No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

New OIG Guidance: Let Compliance Officers Stay in Their Lane

HHS publishes nonbinding recommendations for healthcare & life sciences compliance programs

by Mary Shirley
November 14, 2023
in Compliance
overhead view of stretch of road

The HHS Office of Inspector General has published new guidance for compliance programs in the healthcare industry. Compliance author and CCI columnist Mary Shirley shares her insights into how the guidance is instructive, not just in the healthcare and life sciences industries but beyond.

Corporate Ethics and Compliance Week, which was Nov. 5-11 this year, is basically the holiday season for the ethics and compliance community — our festive season of cheer, celebration and community. So it is perhaps fitting (and definitely super cute) of the U.S. Department of Health and Human Services Office of Inspector General (OIG) to gift Team Compliance (that’s us) with their latest advice, “General Compliance Program Guidance,” to kick off our week of fun, frolic, education and outreach. Best gift ever! 

General observations about the guidance

Weighing in at 91 pages, the OIG’s guidance is comprehensive. It is unlikely, dear reader, that I will be able to do the guidance justice in one summary article. Therefore, I’ve reviewed the document in its entirety and am focusing on the angle I found most compelling from the standpoint of relevant content that will likely cause many compliance leads to think about whether they need to adjust the status quo. 

While we’re on this point, I think the level of care the OIG has put into making this a practical, user-friendly document is wonderful. They’ve taken care to lay out the pages so the content isn’t hard on the eye, given an overview of the U.S. healthcare laws, included useful questions to ask of yourself (like the DOJ’s “Evaluation of Corporate Compliance Programs” guidance) and even offered learning aids of examples to demonstrate their points. It also tells you what to do if you need help or how to submit feedback. I’m going to go out on a limb here and say this is a gold standard guidance document.

Another thing I ought to note is that this guidance is released for the “health care compliance community and other health care stakeholders,” per an OIG email notifying subscribers of the release of the new resource. This statement is also included on Page 2 of the document and captures many organizations falling under the life sciences areas as well, so I’ll also share my views on what this guidance means for compliance professionals outside the targeted industries.

Thirdly, a “User’s Guide” section on how to use the guidance emphasizes that it is voluntary, nonbinding and highlights the use of “should” throughout the document to make clear that the document is of a recommendatory nature only. This makes sense given it’s called “guidance” and not “rules,” though even with this in mind, I think we can agree that practitioners take guidance seriously and consider it to be pretty darn instructive, largely because it sets out what appear to be the government’s preferences and expectations, even if room is being left for them not to apply in every single situation. 

The OIG has highlighted certain passages in bold, which suggests to me that while the guidance is voluntary, the government really wants us to consider implementing the highlighted policies or procedures if we haven’t already.

Compliance officer independence and empowerment

The first section of the guidance focuses on substantive healthcare compliance, which sets out good foundational understanding and tips and then moves onto the seven elements of an effective compliance program, where I think there were some thought provoking takeaways for leadership and compliance officers. 

I therefore take a deep dive into those areas, starting at Page 39 (note passages OIG highlighted in bold):

“To fulfill their duties, the compliance officer should be empowered, and independent of other duties to the entity that might impair their ability, to identify and raise compliance risks and advise on how to mitigate risks, achieve and maintain compliance with Federal health care program requirements, and succeed as a compliant entity. Thus, the compliance officer should not lead or report to the entity’s legal or financial functions, and should not provide the entity with legal or financial advice or supervise anyone who does. The compliance officer should report directly to the CEO or the board. Usually, leaders of these functions are the general counsel and the chief financial officer, but some entities give them different titles.

“To be effective, the compliance officer should also maintain a degree of separation from the entity’s delivery of health care items and services and related operations. Thus, the compliance officer should not be responsible, either directly or indirectly, for the delivery of health care items and services or billing, coding, or claim submission. In addition, involvement in functions such as contracting, medical review, or administrative appeals present potential conflicts. Whenever possible, the compliance officer’s sole responsibility should be compliance.”

There’s a lot to unpack here. The OIG emphasizes that the standard is an independent and empowered compliance officer. The guidance also suggests that, where possible, the CO should be dedicated solely to compliance, but in any event should not be part of legal or finance in particular and also should not carry out the traditional role of legal and finance staff.

So organizations that have compliance reporting into legal ought to reconsider their structure in light of the guidance and what this may mean for general counsel who hold the chief compliance officer mantle as well. Now, of course, with the guidance being nonbinding, some companies may consider keeping their structures if they are comfortable the CO is otherwise empowered and independent and thereby they are achieving the spirit of the guidance. This could apply, for example, to a CCO who reports into the GC/legal and also has a dotted line into the CEO. 

However, given this is one of the instances where the OIG has chosen to highlight recommendations with bold text, I think companies that don’t already have wholly independent reporting lines for compliance should consider it incumbent on them to think carefully about this point and whether there would be any harm in separating the functions formally.

Incentives to report FCPA violations greater than ever for compliance officers
Compliance

New DOJ Guidance Charts a Way Forward on Ephemeral Messaging

by Mary Shirley
March 8, 2023

Read moreDetails

Tale as old as time … well, quite some time, anyway

I have always interpreted this approach as being the preferred one of the OIG, given the requirement for separate legal and compliance functions in many corporate integrity agreements (CIAs), but I think this is the first time the advice has been stated in broader guidance. That means for organizations that may have previously brushed off this approach, justifying the disregard on the basis that they were not in trouble and subject to a CIA will likely need to reconsider their position. 

