Compliance in Healthcare
Corporate Compliance

From Findings to Action

Writing an Objective, Defensible Investigative Report 

Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

An internal investigative report represents the culmination of an internal forensic audit or compliance investigation conducted within your organization. It is the most critical deliverable in any inquiry, transforming data, interviews, and evidence into actionable conclusions. According to the Office of Inspector General’s (OIG) 2023 guidance, well-documented investigations not only demonstrate compliance program effectiveness but also protect organizations from regulatory exposure. This article provides tips to writing an objective and defensible investigative report.  For more information on how to conduct internal investigations and drafting your findings, consider registering and certifying as an Internal Forensic Healthcare Auditor (CIFHA) with the American Institute of Healthcare Compliance, a Licensing/Certification Partner w/CMS.

Introduction

In healthcare, the investigative report serves as both the historical record of an inquiry and the foundation for corrective action. Unlike informal summaries or audit notes, investigative reports must withstand scrutiny from regulators, accreditation bodies, and, in some cases, legal proceedings.

A report that is clear, factual, and defensible establishes credibility and demonstrates that the organization maintains a culture of compliance.

According to the U.S. Department of Justice’s 2024 Evaluation of Corporate Compliance Programs, documentation that reflects diligence, transparency, and follow-up is a decisive factor in evaluating the effectiveness of a compliance program. Similarly, the OIG, 2023 identifies timely reporting and accurate documentation as hallmarks of program integrity. Investigative reports thus become more than administrative records; they are compliance evidence.

The American Institute of Healthcare Compliance emphasizes that reporting is not merely a conclusion but an analytical phase requiring objectivity, ethical awareness, and technical precision.

Investigators are expected to synthesize complex data, maintain neutrality, and communicate findings in language that is factual and free from bias. When written properly, the investigative report transforms an incident into an opportunity for systemic improvement and risk reduction.

The Role of the Investigative Report

The investigative report is the official artifact that captures the who, what, when, where, why, and how of an inquiry. In many cases, the report becomes part of the audit trail reviewed by internal and external regulators.

A typical report lifecycle includes several stages—drafting, legal review, management approval, dissemination, and closure. During drafting, investigators must balance thoroughness with clarity. Legal counsel often reviews the document for privilege, tone, and factual accuracy, ensuring it aligns with both organizational policy and legal expectations. Once finalized, reports are stored in secure repositories, contributing to the organization’s compliance data archive.

Collaboration between departments is necessary. Compliance, Risk Management, Human Resources, and Legal must work together. The OIG’s 2024 Compliance Program Effectiveness Resource Guide notes that interdisciplinary collaboration ensures findings are contextualized, recommendations are actionable, and accountability is shared. Reports that integrate multiple perspectives are more defensible and effective.

Key Elements of a Defensible Investigative Report

1.  Clear Purpose and Scope

Every investigation should begin with a clearly defined purpose and scope. This section establishes the reason for the inquiry, outlines the questions to be answered, and defines the parameters of review. The scope should specify dates, departments, and records included. Ambiguity in this section can lead to confusion or accusations of overreach.

2.  Accurate Summary of Allegations

The summary should precisely capture the complaint or triggering event. Avoid loaded language or assumptions of intent. The investigator should record who made the allegation, what was alleged, and how the issue was reported, whether through a hotline, audit, or direct disclosure. The summary sets the foundation for factual neutrality.

3.  Methodology and Data Sources

Transparency in how evidence was collected and reviewed is vital for credibility. A strong methodology section identifies interviews conducted, documents examined, and systems accessed. According to Deloitte’s 2024 Internal Investigations Report, transparency in data collection fosters confidence among regulators and leadership.

4.  Chronological Narrative of Events

A chronological approach provides structure and logic. The Government Accountability Office’s (GAO) 2023 Fraud Risk Framework recommends organizing findings in sequence to demonstrate due diligence. Timelines clarify causation, highlight delays, and show that each step followed procedural fairness.

