Compliance Program Effectiveness

Compliance Program Effectiveness

An effective compliance program is essential for healthcare organizations to prevent fraud, waste, and abuse; ensure regulatory adherence; and foster an ethical organizational culture. RHIA professionals play important roles in compliance programs, particularly in areas related to coding accuracy, documentation integrity, and privacy/security. This topic covers the structure, elements, and evaluation of compliance programs.

Regulatory Foundation

The Office of Inspector General (OIG) of the U.S. Department of Health and Human Services has issued compliance program guidance for various healthcare sectors, including hospitals, physician practices, clinical laboratories, and home health agencies. These guidance documents build on the Federal Sentencing Guidelines, which identify seven elements of an effective compliance program. Organizations that maintain effective programs may receive reduced penalties if violations occur.

Seven Elements of an Effective Compliance Program

The OIG guidance and Federal Sentencing Guidelines identify seven core elements:

ElementDescriptionHIM Connection
1. Written policies and proceduresClear, accessible documentation of compliance expectations covering coding, billing, documentation, privacy, and operational areasHIM departments maintain coding policies, documentation guidelines, and release of information procedures
2. Compliance officer and committeeA designated compliance officer with authority and resources, supported by a multidisciplinary compliance committeeHIM directors frequently serve on the compliance committee; coding managers may serve as subject matter experts
3. Education and trainingRegular training for all employees on compliance policies, code of conduct, and job-specific regulatory requirementsHIM provides training on proper documentation, coding guidelines, and HIPAA requirements
4. Communication (reporting mechanisms)Open lines of communication including anonymous reporting mechanisms (hotlines, web portals) for employees to report concerns without fear of retaliationHIM staff must know how to report documentation concerns, potential upcoding, or privacy breaches
5. Auditing and monitoringRegular internal audits to detect compliance issues, with ongoing monitoring of risk areasCoding audits, documentation audits, and release of information audits are core HIM compliance activities
6. Enforcement and disciplineConsistent enforcement of compliance policies with clearly defined disciplinary actions for violationsApplies equally to physicians who refuse to complete records and to coders who deviate from guidelines
7. Response and corrective actionPrompt investigation of detected problems, implementation of corrective actions, and prevention of recurrenceWhen coding audits reveal patterns of error, corrective action plans include retraining and re-auditing

Compliance Program Structure

The compliance officer typically reports to the CEO or the board of directors to ensure independence from operational pressures. The compliance committee is a multidisciplinary group that may include representatives from HIM, legal, finance, clinical departments, human resources, and information technology. This structure ensures that compliance concerns from all areas of the organization are addressed.

Coding Compliance

Coding compliance is a major focus area within healthcare compliance programs. The OIG has identified several risk areas:

  • Upcoding: Assigning a code that results in higher reimbursement than what the documentation supports.
  • Unbundling: Separately billing for services that should be reported as a single bundled code.
  • DRG creep: A systematic trend toward higher-weighted DRGs without a corresponding change in patient acuity or documentation.
  • Duplicate billing: Submitting multiple claims for the same service.
  • Insufficient documentation: Submitting claims for services where the medical record does not support the medical necessity or level of service coded.

To address these risks, organizations conduct regular coding audits using a statistically valid sample, compare their coding patterns to external benchmarks, and implement corrective action plans when issues are identified.

Auditing and Monitoring

Effective compliance programs distinguish between auditing and monitoring:

  • Auditing: A formal, systematic examination of compliance with specific standards. Audits are typically periodic, use defined methodologies and sample sizes, and produce documented findings. Examples include prospective coding audits (pre-billing), retrospective coding audits (post-billing), and documentation audits.
  • Monitoring: Ongoing, routine review of processes and data to identify trends or anomalies. Monitoring is more continuous and may involve dashboards, exception reports, or automated alerts. Examples include tracking denial rates, monitoring coding pattern changes, and reviewing access logs for inappropriate PHI access.

The Role of HIM in Compliance

HIM professionals are uniquely positioned to support compliance programs in several ways:

  • Conducting and overseeing coding audits for accuracy and adherence to official guidelines.
  • Developing and maintaining clinical documentation improvement (CDI) programs that ensure documentation supports the codes assigned.
  • Managing release of information processes to ensure HIPAA compliance.
  • Maintaining the integrity of the legal health record and ensuring proper record retention and destruction.
  • Participating in compliance committee activities as subject matter experts on documentation and coding standards.
  • Providing education to physicians and other clinicians on documentation requirements.

False Claims Act and Anti-Kickback Statute

Two federal laws form the backbone of healthcare fraud enforcement:

  • False Claims Act (FCA): Imposes liability on any person who knowingly submits false claims to the government. "Knowingly" includes actual knowledge, deliberate ignorance, and reckless disregard. The FCA includes a qui tam (whistleblower) provision that allows private citizens to file suits on behalf of the government and receive a portion of any recovery.
  • Anti-Kickback Statute (AKS): Prohibits offering, paying, soliciting, or receiving anything of value to induce or reward referrals for services covered by federal healthcare programs. Violations can result in criminal penalties, civil monetary penalties, and exclusion from federal programs.

Measuring Program Effectiveness

An effective compliance program must demonstrate measurable outcomes. Key metrics include:

  • Coding accuracy rates (target is typically 95% or higher).
  • Number and resolution time of reported compliance concerns.
  • Training completion rates.
  • Audit findings trends over time.
  • Denial rates related to coding or documentation issues.
  • Number of corrective actions implemented and their outcomes.

Exam Preparation Tips

For the RHIA exam, memorize the seven elements of an effective compliance program. Understand the difference between auditing and monitoring. Know the OIG risk areas for coding compliance. Be prepared to identify the compliance officer's reporting structure and the composition of the compliance committee. Questions may present a scenario involving a coding pattern and ask you to identify the compliance issue and appropriate response.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.