Compliance in Healthcare
Corporate Compliance

10 Common Mistakes in Internal Investigations

And How to Avoid Them Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

Internal investigations are among the most sensitive and consequential activities within a healthcare compliance program. A single misstep can compromise objectivity, violate confidentiality, or weaken the organization’s legal position.

This article draws directly from the American Institute of Healthcare Compliance (AIHC) Certified Internal Forensic Healthcare Auditor (CIFHA) course section on Accepting the Investigation, offering practical insights into how compliance professionals can avoid the ten most common mistakes that undermine investigative credibility. By recognizing and mitigating bias, maintaining procedural rigor, and aligning with regulatory expectations, investigators can uphold integrity, transparency, and trust throughout the process.

Introduction

Accepting an investigation is one of the most critical phases of the investigative process. It sets the tone for impartiality, credibility, and compliance alignment. According to the Office of Inspector General’s 2023 guidance, healthcare organizations should ensure that all investigations are handled promptly, independently, and in a manner that promotes accurate fact-finding and appropriate corrective action.

The U.S. Department of Justice (DOJ) echoes this standard, emphasizing that organizations must demonstrate a “culture of compliance” through objective internal inquiry and documentation of remedial steps.

Yet, even experienced compliance professionals can make procedural or ethical missteps that jeopardize outcomes. From failing to define the scope to letting personal bias color the process, each mistake introduces risk—not only to the credibility of the investigation but also to the organization’s standing with regulators. Accepting the Investigation is the first critical step to understand how to recognize these pitfalls and establish a disciplined, unbiased approach.

Ten Common Mistakes in Internal Investigations—and How to Avoid Them

1.   Failing to Define Scope Clearly 

A well-defined scope sets boundaries and expectations. Without it, investigators risk “mission creep”—expanding beyond the original allegations and diluting focus. According to the Health Care Compliance Association (HCCA, 2024), scope definition should occur immediately upon assignment and be approved by compliance leadership. Avoid this mistake by drafting a clear investigative plan that identifies issues, potential evidence sources, and expected deliverables.

2.   Allowing Personal Bias to Influence Judgment

Bias can undermine objectivity, even when unintentional. Investigators may have preconceived notions about the individuals involved or the departments under review. According to the Association of Certified Fraud Examiners 2024 report, confirmation bias is one of the most common cognitive errors in fraud examinations. To mitigate this risk, investigators are encouraged to use a standardized evaluation framework, rely on documented evidence, and involve a peer reviewer when feasible.

3.   Neglecting to Secure Evidence Early

Delays in securing documentation, emails, or system access logs can result in data alteration or loss. Early preservation is critical for maintaining evidentiary integrity. The DOJ’s guidance on corporate investigations recommends issuing immediate document preservation notices and maintaining a clear chain of custody. Compliance officers should coordinate promptly with IT, HR, and legal counsel to secure relevant records.

4.   Ignoring Chain-of-Custody Procedures

Even if evidence is obtained, failure to maintain proper chain-of-custody documentation can render it unreliable. Investigators must track who collected each item, when, and under what conditions. This process ensures credibility in both internal reviews and external proceedings. Adhering to established forensic documentation procedures, such as those outlined in the AIHC Investigations training, protects evidence integrity and supports defensible reporting.

5.   Failing to Document Interviews Accurately

Interview summaries form the backbone of many investigations. Inaccurate or incomplete notes can lead to inconsistent conclusions. According to OIG compliance best practices, investigators should use structured templates, record factual statements, and avoid subjective language. Review notes immediately after interviews to ensure accuracy while details are fresh, and maintain them as part of the official investigation record.

6.   Overlooking Confidentiality Protocols

Breaching confidentiality can compromise employee trust and expose the organization to liability. Investigators should disclose only essential information on a need-to-know basis. The OIG’s 2023 General Compliance Program Guidance recommends protecting the identities of whistleblowers and limiting discussion of investigative matters to authorized personnel. Reinforce confidentiality expectations at the outset of every interview.

7.   Mismanaging Communication with Legal Counsel

Failure to coordinate properly with legal counsel can result in privilege issues or inconsistent messaging to regulators. Investigators should engage counsel early in the process, particularly when there is potential for self-disclosure or legal exposure. Counsel can help preserve attorney-client privilege and guide how findings are shared externally.

8.   Failing to Distinguish Between Facts and Assumptions

Investigations must rely on verifiable facts rather than assumptions or opinions. Mistaking interpretation for evidence can erode the report’s credibility. Investigators should clearly separate facts, analysis, and conclusions in their notes and reports. According to Compliance Week (2023), factual accuracy is the single most important determinant of whether an investigative report is considered defensible under regulatory review.

9.   Rushing to Conclusions or Recommendations

Pressure to conclude quickly can lead to incomplete analysis or unjustified findings. The CIFHA curriculum emphasizes patience and thorough review—investigators should evaluate all available data and corroborate key points before finalizing conclusions. Interim summaries and peer reviews can provide checkpoints for accuracy and completeness.

10.  Neglecting Follow-Up and Corrective Actions

An investigation is incomplete if it fails to lead to corrective action. According to the Government Accountability Office’s 2023 Fraud Risk Management Framework, closure should include documented remediation steps, training updates, and monitoring plans. Compliance officers should track outcomes to ensure identified risks are addressed and similar issues do not recur.

Building Investigative Integrity: Best Practices

The American Institute of Healthcare Compliance emphasizes that the credibility of an investigation depends on procedural rigor, ethical consistency, and adherence to compliance principles. Best practices include maintaining neutrality, engaging legal counsel early, and ensuring every step—from planning to reporting—is supported by clear documentation. Investigators should continuously assess their own potential biases and seek peer consultation when objectivity might be compromised.

Other proven strategies include developing investigation charters, maintaining secure digital evidence repositories, and conducting post-investigation debriefings. These steps not only enhance transparency but also create a feedback loop that improves organizational learning.

Conclusion

Conducting a compliant and credible internal investigation requires planning, impartiality, and discipline.

Each of the ten mistakes outlined above can erode trust and expose an organization to risk if not proactively addressed. By integrating appropriate protocols in your investigative framework, healthcare professionals can ensure investigations are fair, defensible, and aligned with regulatory expectations.  When investigators accept assignments with integrity and preparedness, they transform investigations from reactive responses into proactive tools for organizational improvement and compliance maturity.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • U.S. Department of Justice (DOJ). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Health Care Compliance Association (HCCA). (2024). Best Practices for Internal Investigations.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Compliance Week. (2023). Maintaining Objectivity in Internal Investigations.
  • Deloitte. (2024). Emerging Trends in Healthcare Investigations.
  • Office of Inspector General (OIG). (2023). Compliance Program Effectiveness Resource Guide.
  • U.S. Department of Health and Human Services (HHS). (2024). Healthcare Fraud Prevention and Enforcement Action Team (HEAT) Report.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Coding Integrity and CAC

Why Quality Must Precede Compliance in Healthcare Documentation   

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE   

Computer-Assisted Coding, better known as “CAC” has become the norm over the past decade, but are we producing compliant, accurate results?  Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less, which is the reason for this article.

Introduction

In today’s fast-paced healthcare environment, coding accuracy is often caught in the crossfire between compliance pressures, productivity demands, and evolving technology. While documentation may be clinically sound, coding associated with documentation can be misaligned or inaccurate, particularly when it is generated by CAC tools.  CAC can trigger regulatory scrutiny, revenue cycle inefficiencies, and reputational risk without verification by an experienced coding first. As a compliance specialist and educator, I contend that quality cannot be compromised for speed or convenience. In fact, quality is the cornerstone of compliance.

Healthcare consultants recently noted that “documentation is often accurate, but the coding is not,” underscoring a critical gap in the way organizations approach their revenue cycle and risk management. This article explores the current landscape of coding discrepancies, the limitations and risks of CAC, and the essential need for robust internal review processes.

