Essentials for navigating clinical research compliance in skilled nursing facilities

By Sarah Couture RN, CHC, CHRC, CHPC (Principal at Couture Consulting LLC in Indianapolis, IN.); Katy Wane, JD, MPH, CHC; and Joe Zielinski, JD, CHC, CHPC, CHRC

Originally Posted on: Compliance Cosmos


Clinical research is on the rise in all types of provider organizations. With the promise of new and more effective therapies as well as the strong reputation often associated with organizations performing clinical research, more and more provider organizations—from small urgent care groups to physician practices to post-acute care providers—are pursuing involvement in clinical research. Many skilled nursing facility (SNF) organizations are now involved in clinical research. In many ways, driven out of the recent COVID-19 pandemic that impacted all SNFs, geriatric and long-term care residents are increasingly the subjects of many research studies to advance care. Academic medical centers, pharmaceutical companies, and public health organizations are partnering with SNFs on a wide range of geriatric care and treatment options, including but not limited to, influenza vaccine comparison, COVID-19 treatment, discharge planning, in-home dialysis, quality of life, and public health surveillance studies regarding infectious diseases.

With the increased focus on geriatric medicine from a regulatory, public health, and clinical research compliance perspective, compliance professionals in SNFs must be aware of the potential for clinical research in their organizations. They must take steps to learn more and prepare for research compliance as part of their compliance programs. Because SNF involvement in clinical research is newer, many SNF compliance professionals may not be as familiar with clinical research-specific regulations and other research compliance implications. Of course, the SNF compliance professional will have to align and address research-specific regulations considering the long-term care Requirements of Participation and other relevant SNF compliance implications, including privacy, contracting, quality and equitable care, and survey requirements.

While numerous and complex regulations govern clinical research, this article intends to briefly introduce and ensure the SNF compliance professional is aware of the primary regulatory concepts to allow further study. A tenet of research compliance with historical and practical foundations involves human subject protections rules. While informed consent is essential in every study, it is even more of a concern in the geriatric population related to mental status and the ability and capacity of an individual to provide informed consent. SNFs must ensure compliance with research privacy rules—including but not limited to HIPAA—to protect not only protected health information and patient data privacy rights but also potential biological samples. When investigational drugs or devices are being studied, U.S. Food and Drug Administration regulations apply. Conflicts of interest risks must be managed to ensure appropriate care and safeguard the integrity of the study. The research must be designed and conducted according to good clinical research practice standards. If the study is grant-funded, specific grants management requirements apply. Research billing is a compliance risk area, as items that are promised free to the patient or paid for or provided by the sponsor should not be billed to a payer, whether Medicare, Medicaid, or private insurance. Finally, the biosafety/biosecurity of the investigational item should be prioritized and managed according to informed policy and procedure.

Unique challenges of allowing research in a SNF

There is a wide range of challenges regarding clinical research in a SNF, and this article focuses on the following challenges: (1) external research teams; (2) institutional review board (IRB) approval; (3) informed consent; (4) survey items (care issues); (5) time and resources; (6) charting and documentation; (7) billing and payment; and (8) privacy/data security.

External research teams

In the authors’ experience, most SNFs do not employ clinicians who perform the duties of the principal investigator of a clinical research study. As such, the research performed in SNFs is generally conducted by external research teams, likely from an academic medical center, university, or pharmaceutical or medical device manufacturer. The compliance team should screen external individuals performing research within a SNF to ensure each research team member is appropriately licensed and not excluded, sanctioned, or debarred by any federal or state entity.

IRB approval

The Common Rule requires that an IRB must approve research that meets the definition of human subjects research. A vast majority of academic institutions and academic medical centers have their own IRBs, while most SNFs do not. Commercial IRBs also exist for those investigators who may not be affiliated with an organization with its own IRB.

You should request documentation of IRB approval of the research study. IRB approval is needed for both lower-risk studies, such as those that only involve medical record reviews or surveys/questionnaires, and those that are high-risk, such as research that involves the introduction of an investigational drug, device, or clinical protocol. IRBs perform federal regulatory required tasks when reviewing clinical research, including, but not limited to, determining the requirement of informed consent and conducting a risk/benefit analysis of the study and the proposed study population. Absent IRB approval, the SNF cannot allow the research to occur within its setting.

