1/93
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
7 Fundamental Elements of an Effective Compliance Program
1) Implement policies, procedures, & standards
2) Designate a compliance officer & compliance committee
3) Training & education
4) Lines of communication
5) Internal monitoring & auditing
6) Standards enforcement
7) Response and corrective action
6 Phases of Corrective Action Plans
1) Identification
2) Evaluation
3) Root Cause Analysis
4) AP Development
5) AP Implementation
6) Follow-up
CAP Overarching Goal
Facilitate thoughtful analysis of issues and develop long-lasting sustained improvements
RCA
What, why, & how an event occurred
COSO Framework
1) Monitoring
2) Info & communication
3) Control activities
4) Risk Assessment
5) Control environment
Fraud and Abuse Laws
1) Stark Law
2) Anti-Kickback Statute (AKS)
3) False Claims Act (FCA)
4) Civil Monetary Penalties Law (CMP Law)
ACA
-Requires healthcare providers/orgs to have an ethics and compliance program to get Medicare reimbursement
-Requires overpayment be returned w/in 60 days of discovery
-Revised AKS to where individuals can violate AKS without actual knowledge/intent - payment has to be made knowingly and willingly
The hallmark of a well designed compliance program
It is well integrated into the company's operations and workforce
Two types of standards under the HCCA code of ethics
1) Principles
2) Rules of conduct
False Claims Act (FCA)
-Allows the government and citizens to bring civil actions against an organization for fraud
-Provides financial incentive for citizens who come forward (Qui tam)
Qui Tam
-Whistle blower
-15-25% of total award given if DOJ takes the case
-25-30% of the total award if the DOJ declines the case
"Three strikes and you're out" clause requiring permanent expulsion for a health organization found guilty of fraud a third time
The Balanced Budget Act (BBA) of 1997
Corporate Integrity Agreement (CIA)
-A government imposed plan for correction after an organization enters into a settlement agreement with the government
-Usually has a 5 year duration
-A way for organizations to avoid lengthy and costly litigation and admit no fault/liability
Code of Conduct
-Communicates an organizations values, mission, and standards
-Applies to all EE's and organizational reps (vendors, suppliers, contractors)
-Provides a roadmap for proper decision making
The only thing worse than not having a policy is having a policy and not following it
True
Policies and procedures address identified areas of risk and compliance program operation
True
Written charter
-Defines the responsibility and duties of the compliance committee
-Board committee includes responsibility of compliance oversight
First line of defense for a compliance committee
Education and training
Two types of training suggested by the OIG
1) General session for all EE's
2) Specific session for appropriate staff
An effective compliance program is one with a process of constant evaluation
True
Types of Audits
1) Retrospective (historical snapshot)
2) Concurrent (real-time)
Retrospective Audit
-Provides a baseline assessment
-Identifies errors that occurred and need to be fixed
Concurrent Audits
-Identifies and addresses problems as they arise
-Harder to execute
-One of the best ways to effect change
3 core functions of a compliance program infrastructure
1) Compliance Officer
2) Compliance Committee
3) Board/Governing Body
Compliance Officer Role
-Should not lead or report to the entities legal or financial functions, should not provide the entity with legal or financial advice or supervise anyone who does
-Chairs the Compliance Committee
Board of Directors
-Responsible for overseeing fiduciary assets and mission of the organization
Compliance Committee
-A management-level committee charged with oversight
-Meets quarterly
-Has an agenda
-Takes meeting minutes
-Operates under a written charter
-Develops annual goals and objectives
The Strike Force Team
-Focused on investigating and combating rampant fraud schemes
-Comprised of members from OIG, DOJ, US Attorneys Office, FBI, and local law enforcement
Who has exclusive authority to exclude from participation in federally funded healthcare programs due to fraud or abuse?
OIG
HIPAA requires patient notification of a data breach when?
ASAP and no later than 60 days
Not having physician buy-in is one of the biggest obstacles to implementing an effective compliance program
True
Role of Compliance
Prevent, detect, and resolve misconduct
What key departments should feedback be received from during an organizational compliance assessment?
Finance Quality IT
Operations Risk HR
Procurement Marketing Audit
Legal Physicians
Who serves as a primary source of information for compliance purposes?
EE's
What is the first step toward implementation of a compliance plan?
Management's communication of its commitment
Yates Memo
Emergency Medical Treatment and Labor Act (EMTALA)
3 Fiduciary Duties of the Board
1) Duty of Care
2) Duty of Loyalty
3) Duty of Obedience
The Compliance Officer ensures the Board is regularly updated on what?
-High-risk areas
-Fraud, waste, and abuse issues
-AKS/Stark Laws and policies
-OIG advisory opinions and audits
-Government enforcement trends
-Major applicable CMS developments
-Internal reviews
Risk Management
The identification, assessment, and prioritization of risks
Compliance Program Assessment
-A comprehensive review of compliance processes and activities to assess overall impact and effectiveness
-Includes a review of the risk assessment
Compliance Risk Assessment
Identification and evaluation of a company's compliance risks
A compliance risk assessment includes what at a minimum?
-Criminal misconduct
-Legal liability from noncompliance
-Ethical lapse
-Reputational harm
Risk Appetite
The level of enterprise-wide risk that leaders are willing to take
Black Swan Risk
The threat nobody considered or saw coming
Policies
-Describe expectations
-Set rules
Procedures
-Describe specific steps necessary to complete a particular process
When a privacy breach occurs and effects more than 500 people, Compliance must report the breach to the government and local media
True
What channel are employees most likely to use for reporting a concern?