5.  Presentation of Evidence

Evidence must be presented clearly and factually. Data tables, summaries, and appendices can help. Use neutral phrasing such as “the documentation indicates” or “records show.” Avoid speculation or conclusions not supported by evidence.

6.  Analysis and Interpretation

This section bridges fact and meaning. Investigators should explain how findings relate to policies, procedures, or laws. The Association of Certified Fraud Examiners (ACFE, 2024) advises separating analysis from fact statements to maintain objectivity.

7.  Conclusions and Recommendations

A defensible conclusion synthesizes validated evidence and identifies corrective actions. Recommendations should be measurable and achievable, such as policy revisions, training, or audits. Avoid subjective commentary—focus on remediation, not blame.

8.  Documentation and Appendices

Supporting documentation should be referenced systematically. Attachments should include interview notes, data extracts, or relevant policies. Appendices demonstrate transparency and provide traceability for external reviewers.

Analytical Techniques for Investigative Reporting

Modern investigations increasingly rely on data analytics to support conclusions. According to PricewaterhouseCoopers (PwC’s) 2024 study on compliance analytics, quantitative analysis can identify outliers, correlations, and anomalies that qualitative methods may overlook. Tools such as data visualization dashboards, trend charts, and heat maps can make complex findings accessible to leadership and regulators.  For example, an investigator might analyze billing records to identify patterns of upcoding or duplicate claims. By visualizing data trends over time, the investigator can present evidence more persuasively.

The American Institute of Healthcare Compliance curriculum teaches participants how to interpret financial and operational data, integrating forensic accounting with compliance interpretation. The analytical phase also includes peer review and quality assurance.

According to the Society of Corporate Compliance and Ethics (SCCE, 2024), peer review provides an additional safeguard against bias or oversight. It ensures consistency across investigations and maintains trust in the process.

A Real-World Example: The Case of NorthView Behavioral Health

In 2024, NorthView Behavioral Health conducted an internal investigation after a report alleged improper overtime coding by nursing supervisors. The trained investigator used data analytics to compare scheduled shifts with payroll records, revealing discrepancies across three departments.

  • Interview transcripts and electronic timecard reviews confirmed manual overrides without documentation.
  • The investigator followed American Institute of Healthcare Compliance reporting principles, organizing the findings chronologically and using data tables to illustrate patterns of discrepancy.
  • The final report avoided subjective conclusions, instead focusing on systemic control gaps.

NorthView’s leadership responded by implementing automated shift validation, strengthening oversight protocols, and scheduling quarterly forensic audits. Because the report was objective, transparent, and data-driven, the organization self-disclosed to state regulators and avoided civil penalties. This case demonstrates how defensible reporting can convert a compliance issue into a model of organizational integrity.

Ethics, Language, and Professional Judgment

The ethics of reporting extend beyond accuracy to encompass tone and fairness. Investigators must avoid language that implies guilt or bias. According to the OIG’s 2023 Compliance Guidance, neutral phrasing and avoidance of adjectives that imply motive are essential to credibility. Investigative writing should mirror the impartiality of a court transcript, focusing on fact patterns rather than assumptions.

Professional judgment also plays a role in deciding what to include or omit. Transparency must be balanced with confidentiality and privilege. Collaboration with legal counsel helps determine which sections of a report may be privileged and how to handle sensitive information.

Turning Findings into Action

A defensible report achieves its true value only when findings lead to action. Compliance officers should ensure that recommendations translate into corrective and preventive actions (CAPAs). These may include revising policies, retraining employees, or enhancing data monitoring systems. The OIG (2024) recommends that compliance programs document each corrective action and assess its effectiveness through follow-up audits.

Action plans should be SMART—Specific, Measurable, Achievable, Relevant, and time-bound.

For example, if an investigation reveals inconsistent documentation practices, the CAPA may include targeted documentation training within 60 days and follow-up reviews within 90 days. By tying findings to measurable outcomes, organizations demonstrate accountability and compliance maturity.