Informed consent

A simple definition of informed consent for clinical research is a voluntary agreement to participate. In certain circumstances, an IRB may grant a waiver of informed consent. A waiver of informed consent occurs most frequently in low-risk, retrospective, chart-review research studies.

If required by an IRB, a SNF cannot allow research to take place if there is no informed consent. Informed consent in a SNF can be challenging due to the mental capacity of the residents. In addition to what informed consent requires, a SNF should assist the research team in performing an assessment of the resident’s understanding of the consent’s elements. If the residents have sufficient capacity, they can sign with proper education. If the resident lacks capacity, then the researchers will need consent from the resident’s guardian or power of attorney (POA). The SNF can assist the researchers in contacting the appropriate guardian or POA. If none are options, then the researchers will need to obtain court approval for resident participation.

Survey items

There are several possible survey-related risks regarding research in your SNF. Two of the most important are (1) discovery of substandard care and/or inadequate treatment of residents and (2) placebos (residents not actually receiving treatment). There are multiple ways to assess the risk, including but not limited to, IRB review, root cause analysis, a risk assessment, or consulting with the facility’s medical director.

To help minimize the aforementioned risks, a SNF can utilize both internal and external resources. Examples of internal resources include (1) policies and procedures regarding research, (2) quality assurance and performance improvement (QAPI) committee review and monitoring, (3) compliance work plan including auditing and monitoring, and (4) training. External resources include partnering with an IRB and/or with an outside consultant with clinical research expertise.

A way to help protect a SNF and its residents regarding these risks, the SNF should include having a committee or subcommittee that is dedicated to clinical research that is (1) monitoring the risk of outside research and (2) reviewing, approving, and tracking outside research. A SNF can utilize its compliance department and/or QAPI committee to handle this. Generally, outside (or internal research) should be declined when there is a risk related to (1) potential for harm to residents; (2) unequal treatment (e.g., only some residents receive drug(s); and (3) the proposed research would result in a survey tag.[1]

Time and resources

Perhaps the toughest challenge—especially in today’s climate with staffing as challenging as it is—is time. You will need to determine if the SNF has sufficient staff to allow for the proposed research while still providing appropriate and required care for its residents. Further, a SNF must consider the additional time required to complete and document research appropriately. Another item the SNF must determine is who—the SNF or the research sponsor—should be responsible for paying for staff time utilized in research. If the research requires SNF staff to undergo training prior to the start of the study, that time for your staff must also be considered and how that time will be compensated.

Charting

Documentation is a routine challenge in research. You need to determine not just what needs to be charted but where it will be charted, as research records may exist outside the patients’ medical records. Generally, a SNF should document (1) what is being done (care, treatment, therapy, medication, etc.), (2) informed consent, (3) any impacts on the resident (negative or positive), and (4) any change in behaviors (negative or positive).

Beyond ensuring the charting is done appropriately and documented in the correct place, a SNF must determine who (1) is doing the charting, and (2) who is verifying its completeness and accuracy. A SNF’s compliance program or QAPI committee can help by reviewing this information to verify it is sufficient.

Billing/payment

In the authors’ experience, the majority of research coming into SNFs will not include billable services; however, these are things you need to be aware of.

Another crucial issue is clinical research billing/payment. A SNF needs to decide whether the research being done is billable and, if it is, who should pay for it. The core of coverage and decision-making for clinical research billing is found in National Coverage Determination (NCD) 310.1: Routine Costs in Clinical Trials.[2] NCD 310.1 indicates that Medicare covers routine costs in qualifying clinical trials, including care that would be provided outside of the trial, administration of the investigational item, and items and services to prevent, detect, and manage side effects of the investigational item. Medicare does not cover the investigational item itself (unless it is covered outside the study), items and services that are for research purposes only, such as those that are performed solely to collect data, and items and services that are paid for or provided by the sponsor or that are promised free to the patient in the informed consent. Each state that Medicaid also has clinical research coverage rules to consider. A SNF should pay particular attention to how Medicare and Medicaid treat the elements of the research and whether they are considered part of the daily rate and develop controls to ensure appropriate billing. A particular concern would be if the sponsor provided such significant funding related to the study that billing the daily rate would appear to be double billing (i.e., billing Medicare/Medicaid for something you already paid for).

