Service

A Corporate Integrity Agreement (CIA) is, in the Office of Inspector General's words, "an agreement between an entity and the Office of Inspector General (OIG) that outlines obligations to improve compliance and prevent fraud, often as part of a civil settlement" (OIG, Corporate Integrity Agreements). This page is for health care organizations operating under a CIA. Integral Healthcare Solutions (IHS) provides operational compliance support: it turns the agreement into a dated obligations register and drafts the policies, procedures, training materials and report templates the agreement calls for, for your compliance officer and counsel to approve. IHS is not your Independent Review Organization.

Last reviewed: October 2026.

What is a Corporate Integrity Agreement?

A CIA is a negotiated agreement with OIG. OIG describes what it gives in return: "When an entity agrees to the obligations outlined in the Corporate Integrity Agreement, OIG agrees not to seek the entity's exclusion from participation in Medicare, Medicaid, or other Federal health care programs" (OIG).

There is no single published CIA standard. The governing text for your organization is your own executed agreement and its appendices. OIG's public pages describe what agreements share. We read these on 2 October 2026: the Corporate Integrity Agreements hub, About Corporate Integrity Agreements, the Corporate Integrity Agreement Frequently Asked Questions and the Guidance on IRO Independence and Objectivity (2016).

According to OIG, agreements "have many common elements, but each one addresses the specific facts at issue" (OIG, About CIAs). The common requirements OIG lists are:

OIG states the term plainly: "A CIA lasts 5 years." It also states the consequence of failure: "A material breach of the CIA constitutes an independent basis for the entity's exclusion from participation in the Federal health care programs" (OIG).

Who needs it and what triggers it

An organization needs CIA support once it has signed a CIA. OIG says agreements are made "often as part of a civil settlement" (OIG). The work then runs on the agreement's own clock:

How IHS helps

IHS works from your executed CIA and its appendices, which your organization provides. The process has five parts:

  1. Gap assessment against the agreement. IHS reads each term of your CIA and compares it with the policies, records and staffing you have now.
  2. Document and evidence mapping. IHS builds an obligations register that lists every term with its due date, its owner and the evidence that shows it was met.
  3. Drafting. IHS drafts or updates the written policies, training materials, confidential disclosure program procedure, ineligible person screening procedure and reportable event intake procedure the agreement calls for. Your compliance officer and counsel review and approve every document.
  4. Mock review. IHS runs internal readiness checks on your documentation and evidence before a report falls due. This is an internal check for your team, not an IRO review.
  5. Readiness support. IHS prepares templates and a calendar for the implementation report and the annual reports. Your organization completes and submits them.

What you supply: the executed CIA and every appendix; your current policies, training records and screening records; and the names of the compliance officer, committee members and policy owners.

The limit: IHS does not serve as the Independent Review Organization. OIG's FAQ says that, in general, for a claims review the IRO must assign people with "expertise in the applicable Medicare and State Medicaid program requirements," people "knowledgeable about appropriate statistical sampling techniques," coders with "a nationally recognized coding certification" and, where medical necessity is reviewed, "licensed nurses or physicians" (OIG CIA FAQ). OIG's 2016 guidance lists consulting "during the term of the CIA on a matter that is related to the subject matter of the CIA reviews" as a likely impairment of IRO independence (OIG IRO guidance). IHS's reading, as of 2 October 2026: a firm that drafts your program documents during the term is a poor fit to review the same subject matter. Your compliance officer and counsel decide whether an event is reportable and own every submission to OIG. IHS drafts; your organization submits.

What to have ready

Each item below ties to a term OIG describes in CIAs. Your own agreement controls where it differs.

The introductory call is the place to go through this list against your agreement and your current records.

How it compares

Three roles appear around a CIA, each doing a different job.

RoleWhat it doesBasis
Independent Review OrganizationConducts the reviews the CIA requires; selected by the provider from an accounting firm, law firm or consultant that meets the appendix qualifications, subject to OIG objection under most CIAsOIG CIA FAQ; OIG About CIAs
Your compliance staff and outside counselRun the program day to day, decide reportability and make every submission to OIGYour agreement
Operational compliance support (IHS)Obligations register, drafted policies and procedures, training materials, report templates and calendar, internal readiness checksYour agreement; IHS scope

OIG "will not indicate which IROs we believe are most qualified" (OIG CIA FAQ). The same holds for support roles: the choice depends on your agreement, your staff and your counsel. For related work, see exclusion screening program and compliance program development, or return to Compliance Services.

