HomePoliciesHealthcareHealth Care Compliance Program Policies and Code of Conduct

Policy  required document  Healthcare

Health Care Compliance Program Policies and Code of Conduct

The HHS Office of Inspector General's General Compliance Program Guidance describes seven elements of an effective compliance program for anyone who bills federal health care programs.

Four of them are documentary: written policies and procedures including a code of conduct, training and education with records, effective lines of communication including a disclosure program, and enforcement of standards with consequences and incentives.

The other three, compliance leadership and oversight, risk assessment with auditing and monitoring, and response to detected offenses, are operational but produce records the first four depend on.

The guidance is voluntary for most providers. It becomes mandatory by contract for Medicare Advantage and Part D sponsors and their first-tier entities, by state law for some Medicaid providers, by corporate integrity agreement for anyone who has settled with the government, and by accreditor standard for CARF, ACHC and CHAP organizations.

The code of conduct is the one document every version of the requirement names.

Also called: OIG seven-element compliance program, Compliance plan, Code of conduct, Corporate compliance program
AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedCode of conduct 2026by name, on record
Element 1 Handledwith AllyMatter
Seven Elements the Modern WayYour code of conduct, acknowledged by every employee and contractor
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee and contractor on record
Re-collected when the code changes
03
Hand the OIG the trail
From $29/mo, 20 editors, unlimited staff (published)

Obligation ledger

Who requires it, and what each one says.

SourceApplies whenWhat it requiresStatus
HHS-OIG General Compliance Program Guidance
GCPG, November 2023, Section on compliance program infrastructure
Any health care entity, voluntaryThe seven elements, with written policies and procedures and a code of conduct as element one, training and education as element three, open lines of communication and a disclosure program as element four, and enforcement standards with incentives and consequences as element five. Guidance; the Department of Justice and OIG use it to judge program effectiveness in settlements.Market
Medicare Advantage and Part D compliance program requirements
42 CFR 422.503(b)(4)(vi) and 423.504(b)(4)(vi)
MA organizations, Part D sponsors and their first-tier, downstream and related entitiesWritten policies, procedures and standards of conduct; compliance officer and committee; training; lines of communication; disciplinary standards; monitoring and auditing; prompt response. The seven elements as a condition of the CMS contract. Legally required.Mandatory
Long-term care facility compliance and ethics program
42 CFR 483.85
Medicare or Medicaid certified nursing facilitiesA compliance and ethics program with written standards, policies and procedures, designated oversight, training, reporting channels and enforcement; annual review; larger operators must have a compliance officer and a compliance liaison per facility. Legally required.Mandatory
New York Medicaid compliance program requirement
18 NYCRR Part 521; Social Services Law 363-d
New York Medicaid providers meeting the revenue or provider-type thresholdA compliance program with the seven elements, annual certification to the Office of the Medicaid Inspector General, and written policies including a code of conduct. Legally required by state.Mandatory
Corporate integrity agreements
Standard OIG CIA terms
Entity has settled a False Claims Act or similar matter with OIGA written code of conduct distributed to all covered persons with certification of receipt within 30 days, written policies on the settled conduct, annual training with certification, and annual reports. Contractual, enforceable by stipulated penalties and exclusion.Mandatory
Accreditor standards
CARF Section 1.E (legal requirements) and 1.F (financial); ACHC and CHAP governance and compliance standards
You seek accreditationWritten corporate compliance policies and a code of conduct with personnel acknowledgment reviewed at survey. Accreditor expectation, contractual once you apply.Implied

