Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

The Importance of Statistical Significance

Auditing for Compliance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of audit sampling used when Auditing for Compliance, specifically chart or billing audits. It is not intended as being comprehensive, legal, or consulting advice.

Introduction

A statistically significant chart audit in healthcare is a structured, randomized review of medical records designed to project findings onto an entire population of claims (the "universe") with measurable reliability.

The Office of Inspector General (OIG) states these audits be random, unbiased, and sufficiently large to be representative of the population. A common misconception is that a fixed percentage (e.g., 10%) of charts is always sufficient. The OIG does not set a fixed percentage. The sample size must be large enough to provide a reliable estimate of the universe's overpayment amount. A statistically significant chart audit, compliant with OIG guidelines, is a scientifically rigorous process.

In healthcare, audit sampling is crucial when auditing the entire population (100% of claims) is impractical due to high volume. A "statistically valid" sample differs from a simple "probe" or arbitrary sample (e.g., 10 charts) because it allows for the projection of error rates onto the larger population. A statistically valid sample is necessary for:

  • Provider Self-Disclosure Protocol: Submitting self-audits to the OIG.
  • Corporate Integrity Agreements (CIAs): Mandatory compliance for providers under investigation.
  • External Audits: Rebutting audits from Unified Program Integrity Contractors (UPICs) or Medicare Administrative Contractors (MACs).

Even your routine audits should be grounded as statistically significant, which is fundamental when auditing a healthcare organization for compliance. Taking this approach transforms subjective chart reviews into defensible, objective, and scalable evidence that can be used to prove compliance. government agencies.

Statistical significance provides the necessary confidence, typically 90% or higher, that findings from a small sample accurately represent the entire population, minimizing the risk of false positives. Experts often check if the auditor used an appropriate one-sided 90% confidence level, which is a common standard in these audits.

The confidence level defines how often the true population value (e.g., total overpayment) falls within the range calculated from the sample. The precision (Margin of Error) defines the range of accuracy around the point estimate (e.g., +/- $10,000). The trade-off is a higher confidence level (e.g., 99%) which usually requires a wider range of precision, or a significantly higher sample size to maintain precision.

Legal and Regulatory Defensibility

  • Mandatory for Extrapolation - Government contractors, such as Recovery Audit Contractors (RACs), Unified Program Integrity Contractors (UPICs) and Department of Health and Human Services (HHS) Office of Inspector General (OIG) Office of Audit Services, require statistical sampling for projecting overpayment amounts. If an audit lacks statistical significance, it cannot be legally extrapolated to the total claim population.
  • Rebuttal of Audit Findings - Organizations can use statistical expert testimony to challenge improper sampling methods used by auditors, as flawed sampling often leads to inflated repayment demands. Core areas challenged by experts are:
    • Improper Audit Universe/Frame: Auditors may fail to define the correct population of claims, including irrelevant claims or excluding relevant, paid-in-full claims that would balance the error rate.
    • Lack of Randomization/Bias: Experts look for patterns showing the sample was not truly random, such as a sample mean paid amount dramatically higher than the universe mean, indicating a biased selection.
    • Failure to Account for Underpayments: A common, frequently successfully challenged error is the failure of auditors to include underpayments, which skews the audit and "significantly" overstates the overpayment.
    • Imprecise Extrapolation: Even if a sample is random, it may be too small or produce a wide confidence interval (high imprecision), making the projection highly unreliable.
    • Failure to Replicate: Government auditors often fail to document their work sufficiently, making it impossible to reproduce the sample or calculations.
  • Lower Bound Calculation - Statistical methods (like Rat-Stats) calculate the lower limit of a 90% confidence interval, ensuring that recoupment amounts are statistically defensible and conservative.
    • OIG RAT-STATS is a free statistical software package created by the Office of Inspector General (OIG) that provides a "rock-solid," defensible foundation for auditing healthcare claims. It is used to generate random samples, determine sample sizes, and extrapolate error rates to entire populations. It is widely used by auditors, and often by providers in corporate integrity agreements.
    • While RAT-STATS is user-friendly, it requires a thorough understanding of statistics and the software itself to use it properly and to challenge, if necessary, the findings of an audit.

Ensuring Accuracy in Large Datasets

Statistical tools calculate the minimum required sample size (often at least 30 but higher depending on variance) to ensure that the audit has enough power to detect errors without wasting resources on excessive, manual review.

It is important to mitigate potential bias. Statistical sampling prevents "judgmental sampling," where auditors might only select high-dollar or potentially erroneous claims, which would falsely inflate the error rate. To achieve this, we need to address the confidence interval.

Key Components of an Audit Confidence Interval

We strive to reduce "false positives." A 95% confidence level indicates that there is only a 5% chance that observed deviations in documentation or billing were due to random chance, rather than a systematic compliance failure. Let’s dive a little deeper into the confidence level and margins of error.

  • A confidence level (e.g., 95%) is the reliability of the sampling method. A 95% confidence level means that if the audit were repeated 100 times, 95 of the resulting intervals would contain the true population value. Applying a 90% confidence level is a common requirement for CMS contractors to use as a basis for extrapolation.
  • Precision refers to the margin of error or the width of the interval. A tighter (narrower) interval means more precise results, often requiring a larger sample size. Larger samples shrink the confidence interval, providing higher precision. A higher confidence level (e.g., 99% instead of 95%) makes the interval wider (less precise) because you are trying to be more certain.
  • Upper/Lower Limits are the boundaries of the interval, providing the "best-case" and "worst-case" scenario for errors. In healthcare audits, particularly those involving billing compliance, overpayment extrapolation, and quality of care, upper and lower limits define the range of plausible values for a population parameter (such as total overpayment) with a set level of confidence (typically 90% or 95%).
    • Lower Limit (LL): The lowest expected value of the confidence interval. In many CMS audits, the lower limit of a one-sided 90% confidence interval is used to determine the minimum amount of overpayment to be recouped.
    • Upper Limit (UL): The highest expected value of the confidence interval. It represents the worst-case scenario for error rates.
    • Confidence Interval (CI): The full range between the Lower and Upper Limit. A narrower interval indicates higher precision.

Key Statistical Concepts for Auditors

Confidence Levels: The percentage of times (e.g., 90% or 95%) that the true value of an error is expected to fall within the calculated confidence interval.

Null Hypothesis (H0): The assumption that there is no meaningful difference between the audited sample and the expected (compliant) standard.

P-Value: The probability that results were produced by chance. A low p-value (typically $p<0.05$) allows the auditor to reject the null hypothesis and conclude a real, significant error pattern exists.

Randomized & Unbiased: Every claim in the universe must have an equal chance of selection.

Representative: The sample must reflect the characteristics of the entire population.

Standard Deviation: Measures the variation in the data; higher variance in claims requires a larger sample size to achieve statistical significance.

Statistically Valid & Replicable: Another auditor using the same methodology should arrive at similar results.

Universe Definition: The specific time period, the provider, and types of claims being audited (CPT code range 99212-99215 from Jan-Dec 2025).

Limitations to Consider

  • Not Always Meaningful: A statistically significant result (due to a large sample size) does not always mean the error is clinically or financially important.
  • Small Populations: When auditing small departments, high variation may lead to non-significant results, even if errors are present.
  • Requires Expertise: Misapplication of statistical formulas can create misleading conclusions; statistical literacy is crucial for compliance officers.

General Rules of Thumb - When full statistical calculation is not possible, industry guidelines offer the following benchmarks:

  • Small Populations (<100): Audit all records (100% sampling).
  • Large Populations: 10% of the total eligible charts, up to a maximum of 1000, is often sufficient.
  • Rapid Cycle Sampling: Small, consecutive samples (e.g., 5-10 charts) can be used to track changes over time in quality improvement projects and for monitoring purposes.

Conclusion

It’s all about measuring the effectiveness of your compliance program

The effectiveness of the compliance program must identify high-risk patterns. Organizations use statistical significance to track if voluntary changes to coding or billing procedures resulted in significant, measurable reductions in error rates. Taking this approach allows the organization to determine if corrective actions, such as training, efforts to correct Electronic Health Record systems, conducting pre-billing targeted audits, etc. are making the expected improvements required for compliance.

Statistical techniques allow internal auditors to identify trends in data, such as high-frequency billing of complex codes, which indicate potential risk for future external audits.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

CDC

National Library of Medicine

Strategic Management Services

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

OIG’s Focus on Nursing Home Engagement of Medical Directors

Written by Kirsten Taylor-Billups, JD, RN, CHC 

The Nursing Facility Industry Specific Compliance Guidance was published by the Office of Inspector General (OIG) in November 2024 as the first industry-specific guidance since the November 2023 updated general compliance guidance was published. Improving the quality of care and safety of residents within nursing facilities is a top priority for OIG. This educational article is provided for educational purposes only and is not intended as legal or consulting advice.

In June 2025, the OIG workplan was updated to include the Monitoring and Engagement of Medical Directors in Nursing Homes and CMS will begin conducting their reviews in 2026. The scope of the OIG’s focus will be in three areas:

  1. the extent in which medical directors performed required duties in nursing homes,
  2. the extent in which pay-rolled based journal data on medical director’s hours are accurate and useful for oversight, and
  3. opportunities to improve oversight and transparency of nursing homes engagement and funding of medical directors through existing data or other monitoring mechanisms.

Given the up-and-coming medical director reviews by CMS this article will review the regulatory requirements for medical directors in nursing homes, the barriers nursing homes have faced when implementing the regulations and proactive takeaways to consider when analyzing your medical director’s arrangements and the documentation required to quantify the effectiveness of medical director services.

The governing regulations on medical directors in nursing homes we will be reviewing is United States Code of Federal Regulations Title 42 Public Health Chapter IV CMS Part 483-Requirements for States and Long-Term Care (LTC) Facilities section 483.75 Administration. The Administration section requires LTC facilities to be administered in a manner that enables it to use its resources effectively and efficiently to attain or maintain the highest practicable, physical, mental, and psychosocial well-being of each resident. The requirements for medical directors are listed under section 42 CFR 483.75 (i) which indicates the facility must designate a physician to serve as a medical director who will be responsible for implementing resident care policies and coordination of medical care in the nursing facility. The intention of this regulation is to not only provide medical care in the facility but to also provide clinical guidance and clinical oversight on the implementation of resident policies and procedures to help with promoting quality of care and services to nursing homes residents.

The development, implementation and evaluation of resident care policies and procedures must be based on current evidence-based standards of practice and resolve medical and clinical concerns that affect residents’ quality of care and services. This is achieved when the medical director collaborates with the facility leadership (Administrator/ Director of Nursing/ Clinical Staff), attending physicians, physician extenders (nurse practitioners/ physician assistants), and consultants.

Documentation is key - The facility documentation which demonstrates the medical director’s level of involvement will need to be evident within the nursing homes facility assessments and quality assurance and performance improvement meetings. The medical director should be actively involved in the facility assessment process and not just be listed as a participant.

  • The facility documentation should show the medical director’s input in evaluating resident needs, staffing and resources.
  • Document the medical director’s attendance and contributions in meetings updating the facility assessment, during quality assurance and performance improvement (QAPI) meetings, policy reviews, and administrative decisions with the facility leadership team.
  • Record instances where the director intervenes in clinical care such as reviewing diagnoses, prescribing practices, or addressing issues with attending physicians.
  • Documentation should also show that the medical directors’ interventions are based upon current standards of practice.