The Disconnect Between Documentation and Coding

In many provider organizations, clinical documentation accurately reflects the patient’s story—diagnoses, treatments, and provider decision-making—but coding processes fall short. Coders may misinterpret documentation, overlook nuances, or rely too heavily on automation, leading to miscoded encounters that can have ripple effects across billing, audit, and quality reporting systems. When errors go undetected, the result can be upcoded services, denied claims, compliance violations, and patient safety concerns. According to the Office of Inspector General (OIG), improper payments stemming from inaccurate coding continue to plague the Medicare program, costing billions annually (OIG, 2023).

CAC: A Double-Edged Sword

Computer-assisted coding (CAC) software, designed to improve speed and efficiency, is now a common fixture in health information management. While these systems can process large volumes of data quickly, their reliance on algorithms rather than clinical reasoning poses significant challenges.

Research has shown that CAC tools may struggle to interpret context, such as distinguishing between active and historical conditions, or differentiating provider impressions from definitive diagnoses (AHIMA, 2022). Without skilled human oversight, these limitations result in critical coding inaccuracies. Unfortunately, some healthcare systems mistakenly treat CAC outputs as final codes without sufficient validation.

Quality needs to be the focus to meet compliance standards. CAC should be a tool to enhance human accuracy—not replace it.

Compliance Risks from Coding Discrepancies

Coding discrepancies—particularly those uncorrected in CAC workflows—are not simply operational issues; they are compliance risks. Auditors from CMS, OIG, and commercial payers increasingly target mismatches between documentation and billing codes. These discrepancies may be flagged as potential fraud, waste, or abuse.  Examples of common coding problems that trigger scrutiny include:

  • Upcoding or down coding visits that do not align with documentation
  • Inaccurate diagnosis coding affecting risk adjustment
  • Use of unspecified or non-supported codes
  • Failure to reflect clinical severity accurately

The DOJ's increased enforcement under the False Claims Act often centers on patterns of poor coding oversight. Healthcare entities must demonstrate that they are taking proactive steps to ensure coding integrity.

Quality as a Compliance Imperative

Ensuring the integrity of clinical coding isn’t just about reimbursement—it’s about compliance, patient care quality, and data accuracy. As healthcare moves toward value-based models, accurate coding supports correct risk adjustment, patient attribution, and performance measurement.

Implementing regular coding reviews, especially of CAC-assisted encounters, is a best practice that healthcare experts recommend. These reviews should be multidisciplinary, involving coding professionals, clinicians, and compliance officers. They help:

  • Identify patterns of misinterpretation or misclassification
  • Provide targeted coder education and clinical documentation improvement (CDI)
  • Verify whether CAC algorithms need adjustment or replacement

Quality assurance activities are not optional—they are essential to both ethical billing and regulatory compliance.

Balancing Productivity Pressures with Accuracy

It is well understood that providers are under immense pressure to manage high volumes of patients while fulfilling extensive documentation requirements. These constraints often lead to documentation fatigue and over-reliance on templated language or CAC tools.  However, automation cannot replace clinical judgment or attention to detail. Coders must be trained to spot subtle inconsistencies and to understand that their role is pivotal in compliance integrity. Likewise, providers need CDI support that makes documentation more efficient and accurate—not more burdensome.

Healthcare leaders should prioritize investments in coder training, CDI collaboration, and coding audits rather than shortcutting review processes for the sake of productivity.

Recommendations for Compliance-Driven Coding Integrity

To address the systemic risks tied to coding discrepancies and CAC errors, organizations should implement the following:

  1. Routine Internal Coding Audits: Conduct monthly or quarterly reviews of randomly selected encounters, with particular focus on high-risk services.
  2. Coder & Provider Education: Offer ongoing training on documentation standards, code selection, and regulatory updates.
  3. Review of CAC Outputs: Routinely validate CAC-generated codes against documentation. Never treat CAC outputs as final.
  4. Real-Time Feedback Loops: Encourage communication between CDI specialists, coders, and providers to resolve discrepancies quickly.
  5. Compliance-Focused KPI Tracking: Monitor error rates, denial trends, and audit findings to identify areas needing improvement.

Conclusion

Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less.

Automation cannot replace accountability.

Compliance leaders must treat quality assurance and coding integrity as non-negotiable pillars of risk management. Let us not allow convenience to compromise compliance. Instead, let quality lead the way.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  1. American Health Information Management Association (AHIMA). (2022). The Realities of Computer-Assisted Coding. Retrieved from https://www.ahima.org
  2. Office of Inspector General (OIG). (2023). Medicare Improper Payment Reports. Retrieved from https://oig.hhs.gov
  3. Centers for Medicare & Medicaid Services (CMS). (2024). Evaluation and Management Services Guide. Retrieved from https://www.cms.gov
  4. U.S. Department of Justice. (2023). False Claims Act Settlements and Judgments Exceed $2 Billion in Fiscal Year 2023. Retrieved from https://www.justice.gov/opa/pr

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Creating a Culture of Compliance: Beyond Policies and Procedures

Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

Avoid sanctions, civil monetary penalties and other consequences resulting from lack of developing an ethical culture of compliance throughout all layers of your organization.  This article addresses basic steps to create an effective culture of compliance in a healthcare organization.

Introduction

In today’s evolving healthcare landscape, compliance is not merely about adhering to rules—it's about fostering an organizational mindset grounded in ethics, accountability, and patient-centered care. While policies and procedures are essential, they only work when consistently upheld by a culture that values transparency, collaboration, and integrity.

This article explores the foundations of a compliance-driven culture, offering real-world examples and practical strategies to help healthcare organizations embed compliance into the fabric of daily operations.

Why Policies Alone Are Not Enough

Healthcare organizations often implement robust compliance policies to meet federal and state requirements. However, documented policies without cultural reinforcement can lead to significant risk. In 2022, for example, Sutter Health paid $13 million to resolve allegations that it submitted inaccurate information to Medicare Advantage plans, partly due to documentation practices that didn't align with federal compliance expectations (U.S. Department of Justice, 2022).

This case, like many others, highlights how written policies must be supported by ethical behavior, staff engagement, and a culture where employees understand—and believe in—why compliance matters.

Key Elements of a Compliance-Driven Culture

1. Leadership Accountability 
Compliance starts at the top. Leaders must consistently model ethical decision-making, engage in open dialogue, and take visible ownership of compliance goals. In a 2023 survey by the Health Care Compliance Association (HCCA), 81% of compliance professionals stated that strong executive support is the most critical factor in building a successful compliance culture (HCCA, 2023).

2. Psychological Safety 
Organizations must create environments where employees feel safe reporting concerns. The Office of Inspector General (OIG) stresses that effective compliance programs include confidential reporting mechanisms and non-retaliation policies (OIG, 2023).

A real-world example comes from the University of Miami Health System, which updated its compliance hotline protocol after an internal review revealed staff hesitancy to report incidents anonymously, fearing disciplinary action (Becker’s Hospital Review, 2021).

3. Role-Relevant Training 
Generic training can result in disengagement and minimal knowledge retention. Instead, organizations should provide interactive, role-specific education that integrates real scenarios. For example, front-desk staff may need HIPAA training focused on verbal disclosures, while clinicians require deeper insight into documentation and informed consent.

4. Compliance Champions 
Designating compliance ambassadors within organizations helps reinforce policies through peer modeling and encourages early identification of concerns. Champions can attend monthly briefings, facilitate team discussions, and elevate issues in real time.

The Role of Multidisciplinary Teams

Every discipline within healthcare interacts with compliance differently. A registered nurse may encounter issues with medication documentation, a billing specialist may question coding irregularities, and a social worker may balance confidentiality with mandated reporting.

When these roles operate in silos, important compliance insights can be missed. Organizations like Kaiser Permanente have implemented interdisciplinary compliance councils to bridge communication gaps, share observations, and build mutual understanding across roles (Kaiser Permanente, 2020).

Embedding Compliance in Daily Practice

To make compliance part of daily operations, consider the following:

  • Routine Huddles: Use brief team meetings to explore ethical concerns or clarify unclear procedures.
  • Visual Dashboards: Display progress on compliance goals or audit outcomes to reinforce accountability.
  • Feedback Loops: Encourage staff to anonymously share observations or suggest improvements.
  • Ethical Storytelling: Share lessons from real incidents (redacted) to show the practical impact of compliance success—or failure.

Common Barriers and Solutions

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Burnout and compassion fatigue

Integrate wellness and compliance initiatives. Emphasize that well-rested staff are more alert and compliant.

Fear of retaliation

Publicly reinforce non-retaliation policies. Offer leadership training on how to handle reports respectfully.

Check-the-box mentality

Break trainings into micro-learning modules with real examples. Make them interactive.

Siloed communication

Establish interdepartmental compliance committees or shared reporting tools.

Measuring a Healthy Compliance Culture

A balanced approach includes both measurable data and lived experiences. Indicators include:

  • Quantitative: Hotline usage trends, audit compliance scores, time-to-resolution metrics for reported issues.
  • Qualitative: Team members openly discuss compliance, seek clarification without hesitation, and share real-time feedback with leadership.

For example, Johns Hopkins Medicine publishes an internal compliance scorecard and encourages departments to review and discuss the results in staff meetings (Johns Hopkins Compliance Office, 2023).

Conclusion

An effective compliance program is more than documentation—it’s a culture shaped by people, reinforced through daily actions, and supported by intentional leadership. As healthcare systems face increasing regulatory scrutiny and public accountability, building a compliance culture is no longer optional. It’s a strategic imperative that protects both patients and providers.

Organizations that succeed in this space do so not by fear or formality, but by fostering an environment where doing the right thing is encouraged, expected, and consistently practiced across all disciplines.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Understanding Whistleblower Protections in Healthcare

Legal Obligations and Compliance Implications  


Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

The government’s new whistleblower complaint portal launched in April 2025 emphasizes the importance of complying with regulations related to qui tam suits, OCR investigations and protecting the rights of employees submitting a tip or complaint internally or to authorities. This article illustrates how certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation.

Introduction

Healthcare compliance professionals are often the first line of defense when systems break down. Understanding the interplay between legal protections and organizational ethics is vital—not only to ensure legal compliance, but also to foster environments where staff feel empowered and safe to report misconduct.

Whistleblowers are critical to protecting the integrity of healthcare delivery. When individuals report unsafe care, fraudulent billing, privacy violations, or ethical concerns, they help ensure accountability, uphold regulatory compliance, and safeguard patient welfare. For compliance professionals—particularly those working in environments regulated by Medicare, Medicaid, HIPAA, and federal contracts—it is essential to understand the scope and implications of whistleblower protections under current U.S. law.

This article explores the legal framework that underpins whistleblower protections, including the False Claims Act (FCA), HIPAA Privacy Rule exceptions, and National Defense Authorization Act (NDAA) provisions. It also highlights recent federal developments and compliance best practices to foster a culture of transparency and non-retaliation.

The False Claims Act and Qui Tam Provisions

For compliance departments, the implications of Qui Tam lawsuits extend far beyond financial penalties. They can lead to reputational harm, loss of patient trust, and stricter regulatory scrutiny. Therefore, proactive compliance programs must include regular audits, anonymous reporting options, and a culture that encourages early identification of potential violations.

The False Claims Act (31 U.S.C. §§ 3729–3733) is the federal government’s primary tool for combating fraud against public programs. Healthcare fraud accounts for a significant portion of FCA activity. Under its Qui Tam provision, private citizens—known as “relators”—can file lawsuits on behalf of the government when they have direct knowledge of fraudulent activities, such as billing for services not rendered or providing substandard care reimbursed by federal programs.

When the Department of Justice (DOJ) intervenes in these cases, whistleblowers may receive 15%–30% of recovered funds as a reward. In 2023 alone, the DOJ recovered over $1.8 billion from healthcare-related FCA cases, with whistleblower suits representing the vast majority of those recoveries.

Importantly, the FCA also prohibits retaliation. Section 3730(h) protects whistleblowers from termination, demotion, suspension, or harassment due to lawful acts in furtherance of a Qui Tam action or efforts to stop violations of the FCA.

HIPAA and Whistleblower Disclosures

Healthcare entities must train their workforce on the specific conditions under which PHI disclosures are permissible. Internal policies should not only comply with HIPAA but clarify what constitutes a 'good faith belief' and ensure disclosures are directed to appropriate oversight entities.

While the Health Insurance Portability and Accountability Act (HIPAA) is typically associated with patient privacy, it also contains important exceptions that protect whistleblowers. Under 45 CFR § 164.502(j), a workforce member may disclose protected health information (PHI) if:

  1. They believe in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates clinical standards; and
  2. The disclosure is made to a healthcare oversight agency, public health authority, law enforcement agency, attorney, or accreditation organization.

This clause is critical for compliance officers to understand, especially when investigating disclosures involving PHI. Any internal policy must clearly explain the scope of permissible disclosures and educate staff on when HIPAA permits these exceptions.

NDAA Protections and the Role of Contractors

The National Defense Authorization Act (NDAA) of 2013 (41 U.S.C. § 4712) expanded whistleblower protections to employees of federal contractors, grantees, and subcontractors, which includes many healthcare providers receiving federal funds. Under this statute, employees are protected from reprisal for reporting gross mismanagement, fraud, abuse of authority, or dangers to public health and safety.

Notably, these protections apply even if the employee discloses information outside of the organization, including to Congress, an Inspector General, or a federal employee responsible for contract oversight.

Compliance officers working with contractors should incorporate NDAA requirements into onboarding and ethics training materials. Additionally, contract language should affirm non-retaliation protections and clarify processes for raising concerns externally.

Recent Developments: HHS Whistleblower Portal and Enforcement

On April 14, 2025, the U.S. Department of Health and Human Services (HHS) launched a new whistleblower complaint portal specifically designed to receive reports of potential harm to children, including medically controversial treatments involving minors.

This new government portal signals increased federal oversight in how healthcare institutions respond to ethical and religious concerns raised by employees and demonstrates the government’s increased commitment to ensuring that providers and institutions uphold safety, informed consent, and respect for medical ethics.

This tool may also be used to identify systemic gaps in institutional policies around consent, safety, and staff protections.

In a notable case publicized by HHS, a hospital faced sanctions for terminating a nurse who refused to participate in a pediatric procedure due to her religious beliefs. HHS concluded that the hospital violated federal conscience protections, highlighting the intersection of whistleblower law, employment rights, and provider conscience protections.

Such scenarios highlight the importance of thorough documentation and timely response by compliance departments. Independent reviews of whistleblower complaints, performed by third-party investigators or ombudspersons, can enhance transparency and fairness in case handling.

Consider a hypothetical but realistic scenario

  • A behavioral health technician reports unsafe restraint practices involving minors in a residential facility.
  • Shortly after filing the internal report, the technician is placed on administrative leave and subsequently terminated.
  • The technician files a complaint under both the FCA and state labor law.
  • The investigation reveals that internal reports were not documented properly, retaliation safeguards were not in place, and training on non-retaliation was outdated.

This case underscores the need for compliance programs to ensure proactive risk mitigation, thorough documentation, and a robust culture of safety and transparency.

The Compliance Officer’s Role: Promoting a Speak-Up Culture

Organizations should periodically evaluate the effectiveness of their whistleblower protection efforts through anonymous staff surveys, incident response audits, and tracking the outcomes of reported concerns. This proactive approach signals to staff that leadership values integrity and transparency.

Certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation. Organizations must go beyond policy documents and invest in cultural and procedural safeguards:

- Establish and communicate clear non-retaliation policies.
- Train all employees and leadership on reporting rights and retaliation indicators.
- Maintain multiple confidential channels for reporting concerns.
- Ensure prompt and fair investigation of all complaints.
- Audit for compliance with whistleblower protection policies.

Conclusion

Ultimately, the goal of any whistleblower protection program is not merely compliance, but the cultivation of an ethical culture that consistently does what is right—even when it is inconvenient or uncomfortable. This requires leadership buy-in, staff empowerment, and a long-term commitment to transparency.

Whistleblower protections are more than legal requirements—they are pillars of ethical healthcare. Laws like the FCA, HIPAA, and NDAA empower individuals to report wrongdoing without fear. Compliance professionals must champion these safeguards, not only to avoid legal liability but to protect patient welfare, support employee integrity, and sustain organizational trust.

As regulatory enforcement intensifies and new federal protections emerge, healthcare organizations must remain vigilant, proactive, and transparent. The call to protect whistleblowers is not just a mandate—it is a moral and professional imperative.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance.  Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • U.S. Department of Health and Human Services (HHS). (2025). New Whistleblower Guidance and Complaint Portal. Retrieved from https://www.hhs.gov/protect-kids
  • 31 U.S.C. §§ 3729–3733, False Claims Act (FCA).
  • 31 U.S.C. § 3730(h), Anti-Retaliation Protections under the FCA.
  • 45 CFR § 164.502(j), Whistleblower Disclosures under the HIPAA Privacy Rule.
  • National Defense Authorization Act (NDAA) of 2013, 41 U.S.C. § 4712.
  • Office for Civil Rights (OCR), HHS. (2025). Press release on hospital investigation, April 14, 2025.
  • American Institute of Healthcare Compliance (AIHC). (2025). Newsblast: New Whistleblower Complaint Portal.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Community Health
Community Healthcare

Detecting Abuse of the Elderly

Part 2 in a series of articles to support World Elder Abuse Awareness   

Warning Signs of Elder Physical, Sexual, Psychological Abuse, Abandonment and Neglect   

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS of the American Institute of Healthcare Compliance (AIHC), a non-profit healthcare education organization.   

Elder Abuse Awareness for the Healthcare Workforce

The Department of Justice lists the following information that can be used by nurses, physicians and healthcare workforce members.  AIHC is sharing this information in support of World Elder Abuse Awareness Day.  The information below is not all-inclusive or comprehensive, but it is a good start to increase awareness to educate your workforce.

Please feel free to repost, print and make available to your workforce members.  This information can be useful when completing a Social Determinants of Health (SDOH) risk assessment and any time a health care professional determines it is necessary to gain a deeper understanding of presenting problems which are warning signs of elder physical, sexual, psychological abuse, abandonment, neglect and financial extortion.

Detecting Physical Abuse

Warning Signs can present as:

  • Bruises, black eyes, welts, lacerations, or rope marks
  • Bone fractures, broken bones, or skull fractures
  • Open wounds, cuts, punctures, untreated injuries in various stages of healing
  • Sprains, dislocations, or internal injuries/bleeding
  • Broken eyeglasses/frames, physical signs of being subjected to punishment, or signs of being restrained
  • Laboratory findings of medication overdose or under-utilization of prescribed drugs
  • An elder's report of being hit, slapped, kicked, or mistreated
  • An elder's sudden change in behavior
  • The caregiver's refusal to allow visitors to see an elder alone

Consider Asking –

  1. Has anyone hit, kicked, bit, slapped, or thrown things at you?
  2. Has anyone held or tied you down, or locked you in a room or building?
  3. Has anyone shaken, pinched, or burned you?
  4. Has anyone physically hurt you so that you suffered some injury, such as cuts, bruises, or other marks?
  5. Has anyone pushed, shoved, or grabbed you?
  6. Has anyone used a knife or gun on you?
  7. Has anyone not allowed you to go to the bathroom?     
  8. Has anyone given you too much or too little medication?

EXAMPLES: Stories as told by the DOJ regarding physical abuse cases of the elderly

  • Abuse by Guardian/Conservator
    • Blair, 65, had no close relatives. Because of early-onset dementia, he was placed in a nursing home and required guardianship. Chris, Blair’s guardian, came to Blair’s nursing home every few months to see how Blair was doing.
    • During the last visit, Chris began slapping Blair to wake him up. Joan, a care attendant rushed to the room when Blair began crying out for Chris to stop. Joan noticed marks on Blair’s face and asked what had happened. Blair was unable to tell Joan what had happened but Chris quickly left the room.
    • Joan reported the incident to her supervisors who helped her make a report to Adult Protective Services (APS). The report triggered involvement by the state ombudsman and local law enforcement.
  • Abuse by Long-Term Care Aide
    • Monica, 79, was placed in a long-term care facility when her ALS became severe and her family could no longer care for her. Her family became concerned when they saw bruising on her arms and back. Monica was not able to speak and could not tell her family how she got the bruises.
    • Monica’s family asked the staff about the bruising but was not satisfied with the explanation. The family also noticed that when a certain aide helped bathe her, Monica became upset and agitated. They suspected that the aide was hitting Monica and called local law enforcement.
  • Abuse by Disabled Adult Son
    • When George, 79, lost his wife of 50 years to cancer, his son, Lawrence, came to live with him. Lawrence was on disability due to a traumatic brain injury. The brain injury caused behavior changes, including difficulty with self-control and verbal and physical outbursts. The injury also caused violent mood swings.
    • Occasionally, Lawrence went to a neighbor's apartment and got drunk. One night when Lawrence returned home, George asked him if he was drunk. Lawrence yelled "NO" and punched his father in the face. Because George was afraid of further violence, he called 911 to get help from the police.
  • Abuse by Adult Grandsons
    • Katherine, 82, raised two grandsons, Joel and Kent. They had physically abused her since they were teenagers. After 12 years in prison, Joel returned to his grandmother's home because he had nowhere to go. One night Joel came home and was drunk. He banged on the door but Katherine told Joel to go away.
    • After he entered the house through a back window, Joel beat his grandmother. Katherine went to a neighbor’s house and called 911. Joel was arrested and Katherine was taken to the hospital. The police contacted Adult Protective Services (APS).
  • Abuse by Spouse
    • After 58 years of marriage, Virgil and Ella, both 83, knew each other's habits well. Sometimes, when they argued they became physically violent. Nevertheless, they said they loved each other and had never considered divorce. Violence was unfortunately a part of their relationship. As Ella aged, she developed osteoporosis. She began to worry that if she fell down when they were fighting each other she might end up with a broken bone. She confided this to a friend, and her friend suggested calling the local domestic violence hotline to speak with a counselor.

Detecting Abandonment/Neglect

Warning Signs can present as:

  • Dehydration, malnutrition, untreated bed sores, and poor personal hygiene
  • Unattended or untreated health problems
  • Hazardous or unsafe living conditions/arrangements (e.g., improper wiring, no heat, or no running water)
  • Unsanitary and unclean living conditions (e.g., dirt, fleas, lice on person, soiled bedding, fecal/urine smell, inadequate clothing)
  • An elder's report of being neglected
  • The desertion of an elder at a hospital, a nursing facility, or other similar institution
  • The desertion of an elder at a shopping center or other public location
  • An elder's report of being abandoned

Consider Asking – 

  1. Has the person who is supposed to take you to the grocery store, shopping, or to a place of worship stopped taking you there?
  2. Has the person who is supposed to help with household chores or cooking or eating stopped helping you?
  3. Has the person who is supposed to help get you to the doctor, or take medicines at the right times or amounts, or get glasses or dentures stopped helping you?
  4. Has the person who is supposed to help you bathe or shower, or get in and out of bed, or get dressed, or go to the toilet stopped helping you?
  5. Has the person who is supposed to help you pay bills or manage your money stopped helping you?
  6. Has anyone left you alone or deserted you at home or elsewhere for a long period of time?

EXAMPLES: Stories as told by the DOJ regarding abandonment & neglect of the elderly.