Making a clear distinction between legal and compliance is not a new concept when looking more broadly beyond CIAs. Ethics and compliance thought leader Donna Boehme has long been a proponent for legal and compliance being separate, even winning an award from the Society of Corporate Compliance and Ethics for her campaigning work in this area in 2015. 

As a side note, I would point out that at Page 86 of the guidance, the OIG considers that CIAs “can serve as a resource when a health care entity reviews its compliance program’s structure and operations,” so they’re clear on the fact that we should consider CIAs as instructive regardless of whether we’re a company in a compliance crisis or not.

Compliance officers don’t need to be qualified lawyers

Of course, this makes sense, not only when it comes to independence but also when we consider the other messaging the OIG is giving in the aforementioned passage from the guidance — that compliance officers shouldn’t be giving legal advice. So, while it has not been expressly recommended in the guidance, I think the inclusion of this detail should give companies that require that their compliance team consist of (often) U.S.-qualified attorneys and make every role in the team a “counsel” position consider that perhaps they’re taking too legal an approach to a function that is not actually a legal function. 

On Page 38, the OIG runs through compliance officer responsibilities. None of them require a law degree, and I note that the OIG does not recommend that the compliance officer be a U.S.-qualified lawyer with admission to one state bar in good standing. I can find no reference to legal education being the preferred background for compliance roles by any other authority or this being a recommendation in any other guidance either. So why do so many companies continue to insist on this as a requirement? Compliance is its own field with its own responsibilities that are simply not the same as and sometimes are in conflict with what traditional members of a legal function would be doing.

Impact on compliance programs more broadly

In my view, this section of the guidance has earth-shattering consequences for many companies because it challenges the status quo of many organizational structures, and anecdotally I would suggest that compliance reporting into the GC or the compliance officer being the GC reflects the majority of reporting structures outside of healthcare and life sciences. This brings me to the question: What does this mean, if anything, for companies operating outside of the intended scope of the guidance because they’re not healthcare or life science entities?

Well, obviously, it’s not mandatory for even companies in the relevant target markets to follow the guidance to the letter. However, I would suggest that even for companies outside healthcare and life sciences, it could be considered best practice for their organizations. Guidance from various jurisdictions on effective compliance programs does not wholly overlap, but they all seem to be within the same spirit of each other, and the OIG references the DOJ “Evaluation of Corporate Compliance Programs” and U.S. Sentencing Commission guidelines documents as resources within its guidance, indicating support for other guidance within the same context. 

The DOJ’s corporate compliance guidance makes reference to compliance programs being “adequately resourced and empowered to function effectively.” While we are yet to see lower-level examples and suggestions of what this might mean in practice from the DOJ and what would not be considered adequately resourced and empowered (for example, opining on whether appointing a lawyer from the legal department as CCO without a compliance background would meet this expectation), it is not outside the realm of possibility that if they were to expound upon that expectation, certain similar elements or themes to what the OIG has recommended, might be proposed by the DOJ also. So DOJ, if you’re reading, that’s a section we’d love to hear a representative do a speech about soon!

Summary

While the guidance is not binding, the OIG appears to have come out loud and clear with messaging around recommending that legal and compliance departments be separate and compliance officers focus on “compliance-ing,” not lawyering or other activities that belong to the scope of other departments. 

This guidance will ask many organizations that in some way combine legal and compliance to take a careful and serious look at the status quo of their reporting lines and wider place within the organization, a continuous monitoring and improvement exercise that will no doubt have some folks indignant, others wringing their hands and still others embracing an opportunity for change.


Tags: Health Care
Previous Post

Strange Bedfellows? Internal Audit Function Needs to Make Friends With ESG Metrics

Next Post

AI Regulations Are Coming; How Should Companies Prepare?

Mary Shirley

Mary Shirley

Mary Shirley is a New Zealand-qualified lawyer with 20 years of ethics and compliance experience that includes working for data privacy and antitrust regulators, in-house and private practice/consultancy across five countries and four regions of the world. Currently chief compliance officer at ScionHealth, a large U.S. healthcare system, she's also an adjunct professor in the law schools at George Mason University and Fordham University, along with authoring the bestselling book "Living Your Best Compliance Life: 65 Hacks and Cheat Codes to Level Up Your Ethics and Compliance Program" (CCI Press, 2023). She has been named a Compliance Week Top Mind 2019, Trust Across America 2020 Top Thought Leader in Trust and Excellence in Compliance Awards 2022 Mentor of the Year.

Related Posts

Medical professional enters information into electronic medical record

Navigating HIPAA Compliance in the Cloud: Is Google Workspace the Right Fit?

by Nick Harrahill
August 15, 2023

By 2025, an estimated 85% of enterprises will shift to a cloud-first mindset, while others will adopt a hybrid approach...

pharma

Hard Pill to Swallow: Sorting Out Conflicting Guidance for Pharma Speaker Programs

by Randy Luskey
June 7, 2023

False Claims Act litigation surrounding drugmakers’ speaker programs, often used to educate healthcare professionals about a company’s products, has many...

surgery

Healthcare Price Transparency and Its Market Impact: Where Are We Now and What’s Next?

by Christina Steiner
January 18, 2023

Calls for shedding light on price variability, coupled with an industry that is increasingly consumer-focused, is driving greater examination of...

a man sails into an infographic on a paper airplane

What Healthcare Providers and Life Sciences Companies Can Expect for Enforcement in 2022

by Jaime Jones, Brenna Jenny, Paul Kalb, Raj Pai and Matt Bergs
March 3, 2022

Though the Biden administration's first year kept enforcements light, broad shifts and specific measures taken by regulators are set to...

Next Post
ai generated drawing of legislator examining robot

AI Regulations Are Coming; How Should Companies Prepare?

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights