Conducting a Compliance Audit or Review Key Issues

Similar documents
The Rye Ambulatory Surgery Center, LLC Compliance Plan

Compliance Plans. Kelly S. McIntosh July 20, 2017

The Eight Elements of a Compliance Plan and What Has Changed

SALINAS VALLEY MEMORIAL HEALTHCARE SYSTEM. Compliance Program. March 2018

HCCA Audit & Compliance Conference Fundamentals of Health Care Compliance

Over the last ten years, Congress has appropriated hundreds

River City Medical Group ANTIFRAUD PLAN

5/14/2018. Billing and Revenue Integrity How Do We Effectively Audit or Monitor? Today s Agenda. What We Hear as the Revenue Integrity Program Goal

Triple C Housing, Inc. Compliance Plan

Benchmarking Compliance Programs. Bret S. Bissey, MBA, FACHE, CHC, CMPE, Senior Vice President, Compliance Services, MediTract

Fourth Annual Pharmaceutical Regulatory and Compliance Congress

2. The name of a private person bringing a civil action in the name of the U.S. is. 3. Medicare Part A pays primarily for.

What is Compliance? Compliance Preventative Medicine for Your Practice. Commit to consistency. Commit to correctness. Commit to communication

PRESENTERS OVERVIEW. Richard Kusserow, SMS CEO/Former HHS IG Jillian Bower, MPA, CRC Vice President

Measuring Compliance Program Effectiveness

Compliance Program Effectiveness Guide

Compliance Program Start Up: What are the Basics Needed for your Infrastructure?

Does your organization have a designated Compliance Officer? a. Yes b. No c. Don't know

ACO Compliance Your First Audit is Sooner Than You Think

LIBERTY Dental Plan General Compliance Training

New York State School Boards Association Medicaid Compliance Programs - What Now? March 4, :30 pm 5:00 pm

GUIDELINES. Corporate Compliance. Kenneth D. Gibbs President & Chief Executive. Martin A. Cammer Senior Vice President & Corporate Compliance Officer

2/12/2014. Physician Hospital Integration 1. Physician-Hospital Integration Compliance Considerations. Agenda

European CEI. Compliance 101

PT Solutions Holdings, LLC COMPLIANCE PLAN. The Basis of Our Success

Developmental Delay Rehabilitation Services Inc.

OIG Compliance Requirements for Physicians

Strategies to Build An Effective Compliance and Ethics Program

Compliance & Audit Rocks On

BRONX ACCOUNTABLE HEALTHCARE NETWORK IPA INC., D.B.A. MONTEFIORE ACO PIONEER ACO CORPORATE COMPLIANCE PLAN

Presentation Overview

SAMPLE COMPLIANCE PLAN. Last revised. Sample only for educational purposes/does not constitute legal advice

Today s presentation

2005 OIG Supplemental Compliance Guidance for Hospitals Focus on Culture & Leadership Hospitals with an organizational culture that values compliance

Corporate Compliance Plan JANUARY 2011

IMPLEMENTING NYS MANDATORY COMPLIANCE PROGRAMS A YEAR LATER: OMIG AND PROVIDER PERSPECTIVE. HCCA Annual Compliance Institute April 20, 2009

Vanderheyden s. Corporate Compliance Program

DEPARTMENT(S): REVISION #: POLICY #: ALL SPONSORED BY: PREPARED BY: APPROVED BY: DATE ISSUED: EFFECTIVE: DSRIP Compliance Policy Page 1 of 5

A COMPLIANCE SOLUTION DESIGNED TO HELP PLANS MEET CMS REQUIREMENTS

Implementing a Compliance Monitoring Program. January 29, 2014

Contract and Procurement Fraud. Detection and Prevention

SHRINERS HOSPITALS FOR CHILDREN CORPORATE COMPLIANCE PLAN

Anti-Fraud Programs and Control Policy

Medicare Compliance and Fraud, Waste and Abuse Detection and Prevention Program

Presentation Overview

THE ARCG CHARTER. Issued in March 2008

FIRST TIER, DOWNSTREAM AND RELATED ENTITY (FDR) COMPLIANCE GUIDE

Large Hospital Systems

Large Hospital Systems

TACKLING HEALTH CARE FRAUD, WASTE, AND ABUSE WHERE DO YOU START?

