Blog › ICP guides

Healthcare compliance consultant on retainer: OIG compliance program guidance, HIPAA Privacy Rule implementation, coding and billing audit, and healthcare compliance program consultant on monthly retainer

August 6, 2026 · ~22 min read

A 220-bed community hospital — non-profit, $185 million annual net patient revenue, 1,400 employees — receives notice from The Joint Commission (TJC) that it has been selected for an unannounced accreditation survey beginning within an 18-month window. TJC provides hospitals with an 18-to-36-month window rather than a specific survey date, so the hospital’s Chief Compliance Officer (CCO) and Quality Director know only that surveyors could arrive at any point in that span. Within days of receiving the notice, they contact the hospital’s retained healthcare compliance consultant — a Certified in Healthcare Compliance (CHC) professional with 14 years of experience in hospital compliance program implementation, HIPAA Privacy Rule training, coding and billing audit, and TJC survey preparation.

The retained compliance consultant advises the hospital on a three-track preparation program. The first track is an OIG seven-element compliance program gap assessment: reviewing the hospital’s existing compliance infrastructure against the 2023 OIG General Compliance Program Guidance (GCPG) seven-element framework — written policies and procedures, compliance officer and committee, training and education, effective lines of communication, internal monitoring and auditing, well-publicized disciplinary guidelines, and prompt response to detected offenses — and identifying gaps against the OIG’s compliance program effectiveness indicators for each element. The second track is a targeted coding and billing audit: selecting a statistically valid sample of inpatient DRG claims and outpatient E&M visits from the past 12 months for internal audit against CMS documentation requirements, the 2021 AMA E/M coding revisions, and applicable Local Coverage Determinations (LCDs), with particular attention to identifying any overpayment obligations under the 60-day overpayment rule at 42 U.S.C. §1320a-7k(d). The third track is a TJC National Patient Safety Goals (NPSGs) readiness assessment: conducting mock tracer methodology surveys against the 2026 NPSGs — medication reconciliation NPSG 03.06.01, identify patients correctly NPSG 01.01.01, improve staff communication NPSG 02.03.01 — and the TJC Hospital Accreditation Standards to identify preliminary survey vulnerabilities before the actual survey window opens.

Healthcare compliance consultants on monthly retainer — CHC-credentialed professionals implementing OIG-compliant compliance programs, HIPAA Privacy Rule training and privacy notice administration, coding and billing audits, and accreditation maintenance advisory — do most of their highest-value work in the months between OIG advisory opinion releases, OCR audit notices, CMS Conditions of Participation deficiency findings, and TJC survey outcomes that make healthcare compliance vulnerabilities visible to administrators and governing boards. This guide covers OIG compliance program guidance, HIPAA Privacy Rule implementation and de-identification, coding and billing compliance, and accreditation maintenance advisory: the regulatory frameworks behind each service area and how to structure a healthcare compliance consulting retainer that makes the ongoing program work visible between accreditation events.

OIG compliance program guidance and seven-element implementation

OIG compliance program guidance advisory is the retainer function that maintains the organization’s compliance program infrastructure, keeps the program aligned with current OIG expectations, and generates the documented compliance activity that protects the organization in the event of an OIG audit, CMS survey, or False Claims Act investigation. A functioning OIG compliance program does not happen automatically: it requires continuous work plan development, policy review and update, training delivery and documentation, exclusions screening, internal auditing, and hotline administration — all of which is invisible to the governing board and executive team unless the compliance consultant maintains a detailed work log.

2023 OIG General Compliance Program Guidance and seven-element framework

The OIG’s General Compliance Program Guidance (GCPG), released in November 2023, represents the first comprehensive update to the OIG’s compliance program guidance framework in many years. Unlike the OIG’s earlier sector-specific compliance program guidances (which addressed hospitals, nursing facilities, physician practices, and other provider types separately), the 2023 GCPG applies across all healthcare entities subject to the False Claims Act and federal healthcare program regulations. It consolidates and updates the OIG’s expectations for the seven elements of an effective compliance program and introduces a new concept: “compliance program effectiveness indicators” for each of the seven elements.

The seven elements of an effective healthcare compliance program under the 2023 GCPG are: (1) written policies and procedures; (2) compliance officer and compliance committee; (3) training and education; (4) effective lines of communication (including a compliance reporting mechanism and a non-retaliation policy); (5) internal monitoring and auditing; (6) well-publicized disciplinary guidelines; and (7) prompt response to detected offenses and corrective action. The 2023 GCPG does not alter the seven-element framework itself, but it significantly deepens the OIG’s expectations for how each element should be implemented and how the organization should measure and document its compliance program’s effectiveness over time.

Compliance program effectiveness indicators are the 2023 GCPG’s most significant new contribution to the compliance program framework. For written policies and procedures, effectiveness indicators include whether policies address the specific fraud and abuse risk areas identified in the OIG Work Plan, whether policies are updated promptly when regulatory changes occur, and whether front-line staff can articulate the policies relevant to their roles in their own words (indicating actual understanding rather than paper compliance). For internal monitoring and auditing, effectiveness indicators include whether the compliance work plan is risk-based (prioritizing higher-risk areas identified by OIG Work Plan items, MAC comparative billing data, and internal data analytics rather than selecting audit topics arbitrarily), whether audits use statistically valid sampling methodologies, and whether audit findings are presented to the compliance committee and governing board with corrective action plan recommendations and follow-up tracking.