What it costs

OIG does not publish a fee schedule on the pages we reviewed; fees depend on scope. The agreement also carries Stipulated Penalties: OIG says the breach and default provisions "allow OIG to impose certain monetary penalties (referred to as Stipulated Penalties)," and the amounts are set in each agreement (OIG). IHS scopes each engagement after a free introductory call.

What this is not

Frequently asked questions

What does a Corporate Integrity Agreement require us to do, and how long does it last?

OIG says each agreement "addresses the specific facts at issue" and includes requirements such as a compliance officer and committee, written standards and policies, training, an independent review organization, a confidential disclosure program, restrictions on employing ineligible persons, reporting, and an implementation report and annual reports (OIG, About CIAs). OIG also states: "A CIA lasts 5 years." Your own executed agreement and its appendices set the exact terms.

What is an Independent Review Organization, and who selects it?

The Independent Review Organization (IRO) is the outside reviewer the CIA requires the entity to "retain" to "conduct reviews" (OIG). The provider selects it; OIG states that "It is up to the provider to determine the most appropriate accounting firm, law firm, or consultant to engage as its IRO" (OIG CIA FAQ). OIG adds that most CIAs let OIG notify the provider, within 30 days after OIG receives written notice of the IRO's identity, that its choice is unacceptable, and that OIG may ask the provider to replace an IRO if OIG has concerns about its quality, qualifications or independence (OIG CIA FAQ).

Can a consulting firm act as our IRO, and what independence rules apply?

OIG names a consultant as one possible IRO choice, and says the qualifications "are outlined in an appendix to the CIA" (OIG CIA FAQ). OIG's 2016 independence guidance names "the self-review threat": consulting for the provider during the CIA term on matters related to the CIA reviews (OIG IRO guidance, 2016). IHS does not serve as an IRO.

How do we set up the compliance officer and compliance committee the CIA requires?

OIG lists "hire a compliance officer and appoint a compliance committee" among the common CIA requirements (OIG). The duties, reporting lines and timing are set in your agreement. IHS drafts the charter and role descriptions from those terms for your counsel and leadership to approve.

How do we run the training program the CIA requires, and how do we prove it?

OIG lists "implement a comprehensive employee training program" as a common requirement (OIG). Your agreement sets who is trained, on what and by when. IHS drafts the training materials and a completion record your staff keep.

What is a reportable event, and what is the 30-day clock?

A reportable event is defined in each agreement. OIG states that "the provider must report to OIG within 30 days all 'reportable events' as defined by the CIA" (OIG CIA FAQ). Your compliance officer and counsel decide whether an event is reportable and make the report; IHS drafts the intake procedure that starts the clock and records the decision.

How do we build the confidential disclosure program?

OIG lists "establish a confidential disclosure program" among the common requirements (OIG). The specific features come from your agreement. IHS drafts the program procedure and the records your compliance office keeps for each disclosure, for your compliance officer to approve.

How do we handle the ineligible person screening our CIA requires?

OIG lists "restrict employment of ineligible persons" as a common requirement (OIG). IHS drafts the screening procedure against the terms of your agreement, and your staff or chosen vendor runs the checks. The exclusion screening program page covers the screening program itself.

What goes in the implementation report and the annual reports to OIG?

OIG says agreements require the entity to "provide an implementation report and annual reports to OIG on the status of the entity's compliance activities" (OIG). The contents and due dates are in your agreement. IHS prepares templates and a calendar tied to each term; your organization completes and submits the reports.

How do we avoid stipulated penalties for a missed deadline?

OIG says the breach and default provisions "allow OIG to impose certain monetary penalties (referred to as Stipulated Penalties)" (OIG). The amounts are in each agreement. OIG also states that "A material breach of the CIA constitutes an independent basis for the entity's exclusion." IHS builds a dated obligations register with an owner for each term; meeting the deadlines stays with your organization.

Talk with IHS's CEO

A 30-minute introductory meeting with Thomas G. Goddard, JD, PhD, to scope what your organization needs.

Book an introductory meeting