Despite CMS regulations on Medical Directorships within nursing homes, the OIG has also provided ongoing guidance to medical directors’ roles within nursing homes. Initially in 2000 OIG Compliance Program Guidance for Nursing Facilities, which historically emphasized the risks of physician arrangements and medical director contracts being in violation of Anti-Kickback Statute (AKS), Physician Self-Referral and Stark Laws. In 2008 the Supplemental OIG Compliance Program Guidance for nursing homes and medical directorship expanded to the need for these arrangements to have documentation to show the arrangement was fair market value, document the services being provided, and they’re not sham for resident referrals.

Recently in 2024 OIG Nursing Facility Industry Segment-Specific Compliance Guidance (ICPG), medical directors are explicitly considered a compliance risk when it comes to their contracts, services, and likelihood for kickbacks for referrals. OIG also has enhanced their focus on the clinical and administrative responsibilities of medical directors when it comes to resident care policies and procedures, and quality of care and services and the billing for the services.

In addition to regulatory and operational responsibilities, it is essential for nursing homes to ensure that medical director arrangements comply with federal laws governing physician compensation and referrals. Specifically, the medical director’s role and compensation must be carefully structured and monitored to avoid violations of the physician self-referral law (commonly known as the Stark Law), the Anti-Kickback Statute, and related federal regulations.

  • Stark Law: The Stark Law prohibits physicians from making referrals for certain designated health services payable by Medicare or Medicaid to entities with which they (or an immediate family member) have a financial relationship unless an exception applies. Medical director’s agreements must be in writing reflect fair market value for bona fide services provided and not be based on the volume or value of referrals.
  • Anti-Kickback Statute: This statute makes it illegal to knowingly and willfully offer, pay, solicit, or receive any remuneration to induce or reward referrals of items or services reimbursable by federal health care programs. Medical director’s compensation arrangements must not serve as an incentive for directing referrals to the facility.
  • Physician Self-Referral Law: Overlapping with the Stark Law, this law restricts physician referrals when there is a financial relationship with the facility, unless specific safe harbors or exceptions are met.

OIG and Department of Justice (DOJ) have aggressively pursued nursing homes and related entities for sham medical director arrangements that violated the Anti-Kickback Statute and False Claim Act.

Sham arrangements typically involve payments for referrals rather than bona fide administrative or clinical services, with little or no documentation of actual work performed. There have been several settlements involving sham medical director arrangements for not only nursing homes but for other healthcare entities such as hospitals, home care, and assisted living entities. Here are a few healthcare entities who were in violation and entered into settlement agreements with the DOJ.

  • Prema Thekkek, Paksn Inc., and Six California Skilled Nursing Facilities (2023) entered into a $45.6 million consent judgement with a 5-year Corporate Integrity Agreement (CIA) with HHS-OIG where the settlement resolved allegations of False Claims Act and Antikickback Statute violations from 2009-2021. The basis for the settlement was medical director contracts were not used to pay for legitimate administrative services but pay for patient referrals, physicians were paid monthly stipends ($1,500-$10,000) regardless of actual services provided, physicians hired based on promises of patient refers minimums were met and if the minimum referrals weren’t provided the physician was terminated and the nursing homes documentation requirements for the services provided were not enforced.
  • Village Home Care LLC, CEO and Two Doctors (2023) the collective settlement amount was about half a million dollars for allegedly violating the false claims act and anti-kickback statute. The alleged violations involved sham medical director and sublease agreements used to pay physician for patient referrals with no actual services or use of the subleased space.
  • Phillip Esformes/Esformes Nursing Home Network (2019) settlement for violation of AKS and Fraud that resulted in criminal charges and imprisonment. Alleged large-scale kickback scheme where physicians, marketers, and others (Medical directors and consultants) were paid to refer patients to Esformes skilled and assisted living facilities.

Common themes in OIG/DOJ “sham medical director” cases

Across these and similar nursing home cases, the government tends to focus on a fairly consistent pattern:

  • Little or no documented services: Medical director agreements exist on paper, but there are few agendas, minutes, work product, QAPI deliverables, or time records to back up the payments.
  • Compensation not tied to FMV or effort: Physicians receive flat monthly fees that don’t match any reasonable estimate of hours or complexity, or that are unusually high given the size/acuity of the facility.
  • Referral‑driven motive: Evidence (emails, internal comments, timing of contracts) suggests the purpose of the arrangement was to secure or retain admissions, certifications, or orders, not to obtain genuine medical director services.
  • Duplicative or vague roles: Multiple physicians hold overlapping “medical director” or “quality consultant” titles for the same facility or service lines without clear differentiation of duties.
  • Weak compliance oversight: Compliance is either not reviewing these arrangements or is ignored; there’s no systematic FMV analysis, conflict review, or monitoring of actual performance.

The 2024 Nursing Facility ICPG essentially solidified these concerns for SNFs and are calling out medical director arrangements are being typically used by facilities to disguise kickbacks. Therefore, nursing homes compliance teams are encouraged to rigorously scrutinize the medical director’s contracts for their scope of work, fair market value, and services with quantifiable documentation to support the arrangement.

  • For instance, develop a medical director checklist that can be utilized to determine the essential elements of every medical director contract to determine whether there’s documentation to support fair market value, the amount of hours monthly the medical director spends performing medical director tasks and how to track their hours so their time in the facility as an attending isn’t added to their medical director task and duties.
  • Confirm the medical director is getting compensated for their medical director contracted hours only and not receiving additional compensation or financial incentives (a majority of the assigned residents, below market goods and services, bonuses for patient referrals or not providing the required number of hours and duties as a medical director before receiving their monthly stipend).

In 2025-2026 OIG workplan CMS implemented the requirement that nursing homes report medical director hours in the Payroll Based Journal (PBJ) system whether the medical director is an employee or an independent contractor. PBJ work hours only applies to hours work onsite for medical director roles which means only report the hours the medical directors spend performing medical director duties physically onsite. Therefore, any remote or offsite medical director tasks such as consulting, chart or policy reviews or monitoring performed cannot be reported by the nursing home in PBJ. The PBJ reporting system doesn’t have a separate code for medical directors.

Code 17 - The PBJ code that will have to be used is code 17 for Physician/MD/DO and reports the hours worked in the facility only. So, if a medical director is paid a flat monthly stipend, the facility must determine the actual on site hours worked.

When to Report 0 - If the medical director doesn’t do any onsite medical director duty within a quarter the facility must report a “0” zero on PBJ.

Based upon CMS review of the PBJ system, only 36% of nursing homes have reported PBJ hours for their medical directors. Therefore, the OIG is actively evaluating whether medical directors are performing their duties, whether PBJ date on medical directors is accurate and how to improve transparency and oversight of the medical directors in nursing homes. So, nursing homes can expect to see increased scrutiny of PBJ and reported medical director hours, potential audits comparing medical director contracts, invoices, and PBJ submissions as well as tightening of CMS guidance.

Therefore, nursing home administration, compliance and legal teams should incorporate into their medical director arrangements the following:

  • Maintain detailed logs of onsite medical director time.
  • Ensure the contract specifies onsite expectations.
  • Align invoices with documented onsite hours.
  • Avoid reporting offsite administrative time.
  • Audit PBJ submissions quarterly for accuracy.

Conclusion and Key Takeaways

The upcoming OIG and CMS scrutiny of nursing home medical director arrangements underscore the critical need for compliance, transparency, and robust documentation. Nursing homes must ensure their medical director contracts are clearly defined, reflect fair market value, and are supported by thorough records of onsite services. Avoiding sham arrangements and ensuring adherence to federal laws such as the Stark Law and Anti-Kickback Statute are essential to mitigate legal risks.

Key takeaways include:

  • Maintain detailed, contemporaneous documentation of medical director activities, especially onsite work.
  • Ensure contracts specify the scope of responsibilities and compensation aligns with actual services rendered.
  • Regularly audit Payroll Based Journal (PBJ) submissions for accuracy and compliance, reporting only onsite medical director hours as required.
  • Separate medical director’s duties from other physician roles to avoid duplicative or vague arrangements.
  • Engage compliance and legal teams in ongoing monitoring and evaluation of medical director arrangements to address regulatory risks and prevent enforcement actions.

By proactively addressing these areas, nursing homes can better withstand regulatory review, foster quality resident care, and mitigate any costly enforcement actions for noncompliance with the regulations.

About the Author Kirsten Taylor-Billups, JD, RN, CHC

Blog Kirsten

Kirsten Taylor-Billups is the owner and operator of Legal Healthcare Consulting, with 35 years of experience in acute and post-acute care. She holds the qualifications of Registered Nurse (RN), Juris Doctorate Degree (JD), and Certification in Healthcare Compliance (CHC). Over her 30-year tenure in healthcare, Kirsten has undertaken various roles, including Director of Nursing, Quality Assurance Consultant, Risk Manager, and Corporate Compliance Officer at multi-facility healthcare organizations such as University Hospitals, HCR ManorCare, Common Spirit Health, and Catholic Healthcare Initiatives.

Legal Healthcare Consulting, founded by Kirsten 30 years ago, offers expert services to government contractors and acute and post-acute care facilities in capacities including Chief Compliance Officer, Risk Manager, Quality Assurance Consultant and Mediation services. Kirsten’s extensive expertise and experience are invaluable assets.

If your nursing facility needs assistance with auditing, monitoring, or implementing effective medical director arrangements email a request to Ktaylor7284@legalhealthcareconsulting.com

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

From Findings to Action

Writing an Objective, Defensible Investigative Report 

Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

An internal investigative report represents the culmination of an internal forensic audit or compliance investigation conducted within your organization. It is the most critical deliverable in any inquiry, transforming data, interviews, and evidence into actionable conclusions. According to the Office of Inspector General’s (OIG) 2023 guidance, well-documented investigations not only demonstrate compliance program effectiveness but also protect organizations from regulatory exposure. This article provides tips to writing an objective and defensible investigative report.  For more information on how to conduct internal investigations and drafting your findings, consider registering and certifying as an Internal Forensic Healthcare Auditor (CIFHA) with the American Institute of Healthcare Compliance, a Licensing/Certification Partner w/CMS.

Introduction

In healthcare, the investigative report serves as both the historical record of an inquiry and the foundation for corrective action. Unlike informal summaries or audit notes, investigative reports must withstand scrutiny from regulators, accreditation bodies, and, in some cases, legal proceedings.

A report that is clear, factual, and defensible establishes credibility and demonstrates that the organization maintains a culture of compliance.

According to the U.S. Department of Justice’s 2024 Evaluation of Corporate Compliance Programs, documentation that reflects diligence, transparency, and follow-up is a decisive factor in evaluating the effectiveness of a compliance program. Similarly, the OIG, 2023 identifies timely reporting and accurate documentation as hallmarks of program integrity. Investigative reports thus become more than administrative records; they are compliance evidence.

The American Institute of Healthcare Compliance emphasizes that reporting is not merely a conclusion but an analytical phase requiring objectivity, ethical awareness, and technical precision.

