlights recent federal developments and compliance best practices to foster a culture of transparency and non-retaliation.

The False Claims Act and Qui Tam Provisions

For compliance departments, the implications of Qui Tam lawsuits extend far beyond financial penalties. They can lead to reputational harm, loss of patient trust, and stricter regulatory scrutiny. Therefore, proactive compliance programs must include regular audits, anonymous reporting options, and a culture that encourages early identification of potential violations.

The False Claims Act (31 U.S.C. §§ 3729–3733) is the federal government’s primary tool for combating fraud against public programs. Healthcare fraud accounts for a significant portion of FCA activity. Under its Qui Tam provision, private citizens—known as “relators”—can file lawsuits on behalf of the government when they have direct knowledge of fraudulent activities, such as billing for services not rendered or providing substandard care reimbursed by federal programs.

When the Department of Justice (DOJ) intervenes in these cases, whistleblowers may receive 15%–30% of recovered funds as a reward. In 2023 alone, the DOJ recovered over $1.8 billion from healthcare-related FCA cases, with whistleblower suits representing the vast majority of those recoveries.

Importantly, the FCA also prohibits retaliation. Section 3730(h) protects whistleblowers from termination, demotion, suspension, or harassment due to lawful acts in furtherance of a Qui Tam action or efforts to stop violations of the FCA.

HIPAA and Whistleblower Disclosures

Healthcare entities must train their workforce on the specific conditions under which PHI disclosures are permissible. Internal policies should not only comply with HIPAA but clarify what constitutes a 'good faith belief' and ensure disclosures are directed to appropriate oversight entities.

While the Health Insurance Portability and Accountability Act (HIPAA) is typically associated with patient privacy, it also contains important exceptions that protect whistleblowers. Under 45 CFR § 164.502(j), a workforce member may disclose protected health information (PHI) if:

  1. They believe in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates clinical standards; and
  2. The disclosure is made to a healthcare oversight agency, public health authority, law enforcement agency, attorney, or accreditation organization.

This clause is critical for compliance officers to understand, especially when investigating disclosures involving PHI. Any internal policy must clearly explain the scope of permissible disclosures and educate staff on when HIPAA permits these exceptions.

NDAA Protections and the Role of Contractors

The National Defense Authorization Act (NDAA) of 2013 (41 U.S.C. § 4712) expanded whistleblower protections to employees of federal contractors, grantees, and subcontractors, which includes many healthcare providers receiving federal funds. Under this statute, employees are protected from reprisal for reporting gross mismanagement, fraud, abuse of authority, or dangers to public health and safety.

Notably, these protections apply even if the employee discloses information outside of the organization, including to Congress, an Inspector General, or a federal employee responsible for contract oversight.

Compliance officers working with contractors should incorporate NDAA requirements into onboarding and ethics training materials. Additionally, contract language should affirm non-retaliation protections and clarify processes for raising concerns externally.

Recent Developments: HHS Whistleblower Portal and Enforcement

On April 14, 2025, the U.S. Department of Health and Human Services (HHS) launched a new whistleblower complaint portal specifically designed to receive reports of potential harm to children, including medically controversial treatments involving minors.

This new government portal signals increased federal oversight in how healthcare institutions respond to ethical and religious concerns raised by employees and demonstrates the government’s increased commitment to ensuring that providers and institutions uphold safety, informed consent, and respect for medical ethics.

This tool may also be used to identify systemic gaps in institutional policies around consent, safety, and staff protections.

In a notable case publicized by HHS, a hospital faced sanctions for terminating a nurse who refused to participate in a pediatric procedure due to her religious beliefs. HHS concluded that the hospital violated federal conscience protections, highlighting the intersection of whistleblower law, employment rights, and provider conscience protections.

Such scenarios highlight the importance of thorough documentation and timely response by compliance departments. Independent reviews of whistleblower complaints, performed by third-party investigators or ombudspersons, can enhance transparency and fairness in case handling.

Consider a hypothetical but realistic scenario

  • A behavioral health technician reports unsafe restraint practices involving minors in a residential facility.
  • Shortly after filing the internal report, the technician is placed on administrative leave and subsequently terminated.
  • The technician files a complaint under both the FCA and state labor law.
  • The investigation reveals that internal reports were not documented properly, retaliation safeguards were not in place, and training on non-retaliation was outdated.

This case underscores the need for compliance programs to ensure proactive risk mitigation, thorough documentation, and a robust culture of safety and transparency.