Feedback loops are also critical. According to the GAO’s 2023 framework, integrating lessons learned into annual compliance reviews prevents recurrence of systemic issues. Trained investigators are equipped to design these loops, bridging the gap between investigative insight and continuous improvement.

Conclusion

The quality of an investigative report defines the credibility of the entire investigation. It is both a record and a reflection of an organization’s ethics. A defensible report is factual, impartial, and actionable, attributes that align with the standards set forth by OIG, Department of Justice (DOJ), and other oversight agencies. When written properly, the investigative report becomes a tool for learning rather than liability.

Certified Internal Forensic Healthcare Auditor-trained professionals are uniquely positioned to produce such reports. By combining forensic insight, analytical precision, and ethical clarity, they help organizations move from compliance response to proactive risk management. In a healthcare environment where accountability is paramount, the ability to write an objective, defensible report is both a compliance requirement and a professional hallmark of excellence.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • American Institute of Healthcare Compliance – 2025 Certified Internal Forensic Healthcare Auditor curriculum.
  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • Office of Inspector General (OIG). (2024). Compliance Program Effectiveness Resource Guide.
  • U.S. Department of Justice (DOJ). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Deloitte. (2024). Internal Investigations and Reporting Trends in Healthcare.
  • PwC. (2024). Effective Documentation in Corporate Investigations.
  • Society of Corporate Compliance and Ethics (SCCE). (2024). Peer Review in Compliance Investigations.
  • Journal of Health Care Compliance. (2023). Ethics and Documentation Standards in Healthcare Audits.
  • Harvard Business Review. (2023). Transparency and Accountability in Organizational Reporting.
  • U.S. Department of Health and Human Services (HHS). (2024). Health Care Fraud and Abuse Control Program Annual Report.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

10 Common Mistakes in Internal Investigations

And How to Avoid Them Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

Internal investigations are among the most sensitive and consequential activities within a healthcare compliance program. A single misstep can compromise objectivity, violate confidentiality, or weaken the organization’s legal position.

This article draws directly from the American Institute of Healthcare Compliance (AIHC) Certified Internal Forensic Healthcare Auditor (CIFHA) course section on Accepting the Investigation, offering practical insights into how compliance professionals can avoid the ten most common mistakes that undermine investigative credibility. By recognizing and mitigating bias, maintaining procedural rigor, and aligning with regulatory expectations, investigators can uphold integrity, transparency, and trust throughout the process.

Introduction

Accepting an investigation is one of the most critical phases of the investigative process. It sets the tone for impartiality, credibility, and compliance alignment. According to the Office of Inspector General’s 2023 guidance, healthcare organizations should ensure that all investigations are handled promptly, independently, and in a manner that promotes accurate fact-finding and appropriate corrective action.

The U.S. Department of Justice (DOJ) echoes this standard, emphasizing that organizations must demonstrate a “culture of compliance” through objective internal inquiry and documentation of remedial steps.

Yet, even experienced compliance professionals can make procedural or ethical missteps that jeopardize outcomes. From failing to define the scope to letting personal bias color the process, each mistake introduces risk—not only to the credibility of the investigation but also to the organization’s standing with regulators. Accepting the Investigation is the first critical step to understand how to recognize these pitfalls and establish a disciplined, unbiased approach.

Ten Common Mistakes in Internal Investigations—and How to Avoid Them

1.   Failing to Define Scope Clearly 

A well-defined scope sets boundaries and expectations. Without it, investigators risk “mission creep”—expanding beyond the original allegations and diluting focus. According to the Health Care Compliance Association (HCCA, 2024), scope definition should occur immediately upon assignment and be approved by compliance leadership. Avoid this mistake by drafting a clear investigative plan that identifies issues, potential evidence sources, and expected deliverables.

2.   Allowing Personal Bias to Influence Judgment

Bias can undermine objectivity, even when unintentional. Investigators may have preconceived notions about the individuals involved or the departments under review. According to the Association of Certified Fraud Examiners 2024 report, confirmation bias is one of the most common cognitive errors in fraud examinations. To mitigate this risk, investigators are encouraged to use a standardized evaluation framework, rely on documented evidence, and involve a peer reviewer when feasible.

