Compliance Risk Management Program: A Healthcare Operator’s Build Guide
June 16, 2026
On this page
Ready to be survey-ready?
What a healthcare compliance risk management program actually is
A healthcare compliance risk management program is a documented, board-accountable system that identifies, scores, mitigates, and monitors regulatory and patient-safety risks across the seven OIG compliance program elements, and holds up under real scrutiny from CMS, The Joint Commission, OCR, and state licensing boards. The strongest versions live in one operational source of truth, not seventeen spreadsheets and a shared drive nobody updates.
The reference document for the field is the HHS-OIG General Compliance Program Guidance (GCPG), released November 6, 2023. The GCPG provides updated descriptions of the seven elements of an effective compliance program that health care entities have long relied upon, and it includes recommendations to conduct annual internal risk assessments, to consider quality of care as a component of the compliance program, and to emphasize the importance of a board’s and executive leadership’s oversight of compliance.
That last clause matters. Compliance officers who report up to a board that actually reads the risk register get further than compliance officers who report into a vacuum. A serviceable program touches all of this at once: CMS Conditions of Participation, TJC Leadership and Performance Improvement standards, the HIPAA Privacy, Security, and Breach Notification Rules, the False Claims Act, the Anti-Kickback Statute, the Stark Law, EMTALA, the DOJ Evaluation of Corporate Compliance Programs, the U.S. Sentencing Guidelines Chapter 8, and the cybersecurity expectations laid out in the NIST Cybersecurity Framework and HHS 405(d) HICP. State Medicaid Fraud Control Units and CMS UPIC contractors sit on top of all of it.
Why this matters right now: the enforcement picture in plain numbers
The DOJ’s annual scorecard is the cleanest read on where federal enforcement lands. In its January 2025 announcement, DOJ reported that False Claims Act settlements and judgments exceeded $2.9 billion in FY 2024, with approximately $1.67 billion coming from the healthcare industry. Whistleblowers filed 979 qui tam suits, the highest single-year total in the statute’s history, and total FCA recoveries since the 1986 amendments now exceed $78 billion. Principal Deputy Associate Attorney General Benjamin Mizer put it plainly: “The False Claims Act and its whistleblower provisions remain a critical tool in protecting the public fisc.” Build assuming the person who files the next qui tam already works for you.
On the privacy side, OCR’s 2024 Report to Congress on Breaches of Unsecured Protected Health Information is sobering. OCR documented 663 large breaches that occurred in 2024, exposing the PHI of 242,908,056 individuals. Hacking and IT incidents accounted for 81% of large breaches. OCR also identified risk analysis, risk management, information system activity review, audit controls, and person or entity authentication as the standards where regulated entities most often fall short.
The dollar consequence lines up with that. According to the IBM and Ponemon 2024 Cost of a Data Breach Report, healthcare recorded the costliest breaches for the 14th consecutive year at an average of $9.77 million per incident, well above financial services at roughly $6.08 million.
On the accreditation side, The Joint Commission tightened the kit in 2024. TJC revised accreditation standards effective July 1, 2024, eliminating more than 200 Elements of Performance and, in infection prevention and control alone, consolidating from 12 standards with 51 EPs down to 4 standards with 14 EPs. Fewer EPs is not less work. TJC President Jonathan Perlin, MD, framed the intent as “fewer but more meaningful” standards. Surveyor attention concentrates on the ones that remain.
How to actually build the program: the seven OIG elements, translated into operator language
The GCPG keeps the same seven elements operators already know, with a sharper edge. OIG’s key new recommendation is that the compliance committee should conduct annual risk assessments to identify and address risk areas, including through policies and procedures, with common risk areas including billing, coding, sales, marketing, quality of care, patient incentives, and arrangements with physicians. Here is what each element looks like when you stop writing policy and start running it:
- Written policies, procedures, and a code of conduct. One library. Version-controlled. Mapped to the standards they satisfy (CMS CoP tag, TJC EP, HIPAA rule). If a surveyor asks for your policy on patient grievances and your team opens three different SharePoint folders, you have a finding waiting to happen.
- Compliance officer and compliance committee. OIG reiterates that every entity should designate a compliance officer with the authority, stature, access, and resources necessary to lead an effective compliance program. The GCPG is explicit that “designating a compliance officer with appropriate authority is essential to the success of the compliance program,” and that the officer should not lead or report to legal or finance.
- Effective training and education. Track who took what, when, and on which version of the policy. The training matrix has to survive a DOJ subpoena, not just an HR audit.
- Effective lines of communication. Anonymous reporting. A grievance pathway patients can actually find. An incident reporting workflow clinicians will use because it takes 90 seconds, not nine minutes.
- Enforcement of standards through disciplinary guidelines. Consistent, documented, and applied the same to the medical director as to the front desk.
- Internal monitoring and auditing. Chart audits, EOC rounds, EM drills, PSV reviews, exclusion checks against the OIG LEIE and state Medicaid exclusion lists (New York, Texas, Florida, and California all publish their own), and a risk register that gets re-scored on a real cadence.
- Response to detected offenses and corrective action. Root cause analysis, CAPA, follow-through, and a closure step that proves the fix held. This is where most programs fall down. The CAP gets written, signed, filed, and never re-verified.
