Healthcare Compliance Program Development Consulting
Last updated: October 2026
A healthcare compliance program is built by assessing your current risk against the seven elements in the HHS Office of Inspector General's General Compliance Program Guidance, then drafting the policies, training, reporting process and oversight structure the assessment shows you need.
Integral Healthcare Solutions (IHS), founded in 2002 by Thomas G. Goddard, JD, PhD, former Chief Operating Officer and General Counsel of URAC, builds these programs for organizations that are starting from scratch and for established providers whose programs have not been compared with the 2023 guidance. IHS drafts the program for your compliance officer, counsel and leadership to review and approve. This page is part of the Compliance Services practice line.
Schedule a Free Discovery SessionWhat is a healthcare compliance program?
A healthcare compliance program is a structured organizational system for preventing, detecting and responding to violations of healthcare law, such as the False Claims Act, the Anti-Kickback Statute, the physician self-referral law, HIPAA and the state laws that apply to your operations.
It is an operating system, not a document set. A policy manual on a shelf, annual training that staff click through, a software subscription or a checkbox for an accreditation survey does not by itself identify risk, assign accountability or show that your organization can catch and respond to a problem.
What are the seven elements of the OIG guidance?
The OIG General Compliance Program Guidance (GCPG, 2023) names seven elements. OIG states that the GCPG is voluntary and not binding, and that it uses the word "should" to present nonbinding guidance. Page opened October 6, 2026.
| Element in the GCPG | What it covers, by the GCPG's own headings | What IHS drafts |
|---|---|---|
| 1. Written policies and procedures | Code of conduct, compliance policies and procedures, policy maintenance | Code of Conduct and policies matched to your workflows |
| 2. Compliance leadership and oversight | Compliance officer, compliance committee, board compliance oversight | Officer role description, committee charter, board reporting templates |
| 3. Training and education | Training for the organization | Role-specific training content |
| 4. Effective Lines of Communication with the Compliance Officer and Disclosure Programs | Communication with the compliance officer and disclosure programs | Reporting channel design, non-retaliation policy, intake and investigation workflow |
| 5. Enforcing standards | Consequences and incentives | Discipline and recognition policies |
| 6. Risk assessment, auditing and monitoring | Risk assessment, auditing and monitoring | Risk assessment method, audit schedule, monitoring plan |
| 7. Responding to Detected Offenses and Developing Corrective Action Initiatives | Investigations of violations, reporting to the government, corrective action initiatives | Investigation and corrective action procedures |
What does the 2023 guidance say about size, ownership and industry segments?
The GCPG includes a section on compliance program adaptations for small and large entities, and a section on other compliance considerations that includes ownership, including private equity and others. OIG also states in the GCPG that it plans to publish industry segment-specific compliance program guidances (ICPGs) for provider and supplier subsectors. Check OIG's site for the ICPGs that apply to your segment. Page opened October 6, 2026.
How does the False Claims Act relate to a compliance program?
The False Claims Act, 31 U.S.C. 3729, makes a person who commits a listed false claim act liable for a civil penalty plus 3 times the government's damages, and section 3729(a)(2) allows a reduction to not less than 2 times when the person gives the government all information known about the violation within 30 days after first obtaining it, cooperates fully, and had no action begun and no knowledge of an investigation when the information was given. Page opened October 6, 2026. A compliance program gives your organization a process for finding and reporting problems. Your counsel advises on how the statute applies to your facts.
Who needs a compliance program built from scratch?
This work fits three situations: a digital health startup, an organization preparing for an acquisition or integration, and an established provider whose program is older than the 2023 guidance.
Digital health startups
A startup has revenue models, referral arrangements and patient incentive structures that may raise Anti-Kickback Statute and physician self-referral questions. A startup program is designed to scale with the company and to give investors and counsel documentation for due diligence.
Organizations preparing for an acquisition or integration
An acquirer or target may need a compliance program assessment and a plan to build or remediate the program during integration. IHS prioritizes the highest-risk areas identified in diligence and builds toward all seven elements over the integration period. Your counsel handles legal diligence.
Established providers with older programs
If your program was last updated before the 2023 guidance, a gap assessment compares it with the seven elements as the GCPG presents them. A program with policies and a hotline but no documented risk assessment is missing element 6.
How is compliance consulting different from compliance software?
Compliance software administers a program: it can track training completion, policy distribution, business associate agreements and exclusion screening. Consulting designs the program: policies that match your workflows, a risk assessment for your revenue model and board education. The two work together. IHS builds the framework and your team can use software for ongoing administration.
What is the IHS compliance program development process?
IHS runs the work in seven phases, from a gap assessment against the seven elements through board education and an oversight framework.
Phase 1: Gap assessment and risk analysis
IHS assesses your current posture against the seven elements. For a new program, the assessment sets the baseline and the highest-risk areas to address first. For an established program, it produces a gap analysis, not a list of what the program already includes.
Phase 2: Policy and procedure development
IHS drafts or revises the Code of Conduct, billing and coding policies, vendor due diligence procedures, an Anti-Kickback Statute compliance framework, telehealth documentation and security requirements, and incident response procedures. Each is written for your clinical and billing workflows.