3.   Neglecting to Secure Evidence Early

Delays in securing documentation, emails, or system access logs can result in data alteration or loss. Early preservation is critical for maintaining evidentiary integrity. The DOJ’s guidance on corporate investigations recommends issuing immediate document preservation notices and maintaining a clear chain of custody. Compliance officers should coordinate promptly with IT, HR, and legal counsel to secure relevant records.

4.   Ignoring Chain-of-Custody Procedures

Even if evidence is obtained, failure to maintain proper chain-of-custody documentation can render it unreliable. Investigators must track who collected each item, when, and under what conditions. This process ensures credibility in both internal reviews and external proceedings. Adhering to established forensic documentation procedures, such as those outlined in the AIHC Investigations training, protects evidence integrity and supports defensible reporting.

5.   Failing to Document Interviews Accurately

Interview summaries form the backbone of many investigations. Inaccurate or incomplete notes can lead to inconsistent conclusions. According to OIG compliance best practices, investigators should use structured templates, record factual statements, and avoid subjective language. Review notes immediately after interviews to ensure accuracy while details are fresh, and maintain them as part of the official investigation record.

6.   Overlooking Confidentiality Protocols

Breaching confidentiality can compromise employee trust and expose the organization to liability. Investigators should disclose only essential information on a need-to-know basis. The OIG’s 2023 General Compliance Program Guidance recommends protecting the identities of whistleblowers and limiting discussion of investigative matters to authorized personnel. Reinforce confidentiality expectations at the outset of every interview.

7.   Mismanaging Communication with Legal Counsel

Failure to coordinate properly with legal counsel can result in privilege issues or inconsistent messaging to regulators. Investigators should engage counsel early in the process, particularly when there is potential for self-disclosure or legal exposure. Counsel can help preserve attorney-client privilege and guide how findings are shared externally.

8.   Failing to Distinguish Between Facts and Assumptions

Investigations must rely on verifiable facts rather than assumptions or opinions. Mistaking interpretation for evidence can erode the report’s credibility. Investigators should clearly separate facts, analysis, and conclusions in their notes and reports. According to Compliance Week (2023), factual accuracy is the single most important determinant of whether an investigative report is considered defensible under regulatory review.

9.   Rushing to Conclusions or Recommendations

Pressure to conclude quickly can lead to incomplete analysis or unjustified findings. The CIFHA curriculum emphasizes patience and thorough review—investigators should evaluate all available data and corroborate key points before finalizing conclusions. Interim summaries and peer reviews can provide checkpoints for accuracy and completeness.

10.  Neglecting Follow-Up and Corrective Actions

An investigation is incomplete if it fails to lead to corrective action. According to the Government Accountability Office’s 2023 Fraud Risk Management Framework, closure should include documented remediation steps, training updates, and monitoring plans. Compliance officers should track outcomes to ensure identified risks are addressed and similar issues do not recur.

Building Investigative Integrity: Best Practices

The American Institute of Healthcare Compliance emphasizes that the credibility of an investigation depends on procedural rigor, ethical consistency, and adherence to compliance principles. Best practices include maintaining neutrality, engaging legal counsel early, and ensuring every step—from planning to reporting—is supported by clear documentation. Investigators should continuously assess their own potential biases and seek peer consultation when objectivity might be compromised.

Other proven strategies include developing investigation charters, maintaining secure digital evidence repositories, and conducting post-investigation debriefings. These steps not only enhance transparency but also create a feedback loop that improves organizational learning.

Conclusion

Conducting a compliant and credible internal investigation requires planning, impartiality, and discipline.