HCCA AUDIT & COMPLIANCE COMMITTEE CONFERENCE

Compliance Effectiveness Strategies HOW TO SUCCEED AS A COMPLIANCE PROFESSIONAL

Discussion Goals. Compliance Effectiveness Strategies HOW TO SUCCEED AS A COMPLIANCE PROFESSIONAL. Federal Sentencing Guidelines 3/16/2016

TEACHERS RETIREMENT BOARD. AUDITS AND RISK MANAGEMENT COMMITTEE Item Number: 9 SUBJECT: Scope and Structure of the Enterprise Compliance Program

Effective Physician Contracting: Understanding the Relationships Between Finance, Operations, and Compliance

First Tier, Downstream and Related Entities (FDR) Medicare Compliance Program Guide

Strategies For Better Positioning Your Company To Do Business With The Federal Government

Corporate Compliance Plan

2016 Compliance Program Passport Advantage

Anthony M. Tocco CCEP, CIA, CFE Chief Compliance Officer DTE Energy

The following topics will be covered in this course: 1) Don t let pressure influence ethics and reasoning 2) Be careful about rationalizations 3)

Compliance Code Conduct

Long Island Association for AIDS Care, Inc. Corporate Compliance Plan

HAMASPIK OF ROCKLAND COUNTY, INC. CORPORATE COMPLIANCE PLAN JANUARY 2011

Enterprise Research Risk

Compliance Program Requirements for Medicare Advantage First Tier, Downstream or Related Entities (FDRs), Annual Attestation and Disclosure Statement

Compliance in 2016: Navigating the New Expectations

A. Establish compliance standards and system-wide policies and procedures;

2016 Medicare-Medicaid Plan Compliance Plan

Report on Compliance and Ethics

Delta Dental of Michigan, Ohio, and Indiana. Compliance Plan

Effective Compliance Programs How Does Your Program Measure Up?

MEDICARE COMPLIANCE PLAN & PROGRAM POLICIES

University of Florida, Pediatric Integrated Care System. Compliance Program. Policy: Ped-I-Care Program Integrity Plan Number: CD-0003

Verifying Compliance Program Effectiveness in Managed Care

NEXT GENERATION COMPLIANCE: HOW METRICS SHOULD DRIVE YOUR COMPLIANCE AND ETHICS PROGRAM

Blockbuster Compliance Trainings: Reaching Your Audience Without Knocking Them Out Cold

The New Era of Transparent Internal Audit: What You Should Know

Compliance Risk Management

NYSARC/CP Compliance Seminar: Risk Assessments. May 2, 2016 Robert Hussar and Melissa Zambri

In Place; No Changes Recommended DRAFT

ESTERLINE ANTI-CORRUPTION PROGRAM CHARTER

ATTACHMENT C CORPORATE COMPLIANCE PROGRAM

BUILDING AN EFFECTIVE COMPLIANCE PROGRAM

DRAFTING AN COMMUNICATING EFFECTIVE POLICIES AND PROCEDURES AGENDA

IIA ACFE Conference April 17, 2015

American Academy of Orthopaedic Surgeons 2010 Annual Meeting

Physician Compliance Program

Appendix A. Simplified Sample Entity-Level Control Matrices

Best Practices for Overseeing an Internal Audit

The Company seeks to comply with both the letter and spirit of the laws and regulations in all countries in which it operates.

3/16/2016. In this mornings session, we will discuss: Developing the Framework for your Compliance Program Policies & Procedures

Leveraging Internal Audit and Corporate Compliance for Effective Risk Management

THE GULF COAST CENTER CORPORATE COMPLIANCE PLAN

Outdated and/or Ineffective Laws and Regulations. Jane Thorpe, J.D. Milken Institute School of Public Health George Washington University

Managing Compliance Risk in M&A, and Special Considerations for Joint Ventures

convercent Sample Board Report* Ethics & Compliance Program Update

Consent Item (D) Washington Metropolitan Area Transit Authority Board Action/Information Summary

SUNRISE TELECOM CODE OF BUSINESS CONDUCT AND ETHICS Overview Sunrise Telecom is committed to its customers, partners, employees and stockholders.