Investigators are expected to synthesize complex data, maintain neutrality, and communicate findings in language that is factual and free from bias. When written properly, the investigative report transforms an incident into an opportunity for systemic improvement and risk reduction.

The Role of the Investigative Report

The investigative report is the official artifact that captures the who, what, when, where, why, and how of an inquiry. In many cases, the report becomes part of the audit trail reviewed by internal and external regulators.

A typical report lifecycle includes several stages—drafting, legal review, management approval, dissemination, and closure. During drafting, investigators must balance thoroughness with clarity. Legal counsel often reviews the document for privilege, tone, and factual accuracy, ensuring it aligns with both organizational policy and legal expectations. Once finalized, reports are stored in secure repositories, contributing to the organization’s compliance data archive.

Collaboration between departments is necessary. Compliance, Risk Management, Human Resources, and Legal must work together. The OIG’s 2024 Compliance Program Effectiveness Resource Guide notes that interdisciplinary collaboration ensures findings are contextualized, recommendations are actionable, and accountability is shared. Reports that integrate multiple perspectives are more defensible and effective.

Key Elements of a Defensible Investigative Report

1.  Clear Purpose and Scope

Every investigation should begin with a clearly defined purpose and scope. This section establishes the reason for the inquiry, outlines the questions to be answered, and defines the parameters of review. The scope should specify dates, departments, and records included. Ambiguity in this section can lead to confusion or accusations of overreach.

2.  Accurate Summary of Allegations

The summary should precisely capture the complaint or triggering event. Avoid loaded language or assumptions of intent. The investigator should record who made the allegation, what was alleged, and how the issue was reported, whether through a hotline, audit, or direct disclosure. The summary sets the foundation for factual neutrality.

3.  Methodology and Data Sources

Transparency in how evidence was collected and reviewed is vital for credibility. A strong methodology section identifies interviews conducted, documents examined, and systems accessed. According to Deloitte’s 2024 Internal Investigations Report, transparency in data collection fosters confidence among regulators and leadership.

4.  Chronological Narrative of Events

A chronological approach provides structure and logic. The Government Accountability Office’s (GAO) 2023 Fraud Risk Framework recommends organizing findings in sequence to demonstrate due diligence. Timelines clarify causation, highlight delays, and show that each step followed procedural fairness.

5.  Presentation of Evidence

Evidence must be presented clearly and factually. Data tables, summaries, and appendices can help. Use neutral phrasing such as “the documentation indicates” or “records show.” Avoid speculation or conclusions not supported by evidence.

6.  Analysis and Interpretation

This section bridges fact and meaning. Investigators should explain how findings relate to policies, procedures, or laws. The Association of Certified Fraud Examiners (ACFE, 2024) advises separating analysis from fact statements to maintain objectivity.

7.  Conclusions and Recommendations

A defensible conclusion synthesizes validated evidence and identifies corrective actions. Recommendations should be measurable and achievable, such as policy revisions, training, or audits. Avoid subjective commentary—focus on remediation, not blame.

8.  Documentation and Appendices

Supporting documentation should be referenced systematically. Attachments should include interview notes, data extracts, or relevant policies. Appendices demonstrate transparency and provide traceability for external reviewers.

Analytical Techniques for Investigative Reporting

Modern investigations increasingly rely on data analytics to support conclusions. According to PricewaterhouseCoopers (PwC’s) 2024 study on compliance analytics, quantitative analysis can identify outliers, correlations, and anomalies that qualitative methods may overlook. Tools such as data visualization dashboards, trend charts, and heat maps can make complex findings accessible to leadership and regulators.  For example, an investigator might analyze billing records to identify patterns of upcoding or duplicate claims. By visualizing data trends over time, the investigator can present evidence more persuasively.

The American Institute of Healthcare Compliance curriculum teaches participants how to interpret financial and operational data, integrating forensic accounting with compliance interpretation. The analytical phase also includes peer review and quality assurance.

According to the Society of Corporate Compliance and Ethics (SCCE, 2024), peer review provides an additional safeguard against bias or oversight. It ensures consistency across investigations and maintains trust in the process.

A Real-World Example: The Case of NorthView Behavioral Health

In 2024, NorthView Behavioral Health conducted an internal investigation after a report alleged improper overtime coding by nursing supervisors. The trained investigator used data analytics to compare scheduled shifts with payroll records, revealing discrepancies across three departments.

  • Interview transcripts and electronic timecard reviews confirmed manual overrides without documentation.
  • The investigator followed American Institute of Healthcare Compliance reporting principles, organizing the findings chronologically and using data tables to illustrate patterns of discrepancy.
  • The final report avoided subjective conclusions, instead focusing on systemic control gaps.

NorthView’s leadership responded by implementing automated shift validation, strengthening oversight protocols, and scheduling quarterly forensic audits. Because the report was objective, transparent, and data-driven, the organization self-disclosed to state regulators and avoided civil penalties. This case demonstrates how defensible reporting can convert a compliance issue into a model of organizational integrity.

Ethics, Language, and Professional Judgment

The ethics of reporting extend beyond accuracy to encompass tone and fairness. Investigators must avoid language that implies guilt or bias. According to the OIG’s 2023 Compliance Guidance, neutral phrasing and avoidance of adjectives that imply motive are essential to credibility. Investigative writing should mirror the impartiality of a court transcript, focusing on fact patterns rather than assumptions.

Professional judgment also plays a role in deciding what to include or omit. Transparency must be balanced with confidentiality and privilege. Collaboration with legal counsel helps determine which sections of a report may be privileged and how to handle sensitive information.

Turning Findings into Action

A defensible report achieves its true value only when findings lead to action. Compliance officers should ensure that recommendations translate into corrective and preventive actions (CAPAs). These may include revising policies, retraining employees, or enhancing data monitoring systems. The OIG (2024) recommends that compliance programs document each corrective action and assess its effectiveness through follow-up audits.

Action plans should be SMART—Specific, Measurable, Achievable, Relevant, and time-bound.

For example, if an investigation reveals inconsistent documentation practices, the CAPA may include targeted documentation training within 60 days and follow-up reviews within 90 days. By tying findings to measurable outcomes, organizations demonstrate accountability and compliance maturity.

Feedback loops are also critical. According to the GAO’s 2023 framework, integrating lessons learned into annual compliance reviews prevents recurrence of systemic issues. Trained investigators are equipped to design these loops, bridging the gap between investigative insight and continuous improvement.

Conclusion

The quality of an investigative report defines the credibility of the entire investigation. It is both a record and a reflection of an organization’s ethics. A defensible report is factual, impartial, and actionable, attributes that align with the standards set forth by OIG, Department of Justice (DOJ), and other oversight agencies. When written properly, the investigative report becomes a tool for learning rather than liability.

Certified Internal Forensic Healthcare Auditor-trained professionals are uniquely positioned to produce such reports. By combining forensic insight, analytical precision, and ethical clarity, they help organizations move from compliance response to proactive risk management. In a healthcare environment where accountability is paramount, the ability to write an objective, defensible report is both a compliance requirement and a professional hallmark of excellence.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • American Institute of Healthcare Compliance – 2025 Certified Internal Forensic Healthcare Auditor curriculum.
  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • Office of Inspector General (OIG). (2024). Compliance Program Effectiveness Resource Guide.
  • U.S. Department of Justice (DOJ). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Deloitte. (2024). Internal Investigations and Reporting Trends in Healthcare.
  • PwC. (2024). Effective Documentation in Corporate Investigations.
  • Society of Corporate Compliance and Ethics (SCCE). (2024). Peer Review in Compliance Investigations.
  • Journal of Health Care Compliance. (2023). Ethics and Documentation Standards in Healthcare Audits.
  • Harvard Business Review. (2023). Transparency and Accountability in Organizational Reporting.
  • U.S. Department of Health and Human Services (HHS). (2024). Health Care Fraud and Abuse Control Program Annual Report.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

10 Common Mistakes in Internal Investigations

And How to Avoid Them Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

Internal investigations are among the most sensitive and consequential activities within a healthcare compliance program. A single misstep can compromise objectivity, violate confidentiality, or weaken the organization’s legal position.

This article draws directly from the American Institute of Healthcare Compliance (AIHC) Certified Internal Forensic Healthcare Auditor (CIFHA) course section on Accepting the Investigation, offering practical insights into how compliance professionals can avoid the ten most common mistakes that undermine investigative credibility. By recognizing and mitigating bias, maintaining procedural rigor, and aligning with regulatory expectations, investigators can uphold integrity, transparency, and trust throughout the process.

Introduction

Accepting an investigation is one of the most critical phases of the investigative process. It sets the tone for impartiality, credibility, and compliance alignment. According to the Office of Inspector General’s 2023 guidance, healthcare organizations should ensure that all investigations are handled promptly, independently, and in a manner that promotes accurate fact-finding and appropriate corrective action.

The U.S. Department of Justice (DOJ) echoes this standard, emphasizing that organizations must demonstrate a “culture of compliance” through objective internal inquiry and documentation of remedial steps.

Yet, even experienced compliance professionals can make procedural or ethical missteps that jeopardize outcomes. From failing to define the scope to letting personal bias color the process, each mistake introduces risk—not only to the credibility of the investigation but also to the organization’s standing with regulators. Accepting the Investigation is the first critical step to understand how to recognize these pitfalls and establish a disciplined, unbiased approach.

Ten Common Mistakes in Internal Investigations—and How to Avoid Them

1.   Failing to Define Scope Clearly 

A well-defined scope sets boundaries and expectations. Without it, investigators risk “mission creep”—expanding beyond the original allegations and diluting focus. According to the Health Care Compliance Association (HCCA, 2024), scope definition should occur immediately upon assignment and be approved by compliance leadership. Avoid this mistake by drafting a clear investigative plan that identifies issues, potential evidence sources, and expected deliverables.

2.   Allowing Personal Bias to Influence Judgment

Bias can undermine objectivity, even when unintentional. Investigators may have preconceived notions about the individuals involved or the departments under review. According to the Association of Certified Fraud Examiners 2024 report, confirmation bias is one of the most common cognitive errors in fraud examinations. To mitigate this risk, investigators are encouraged to use a standardized evaluation framework, rely on documented evidence, and involve a peer reviewer when feasible.

3.   Neglecting to Secure Evidence Early

Delays in securing documentation, emails, or system access logs can result in data alteration or loss. Early preservation is critical for maintaining evidentiary integrity. The DOJ’s guidance on corporate investigations recommends issuing immediate document preservation notices and maintaining a clear chain of custody. Compliance officers should coordinate promptly with IT, HR, and legal counsel to secure relevant records.

4.   Ignoring Chain-of-Custody Procedures

Even if evidence is obtained, failure to maintain proper chain-of-custody documentation can render it unreliable. Investigators must track who collected each item, when, and under what conditions. This process ensures credibility in both internal reviews and external proceedings. Adhering to established forensic documentation procedures, such as those outlined in the AIHC Investigations training, protects evidence integrity and supports defensible reporting.

5.   Failing to Document Interviews Accurately

Interview summaries form the backbone of many investigations. Inaccurate or incomplete notes can lead to inconsistent conclusions. According to OIG compliance best practices, investigators should use structured templates, record factual statements, and avoid subjective language. Review notes immediately after interviews to ensure accuracy while details are fresh, and maintain them as part of the official investigation record.

