A Corporate Integrity Agreement (CIA) is, in the Office of Inspector General's words, "an agreement between an entity and the Office of Inspector General (OIG) that outlines obligations to improve compliance and prevent fraud, often as part of a civil settlement" (OIG, Corporate Integrity Agreements). This page is for health care organizations operating under a CIA. Integral Healthcare Solutions (IHS) provides operational compliance support: it turns the agreement into a dated obligations register and drafts the policies, procedures, training materials and report templates the agreement calls for, for your compliance officer and counsel to approve. IHS is not your Independent Review Organization.
Last reviewed: October 2026.
What is a Corporate Integrity Agreement?
A CIA is a negotiated agreement with OIG. OIG describes what it gives in return: "When an entity agrees to the obligations outlined in the Corporate Integrity Agreement, OIG agrees not to seek the entity's exclusion from participation in Medicare, Medicaid, or other Federal health care programs" (OIG).
There is no single published CIA standard. The governing text for your organization is your own executed agreement and its appendices. OIG's public pages describe what agreements share. We read these on 2 October 2026: the Corporate Integrity Agreements hub, About Corporate Integrity Agreements, the Corporate Integrity Agreement Frequently Asked Questions and the Guidance on IRO Independence and Objectivity (2016).
According to OIG, agreements "have many common elements, but each one addresses the specific facts at issue" (OIG, About CIAs). The common requirements OIG lists are:
- "hire a compliance officer and appoint a compliance committee"
- "develop written standards and policies"
- "implement a comprehensive employee training program"
- "retain an independent review organization to conduct reviews"
- "establish a confidential disclosure program"
- "restrict employment of ineligible persons"
- "report overpayments, reportable events, and ongoing investigations and legal proceedings"
- "provide an implementation report and annual reports to OIG on the status of the entity's compliance activities"
OIG states the term plainly: "A CIA lasts 5 years." It also states the consequence of failure: "A material breach of the CIA constitutes an independent basis for the entity's exclusion from participation in the Federal health care programs" (OIG).
Who needs it and what triggers it
An organization needs CIA support once it has signed a CIA. OIG says agreements are made "often as part of a civil settlement" (OIG). The work then runs on the agreement's own clock:
- The start of the five-year term: "A CIA lasts 5 years." (OIG).
- Each annual report to OIG on the status of compliance activities (OIG).
- A reportable event, which OIG's FAQ says must be reported to OIG "within 30 days" as the CIA defines the event; your CIA's own wording controls (OIG CIA FAQ).
- An identified overpayment, which must be reported to the payor and repaid "promptly" (OIG CIA FAQ).
How IHS helps
IHS works from your executed CIA and its appendices, which your organization provides. The process has five parts:
- Gap assessment against the agreement. IHS reads each term of your CIA and compares it with the policies, records and staffing you have now.
- Document and evidence mapping. IHS builds an obligations register that lists every term with its due date, its owner and the evidence that shows it was met.
- Drafting. IHS drafts or updates the written policies, training materials, confidential disclosure program procedure, ineligible person screening procedure and reportable event intake procedure the agreement calls for. Your compliance officer and counsel review and approve every document.
- Mock review. IHS runs internal readiness checks on your documentation and evidence before a report falls due. This is an internal check for your team, not an IRO review.
- Readiness support. IHS prepares templates and a calendar for the implementation report and the annual reports. Your organization completes and submits them.
What you supply: the executed CIA and every appendix; your current policies, training records and screening records; and the names of the compliance officer, committee members and policy owners.
The limit: IHS does not serve as the Independent Review Organization. OIG's FAQ says that, in general, for a claims review the IRO must assign people with "expertise in the applicable Medicare and State Medicaid program requirements," people "knowledgeable about appropriate statistical sampling techniques," coders with "a nationally recognized coding certification" and, where medical necessity is reviewed, "licensed nurses or physicians" (OIG CIA FAQ). OIG's 2016 guidance lists consulting "during the term of the CIA on a matter that is related to the subject matter of the CIA reviews" as a likely impairment of IRO independence (OIG IRO guidance). IHS's reading, as of 2 October 2026: a firm that drafts your program documents during the term is a poor fit to review the same subject matter. Your compliance officer and counsel decide whether an event is reportable and own every submission to OIG. IHS drafts; your organization submits.
What to have ready
Each item below ties to a term OIG describes in CIAs. Your own agreement controls where it differs.
- Your executed CIA and every appendix. Each agreement "addresses the specific facts at issue" (OIG), and the IRO qualifications "are outlined in an appendix to the CIA" (OIG CIA FAQ).
- Appointment records for your compliance officer and compliance committee (OIG).
- Your current written standards and policies (OIG).
- Training content, rosters and completion records (OIG).
- Your IRO engagement letter and the appendix qualifications it must meet, including the claims review expertise OIG summarizes (OIG CIA FAQ).
- Your confidential disclosure program procedure and its records (OIG).
- Your ineligible person screening procedure and screening records (OIG).
- A reportable event intake log showing the date each event was identified, against the reporting deadline in your CIA; OIG's FAQ states 30 days (OIG CIA FAQ).
- Overpayment identification, payor notice and repayment records (OIG CIA FAQ).