Of course, payments from sponsors should also be considered related to Anti-Kickback Statute risks. Just like all other contractual arrangements between SNFs and vendors and clinical providers, the compensation cannot exceed the fair market value rate for the service provided. Payments that exceed fair market value could be interpreted as an inducement and could also appear as a “pay-to-play” type arrangement. The compliance department should carefully review clinical research budgets in conjunction with finance and revenue cycle team members.

Privacy/security

A potentially overlooked area when allowing research in a SNF is privacy and/or security concerns. A SNF must ensure that any research performed in the facility follows both HIPAA and the Health Information Technology for Economic and Clinical Health Act, along with other federal and state privacy statutes.

There are specific HIPAA requirements related to research. The use and disclosure of protected health information (PHI) for research purposes is only permitted under specific circumstances. A SNF cannot release a resident’s PHI without their authorization—except under limited exceptions outlined in HIPAA. We recommend that the SNF develop a thorough understanding of research privacy regulations and ensure that controls are in place to maintain compliance. In addition to considering privacy concerns, a SNF must also be concerned with data security. If a SNF decides to allow outside researchers to access their electronic medical records or other systems, the SNF must ensure appropriate security controls are in place to protect the data and that agreements are in place before starting the research. A best practice for SNFs is to consult their IT security team and legal counsel to ensure appropriate agreements are in place. Agreements that may need to be drafted include—but are not limited to—data use agreements and business associate agreements.

Practical tips for SNF research compliance

Clinical research in SNFs has become an essential avenue for advancing healthcare in our country. If your SNF is not yet participating in any clinical research studies, there is a good chance that you could be soon. Ensure compliance involvement in leadership and strategy discussions to promote compliance program awareness of potential clinical research strategies and opportunities. Also, research compliance training should be pursued, as it is imperative that the compliance team be well-educated in clinical research concepts. While the seven elements are the same, the risks—as previously discussed—are very specific and nuanced. HCCA offers a Research Compliance Academy twice each year, as well as an annual Research Compliance Conference. Several other organizations and vendors offer webinars and additional training resources specific to clinical research.

If your organization is not yet involved in clinical research, take proactive steps now to understand how you should prepare for clinical research and begin laying the proper foundation for compliant and effective clinical research. If your organization is involved in clinical research or planning to do so very soon, prioritize developing an effective research compliance program that engages operations. Start by educating leadership regarding research compliance risks and the controls needed to promote participant safety, quality of research, and regulatory compliance. This education should combine both formal training, such as a SNF research compliance training session or module, and regular communications at various meetings and via routes such as emails and newsletters. The CITI (Collaborative Institutional Training Initiative) Program is an excellent external resource available to all types of organizations which provides training on a variety of research topics, including research ethics and compliance.[3]

To ensure ongoing engagement, include regular content regarding clinical research compliance in your compliance communication and training plan. As leadership understands the risks and necessary controls, work with them to ensure that operations managers and teams are provided with the right resources to be compliant. These resources include—but are not limited to—policies and procedures and education and training that discuss the risks and instruct teams on what to do and how to operate regarding that risk (see discussion of regulations and risks above). For example, it is vital to have policies and procedures and accompanying education and training for staff regarding human subject protections, such as how to consent to the patient, ongoing monitoring, patient rights, reporting issues, etc. It is also important for operations to perform monitoring to ensure compliance and promote a culture of accountability and transparency. Remember, it is the responsibility of the operations department to develop and implement these controls, and compliance should be a resource that provides as-needed advice to operations. This allows compliance to remain objective so that compliance can perform auditing over time.

Evolve your compliance program to include clinical research risk assessment. Ensure clinical research-related risks are included in the risk assessment and prioritization and that operational leaders and managers overseeing research are involved in the risk assessment process.[4] From there, include high-priority research compliance risks in the compliance work plan. Also, examine your compliance program’s operational engagement strategy, including but not limited to the compliance committee, to ensure clinical research stakeholders are included; a research compliance subcommittee may benefit your organization. Review the code of conduct and compliance policies and procedures to confirm they include research compliance elements. Also, the education and training plan and content should be updated to include research compliance risks. Audits and investigations should be conducted by those who understand the research subject matter, so ensure auditors and investigators are appropriately qualified and/or engage a third-party firm to assist with research compliance-related audits and investigations. In regular reports to leadership and the board of directors, include relevant updates and content regarding research compliance.