A manager
What is the best strategy for prevention?
Education
An internal reporting system is a key aspect of detecting potential areas of noncompliance
True
Enterprise Risk Management (ERM)
A structured process that helps organizations identify, assess, and manage risks that could impact their operations or mission
4 Elements of a successful ERM program
1) Understanding the history of ERM and healthcare specifics
2) A systematic collection of risk related data
3) A decision framework for management that connects strategic goals to the risk data
4) A top-down risk aware culture
ISO 31000
An international standard for risk management, providing guidelines and a framework for organizations to identify, assess, and manage risks
What informs a risk priority?
1) Organizational strategic priorities
2) Risk culture
Risk and control register
-Definition: A critical tool used by organizations to manage and monitor risks and their associated controls
-Purpose: Provide a centralized, organized approach to identifying, assessing, and managing risks and the controls in place to manage them
COSO 5 Components of Effective Internal Control Systems
1) Control environment
2) Risk assessment
3) Control activities
4) Info and communication
5) Monitoring activities
Program for Evaluating Payment Patterns Electronic Report (PEPPER)
-A Microsoft Excel file summarizing provider-specific Medicare data statistics for target areas often associated with Medicare improper payments
-Supports auditing and monitoring compliance with a goal of complying with Medicare regulations and preventing improper Medicare payments
Auditing vs Monitoring
Auditing
-A formalized independent approach to measuring effectiveness
-Needs to be performed by people independent of operations being audited
-Validates monitoring effectiveness
Monitoring
-A form of self-assessment
-Can be performed by anyone
Monitoring programs should be designed to test for inconsistencies, duplication, errors, policy violations, or other breakdowns in internal controls
True
Types of audits
1) Internal/external
2) Prospective/retrospective
Prospective audits
Examine a system in action
Retrospective audits
Look at work that has already been done
Who must audit findings be reported to?
1) Senior management
2) Compliance or audit committee
3) The governing body
How often does the OIG update the work plan?
Monthly
4 Stages of the Audit Process
1) Planning
2) Execution
3) Reporting
4) Follow-up
US Federal Sentencing Guidelines for Organizations (FSGO)
A federal law that pertains to the assessment of damages in cases of fraud against the government
The organization's board is ultimately responsible for overseeing and managing efforts to manage risk and ensure compliance with applicable laws and regulations
True
What is best practice for completing an external assessment?
Every 3 years
If an organization can demonstrate that it had put into place an effective compliance program, the potential fine can be mitigated by 95% in some cases
True - FSGO
What is a company's first opportunity to learn about an allegation?
Complaint intake and investigation
Types of Investigation Programs
1) Centralized: Performed by one group
2) Semi-Centralized: Performed by more than one group
3) Decentralized: Performed by individual groups
4) Outsourced: Performed by skilled external resources
Communications made for purposes other than to obtain legal advice are not privileged
True
A well-designed disciplinary policy with documented enforcement that is fair and consistent is a key component of an effective compliance program
True
6 Phases of Corrective Action Plans (CAP)
1) Identification
2) Evaluation
3) RCA
4) AP Development
5) AP Implementation
6) Follow-up
Successful action plans must have someone accountable for their implementation and ongoing effectiveness
True
What is the overarching goal of any CAP process?
To facilitate thoughtful analysis of issues and to develop long-lasting sustained improvements
The 60-Day Rule
Requires healthcare providers to return an overpayment within 60 days of identification of an overpayment
What is the look back period for overpayments?
6 years
AKS minimum settlement amount
$5k + repayment of any overpayment
Penalty amount under Stark Law
$30k per inappropriate service
AKS fine amount for criminal violations
$100k per violation
FCA fine amount
Triple the damages or $20k per claim
What is the Anti-Kickback Statute?
Federal criminal statute prohibiting transactions to induce or reward referrals for items or services reimbursed by federal healthcare programs.
Has criminal and civil penalties
What is the Civil Monetary Penalties Law (CMPL)?
Authorizes HHS to impose civil money penalties for fraudulent claims to a federal or a state agency
Includes knowingly keeping an overpayment and billing for medically unnecessary services
What is Stark Law?
The Physician Self-Referral Law
A strict liability statute - doesn't require specific intent to violate the law
What is the False Claims Act (FCA)?
It protects the government from being overcharged or sold faulty goods or services
Who does the Eliminating Kickbacks in Recovery Act (EKRA) apply to?
1) Clinical treatment/recovery facilities
2) Clinical laboratories
What is the Emergency Medical Treatment and Labor Act (EMTALA)?
A federal law that prevents discrimination of patients in hospital ED's and bans "patient dumping"
What are the 3 main legal obligations under EMTALA?
1) Any person in the ED must be able to receive a screening exam to determine if an emergency medical condition exists
2) Treatment of an emergency medical condition must be provided until the condition is resolved or the patient is stabilized
3) Hospitals with specialized capabilities must accept transfers that lack capacity to treat unstable emergency medical conditions
What are the penalties under EMTALA?
1) Up to $50k per violation for large hospitals
2) Up to $25k per violation for hospitals with less than 100 beds
Under Caremark and Stone, directors of healthcare organizations owe a fiduciary duty of shareholders concerning compliance with the law
A program is generally effective when it is specifically tailored to applicable business standards, size of the organization, and similar misconduct in the organization
How does an excluded individual or organization get reinstated?
Once the term of exclusion ends, they must apply for reinstatement and receive written notice from the OIG that reinstatement has been granted
The process can begin 90 days prior to the end of the exclusion period