6.   Overlooking Confidentiality Protocols

Breaching confidentiality can compromise employee trust and expose the organization to liability. Investigators should disclose only essential information on a need-to-know basis. The OIG’s 2023 General Compliance Program Guidance recommends protecting the identities of whistleblowers and limiting discussion of investigative matters to authorized personnel. Reinforce confidentiality expectations at the outset of every interview.

7.   Mismanaging Communication with Legal Counsel

Failure to coordinate properly with legal counsel can result in privilege issues or inconsistent messaging to regulators. Investigators should engage counsel early in the process, particularly when there is potential for self-disclosure or legal exposure. Counsel can help preserve attorney-client privilege and guide how findings are shared externally.

8.   Failing to Distinguish Between Facts and Assumptions

Investigations must rely on verifiable facts rather than assumptions or opinions. Mistaking interpretation for evidence can erode the report’s credibility. Investigators should clearly separate facts, analysis, and conclusions in their notes and reports. According to Compliance Week (2023), factual accuracy is the single most important determinant of whether an investigative report is considered defensible under regulatory review.

9.   Rushing to Conclusions or Recommendations

Pressure to conclude quickly can lead to incomplete analysis or unjustified findings. The CIFHA curriculum emphasizes patience and thorough review—investigators should evaluate all available data and corroborate key points before finalizing conclusions. Interim summaries and peer reviews can provide checkpoints for accuracy and completeness.

10.  Neglecting Follow-Up and Corrective Actions

An investigation is incomplete if it fails to lead to corrective action. According to the Government Accountability Office’s 2023 Fraud Risk Management Framework, closure should include documented remediation steps, training updates, and monitoring plans. Compliance officers should track outcomes to ensure identified risks are addressed and similar issues do not recur.

Building Investigative Integrity: Best Practices

The American Institute of Healthcare Compliance emphasizes that the credibility of an investigation depends on procedural rigor, ethical consistency, and adherence to compliance principles. Best practices include maintaining neutrality, engaging legal counsel early, and ensuring every step—from planning to reporting—is supported by clear documentation. Investigators should continuously assess their own potential biases and seek peer consultation when objectivity might be compromised.

Other proven strategies include developing investigation charters, maintaining secure digital evidence repositories, and conducting post-investigation debriefings. These steps not only enhance transparency but also create a feedback loop that improves organizational learning.

Conclusion

Conducting a compliant and credible internal investigation requires planning, impartiality, and discipline.

Each of the ten mistakes outlined above can erode trust and expose an organization to risk if not proactively addressed. By integrating appropriate protocols in your investigative framework, healthcare professionals can ensure investigations are fair, defensible, and aligned with regulatory expectations.  When investigators accept assignments with integrity and preparedness, they transform investigations from reactive responses into proactive tools for organizational improvement and compliance maturity.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • U.S. Department of Justice (DOJ). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Health Care Compliance Association (HCCA). (2024). Best Practices for Internal Investigations.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Compliance Week. (2023). Maintaining Objectivity in Internal Investigations.
  • Deloitte. (2024). Emerging Trends in Healthcare Investigations.
  • Office of Inspector General (OIG). (2023). Compliance Program Effectiveness Resource Guide.
  • U.S. Department of Health and Human Services (HHS). (2024). Healthcare Fraud Prevention and Enforcement Action Team (HEAT) Report.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Nursing Home Compliance Audit Tool

Updates to OIG’s Area of Focus on Care & Safety of Nursing Facility Residents  

Written by Kirsten Taylor-Billups, JD, RN, CHC  

The Nursing Facility Industry Specific Compliance Guidance was published by the Office of Inspector General (OIG) in November 2024 as the first industry-specific guidance since the November 2023 updated general compliance guidance was published.  Improving the quality of care and safety of residents within nursing facilities is a top priority for OIG. Quality of care and safety are matters of critical importance for residents, their loved ones, and the nursing facility workforce. The Nursing Facility ICPG, together with the GCPG, addresses the Government and private industry’s shared goals of reducing fraud, waste, and abuse; promoting cost-effective and quality care; enhancing the effectiveness of providers’ operations; and propelling improvements in compliance, quality of care, and resident safety within nursing facilities.

The Office of Inspector General (OIG) continues to have nursing facilities on their radar for compliance guidance and workplans. We’re too far into the year 2025 to say “Happy New Year” but your nursing facilities aren’t too far along into the new year to revise their compliance programs auditing and monitoring tools. In late 2024, OIG released the Nursing Facility Industry Segment Specific Program Guidance (ICPG) which is the OIG guidance for post-acute nursing facilities to update and individualize your compliance programs to promote quality of life, quality of care, risk areas. Together with the General Compliance Guidance Program (GCPG), nursing can mitigate risks as well as other important information OIG believes nursing facilities should consider when implementing, evaluating, and updating their compliance and quality programs. This illustration is from the OIG demonstrating the migration of compliance guidance’s for nursing facilities:

In addition to the ICPG’s release the OIG’s monthly workplan updates should also be considered when updating your compliance programs for your nursing facilities. Upon review of the nursing home focused workplans you’ll see how they correlate with the topics detailed in the ICPG.

Although the Industry Segment Specific Program Guidance (ICPG) for Nursing Homes is not mandatory, the Requirements of Participation for Nursing Home compliance (ROP) which are modeled after the OIG’s Compliance Guidelines, are mandatory.

Nursing homes must adhere to the ROPs established by the Centers for Medicare & Medicaid Services (CMS) to receive reimbursement for Medicare and Medicaid patients. The Compliance Program (ROPs) for nursing facilities include the seven elements the OIG have identified to promote an effective compliance program:

  1. Compliance Policies and Procedures/Compliance Officer are to ensure that all federal and state regulations are being followed;
  2. Training/Education of staff on compliance requirements which the policies and procedures are patterned after;
  3. Auditing/Monitoring which requires routine audits of billing practices, overpayment rates and ethics practices and to ensure staff are following compliance and ethics policies and procedures;
  4. Reassessments/Modifications to one’s compliance program to address identified weaknesses or changes in regulations;
  5. Addressing Quality of Care Issues to ensure care planning is up to date and accurate;
  6. Preventing Abuse with the development of policies and procedures to prevent abuse and neglect; and
  7. Enforcement of disciplinary mechanisms consistently for violations of compliance and ethics policies/procedures and regulations.

The implementation of these seven elements can be utilized to mitigate fines, penalties and enforcements of Corporate Integrity Agreements (CIAs) with the government if violations are identified.

The OIGs Nursing Home ICPG and Workplan recommendations are based upon decades of findings and observations on matters involving nursing homes from audits, investigations, enforcement actions and monitoring of Corporate Integrity Agreements (CIA). The recommendations are also based upon legal actions and investigations by the OIG current enforcement priorities and interactions with owners, operators and leaders of nursing homes, trade associations, resident advocacy groups, and other industry stakeholders.

Agencies Working Together - The OIG, CMS and the Department of Justice (DOJ) and other law enforcement agencies have been working in a concerted effort to pursue nursing facilities that provide grossly substandard care that is being submitted for billing. The government looks at the bills as being fraudulent because the care and services were so inadequate, as if the care and services weren’t provided.

Use the Guidance as a Road Map - The ICPG and Workplans both serve as road maps to help nursing facilities focus their efforts on issue self-identification and corrective actions to minimize the likelihood of civil, criminal or administrative noncompliance. The ICPG has been written to identify specific categories of compliance risk areas such as quality of care and life, Medicare and Medicaid billing requirements, federal anti-kickback statute as well as other areas of risk such as physician self-referrals, anti-supplementation, privacy and security issues within post-acute care facilities. The list of risks isn’t all inclusive, but it is a good starting point. Facility risk assessments can also be used to formulate audit tools and develop action plans so corrective actions can be implemented and operationalized to demonstrate an effective compliance program because compliance manuals sitting on a shelf aren’t going to be adequate.

The OIG currently has 13 active workplans targeted for nursing homes, some of which have been active since 2023 and are being revised and are being brought forward into 2024-2026 compliance OIG reviews. Upon further review of these workplans they primarily fall into two categories. One category being Financial (1-5) and the other category being Quality of Care and Life (6-13):

  1. Skilled Nursing Facilities (SNF) Medicare Payments to Related Parties;
  2. SNFs billing accuracy of Patient Driven Payment Model (PDPM) reimbursement system;
  3. Billing of Medicare part B services during a Medicare Part A stay;
  4. Supplemental Payments for Medicaid;
  5. SNFs Financial Responsibility for Medicare Part D enrollee(s) Medication During Part A stays;
  6. Potentially Preventable Hospitalizations;
  7. Employee Background Checks;
  8. Infection Prevention and Control;
  9. Accuracy of Reported Falls;
  10. Staffing Hours;
  11. Emergency Power Systems;
  12. Accurate and appropriate Reporting; and
  13. Usage of Antipsychotic Medications.

These 13 active workplans should be incorporated into your compliance reviews to some degree as well as conducting periodic audits to ensure your facility is compliant.

OIG’s Financial Focus - The OIGs review of SNFs Medicare payments to related parties includes the cost of services, facilities, and supplies furnished to a provider by an organization, related to the provider by common ownership or control. The allowable cost to the provider should only be an amount equal to the related organization's cost not to exceed the price of comparable services, facilities, and supplies that could be purchased elsewhere.

  • Medicare requires that a reported amount be the lower of either the actual cost to the related organization or the market price for comparable services, facilities, or supplies, thereby removing any incentive to realize profits through these transactions.
  • The OIGs audit examined whether selected SNFs reported related parties as required 42 CFR 413.17 (d) and whether their related-party costs complied with Medicare requirements. The review is partially complete, and the OIG identified SNFs weren’t following proper reporting requirements for payments to related parties. Therefore, OIG made 3 recommendations to CMS to correct the issues and CMS adopted 2 of the 3 recommendations.
  • CMS agreed to develop and implement guidance for SNFs on the appropriate methods for providers to determine their allowable related-party costs; and provide guidance to reeducate MACs on the need to review, grant, and document requests from SNFs for exceptions to cost reporting requirements in compliance with 42 CFR §413.17(d).

Given the OIG has forwarded this area of review into FY 2025 it would be prudent of your own facilities to become familiar with the related parties’ cost report requirements and review your cost reports for allowable related provider cost to determine if your facility is following the regulations. If not, implement an action plan to correct the deficiencies identified.

The other areas of financial focus by the OIG include their review of nursing facility Skilled Nursing reimbursement, Medicare Part B services during a Medicare Part A stay, Supplemental Payments for Medicaid and lastly SNFs Financial Responsibility for Medicare Part D enrollee(s) Medications during Part A stays. These reviews should already be on your annual compliance audit tools to some degree to measure your facilities level of general billing compliance. However, it does help to narrow your focus and identify the areas being reviewed by the OIG in the above listed areas.

When conducting a review of a skilled facilities reimbursement, the review can go back as far as 2019 when the CMS implemented a new payment system Payment Driven Payment Model (PDPM) for determining Medicare Part A payments to skilled nursing facilities. Specifically, CMS implemented the Patient Driven Payment Model (PDPM), a new case-mix classification system for classifying SNF patients in a Medicare Part A covered stay into payments groups under the SNF Prospective Payment System.