The Compliance Officer’s Role: Promoting a Speak-Up Culture

Organizations should periodically evaluate the effectiveness of their whistleblower protection efforts through anonymous staff surveys, incident response audits, and tracking the outcomes of reported concerns. This proactive approach signals to staff that leadership values integrity and transparency.

Certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation. Organizations must go beyond policy documents and invest in cultural and procedural safeguards:

- Establish and communicate clear non-retaliation policies.
- Train all employees and leadership on reporting rights and retaliation indicators.
- Maintain multiple confidential channels for reporting concerns.
- Ensure prompt and fair investigation of all complaints.
- Audit for compliance with whistleblower protection policies.

Conclusion

Ultimately, the goal of any whistleblower protection program is not merely compliance, but the cultivation of an ethical culture that consistently does what is right—even when it is inconvenient or uncomfortable. This requires leadership buy-in, staff empowerment, and a long-term commitment to transparency.

Whistleblower protections are more than legal requirements—they are pillars of ethical healthcare. Laws like the FCA, HIPAA, and NDAA empower individuals to report wrongdoing without fear. Compliance professionals must champion these safeguards, not only to avoid legal liability but to protect patient welfare, support employee integrity, and sustain organizational trust.

As regulatory enforcement intensifies and new federal protections emerge, healthcare organizations must remain vigilant, proactive, and transparent. The call to protect whistleblowers is not just a mandate—it is a moral and professional imperative.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance.  Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • U.S. Department of Health and Human Services (HHS). (2025). New Whistleblower Guidance and Complaint Portal. Retrieved from https://www.hhs.gov/protect-kids
  • 31 U.S.C. §§ 3729–3733, False Claims Act (FCA).
  • 31 U.S.C. § 3730(h), Anti-Retaliation Protections under the FCA.
  • 45 CFR § 164.502(j), Whistleblower Disclosures under the HIPAA Privacy Rule.
  • National Defense Authorization Act (NDAA) of 2013, 41 U.S.C. § 4712.
  • Office for Civil Rights (OCR), HHS. (2025). Press release on hospital investigation, April 14, 2025.
  • American Institute of Healthcare Compliance (AIHC). (2025). Newsblast: New Whistleblower Complaint Portal.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

You Play a Vital Role in Protecting the Integrity of the U.S. Healthcare System

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The U.S. health care system relies heavily on third-party payers to pay the majority of medical bills on behalf of patients. Health care insurance fraud is a pressing problem, causing substantial and increasing costs in medical insurance programs. To combat fraud and abuse, all levels within a medical practice, hospital or health care organization must know how to protect the organization from engaging in abusive practices and violations of civil or criminal laws.


If you are a health care provider, remember that payers trust you to provide medically necessary, cost-effective, quality care. You exert significant influence over what services your patients get. You control the documentation describing services they receive, and your documentation serves as the basis for claims you submit. Generally, the health care system pays claims based solely on your representations in the claims documents.


When the federal government covers items or services rendered to Medicare and Medicaid beneficiaries, the federal fraud and abuse laws apply. Many similar state fraud and abuse laws apply to your provision of care under state-financed programs and to private-pay patients. The most important federal fraud and abuse laws that apply to healthcare are the:

  1. False Claims Act (FCA);
  2. Anti-Kickback Statute (AKS);
  3. Physician Self-Referral Law (Stark Law);
  4. United States Criminal Code
  5. Exclusion Authorities; and
  6. Civil Monetary Penalties Law (CMPL).

Implementing a successful compliance program not only assists in protecting your organization but individuals within the organization. It is crucial for providers, coders and billers to understand these laws not only because following them is the right thing to do but also because violating them could result in criminal penalties, civil fines, exclusion from the federal health care programs or loss of your medical license from your state medical board.


Government programs, such as the Centers for Medicare & Medicaid Services (CMS), find the investment in their audit and monitoring programs are effective. CMS announced in the fall of 2021 that their aggressive corrective actions led to an estimated $20.72 billion reduction of Medicare Fee-for-Service (FFS) improper payments over seven years.


When you submit a claim for services provided to a Medicare beneficiary, you are filing a bill with the federal government and certifying you earned the payment requested and complied with the billing requirements. If you knew or should have known the submitted claim was false, then the attempt to collect payment is illegal.


When an organization fails to provide training and education to deter and detect fraud and/or abuse, it is likely to be detected by an outside investigative source via action such as:

  • Focused audit by the payer due to detection of suspect billing patterns when compared to your peers;
  • Routine audits conducted by the payer, such as Medicare’s Comprehensive Error Rate Testing (CERT); and
  • Internal whistleblower or qui tam action.