Required sections

  • Code of conduct: mission and values, commitment to compliance, expectations of every workforce member, duty to report, non-retaliation, consequences, how to reach the compliance officer (element 1; CIAs require distribution to all covered persons)
  • Compliance officer and compliance committee charters, reporting line to the board, board oversight and reporting cadence (element 2)
  • Written policies on the risk areas relevant to the entity: billing and coding, medical necessity documentation, Anti-Kickback Statute and Stark arrangements, beneficiary inducements, credit balances and overpayment refunds within 60 days, exclusion screening, HIPAA privacy and security cross-reference, quality of care (element 1; GCPG lists these)
  • Training and education plan: general compliance training at hire and annually, role-based training, board training, records of completion (element 3)
  • Lines of communication: hotline or other anonymous route, open door, disclosure program, non-retaliation, log of reports and dispositions (element 4)
  • Enforcement and discipline: consistent consequences, incentives for compliance, documentation of actions taken (element 5)
  • Risk assessment process, annual audit and monitoring work plan, and use of OIG Work Plan and audit results (element 6)
  • Response to detected offenses: investigation procedure, corrective action, self-disclosure protocol, overpayment reporting and return (element 7)
  • Exclusion screening of employees, contractors and vendors against the LEIE and state lists at hire and monthly (GCPG recommendation; CIA requirement)
  • Annual program effectiveness review and board report (GCPG; 483.85 requires annual review; NY requires annual certification)
  • Records retention for compliance program documents (six years HIPAA, ten years for False Claims Act exposure is the common practice)
  • Contractor and vendor flow-down of compliance obligations (MA and Part D first-tier and downstream entities)

What the examiner asks for

Written planThe compliance program description, the code of conduct, and the policy set, each with effective dates and approvals, plus superseded versions. Health care compliance consultants and health law firms write; outsourced compliance officers maintain; policy tools hold versions
AttestationSigned or electronic certification of receipt of the code of conduct per workforce member and per version (CIAs require it within 30 days of distribution); annual training certifications; board training records; conflict of interest disclosures. Policy tools, LMS, compliance management platforms
Operational recordsHotline log and investigation files, disciplinary action log, exclusion screening results, audit and monitoring reports, risk assessment, compliance committee minutes, board reports, self-disclosures and refunds. The compliance officer; hotline vendors; exclusion screening vendors; outsourced audit firms
Technical controlsExclusion screening automation, claims auditing software, hotline platform, access controls for PHI. Exclusion screening vendors, revenue cycle audit tools, hotline vendors

What changed

Change log.

2025-01OIG published Industry Segment-Specific Compliance Program Guidance for nursing facilities (Nov 2024) and stated plans for further segment guidance; verify what has issued since.
2023-11-06OIG issued the General Compliance Program Guidance, replacing the 1998 to 2008 compliance program guidance documents as the general reference and adding quality of care, annual risk assessment and board oversight emphasis.
2019-11-28Phase 3 of the long-term care requirements of participation, including 42 CFR 483.85 compliance and ethics program, took effect. Verify.
1998-02-23OIG published its first Compliance Program Guidance for Hospitals, the origin of the seven-element structure. Verify.

Frameworks

Where this document is required.

Who looks at it

Where this document gets checked.

No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.

Where it is looked atWho looks at it
42 CFR Part 2HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification
ACHC/CHAPACHC and CHAP surveyors employed or contracted by each accreditor, typically clinicians with home care or hospice experience. Surveys for Medicare deemed programs are unannounced
CARFCARF surveyors, who are peer professionals employed in accredited or comparable organizations, trained and assigned by CARF. Surveys are scheduled and on site for two to three days
HIPAAGovernment enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary
OIG 7-element programNo certification. OIG, DOJ, and CMS evaluate program effectiveness during investigations and audits; organizations under a corporate integrity agreement are reviewed annually by an independent review organization. Boards and internal audit typically commission periodic effectiveness reviews

Who helps write it

Consultants.

Firms that name these standards in their own material.

No firm has claimed a listing for this document yet. Claim yours →

Need a hand implementing it?

Find a Consultant for Health Care Compliance Program Policies and Code of Conduct

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Manage This Document in AllyMatter

Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Questions

What people ask.

Is a compliance program legally required?

For most providers it is guidance, not law. It becomes law by contract for Medicare Advantage and Part D participants, by regulation for nursing facilities, by state law in New York and a few other states, and by corporate integrity agreement after a settlement. The Department of Justice evaluates the program's effectiveness when deciding penalties, which is why nearly everyone treats it as required.

What is the difference between the code of conduct and the policies?

The code is a short statement of values and expectations that every person receives and certifies. The policies are the detailed procedures for each risk area. OIG says both are element one.

Do board members have to be trained?

The GCPG recommends board education on compliance oversight and the entity's risk areas. Corporate integrity agreements require it. Nursing facility rules require the governing body to oversee the program.

How often do we re-certify the code of conduct?

At hire and after each revision at minimum. Annual re-certification alongside annual training is the norm and is required under most corporate integrity agreements.

Who owns this site?

AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.