Compliance officer independence is another area the 2023 GCPG addresses with new specificity. The GCPG states that the compliance officer must have direct access to the governing board (without going through the CEO or other executive staff), must not report to the general counsel or CFO (to preserve independence from both legal strategy and financial pressure on compliance reporting), and must have sufficient resources — budget, staff, and technology — to implement and monitor the compliance program effectively. A compliance officer who reports to the CFO faces an inherent structural conflict: the CFO has financial interests in billing practices that the compliance officer may need to audit and criticize. The retained compliance consultant who serves as the organization’s de facto compliance officer (for organizations without a dedicated internal CCO) must have the organizational independence the 2023 GCPG requires.

OIG Work Plan integration is the mechanism through which the retained compliance consultant keeps the organization’s internal audit work plan aligned with current OIG enforcement priorities. The OIG publishes its annual Work Plan — and updates it monthly — on OIG.HHS.gov; it identifies the auditing, evaluation, and investigative priorities the OIG plans to pursue in the upcoming fiscal year. If the OIG announces that it plans to audit inpatient rehabilitation facility case-mix documentation, physician-owned distributorship arrangements in spine surgery, or telehealth E/M coding for services furnished during the COVID public health emergency, the retained compliance consultant incorporates those Work Plan items into the organization’s internal audit plan. An organization whose internal audit files document that it audited the same compliance risk area that the OIG is now investigating — and implemented corrective actions in response to its own findings — is in a substantially stronger position during an OIG audit or government investigation than an organization that never reviewed the risk area.

OIG exclusions screening and compliance program monitoring

The OIG List of Excluded Individuals and Entities (LEIE) is the federal database of individuals and entities that have been excluded from participation in Medicare, Medicaid, and other federal healthcare programs. Exclusion from federal healthcare programs is mandatory under 42 U.S.C. §1320a-7 for individuals and entities convicted of certain criminal offenses (Medicare or Medicaid fraud, patient abuse or neglect, felony convictions relating to healthcare fraud, or felony convictions relating to controlled substances), and permissive for a broader range of offenses specified in 42 C.F.R. Part 1001. The OIG maintains the LEIE at exclusions.oig.hhs.gov and updates it monthly.

Federal healthcare program payment prohibition for excluded persons is severe: 42 U.S.C. §1395cc(a)(1)(K) prohibits Medicare payment for items or services furnished by excluded individuals, and 42 C.F.R. §1001.1901 specifies that no federal healthcare program payment may be made for items or services furnished by excluded individuals or entities or at the medical direction or prescription of an excluded physician. An organization that employs or contracts with an excluded individual can be subject to civil money penalties (CMPs) of $10,000 per item or service furnished by the excluded person, plus assessment of up to three times the amount claimed, plus OIG permissive exclusion of the organization itself. The OIG has made clear that ignorance of the excluded status is not a defense: organizations are expected to screen before hiring or contracting and to continue screening monthly.

Monthly LEIE screening workflow is the retained compliance consultant’s implementation of this requirement. The OIG recommends that organizations screen all employees, contractors, vendors, and medical staff against the LEIE on a monthly basis — not just at hire or initial credentialing. The compliance consultant implements the monthly screening workflow, maintains documentation of each monthly screening (date, names screened, results, any matches found and their disposition), and advises on remediation when a current employee or contractor is found to have been excluded: immediate removal from any activities related to federal healthcare programs, notification to HR and legal counsel, self-disclosure evaluation if federal healthcare program claims were submitted during the period the person was employed or contracted, and documentation of the corrective action. In addition to LEIE screening, organizations that contract with the federal government must screen against the SAM.gov Exclusions database; the compliance consultant coordinates LEIE and SAM.gov screening workflows to avoid duplication and ensure comprehensive coverage.

OIG Self-Disclosure Protocol (SDP) advisory is the compliance consultant’s role when internal monitoring identifies a potential overpayment or compliance violation that could constitute a False Claims Act violation. The OIG SDP (updated in 2013) allows healthcare entities to voluntarily disclose to OIG conduct that the entity believes may constitute a violation of federal criminal, civil, or administrative law in connection with federal healthcare programs. SDP submitters typically receive settlement multipliers of 1.5 times the single damages amount rather than the False Claims Act’s treble damages; in contrast to the standard DOJ FCA resolution process. The SDP requires disclosure of the nature and extent of the conduct, submission of a claims sample and extrapolated overpayment amount, and a corrective action plan. The compliance consultant advises the organization on when an internal audit finding rises to the level of an SDP-eligible disclosure (as opposed to a simple voluntary MAC refund), coordinates the financial quantification required for the disclosure, and refers the legal assessment of FCA exposure and SDP strategy to healthcare attorneys. The compliance consultant does not independently make legal determinations about FCA liability — that determination belongs to counsel.

Compliance training program design and effectiveness measurement

The 2023 GCPG specifies that an effective compliance training program has three components: general training for all employees, role-specific training for employees in high-risk functions, and measurement of training effectiveness through post-training assessments and behavioral change indicators. The retained compliance consultant designs, delivers, and documents all three components.

Annual general compliance training covers the compliance program’s core requirements for all employees: the code of conduct and its behavioral expectations; how to report compliance concerns (compliance hotline number, direct compliance officer contact information, non-retaliation policy under 42 U.S.C. §1320a-7k(h) and applicable state law equivalents); HIPAA Privacy and Security Rule basics appropriate for the employee’s level of PHI access; high-level Anti-Kickback Statute and Stark Law concepts (for clinical and administrative staff who have any involvement with physician referral relationships, vendor relationships, or marketing); and False Claims Act qui tam provisions (explaining that employees who are aware of false claims submitted to Medicare or Medicaid can file qui tam lawsuits on behalf of the federal government and receive a share of any recovery, and that the organization’s non-retaliation policy protects good-faith reporters). For hospital employees, training also covers the organization’s Patient Rights policy under 42 C.F.R. §482.13 and the process for filing a patient complaint or grievance.

