On this page
Ready to be survey-ready?
What compliance program management actually is
Compliance program management in healthcare is the continuous operating system that turns regulator expectations into daily workflows, evidence, and corrective action. It connects the OIG’s Seven Elements, CMS Conditions of Participation under 42 CFR 482, HIPAA Privacy and Security obligations enforced by HHS OCR, EMTALA, the False Claims Act, the Anti-Kickback Statute, and accreditor standards from The Joint Commission, DNV Healthcare, AAAHC, CARF, and HFAP into one survey-ready record. Done well, operators stop hunting binders the week before a site visit.
HHS-OIG refreshed its expectations in the General Compliance Program Guidance on November 6, 2023. It was the first new general guidance from OIG in 15 years, and it added recommendations to conduct annual internal risk assessments, to consider quality of care as a component of the compliance program, and to emphasize the importance of a board’s and executive leadership’s oversight of compliance.
The numbers explain the urgency. DOJ reported that over $5.7 billion of the more than $6.8 billion in False Claims Act settlements and judgments in FY 2025 involved the health care industry. That figure was a sharp jump from $1.8 billion in healthcare-related recoveries the year before, and healthcare made up 83% of all FCA recoveries in FY 2025. Compliance officers in Texas, Florida, and California are not running a paperwork drill. They are running the system that keeps the doors open.
The Seven Elements, mapped to evidence operators can actually pull
The OIG’s Seven Fundamental Elements read like a checklist. Operators have to translate each one into evidence a surveyor or investigator can hold:
- Written policies, procedures, and standards of conduct. Version history, owners, last review date, attestation logs.
- A compliance officer and committee. Charter, meeting minutes, board reports, escalation paths. OIG confirms the Compliance Officer should report to the CEO with direct access to the board, have equal stature to other senior leaders, and serve as advisor to the CEO, the board and senior leaders on compliance risks.
- Training and education. Role-based curricula, completion rates, attestations tied to HR.
- Effective lines of communication. Hotline intake records, non-retaliation policy, grievance logs.
- Internal monitoring and auditing. Chart audits, EOC rounds, mock surveys, exclusion screening run monthly.
- Enforcement through publicized disciplinary guidelines. Documented actions tied to policy and code of conduct.
- Prompt response and corrective action. CAPAs with owners, root cause analysis, effectiveness checks.
The GCPG also pushes leaders in a direction most compliance officers already saw coming. OIG now expects entities to consider quality of care as a component of the compliance program. Boards and executive teams are expected to demonstrate active oversight, and quality of care now sits inside compliance rather than next to it.
At AccrediCulture we help operators map each element to a live evidence stream. Policy versioning sits next to training attestations. Incidents and grievances flow into the same record as EOC rounds and CAPAs. Credentialing files with primary source verification live where the auditor expects them. One source of truth, not seven inboxes.
What recent enforcement is telling operators to fix
Three regulator signals deserve a place on every compliance committee agenda this quarter.
First, DOJ continues to lean on whistleblowers. Whistleblowers filed 1,297 qui tam lawsuits in FY 2025, the highest number in a single year, and the government opened 401 investigations. If your staff in New York or Ohio cannot get a concern to compliance through a clean, non-retaliatory path, they will use the government’s path. As Deputy Attorney General Todd Blanche put it: “Stopping rampant fraud is a top priority, and this record-breaking year proves the False Claims Act remains one of the government’s most powerful weapons against fraud.”
Second, cyber risk is operational risk. The IBM Cost of a Data Breach Report 2024 put the average healthcare breach at $9.77 million, the costliest industry for the 14th year in a row. HIPAA Security, NIST 800-66 implementation guidance, and incident response readiness belong in the middle of the compliance program, not on the edge.
Third, accreditors keep cycling through the most-cited standards. Joint Commission has long flagged medication management, infection control, environment of care, and life safety as the perennial trouble spots. Under Accreditation 360, the Environment of Care and Life Safety chapters consolidate into a new Physical Environment chapter, and Joint Commission is removing 714 requirements from the hospital accreditation program. Accreditation 360 takes effect January 1, 2026 for hospitals and critical access hospitals. Operators still running last cycle’s checklist will be caught flat-footed.
The operator translation is simpler than the regulator language. Document what you do, do what you document, and fix what breaks before someone else has to.
How operators run one without it owning their week
A working compliance program management approach has five moving parts that all reference each other:
- A single source of truth. Policies, attestations, incidents, grievances, EOC rounds, credentialing files, chart audits, and CAPAs in one place, mapped to specific CMS CoPs and accreditor chapters.