Each of the ten mistakes outlined above can erode trust and expose an organization to risk if not proactively addressed. By integrating appropriate protocols in your investigative framework, healthcare professionals can ensure investigations are fair, defensible, and aligned with regulatory expectations.  When investigators accept assignments with integrity and preparedness, they transform investigations from reactive responses into proactive tools for organizational improvement and compliance maturity.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • U.S. Department of Justice (DOJ). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Health Care Compliance Association (HCCA). (2024). Best Practices for Internal Investigations.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Compliance Week. (2023). Maintaining Objectivity in Internal Investigations.
  • Deloitte. (2024). Emerging Trends in Healthcare Investigations.
  • Office of Inspector General (OIG). (2023). Compliance Program Effectiveness Resource Guide.
  • U.S. Department of Health and Human Services (HHS). (2024). Healthcare Fraud Prevention and Enforcement Action Team (HEAT) Report.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

When Compliance Meets Forensics

Why Every Healthcare Organization Needs an Internal Investigator 

Written By: Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

Abstract 

In today’s complex healthcare environment, compliance alone is insufficient to detect and prevent misconduct, fraud, and abuse. Rising regulatory scrutiny, financial pressures, and technological complexity demand a proactive approach that blends compliance oversight with forensic auditing. This article introduces the concept of forensic auditing in healthcare, explains how internal investigators identify and mitigate internal risks before they escalate, and provides a real-world scenario that demonstrates the practical application of forensic principles. As the first in a three-part series aligned with the Certified Internal Forensic Healthcare Auditor (CIFHA) curriculum offered by the American Institute of healthcare Compliance (AIHC), this article establishes why healthcare organizations need internal forensic investigators to ensure accountability, compliance, and integrity across systems and staff.

Introduction

Healthcare organizations operate within one of the most highly regulated industries in the United States. Federal oversight through the Centers for Medicare and Medicaid Services (CMS), the Department of Justice (DOJ), and the Office of Inspector General (OIG) combined with state and accreditation requirements create a multifaceted compliance landscape. As regulatory expectations evolve, organizations must go beyond compliance checklists and adopt investigative capabilities that actively detect and mitigate risk. According to the Office of Inspector General’s 2023 guidance, healthcare compliance programs should include mechanisms for internal investigation and response to suspected violations to ensure early detection and self-disclosure opportunities.

Traditional compliance programs rely on audits and monitoring to identify irregularities and though these methods are proven; these processes are often periodic and limited in scope. Forensic auditing, on the other hand, integrates data analytics, investigative interviewing, and financial tracing to uncover intentional misconduct, hidden patterns, or emerging risks. When integrated within a compliance program, internal forensic investigators bridge the gap between prevention and enforcement.

Defining Forensic Auditing in Healthcare

Forensic auditing combines accounting, auditing, and investigative techniques to identify financial or operational irregularities that could indicate fraud, waste, or abuse. It differs from routine auditing because it assumes concealment, deception, and intent. Forensic auditing emphasizes verification, evidence preservation, and analytical reconstruction of transactions to determine whether misrepresentation occurred. According to the Association of Certified Fraud Examiners’ 2024 Report to the Nations, healthcare fraud remains one of the costliest forms of occupational abuse, with average losses exceeding $100,000 per incident in the provider sector.

Healthcare organizations are especially vulnerable because of the complexity of coding and billing systems, fragmented data environments, and third-party relationships. Forensic auditing in healthcare may involve reviewing claims data, vendor payments, procurement contracts, or physician compensation models. According to CMS program integrity data (2023), more than $60 billion in estimated improper payments were made across federal healthcare programs last year—highlighting the ongoing need for internal vigilance.

Roles, Skills, and Governance of an Internal Forensic Investigator

An internal forensic investigator provides a specialized function within the compliance ecosystem. This professional must possess a blend of analytical, legal, and ethical expertise. Recommended competencies include knowledge of healthcare reimbursement models, coding accuracy, and claims analysis; strong investigative skills such as interviewing, documentation review, and evidence preservation; and familiarity with relevant statutes including the False Claims Act, Anti-Kickback Statute, and HIPAA Privacy Rule.

The investigator’s independence is critical. According to the DOJ’s 2020 Evaluation of Corporate Compliance Programs, the credibility of internal investigations depends on independence, competence, and appropriate resources. Investigators should report directly to the Compliance Officer, Board Audit Committee, or General Counsel to avoid conflicts of interest. Collaboration with IT, Human Resources, and Finance is often necessary for effective data gathering and root-cause analysis.