Develop an inclusive approach to research compliance that prevents silos and promotes collaboration. The compliance team can help champion communication and partnership between the various areas where research compliance risks exist (i.e., clinical care, pharmacy, billing, IT, etc.) and with legal, HR, and other support functions. As previously discussed, this collaboration may best occur through the research compliance committee and/or other committees that may already exist. Communication, transparency, and collaboration are keys to ensuring the compliant conduct of clinical research.

Compliance can also help leadership promote a culture of compliance and accountability. Be intentional to communicate the availability of the compliance team to be thought partners and report concerns. Engage leaders and managers in their responsibility to encourage transparency, reporting, and nonretaliation. And discuss with leadership the significance of accountability when issues are identified. This helps protect patients, ensures compliance in all risk areas, and communicates that noncompliance will not be tolerated.

Conclusion

The benefits of clinical research in the skilled nursing population are numerous and can significantly contribute to the long-term development of healthcare advances. With the conduct of clinical research also comes numerous regulatory obligations and potential risks to patients. SNFs can best help mitigate these risks and provide research opportunities to patients by ensuring an informed leadership and management team and an effective research compliance strategy and program.

Takeaways

1 This is not a complete list of reasons why outside research (or internal research) should be declined. A skilled nursing facility should consult with its legal counsel to determine when to decline outside research (or internal research).

2 Centers for Medicare & Medicaid Services, “Routine Costs in Clinical Trials,” May 27, 2024, https://www.cms.gov/medicare-coverage-database/view/ncd.aspx?ncdid=1&ncdver=3&bc=0.

3 CITI Program, home page, accessed March 10, 2025, https://about.citiprogram.org/.

4 Sarah M. Couture and Katherine Cohen, “Research is risky business: Effective risk assessments for your research compliance program,” Compliance Today, September 2024, https://compliancecosmos.org/research-risky-business-effective-risk-assessments-your-research-compliance-program.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Effective engagement with outside advisers

By Sarah Couture (Principal at Couture Consulting LLC in Indianapolis, IN.)

Originally Posted on: Compliance Cosmos


Over the course of this calendar year, this column has discussed the importance of and strategies for engaging many different groups of people who impact compliance program effectiveness. From the board and internal stakeholders to vendors and your network of compliance contacts, we have provided a host of pragmatic ways to prioritize engagement in our compliance program efforts. In this final column, we will discuss effective working relationships with outside advisers, including consultants and outside counsel.

Those who have been compliance professionals for more than a brief period know there are times and seasons when securing outside expertise and help is necessary. This may be because an objective viewpoint is needed relative to an audit or investigation or to gain a third-party perspective on the compliance program’s effectiveness. It may also be because the internal compliance team does not have the requisite expertise to perform a specific needed task, such as an audit or investigation that requires skills not found in-house. Outside help may also be sought in times of compliance staffing transitions, whether for interim support or to provide additional fractional staffing for a season. There also may be issues that require outside legal advice and navigational support.

In times when outside expertise is required, there are several keys to ensuring the best outcomes and ensuring effective prevention and detection of fraud, waste, and abuse. First, be up-front with expectations and provide clarity and agreement—in writing—on the scope of what is being asked and the approach the outside adviser will be taking. Ensure there is a method to address and manage additional out-of-scope issues should they arise. Develop a communication plan with the outside adviser, including project milestones, meeting cadence, and how to communicate more urgent concerns that surface between regular touchpoints. Make sure the internal team is available to support the outside work and confirm what level of support will be needed. The internal team will need to provide time, discussion and perspectives, data, documents, etc., and the outside experts may need to accomplish the project objectives in a timely manner. Be transparent with the outside team and encourage your internal team and other stakeholders to be transparent as well. Not being forthright or obscuring information can result in not only inefficiency but also invalid findings or recommendations. Finally, communicate in a timely manner if concerns arise, addressing them before they become more complex.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Engaging the next generation of compliance professionals

By Sarah Couture (Principal at Couture Consulting LLC in Indianapolis, IN.)