Under PDPM, payment is determined by factoring in a combination of six payment components. Five of the components are case-mix adjusted and include a physical therapy component, an occupational therapy component, a speech-language pathology component, a nontherapy ancillary services component, and a nursing component. Additionally, there is a non-case-mix adjusted component to cover utilization of SNF resources that do not vary according to patient characteristics. OIG will determine whether Medicare payments to SNFs under PDPM complied with Medicare requirements.

When it comes to Medicare part B services during a Medicare Part A stay the OIG will determine whether Part B payments to Medicare beneficiaries in NHs are appropriate and whether nursing facilities have effective compliance programs and adequate controls over the care provided to their residents. Medicare pays physicians, non-physician practitioners, and other providers for services rendered to Medicare beneficiaries, including those residing in nursing homes (NHs).

  • Most of these Part B services are not subject to consolidated billing; therefore, each provider submits a claim to Medicare.
  • Since the 1990s, OIG has identified problems with Part B payments for services provided to NH residents. An opportunity for fraudulent, excessive, or unnecessary Part B billing exists because NHs may not be aware of the services that the providers bill directly to Medicare, and because NHs provide access to many beneficiaries and their records.

OIG review of Supplemental Payments from CMS has approved Medicaid nursing facility upper payment limit (UPL) supplemental payment programs in several states. In these States, nursing facilities may be eligible for supplemental payments that, when combined with a base payment, may not exceed a reasonable estimate of the amount that Medicare would pay for the services.

  • Under the UPL supplemental payment programs, a State may use a variety of financing mechanisms to fund that State's share of supplemental payments.
  • Medicaid will determine whether payments States claimed under their Medicaid supplemental payment programs complied with Federal and State requirements and describe how those payments were distributed and used.
  • A review of your cost reports on how your facility utilizes Medicaid UPL payments should be analyzed to determine if your facility is following the regulation.

Last of the financial Workplans is the OIGs review of SNFs financial responsibility for Medicare Part D enrollee(s) medication during Part A stays and whether SNFs complied with federal requirements for assuming financial responsibility for drugs for Part D enrollees in Part A SNF stays.

  • Medicare Part A prospective payments to skilled nursing facilities (SNFs) cover most services, including drugs and biologicals, furnished by a SNF for use in the facility for the care and treatment of enrollees.
  • Accordingly, Medicare Part D drug plans should not pay for prescription drugs related to posthospital SNF care, because payment for the drugs is included in the prospective payment for a Part A SNF stay. A prior OIG audit found that up to $465.1 million in part D total cost was improperly paid for drugs for which payment was available under the part A SNF benefit. That audit also found that some of the drugs administered to part D enrollees during their Part A SNF stays had been provided to the SNFs by the enrollees or their families, even though the SNFs were financially responsible for providing the drugs. For this audit, the OIG will determine whether SNFs complied with federal requirements for assuming financial responsibility for drugs for part D enrollees in part A SNF stays.

When it comes to OIGs active workplans that target quality of care and life areas your organization should focus on the following: Preventable hospitalizations of skilled residents, employee background checks, infection prevention and control, accuracy of documentation of falls and antipsychotics, staffing and emergency systems.

When it comes to potentially preventable hospitalizations of Medicare-eligible skilled nursing residents prior CMS studies found that five conditions (pneumonia, congestive heart failure, UTIs, dehydration, and chronic obstructive pulmonary disease/asthma) constituted 78 percent of the long-term care resident transfers to hospitals, according to the OIG Oct 2022 Workplan item. Additionally, sepsis is often considered a preventable condition when the underlying cause of sepsis can be prevented during the stay.

OIG's review of claims shows that skilled nursing facility (SNF) residents often present with one of these six conditions (pneumonia, congestive heart failure, UTIs, dehydration, chronic obstructive pulmonary disease/asthma, and sepsis) on inpatient hospitalization. The OIG will review inpatient hospitalizations of SNF residents with any of these six conditions and determine whether the SNF provided services to residents in accordance with their care plans and professional standards of practice (42 CFR § 483.21 and 42 CFR § 483.25).

The CMS National Background Check Program established the framework for a nationwide program to conduct background checks on a statewide basis on all prospective direct patient access employees of long term care (LTC) facilities and providers. LTC facilities and providers include skilled nursing and nursing facilities, home health agencies, hospice and personal care providers, LTC hospitals, residential care providers arranging for or providing LTC services, and intermediate care facilities for individuals with intellectual disabilities.

  • The program's purpose is to identify efficient, effective, and economical procedures for conducting background checks. The program will be administered by the Centers for Medicare & Medicaid Services (CMS), in consultation with the Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI).
  • OIG work has shown that not all States complied with the National Background Check program for LTC providers. The OIG will determine whether Medicaid beneficiaries in nursing homes in selected States were adequately safeguarded from caregivers with a criminal history of abuse, neglect, exploitation, mistreatment of residents, or misappropriation of resident property, according to Federal requirements.
  • A random review of your facilities employees’ human resources personnel records for background checks should be standard on your compliance audits and cross references with disciplinary actions of employees.

Audit of Nursing Home Infection Prevention and Control Program Deficiencies - The OIGs nursing home infection prevention and control program deficiency’s objective is to determine whether selected nursing homes have programs for infection prevention and control and emergency preparedness in accordance with Federal requirements. Severe weather events have highlighted the need for and importance of emergency power systems for nursing homes.

  • In 2023 the OIG announced their review of emergency systems which is still an active area of focus for 2025. Nursing homes are required to provide an alternate source of energy (usually a generator) to maintain temperatures to protect residents' health and safety, as well as for food storage, emergency lighting, fire protection, and sewage disposal (if applicable), or to evacuate the residents.
  • Nursing homes with generators must have them installed in a safe location and are required to perform weekly maintenance checks. During OIG onsite inspections of 154 nursing homes in eight States as part of our recent life safety and emergency preparedness audits, numerous facilities that had generators that were more than 30 years old.
  • The OIG plans to conduct ongoing audits to determine the age of nursing home emergency power systems and whether the systems sustain the well-being and safety of their residents. The emergency plans will have to be able to reliable and maintain emergency power, food and water supplies, as well as have alternative facilities for residents who may need to be evacuated per federal regulations.

The “PBJ” - OIG also announced in 2023 their audit of staffing hours reported through the Payroll-Based Journal (PBJ). The PBJ data is used by CMS and other stakeholders to monitor nursing home staffing levels, assess quality of care, and identify compliance issues. The OIG is expected to issue audit findings in 2025.

  • Nursing homes are required to electronically submit complete and accurate direct care staffing information to CMS's Payroll-Based Journal (PBJ) system on a quarterly basis.
  • Direct care staff include nurse and non-nurse staff who, through interpersonal contact with nursing home residents or resident care management, provide care and services to residents to allow them to attain or maintain the highest practicable physical, mental, and psychosocial well-being.

CMS and other stakeholders use the staffing information in the PBJ to:

  1. measure nursing home performance;
  2. better understand the relationship between nursing home staffing levels and the quality of care that nursing homes provide;
  3. identify noncompliance with Federal nurse staffing regulations; and
  4. facilitate the development of nursing home staffing measures.

OIG will audit the nursing staffing hours reported in the PBJ to determine whether the reported hours are accurate and meet regulatory staffing ratios.

Quality of Care - When it comes to Quality of Care, the OIG has actively focused on clinical areas that are high risk, cause serious injuries, increase cost and documentation manipulated to avoid regulatory review. The primary clinical areas targeted are falls and antipsychotic medication prevalence, negative impact and reporting accuracy on the long-term care beneficiaries. The OIGs active review of these clinical measures was in 2023 while falls were announced in 2024, and they both remain on the active workplan for 2025-2026.

  • In the Medicare and Medicaid programs, when a nursing home resident experiences a fall, the nursing home is required to report that fall, and the severity of any resulting injury, in a patient assessment.
  • CMS then uses this information to determine, for each Medicare-certified nursing home, the percentage of residents experiencing falls resulting in major injury. This percentage is posted on CMS's Care Compare website to give consumers information about the relative performance of each nursing home.
  • The OIG will assess the accuracy of the patient assessment data used to calculate nursing home falls rates, identify hospitalizations due to falls with major injury among Medicare enrollees receiving nursing home care using Medicare claims. In the first study, the OIG assessed the extent to which those falls were reported by nursing homes in patient assessments. A review of the characteristics of the people who did not have their falls reported and consider the characteristics of nursing homes that did not report falls among their residents.
  • The OIG will provide additional details about the falls with major injury and hospitalization identified, which could include the amount of time spent in the hospital, the cost of the hospital stays to the Medicare program and enrollees, and outcomes to determine over coding and billing issues.

Use of antipsychotic drugs - The potentially inappropriate use of antipsychotic drugs among nursing home residents remains a concern despite efforts to decrease their use over the last decade. Antipsychotic drugs were developed to treat schizophrenia—a serious mental disorder that is generally diagnosed before the age of 30. These powerful drugs are known to have severe side effects, particularly among elderly individuals with dementia.

  • In 2008, the Food and Drug Administration issued a boxed warning against the use of all antipsychotic drugs among elderly individuals with dementia because of the increased risk of death.
  • OIG raised concerns about the high use of antipsychotic drugs among nursing home residents, and in response, CMS took steps to discourage the use of these drugs by, for example, developing publicly reported quality measures related to the use of antipsychotic drugs among nursing home residents.

More recently, OIG has raised concerns about the potential falsification of schizophrenia diagnoses to make the use of antipsychotic drugs appear appropriate and avoid Federal attention. OIG will conduct an in-depth review of survey reports to:

  1. examine the nature of nursing home citations related to the use of antipsychotic drugs; and
  2. identify vulnerabilities that contribute to the inappropriate use of these drugs.

Conclusion

In summary, your nursing facility compliance audit tools should be comprehensive and updated based upon the trends within the post-acute care nursing home healthcare arena. A comprehensive compliance program should reflect question sets that should include the guidance provided by the newly released Nursing Home Industry Segment Specific Program Guidance to help you target your audits. The OIG’s active Workplans specifically focused on nursing homes should also be taken into consideration. As mentioned, the OIG developed these tools on regulatory findings, some of which have resulted in federal settlements, Compliance Integrity Agreements and negative trends in the industry that resulted in recommendations to CMS. CMS, being the deciding entity, adopted some of the OIG’s recommendations and dismissed others. Despite CMS not acting on all the OIG’s recommendations as a proactive measure the OIG’s findings should be considered, and a sample review of your nursing facilities should be conducted to help emphasize how advanced and proactive your audit and monitoring process may help to mitigate in future regulatory review for your facilities.

About the Author Kirsten Taylor-Billups

Blog Kirsten

Kirsten Taylor-Billups is the owner and operator of Legal Healthcare Consulting, with 35 years of experience in acute and post-acute care. She holds the qualifications of Registered Nurse (RN), Juris Doctorate Degree (JD), and Certification in Healthcare Compliance (CHC). Over her 30-year tenure in healthcare, Kirsten has undertaken various roles, including Director of Nursing, Quality Assurance Consultant, Risk Manager, and Corporate Compliance Officer at multi-facility healthcare organizations such as University Hospitals, HCR ManorCare, Common Spirit Health, and Catholic Healthcare Initiatives.