Training and certification enhance credibility. Many investigators pursue credentials such as Certified Fraud Examiner (CFE), Certified in Financial Forensics (CFF), or Certified Professional Compliance Officer (CPCO). The CIFHA curriculum integrates these skill sets by combining investigative methods with forensic analytics and compliance oversight principles, preparing professionals to handle internal inquiries ethically and effectively.

A Realistic Scenario: The Case of EchoHealth Radiology Network

EchoHealth Radiology Network, a midsize radiology provider, noticed a rise in payer denials and outlier utilization trends within its Magnetic Resonance Imaging (MRI) service line. Routine audits did not reveal significant errors, but a compliance analyst flagged a spike in modifier use for certain spinal studies. The internal investigator initiated a forensic review and uncovered that one radiology group had systematically upcoded imaging services at the direction of a billing manager. Interviews revealed that coders were encouraged to “maximize revenue” by adding modifiers without sufficient documentation.

  • The investigator traced the pattern across six facilities, identified more than $1.2 million in questionable claims, and confirmed documentation gaps.
  • Because the issue was identified internally, EchoHealth voluntarily disclosed the overpayments, retrained coding staff, and implemented a pre-billing review process. The early forensic response protected the organization from potential False Claims Act liability, demonstrated good-faith remediation, and reinforced a culture of compliance and accountability.

Key Benefits and Return on Investment

According to the Government Accountability Office (GAO, 2023), proactive detection and response programs can reduce fraud-related losses by as much as 40 percent. The presence of an internal investigator also promotes a culture of transparency and reinforces the ethical tone of leadership. Internal forensic capacity delivers benefits such as early risk identification, reduced penalties through self-disclosure, improved internal controls, and measurable cost avoidance. Organizations that invest in forensic auditing capability often discover that the savings from avoided regulatory penalties and recovered funds exceed the cost of the program itself.

  • From a compliance culture standpoint, the visibility of an internal investigator acts as a deterrent. 

Employees are more likely to report concerns through proper channels when they see issues being addressed promptly and professionally. This aligns with the OIG’s emphasis on maintaining effective lines of communication and timely corrective action in healthcare compliance programs (OIG, 2023).

Challenges, Limitations, and Mitigations

Despite its value, integrating forensic auditing within compliance presents challenges. Resource limitations are common, particularly for smaller providers. Legal considerations such as maintaining privilege and confidentiality require coordination with counsel. Data analytics and automation can introduce false positives that distract investigators from genuine issues. To mitigate these challenges, organizations can start with pilot programs, outsource complex investigations as needed, and establish clear investigation protocols aligned with OIG and DOJ standards.

Another challenge involves maintaining staff trust. Employees may perceive investigations as punitive rather than corrective. Compliance leaders can address this by communicating the purpose of forensic reviews as a means of protecting both the organization and its workforce. Transparency, education, and post‑investigation feedback sessions can reduce anxiety and improve cooperation.

Alignment with CIFHA Goals

Certified Internal Forensic Auditor

This article—the first in a three-part series—introduces an essential component of the CIFHA curriculum: the intersection between compliance and forensics, embodied in the role of the internal investigator. The next two articles in this series will continue to build upon this foundation:

  • Article 2: “10 Common Mistakes in Internal Investigations—And How to Avoid Them” will draw directly from the CIFHA course section on Accepting the Investigation. It will offer practical insights into how investigators can recognize and avoid common sources of bias, procedural missteps, and compliance pitfalls that compromise investigative integrity.
  • Article 3: “From Findings to Action: Writing an Objective, Defensible Investigative Report” will focus on the analytical and reporting phase—how to synthesize data, present factual findings, and communicate results effectively and ethically. It will demonstrate how the course equips participants to transform raw information into defensible, actionable reports that withstand regulatory and legal scrutiny.