- A real-time risk picture. Annual risk assessment as the floor, not the ceiling. Monthly exclusion screening against the OIG List of Excluded Individuals/Entities, quarterly chart audit samples, ongoing incident and grievance trending feeding the next mock survey.
- Mock surveys you trust. A tracer that follows a real patient from intake to discharge across credentialing, medication management, EOC, infection control, and documentation. Findings flow straight to CAPA with owners and effectiveness checks.
- Credentialing and PSV on a clock. Primary source verification with expirables tracked, re-credentialing on schedule, sanction screening tied to HRIS so the same file does not live in three systems.
- Board-grade reporting. A compliance dashboard the CEO and board actually read, with metrics tied to the Seven Elements and live evidence behind every line.
The reader test is simple. When a TJC surveyor in Pennsylvania asks for the last three EOC rounds, the most recent grievance closed, the policy that governs medication reconciliation with its version history, and the CAPA from the last incident, an operator should answer in minutes, not days. That is what continuous readiness looks like in practice.
Why this work compounds
One more reason operators who do this work the right way pull ahead: Joint Commission has signaled that Accreditation 360 is structured around continuous readiness rather than episodic preparation. The new National Performance Goals emphasize sustained reliability, not just survey preparation. Operators who already run with live evidence will recognize the model. Operators still building binders in the final 90 days will not.
The DOJ data points the same direction. FY 2025’s $6.8 billion in FCA recoveries surpassed the prior record of $6.2 billion set in 2014. Roughly $5.3 billion of those FY 2025 recoveries came from qui tam matters, more than double the approximately $2.6 billion recovered from qui tam actions in FY 2024. Operators who give their teams a clean internal channel close the gap before a relator does.
At AccrediCulture, we help compliance officers, COOs, and chief quality officers run that single source of truth, the live risk picture, the mock survey program, the credentialing clock, and the board report from one command center. The work does not get smaller. It gets organized.
Frequently asked questions
What are the seven elements of an effective healthcare compliance program under the OIG’s 2023 General Compliance Program Guidance?
Written policies and standards of conduct; a designated compliance officer and committee; effective training and education; effective lines of communication; internal monitoring and auditing; enforcement through publicized disciplinary guidelines; and prompt response with corrective action. The November 2023 GCPG kept all seven and added explicit recommendations to conduct annual internal risk assessments, to consider quality of care as a component of the compliance program, and to emphasize board and executive leadership oversight.
How big is False Claims Act exposure for healthcare right now?
DOJ reported that FCA settlements and judgments exceeded $6.8 billion in FY 2025, with more than $5.7 billion tied to the healthcare industry. Whistleblowers filed a record 1,297 qui tam lawsuits, breaking the prior record of 980 in FY 2024, which means internal reporting channels and non-retaliation policies are not optional.
What changes January 1, 2026 under Joint Commission’s Accreditation 360?
Accreditation 360 launches first for hospitals and critical access hospitals. The Environment of Care and Life Safety chapters consolidate into a new Physical Environment chapter, Joint Commission is removing 714 requirements from the hospital program, and selected standards move to a new National Performance Goals chapter that replaces the prior NPSGs. Core expectations do not change; the labeling, structure, and emphasis on outcomes do.
What is the average cost of a healthcare data breach, and why does it belong in the compliance program?
IBM’s 2024 Cost of a Data Breach Report put the healthcare average at $9.77 million, the costliest of any industry for the 14th year in a row. HIPAA Security, incident response, and breach notification belong inside the compliance program because HHS OCR enforcement, state AG actions, and FCA cybersecurity theories now intersect on the same incident.
References
- U.S. Department of Justice, “False Claims Act Settlements and Judgments Exceed $6.8B in Fiscal Year 2025” (Jan. 16, 2026)
- HHS-OIG, General Compliance Program Guidance (November 2023)
- Crowell & Moring, “OIG Issues Updated General Compliance Program Guidance: Overview of Key Elements & Changes”
- IBM, “Cost of a Data Breach Report 2024” (Press Release, July 30, 2024)
- HFM Magazine, “Joint Commission shares more details about Accreditation 360”
- ASHE, “Joint Commission Standards Receive Significant Updates”
- Gibson Dunn, False Claims Act 2025 Year-End Update
- Sheppard Mullin, OIG General Compliance Program Guidance November 2023