CHC UPDATED FINAL PAPER QUESTIONS AND SOLUTIONS
RATED A+
✔✔Federal Sentencing Guidelines - 2004 Amendment Compliance Program
Recommendations - ✔✔1. culture of ethics and compliance
2. defining ethics and compliance standards and procedures
3. spelling out compliance obligations
4. adequate resources
5. clarifying employee screening practices
6. training as an essential element
7. means for anonymous reporting
8. ongoing risk assessments (emphasized)
✔✔Governing Authority (relationship to compliance program) - ✔✔1. Board of Directors
2. knowledgeable about compliance program with reasonable oversight
3. understand program background
4. fully engaged in oversight of the compliance program
5. adopt a resolution (outline duties, commitment to compliance, reporting requirement)
6. responsibility for the plan
✔✔Developing a Compliance Plan (resources) - ✔✔1. OIG Work Plan(*), Advisory
Opinions, Fraud Alerts, Settlements
2. State Attorney General Actions
3. AUSA Settlements/Convictions
4. Medicaid Fraud Units (Communications/Investigations)
5. Department of Managed Health Care
6. Department of Insurance
7. Senate Committee
✔✔Risk Assessment (definition) - ✔✔1. identification of risks
2. determination of the quantitative or qualitative value of risk related to a concrete
situation and a recognized threat (*)
3. basis for other elements of the compliance program
4. goal is the identification, measurement, and prioritization of likely relevant events or
risks that may have a material consequence on ability to meet objectives
✔✔Why conduct a risk assessment? - ✔✔1. Critical activity for the compliance program
development and/or ongoing evolution
2. provides knowledge about culture
3. helps to further define risk intelligence/risk tolerance of an organization
4. increased government scrutiny
5. proactive vs. reactive
6. identify and prioritize risk
7. allocate resources
8. implement corrective action plan
,9. reduce compliance violations
10. decrease potential fines and expenses
11. meet Federal Sentencing Guidelines
✔✔Risk Assessment process - ✔✔identify risk -> analyze/measure risk -> prioritize risk
✔✔What is risk? - ✔✔1. risk = things that might prevent an organization from meeting
an objective
2. the possibility the organization will have lower than anticipated profits or will
experience loss
3. strategic, operational, objective
✔✔Risk Management (definition) - ✔✔identification, assessment and prioritization of
risks followed by coordinated and economical application of resources to minimize,
monitor, and control the probability and/or impact of unfortunate events or maximize
realization of opportunities
✔✔A risk assessment review will... - ✔✔1. reduce the settlement if investigated
2. demonstrate to prosecutors that treble damages are unnecessary (*)
3. demonstrate to the OIG that a corporate integrity agreement is unnecessary or
should be reduced
4. clarify necessary budgeting expenses for compliance
5. prioritize existing compliance resources
6. fulfill your board's compliance oversight responsibility (*)
7. determine whether education has been adequate and whether staff understand
policies and procedures
8. establish whether employees trust and use the anonymous reporting mechanism
9. ensure that reported incidence are resolved
✔✔Things that affect risk - ✔✔1. organizational ethics
2. financial demands
3. technology
4. competition
5. mergers/joint ventures/acquisitions/alliances (*)
6. laws/rules/regulations
7. unknown (things happening in the organization)
✔✔Risk Identification - ✔✔1. interviews (management/staff)
2. document review
3. employee surveys
4. others?
✔✔Management Responsibility Related to Risk - ✔✔1. identify risk (*)
2. implement controls (*) - avoid risk, transfer risk, accept risk, reduce/mitigate risk
,✔✔It is incumbent upon a health system's ______ to provide ethical leadership to the
organization and assure that adequate systems are in place to facilitate ethical and
legal conduct. - ✔✔corporate officers and managers
adequate systems = internal controls (*)
✔✔Code of Conduct (elements) - ✔✔1. keep it real; values based; avoid legalese
2. tailor to organization's culture, ethical attitude, business, and corporate identity (*)
3. get input from focus groups, senior executives, etc. (*)
4. guidance on seeking help and reporting concerns (non retaliation)
5. high-level concepts and key policies
6. scenarios and FAQs
7. clearly stated expectations
8. primary language (watch translations)
9. periodically reviewed
10. emphasis on compliance with all applicable laws and regulations
11. applies to all employees and all representatives
12. plain, concise, and relatively short
13. signed by employees annually
14. training on code provided
15. consistently enforced
16. outlines discipline for noncompliance
✔✔Code of Conduct (definition) - ✔✔define how to behave
✔✔Standards and Procedures - ✔✔1. Structural (risk assessment methodology,
anonymous mechanism and reporting, etc.)