Role-specific billing and coding training targets employees in the revenue cycle, coding, clinical documentation improvement (CDI), and medical staff functions whose work directly affects the accuracy of claims submitted to federal healthcare programs. This training covers the specific coding systems and guidelines applicable to the organization’s claim types: Correct Coding Initiative (CCI) edits and National Correct Coding Initiative (NCCI) bundling rules (the automated claim editing policies CMS uses to prevent payment for improperly unbundled or mutually exclusive procedures); modifier usage (CPT modifiers that override CCI edits require documentation supporting the modifier — the compliance consultant trains coders on which modifiers trigger post-payment audit risk); medical necessity documentation requirements (coverage articles for CPT codes under applicable LCDs, including the specific documentation elements that must be present in the medical record to support the billed code under the applicable LCD); and ICD-10-CM diagnosis code selection to the highest level of specificity available in the medical record (undercoding at a less specific diagnosis code level when the medical record supports a more specific code is as much a compliance concern as overcoding, since it misrepresents the complexity of the patient’s condition to the payer).

Training documentation and effectiveness measurement are as important as training delivery for OIG compliance program purposes. The retained compliance consultant maintains training completion records for each employee, including the date, training content version, attendee name and role, and post-training assessment score. Training records are a critical element of the OIG’s compliance program effectiveness assessment: an OIG auditor evaluating the hospital’s compliance program will request training completion documentation and compare completion rates against the total employee population. An OIG that finds that 30% of billing staff did not complete role-specific billing compliance training in the prior year has evidence that the training element of the seven-element framework was not effectively implemented. Effectiveness measurement goes beyond completion rates: the compliance consultant tracks whether post-training assessment scores improved relative to prior years and whether the compliance violation rate in audited areas declined following targeted training — the behavioral change indicators the 2023 GCPG identifies as the real measure of training effectiveness.

HIPAA Privacy Rule implementation and de-identification

HIPAA Privacy Rule implementation is the retainer function that maintains the organization’s compliance with the Privacy Rule’s requirements for using and disclosing protected health information (PHI), administering patient rights, and ensuring that business partners and research programs handle PHI appropriately. The compliance consultant who manages HIPAA Privacy Rule compliance is implementing and monitoring policies, training staff, processing patient rights requests, and advising on de-identification and research programs — not providing legal advice on the interpretation of HIPAA requirements (which is the domain of healthcare attorneys) but implementing the Privacy Rule’s operational requirements at the workflow level.

HIPAA Privacy Rule training, Notice of Privacy Practices, and patient rights administration

The HIPAA Privacy Rule at 45 C.F.R. Part 164, Subpart E governs the use and disclosure of protected health information by covered entities — health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in HIPAA standard transactions. PHI is individually identifiable health information relating to an individual’s past, present, or future physical or mental health condition, the provision of healthcare to the individual, or the past, present, or future payment for the provision of healthcare, that is transmitted or maintained in any form or medium. The Privacy Rule permits covered entities to use and disclose PHI for treatment, payment, and healthcare operations without patient authorization, and requires patient authorization (or a specific Privacy Rule exception) for uses and disclosures for other purposes.

Notice of Privacy Practices (NPP) administration under 45 C.F.R. §164.520 is a core operational responsibility of the retained compliance consultant. The NPP is the document that tells patients how the covered entity uses and discloses their PHI, what rights they have with respect to their PHI, and how to file a complaint with the Department of Health and Human Services Office for Civil Rights (OCR). The NPP must describe: all the purposes for which the covered entity may use or disclose PHI; the individual’s rights with respect to PHI (including the right to access, right to amend, right to an accounting of disclosures, right to request restrictions on use and disclosure, and right to request confidential communications); the covered entity’s duties with respect to PHI; and how to file an OCR complaint. The NPP must be provided at the first service encounter (or upon enrollment for health plans), posted prominently at care delivery sites and in waiting areas, and made available on the covered entity’s public website. The retained compliance consultant reviews the NPP at least annually for regulatory accuracy, coordinates legal review of the NPP when HIPAA regulatory changes occur (such as the 2024 proposed HIPAA rule changes regarding reproductive health information use and disclosure), and ensures that NPP distribution and posting procedures are documented.

Patient rights request administration requires the compliance consultant to implement and monitor the covered entity’s procedures for responding to patient rights requests within the timeframes the Privacy Rule specifies. The right of access to PHI under §164.524 requires the covered entity to respond to access requests within 30 days, or 60 days with a single 30-day extension for records held off-site; the HITECH Act reinforces the individual access right, and the 2016 OCR Guidance on right of access clarifies that covered entities cannot require individuals to use a patient portal to exercise their access rights and cannot charge fees beyond the cost of producing the copy. The right to amend PHI under §164.526 requires a response within 60 days, or 90 days with a single 30-day extension; the covered entity may deny the amendment request only on specified grounds (the PHI was not created by the covered entity, the PHI would not be available for inspection under §164.524, or the PHI is accurate and complete as it stands). The right to an accounting of disclosures under §164.528 requires the covered entity to provide an accounting of disclosures of PHI made for purposes other than treatment, payment, or healthcare operations for the six years preceding the request. The compliance consultant implements the tracking systems, response templates, and escalation procedures for each patient rights request type, monitors compliance with the response timeframes, and documents each request and response for audit purposes.

Minimum necessary standard implementation under 45 C.F.R. §164.502(b) requires covered entities to make reasonable efforts to use, disclose, and request only the minimum amount of PHI necessary to accomplish the intended purpose of the use, disclosure, or request. The minimum necessary standard applies to routine uses and disclosures (for which the covered entity must have policies identifying who may access PHI for routine purposes), non-routine uses and disclosures (for which the covered entity must make individual determinations based on the criteria in the minimum necessary policies), and requests for PHI from other covered entities (for which the covered entity must limit its requests to the minimum PHI reasonably necessary to accomplish the purpose). The compliance consultant develops the organization’s minimum necessary policies, implements role-based access controls in EHR systems that are aligned with minimum necessary principles (only staff with a need to access a patient’s record for their assigned function can access that record), and trains staff on minimum necessary applications in clinical workflows — including the common minimum necessary error of pulling full medical records for tasks that only require a subset of the record.