Originally Posted on: Compliance Cosmos

While many of us “fell” into compliance after years in other roles, a new generation of compliance professionals is doing something most of us did not: go to school to study compliance. There are undergraduate, graduate, and certificate programs at a variety of universities offering a new generation of compliance professionals a more formal education than what was available for the first generation. While some of these offerings may seem new and different and will certainly keep evolving, they are likely the way that a substantial percentage of future compliance professionals will be trained and enter our compliance programs.

How should compliance programs and compliance professionals respond to compliance students? Our profession needs to invest in the next generation of those interested in healthcare compliance, including those who are in school pursuing compliance-related degrees. This will contribute to the successful evolution of what is still a relatively new profession. Investing in students may also help more seasoned compliance professionals grow and stretch in new ways as we interact with a new generation who may see issues, technology, and methods differently than we do. More immediately, this may help us find our next quality hire, further contributing to the effectiveness of our own compliance programs.

How to connect with and invest in compliance students may not be immediately obvious. Research which schools have graduate and undergraduate compliance degree programs and reach out and ask how you can get involved. There may be very practical ways you can be a resource for students or the programs. Be open to having interns in your compliance program. Not only is an internship an invaluable experience for the student, but it is also a great way to help a compliance program make progress on initiatives for which your team never seems to have enough time to complete. And that intern may be your next great hire! Consider exploring whether there are opportunities to teach and lend your expertise to one of the degree programs. Be willing to mentor compliance students and new graduates, including helping them find their path and first compliance position.

It will take intentionality to invest in the next generation, but there will be payoff for the profession, for your compliance program, and for you and the students with whom you interact.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Mentoring: A Key to Personal and Professional Growth of Compliance Professionals

By Sarah Couture (Principal at Couture Consulting LLC in Indianapolis, IN.)

Originally Posted on: Compliance Cosmos

Most compliance professionals are who and where they are because of a mix of factors: hard work, grit, personality, upbringing, etc. Another significant contributor to each person’s success has very likely been people: those who took a chance on a hire, those who saw something special to be developed in a person, and those who took time to invest in someone coming up behind them. Whether it was done formally or informally, most of us can thank a variety of mentors along the way who helped guide and shape us into the professionals we are today.

Mentoring can be beneficial in multiple ways. It helps individuals—both the mentees and mentors—grow personally and professionally. It allows us to meet, impact, and benefit from others in a unique way that may not have occurred were it not for the mentoring relationship. It allows us to “pay it forward,” investing in others as we were invested in. It helps ensure a strong healthcare compliance profession in the future. And it helps contribute to effective compliance programs by ensuring growth and expanding the proficiency and capability of those who lead, manage, and staff healthcare compliance programs.

Whether you are a mentor, mentee, or both, begin by gaining an understanding of your goals or objectives related to mentorship. What do you need, want to do, and how will you know if it is successful and when it is complete? Seek out potential mentors who can help move toward your goals. This may be someone you have met through the HCCA community, someone who appears to have achieved objectives like yours in your organization, or even someone in a mentoring network. Consider whether a more formal or informal approach makes the most sense based on your objectives and the nature of the personalities and relationships. Decide how often to meet and how to connect, whether over coffee or over a virtual call. Think about what approach and activities can best accomplish your goals. These may include a discussion of specific challenges or obstacles and potential strategies and solutions to address them. It could include reading and discussing specific articles or books. It could involve working through strength and/or personality tests and how the related insights may play into your goals, challenges, and future directions. Ensure there is clear discussion regarding concluding the mentoring relationship and evaluation of the impact it had.[1]

1 Sarah Couture, “Chapter 3: Running an Effective Compliance Program, Complete Healthcare Compliance Manual 2024https://compliancecosmos.org/mentoring-compliance-professionals.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Research is Risky Business: Effective Risk Assessments for Your Research Compliance Program

by Sarah M. Couture and Katherine Cohen

Originally Posted on: Compliance Cosmos

Risk assessment may be somewhat of a buzzword in compliance circles. Compliance officers know their compliance programs should be based on risk, but some may not know where to begin when it comes to developing an approach to risk assessment. The charge is no different for research compliance programs; some risks are very distinct. Clinical research is a risky business, and effective research compliance programs must be based on prioritized risk. This article will explain what a risk assessment is,why it is essential, how to use risk assessment results in the research compliance program, and approaches and considerations in performing a research compliance risk assessment.

What is a risk assessment, and why is it essential?