  • Neglect by Daughter and Son-in-Law
    • Kofi, 84, was diagnosed with Alzheimer’s disease and moved in with his daughter's family. Sometimes Kofi had trouble sleeping, had physical and verbal outbursts, and began wandering. His daughter and son-in-law were afraid that Kofi might wander out of the house if they left him alone.
    • They locked the doors to the house so that Kofi could not get out and wander around when they left for work. A neighbor noticed Kofi trying to get out of the house. She contacted the local police and Adult Protective Services (APS).
  • Neglect by Son and Daughter-in-Law
    • Tamara, 76, lived alone but had trouble getting around. Her son and his wife asked Tamara to move in with them. Tamara had her own bedroom on the second floor and stayed there most of the time. She could not use the stairs easily.
    • Her son and daughter-in-law both traveled frequently for work and sometimes neglected to give her adequate food and water. They also failed to groom her or to clean her room consistently.
    • One day Tamara became dizzy, weak and disoriented so her daughter took her to the hospital. The hospital staff discovered that she was dehydrated, disheveled and obviously unwashed. They asked about her care, but Tamara said she was well cared for. 
    • Nevertheless, as required by law, the hospital staff reported suspected neglect to Adult Protective Services (APS).
  • Neglect by Sons
    • Clarence, 79, invited his two adult sons to move in with him so he would not be alone after his wife died.
    • The sons soon sent Clarence out to live in the shed and locked him out of the house. Sometimes his sons put food out for him. Occasionally they gave him a basin of cold water with a washcloth.
    • When one of Clarence’s neighbors noticed that Clarence seemed to be living in the shed, she called Adult Protective Services (APS) anonymously and reported what she had seen. She then decided Clarence may need immediate help so she called the police to do a welfare check.
  • Abandonment by Adult Daughter
    • Juliette, 87, lived with her daughter, Nanette, for the past three years. Nanette helped Juliette with daily activities, such as getting her meals, bathing, and cleaning the house.
    • Nanette decided to move in with her boyfriend in another state and left her mother alone in the home.
    • About a week later, Juliette’s niece happened to be in town and stopped by to visit her aunt. She saw that the inside of the house was in very bad condition and found Juliette in poor health. Juliette’s niece contacted Adult Protective Services (APS) and the State Area Agency on Aging.
  • Abandonment by Guardian/Conservator
    • Henrietta, 88, required a court appointed guardian due to combined physical and mental disabilities that left her partially incapacitated. Her niece, Roberta, was appointed as Henrietta’s guardian.
    • Roberta visited Henrietta in her home a few times but then never came back and made no further arrangements for her care.
    • A neighbor noticed the lack of activity at Henrietta’s house. The neighbor knocked but couldn’t get Henrietta to answer door, so she called law enforcement for a welfare check and Adult Protective Services (APS).
  • Another Abandonment by Guardian/Conservator
    • June, 73, suffered a severe brain injury. At first, she was able to care for herself but as she got worse, a court appointed Sam as her legal guardian to assist her. He saw June two times in the first six months but did not return to see June and did not arrange for her care.
    • He falsified reports to the court stating that he saw June every three months. As a result, no one knew that June was living on her own without Sam’s help.
    • June was unable to remember to clean her house and the trash had not been taken out in many months. Due to the deterioration of her house, June received a visit from a county health officer who discovered that June was very frail.
    • The county health officer was a mandatory reporter and called Adult Protective Services (APS). APS petitioned the court for a new guardian.

Detecting Signs of Psychological Abuse

Warning Signs can present as: 

  • Being emotionally upset or agitated
  • Being extremely withdrawn, non-communicative or non-responsive
  • Unusual behavior, such as sucking, biting, rocking
  • An elder's report of being verbally or emotionally mistreated
  • Witnessing a caregiver controlling an older adult or isolating an older adult
  • Exhibiting a change in sleeping patterns or eating habits
  • Personality changes, such as apologizing excessively, or depression or anxiety

Consider Asking –

  1. Has anyone verbally attacked, scolded, or yelled at you so that you felt threatened or intimidated, or afraid for your safety?
  2. Has anyone made you feel embarrassed by calling you names such as “stupid,” telling you that you or your opinion was worthless or blaming you for things that you did not do?
  3. Has anyone talked to you so that you felt that they were talking to a child?
  4. Has anyone forcefully or repeatedly asked you to do something so that you felt forced into doing something against your will?
  5. Has anyone close to you completely refused to talk to you or ignored you for days at a time, even when you wanted to talk to them?
  6. Has anyone kept you away from family, friends, or regular activities against your will?
  7. Has anyone close to you looked at you in such a way that you felt afraid that they were going to hurt you?
  8. Have you felt that someone was watching your every move to try to control you or that that person was stalking you?
  9. Has anyone you know made unwanted phone calls to you or left messages or sent unwanted emails, texts, or instant messages to you?

EXAMPLES: Stories as Told by the DOJ regarding psychological abuse of the elderly

  • Psychological Abuse by Stranger
    • Rosie, 75, lived alone in an independent senior housing community. Her next-door neighbor, a disabled retiree, repeatedly emailed her rude messages and sent vulgar and threatening messages to her cell phone.
    • Fearing her neighbor might harm her if she told him to stop, Rosie contacted local law enforcement and filed criminal charges as well as a petition for a civil restraining order. She also notified housing management.
  • Psychological Abuse by Son
    • Jane had not seen her friend Harry, 87, at Mass for weeks. This was not like her friend since Harry went to Mass almost every Sunday. Jane stopped by Harry’s house. Harry answered the door and Jane was shocked.
    • Her friend had lost weight, looked terrible, and had obviously been crying. Harry told Jane in a hushed voice that since his son had moved in, he would not let him go to church, the senior center, or even out of the house.
    • Harry said that his son was now controlling everything including his money. Before Jane could say anything, Harry’s son started yelling and Harry quickly closed the door. Jane decided to make an anonymous report to Adult Protective Services (APS).
  • Psychological Abuse by Spouse
    • Sarah, 75, had been married for over 50 years to Saul who was abusive. The abuse had a pattern. Her husband would start following her around watching her every move. Then he would make comments under his breath. Finally, he would start pointing his finger in her face and pushing her around.
    • Since Saul’s retirement, this pattern seemed to be getting worse and happening more often. Sarah picked up a pamphlet on Domestic Violence at her synagogue and decided to make her first call for help.
    • From her conversation with the domestic violence advocate, she learned about resources in her area and steps she could take to be safe.
  • Psychological Abuse by Daughter
    • Zoe, 79, was healthy, independent and lived with her unmarried daughter, Trish, to share expenses. Zoe believed they had a good relationship. Nevertheless, Trish sometimes yelled at Zoe, calling her horrible names and telling her she was worthless.
    • Trish began threatening to put Zoe in a nursing home. Zoe tried to ignore these rants because she was grateful to live with her daughter.  However, she thought she deserved to be safe from such comments.
    • Zoe eventually told a close friend about Trish’s yelling and threats. The friend suggested that Trish and Zoe seek counseling and that Trish get respite help from a local Agency on Aging.
  • Psychological Abuse by Guardian/Conservator
    • Mark, 75, had Alzheimer’s disease and was beginning to have severe memory loss and trouble walking around the house.  Mark’s paid caregiver, Yolanda, asked the court to appoint a guardian.
    • Each time the guardian, Mrs. McKee, visited with Mark, she made fun of his memory problems and inability to remember where he was or even who Yolanda was. Yolanda became worried about Mark and the fact that Mrs. McKee, the court appointed guardian, did not seem to take Mark’s condition seriously.
    • Yolanda called Adult Protective Services (APS) and the probate court to review Mark’s guardianship.

Detect Warning Signs of Sexual Abuse

Warning Signs can present as:

  • Bruises around the breasts or genital area
  • Unexplained venereal disease or genital infections
  • Unexplained vaginal or anal bleeding
  • Changes in an older adult's demeanor, such as showing fear or becoming withdrawn when a specific person is around
  • Evidence of pornographic material being shown to a older adult with diminished capacity
  • Blood found on sheets, linens or an older adult’s clothing
  • An elder's report of being sexually assaulted or raped

Consider Asking –

  1. Has anyone forced you to have sexual intercourse or oral sex if you did not want to?
  2. Has anyone touched you in a sexual way or forced you to touch them in a sexual way against your will?
  3. Has anyone made you undress or expose yourself when you didn’t want to?
  4. Has anyone taken pictures of you with your clothes partially or completely off when you didn’t want them to?
  5. Has anyone talked to you in a sexual way that made you feel uncomfortable?
  6. Has anyone made you watch pornography against your will?

EXAMPLES: Stories as told by the DOJ regarding sexual abuse cases of the elderly.