De-identification of PHI: Expert Determination and Safe Harbor methods

De-identification is the process of removing from health information the elements that make it individually identifiable, so that the resulting information is not PHI and therefore not subject to the HIPAA Privacy Rule. The de-identification standard at 45 C.F.R. §164.514(a) states that health information that does not identify an individual and for which there is no reasonable basis to believe the information can be used to identify an individual is not PHI. The Privacy Rule provides two methods for achieving HIPAA de-identification: the Expert Determination method and the Safe Harbor method.

Expert Determination method under §164.514(b)(1) allows a covered entity to de-identify health information by having a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable apply those principles and methods to determine that the risk of identifying an individual is very small, and document the methods and results of the analysis that justify the determination. The Expert Determination method is more flexible than Safe Harbor — it can retain geographic subdivisions below the state level, dates including full birth dates and admission and discharge dates, and other data elements that would be required to be stripped under Safe Harbor — but it requires actual expert analysis and documentation. The expert is not required to hold any specific credential (not required to be a statistician in the formal sense), but must have genuine expertise in statistical privacy methods. The compliance consultant advises research departments and analytics vendors on when Expert Determination is appropriate, reviews expert de-identification reports for completeness and adequacy, and ensures that the expert’s methods and findings are documented in a form that would satisfy OCR scrutiny.

Safe Harbor method under §164.514(b)(2) requires the covered entity to remove 18 specific categories of identifiers from the health information. The 18 identifiers are: names; geographic subdivisions smaller than a state (including street address, city, county, precinct, and zip code, except that the first three digits of a zip code may be retained if the geographic unit formed by combining all zip codes with those three digits contains more than 20,000 people); all elements of dates directly related to an individual (except year) including birth date, admission date, discharge date, and date of death; telephone numbers; fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate and license numbers; vehicle identifiers and serial numbers including license plate numbers; device identifiers and serial numbers; web universal resource locators (URLs); internet protocol (IP) addresses; biometric identifiers including finger and voice prints; full-face photographs and any comparable images; and any other unique identifying number, characteristic, or code. The covered entity must also have no actual knowledge that the remaining information can be used alone or in combination with other information to identify an individual who is a subject of the information. If all 18 identifiers are removed, the information is de-identified under the Safe Harbor method without any expert analysis.

Limited data set under §164.514(e) is a middle ground between PHI and fully de-identified information: a limited data set excludes 16 of the 18 Safe Harbor identifiers (all except dates and geographic subdivisions at the level of city, state, and five-digit zip code, which may be retained) but retains enough contextual information to be useful for research, public health, and healthcare operations purposes. A limited data set may be used and disclosed for research, public health, or healthcare operations purposes without patient authorization if the covered entity executes a data use agreement (DUA) with the recipient that prohibits the recipient from identifying or contacting any individual whose information is included in the limited data set. The compliance consultant advises research departments, quality improvement teams, and analytics vendors on which de-identification method is appropriate for each specific data use — when Safe Harbor is sufficient, when Expert Determination is needed to retain useful data elements, and when a limited data set with a DUA is the most practical approach — and prepares data use agreements for limited data set disclosures.

Research authorizations and HIPAA-compliant research program administration

Research programs at hospital systems, academic medical centers, and clinical research organizations must navigate the intersection of HIPAA Privacy Rule requirements and federal human subjects protection regulations (45 C.F.R. Part 46, the Common Rule). The compliance consultant manages the HIPAA Privacy Rule side of this intersection: ensuring that research uses and disclosures of PHI are authorized, waived, or excepted in compliance with the Privacy Rule, and that the organization’s research authorization and IRB waiver processes are documented and functioning.

HIPAA research authorization under §164.508 permits a covered entity to use and disclose PHI for research if the individual provides a valid, HIPAA-compliant authorization. A valid research authorization must contain: a description of the PHI to be used or disclosed; identification of who is authorized to make the use or disclosure; identification of who is authorized to receive the PHI; a description of each purpose of the requested use or disclosure; an expiration date (or an expiration event such as the end of the research study); a statement that the individual has the right to revoke the authorization in writing; a statement that if the covered entity is using or disclosing the PHI for the purposes of research and the covered entity is combining the research activities with treatment, the individual may not be required to sign the authorization as a condition of receiving treatment; a statement about the potential for information disclosed pursuant to the authorization to be subject to redisclosure by the recipient and no longer protected by the Privacy Rule; and the individual’s dated signature. The compliance consultant reviews research authorization forms for completeness and HIPAA compliance, trains research staff on the authorization requirements, and monitors the consent and authorization processes in active research protocols.

Waiver of authorization by IRB or Privacy Board under §164.512(i) permits a covered entity to use or disclose PHI for research without patient authorization if an Institutional Review Board (IRB) or Privacy Board approves a waiver of authorization. The IRB or Privacy Board must find: (1) the use or disclosure involves no more than minimal risk to the privacy of individuals, based on, at least, an adequate plan to protect PHI identifiers from improper use and disclosure, an adequate plan to destroy the identifiers at the earliest opportunity consistent with the conduct of the research, and adequate written assurances that the PHI will not be reused or disclosed for other purposes except as required by law; (2) the research could not practicably be conducted without the waiver or alteration; (3) the research could not practicably be conducted without access to and use of the PHI; and (4) the privacy interests of the individuals whose PHI is being used are adequately protected. The compliance consultant monitors waiver approvals, ensures that waiver documentation is maintained, and verifies that researchers are using PHI only in the ways approved by the IRB or Privacy Board.

