The Role of Compliance Officers in HHS OIG Regulations
The role of compliance officers in HHS OIG regulations is to ensure policies and procedures are in place to mitigate the risk of a healthcare organization violating a law protecting HHS programs and beneficiaries from fraud or abuse. It is also the role of compliance officers in HHS OIG regulations to monitor compliance with the policies and procedures, and to enforce sanctions on workforce members when they fail to comply with the policies and procedures. While this explanation of the role of compliance officers in HHS OIG regulations may sound complicated, it is not as difficult as it seems. There are usually only five healthcare regulations enforced by the Department of Health and Human Services’ (HHS) Office of Inspector General (OIG) – these being: The False Claims Act The Anti-Kickback Regulations The Physician Self-Referral Law The HHS OIG Exclusion Statute The Emergency Medical Treatment and Active Labor Act (EMTALA) The False Claims Act The False Claims Act protects HHS programs from being fraudulently charged for medical items or services. It is an offense to submit any...
Patient Confidentiality and HIPAA
Patient confidentiality and HIPAA compliance are not the same thing because although one of the primary goals of HIPAA is to protect individually identifiable health information from impermissible disclosures and unauthorized access, confidential patient information consists of more than just health information. One of the most common misconceptions about patient confidentiality and HIPAA compliance is that all patient information is automatically protected by HIPAA. It’s not. HIPAA automatically protects a patient’s health information, treatment information, and payment information. Any other information that could be used to identity the patient is only protected by HIPAA when it is maintained in the same data set as Protected Health Information (PHI). In many cases, non-health information is maintained in the same data set as patients’ PHI. But there are plenty of exceptions. If, for example, a healthcare provider maintains a separate database of names, ages, genders, and email addresses for marketing purposes, the information could be considered confidential. However, because...
LockBit Affiliate Sentenced to 4 Years in Jail and Ordered to Pay $860,000 in Restitution
An affiliate of the notorious LockBit ransomware group has been sentenced in Canada to almost four years in jail and has been ordered to pay more than $860,000 in restitution. Mikhail Vasiliev, 34, is a Russian-Canadian national who was born in Moscow and moved to Canada more than 20 years ago. During the COVID-19 pandemic, Vasiliev became an affiliate of the LockBit ransomware operation, one of the most prolific ransomware-as-a-service groups over the past few years. Around 18 months ago, Vasiliev was arrested following a raid of his home in Bradford, Ontario. The search of his property uncovered a list of prospective and historical victims, instructions on how to deploy LockBit ransomware, the source code of the ransomware, the control panel used to deliver the ransomware, and screenshots of conversations with a core member of the LockBit Group – LockBitSupp – on the Tox messaging platform. Vasiliev admitted to being an affiliate of the LockBit group between 2021 and 2022 and having conducted attacks on businesses in Saskatchewan, Montreal, and Newfoundland, from whom...
HHS-OIG: Pennsylvania Improperly Claimed $551 Million in Medicaid Funds
Audits conducted by the Department of Health and Human Services Office of Inspector General (HHS-OIG) of states that claim Medicaid school-based costs with the assistance of contractors have revealed some states have claimed unallowable federal funds due to their contractors improperly conducting random moment time studies (RMTSs). Pennsylvania is the latest state to be audited by HHS-OIG, which found that approximately $590 million was claimed in federal Medicaid payments for school-based services between July 1, 2015, and June 30, 2019, $551.4 million of which was improperly claimed. For the audit, HHS-OIG reviewed a stratified random sample of 310 random moments, each of which was coded as a health service or administrative activity. HHS-OIG also looked at the methods Pennsylvania used to allocate health services costs to Medicaid. Based on the sample, HHS-OIG estimated that Pennsylvania claimed $182.5 million in unallowable Federal funds because it did not support that all moments used in RMTSs and coded as Medicaid-eligible were actually for Medicaid-eligible health services...
What is an HHS OIG Compliance Program?
An HHS OIG compliance program consists of best practices that should be included in an integrated healthcare compliance program to avoid violating fraud and abuse laws enforced by the Department of Health and Human Service (HHS) Office of Inspector General (OIG). Adding HHS OIG compliance best practices to an integrated program not only helps avoid penalties for HHS OIG compliance failures, but may also improve compliance with the integrated program. The best way to run your HHS OIC compliance program is with specially designed software designed for compliance officers. Integrated healthcare compliance programs are programs that combine some or all applicable healthcare rules, regulations, and standards into a single compliance program. For example, a healthcare facility might combine CMS’ Emergency Preparedness Rule (81 FR 63860) with OSHA’s Emergency Planning Regulation (§1910.38) and HIPAA’s Contingency Plan Standard (§164.308(a)(7)) to comply with all three requirements via a single activity. Although integrated healthcare compliance programs can be complicated to develop and...