Legal Healthcare Consulting, founded by Kirsten 30 years ago, offers expert services to government contractors and acute and post-acute care facilities in capacities including Chief Compliance Officer, Risk Manager, Quality Assurance Consultant and Mediation services. Kirsten’s extensive expertise and experience are invaluable assets. She can be contacted via cell at (216) 385-0008 or email Ktaylor7284@legalhealthcareconsulting.com.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Creating a Culture of Compliance: Beyond Policies and Procedures

Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

Avoid sanctions, civil monetary penalties and other consequences resulting from lack of developing an ethical culture of compliance throughout all layers of your organization.  This article addresses basic steps to create an effective culture of compliance in a healthcare organization.

Introduction

In today’s evolving healthcare landscape, compliance is not merely about adhering to rules—it's about fostering an organizational mindset grounded in ethics, accountability, and patient-centered care. While policies and procedures are essential, they only work when consistently upheld by a culture that values transparency, collaboration, and integrity.

This article explores the foundations of a compliance-driven culture, offering real-world examples and practical strategies to help healthcare organizations embed compliance into the fabric of daily operations.

Why Policies Alone Are Not Enough

Healthcare organizations often implement robust compliance policies to meet federal and state requirements. However, documented policies without cultural reinforcement can lead to significant risk. In 2022, for example, Sutter Health paid $13 million to resolve allegations that it submitted inaccurate information to Medicare Advantage plans, partly due to documentation practices that didn't align with federal compliance expectations (U.S. Department of Justice, 2022).

This case, like many others, highlights how written policies must be supported by ethical behavior, staff engagement, and a culture where employees understand—and believe in—why compliance matters.

Key Elements of a Compliance-Driven Culture

1. Leadership Accountability 
Compliance starts at the top. Leaders must consistently model ethical decision-making, engage in open dialogue, and take visible ownership of compliance goals. In a 2023 survey by the Health Care Compliance Association (HCCA), 81% of compliance professionals stated that strong executive support is the most critical factor in building a successful compliance culture (HCCA, 2023).

2. Psychological Safety 
Organizations must create environments where employees feel safe reporting concerns. The Office of Inspector General (OIG) stresses that effective compliance programs include confidential reporting mechanisms and non-retaliation policies (OIG, 2023).

A real-world example comes from the University of Miami Health System, which updated its compliance hotline protocol after an internal review revealed staff hesitancy to report incidents anonymously, fearing disciplinary action (Becker’s Hospital Review, 2021).

3. Role-Relevant Training 
Generic training can result in disengagement and minimal knowledge retention. Instead, organizations should provide interactive, role-specific education that integrates real scenarios. For example, front-desk staff may need HIPAA training focused on verbal disclosures, while clinicians require deeper insight into documentation and informed consent.

4. Compliance Champions 
Designating compliance ambassadors within organizations helps reinforce policies through peer modeling and encourages early identification of concerns. Champions can attend monthly briefings, facilitate team discussions, and elevate issues in real time.

The Role of Multidisciplinary Teams

Every discipline within healthcare interacts with compliance differently. A registered nurse may encounter issues with medication documentation, a billing specialist may question coding irregularities, and a social worker may balance confidentiality with mandated reporting.

When these roles operate in silos, important compliance insights can be missed. Organizations like Kaiser Permanente have implemented interdisciplinary compliance councils to bridge communication gaps, share observations, and build mutual understanding across roles (Kaiser Permanente, 2020).

Embedding Compliance in Daily Practice

To make compliance part of daily operations, consider the following:

  • Routine Huddles: Use brief team meetings to explore ethical concerns or clarify unclear procedures.
  • Visual Dashboards: Display progress on compliance goals or audit outcomes to reinforce accountability.
  • Feedback Loops: Encourage staff to anonymously share observations or suggest improvements.
  • Ethical Storytelling: Share lessons from real incidents (redacted) to show the practical impact of compliance success—or failure.

Common Barriers and Solutions

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Barrier

Barrier

Barrier

Solution

Solution

Solution

Barrier

Barrier

Solution

Solution

Solution

Solution

Burnout and compassion fatigue

Integrate wellness and compliance initiatives. Emphasize that well-rested staff are more alert and compliant.

Fear of retaliation

Publicly reinforce non-retaliation policies. Offer leadership training on how to handle reports respectfully.

Check-the-box mentality

Break trainings into micro-learning modules with real examples. Make them interactive.

Siloed communication

Establish interdepartmental compliance committees or shared reporting tools.

Measuring a Healthy Compliance Culture

A balanced approach includes both measurable data and lived experiences. Indicators include:

  • Quantitative: Hotline usage trends, audit compliance scores, time-to-resolution metrics for reported issues.
  • Qualitative: Team members openly discuss compliance, seek clarification without hesitation, and share real-time feedback with leadership.

For example, Johns Hopkins Medicine publishes an internal compliance scorecard and encourages departments to review and discuss the results in staff meetings (Johns Hopkins Compliance Office, 2023).

Conclusion

An effective compliance program is more than documentation—it’s a culture shaped by people, reinforced through daily actions, and supported by intentional leadership. As healthcare systems face increasing regulatory scrutiny and public accountability, building a compliance culture is no longer optional. It’s a strategic imperative that protects both patients and providers.

Organizations that succeed in this space do so not by fear or formality, but by fostering an environment where doing the right thing is encouraged, expected, and consistently practiced across all disciplines.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Celebrating the Healthcare Compliance Officer

Celebrating the Healthcare Compliance Officer   

The American Institute of Healthcare Compliance is recognizing healthcare Compliance Officers – hats off to you!    

The primary goal of a compliance officer is to mitigate risk.  Compliance officers must keep up with new and evolving regulations to ensure their organization is compliant.  This involves investigating complaints and conducting internal auditing and monitoring for compliance. Larger health organizations have compliance teams and utilize internal auditors to delegate the auditing and monitoring functions within the organization.  Compliance is a complex and difficult job!

Healthcare compliance began as a response to concerns about the quality of healthcare provided by medical practitioners. The compliance profession itself emerged in the 20th Century and has progressed to become a critical part of a healthcare organization’s infrastructure. 

Since then, compliance officers have become indispensable to the successful and safe running of a business. Compliance officers are responsible for ensuring that companies and businesses obey regulations and requirements imposed on them. The field has since diversified to fit all kinds of firms and businesses. Compliance officers are expected to have high ethical standards, to be reliable, honest, and effective to promote not only a culture of compliance, but to ensure quality of care and patient safety.

The Office of Inspector General (OIG) began publishing Compliance Program Guidances (CPGs) in the late 1990s.  These guides were to be used as voluntary, nonbinding documents to support health care industry stakeholders with the intent that they be used for self-monitoring purposes.  Access has been available on the Internet at www.oig.hhs.gov to the public. These include CPGs directed at:

  1. hospitals;
  2. home health agencies;
  3. clinical laboratories;
  4. third-party medical billing companies;
  5. the durable medical equipment, prosthetics, orthotics, and supply industry;
  6. hospices;
  7. Medicare Advantage (formerly known as Medicare+Choice) organizations;
  8. nursing facilities;
  9. physicians;
  10. ambulance suppliers; and
  11. pharmaceutical manufacturers.

More recently, on November 6, 2023, the OIG has published a general compliance program guidance (GCPG) with promise to publish industry-sector specific guidances in the near future.  On February 21, 2024 the OIG stated that the first two industry segment-specific CPGs (ICPGs) will address Medicare Advantage and nursing facilities. OIG intends to publish these guidance documents in 2024, but as of September 2024, we are still waiting for more ICPG information. According to an OIG statement on their website, for the next two ICPGs, OIG anticipates addressing hospitals and clinical laboratories.

About the GCPG vs ICPGs

The General Compliance Program Guidance (GCPG) is a reference guide for the health care compliance community and other health care stakeholders. The GCPG provides information about relevant Federal laws, compliance program infrastructure, OIG resources, and other information useful to understanding health care compliance. This voluntary guide is a document to be updated over time by the OIG.

The GCPG covers the following topics:

  • Health Care Fraud Enforcement and Other Standards: Overview of Certain Federal Laws
  • Compliance Program Infrastructure: The Seven Elements
    • Written Policies and Procedures
    • Compliance Policies and Procedures
    • Compliance Leadership and Oversight
      • Board Compliance Oversight
    • Effective Lines of Communication with the Compliance Officer and Disclosure Programs
    • Enforcing Standards: Consequences and Incentives
    • Risk Assessment, Auditing, and Monitoring
    • Responding to Detected Offenses and Developing Corrective Action Initiatives
  • Compliance Program Adaptations for Small and Large Entities
  • Other Compliance Considerations
  • OIG Resources and Processes

The ICPGs will address the following:

  • Standards for different types of providers, suppliers and other participants in the health care industry subsector or ancillary industry sectors
  • These guidances will be tailored to fraud and abuse risk areas for each industry subsector
  • Outlines compliance measures that participants are expected to take to reduce risk

Free Compliance Resources Offered by AIHC

This Article is Written by the AIHC Education Department.  AIHC offers online training w/certification in the field of Corporate Compliance, Internal Forensic Auditing on How to Conduct Internal Investigations and Auditing for Compliance for those requiring more than on-the-job training.


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Provider Credentialing Verifies Expertise

Written by Angela Chorny, MA, President and CEO of Emerge and See, LLC




Payor Enrollment – An Understated and Overlooked Process


Oh, the all-important question of credentialing! Why do we need to be credentialed and what is it?

Credentialing is the anchor between billing and being PAID. It is one of the most important aspects to healthcare, AND, in many cases, it is REQUIRED!


So, what is credentialing? Credentialing is the process of verifying that a provider’s expertise and qualifications to render care to patients are real and valid, this process is also called Primary Source Verification, or PSV… simply stated.


Many facilities and groups who are accredited by an entity, such as JCAHO, AAAHC, AAAASF (just to name a few), are REQUIRED to complete this process for every provider who is rendering services within the group or facility, especially active, licensed, independent practitioners, or LIPs. The accreditation agency will provide their own list of requirements, but a group or facility may include additional requirements of their own in order to privilege a provider.


The buck doesn’t stop there, though, that’s only about half of the credentialing process. Payor enrollment is an understated and overlooked process. This is where the provider is enrolled into the health plans that they would like to accept from their patients. If the provider is not enrolled in the plan, you will not be able to bill for services rendered, ESPECIALLY with Medicare and Medicaid.


In addition, once the provider is enrolled with the payor/insurance health plan, they are added to the roster of available care in their area… built in marketing! When a patient calls and requests a list of providers that accept their health plan in the area requested, the enrolled provider and/or practice will be on that list provided to the potential new client.


So Why Is Credentialing So Important?


  1. Protecting Patients and Ethics.

    Credentialing is undertaken to determine whether a practice or healthcare professional is fully qualified to treat patients. Patient care has always been the core purpose of medical credentialing. The process itself is rather tedious and involves verifying a practitioner’s credentials against various relevant data points.

    For instance, a provider is continuously monitored against major publications like the Death Master File, Sex Offender Registries, National Abuse Registry, OFAC, and many other sources. A provider can be denied credentialing if their name shows up in any of the above data points.