Research Preparatory to Research (RPR) exception under §164.512(i)(1)(ii) allows a covered entity to permit researchers to access PHI without authorization solely to prepare a research protocol or to assess the feasibility of a study, provided the researcher represents that: the access is sought solely to review PHI as necessary to prepare a research protocol or for similar purposes preparatory to research; the PHI will not be removed from the covered entity by the researcher in the course of the review; and the PHI for which access is sought is necessary for the research purpose. The compliance consultant monitors RPR access (maintaining a log of researcher access granted under the RPR exception), documents the representations the researcher makes, and verifies that PHI is not removed from the covered entity’s systems in violation of the RPR exception conditions.

Coding and billing compliance audit and accreditation maintenance

Coding and billing compliance is the retainer function that identifies and corrects coding errors, overpayments, and documentation gaps before they become the basis for MAC post-payment audits, RAC recovery demands, or OIG investigations. Accreditation maintenance advisory is the function that prepares the organization for TJC surveys and CMS Conditions of Participation assessments through continuous monitoring, mock surveys, and corrective action planning throughout the inter-survey period rather than only when the survey window is imminent.

Internal coding and billing compliance audit methodology

Internal coding and billing compliance audits are the mechanism through which the retained compliance consultant identifies the organization’s specific coding and billing compliance vulnerabilities and quantifies their financial and regulatory impact. An effective audit program is risk-based, methodologically sound, and generates findings that support both corrective action and, where necessary, voluntary refund or OIG self-disclosure.

Risk-based audit selection drives the annual compliance audit work plan. The compliance consultant identifies audit topics based on four data sources: OIG Work Plan items relevant to the organization’s services (if the OIG has identified hospital outpatient E/M coding as an audit priority, the compliance consultant schedules a targeted hospital outpatient E/M audit); MAC (Medicare Administrative Contractor) comparative billing reports showing the organization’s coding patterns relative to similar providers in the same geographic region (a hospital whose DRG code-mix shows significantly higher Case Mix Index than regional peers warrants targeted DRG coding audit); Targeted Probe and Educate (TPE) and Recovery Audit Contractor (RAC) audit history (claim types that have been audited and subject to recoupment or education letters warrant continued monitoring); and internal data analytics (billing system data showing unusually high E/M level selection rates, unusually high outlier claim rates, high denial rates for specific DRGs or CPT codes, or unusually low CC/MCC capture rates relative to national benchmarks).

Statistically valid sampling methodology is the standard the OIG endorses for internal coding compliance audits. The compliance consultant uses RAT-STATS (the OIG’s free statistical software, available on OIG.HHS.gov) or comparable statistical software to design samples at the 90% confidence interval and ±10% precision level. For universes of 50 or more claims, a random sample designed to those parameters typically requires 50-100 claims; for universes under 50 claims, the compliance consultant may use judgment sampling with documentation of the selection criteria. Sample results are extrapolated to the universe using the point estimate of error rate times the universe value to quantify the financial impact of the identified coding discrepancies. The extrapolated overpayment figure is the basis for the 60-day overpayment obligation analysis.

2021 AMA E/M coding revisions govern outpatient E/M coding for office and outpatient visits effective January 1, 2021, when CMS adopted the AMA’s revised E/M coding guidelines. The revisions eliminated the requirement to document all three key components (history, examination, and medical decision making) for level selection and replaced it with a choice between two alternative bases for level selection: (1) Medical Decision Making (MDM) complexity — assessed based on the number and complexity of problems addressed at the encounter, the amount and/or complexity of data reviewed and analyzed, and the risk of complications and/or morbidity or mortality of patient management; or (2) Total Time — the total time the clinician spends on the date of service, including pre-visit preparation time, face-to-face encounter time, and post-visit tasks such as ordering tests, communicating results to patients, and coordinating care. The compliance consultant audits against the 2021 E/M guidelines to confirm that each audited encounter’s billed E/M level is defensible under either MDM or total time, identifies E/M levels that are not supported by the documentation, and provides root cause analysis distinguishing between documentation deficiencies (the service was provided at the billed level but documentation does not support it) and coding errors (the service was not actually provided at the billed level).

60-day overpayment reporting obligation under 42 U.S.C. §1320a-7k(d) and 42 C.F.R. §401.305 requires Medicare providers and suppliers to report and return identified overpayments within 60 days of identification — where “identification” is defined as the date on which the provider has, or should have through the exercise of reasonable diligence, determined that it has received an overpayment. Failure to timely report and return an identified overpayment is itself a False Claims Act violation under the reverse false claims theory (“knowingly conceal[ing] or knowingly and improperly avoid[ing] or decreas[ing] an obligation to pay or transmit money or property to the Government”). The compliance consultant advises on when an internal coding audit finding constitutes an “identified overpayment” triggering the 60-day clock, calculates the refund amount using the statistical extrapolation methodology, prepares the voluntary refund submission to the MAC with a cover letter explaining the root cause and corrective action taken, and refers to healthcare attorneys the question of whether the identified overpayments require OIG Self-Disclosure Protocol submission (as opposed to a simple voluntary MAC refund) based on the nature and extent of the conduct.

CMS Conditions of Participation and state survey preparation

CMS Conditions of Participation (CoPs) for hospitals under 42 C.F.R. Part 482 are the federal participation requirements that hospitals must meet to receive Medicare or Medicaid payment. Unlike TJC accreditation standards (which TJC publishes and interprets), CMS CoPs are federal regulations interpreted by state survey agencies acting on behalf of CMS. The retained compliance consultant prepares the organization for state CoP surveys through continuous self-assessment rather than reactive preparation only when a survey is imminent.