Internal auditing and monitoring programs are essential to keeping medical records and billing accurate. However, a routine internal billing and documentation review could turn into a more focused internal investigation. During that investigation, is it possible that an aberrant pattern of inappropriate billing is revealed? Do you know how to proceed if this happens?


First, remember that anyone can commit health care fraud. Fraud schemes range from solo ventures to widespread activities by an institution or group. Your organization should have a designated Compliance Officer. Audit professionals should have the authority to report potential fraud and abuse situations directly to the Compliance Officer for further investigation and resolution.


Problem areas brought to the attention of the Compliance Officer should also be included in corrective action training programs to avoid the continuation of the situation. One of the most important aspects of a compliance program is training and education at all levels of the organization.


Now, let’s talk more about qui tam action. There are five potential areas in which qui tam cases arise related to Medicare or Medicaid claims and the False Claims Act (“FCA”). Qui tam claims involving Medicaid/Medicare healthcare vary, depending on the level of care needed and provided. Categories often involve allegations of total neglect or no services, worthless services, inadequate and inferior services and products, and aggressive patient treatment. Other areas of fraud involve misrepresentation of credentials, upcoding of services, unbundling of services, and misrepresentation of patient data or populations.


Words of Advice


Maintain accurate and complete medical records and documentation of the services you provide.

  • Ensure your documentation supports the claims you submit for payment. Good documentation practices help to ensure your patients get appropriate care and allow other providers to rely on your records for patients’ medical histories.

Anytime a health care business offers you something for free or below fair market value, ask yourself, “Why?”

  • Remember, when a vendor or consultant provides coding and billing advice, the provider filing the claim is responsible for the accuracy of that claim. Be suspicious when you are told that a huge enhancement of revenue will be realized if you bill like this . . .

Get expert advice from a qualified source before investing or getting into a joint venture.

  • Some physicians who invest in health care business ventures with outside parties, such as imaging centers, laboratories, equipment vendors, or physical therapy clinics, may refer more patients for the services provided by those parties than physicians who do not invest. These business relationships may improperly influence or distort physician decision-making and result in the improper steering of patients to a therapy or service where a physician has a financial interest. Arrangements could be viewed as illegal.

Avoid illegal incentives to join a hospital’s community.

  • A hospital may pay you a fair market-value salary as an employee or pay you fair market value for specific services you render to the hospital as an independent contractor. However, the hospital may not offer you money, provide you free or below-market rent for your medical office, or engage in similar activities designed to influence your referral decisions.
  • Admit your patients to the hospital best suited to care for their medical conditions or to the hospital your patients select based on their preference or insurance coverage.

Don’t sell free product samples.

  • Many drug/biologic companies provide free product samples to physicians. It is legal to give these samples to your patients free of charge, but it is illegal to sell the samples.
  • The federal government has prosecuted physicians for billing Medicare for free samples.
  • If you choose to accept free samples, you need reliable systems in place to safely store the samples and ensure samples remain separate from your commercial stock.

Relationships with the pharmaceutical and medical device companies

  • As a practicing physician, you may have opportunities to work as a consultant or promotional speaker for the drug or device industry. For every financial relationship offered to you, evaluate the link between the services you can provide and the compensation you will get. Test the appropriateness of any proposed relationship by asking yourself the following questions and when in doubt, get legal advice: o Does the company really need your specific expertise or input? o Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services? o Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?

o  Does the company really need your specific expertise or input?

o  Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services?

o  Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?


Educate C-Suite and Compliance Officials in Your Company


An executive, top-down approach is required for a successful compliance program. The following seven components provide a solid basis for a compliance program:


1. Conduct internal monitoring and auditing

2. Implement compliance and practice standards

3. Designate a compliance officer or contact

4. Conduct appropriate training and education

5. Respond appropriately to detected offenses and develop corrective action

6. Develop open lines of communication with employees

7. Enforce disciplinary standards through well-publicized guidelines


Establishing and following a compliance program helps health care providers avoid fraudulent activities and submit accurate claims. However, implementing mechanisms to develop a culture of compliance requires educating high-level influencers within your organization. 


Suggest C-Suite executives take online training in healthcare Corporate Compliance.

Require your Compliance Officer, Chief Executive Officer and Chief Financial Officer to become certified not only in Compliance, but in Auditing for Compliance and Conducting Internal Investigations.


Joanne Byron is the Board Chair and Chief Executive Officer of the American Institute of Healthcare Compliance (AIHC) with more than 35 years of health care coding, documentation, billing and compliance experience as a consultant, health care executive and corporate trainer. Learn more about AIHC, a 501(c)(3) non-profit training organization, today.  

Read More