The U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) defines a risk assessment as “a process for identifying, analyzing, and responding to risk” and as a process that “looks at risk to the organization stemming from violations of law, regulations, or other legal requirements.”[1] Every compliance program will approach their risk assessment differently. The key is to have a defined process that looks at a variety of sources to identify potential risks and uses a consistent methodology to evaluate and prioritize those risks. No compliance team can address every risk for their organization. The risk assessment process allows the organization to ensure they are aware of their risks and have decided how to allocate their resources to address the highest priority risks.

The risk assessment process is a critical component of an effective compliance program. The updated OIG General Compliance Program Guidance lists it as one of the seven elements of an effective compliance program (Element 6 – Risk Assessment, Auditing and Monitoring). Because of this, being able to show your risk assessment process and risk mitigation activities can help decrease or prevent potential consequences in case of enforcement action. It is also a vital tool to help your compliance function and the organization be proactive rather than reactive. Risk assessment is an expected activity for an effective compliance program, but it can also be used to measure effectiveness of your program. The process can help you identify and prioritize risk to best allocate resources towards the highest priority risks. Your risk assessment activities can also help you identify and reduce fraud, waste, abuse, or other compliance risks. One of the most important reasons to prioritize risk assessment is that it can help you engage the operational teams in their compliance responsibilities, foster collaboration between compliance and operations, and form or improve relationships. It is also a vital tool that establishes accountability for those who govern the organization, as the document should be reviewed and approved by your compliance committee and governing board(s).

Performing a research-specific risk assessment in the clinical research setting is also imperative. While all the reasons to complete a risk assessment already listed here also apply to why you should complete a research-specific risk assessment, there are additional reasons to engage in this exercise for your clinical research program. First, research adds an extra layer of rules and regulations that must be complied with and that creates risk for your organization. The risk assessment helps you identify which risks you have based on the specifics of your research program and categorize their priority within the context of your other organizational risks. Engaging in the research risk assessment exercise also communicates to your organization, partners, research sponsors, and research participants that the organization values and takes steps to protect the integrity of research and the individuals who participate in research projects. Ensuring the organization performs research risk assessment is also a way to proactively ensure the appropriate use of federal funding you have received for research and protect your organization’s ability to continue to receive federal funding for those purposes.

What to do with the risk assessment

It is clear that risk assessment is essential to ensure the research compliance program is effective, but once the process is launched, what should the program do with the risk assessment? First—and certainly the goal related to risk assessment that is most commonly discussed—use it to guide your annual research compliance work plan development. The risks that are the highest priority as assessed by the risk assessment are those that the research compliance program should focus on. What kind of audit or evaluation will help you gauge compliance in that risk area? How can you audit to ensure the risk is appropriately controlled? Are sufficient controls like policies, procedures, education and training, and monitoring in place to help manage the risk? How can you “test” the risk area to see if the organization functions compliantly regarding the risk? The work plan outlines what your program will prioritize in the upcoming year. What is significant enough to prioritize while dealing with your day-to-day role? And how many of the highest priority items from the risk assessment should the compliance program include in the work plan? These are questions of resources.

Only include tasks, audits, or evaluations in the work plan that you have staff time and resources to complete. Organizations with small compliance teams may have a small number of risks. It is better to start with fewer work plan items and be able to finish them than to include more than your program can handle and have to explain why the work plan items were not completed. Second, use it to inform your education and training approaches. Educate your board, leaders, and compliance committee on the universe and prioritization of the risks. This is your organization’s research compliance risk profile, and leaders should understand it. Also, use it to evaluate your research compliance education and training plan each year. The risk profile should drive the education and training approach and content, so ensure both annual general research compliance training and risk-based training sessions are updated according to the risk assessment. Third, keep your research compliance program structure, as in how you have built and implemented the seven elements, aligned with the risk profile. At least annually, evaluate your program elements, such as the code of conduct, policies, procedures, etc., according to the risk assessment to ensure they are updated and aligned with the current risk profile. This could be part of your annual assessment of your program’s effectiveness. Finally, ensure the risk assessment itself stays updated. Risk assessment is a dynamic process that should remain updated as the regulatory landscape and our organizations change.

