Draft Risk Assessment Policy and Process
In accordance with Office of Inspector General (OIG) Compliance Program Guidance, the U.S. Sentencing Guidelines and in support of the eighth element of an effective compliance program, (Insert name of company) has developed and implemented a centralized risk assessment and internal review process to identify and address risks associated with the Company’s participation in Federal health care programs, including but not limited to the risks associated with the submission of claims for items and services furnished to Medicare and Medicaid program beneficiaries. Annually, Compliance, Internal Audit, Legal and Operations conducts a risk assessment and internal review process that:
-
Identifies and prioritizes risks.
-
Develop internal audit and compliance monitoring work plans related to the identified risk areas.
-
Implements the Internal Audit and Compliance Monitoring work plans.
-
Develop corrective action plans in response to the results of any internal audits or compliance monitoring performed, and
-
Track the implementation of the corrective action plans in order to assess the effectiveness of such plans.
The risk assessment process is conducted during the fourth quarter of the fiscal year and includes:
-
Reviewing the OIG Workplan and Workplan updates for audit areas that are applicable to (Insert name of company).
-
Reviewing OIG Audit results, Corporate Integrity Agreements, Department of Justice settlement agreements, advisory opinions, fraud alerts and other government publications for risk areas that may be applicable to (Insert name of company).
-
Reviewing PEPPER Reports, internal risk scorecards, prior audit results, government audit results, exit interviews, hotline call trends, investigation trends, risk management cases, QAPI, for potential areas to review or follow up.
-
Reviewing regulatory changes and emerging legislation/regulations, such as changes in government payment models or implementation of new regulations, that could impact the organization.
-
Presenting summary of government audit focus areas to Senior Leadership and Operations for consideration during development of the annual Internal Audit Plan and Compliance Monitoring Plan.
-
Conducting a survey of the company’s entities to identify gaps in compliance.
-
Conducting interviews with Senior Leadership and Operations to assess risk concerns.
-
Incorporating areas for consideration such as bad debt, billing and coding, clinical, cost reports, credit balances, clinical research, documentation, excluded providers, quality, finance, privacy and security, Information Technology, marketing, physician transactions (Stark Law), licensure, record retention, reimbursement, regulatory, medical necessity, environmental, facilities, policies, and procedures, staffing, education, and mergers, acquisitions and divestitures, among others.
-
Compiling results of the reviews and interviews and prioritizing or ranking the risks for the next fiscal year using the approach in the Compliance Risk Assessment Scoring Matrix, Exhibit A, and tabulating a score using the Risk Prioritization Scorecard, Exhibit B.
-
Using the results to determine the organization’s appetite for compliance risk and finally prioritizing the risks.
-
Developing the annual Internal Audit Plan and Compliance Monitoring Plan and present to the High Risk Team, Executive Management Compliance Committee (EMCC) and Board of Managers for approval.
-
Implementing the annual Internal Audit Plan and Compliance Monitoring Plan, assessing results and working with leadership to implement corrective action plans.
-
Reporting results from the annual Internal Audit Plan and Compliance Monitoring Plan a minimum of quarterly to the High Risk Team, EMCC and the Board.
-
Following up to ensure the corrective action plans resolved any issues identified.