High-deficiency CoP areas that the compliance consultant monitors continuously include: §482.13 Patient Rights (informed consent procedures, patient grievance process, restraint and seclusion requirements including the requirement to notify the patient’s physician when restraint or seclusion is initiated and to evaluate the patient face-to-face within one hour of restraint initiation); §482.24 Medical Records Services (content requirements including authentication of all entries, retention requirements, and timeliness of record completion); §482.25 Pharmaceutical Services (medication storage and labeling requirements, drug administration procedures, and the pharmacy and therapeutics committee function); and §482.21 Quality Assessment and Performance Improvement (QAPI) program requirements (the QAPI program must address all aspects of patient care in the hospital, use data to identify opportunities for improvement, and track compliance with care processes and outcomes across service lines). The compliance consultant maintains a self-assessment tracking tool organized by CoP citation, documents the results of periodic self-assessments, and identifies corrective actions needed before the next state survey.

Immediate Jeopardy (IJ) condition is the most serious CMS deficiency finding: a situation in which the provider’s noncompliance with one or more CoP requirements has caused, or is likely to cause, serious injury, harm, impairment, or death to a patient. IJ findings require the provider to submit an acceptable Allegation of Compliance (AoC) within 24 hours of the IJ being communicated by the surveyor; the AoC must identify the specific corrective actions the provider has taken or will take to immediately address the IJ situation, the completion dates for each corrective action, and the evidence available at the time of submission demonstrating that the IJ has been removed. The compliance consultant advises hospital leadership on IJ response procedures in advance of any survey, ensuring that designated staff know how to initiate an IJ response team, what evidence to assemble for the AoC, and how to document removal of the IJ condition. For hospitals that have received an IJ finding in a prior survey, the compliance consultant conducts specific mock IJ scenario exercises to test the hospital’s IJ response capability.

The Joint Commission accreditation survey preparation

TJC accreditation is required by CMS as a condition for Medicare payment under the CMS “deemed status” pathway at 42 C.F.R. Part 488 for hospitals, critical access hospitals, and ambulatory surgical centers. TJC surveys are unannounced within an 18-to-36-month window following the most recent accreditation survey (TJC notifies hospitals that they are in the survey window but does not announce specific survey dates). The compliance consultant prepares the organization throughout the entire inter-survey period, conducting continuous monitoring, quarterly mock surveys, and progressive corrective action implementation rather than conducting intensive preparation only when the survey window opens.

TJC tracer methodology is the survey method TJC surveyors use to evaluate the organization’s compliance with accreditation standards in real-world clinical practice. Individual tracer methodology involves a TJC surveyor selecting a current or recently treated patient and following that patient’s care through the organization — reviewing the medical record, interviewing clinical staff who provided care, and directly observing care delivery processes at each care setting the patient encountered. System tracer methodology examines cross-cutting organizational systems (medication management, infection prevention and control, data use for quality improvement, and environment of care) across the entire organization, looking for systemic vulnerabilities rather than patient-specific issues. The compliance consultant conducts mock individual and system tracer exercises with hospital staff, simulating the tracer methodology to identify process vulnerabilities, staff knowledge gaps, and documentation deficiencies before TJC surveyors arrive. Mock tracers are conducted quarterly during the inter-survey period, with findings documented and corrective actions tracked to completion.

National Patient Safety Goals (NPSGs) are TJC’s annual compilation of specific patient safety practices that hospitals must implement to maintain accreditation. TJC publishes the Hospital NPSGs annually, effective January 1; NPSGs are evidence-based patient safety interventions identified in response to sentinel events and safety research. Key 2026 Hospital NPSGs that the compliance consultant assesses include: NPSG.01.01.01 (Identify Patients Correctly — use at least two patient identifiers when administering medications, blood products, or other treatments, and before collecting blood specimens or other specimens for clinical testing; eliminate wrong-patient errors in radiology through patient identification verification at point of care); NPSG.02.03.01 (Improve Staff Communication — report critical test results and diagnostic values to the responsible licensed caregiver within an established time frame); NPSG.03.06.01 (Maintain and Communicate Accurate Patient Medication Information — conduct medication reconciliation at care transition points including admission, transfer between units or services, and discharge); NPSG.06.01.01 (Improve the Safety of Clinical Alarm Systems — establish alarm management as an organizational priority, identify the most important alarm signals to manage, and establish policies and procedures for responding to clinical alarms); NPSG.07.01.01 (Reduce the Risk of Healthcare-Associated Infections — comply with current hand hygiene guidelines from the CDC or WHO and monitor hand hygiene compliance); and NPSG.15.01.01 (Identify Patient Safety Risks — identify patients at risk for suicide in behavioral health programs or settings where behavioral health patients are treated). The compliance consultant conducts NPSG-specific readiness assessments for each active NPSG applicable to the organization’s care settings, documents assessment findings, and prepares corrective action plans for NPSG compliance gaps.

TJC-aligned document management is the compliance consultant’s function of maintaining the organization’s policy and procedure library in a format that can be directly cross-referenced against the applicable TJC accreditation standards chapter and element of performance (EP). TJC Hospital Accreditation Standards are organized in chapters: Human Resources, Environment of Care, Emergency Management, Infection Prevention and Control, Information Management, Leadership, Life Safety, Medication Management, Medical Staff, Nursing, Provision of Care Treatment and Services, Quality Improvement, Record of Care Treatment and Services, Rights and Responsibilities of the Individual, Transplant Safety, and Waived Testing. Each chapter contains standards, and each standard contains numbered elements of performance that describe what the organization must do to comply with the standard. The compliance consultant maps each organizational policy and procedure to the applicable TJC standard EP number, maintains a crosswalk document showing which EPs are addressed by which policies, and identifies EPs that lack a corresponding policy or procedure.