2. Substantive (conflict of interest, privacy, etc.)
3. integrate and compliment other departmental policies and procedures
4. avoid repetition/duplication
✔✔Training and Communication - ✔✔1. mandatory
2. needs to be consistent
3. effectiveness is seen in behavior
✔✔Monitoring and Auditing Plan - ✔✔1. essential for effectiveness
2. based on risk assessment
3. scalable to the organization's risks and resources
✔✔OIG Questions on Audit Plan - Assessing Effectiveness of Compliance Program -
✔✔1. is audit plan re-evaluated annually
2. does audit plan address the proper areas of concern
3. does audit plan include an assessment of billing systems
4. does audit plan clearly establish role of auditors
5. is audit department available to conduct unscheduled reviews
, 6. does mechanism exist to allow compliance to request additional audits/monitoring
should the need arise
7. has hospital evaluated error rates
8. if error rates not decreasing, has hospital conducted further investigation to determine
weakness/deficiencies (* - need to know determine reason for increasing or maintained
high error rate)
9. does audit include review of all billing documentation (including clinical) in support of
claim
✔✔Auditing (*) - ✔✔1. independent/objective (no vested interest) - more independent =
better
2. formalized methodology
3. design established before beginning
4. error rate - 5% threshold
✔✔Monitoring (*) - ✔✔1. management tool usually (compliance usually not part of
monitoring)
2. can be objective but not always
3. easy day to day tool (ex. checklist)
4. not necessarily independent of business unit
5. part of doing business
6. approach may be informal
✔✔When to Audit (*) - ✔✔1. when objective results are needed and integrity is critical
(more objective = more integrity)
2. for cause reviews
3. not-for-cause reviews to assess risk
4. effectiveness of corrective actions
✔✔When to Monitor (*) - ✔✔1. when watching compliance becomes part of daily
operations
2. implementing new rules (*)
3. implementing corrective actions
4. high risk areas between audits
✔✔What is Needed for An Effective Compliance Auditing and Monitoring Plan? - ✔✔1.
understanding of current and applicable business risks and strategies (*) - areas of
focus; include audit/monitor plan for each substantive area
2. appropriate, credible resources - subject matter experts, limited focus, understand
protocols
3. ownership and accountability for resolution at appropriate level
4. follow-up to assure resolutions in place
✔✔Creating/Updating Annual Compliance Audit and Monitoring Plan - ✔✔1. conduct a
risk assessment
2. prioritize risks identified
RATED A+
✔✔Federal Sentencing Guidelines - 2004 Amendment Compliance Program
Recommendations - ✔✔1. culture of ethics and compliance
2. defining ethics and compliance standards and procedures
3. spelling out compliance obligations
4. adequate resources
5. clarifying employee screening practices
6. training as an essential element
7. means for anonymous reporting
8. ongoing risk assessments (emphasized)
✔✔Governing Authority (relationship to compliance program) - ✔✔1. Board of Directors
2. knowledgeable about compliance program with reasonable oversight
3. understand program background
4. fully engaged in oversight of the compliance program
5. adopt a resolution (outline duties, commitment to compliance, reporting requirement)
6. responsibility for the plan
✔✔Developing a Compliance Plan (resources) - ✔✔1. OIG Work Plan(*), Advisory
Opinions, Fraud Alerts, Settlements
2. State Attorney General Actions
3. AUSA Settlements/Convictions
4. Medicaid Fraud Units (Communications/Investigations)
5. Department of Managed Health Care
6. Department of Insurance
7. Senate Committee
✔✔Risk Assessment (definition) - ✔✔1. identification of risks
2. determination of the quantitative or qualitative value of risk related to a concrete
situation and a recognized threat (*)
3. basis for other elements of the compliance program
4. goal is the identification, measurement, and prioritization of likely relevant events or
risks that may have a material consequence on ability to meet objectives
✔✔Why conduct a risk assessment? - ✔✔1. Critical activity for the compliance program
development and/or ongoing evolution
2. provides knowledge about culture
3. helps to further define risk intelligence/risk tolerance of an organization
4. increased government scrutiny
5. proactive vs. reactive
6. identify and prioritize risk
7. allocate resources
8. implement corrective action plan
,9. reduce compliance violations
10. decrease potential fines and expenses
11. meet Federal Sentencing Guidelines
✔✔Risk Assessment process - ✔✔identify risk -> analyze/measure risk -> prioritize risk
✔✔What is risk? - ✔✔1. risk = things that might prevent an organization from meeting
an objective
2. the possibility the organization will have lower than anticipated profits or will
experience loss
3. strategic, operational, objective
✔✔Risk Management (definition) - ✔✔identification, assessment and prioritization of
risks followed by coordinated and economical application of resources to minimize,
monitor, and control the probability and/or impact of unfortunate events or maximize
realization of opportunities
✔✔A risk assessment review will... - ✔✔1. reduce the settlement if investigated
2. demonstrate to prosecutors that treble damages are unnecessary (*)
3. demonstrate to the OIG that a corporate integrity agreement is unnecessary or
should be reduced
4. clarify necessary budgeting expenses for compliance
5. prioritize existing compliance resources
6. fulfill your board's compliance oversight responsibility (*)
7. determine whether education has been adequate and whether staff understand
policies and procedures
8. establish whether employees trust and use the anonymous reporting mechanism
9. ensure that reported incidence are resolved
✔✔Things that affect risk - ✔✔1. organizational ethics
2. financial demands
3. technology
4. competition
5. mergers/joint ventures/acquisitions/alliances (*)
6. laws/rules/regulations
7. unknown (things happening in the organization)
✔✔Risk Identification - ✔✔1. interviews (management/staff)
2. document review
3. employee surveys
4. others?
