Policy required document Healthcare
Health Care Compliance Program Policies and Code of Conduct
The HHS Office of Inspector General's General Compliance Program Guidance describes seven elements of an effective compliance program for anyone who bills federal health care programs.
Four of them are documentary: written policies and procedures including a code of conduct, training and education with records, effective lines of communication including a disclosure program, and enforcement of standards with consequences and incentives.
The other three, compliance leadership and oversight, risk assessment with auditing and monitoring, and response to detected offenses, are operational but produce records the first four depend on.
The guidance is voluntary for most providers. It becomes mandatory by contract for Medicare Advantage and Part D sponsors and their first-tier entities, by state law for some Medicaid providers, by corporate integrity agreement for anyone who has settled with the government, and by accreditor standard for CARF, ACHC and CHAP organizations.
The code of conduct is the one document every version of the requirement names.
Obligation ledger
Who requires it, and what each one says.
| Source | Applies when | What it requires | Status |
|---|---|---|---|
| HHS-OIG General Compliance Program Guidance GCPG, November 2023, Section on compliance program infrastructure | Any health care entity, voluntary | The seven elements, with written policies and procedures and a code of conduct as element one, training and education as element three, open lines of communication and a disclosure program as element four, and enforcement standards with incentives and consequences as element five. Guidance; the Department of Justice and OIG use it to judge program effectiveness in settlements. | Market |
| Medicare Advantage and Part D compliance program requirements 42 CFR 422.503(b)(4)(vi) and 423.504(b)(4)(vi) | MA organizations, Part D sponsors and their first-tier, downstream and related entities | Written policies, procedures and standards of conduct; compliance officer and committee; training; lines of communication; disciplinary standards; monitoring and auditing; prompt response. The seven elements as a condition of the CMS contract. Legally required. | Mandatory |
| Long-term care facility compliance and ethics program 42 CFR 483.85 | Medicare or Medicaid certified nursing facilities | A compliance and ethics program with written standards, policies and procedures, designated oversight, training, reporting channels and enforcement; annual review; larger operators must have a compliance officer and a compliance liaison per facility. Legally required. | Mandatory |
| New York Medicaid compliance program requirement 18 NYCRR Part 521; Social Services Law 363-d | New York Medicaid providers meeting the revenue or provider-type threshold | A compliance program with the seven elements, annual certification to the Office of the Medicaid Inspector General, and written policies including a code of conduct. Legally required by state. | Mandatory |
| Corporate integrity agreements Standard OIG CIA terms | Entity has settled a False Claims Act or similar matter with OIG | A written code of conduct distributed to all covered persons with certification of receipt within 30 days, written policies on the settled conduct, annual training with certification, and annual reports. Contractual, enforceable by stipulated penalties and exclusion. | Mandatory |
| Accreditor standards CARF Section 1.E (legal requirements) and 1.F (financial); ACHC and CHAP governance and compliance standards | You seek accreditation | Written corporate compliance policies and a code of conduct with personnel acknowledgment reviewed at survey. Accreditor expectation, contractual once you apply. | Implied |
Required sections
- Code of conduct: mission and values, commitment to compliance, expectations of every workforce member, duty to report, non-retaliation, consequences, how to reach the compliance officer (element 1; CIAs require distribution to all covered persons)
- Compliance officer and compliance committee charters, reporting line to the board, board oversight and reporting cadence (element 2)
- Written policies on the risk areas relevant to the entity: billing and coding, medical necessity documentation, Anti-Kickback Statute and Stark arrangements, beneficiary inducements, credit balances and overpayment refunds within 60 days, exclusion screening, HIPAA privacy and security cross-reference, quality of care (element 1; GCPG lists these)
- Training and education plan: general compliance training at hire and annually, role-based training, board training, records of completion (element 3)
- Lines of communication: hotline or other anonymous route, open door, disclosure program, non-retaliation, log of reports and dispositions (element 4)
- Enforcement and discipline: consistent consequences, incentives for compliance, documentation of actions taken (element 5)
- Risk assessment process, annual audit and monitoring work plan, and use of OIG Work Plan and audit results (element 6)
- Response to detected offenses: investigation procedure, corrective action, self-disclosure protocol, overpayment reporting and return (element 7)
- Exclusion screening of employees, contractors and vendors against the LEIE and state lists at hire and monthly (GCPG recommendation; CIA requirement)
- Annual program effectiveness review and board report (GCPG; 483.85 requires annual review; NY requires annual certification)
- Records retention for compliance program documents (six years HIPAA, ten years for False Claims Act exposure is the common practice)
- Contractor and vendor flow-down of compliance obligations (MA and Part D first-tier and downstream entities)
What the examiner asks for
What changed
Change log.
Who looks at it
Where this document gets checked.
No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.
| Where it is looked at | Who looks at it |
|---|---|
| 42 CFR Part 2 | HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification |
| ACHC/CHAP | ACHC and CHAP surveyors employed or contracted by each accreditor, typically clinicians with home care or hospice experience. Surveys for Medicare deemed programs are unannounced |
| CARF | CARF surveyors, who are peer professionals employed in accredited or comparable organizations, trained and assigned by CARF. Surveys are scheduled and on site for two to three days |
| HIPAA | Government enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary |
| OIG 7-element program | No certification. OIG, DOJ, and CMS evaluate program effectiveness during investigations and audits; organizations under a corporate integrity agreement are reviewed annually by an independent review organization. Boards and internal audit typically commission periodic effectiveness reviews |
Who helps write it
Consultants.
Firms that name these standards in their own material.
No firm has claimed a listing for this document yet. Claim yours →
Where it lives
Software.
Tools that hold documents like this one and record who has read them.
Need a hand implementing it?
Find a Consultant for Health Care Compliance Program Policies and Code of Conduct
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Manage This Document in AllyMatter
Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.
Questions
What people ask.
Is a compliance program legally required?
For most providers it is guidance, not law. It becomes law by contract for Medicare Advantage and Part D participants, by regulation for nursing facilities, by state law in New York and a few other states, and by corporate integrity agreement after a settlement. The Department of Justice evaluates the program's effectiveness when deciding penalties, which is why nearly everyone treats it as required.
What is the difference between the code of conduct and the policies?
The code is a short statement of values and expectations that every person receives and certifies. The policies are the detailed procedures for each risk area. OIG says both are element one.
Do board members have to be trained?
The GCPG recommends board education on compliance oversight and the entity's risk areas. Corporate integrity agreements require it. Nursing facility rules require the governing body to oversee the program.
How often do we re-certify the code of conduct?
At hire and after each revision at minimum. Annual re-certification alongside annual training is the norm and is required under most corporate integrity agreements.
Who owns this site?
AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.