A payer's special investigations unit sent a five-physician family practice a letter in February asking for 30 charts and "a copy of your compliance program." The practice manager forwarded it to us with one line: "Do we have one?" They had a HIPAA binder from 2019, an employee handbook and a good billing team. They did not have a compliance program, and the letter made clear that the payer considered its absence relevant.
That is the moment most small practices start thinking about this, and it is the wrong moment. A compliance program for a small medical practice is not a defense you assemble after a letter arrives. It is a modest set of habits, written down, that lets you find your own billing errors before someone else does and prove that you looked. The Office of Inspector General (OIG), the enforcement arm of the Department of Health and Human Services, has said since its October 5, 2000 guidance for individual and small group physician practices that the program should be scaled to the practice, and its November 6, 2023 General Compliance Program Guidance repeats the point with a section written for small organizations.
This article is what we set up in year one for a practice with two to ten clinicians, element by element, and the folder of documents that exists at the end of it.
Key takeaways
- The seven elements are written policies, a compliance officer, training, open lines of communication, enforced standards, auditing and monitoring, and response to detected problems; a small practice can meet all seven with a part-time compliance officer.
- No federal law currently requires a physician practice to have a program, but an effective one reduces penalties, is asked about by payers and buyers, and is the only way to use the 60-day overpayment rule safely.
- Year one is a calendar, not a binder: a risk assessment in the first quarter, a written code of conduct and five policies by midyear, one baseline audit per clinician, and monthly exclusion screening from month one.
- The documents that prove the program exists are the training log, the screening results, the audit workpapers, the hotline or concern log and the corrective action file, all dated.
- The most common failure is a program written once and never touched again; an undated policy from 2019 is evidence against you.
What a compliance program for a small medical practice actually contains
The OIG's seven elements have been stable for 25 years, with the 2023 guidance sharpening the wording. Here is each one as it looks in a practice with five clinicians and twelve staff, with the minimum evidence for it.
| Element | What it looks like in a small practice | Evidence to keep |
|---|---|---|
| 1. Written policies, procedures and standards of conduct | A two-page code of conduct signed by every employee, plus policies on coding and documentation, overpayment refunds, exclusion screening, gifts and inducements, and reporting concerns | Signed acknowledgments; policies with version dates and an annual review date |
| 2. Compliance officer and oversight | A named person, often the practice manager or a physician owner, with direct access to the owners and a quarterly compliance item at the partner meeting | Appointment memo; meeting minutes with the compliance item |
| 3. Training and education | One hour at hire and one hour a year for all staff; two hours a year of coding and documentation training for clinicians and billers | Training log with date, topic, attendee and materials |
| 4. Open lines of communication | A way to raise a concern that is not the person's direct supervisor: an email box the compliance officer reads, a form, or a vendor hotline; a written non-retaliation statement | Concern log, including "no reports this quarter" entries |
| 5. Enforced standards | The handbook states that compliance violations are disciplinary matters and that consequences apply to owners too; incentives can be as simple as compliance goals in reviews | Disciplinary records where they exist; review templates |
| 6. Auditing, monitoring and risk assessment | An annual written risk assessment; a baseline audit of 10 claims per clinician; monthly exclusion screening; quarterly review of denial and modifier reports | Risk assessment; audit workpapers and findings; screening printouts |
| 7. Responding to detected offenses | A written procedure for what happens when an audit finds an error: quantify, refund within 60 days of identification, retrain, re-audit | Corrective action file with the refund letters and re-audit results |
Read down the third column and you have the folder that answers the payer letter. None of it requires a consultant to produce.
Whether you are required to have one
Section 6401 of the Affordable Care Act, signed March 23, 2010, gave the Secretary of HHS authority to require compliance programs as a condition of Medicare and Medicaid enrollment. CMS has never issued the regulation defining the core elements for physician practices, so as of April 2026 there is no federal mandate. Several states require one for Medicaid providers above a spending threshold, New York being the best-known example, and some Medicaid managed care and commercial contracts contain a compliance program clause, so check your contracts.
The practical reasons matter more than the legal one. The federal sentencing guidelines and the OIG's enforcement approach treat an effective program as a mitigating factor. And the 60-day overpayment rule, which requires a provider to report and return an identified Medicare or Medicaid overpayment within 60 days of identifying it, is only workable when someone is actually looking. The CY 2025 Physician Fee Schedule final rule, effective January 1, 2025, aligned the standard for "identified" with the False Claims Act's knowledge standard and allows up to 180 days to investigate and quantify once you have credible information of a possible overpayment. Those clocks are manageable for a practice that audits routinely.
A realistic first year, quarter by quarter
We plan year one in quarters because a small practice cannot absorb it all at once.