The thread connecting all seven is evidence. The U.S. Sentencing Commission’s Guidelines require that an organization’s governing body be knowledgeable about the content and operation of the compliance and ethics program and exercise reasonable oversight of its implementation and effectiveness. That governance is not decorative. It is the reason a well-run program can materially reduce a fine when violations occur.
The command-center view: what survey-defensible evidence actually looks like
Here is where most programs drift. The policy lives in one system. The chart audit findings live in another. Incident reports sit in a third. Credentialing files are in the medical staff office. The risk register is a spreadsheet on the compliance officer’s laptop. When a CMS validation survey or a TJC triennial lands, nobody can connect a risk to the policy that addresses it, the audit that tested it, the incident that proved the gap, and the corrective action plan that closed it.
That disconnect is the gap we help operators close at AccrediCulture. One operational source of truth where the risk register entry links to the controlling policy, the chart audits and EOC rounds that test it, the incidents and grievances that flag it, and the CAP that resolves it. Real-time visibility for the COO. Survey-ready packets for the compliance officer. Board-level reporting that does not require a week of formatting.
A few specific places this approach pays for itself:
- Risk analysis under HIPAA. OCR’s 2024 report to Congress states that “there is a continued need for HIPAA-regulated entities to improve compliance” and identifies risk analysis and risk management as top areas where entities fall short. An enterprise-wide risk analysis tied to remediation tickets is the single highest-yield piece of evidence you can have on hand.
- Credentialing and exclusion screening. Primary source verification at hire, ongoing OIG LEIE and state Medicaid exclusion checks, and re-credentialing on cycle. One missed exclusion screen on a billing provider is an FCA case in waiting.
- Environment of care and emergency management. EOC rounds, EM drills, life safety logs, and ventilation/temperature monitoring data ready on demand. TJC surveyors routinely pull these on day one.
- Incident and grievance management. Each event scored, trended, and connected back to the risk register. Trends drive the next chart audit, not the other way around.
- Policy management. Effective dates, attestations, and version history that match what training records say staff received.
The DOJ’s Evaluation of Corporate Compliance Programs asks one core question of any program under investigation: is it well designed, adequately resourced and empowered, and does it work in practice? A command-center view answers that question on demand instead of after a 60-day document request.
What operators should walk away with
Compliance officers who build against the GCPG, wire evidence together in one place, and put quality and patient safety inside the compliance program (not next to it) are the ones who survey well. Not because their binders are thicker. Because when a surveyor from Joint Commission, CARF, AAAHC, or COA asks a question, the answer is one click away, and the answer ties to a policy, a training record, an audit, an incident, and a closed CAP. That is what a modern compliance risk management program looks like. That is what we help healthcare operators run.
Frequently asked questions
What are the seven elements of an effective healthcare compliance program under OIG guidance?
Written policies and procedures; a designated compliance officer and compliance committee; effective training and education; effective lines of communication including anonymous reporting; well-publicized disciplinary guidelines; internal monitoring and auditing with risk assessment; and response to detected offenses with corrective action. The 2023 HHS-OIG General Compliance Program Guidance adds an explicit expectation of annual risk assessments, board-level oversight, and incorporation of quality and patient safety into the compliance program.
How often should a healthcare compliance risk assessment be refreshed?
OIG’s GCPG expects the compliance committee to conduct annual risk assessments at a minimum, with event-driven updates whenever something material changes: a new service line, a multi-site acquisition, a new EHR, a regulatory change, a serious incident, or a sentinel event. Multi-site operators typically run a rolling cadence so risk areas are touched on a quarterly basis instead of one giant lift each year.
What are the biggest financial and enforcement risks of getting healthcare compliance wrong right now?
Two numbers frame the exposure. DOJ recovered more than $2.9 billion in False Claims Act settlements and judgments in FY 2024, roughly $1.67 billion of which came from healthcare, driven by a record 979 qui tam whistleblower suits. On the privacy side, OCR reported 663 large breaches in 2024 exposing PHI on 242.9 million individuals, and IBM/Ponemon put the average healthcare data breach cost at $9.77 million, the highest of any industry for 14 straight years.
What documentation will CMS, TJC, or DOJ actually ask to see during a survey or investigation?
The current risk register with dates and scoring, controlling policies mapped to CMS CoP tags and TJC Elements of Performance, training completion by version, exclusion screening logs against the OIG LEIE and state Medicaid lists, chart audit findings, incident and grievance reports with trend analysis, EOC rounds and EM drill records, primary source verification files, and corrective action plans with closure evidence. The DOJ’s Evaluation of Corporate Compliance Programs asks whether the program is well designed, adequately resourced, and working in practice; that question is answered by evidence, not by binders.
References
- HHS-OIG, General Compliance Program Guidance (November 2023)
- U.S. Department of Justice, False Claims Act Settlements and Judgments Exceed $2.9 Billion in Fiscal Year 2024
- HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information (Calendar Year 2024)
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance (2024)
- IBM & Ponemon Institute, 2024 Cost of a Data Breach Report
- The Joint Commission, EP Revisions Effective July 1, 2024 (Joint Commission Online, Feb. 14, 2024)