- A list of ongoing investigations and legal proceedings, which the agreement requires you to report (OIG).
- The due dates for your implementation report and each annual report (OIG).
The introductory call is the place to go through this list against your agreement and your current records.
How it compares
Three roles appear around a CIA, each doing a different job.
| Role | What it does | Basis |
|---|---|---|
| Independent Review Organization | Conducts the reviews the CIA requires; selected by the provider from an accounting firm, law firm or consultant that meets the appendix qualifications, subject to OIG objection under most CIAs | OIG CIA FAQ; OIG About CIAs |
| Your compliance staff and outside counsel | Run the program day to day, decide reportability and make every submission to OIG | Your agreement |
| Operational compliance support (IHS) | Obligations register, drafted policies and procedures, training materials, report templates and calendar, internal readiness checks | Your agreement; IHS scope |
OIG "will not indicate which IROs we believe are most qualified" (OIG CIA FAQ). The same holds for support roles: the choice depends on your agreement, your staff and your counsel. For related work, see exclusion screening program and compliance program development, or return to Compliance Services.
What it costs
OIG does not publish a fee schedule on the pages we reviewed; fees depend on scope. The agreement also carries Stipulated Penalties: OIG says the breach and default provisions "allow OIG to impose certain monetary penalties (referred to as Stipulated Penalties)," and the amounts are set in each agreement (OIG). IHS scopes each engagement after a free introductory call.
What this is not
- IHS is a consulting firm, not a law firm, and this page is not legal advice. Your counsel advises on the agreement and on reportability.
- IHS is not your Independent Review Organization and does not perform the CIA reviews.
- IHS does not submit reports to OIG or correspond with OIG for your organization, and cannot guarantee how OIG treats any report or event.
Frequently asked questions
What does a Corporate Integrity Agreement require us to do, and how long does it last?
OIG says each agreement "addresses the specific facts at issue" and includes requirements such as a compliance officer and committee, written standards and policies, training, an independent review organization, a confidential disclosure program, restrictions on employing ineligible persons, reporting, and an implementation report and annual reports (OIG, About CIAs). OIG also states: "A CIA lasts 5 years." Your own executed agreement and its appendices set the exact terms.
What is an Independent Review Organization, and who selects it?
The Independent Review Organization (IRO) is the outside reviewer the CIA requires the entity to "retain" to "conduct reviews" (OIG). The provider selects it; OIG states that "It is up to the provider to determine the most appropriate accounting firm, law firm, or consultant to engage as its IRO" (OIG CIA FAQ). OIG adds that most CIAs let OIG notify the provider, within 30 days after OIG receives written notice of the IRO's identity, that its choice is unacceptable, and that OIG may ask the provider to replace an IRO if OIG has concerns about its quality, qualifications or independence (OIG CIA FAQ).
Can a consulting firm act as our IRO, and what independence rules apply?
OIG names a consultant as one possible IRO choice, and says the qualifications "are outlined in an appendix to the CIA" (OIG CIA FAQ). OIG's 2016 independence guidance names "the self-review threat": consulting for the provider during the CIA term on matters related to the CIA reviews (OIG IRO guidance, 2016). IHS does not serve as an IRO.
How do we set up the compliance officer and compliance committee the CIA requires?
OIG lists "hire a compliance officer and appoint a compliance committee" among the common CIA requirements (OIG). The duties, reporting lines and timing are set in your agreement. IHS drafts the charter and role descriptions from those terms for your counsel and leadership to approve.
How do we run the training program the CIA requires, and how do we prove it?
OIG lists "implement a comprehensive employee training program" as a common requirement (OIG). Your agreement sets who is trained, on what and by when. IHS drafts the training materials and a completion record your staff keep.
What is a reportable event, and what is the 30-day clock?
A reportable event is defined in each agreement. OIG states that "the provider must report to OIG within 30 days all 'reportable events' as defined by the CIA" (OIG CIA FAQ). Your compliance officer and counsel decide whether an event is reportable and make the report; IHS drafts the intake procedure that starts the clock and records the decision.
How do we build the confidential disclosure program?
OIG lists "establish a confidential disclosure program" among the common requirements (OIG). The specific features come from your agreement. IHS drafts the program procedure and the records your compliance office keeps for each disclosure, for your compliance officer to approve.
How do we handle the ineligible person screening our CIA requires?
OIG lists "restrict employment of ineligible persons" as a common requirement (OIG). IHS drafts the screening procedure against the terms of your agreement, and your staff or chosen vendor runs the checks. The exclusion screening program page covers the screening program itself.
What goes in the implementation report and the annual reports to OIG?
OIG says agreements require the entity to "provide an implementation report and annual reports to OIG on the status of the entity's compliance activities" (OIG). The contents and due dates are in your agreement. IHS prepares templates and a calendar tied to each term; your organization completes and submits the reports.
How do we avoid stipulated penalties for a missed deadline?
OIG says the breach and default provisions "allow OIG to impose certain monetary penalties (referred to as Stipulated Penalties)" (OIG). The amounts are in each agreement. OIG also states that "A material breach of the CIA constitutes an independent basis for the entity's exclusion." IHS builds a dated obligations register with an owner for each term; meeting the deadlines stays with your organization.