Universal research risks that should be considered in your research risk assessment

Each organization’s risks will vary based on the type of research conducted, the type of funding received, and the resources dedicated to the research operations. A comprehensive research compliance risk assessment should include a review of the primary risks most research organizations face. First, examine research integrity and HHS Office of Research Integrity (ORI) requirements for those that receive federal funding. For issues that trigger the research integrity regulations, review your policy, history of annual reporting, and education of staff. If you have received allegations of falsification, fabrication, or plagiarism, how have those been reviewed, and did your process align with the regulations? Conflict of interest (COI) regulations and rules may vary depending on the funding source of the research you conduct. Evaluate the risks created by multiple COI standards, where you evaluate the potential for COI in research, how you implement management plans, and whether you monitor compliance with those plans. Organizations that receive federal grants should evaluate the processes for complying with the COI requirements for subrecipients. Do not forget about institutional COI (ICOI) when looking at COI risks. If you do not have a separate ICOI policy, how might an unidentified or unmanaged ICOI risk impact your organization? If your organization receives federal research grants, how are the grant and financial compliance risks managed, such as compliance with the uniform guidance and effort reporting obligations?

In human subject research studies, what types of regulations is your organization subject to? Is it only the Common Rule (HHS Office of Human Research Protections (OHRP)), or is it also U.S. Food and Drug Administration (FDA) regulations? Are you conducting other human subjects research with different regulatory requirements? How would your organization address complaints of a research participant? Are those studies required to comply with good clinical practice rules and, if so, how are you monitoring compliance with those requirements? Have you evaluated the privacy risks posed by your research program? Is HIPAA-covered data included in research being conducted, and if so, how? Do other privacy regulations, such as the General Data Protection Regulation or the California Consumer Privacy Act, apply to your research? If there was a privacy incident in the context of a research study, who handles the evaluation of those incidents?

How do you manage the risk involved in that billing process for clinical research studies involving services that can be billed to Medicare or other insurance providers? Are you appropriately identifying the research participants to ensure the billing of services provided is compliant in the context of a research study? Are you completing a coverage analysis and ensuring it aligns with what services you are billing? Do you have a process for putting the proper codes, diagnosis codes, and modifiers on the claims for the research services? Clinical research billing processes often depend on siloed functions working together. How is this process managed to ensure communication across those silos?

For organizations conducting research with animal subjects, does your Institutional Animal Care and Use Committee comply with all applicable requirements? Do you know which animals you have in your facility and the different regulations that might apply to you based on the types of animals you are working with?

Research organizations face risks like biosafety, export control, and data security. This is not intended to be a comprehensive list of risks for research organizations but rather a place to start for those who might be asking themselves where to look for risks within the research program.

Risk assessment considerations: Building your process

The risks discussed above are related to specific research regulations, and each of these risks should have appropriate controls in place. Insufficient controls are a risk in themselves. In addition to the research regulation and related controls risks, there are both external risk factors and internal risk factors that must be overlayed and included in your research compliance risk assessments. External risk factors to consider include recent enforcement actions related to research risk areas, advisory opinions, guidance documents, government reports or updates, OIG Work Plan items, or priorities of other relevant research-related government agencies. Internal factors are those that are specific to the organization. These may include culture-related issues, such as transparency, accountability, and fears of retaliation; specific issues in certain departments; turnover rate of staff in risk areas; results of recent audits—whether conducted internally or externally; an organization’s specific software systems used; and the physical plant and facility, including consideration of how buildings, equipment, security, etc., impact risks. There may be other internal factors to consider at your organization. With some thought, it becomes easy to see how these external and internal factors could impact your risk profiles and why they should be part of your risk assessment considerations.

As the introduction discusses, there is no one way to conduct a compliance risk assessment. The approach should be one that works for the organization and incorporates several concepts: subjective input, objective input, external factors, internal factors, risk tolerance, prioritization, diverse perspectives and collaboration, ongoing evolution, and documentation.

Before you develop a stand-alone research compliance risk assessment, determine if other risk assessments are taking place in the organization, whether general compliance, enterprise risk management (ERM), or otherwise. It will be wise to learn from these approaches and potentially adopt one, tailor it for research risk, and/or collaborate on the risk assessment.

