The Seven Elements of an Effective Compliance Program: The Evidence Behavioral Health Operators Need on File

, ,
Behavioral Health Compliance Training

Most behavioral health operators can produce a compliance plan on request. Far fewer can produce evidence that the plan does anything. That gap is what a payer auditor, a state Medicaid integrity unit or a buyer’s due diligence team looks for. This guide covers what the HHS Office of Inspector General describes as an effective compliance program, and the records that show each element is operating.

This is operational guidance, not legal advice. Requirements differ by state, payer and program type, and the primary sources linked below are the authority.

What OIG’s General Compliance Program Guidance Says

In November 2023, the HHS Office of Inspector General published its General Compliance Program Guidance (GCPG), a reference document intended as the starting point for any health care entity building a compliance program. The GCPG organizes an effective compliance program around seven elements: written policies and procedures; compliance leadership and oversight; training and education; effective lines of communication with the compliance officer, including a way to report concerns; enforcing standards through consequences and incentives; risk assessment, auditing and monitoring; and responding to detected offenses with corrective action. OIG’s guidance is voluntary, but it is the yardstick auditors, prosecutors and acquirers use to judge whether a program was real. The full document is available on OIG’s compliance guidance page.

Voluntary does not mean optional in practice. Some state Medicaid programs require certain providers to maintain a compliance program, many managed care contracts require one by reference, and when an overpayment surfaces, the first question is whether an effective program was already in place.

Why Behavioral Health Compliance Programs Fail Review

When we review compliance programs at residential, PHP, IOP and outpatient behavioral health operators, the same patterns account for most of the weakness. None of them are about missing policies. They are about missing proof.

A compliance officer with no independence: the role sits with the CFO, the clinical director or the owner, so the person receiving a billing complaint is often the person whose decisions created it.

A committee that meets but does not decide: minutes read “compliance updates reviewed” with no risk named, no owner assigned and no follow-up from the prior meeting.

A hotline nobody can find: the reporting line rings to a manager’s cell phone, or exists only in the employee handbook signed at hire.

Training that stops at orientation: staff complete HIPAA and fraud-and-abuse modules on day one and never again, and nothing in the training reflects the program’s actual billing or documentation risks.

Auditing without a risk assessment behind it: chart audits happen, but they sample whatever is convenient instead of the services, payers and levels of care where the money and the denials actually are.

Corrective action that is never closed: an audit finds a problem, someone sends an email, and there is no record showing the fix was made, re-tested and reported back to leadership.

The Evidence File for Each of the Seven Elements

An auditor will not take a policy’s word for it. For each element, here is what demonstrates that the program is functioning.

Written policies and procedures. A code of conduct and compliance policies that name your actual services and payers, with a document-control history showing review dates and approvals. Generic templates that mention service lines you do not offer are an immediate signal that nobody reads them.

Compliance leadership and oversight. A written designation of the compliance officer, a reporting line to the governing body or owner that does not run through operations or finance, and governing-body minutes showing compliance reports were received and questioned. If you are too small to justify a full-time compliance officer, a fractional compliance officer can provide that independence without the payroll line.

Training and education. Sign-in sheets or LMS completion records for general compliance training at hire and at least annually, plus targeted training for billing, intake and clinical documentation staff tied to findings from your own audits.

Effective lines of communication. A reporting mechanism that allows anonymous reports, is posted where staff actually see it, and has a log. An empty log in a program with dozens of staff is itself a finding.

Enforcing standards. Evidence that discipline for compliance violations is applied consistently, plus screening of every employee, contractor and referral source against the exclusion lists. OIG updates its List of Excluded Individuals/Entities (LEIE) monthly, which is why a check performed only at hire leaves the file stale within weeks.

Risk assessment, auditing and monitoring. A dated, written risk assessment that ranks your exposures, and an audit plan that follows from it. If your largest revenue line is residential SUD billed to Medicaid managed care, the audit plan should sample those claims first, against the documentation the payer actually requires.

Responding to offenses and corrective action. A tracking log for every identified issue showing the root cause, the corrective step, who owns it, the re-audit result and the date it was closed. Where an issue involves payments received in error, the log should show when the overpayment was identified and how repayment was handled, because federal overpayment rules run on their own clock.

The Compliance Committee: Where Programs Prove Themselves

The compliance committee is the single place where all seven elements meet, and its minutes are the most persuasive evidence you can hand an auditor. Strong minutes have a recognizable shape: each meeting names the top risks from the current risk assessment, reports audit results with numbers, records hotline volume and themes without identifying reporters, lists open corrective actions with their status, and ends with decisions and owners.

Weak minutes describe a conversation. Strong minutes describe decisions. If an auditor reads twelve months of minutes and cannot tell what the committee changed, the committee did not function in any way that counts.

Put the clinical director or a designee on the committee. Many of the highest-risk findings in behavioral health are documentation findings, not coding findings.

Where Privacy Fits

Behavioral health operators carry an extra layer: HIPAA, and for SUD programs, 42 CFR Part 2. These belong inside the same compliance program rather than in a separate privacy silo. Your risk assessment should include privacy and security risks, your audit plan should include access and disclosure audits, and your corrective action log should capture privacy incidents alongside billing ones. The HHS Office for Civil Rights maintains HIPAA guidance for covered entities, and our HIPAA compliance checklist is a practical place to start mapping those requirements to your own records.

The Inconvenient Truth About Program Size

Smaller operators often assume that OIG’s guidance is written for hospital systems and does not reach a 30-bed residential program. The GCPG explicitly expects programs to be scaled to the organization’s size and resources, which cuts both ways. A small program is not expected to have a compliance department. It is expected to have the seven elements in a form proportionate to its risk, and “we are too small” is not an answer to an auditor who asks who reviews billing accuracy.

The smaller the program, the more the compliance officer role collapses into the owner. That is the most common structural weakness we see, and an outside designee fixes it.

What to Do This Week

Pull three documents and lay them side by side: your written compliance plan, the last twelve months of compliance committee minutes, and your corrective action log. For each of the seven elements, find one dated record that proves it operated in the past year. Any element where you cannot find that record is your first remediation item, and it should be on the agenda for your next committee meeting with a named owner and a date.

Then run one check before Friday: confirm that every current employee and contractor was screened against the LEIE within the last month, and that the result is filed. If the most recent check is older than that, you have already found your first corrective action.

If you would like a second set of eyes on your program before a payer or state auditor provides one, our compliance services team runs gap assessments against all seven elements. Call us at (888) 458-6619 to talk through what an assessment would cover for your program.

Frequently Asked Questions

Is a compliance program legally required for behavioral health providers? OIG’s General Compliance Program Guidance is voluntary, but some state Medicaid programs and many payer contracts require a compliance program, and its absence weighs heavily when an overpayment or false claim is investigated. Check your state Medicaid rules and your managed care contracts.

Can the owner serve as compliance officer? Nothing prohibits it in most settings, but it undermines the independence OIG’s guidance emphasizes. If the owner holds the role, the program should have a clear route for concerns to reach someone other than the owner, such as an outside designee or board member.

Questions about where your program stands? Reach Circa Behavioral at (888) 458-6619.