    Credentialing also monitors sanctions on a provider’s license via the Office of Inspector General (OIG) as well as any possible lawsuits and their outcomes via the National Provider Data Bank, or NPDB. These tools have been put in place and are required to be utilized to help the practice make a determination as to whether the provider should be privileged or employed by the entity. Credentialing can also be denied based on a provider’s license having expired or having defaulted on their student loans.

    Credentialing instills confidence among patients and provides added comfort that the organization wants to provide professional and ethical services to a patient. For example, it would be nice to know that a particular provider in charge of providing treatment to a child is not a registered sex offender or that a psychologist has the qualifications necessary to provide you with sound advice.

    Competency and performance reviews are a fundamental part of the credentialing process. Organizations who implement this process leave no stone unturned in determining whether a practice or healthcare professional is worthy of being credentialed. As a result, patients can feel safe going for treatment to clinics and hospitals whose staff are all credentialed.
  2. Prevents Lost Revenue.

    Insurance carriers do not reimburse for services rendered if the provider and/or entity is not credentialed, or enrolled, with them. It is important to note here, that being enrolled with a payor and being “in network” are two different things. Once the provider is enrolled with the payor, services rendered may then be billed. Becoming “in network” means that the provider now has a contract with the payor and rates are set as per the agreement and cannot be negotiated until the agreement term has expired.

    Furthermore, it is illegal for the payor to reimburse anyone prior to having completed their own Primary Source Verification process. Therefore, at all times, a payor will advise you NOT to see their patients until the provider or organization is credentialed with them.

    Once enrolled with a payor, you are ready to bill for services rendered and will be reimbursed according to the agreed upon fee schedule. You just opened the door to an entirely new set of patients, thereby increasing your revenue!

    In addition, as previously mentioned, the provider will also be added to the roster and registry for patients who call in to request a particular type of provider in their area. So, the payor, is driving more patients through your door.
  3. Mitigate and manage risk.

    With the latest increase in lawsuits over lack of appropriate credentialing on behalf of an entity, it’s one of the most basic parts of your practice that you want to protect. As immunity began to lose ground as a viable legal argument, the 1957 case Bing v. Thunig firmly established that hospitals have an ethical responsibility for the medical care received by patients.

    A few years later, the 1965 case of Darling v Charleston Community Memorial Hospital—in which a staff provider so severely erred in the setting of a broken leg that it eventually had to be amputated—set the legal precedent that a hospital could be held negligent for failing to assess or monitor the competency of their medical staff.

    To limit liability in the aftermath of these cases, hospitals implemented more   rigorous credentialing and privileging protocols. Unfortunately, this led to another problem… Providers being denied appointment or privileges by a hospital’s governing body turned to the Sherman Act and state antitrust laws to claim that the practice of credentialing amounted to anti-competitive collusion. Providers claiming injury under the Sherman Act must demonstrate that the denial or revocation decision negatively impedes the availability of medical services within the community.

    Stuck between a rock and a hard spot of this legal minefield, hospital and medical staff leadership, in particular those assigned with peer review responsibilities, were reluctant to deny medical staff appointment or privileges. The Health Care Quality Improvement Act (HCQIA) of 1986 provided those physicians involved in peer review activities a layer of protection against lawsuits filed by the physician under review in retaliation for a negative decision by their peers. Improperly used, HCQIA can be seen as a shield inviting abuse by those in a peer review position for decisions that benefit themselves directly or indirectly. As a result, antitrust claims continue.

    Over the years, hospitals have recognized that strong and transparent credentialing and privileging processes provide the greatest guarantee of qualified and competent medical staff and the best defense against legal risks. CFR regulations (U.S. Code of Federal Regulations (CFR)  have, as a result, become the best standard for due diligence.

Know the Law


As healthcare credentialing becomes increasingly more important, be sure that you know your way around. Hospitals generally follow a basic credentialing and privileging framework established within the section of the U.S. Code of Federal Regulations (CFR) comprising the Public Health Service Act. However, these CFR Title 42 regulations (Conditions of Participation—CoPs) only specify credentialing and privileging requirements for hospitals to gain or maintain accreditation to participate in Medicare and Medicaid.


Even though Title 42 CoPs do not directly affect hospitals outside of Centers for Medicaid and Medicare Services (CMS) jurisdiction, they are still important to an unregulated health sector operating in a patchwork of federal, state, and civil legal landscape.


Create a Credentialing Process


Be clear on what you expect your providers to present to you for all background checks and scans as well as for payor enrollment purposes. That way, you will be able to streamline. Be sure to assign a person to the task. It can be a very tedious and time-consuming process, so it’s usually best if you have help that can handle all tracking of enrollment applications as well as any expirables that may be coming up.


Don’t miss the reappointment dates! If reappointment dates are missed you are back to square one in the credentialing process of payor enrollment, and if you miss any within your organization, you are no longer in compliance with your accrediting agency and neither is the provider!


If you choose to outsource, which is becoming exceedingly more popular now, be sure to choose a reputable organization. Many organizations are popping up nowadays, so it is definitely important that your Credentials Verification Processor (CVO) knows what they’re doing as regulations absolutely need to be followed.


About My Company


There are also enrollment companies and one stop shops available, such as Emerge and See, LLC where we handle the entire process for you. Emerge and See is based on a solid foundation of seasoned Credentialing Specialists. We become your full-service Credentialing Department while saving you an enormous amount of money on payroll. Please feel free to visit our website at www.emergeandsee.com, it would be our pleasure to be at your service!


As we say in the credentialing world… Happy Credentialing!

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Compliance & Internal Investigations

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




Are you an internal auditor conducting “routine” reviews? Have you ever uncovered erroneous or potentially fraudulent evidence? Once your suspicions have been reported to the Compliance Officer, were you asked to partake in evidence gathering during the investigation? The content of this article is for educational purposes and not intended as consulting or legal advice.


For those of you more experienced auditors, additional training in how to handle evidence during an internal investigation not only advances your career but helps secure evidence that can be used if an actual crime has been committed. I also recommend reading When Healthcare White-Collar Crimes Turn Red, an AIHC blog article from 2021.


Do you need to convince executives that crime is a potential problem for your organization? The Department of Justice (DOJ) posts “News & Noteworthy” cases here. 


What Comes to Mind When You Hear the Word “Forensic”?

 

Most of us think about investigations as seen on television programs, such as “CSI” or “Bones.” Forensic science is a critical element of the criminal justice system – “Forensic scientists examine and analyze evidence from crime scenes and elsewhere to develop objective findings that can assist in the investigation and prosecution of perpetrators of crime or absolve an innocent person from suspicion.”


According to the Merriam-Webster dictionary, the word forensic is defined as the following:

  • Belonging to, used in, or suitable to courts of judicature or to public discussion and debate
  • Relating to or dealing with the application of scientific knowledge to legal problems

Your auditing and compliance skills become valuable to professional law enforcement, but you need to know what, when and how to handle a situation which could potentially turn into criminal charges against someone within your organization. First, let’s start with prevention.


Is It an Internal or External Investigation?


Internal Investigations are conducted by skilled employees (or a consultant under contract working for the organization) trained to perform specialized audits to gather evidence when there is suspected fraud, abuse or crime. These investigations are typically conducted to gather information sufficient for legal counsel to determine whether an external investigation is warranted by the appropriate authorities.  These employees are often referred to as Internal Forensic Auditors or Internal Investigators. For the purpose of this course, we will refer to this position as an Internal Forensic Auditor.


Internal Forensic Auditors report to a Board of Directors, Compliance Officer and/or Audit Committee of the health care organization and typically work under the direction of the organization’s legal counsel.


External Forensic Auditors are independent of the organization they are auditing. They are experts working as an investigator for an accounting or consulting firm, CMS, a police department, the FBI or another agency as described above.


The process of conducting a forensic investigation is, in many ways, similar to the process of conducting an audit, but with some additional considerations. The various stages are briefly described below. 


Step 1: Accepting the Investigation


Review information regarding the matter and consider whether you (and your team) have the necessary skills and experience to accept the work.

  • Forensic investigations are specialized in nature, and the work requires detailed knowledge of fraud investigation techniques and the legal framework.
  • Investigators must also have received training in interview and interrogation techniques and in how to maintain the safe custody of evidence gathered.
  • Investigators must be able to address potential conflicts of interest or bias and achieve objectivity.

Step 2: Planning the Investigation


The investigating team must carefully consider what they have been asked to achieve and plan their work accordingly. The objectives of the investigation will include:

  • Recognize if there is sufficient evidence to warrant a forensic investigation. If so, then anticipate planning required to achieve the following:

      o Identify the type of fraud that has been operating, how long it has been operating for,
    and how the fraud has been concealed;

           Determine deadlines and timeframes to complete the investigation which may
    be driven by regulatory factors;

      o Identify the fraudster(s) involved;

      o Quantify the financial loss suffered by the organization;

      o Gather evidence for potential use in court proceedings;

           Identify the type of report format required and record evidence appropriately; and

      o Provide advice to prevent the reoccurrence of the fraud. 

The investigators should also consider the best way to gather evidence. They may choose the use of computer assisted audit techniques or other various methods appropriate for the situation.


Step 3:  Gathering Evidence – Fact Finding


In order to gather detailed evidence, the investigator must understand the specific type of fraud that is suspected. The evidence should be sufficient to ultimately prove the identity of the fraudster(s), the mechanics of the fraud scheme, and the amount of damage or loss suffered by the organization.


It is important that the investigating team is skilled in collecting evidence that can be used in a court case and in keeping a clear and secure chain of custody until the evidence is presented in court. If any evidence is inconclusive, or there are gaps in the chain of custody, then the evidence may be challenged in court or even become inadmissible. Investigators must be alert to documents being falsified, damaged or destroyed by the suspect(s). 


“Chain of custody” is defined by Dictionary.com as “the order in which a piece of criminal evidence should be handled by persons investigating a case, specifically, the unbroken trail of accountability that ensures the physical security of samples, data and records in a criminal investigation.” To prove the chain of custody, and ultimately show that the evidence has remained intact, prosecutors generally need internal investigators who can testify:

  • That the evidence offered in court is the same evidence they collected or received.
  • To the time and date the evidence was received or transferred to another provider.
  • That there was no tampering with the item while it was in custody.

Evidence can be gathered using various techniques, including: 

  • Testing controls to gather evidence which identifies the weaknesses which allowed the fraud to be perpetrated;
  • Using analytical procedures to compare trends over time or to provide comparatives between different segments of the business;
  • Applying computer assisted audit techniques which may help to identify the timing and location of relevant details being altered in the computer system;
  • Discussions and interviews with employees;
  • Substantive techniques such as: reconciliations, cash counts and reviews of documentation.

Step 4: Analyzing Data


After evidence and facts have been gathered and recorded, it is time to analyze all the data. The goal of data analysis is to determine if there is a relationship between the independent and dependent variables and to look for patterns within the data. 