Phase 3: Compliance officer appointment and support
IHS supports the designation or hiring of a compliance officer, including position description, role scope and onboarding. For organizations permitted to use an outside officer, IHS provides fractional Chief Compliance Officer services during the build period and structures the role for later internalization. A Medicare Advantage organization may not use an outside compliance officer: 42 CFR 422.503(b)(4)(vi)(B)(1) requires an employee of the organization, its parent or a corporate affiliate, and bars an employee of a first tier, downstream or related entity. For those organizations IHS supports the designation or hiring of the employee officer and does not serve in the role. Your organization's named contact, not IHS, communicates with regulators and accreditors.
Phase 4: Training and education rollout
IHS drafts role-specific training. Billing staff training covers documentation accuracy and false claims exposure. Clinician training covers Anti-Kickback Statute red flags, referral documentation and telehealth compliance. Executive and board training covers oversight responsibilities.
Phase 5: Reporting mechanism implementation
IHS helps you select and configure an anonymous reporting channel suited to your size, drafts the non-retaliation policy, and sets up the intake and investigation workflow so reports are acted on.
Phase 6: Auditing and monitoring program design
IHS designs the risk assessment method, billing accuracy audit schedule, clinical documentation monitoring, vendor and business associate agreement review cycle, and exclusion screening process. The monitoring program is sized so your team can sustain it after the engagement ends.
Phase 7: Board education and oversight framework
IHS provides board-level compliance education and drafts the oversight framework: reporting templates, escalation protocols and an annual compliance review structure.
How does this connect to accreditation work?
Many organizations build a compliance program alongside URAC or ACHC accreditation. IHS coordinates policy drafting across the programs so the compliance program and the accreditation documents say the same thing and work is not done twice. See URAC accreditation consulting.
What does compliance program development cost?
The total has several parts: consulting, your staff time for interviews and document review, any hotline or compliance software you select, and your counsel's review. Software and hotline vendors set their own prices. IHS sets a fixed fee for each engagement after a free discovery session, because scope, number of sites and gap severity change the work.
What this is not
- IHS is not a law firm and this page is not legal advice. Your counsel advises on how laws apply to your organization.
- IHS is not a government agency and does not communicate with regulators for you. IHS drafts, and your organization's named contact acts.
- A compliance program does not guarantee a regulatory outcome, and OIG describes its own guidance as voluntary.
- IHS drafts the program for your review and approval. Your organization adopts and runs it.
Frequently asked questions
What are the seven elements of an effective compliance program?
The HHS Office of Inspector General (OIG) organizes its General Compliance Program Guidance (2023) around seven elements: written policies and procedures, compliance leadership and oversight, training and education, effective lines of communication with the compliance officer and disclosure programs, enforcing standards, risk assessment, auditing and monitoring, and responding to detected offenses and developing corrective action initiatives. OIG describes the guidance as voluntary and not binding. Page opened October 6, 2026.
Is a healthcare compliance program legally required?
The OIG guidance is voluntary and not binding on any individual or entity. Whether a statute, regulation, payer contract or accreditation program requires a compliance program for your organization depends on your organization type and states, and your counsel confirms that. One example of a rule that sets compliance officer requirements is 42 CFR 422.503 for Medicare Advantage organizations (page opened October 6, 2026).
What does the False Claims Act provide?
Under 31 U.S.C. 3729(a)(1), a person who commits a listed act involving a false claim to the government is liable for a civil penalty, adjusted for inflation, plus 3 times the damages the government sustains. Section 3729(a)(2) allows a court to reduce damages to not less than 2 times when the person gives the government all information known about the violation within 30 days after first obtaining it, cooperates fully, and had no action begun and no knowledge of an investigation when the information was given. Page opened October 6, 2026. Your counsel advises on how the statute applies to your facts.
Who is this not for?
This service is not for an organization that only needs an administrative tool to track training, policies or exclusion screening and already has a working program. It is also not for an organization that needs legal advice on a pending investigation, which is a matter for your counsel. If you want an assessment of an existing program, the gap assessment in Phase 1 is the right starting point.
What does IHS do and what does my organization do?
IHS drafts the program, policies and training for your compliance officer, counsel and leadership to review and approve. Your organization decides, adopts and runs the program. Your organization's named contact, not IHS, communicates with any regulator or accreditor.
Can a consultant serve as my compliance officer?
It depends on the organization type. For Medicare Advantage organizations, 42 CFR 422.503(b)(4)(vi)(B)(1) provides that the compliance officer must be an employee of the MA organization, its parent organization or a corporate affiliate, and may not be an employee of a first tier, downstream or related entity (page opened October 6, 2026). For those organizations IHS supports the designation or hiring of an employee officer and does not serve in the role. For other organizations, ask your counsel whether an outside officer is permitted during the build period.
How much does compliance program development cost?
Cost has several parts: consulting, your staff time for interviews and review, any hotline or compliance software you choose, and counsel review. Software and hotline vendors set their own prices. IHS sets a fixed fee for each engagement after a free discovery session, because scope, number of sites and gap severity change the work.
Is compliance software enough?
Software helps administer a program that already exists, for example by tracking training completion, policy distribution and exclusion screening. A program also needs policies that match your workflows, a risk assessment for your operations and board education, which are drafting and design work. Many organizations use IHS to build the framework and software to run it.
Ready to start your compliance program?
Engagements begin with a gap assessment that shows where your program stands against the seven elements before you commit to the full build.
Schedule a Free Discovery Session