CORPORATE COMPLIANCE PLAN

Transcription:

Conducting a Compliance Audit or Review Key Issues Prepared By: Ethan E. Rii, Esq. Partner Katten Muchin Rosenman LLP ethan.rii@kattenlaw.com Do you have an effective compliance program? Competitive advantages Establish reputational advantages Address auditor concerns Avoids fear that can chill creativity Reduces likelihood of legal violations Avoids compliance hurdles to transactions May reduce penalties/avoid CIA in the event of a Government investigation Minimizes institutional risk and avoids adverse PR 1 Challenges to Establishing an Effective Compliance Program Limited resources Ineffective and infrequent compliance education Embedding compliance within the business culture Getting the business to own compliance Tone at the middle/manager buy in Inadequate commitment to auditing/internal reviews Lack of clear communications channels 2 1

Typical Compliance Pitfalls Policies too complicated and theoretical Lack of policies in relevant and applicable risk areas (e.g., non-monetary compensation; response to government inquiries; bundled contracts) Inadequate internal controls to ensure policies are followed Early involvement of Legal/Compliance when issues or need for guidance arises Failure to involve the business in compliance policy development, implementation and education 3 Recent Legal Changes Sunshine Act Updated Foreign Corrupt Practices Act (FCPA) guidance False Claims Act (FCA) changes 60-day rule for reporting and refunding identified overpayments HITECH Act 4 Need for Compliance Gap Analysis Health care reforms create new compliance risks for health care providers and life science companies Statutory changes provide new tools and additional resources to investigate and prosecute health care fraud & abuse, while making violations easier to prove Increased focus on physician relationships Advent of RAC, HEAT and other audit and enforcement initiatives 5 2

Legal Areas to Consider State and Federal False Claims Acts Billing, Coding and Documentation Requirements Anti-Kickback Statute Stark Act Licensing and Medicare/Medicaid Requirements Tax Exemption Considerations FCPA FDA Sunshine Act 6 Areas of Compliance Review Compliance program infrastructure Channels for communicating compliance issues and seeking guidance Compliance education Auditing/monitoring function Billing/coding function coding Licensing requirements 7 Areas of Compliance Review (cont d) Medicare/Medicaid participation, payment and performance standards Medical record documentation Marketing FCPA issues Physician financial relationships Interplay among quality, UM, billing and compliance functions 8 3

Road Map for Compliance Review Step 1 - Kickoff teleconference to define project scope, objectives and content/timing of deliverables Step 2 Issue work plan and information request Step 3 Review compliance plan, policies and other documents provided in response to information request Step 4 Conduct focus group interviews of key client Compliance and Legal representatives and leadership Step 5 Deliver draft report identifying gaps from regulatory/ best practice standards and recommendations to fill gaps Step 6 Vet preliminary report with Compliance and Legal. Step 7 Revise report and draft executive summary Step 8 Present findings and recommendations to Board or Audit Committee 9 Questions to Consider Does the organization have an effective compliance function that: Minimizes enterprise risk by promoting compliance with applicable legal parameters? Enables the organization to proactively identify and address any compliance issues that arise? Is there reason to believe that the organization faces material compliance exposure in any regulatory risk area? 10 Elements of an Effective Compliance Plan Written standards of conduct, policies and procedures that promote the health system s commitment to compliance Designation of a Compliance Officer and other appropriate compliance infrastructure Training and education Effective lines of communication Auditing and monitoring Enforcement of disciplinary standards through well publicized guidelines Prompt and appropriate response to suspected non-compliance 11 4

Key Recommendations Establish communication protocols and policies to consistently address the billing/compliance implications of quality and regulatory issues in a manner that minimizes both False Claims Act and malpractice exposure Upgrade policies, tools and educational programs on physician transactions to arm leaders with knowledge of what they can do, as well as what they cannot do Require business ownership of all policies Develop internal controls to guard against violation of scope of practice and scope of authority parameters Develop contract tracking mechanisms 12 Key Recommendations Institute a rapid response protocol to address Government inquiries Develop and implement an annual compliance education plan identifying the curriculum, target audience, format and teaching methodology for programs that proactively focus on topics that minimize enterprise risk Create more effective channels of communication to assure awareness of compliance policy changes, legal developments and potential compliance issues Make sure that sound auditing/monitoring plan and investigation protocols are in place to address all risk areas Shift from retrospective to concurrent auditing in known risk areas 13 Gap Analysis Follow Up Identify and prioritize recommendations for implementation Develop work plan to effectuate recommendations Solicit leadership team input on recommendations and work plan Implement work plan, including policy, protocol, and process revisions to improve compliance plan effectiveness Educate workforce on compliance program changes 14 5