Tracking healthcare compliance consultant retainer hours with a shared dashboard

Healthcare compliance consulting has a particular invisible-work problem: the work product is a functioning compliance program, a trained workforce, a clean audit, a successful survey — outcomes that are visible only in the absence of a deficiency. When TJC surveyors arrive and find no significant findings, when OIG auditors review the organization’s compliance files and find a functioning seven-element program, when OCR receives a complaint and finds documented Privacy Rule policies and training records — those outcomes are the product of 20-40 hours per month of advisory work by the retained compliance consultant that produced no visible artifact between survey events. The hospital’s CFO, who approved the $12,000 monthly compliance consulting retainer three years ago, has seen no tangible output because the compliance program worked.

A retainer dashboard with a detailed work log transforms the healthcare compliance consulting retainer from an opaque monthly fee into a documented compliance activity record. Which OIG Work Plan items were addressed this month? How many coding claims were audited, and what was the error rate? Which NPSG was the focus of this month’s mock tracer exercise? How many staff members completed annual compliance training, and what was the average post-training assessment score? The hospital’s CCO and CFO can see the compliance program investment in terms of specific audit activity, training completion, exclusions screening results, and survey preparation progress — not a monthly invoice for “compliance consulting services.” When the TJC survey finds no significant findings, they understand why: because the retained compliance consultant conducted quarterly mock tracers, reviewed staff knowledge gaps, and implemented corrective actions for 18 months before the survey window opened.

HourTab provides the public, no-login retainer dashboard URL that the healthcare compliance consultant shares with the hospital’s CCO and CFO once, and that those administrators bookmark and check throughout the month. The dashboard shows the current retainer burn-down (hours used and hours remaining in the current billing cycle), the reset date for the next cycle, and the chronological work log of compliance activities the consultant has completed. No client login required. No portal to manage. The CCO can check on Monday morning whether the Q3 coding audit sample review was completed without sending the compliance consultant a status email — and the compliance consultant’s monthly billing conversation starts from a shared understanding of what was accomplished, not a dispute about whether 14.5 hours of ED coding audit work was actually performed.

Frequently asked questions

What does a healthcare compliance consultant on retainer typically do?

A healthcare compliance consultant on monthly retainer — typically a Certified in Healthcare Compliance (CHC) professional credentialed through the Health Care Compliance Association (HCCA) — provides ongoing non-attorney compliance program implementation and monitoring across five principal areas: (1) OIG seven-element compliance program implementation and gap assessment, including annual work plan development based on OIG Work Plan items and MAC comparative billing data; (2) monthly LEIE and SAM.gov exclusions screening for all employees, contractors, medical staff, and vendors under 42 U.S.C. §1320a-7, with documentation and remediation procedures for any matches; (3) annual general and role-specific compliance training design, delivery, and documentation covering code of conduct, False Claims Act qui tam provisions, HIPAA basics, CCI and NCCI coding rules, and medical necessity documentation requirements; (4) HIPAA Privacy Rule compliance including NPP administration under 45 C.F.R. §164.520, patient rights request management (access under §164.524, amendment under §164.526, accounting of disclosures under §164.528), minimum necessary policy implementation under §164.502(b), and research authorization and de-identification advisory; and (5) internal coding and billing compliance audit using statistically valid sampling (RAT-STATS, 90% confidence, ±10% precision), 60-day overpayment obligation identification under 42 U.S.C. §1320a-7k(d), and voluntary MAC refund coordination. The compliance consultant also manages TJC accreditation preparation through quarterly mock tracer methodology exercises and NPSG readiness assessments, and CMS Conditions of Participation self-assessment under 42 C.F.R. Part 482. The compliance consultant does not provide legal advice; legal issues identified in compliance reviews are referred to healthcare attorneys.

What healthcare compliance consulting work is most commonly underlogged?

The most systematically underlogged categories in healthcare compliance consultant retainers are: OIG Work Plan monitoring and audit plan updates (reviewing monthly OIG Work Plan additions and adjusting the internal audit work plan to address newly identified OIG priorities — typically 4-8 hours per month, invisible until the next OIG audit or MAC Targeted Probe and Educate review); monthly LEIE and SAM.gov exclusions screening (screening all employees, contractors, medical staff, and vendors against the OIG LEIE at exclusions.oig.hhs.gov and the SAM.gov Exclusions database, documenting results, and managing any matches — civil money penalties of $10,000 per item or service under 42 U.S.C. §1320a-7a make this high-stakes work that rarely appears in work logs; typically 3-6 hours per month); HIPAA minimum necessary policy review for new clinical workflows (evaluating whether a proposed new EHR workflow, vendor integration, or care coordination program creates impermissible PHI disclosures under 45 C.F.R. §164.502(b) — typically 4-10 hours per workflow review, invisible until an OCR complaint or audit identifies the gap); internal coding audit sample review (selecting, reviewing, and documenting findings for 30-50 coding audit claims using statistically valid sampling and extrapolating findings to the universe — typically 10-20 hours per quarterly audit cycle); and TJC mock tracer methodology preparation (conducting mock individual and system tracers against the 2026 NPSGs, interviewing staff, observing care delivery processes, and preparing corrective action plans — typically 15-30 hours per quarterly mock survey cycle, invisible to the governing board until the actual TJC survey window opens and the organization either passes or does not).

What should a healthcare compliance consultant retainer agreement include?