  • Sexual Abuse by Nursing Home Aide
    • Margaret, 77, lived in a nursing home that was known for good residential care. One day, a nursing aide noticed that Margaret appeared anxious, but Margaret would not explain why.
    • While preparing her for a bath, the nursing aide saw multiple bruises on Margaret's arms, neck and back and asked what happened. Initially, Margaret did not say anything. Subsequently, the director of nursing learned from another resident that a new aide had sexually assaulted Margaret.
    • As required by law, the director of nursing reported the sexual assault to Adult Protective Services (APS), and APS initiated an investigation, involving the Ombudsman and local law enforcement.
  • Sexual Abuse by In-Home Caregiver
    • Eduardo, 80, had a stroke. His family hired an in-home caregiver to assist with his daily needs such as bathing and going to the toilet. One day his daughter stopped by to help see her dad.
    • As she helped him get dressed, he winced, and she noticed that his genital area was red and irritated. Her father started to cry and mumbled something about the caregiver hurting him there.
    • The daughter immediately called Adult Protective Services (APS) to make a report. She also called the agency where the caregiver worked, made a complaint, and ended services. APS alerted the law enforcement.
  • Sexual Abuse by Family Member
    • Pearl, 70, took her nephew in when his mother could not handle his behavior problems. The nephew began viewing pornography on the TV that he shared with his aunt. Pearl was uncomfortable about this and told her nephew to stop.
    • One day, the nephew came home and was high on drugs. He forced himself sexually upon his aunt. Pearl called 911 for local law enforcement and went to the hospital where she met with a sexual assault victim specialist.
  • Sexual Abuse by Guardian/Conservator
    • Angela, 71, required guardianship because of her continued alcohol and drug abuse. The court appointed Richard as her guardian.
    • Soon after his appointment, he gave Angela more drugs, sexually assaulted her, and threatened her with prison for her drug use if she reported him.
    • Angela summoned the courage to go to the local police and contacted a lawyer to obtain a new guardian.

Don’t Turn a Blind Eye – Be Part of the Solution

If you see something, say something to your Compliance Officer, Manager or someone in authority.  Ignoring a potentially harmful situation is to neglect our duty of care to our patients. 

Duty of care is a requirement that a person act toward others and the public with the watchfulness, attention, caution and prudence that a reasonable person in the circumstances would use. If a person's actions do not meet this standard of care, then the acts are considered negligent, and any damages resulting may be claimed in a lawsuit for negligence.

This article is sponsored by the American Institute of Healthcare Compliance (AIHC), a non-profit healthcare compliance training organization. Please re-post this article or print and distribute to your workforce for educational purposes.  Locate more information from your State, local law enforcement, medical society and use this link for additional information from the U.S. Department of Justice.  For more information to obtain online training in corporate compliance, click here.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Part 2: Who Regulates Healthcare AI?

Artificial Intelligence & Regulatory Compliance


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest articles.  As stated in Part 1, the Office of the National Coordinator for Health Information Technology (ONC) and the Agency for Healthcare Research and Quality (AHRQ), with support from the Robert Wood Johnson Foundation, turned to an independent group of scientists and academics to consider how AI might shape the future of public health, community health, and healthcare delivery.  The question remains, how will the use of AI be regulated for health care use?


Artificial Intelligence/Machine Learning has gained heightened attention globally.  Augmented Intelligence has been embraced as a concept by physician organizations to underscore that emerging AI systems are designed to aid humans in clinical decision-making, implementation and administration to scale healthcare, according to Act Online Key Terminology for AI in Health.


Although the United States is making progress in developing domestic AI regulation, including with the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the existing laws and regulations that apply to AI systems is still a work-in-progress.  The goals are to protect people from unsafe or ineffective systems. 


So, Who Regulates Healthcare AI?


What seems like a simple question is really a complex situation.  This article only scratches the surface of various regulatory agencies involved in the regulation of AI.  The Health & Human Services (HHS) response to OMB Memorandum 21-06 “Guidance for Regulation of Artificial Intelligence Applications” was drafted in November 2020 and is directed to the heads of all Executive Branch departments and agencies, including independent regulatory agencies.  Much has happened since then.


On April 25, 2023, the Federal Trade Commission (FTC), the Civil Rights Division of the U.S. Department of Justice (DOJ), the Consumer Financial Protection Bureau (CFPB), and the U.S. Equal Employment Opportunity Commission (EEOC) released a joint statement highlighting their commitment to "vigorously use [their] collective authorities to protect individuals" with respect to artificial intelligence and automated systems (AI), which have the potential to negatively impact civil rights, fair competition, consumer protection, and equal opportunity.


The joint statement from the DOJ, FTC, CFPB, and EEOC signifies a growing awareness and concern among federal agencies about the potential risks and challenges posed by AI and automated systems. As AI continues to become more integrated into all aspects of daily life, the importance of addressing potential biases, transparency issues, and flawed design becomes increasingly critical.


Federal Trade Commission (FTC) Raises Concerns


The FTC’s mission is to protect consumers and competition through preventing anticompetitive, deceptive and unfair business practices.  This is achieved through law enforcement, advocacy, and education without unduly burdening legitimate business activity.  The FTC Act’s prohibition on deceptive or unfair conduct can apply if you make, sell, or use a tool that is effectively designed to deceive – even if that’s not its intended or sole purpose. The FTC’s action should help protect healthcare organizations by limiting deceptive or exaggerated promises of what a medical device or AI software can actually do.  It’s not uncommon for advertisers to say that some new-fangled technology makes their product better – perhaps to justify a higher price or influence labor decisions.


On May 18, 2023, the FTC issued a warning that the increasing use of consumers’ biometric information and related technologies, including those powered by machine learning, raises significant consumer privacy and data security concerns and the potential for bias and discrimination. Biometric information refers to data that depict or describe physical, biological, or behavioral traits, characteristics, or measurements of or relating to an identified or identifiable person’s body.


The Federal Drug Administration & AI


The Food & Drug Administration (FDA) released a discussion paper in 2019 and then an action plan on January 21, 2021 regarding Artificial Intelligence and Machine Learning, or AI/ML.  This action plan describes a multi-pronged approach to advance the Agency’s oversight of AI/ML-based medical software.  Then, in April 2023, the FDA is publishing a draft guidance, "Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence/Machine Learning (AI/ML)-Enabled Device Software Functions."

  • This draft guidance proposes a science-based approach to ensuring that AI/ML-enabled devices can be safely, effectively, and rapidly modified, updated, and improved in response to new data.

The approach the FDA is proposing in this draft guidance would put safe and effective advancements in the hands of health care providers and users faster, increasing the pace of medical device innovation in the United States and enabling more personalized medicine.

  • This means, for example, that diagnostic devices could be built to adapt to the data and needs of individual health care facilities and that therapeutic devices could be built to learn and adapt to deliver treatments according to individual users' particular characteristics and needs.

National Institute of Standards and Technology (NIST) AI Risk Management Framework


Released on January 26, 2023, NIST’s AI Risk Management Framework or “AI RMF” which is intended to be used voluntarily to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.  The Framework was developed through a consensus-driven, open, transparent, and collaborative process with the intention to build on, align with, and support AI risk management efforts by others.


Recently NIST launched the Trustworthy and Responsible AI Resource Center (AIRC), which will facilitate implementation of, and international alignment with, the AI RMF.  We recommend watching the introduction video:  https://www.nist.gov/video/introduction-nist-ai-risk-management-framework-ai-rmf-10-explainer-video


For healthcare HIPAA covered entities, NIST is likely a familiar organization to you.  NIST published prior documents related to AI.  The initial draft of the AI RMF was published March 17, 2022 and a second draft on August 18, 2022.


The Health Insurance Portability and Accountability Act (HIPAA)

Public Law 104-191


The Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy and Security Rules (45 C.F.R. Parts 160 and 164, Subparts A, C, and E). One of the ways that OCR carries out this responsibility is to investigate complaints.  As health care organizations evolve with the use of AI, there is increased potential for cyber criminals to exploit vulnerabilities.