- Months one to three: appoint the compliance officer in writing, start monthly exclusion screening of every employee, clinician, contractor and vendor against the OIG List of Excluded Individuals and Entities (LEIE) and your state Medicaid exclusion list, and write the risk assessment, a two-page list of your top risk areas with a sentence each on why. For most practices: E/M level distribution, modifier 25 use, incident-to billing, time-based codes, credit balances, and any arrangement with a referral source such as a lease or a medical directorship.
- Months four to six: write the code of conduct and the five core policies (coding and documentation, overpayments and refunds, exclusion screening, gifts and inducements, reporting concerns and non-retaliation). Hold the first all-staff training, collect signatures and open the concern channel.
- Months seven to nine: run the baseline audit, 10 paid claims per clinician pulled at random from the last six months, reviewed against the notes by someone other than the person who coded them. Score each claim as correct, over-coded, under-coded or unsupported, and start any refund the same month.
- Months ten to twelve: deliver the audit results to each clinician in a 20-minute meeting, retrain on the findings, hold the annual training, review the concern log and denial trends, and write next year's risk assessment.
A worked example of what the audit finds. A five-clinician practice audits 50 claims. Forty-one are correct, four are under-coded, three are over-coded 99214s with low medical decision making, and two 99214 visits were billed with modifier 25 alongside a joint injection where the note did not support a separately identifiable visit. The five problem claims are refunded, roughly $210 in total to two payers, with a cover letter that cites the internal audit. A small check, and the whole point: a documented finding, a documented refund and a documented retraining, all inside 60 days.
The documents to keep and for how long
We keep the compliance file as one electronic folder with a subfolder per element, and we date every document in the filename. The core set is the appointment memo, the code of conduct and policies with version history, the annual risk assessments, training logs and materials, the dated monthly exclusion screening results, the concern log, the audit workpapers and findings letters, and the corrective action file with refund letters and re-audit results. Keep everything for at least six years, which matches the HIPAA documentation retention period and the False Claims Act's standard limitations period, and keep audit and refund records for ten because the FCA's outer limit runs that long.
Two habits protect the file. First, log the absence of events: a concern log that says "Q1 2026: no concerns reported, channel tested on March 3" proves the channel existed and was monitored. Second, when you find a problem, write down when you first learned of it. That date starts the 60-day clock and is the first thing counsel will ask for.
Where small practices go wrong
The binder problem is the most common. A practice bought a compliance manual in 2019, put a physician's name on the cover as compliance officer, and never opened it again. Under audit, that document is worse than nothing, because it shows the practice knew what it was supposed to do and did not do it.
The second is auditing only what is safe. Practices audit E/M levels because that is what the coding vendor offers, and never look at the lease with the imaging center down the hall, the free lunches from the lab, or the physician who bills incident-to on days she is not in the suite. The 2000 physician practice guidance named four risk areas: coding and billing, reasonable and necessary services, documentation, and improper inducements, kickbacks and self-referrals. The last one is where the large settlements come from, and it needs a lawyer's eyes on your arrangements, not a coder's eyes on your notes.
The third is treating the compliance officer's role as ceremonial. The person needs authority to pull charts, hold a claim, and bring a finding to the owners without going through the physician whose claims are at issue, and that includes the owner. If that conversation is hard, an outside coding and billing audit once a year gives the compliance officer findings that do not depend on office politics, and our compliance basics course covers how to run the internal meetings.
Questions we hear
Can the practice manager be the compliance officer, or does it have to be a physician?
The practice manager is the usual and workable choice, provided the appointment memo gives her direct access to the owners and the authority to hold claims and pull records. The OIG cautions against placing the role with the person who runs billing, because the compliance officer should not audit her own work; if the manager also runs billing, pair her with a physician owner.
How many charts do we need to audit each year?
The 2000 physician practice guidance suggested five to ten records per physician as a reasonable baseline, and that is still what we use: ten paid claims per clinician for the baseline, then five per quarter for anyone whose baseline showed problems and five per year for everyone else. Volume matters less than doing it on a schedule and writing down the results.
We found an overpayment during our audit. Do we refund just those claims?
Not necessarily. Once you have identified an error pattern, the rule expects you to determine its scope, which normally means extending the review across the six-year Medicare look-back period and quantifying the total. A single miscoded claim is a refund. A pattern across a year of claims is a quantification project, and the point at which most practices should involve counsel before sending anything.
What to do this week
- Write a one-paragraph memo naming the compliance officer and describing her authority, and have the owners sign it.
- Run every clinician, employee, contractor and vendor through the OIG LEIE and your state Medicaid exclusion list, save the dated results, and put the monthly recurrence on the calendar.
- Draft the two-page risk assessment for 2026, including every financial arrangement with anyone who refers to you or receives your referrals.
- Create the compliance folder with seven subfolders and move whatever you already have into it, dated.
- Pick the month for the baseline audit and tell the clinicians now that it applies to everyone, owners included.
