Framework Healthcare & Human Services
OIG 7-element program
The seven elements of an effective compliance program come from the HHS Office of Inspector General's compliance program guidance, first issued for hospitals in 1998 and consolidated in the General Compliance Program Guidance published November 6, 2023.
The GCPG is voluntary, but it is the yardstick OIG and the Department of Justice use when they evaluate a health care organization's compliance efforts in fraud investigations, settlements, and corporate integrity agreements, and it mirrors the federal sentencing guidelines.
OIG followed it with industry-specific guidance for nursing facilities in November 2024 and continues to publish segment guidance.
The seven elements are: written policies and procedures including a code of conduct; compliance leadership and oversight (a compliance officer and committee reporting to the board); training and education; effective lines of communication with the compliance officer, including an anonymous reporting channel; enforcing standards through consequences and incentives; risk assessment, auditing, and monitoring; and responding to detected offenses with corrective action and, where required, repayment and self-disclosure.
The written program document, code of conduct, policies, annual risk assessment, work plan, and board reporting are the paper trail an organization is expected to keep.
Who has to comply
Guidance rather than a mandate, but relevant to every organization that bills or supports federal health care programs: providers, suppliers, health plans, pharmaceutical and device manufacturers, and contracted service vendors.
Certain providers must have compliance programs by rule (for example Medicare Advantage and Part D sponsors, and nursing facilities under 42 CFR 483.85), and New York Medicaid providers above a spending threshold must certify to a program under state law.
What you have to write
Documents on this site that OIG 7-element program requires or expects, each with who must have it, the review cycle and the obligations that cite it.
- HIPAA Privacy Policies and Procedures Healthcare
- 42 CFR Part 2 Consent and Redisclosure Policy Healthcare
- Employee Handbook Acknowledgment Workplace
- Health Care Compliance Program Policies and Code of Conduct Healthcare
What the assessor asks to see
An investigator or reviewer asks for the compliance program description and code of conduct, the compliance officer's job description and reporting line, compliance committee and board minutes, policies and procedures with review dates, the annual risk assessment and work plan, training materials and completion records, hotline logs and investigation files, audit and monitoring reports, disciplinary records showing consistent enforcement, exclusion screening records, and overpayment refund and self-disclosure files.
Where the requirement sits: HHS-OIG General Compliance Program Guidance (Nov 2023): elements 1 policies, 3 training, 4 communication, 5 enforcement documentary; 2, 6, 7 operational
Key dates
General Compliance Program Guidance published November 6, 2023. Industry segment-specific guidance for skilled nursing facilities and nursing facilities published November 2024, with further segment guidance planned. OIG has said it will no longer publish compliance guidance in the Federal Register and instead updates it on its website.
What AllyMatter does here
Produces the evidence for elements 1, 3 and 5 and the policy-communication half of element 4.
AllyMatter publishes this site.
Assessors
Who assesses OIG 7-element program
No certification. OIG, DOJ, and CMS evaluate program effectiveness during investigations and audits; organizations under a corporate integrity agreement are reviewed annually by an independent review organization. Boards and internal audit typically commission periodic effectiveness reviews.
No firm has claimed a OIG 7-element program assessor listing yet. Claim yours →
Consultants
Who helps with OIG 7-element program
A broad market of health care compliance consultants, law firms, and outsourced compliance officer providers. Typical engagements are a program effectiveness assessment against the seven elements, an annual risk assessment and audit work plan, policy and code of conduct drafting, and board training.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a OIG 7-element program consultant listing yet. Claim yours →
Software
Tools for OIG 7-element program
Tools that name this framework in their own material.
Related reading
- OIG Issues Updated General Compliance Program Guidance: Overview of Key Elements and ChangesElement-by-element read of the November 2023 guidance, including the new expectations on risk assessment and board oversight.Crowell & Moring
- OIG Publishes General Compliance Program Guidance for the Health Care IndustryPicks out what is genuinely new in the guidance and how it signals OIG's current enforcement posture, for legal and compliance staff.Arnold & Porter
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for OIG 7-Element Program
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of OIG 7-Element Program in AllyMatter
Approve the policies OIG 7-element program asks for, keep every version, and record a named acknowledgment from each person who has to read them.