Healthcare compliance consultant retainer agreements should specify: the services covered (OIG seven-element compliance program maintenance, monthly LEIE and SAM.gov exclusions screening, annual general and role-specific compliance training, HIPAA Privacy Rule compliance including NPP administration and patient rights request management, internal coding and billing audit including 60-day overpayment analysis and voluntary MAC refund coordination, CMS Conditions of Participation self-assessment under 42 C.F.R. Part 482, and TJC accreditation preparation including quarterly mock tracers and NPSG readiness assessments — or a specifically defined subset); the applicable regulatory frameworks (42 U.S.C. §1320a-7 OIG exclusion statute; 2023 OIG General Compliance Program Guidance; 45 C.F.R. Part 164 HIPAA Privacy and Security Rules; 42 C.F.R. Part 482 CMS Conditions of Participation; TJC Hospital Accreditation Standards; applicable OIG Work Plan items; and applicable Medicare Administrative Contractor Local Coverage Determinations); the audit deliverables format (written audit reports with universe description, sample design using RAT-STATS or equivalent, findings by claim including specific ICD-10-CM or CPT code discrepancies, error rate with confidence interval, extrapolated financial impact, root cause analysis, and corrective action plan recommendations); and the work log format showing compliance activity type, applicable regulatory standard reviewed, and time spent. Monthly retainer amounts are typically $3,000-$8,000 per month for physician practices and ambulatory surgery centers; $8,000-$20,000 per month for community hospitals; $20,000-$50,000 or more per month for health systems or during active OIG investigation, CMS Immediate Jeopardy remediation, or TJC conditional accreditation follow-up. The agreement should explicitly state that the compliance consultant does not provide legal advice and that legal matters identified in compliance work are referred to qualified healthcare attorneys.

What are typical retainer rates for healthcare compliance consultants?

Healthcare compliance consultants with 3-7 years of experience holding the CHC credential from the Health Care Compliance Association (HCCA) typically bill at $125-$250 per hour for ongoing retainer work. Senior compliance consultants with 10 or more years of experience, the CHC-F (CHC-Fellow) credential, prior experience as a hospital Chief Compliance Officer, or former CMS or OIG experience typically bill at $200-$400 per hour. Consultants with specialized sector expertise in inpatient rehabilitation facilities (IRFs), long-term acute care hospitals (LTACHs), ambulatory surgery centers, behavioral health, or academic medical center research compliance may command rates at the top of or above these ranges for sector-specific engagements. Monthly retainer amounts are: $3,000-$8,000 per month for small physician practices (solo to small group), ambulatory surgery centers, and independent behavioral health programs; $8,000-$20,000 per month for community hospitals (100-400 beds) covering full OIG compliance program maintenance, HIPAA Privacy Rule administration, coding audit, and TJC survey preparation; $20,000-$50,000 or more per month for health systems or for hospitals in active OIG investigation, CMS Immediate Jeopardy remediation, or TJC conditional accreditation remediation. Project fees above the monthly retainer are standard for specific deliverables: OIG seven-element compliance program gap assessment ($5,000-$15,000), TJC pre-survey accreditation readiness assessment ($8,000-$20,000), large multi-service-line coding audit project ($10,000-$30,000). Healthcare compliance consultants do not provide legal advice; legal issues identified in compliance work are referred to healthcare attorneys whose rates are typically $325-$900 per hour depending on experience and specialization.

How should healthcare compliance consultant retainer hours be logged?

Healthcare compliance consultant retainer work log entries should capture the activity type, specific task, applicable regulatory standard or TJC accreditation standard, and finding or recommendation. A complete example demonstrates the level of detail that transforms a compliance consulting retainer from an opaque monthly fee into a defensible compliance activity record: “ICD-10-CM Coding Compliance Audit — Emergency Department Facility Claims Sample (Q2 2026). Universe: 847 ED facility claims with CPT facility level codes 99282-99285 (mid- to high-complexity ED visits) billed April 1-June 30, 2026. Sample: 50 claims selected using stratified random sample (RAT-STATS, 90% confidence, ±10% precision), stratified by ED facility level (5 strata). Audit criteria: (1) ICD-10-CM principal diagnosis code selection — does the billed principal diagnosis code (the condition established after study to be chiefly responsible for the visit) match the medical record? (2) Secondary diagnosis code selection — are additional ICD-10-CM codes captured for conditions that coexisted at admission or developed subsequently and affected the care provided? (3) CC/MCC capture — are Complication and Comorbidity or Major Complication and Comorbidity diagnoses coded when documented in the medical record? Findings: 50 claims reviewed; 8 claims (16%) had coding discrepancies: 3 claims with principal diagnosis undercoded (e.g., K92.1 Melena coded instead of K57.31 Diverticulosis of large intestine with bleeding); 4 claims with secondary diagnosis CC omitted (e.g., hypertensive chronic kidney disease stage 3 documented in the medical history but not coded as secondary diagnosis); 1 claim with principal and secondary diagnosis sequence incorrect. Extrapolated error rate: 16% (±10% at 90% confidence = 6%-26%). Financial impact: estimated net coding impact $1,900-$4,200 across Q2 universe. Root cause: ED physician documentation improvement opportunity for CKD staging specificity. Recommended actions: (1) ED physician documentation improvement education session on CC/MCC capture; (2) coder query template for missing CKD staging; (3) 60-day overpayment obligation analysis for 3 undercoded principal diagnosis claims under 42 U.S.C. §1320a-7k(d). 14.5 hours.” This level of detail — universe, sample design, audit criteria, claim-level findings, extrapolated error rate, root cause, and corrective action recommendations — gives the hospital’s CCO and CFO a compliance audit report in the work log entry itself, not just a time entry.


HourTab gives healthcare compliance consultants a public retainer dashboard URL their clients can bookmark — no client login, no portal, just a URL that shows hours used, hours remaining, and the work log behind the compliance program advisory. Learn more at hourtab.com.