At the present, there are two exclusions existing in the HIPAA Privacy Rule that allow Covered Entities to share Protected Health Information (PHI) with device vendors and other organizations without the authorization of the individual(s) to whom the PHI relates. The two exclusions can be found in 45 CFR §164.512(b)(1) and 45 CFR §164.512(i)(1). Respectively, they relate to:

  • Disclosures to vendors regulated by the Federal Drug Administration are permitted by the Privacy Rule for the “purpose of activities related to the quality, safety or effectiveness of such FDA-regulated product or activity”.   The FDA regulates the sale of all medical device products, including personal health devices that transmit data to AI-driven healthcare solutions as described above.
  • PHI can also be disclosed without authorization for research purposes without being de-identified if the disclosure is approved by an Institutional Review Board or Privacy Board. In such circumstances, the disclosed PHI must remain in the possession of the Covered Entity and the disclosure(s) can only be for the purpose of preparatory research (i.e., programming a “Supervised Learning Algorithm”).


Conclusion


Simply stated, a shift to AI calls for new skills.  It warrants increased knowledge of HIPAA privacy, security and anticipating other legal issues surrounding it’s use in healthcare.


Needless to say, it is important to maintain a robust HIPAA program and utilize information from the National Institute of Standards and Technology (NIST) AI Risk Management Framework as mentioned above.


In the context of HIPAA, healthcare data, and AI technologies, AI developers and vendors should consider that HIPAA only provides a federal floor of privacy and security standards. Often, other state and federal laws can apply that pre-empt HIPAA – particularly with regard to healthcare adjacent data – or apply to more organizations than Covered Entities and Business Associates.  Also, many Managed Service Providers (MSP) companies providing services to healthcare organizations should be aware of AI applications and security vulnerabilities.


If your organization plans or is using AI for medical diagnostics, reference the annual joint publication by the U.S. Government Accountability Office (GAO) and the National Academy of Medicine published each September entitled “Technology Assessment – Artificial Intelligence in Health Care – Benefits and Challenges of Machine Learning Technologies for Medical Diagnostics”.   A new publication is posted each year: https://www.gao.gov/products/gao-22-104629


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
Release of Information
HIPAA, Release of Information

OCR Enforcement of HIPAA Right of Access and Release of Information (ROI)

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The article addresses the HIPAA Privacy Rule for Covered Entities regarding time limitations to respond to an individual’s request for access of protected health information or “PHI.” This article is not all inclusive and should not be used as legal or consulting advice. Scroll down for hyperlinks to free and low-cost training related to Right of Access & ROI.



What Is HIPAA Right of Access?


The HIPAA Privacy Rule generally provides individuals with a legal, enforceable right to see and receive copies, upon request, of the information in their medical and other health records maintained by their health care providers and health plans. This right is known as the HIPAA Right of Access.


HIPAA Right of Access policies have evolved over the years to ensure that patients have equitable access to their medical records. HIPAA requires covered entities to provide patients with access to their medical records. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009, helped right of access policies evolve to reflect the growing use of EHR systems.


HIPAA Enforcement


HIPAA compliance it monitored by the Health & Human Services (HHS) enforcement agency, the Office for Civil Rights (OCR). The Office for Civil Rights is responsible for enforcing the Privacy and Security Rules. Enforcement of the Privacy Rule began April 14, 2003, for most HIPAA covered entities. Since 2003, OCR's enforcement activities have obtained significant results that have improved the privacy practices of covered entities. OCR also works in conjunction with the Department of Justice (DOJ) to refer possible criminal violations of HIPAA.


In 2019, the OCR launched the HIPAA Right of Access Initiative to advocate for individuals trying to obtain their health records in a timely manner at a reasonable cost as required by covered entities in the HIPAA Privacy Rule.


Complying With the HIPAA Privacy Right of Access Rule


If your organization is not responding timely to requests for medical records, a complaint to the Office for Civil Rights can trigger an investigation resulting in fines and other consequences, such as being posted on the OCR HIPAA website and a forced Corrective Action Plan.


A dedicated government webpage lists HIPAA News Releases & Bulletins listing OCR cases after investigating organizations which includes Right of Access settlements. Click Here to access this page. https://www.hhs.gov/hipaa/newsroom/index.html


The July 15, 2022, Health & Human Services (HHS) Press Release announces the resolution of eleven investigations and the enforcement actions taken with these eleven organizations related to violations of patient’s rights under HIPAA. In this press release the OCR Director Lisa J. Pino states:


“It should not take a federal investigation before a HIPAA covered entity provides patients, or their personal representatives, with access to their medical records. Health care organizations should take note that there are now 38 enforcement actions in our Right of Access Initiative and understand that OCR is serious about upholding the law and peoples’ fundamental right to timely access to their medical records.”

 

So, how timely must a covered entity be in responding to individuals’ requests for access to their PHI?


This is addressed under 45 CFR 164.524(b)(2) of the HIPAA Privacy Rule regarding access of individuals to protected health information (PHI). Under the HIPAA Privacy Rule, a covered entity must act on an individual’s request for access no later than 30 calendar days after receipt of the request.


If the covered entity is not able to act within this timeframe, the entity may have up to an additional 30 calendar days as long as it provides the individual, within that initial 30-day period, a written statement of the reasons for the delay and date when the entity will complete its action on the request. The 30-day timeline applies regardless of the following circumstances:

  • The PHI that is the subject of the request is maintained by the covered entity or by a business associate on behalf of the covered entity, or the covered entity uses a business associate to fulfill individual requests for access.

o The 30-day clock starts on the date that the covered entity receives a request for access, so any delay in obtaining the necessary information from a business associate or forwarding the request to the business associate for action “uses up” part of the allotted time.


o Alternatively, the 30-day clock starts when, instead of the covered entity, a business associate receives a request directly from an individual because the covered entity instructed the individual through its notice of privacy practices (or otherwise) to submit the access request directly to its business associate for processing. 

  • The covered entity negotiates with the individual on the format of the response. Covered entities that spend significant time before reaching agreement with individuals on format are depleting the 30 days allotted for the response by that amount of time.

  • The PHI that is the subject of the request is old, archived, and/or not otherwise readily accessible.

As noted by OCR, these timelines are outer limits. The government expects that covered entities should be able to respond to requests for access well before these outer limits are reached. However, in cases where a covered entity is aware that an access request may take close to these outer time limits to fulfill, the entity is encouraged to provide the requested information in pieces as it becomes available, if the individual indicates a desire to receive the information in this manner.


Resources to Comply With ROI and Right of Access


Learn more about 45 CFR § 164.524 - Access of individuals to protected health information. Free and reasonably priced training for you and your workforce is listed below:


Right of Access Specialist - Online Course

AIHC HIPAA Compliance Training Videos Free

Legal Information Institute (Cornell Law School) Free

HIPAA Online Privacy Course (Earn 12 AIHC and AHIMA CEUs)

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Compliance & Internal Investigations

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




Are you an internal auditor conducting “routine” reviews? Have you ever uncovered erroneous or potentially fraudulent evidence? Once your suspicions have been reported to the Compliance Officer, were you asked to partake in evidence gathering during the investigation? The content of this article is for educational purposes and not intended as consulting or legal advice.


For those of you more experienced auditors, additional training in how to handle evidence during an internal investigation not only advances your career but helps secure evidence that can be used if an actual crime has been committed. I also recommend reading When Healthcare White-Collar Crimes Turn Red, an AIHC blog article from 2021.


Do you need to convince executives that crime is a potential problem for your organization? The Department of Justice (DOJ) posts “News & Noteworthy” cases here. 


What Comes to Mind When You Hear the Word “Forensic”?

 

Most of us think about investigations as seen on television programs, such as “CSI” or “Bones.” Forensic science is a critical element of the criminal justice system – “Forensic scientists examine and analyze evidence from crime scenes and elsewhere to develop objective findings that can assist in the investigation and prosecution of perpetrators of crime or absolve an innocent person from suspicion.”


According to the Merriam-Webster dictionary, the word forensic is defined as the following:

  • Belonging to, used in, or suitable to courts of judicature or to public discussion and debate
  • Relating to or dealing with the application of scientific knowledge to legal problems

Your auditing and compliance skills become valuable to professional law enforcement, but you need to know what, when and how to handle a situation which could potentially turn into criminal charges against someone within your organization. First, let’s start with prevention.


Is It an Internal or External Investigation?


Internal Investigations are conducted by skilled employees (or a consultant under contract working for the organization) trained to perform specialized audits to gather evidence when there is suspected fraud, abuse or crime. These investigations are typically conducted to gather information sufficient for legal counsel to determine whether an external investigation is warranted by the appropriate authorities.  These employees are often referred to as Internal Forensic Auditors or Internal Investigators. For the purpose of this course, we will refer to this position as an Internal Forensic Auditor.