Steps to Compliance Written Standards of Conduct, Policies and Procedures Document compliance expectations Aligned with regulatory guidance Code of Conduct Compliance program documents Up-to-date policies and procedures addressing risk areas Proof of distribution to employees and FDRs Employee/contractor certifications/acknowledgements Vendor credentialing and certifications Policy or statement of non-intimidation and non-retaliation Establish schedule for and track periodic updates 15 Steps to Compliance Oversight/ Appropriate Compliance Infrastructure Compliance Committee charters, agendas and minutes Updates to CEO on program status and issues Periodic Board updates, agendas and minutes. Ability for Compliance Officer to make in-person reports to CEO and Board Org Charts to demonstrate reporting structure Job descriptions Be ready to answer auditor questions when interviewed 16 Steps to Compliance Training and Education Annual compliance education plan/curriculum All employees educated within 30 days of hire and at least annually thereafter Retain training materials, agendas, sign-in sheets Use and document scenario-based training whenever practicable Methods to track completion and follow-up Track all training Job-specific Ad-hoc training/coaching Third party conferences Completion of electronic modules Document methods to determine effectiveness of training (e.g., tests, surveys, post-training discussions) Compliance training as a documented element of performance reviews 17 6

Steps to Compliance Create Open Communication Channels Multiple, well-publicized communication channels available to employees, Board and FDRs Anonymous reporting option available Reporting channels posted in employee areas and on intranet Code of Conduct requires reporting of concerns Code also encourages employees/contractors to seek compliance guidance prior to taking action when they are unclear on compliance parameters System to track reports and follow up Policy or statement of non-retaliation Documented hotline testing Email blasts, newsletters and other forms of information exchange on compliance issues and developments Compliance officer feedback to management on compliance risk areas 18 Steps to Compliance Auditing and Monitoring Risk assessments Annual work plans and progress tracking Auditing and monitoring results shared with Compliance Officer, CEO, Board, Compliance Committee and key managers Work plans for follow up on adverse audit results Annual audit of compliance program effectiveness Monthly review of sanctions and exclusions Data analysis to identify fraud, waste and abuse List of auditing and monitoring activities, frequency, systems used Process to audit and monitor FDRs Document coordination with other areas (Internal Audit, Compliance, Business owners, Special Investigation Unit, etc.) 19 Steps to Compliance Enforcement Policies and procedures have clear, specific disciplinary standards Timely and consistent enforcement Provide examples of non-compliant conduct Retention of records Track so it can be trended or reported Management team accountability for foreseeable compliance failures of subordinates 20 7

Steps to Compliance Rapid Response to Suspected Non-Compliance Investigation protocols Document holds Investigation steps are logged and well documented Retain documentation of interviews and documents reviewed Segregate privileged materials Identify root cause of issues Corrective action plans designed to correct and prevent future occurrences Assessments of corrective action plan effectiveness/lack of repeat issues Policy revisions and education to prevent recurrence of non-compliant behavior Reports to government authorities when required or deemed appropriate Referrals to law enforcement or other agencies 21 Practical Decision Points to Consider Scope of review Frequency and number of reviews to be conducted Criteria for review (e.g., divisions, departments, entire organization) Potential use of sampling methodology Process for conducting reviews Who will conduct review Legal/Compliance Outside Counsel Combination Use of results of review Topics of discussion Suggest or require process improvements/remediation Tangible steps Change in business operations Other 22 Katten s Perspective on Compliance National health care practice representing health systems, hospitals, large physician groups, ancillary service providers, health plans and life science companies Our perspective on compliance program effectiveness is informed by our experience: Representing clients in internal investigations, government investigations and qui tam suits Negotiating and navigating settlement agreements, corporate integrity agreements and deferred prosecution agreements Counseling clients through self-reporting options Developing and updating compliance plans and policies Participating in compliance education programs Conducting compliance program effectiveness reviews 23 8

Questions? 24 9