Together, these articles trace the natural progression of the investigative process—from recognizing the need for internal forensics, to conducting unbiased inquiries, to articulating findings that drive organizational accountability and improvement.

Conclusion

Healthcare organizations that embed forensic auditing within compliance are better positioned to detect misconduct, preserve integrity, and demonstrate proactive risk management. According to the DOJ and OIG, organizations that identify and correct issues internally are viewed more favorably in enforcement actions. Internal investigators serve as both a safeguard and a strategic asset—protecting financial integrity while promoting an ethical culture. As healthcare continues to evolve, forensic auditing will remain a cornerstone of mature compliance programs that prioritize transparency, accountability, and continuous improvement.

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Office of Inspector General (OIG). (2023). Compliance Program Guidance for Hospitals.
  • U.S. Department of Justice (DOJ). (2020). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Centers for Medicare & Medicaid Services (CMS). (2023). Improper Payments Data.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Health Care Compliance Association (HCCA). (2024). Best Practices in Internal Investigations.
  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • U.S. Department of Health and Human Services (HHS). (2024). Health Care Fraud and Abuse Control Program Annual Report.
  • Compliance Week. (2023). The Rising Role of Forensic Auditing in Healthcare.
  • Deloitte. (2024). Internal Investigation Trends in the Health Sector.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

The Challenge of Conducting Internal Investigations

Why do interviewees try to deceive you?   


Written by Meric Craig Bloch, Certified Fraud Examiner, Certified Financial Crime Specialist, Certified Compliance and Ethics Professional-Fellow, Professional Certified Investigator    

Does the name Meric Craig Bloch “ring a bell”?  If you completed the AIHC Internal Forensic Auditor - Conducting Investigations certification course, then it should!  Meric is the author of the textbook for the investigative interviewing lessons. One of the biggest challenges we face when investigating a complaint as a healthcare administrator or compliance officer is obtaining facts.  Do you know how to tell if someone is being deceptive?  

Interviewees try to deceive you because they believe that deception will help them more than telling you the truth. You need to convince the interviewee that telling the truth will be better for them than lying through the interview.

Deception means that the interviewee is taking steps to keep the truth from you. Lying is a type of deception, but it is not the only type.

Lying is not natural human behavior. It must be done consciously. Consequently, it can be seen. And do not jump to conclusions about the reasons the interviewee may be lying. Liars have plenty of reasons for what they do.

One way to detect lying is by comparing it to telling the truth. Because the interviewees are not afraid of the true facts about which you are asking, there is no need for them to be unusually anxious or respond in a convoluted way. Their answers are simple, direct and respond to the question. Look for these characteristics in a truthful interviewee, which will bolster the credibility of their information:

  • The interviewee keeps direct eye contact.
  • The interviewee is audible and clearly spoken.
  • The interviewee speaks directly to you.
  • The interviewee answers your questions without excessive requests for clarification.
  • The interviewee responds to the questions you ask.
  • The interviewee appears relaxed and composed.
  • The interviewee shows interest and concern.
  • The interviewee is cooperative.
  • The interviewee does not try to rush the interview.
  • The interviewee answers quickly without too much thought about the answer
  • The interviewee is open with answers and body language.
  • The interviewee provides information.
  • The interviewee can repeat the same answer or give the same answer if you later ask the same question in a different way.

How many types of lies are there? There are five basic types of lies that the interviewee may use.

The first type of lie is the simple denial. Its simplicity might lead you to think that this type would be chosen often. But many interviewees avoid denying the incident directly. Psychologists call this “cognitive dissonance.” To avoid this, the interviewee will go to great lengths to avoid having to deny it directly.

The second type of lie is the lie of omission. This is the most common type. It is the simplest lie because the interviewee merely tells the truth but leaves out the information that could be embarrassing or incriminating. Because the remaining part of the interviewee’s statement is true, it can be repeated consistently. If the interviewee is presented with the omitted information, they can just say they forgot to mention it. A lie of omission can only succeed if you are not prepared to force the subject, for example, by mentioning the excluded information.

The third type is the lie of fabrication. This is the most difficult type of lie because it requires the interviewee to be inventive and have a good memory so that the lie is still consistent. This type of lie also creates the most stress for the interviewee.

Ask questions when this type is suspected to show that the explanation does not hold up to specific questioning. If the investigation can disprove the interviewee’s sequence of events or details it may prove as damning as a confession of wrongdoing.

The fourth type of lie is minimization. Here, the interviewee offers a small admission of fault hoping that you will be satisfied and stop any further questioning. When this type of lie is used, it is a strong sign that other information is being withheld.

The final type of lie is the lie of exaggeration. An interviewee may exaggerate the actions of another person or an aspect of a particular conversation. The lie may be used by someone who wants to increase the value of his information or inflate his own importance. If you keep a healthy skepticism and question each claim, you should be able to find any contractions.

Lies told in an interview can be as powerful as a confession. Lying in a workplace investigation exposes the interviewee to disciplinary action. You must constantly be aware of the possibility that the interviewee is withholding information or intentionally trying to deceive.

Finally, the detection of a lie is not the time for a “gotcha” moment. When it happens, first confirm that you understood the interviewee clearly, and that this was what they intended to say. Second, do not dwell on the topic but move to another one temporarily. (This may lead them to relax, believing that they have fooled you.) Eventually come back to the point and confront them with the details you know. Remember that a lie also leaves you with a factual contradiction the investigation must resolve.

On a related note, if you predict that the interviewee may lie to you, try to preempt it by hinting that you already know the answer to your key questions before you ask them. (Of course, this is most effective when interrogating the subject in the final stages of the investigation.) Boxing in the interviewee so they have no alternative but to give you the truth may be your most-effective path to understanding what happened.

Lying interviewees pose two risks to an investigator. First, falsehoods deny you relevant information and may send you off pursuing leads in the wrong places. Second, proven falsehoods on one or more interview topics destroy the credibility of the interviewee for those topics on which they might have been telling you the truth.

Interviewees will lie to you if they believe that lying helps them more than telling you the truth. It makes sense, therefore, that a good way to get the truth in an interview is to persuade the interviewee that telling the truth is more beneficial than lying.

Liars have different motivations. But try to understand what motivates the lies so you can overcome them. Is it a fear of getting involved? Is the interviewee lying because they fear retaliation from the subject or being labeled a “rat?” Does the interviewee have some minor culpability that they now fear you will link to the larger problem under investigation? If you can understand the motive, you might be able to overcome it and get truthful testimony.

A zero-tolerance towards lying in an investigation is good as a basic rule—as with similar rules, who in your company leadership would oppose it? But it has limited practical value. If you are investigating issues so you can explain them and offer business-focused help, firing someone for lying, however justified, will not get you that information. You need to see a lying interviewee as a challenge, not an opportunity for a “gotcha” moment to get them fired.

If you cannot overcome the interviewee’s desire to lie to you, the integrity of the investigations process requires you to address the falsehood. But you will still have to prove the lie. You will need sufficient facts to show that the interviewee made a deliberate misstatement of fact that was intended to deceive or mislead you. This can be done by assembling sufficient contradictory testimony or circumstantial proof to show, by a preponderance of evidence, that the interviewee’s statement was knowingly false.

Either way, a lying interviewee does not help you gather the relevant facts to give business-focused advice. You must try to sidestep it or stamp it out. It is better to encourage the interviewee to rationalize his behavior in some factual context—like the proverbial hangover caused by a night of drinking, which seemed like a good idea the night before—rather than fight the lie. Admissions of fact would show misconduct, however rationalized. These admissions will bring you closer to your goal.

About the Author

Meric Bloch is the Principal of Winter Investigations, a consulting firm specializing in workplace investigations. Meric has designed, implemented, and managed workplace-investigations processes for multinational public companies. He has trained thousands of HR and compliance professionals to conduct workplace investigations. Meric has personally conducted over 800 workplace investigations globally. Learn more about Meric by visiting his website:  www.winterinvestigations.org.


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 

Read More