Internal Forensic Auditors report to a Board of Directors, Compliance Officer and/or Audit Committee of the health care organization and typically work under the direction of the organization’s legal counsel.


External Forensic Auditors are independent of the organization they are auditing. They are experts working as an investigator for an accounting or consulting firm, CMS, a police department, the FBI or another agency as described above.


The process of conducting a forensic investigation is, in many ways, similar to the process of conducting an audit, but with some additional considerations. The various stages are briefly described below. 


Step 1: Accepting the Investigation


Review information regarding the matter and consider whether you (and your team) have the necessary skills and experience to accept the work.

  • Forensic investigations are specialized in nature, and the work requires detailed knowledge of fraud investigation techniques and the legal framework.
  • Investigators must also have received training in interview and interrogation techniques and in how to maintain the safe custody of evidence gathered.
  • Investigators must be able to address potential conflicts of interest or bias and achieve objectivity.

Step 2: Planning the Investigation


The investigating team must carefully consider what they have been asked to achieve and plan their work accordingly. The objectives of the investigation will include:

  • Recognize if there is sufficient evidence to warrant a forensic investigation. If so, then anticipate planning required to achieve the following:

      o Identify the type of fraud that has been operating, how long it has been operating for,
    and how the fraud has been concealed;

           Determine deadlines and timeframes to complete the investigation which may
    be driven by regulatory factors;

      o Identify the fraudster(s) involved;

      o Quantify the financial loss suffered by the organization;

      o Gather evidence for potential use in court proceedings;

           Identify the type of report format required and record evidence appropriately; and

      o Provide advice to prevent the reoccurrence of the fraud. 

The investigators should also consider the best way to gather evidence. They may choose the use of computer assisted audit techniques or other various methods appropriate for the situation.


Step 3:  Gathering Evidence – Fact Finding


In order to gather detailed evidence, the investigator must understand the specific type of fraud that is suspected. The evidence should be sufficient to ultimately prove the identity of the fraudster(s), the mechanics of the fraud scheme, and the amount of damage or loss suffered by the organization.


It is important that the investigating team is skilled in collecting evidence that can be used in a court case and in keeping a clear and secure chain of custody until the evidence is presented in court. If any evidence is inconclusive, or there are gaps in the chain of custody, then the evidence may be challenged in court or even become inadmissible. Investigators must be alert to documents being falsified, damaged or destroyed by the suspect(s). 


“Chain of custody” is defined by Dictionary.com as “the order in which a piece of criminal evidence should be handled by persons investigating a case, specifically, the unbroken trail of accountability that ensures the physical security of samples, data and records in a criminal investigation.” To prove the chain of custody, and ultimately show that the evidence has remained intact, prosecutors generally need internal investigators who can testify:

  • That the evidence offered in court is the same evidence they collected or received.
  • To the time and date the evidence was received or transferred to another provider.
  • That there was no tampering with the item while it was in custody.

Evidence can be gathered using various techniques, including: 

  • Testing controls to gather evidence which identifies the weaknesses which allowed the fraud to be perpetrated;
  • Using analytical procedures to compare trends over time or to provide comparatives between different segments of the business;
  • Applying computer assisted audit techniques which may help to identify the timing and location of relevant details being altered in the computer system;
  • Discussions and interviews with employees;
  • Substantive techniques such as: reconciliations, cash counts and reviews of documentation.

Step 4: Analyzing Data


After evidence and facts have been gathered and recorded, it is time to analyze all the data. The goal of data analysis is to determine if there is a relationship between the independent and dependent variables and to look for patterns within the data. 


Recording and organizing data may take different forms depending on the kind of information being collected. The way you collect your data should relate to how you’re planning to analyze and use it. Regardless of what method you decide to use, recording should be done concurrently with data collection if possible, or soon afterwards, so that nothing gets lost and memory doesn’t fade. Some of the things to do with the information collected can include:

  • Gather together information from all sources and observations;
  • Make photocopies of all recording forms, records, audio or video recordings, and any other collected materials to guard against loss, accidental erasure, or other problems;
  • Enter narratives, numbers, and other information into a computer program where they can be arranged and/or worked on in various ways;
  • Perform any mathematical or similar operations needed to get quantitative information ready for analysis;
      o These could include entering numerical observations into a chart, table, or spreadsheet, or figuring the mean (average), median (midpoint), and/or mode (most frequently occurring) of a set of numbers.
  • Transcribe (making an exact, word-for-word text version of) the contents of audio or video
    recordings;
  • Code data (translating data), particularly qualitative data that isn’t expressed in numbers, into a form that allows it to be processed by a specific software program or subjected to statistical analysis; and
  • Organize data in ways that make it easier to work with. This will depend on your research design and your evaluation questions.
      o Consider grouping observations by the dependent variable (indicator of success) they
    relate to, by individuals or groups of participants, by time, by activity, etc.
      o You might also want to group observations in several different ways so that you can study interactions among different variables. 

There are two kinds of data you’re apt to be working with. However, not all evaluations will necessarily include both.

  • Quantitative data refers to the information that is collected as, or can be translated into, numbers which can then be displayed and analyzed mathematically.
  • Qualitative data can be collected as descriptions, anecdotes, opinions, quotes, interpretations, etc. They are generally not able to be reduced to numbers and/or are considered more valuable or informative if left as narratives.

As you might expect, quantitative and qualitative information need to be analyzed differently. The investigation is likely to lead to legal proceedings against one or several suspects. Therefore, members of the investigative team must be comfortable with appearing in court to explain how the investigation was conducted and how the evidence was gathered.


Step 5: Report Your Findings


Draft the report in an objective manner. Do not draw conclusions, just report the facts. The checklist below summarizes what a typical report should contain:

  • Provide a Summary of the Investigation or Case
  • Describe the Investigation Plan
  • Case Notes – Keep an Investigator Diary
  • Information Interview Summaries
  • Interview Reports
  • Analysis of Investigation
  • Conclusion
  • Recommendations and Additional Action(s) Required With This Case
  • Exhibit Listing - attachments and evidence related to the case

Conclusion


An Ounce of Prevention Is Worth a Pound of Cure – So Learn More About Health Care Crime


A little precaution before a crisis occurs is preferable to a lot of legal complications, “bad press” and huge potential losses afterward. Preventing fraud in your organization starts with not hiring criminals! That might sound ridiculous, but are we really doing everything we should during the hiring phase of employees and contractors?


Most organizations are using the LEIE on the OIG website to screen new hires and conduct monthly verifications. But is this enough?


Unverified employees can put your organization at risk with a dramatic impact on your company’s brand reputation, performance and finances. Screening employees at hire, and periodically during employment, is a must for creating a safe workplace.


Below is a “short list” of screening tactics to consider before extending an offer to a candidate for hire. Be sure to review your procedure with legal counsel or a human resources expert to avoid any potential legal consequences with the U.S. Equal Employment Opportunity Commission (EEOC) related to changing your current hiring practices.

  • Criminal background check
  • Office of Inspector General (OIG) Exclusions Database check
  • Education – verify graduation, degree
  • Professional Certifications (check all certifications with the certifying agency – do not accept certificates from the potential employee as proof)

The EEOC has a webpage dedicated to help employers that addresses “Background Checks – What Employers Need to Know.” The information on this page is a joint publication between the EEOC and the Federal Trade Commission or FTC.


When making personnel decisions, which include hiring, retention, promotion, and reassignment, the EEOC states that employers should consider the background of applicants and employees. For example, the EEOC states you may want to consider verifying:

Except for certain restrictions related to medical and genetic information (per HIPAA, addressed further on the EEOC website), it's not illegal for an employer to ask questions about an applicant's or employee's background or to require a background check.


AIHC offers training – a “how to” participate in or conduct an internal investigation. The course is offered online with the option to certify (with a professional proctor online). The program is entitled Internal Forensic Auditor. If this course seems too intense, you may want to begin with the Auditing for Compliance online program.

Read More