Recording and organizing data may take different forms depending on the kind of information being collected. The way you collect your data should relate to how you’re planning to analyze and use it. Regardless of what method you decide to use, recording should be done concurrently with data collection if possible, or soon afterwards, so that nothing gets lost and memory doesn’t fade. Some of the things to do with the information collected can include:

  • Gather together information from all sources and observations;
  • Make photocopies of all recording forms, records, audio or video recordings, and any other collected materials to guard against loss, accidental erasure, or other problems;
  • Enter narratives, numbers, and other information into a computer program where they can be arranged and/or worked on in various ways;
  • Perform any mathematical or similar operations needed to get quantitative information ready for analysis;
      o These could include entering numerical observations into a chart, table, or spreadsheet, or figuring the mean (average), median (midpoint), and/or mode (most frequently occurring) of a set of numbers.
  • Transcribe (making an exact, word-for-word text version of) the contents of audio or video
    recordings;
  • Code data (translating data), particularly qualitative data that isn’t expressed in numbers, into a form that allows it to be processed by a specific software program or subjected to statistical analysis; and
  • Organize data in ways that make it easier to work with. This will depend on your research design and your evaluation questions.
      o Consider grouping observations by the dependent variable (indicator of success) they
    relate to, by individuals or groups of participants, by time, by activity, etc.
      o You might also want to group observations in several different ways so that you can study interactions among different variables. 

There are two kinds of data you’re apt to be working with. However, not all evaluations will necessarily include both.

  • Quantitative data refers to the information that is collected as, or can be translated into, numbers which can then be displayed and analyzed mathematically.
  • Qualitative data can be collected as descriptions, anecdotes, opinions, quotes, interpretations, etc. They are generally not able to be reduced to numbers and/or are considered more valuable or informative if left as narratives.

As you might expect, quantitative and qualitative information need to be analyzed differently. The investigation is likely to lead to legal proceedings against one or several suspects. Therefore, members of the investigative team must be comfortable with appearing in court to explain how the investigation was conducted and how the evidence was gathered.


Step 5: Report Your Findings


Draft the report in an objective manner. Do not draw conclusions, just report the facts. The checklist below summarizes what a typical report should contain:

  • Provide a Summary of the Investigation or Case
  • Describe the Investigation Plan
  • Case Notes – Keep an Investigator Diary
  • Information Interview Summaries
  • Interview Reports
  • Analysis of Investigation
  • Conclusion
  • Recommendations and Additional Action(s) Required With This Case
  • Exhibit Listing - attachments and evidence related to the case

Conclusion


An Ounce of Prevention Is Worth a Pound of Cure – So Learn More About Health Care Crime


A little precaution before a crisis occurs is preferable to a lot of legal complications, “bad press” and huge potential losses afterward. Preventing fraud in your organization starts with not hiring criminals! That might sound ridiculous, but are we really doing everything we should during the hiring phase of employees and contractors?


Most organizations are using the LEIE on the OIG website to screen new hires and conduct monthly verifications. But is this enough?


Unverified employees can put your organization at risk with a dramatic impact on your company’s brand reputation, performance and finances. Screening employees at hire, and periodically during employment, is a must for creating a safe workplace.


Below is a “short list” of screening tactics to consider before extending an offer to a candidate for hire. Be sure to review your procedure with legal counsel or a human resources expert to avoid any potential legal consequences with the U.S. Equal Employment Opportunity Commission (EEOC) related to changing your current hiring practices.

  • Criminal background check
  • Office of Inspector General (OIG) Exclusions Database check
  • Education – verify graduation, degree
  • Professional Certifications (check all certifications with the certifying agency – do not accept certificates from the potential employee as proof)

The EEOC has a webpage dedicated to help employers that addresses “Background Checks – What Employers Need to Know.” The information on this page is a joint publication between the EEOC and the Federal Trade Commission or FTC.


When making personnel decisions, which include hiring, retention, promotion, and reassignment, the EEOC states that employers should consider the background of applicants and employees. For example, the EEOC states you may want to consider verifying:

Except for certain restrictions related to medical and genetic information (per HIPAA, addressed further on the EEOC website), it's not illegal for an employer to ask questions about an applicant's or employee's background or to require a background check.


AIHC offers training – a “how to” participate in or conduct an internal investigation. The course is offered online with the option to certify (with a professional proctor online). The program is entitled Internal Forensic Auditor. If this course seems too intense, you may want to begin with the Auditing for Compliance online program.

Read More
General Compliance

Uncompensated Care and DSH (Medicare disproportionate share hospitals)

Written by: Scott Mertie, CHFP, FHFMA, CMPE, CCRS, CHCO, CIFHA (KraftCPAs) and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCSAs (CEO of AIHC)


This article is written for education purposes and should not be considered accounting, consulting or legal advice regarding hospital charity care bad debt and disproportionate share hospitals aka DSH. For more information on filing compliance cost reports, attend the Medicare Cost Report Camp in March 2022 presented by KraftCPAs and sponsored by the American Institute of Healthcare Compliance.


Medicare Uncompensated Care Payments & DSH


Hospitals' charity care and bad debt, together known as uncompensated care, is used to calculate disproportionate-share hospital payments. The Centers for Medicare and Medicaid Services (CMS) distributes a prospectively determined amount of uncompensated care payments to “Medicare disproportionate share hospitals” or better known as “DSH.” This is calculated based on the hospital’s relative share of uncompensated care nationally.

 

As required under law, this amount is equal to an estimate of 75 percent of what otherwise would have been paid as Medicare disproportionate share hospital payments, adjusted for the change in the rate of uninsured people. In this rule, CMS will distribute roughly $8.3 billion in uncompensated care payments for FY 2021, a decrease of approximately $60 million from FY 2020. This estimate of total uncompensated care payments reflects CMS Office of the Actuary’s projections that incorporate the estimated impact of the COVID-19 pandemic.


For FY 2021, CMS will use a single year of data on uncompensated care costs from Worksheet S-10 of hospitals’ FY 2017 cost reports to distribute these funds, in part because CMS has conducted audits of this data. Mindful of the unique challenges facing Indian Health Service and Tribal hospitals and Puerto Rico hospitals, CMS will continue to use data regarding low-income insured days (Medicaid days for FY 2013 and FY 2018 SSI days) to determine the amount of uncompensated care payments for Puerto Rico hospitals and Indian Health Service and Tribal hospitals for FY 2021, similar to the FY 2020 methodology.


Background on the IPPS and LTCH PPS


CMS pays acute care hospitals (with a few exceptions specified in the law) for inpatient stays under the Inpatient Prospective Payment System (IPPS). LTCHs are paid under the Long-Term Care Hospital Prospective Payment System (LTCH PPS). Under these two payment systems, CMS sets base payment rates prospectively for inpatient stays based on the patient’s diagnosis and severity of illness. Subject to certain adjustments, a hospital receives a single payment for the case based on the payment classification assigned at discharge. The classification systems are:

  • IPPS: Medicare Severity Diagnosis-Related Groups (MS-DRGs)
  • LTCH PPS: Medicare Severity Long-Term Care Diagnosis-Related Groups (MS‑LTC‑DRGs).

The law requires CMS to update payment rates for IPPS hospitals annually, and to account for changes in the prices of goods and services used by these hospitals in treating Medicare patients, as well as for other factors. This is known as the hospital “market basket.” The IPPS pays hospitals for services provided to Medicare beneficiaries using a national base payment rate, adjusted for a number of factors that affect hospitals’ costs, including the patient’s condition and the cost of hospital labor in the hospital’s geographic area. Payment rates to LTCHs are typically updated annually according to a separate market basket based on LTCH-specific goods and services.


In 2020, CMS issued a final rule for acute care and long-term care hospitals that ensures access to potentially life-saving diagnostics and therapies by unleashing innovation in medical technology and removing barriers to competition.


On August 2, 2021, the CMS issued the final rule for fiscal year (FY) 2022 Medicare Hospital Inpatient Prospective Payment System (IPPS) and Long-Term Care Hospital (LTCH) Prospective Payment System (PPS). The FY 2022 IPPS and LTCH PPS final rule will be issued in multiple parts. 


The final rule updates Medicare payment policies and rates for operating and capital-related costs of acute care hospitals and for certain hospitals and hospital units excluded from the IPPS for FY 2022. The policies in this IPPS and LTCH PPS final rule build on key priorities to close health care equity gaps and support greater access to life-saving diagnostics and therapies during the COVID-19 public health emergency (PHE) and beyond.


The rule’s provisions seek to:


Sustain hospital readiness to respond to future public health threats;

Enhance the health care workforce in rural and underserved communities; and

Revise scoring, payment and public quality data reporting methods to lessen the adverse impacts of the pandemic and future unplanned events. 


The final rule updates Medicare fee-for-service payment rates and policies for inpatient hospitals and long-term care hospitals for FY 2022. In this final rule, CMS approved 13 technologies that applied for new technology add-on payments for FY 2021. This includes two technologies under the alternative pathway for new medical devices that are part of the FDA Breakthrough Devices Program and five technologies approved under the alternative pathway for products that received FDA Qualified Infectious Disease Product (QIDP) designation. 


Additionally, CMS conditionally approved one technology designated as a QIDP that otherwise meets the alternative pathway criteria but has not yet received FDA approval. After consideration of public comments, CMS also approved six technologies submitted under the traditional new technology add-on payment pathway criteria.


CMS is continuing the new technology add-on payments for 10 of the 18 technologies currently receiving the add-on payment (the remaining 8 technologies will no longer be within their newness period in FY 2021, which includes the Chimeric Antigen Receptor (CAR) T-cell therapies approved for the new technology add-on payment in FY 2019).


In total, 24 technologies are eligible to receive add-on payments for FY 2021. CMS estimates that FY 2021 Medicare spending on new technology add-on payments will be approximately $874 million, nearly a 120% increase over the FY 2020 spending.


CMS is adopting some changes regarding new technology add-on payments for certain antimicrobials for FY 2021:

  • Expansion of alternative new technology add-on payment pathway for antimicrobial products designated by FDA as QIDPs to include products approved under FDA’s Limited Population Pathway for Antibacterial and Antifungal Drugs (LPAD pathway).

o The LPAD pathway encourages the development of safe and effective drug products that address unmet needs of patients with serious bacterial and fungal infections. As is the case for QIDPs, under this policy an antimicrobial drug approved under FDA’s LPAD pathway will be considered new and not substantially similar to an existing technology and will not need to demonstrate that it meets the substantial clinical improvement criterion (the technology will need to meet the cost criterion).

  • CMS is adopting a policy to provide for conditional approval for antimicrobial products that otherwise meet the NTAP alternative pathway criteria but do not receive FDA approval in time for consideration in the final rule. This is to allow eligible antimicrobial products to begin receiving the new technology add-on payment sooner.

o Under this policy, those antimicrobial products that otherwise meet the applicable addon payment criteria will begin receiving the new technology add-on payment, effective for discharges the quarter after the date of FDA marketing authorization instead of waiting until the next fiscal year, provided FDA marketing authorization is received by July 1 of the year for which the applicant applied for new technology add-on payments


Conclusion


CMS estimates total Medicare spending on acute care inpatient hospital services will increase by about $3.5 billion in FY 2021, or 2.7 percent. The Office of Inspector General (OIG) has added reviews of MAC cost report oversight for 2022. This project is described in the OIG January 2022 Work Plan Item. Filing accurate and compliant cost reports should be part of your institution’s risk mitigation program. 


Additional Resources

Read More