✔✔Management Responsibility Related to Risk - ✔✔1. identify risk (*)
2. implement controls (*) - avoid risk, transfer risk, accept risk, reduce/mitigate risk
,✔✔It is incumbent upon a health system's ______ to provide ethical leadership to the
organization and assure that adequate systems are in place to facilitate ethical and
legal conduct. - ✔✔corporate officers and managers
adequate systems = internal controls (*)
✔✔Code of Conduct (elements) - ✔✔1. keep it real; values based; avoid legalese
2. tailor to organization's culture, ethical attitude, business, and corporate identity (*)
3. get input from focus groups, senior executives, etc. (*)
4. guidance on seeking help and reporting concerns (non retaliation)
5. high-level concepts and key policies
6. scenarios and FAQs
7. clearly stated expectations
8. primary language (watch translations)
9. periodically reviewed
10. emphasis on compliance with all applicable laws and regulations
11. applies to all employees and all representatives
12. plain, concise, and relatively short
13. signed by employees annually
14. training on code provided
15. consistently enforced
16. outlines discipline for noncompliance
✔✔Code of Conduct (definition) - ✔✔define how to behave
✔✔Standards and Procedures - ✔✔1. Structural (risk assessment methodology,
anonymous mechanism and reporting, etc.)
2. Substantive (conflict of interest, privacy, etc.)
3. integrate and compliment other departmental policies and procedures
4. avoid repetition/duplication
✔✔Training and Communication - ✔✔1. mandatory
2. needs to be consistent
3. effectiveness is seen in behavior
✔✔Monitoring and Auditing Plan - ✔✔1. essential for effectiveness
2. based on risk assessment
3. scalable to the organization's risks and resources
✔✔OIG Questions on Audit Plan - Assessing Effectiveness of Compliance Program -
✔✔1. is audit plan re-evaluated annually
2. does audit plan address the proper areas of concern
3. does audit plan include an assessment of billing systems
4. does audit plan clearly establish role of auditors
5. is audit department available to conduct unscheduled reviews
, 6. does mechanism exist to allow compliance to request additional audits/monitoring
should the need arise
7. has hospital evaluated error rates
8. if error rates not decreasing, has hospital conducted further investigation to determine
weakness/deficiencies (* - need to know determine reason for increasing or maintained
high error rate)
9. does audit include review of all billing documentation (including clinical) in support of
claim
✔✔Auditing (*) - ✔✔1. independent/objective (no vested interest) - more independent =
better
2. formalized methodology
3. design established before beginning
4. error rate - 5% threshold
✔✔Monitoring (*) - ✔✔1. management tool usually (compliance usually not part of
monitoring)
2. can be objective but not always
3. easy day to day tool (ex. checklist)
4. not necessarily independent of business unit
5. part of doing business
6. approach may be informal
✔✔When to Audit (*) - ✔✔1. when objective results are needed and integrity is critical
(more objective = more integrity)
2. for cause reviews
3. not-for-cause reviews to assess risk
4. effectiveness of corrective actions
✔✔When to Monitor (*) - ✔✔1. when watching compliance becomes part of daily
operations
2. implementing new rules (*)
3. implementing corrective actions
4. high risk areas between audits
✔✔What is Needed for An Effective Compliance Auditing and Monitoring Plan? - ✔✔1.
understanding of current and applicable business risks and strategies (*) - areas of
focus; include audit/monitor plan for each substantive area
2. appropriate, credible resources - subject matter experts, limited focus, understand
protocols
3. ownership and accountability for resolution at appropriate level
4. follow-up to assure resolutions in place
✔✔Creating/Updating Annual Compliance Audit and Monitoring Plan - ✔✔1. conduct a
risk assessment
2. prioritize risks identified