A healthcare compliance program is judged less by what its policy manual says than by what its records prove it did. OIG's General Compliance Program Guidance (GCPG), reissued in November 2023 as the agency's first full update in fifteen years, lays out seven elements every compliance program should have in place. The Department of Justice applies a separate, and often more consequential, test when a matter reaches the charging or settlement stage: whether the program is well designed, applied in good faith, and actually works. For a compliance officer, the space between having the seven elements on paper and being able to document that they operate is the space that decides how an investigation ends.

The Elements OIG Expects To See In Writing

The first four of OIG's seven elements are structural: written policies and procedures, compliance leadership and oversight through a designated compliance officer and committee, training and education for the workforce, and effective lines of communication that include a way to report concerns without fear of retaliation. The policies have to reach the organization's actual risk areas, not a generic template. For a provider group, that means documented standards addressing referral relationships under the anti-kickback statute and physician self-referral under the Stark Law, not just a billing manual. OIG has used a version of these categories for more than twenty-five years, and they trace back to the organizational sentencing factors in the U.S. Sentencing Guidelines.

The Elements That Prove The Program Operates

The remaining three elements are where most programs fail under scrutiny: enforcing standards through consistent consequences and incentives, risk assessment, auditing, and monitoring performed on a set schedule, and responding to detected offenses with documented corrective action. A policy that has never been tested by an internal audit, a hotline log with no entries in three years, or a disciplinary standard applied to line staff but never to a physician-owner, are the specific gaps that turn a paper program into a liability rather than a defense. Evidencing operation means keeping the audit schedule, the findings, the corrective action plans, and the sign-off on remediation, not just the policy that describes the process.

What DOJ Actually Credits At Charging And Settlement

DOJ's Evaluation of Corporate Compliance Programs asks three questions of a prosecutor deciding how to resolve a healthcare fraud matter: is the program well designed for the entity's actual risk profile, is it applied earnestly and in good faith rather than existing only on paper, and does it work in practice. The September 2024 update added a fourth practical test, whether compliance personnel have data access comparable to the sales and billing side of the business, and sharpened the guidance on protecting employees who report internally. These factors shape charging decisions, plea terms, and corporate integrity agreement posture. When an investigation reaches the stage of a civil investigative demand or a grand jury subpoena, the compliance program's own audit files are frequently among the first records requested, which is why the documentation trail matters as much as the program design.

Two related posts cover the response mechanics in more detail: Responding to a Civil Investigative Demand (CID) and Grand Jury Subpoenas in Healthcare Investigations.

A compliance program that exists only in a policy binder is not a compliance program regulators will credit. What counts is the audit trail showing the seven elements operated before the government came asking.

Why Early Legal Counsel Is Critical

It is critical that healthcare providers and compliance officers retain experienced healthcare defense counsel promptly upon receiving a subpoena, audit notice, investigative request, or other government inquiry touching the compliance program. Early legal intervention can protect the organization's rights, ensure the compliance file is produced in a way that supports rather than undermines the DOJ's good-faith assessment, avoid inadvertent admissions, and preserve defenses that are available at the outset of a matter, including where the underlying conduct implicates the False Claims Act or the federal healthcare fraud statute. Delaying representation until after records are already in the government's hands can foreclose options that were available earlier.

How Health Law Alliance Can Help

Health Law Alliance advises healthcare compliance officers and general counsel on building, auditing, and defending compliance programs against DOJ and OIG scrutiny, and represents providers once an investigation is underway. If your organization needs to assess whether its compliance program will hold up under a healthcare fraud defense review, contact us for a free, confidential consultation.