Performing the research compliance risk assessment

As you begin your research compliance risk assessment, start by gaining an understanding of your research portfolio. What kind of research are you doing? Based on the types of research at your institution, what regulations and rules apply to you? What is the maturity of your research program and the research administration/operations infrastructure? Also, engage your research compliance committee in the process. Ensure that they understand both the risk assessment process and their roles in the process. Get their input on your proposed risk assessment approach, including the risk gathering, cataloging, and prioritization process. During regular meetings, keep them informed throughout the process and discuss findings, observations, and recommended pivots. Leverage their perspectives in the draft research compliance work plan that results from the risk assessment.

As you begin to gather risks, start with research leadership. Set up time to discuss their perspectives on the research compliance risk assessment as well as their perspectives on the risk profile. What is top of mind for them? Where are the areas they think you have risk? What keeps them up at night? After gathering risks from leaders, talk to the research operations, finance, and regulatory “doers.” What gaps do they see? What concerns do they have? What do they feel unprepared to handle?

As you gather these subjective perspectives, begin to look for objective evidence of risks. Have there been audits with findings at your organization, such as FDA inspections or billing audits? What data in your research infrastructure can be reviewed to identify potential risks?

Then, evaluate eternal risks. Look at recent enforcement actions—what themes can you draw out? What parallels do you see to your organization? Review ORI, OIG, FDA, and OHRP enforcement and reports. And consider internal specifics that are risks or could impact risks.

As you are gathering the risks, you will be documenting, literally listing, them. Develop a compliance risk tracking tool that can be leveraged for ongoing risk assessment. This can be as simple as a spreadsheet tool developed internally or could be part of your compliance program management software tools. Many tools have been shared in HCCA presentations or on the HCCA.net social site. Explore these options and consider tailoring one that works for you. If this is your first time working on a risk assessment, you’ll likely be surprised at how many risks are mentioned by those you interview and/or survey and that are identified from internal document review and external activity review. Let both your compliance committee members and leaders know that it is very normal to have up to 100 or more risks identified in the risk assessment.

Once the risks are cataloged, it is time to rank them. Ranking the risks is how we get the prioritization. Use your existing ERM prioritization approach, or if one does not exist, develop a methodology to rank the likelihood of each risk happening, the impact each risk could have if uncontrolled, and the sufficiency of any existing mitigation/controls that may be in place around each risk. Many organizations use a 1–5 ranking system, with each number having defined criteria for the likelihood, the impact (1 being lowest likelihood/impact, and 5 being the highest), and the sufficiency of existing controls (1 being no controls, and 5 being sufficient controls). Compliance and risk professionals have shared many tools online that can serve as inspiration. Note that likelihood and impact scores would increase a ranking, while sufficiency of internal controls would decrease a ranking: risk ranking = (likelihood + impact) - mitigation. It is critical to have both compliance and operations and finance perspectives on the ranking, as this provides a balanced outcome. Leverage four to five members of your research compliance committee to separately rank the risks, then average the scores. Ranking the risks for the first time will feel challenging, but the process becomes more natural on subsequent assessments (i.e., in following years). Once the risks are ranked, put them in numerical order. This will display the rankings from highest to lowest and provide the organization with an understanding of its research compliance risk profile.

Then what?

As previously discussed, the risk assessment results will be used to develop the annual research compliance work plan. This work plan becomes a true picture of what the compliance program is doing to evaluate the organization’s highest risks. Present both the risk assessment results and the resulting work plan to the research organization’s governing body. As compliance tests or evaluates the risks and the controls in place, remember that research operations and/or finance develop and implement the corrective action plans to help mitigate the risks. These discussions and activities can be part of the work performed by the research compliance committee.

Keep the risk assessment updated with your research compliance committee. New risks will surface as older risks go from a higher ranking to a lower one as the result of operations’ mitigation activities. On a regular basis, update the overall risk assessment by again gathering perspectives, examining documents and data, and considering outside regulatory activity and internal factors. Because the tools developed for the initial risk assessment will be leveraged, subsequent risk assessments will likely feel less onerous. Keep leadership and the board informed of the changing risk profile and the work compliance that is being done to evaluate the risks and operations and finance mitigation activities.

Developing and performing a risk assessment for the first time is both a significant and rewarding job. The insights it brings to the compliance program, the engagement it fosters with operations and finance, and the organizational risk mitigation will prove that the risk assessment is well worth the effort.

Takeaways

1 U.S. Department of Health and Human Services, Office of Inspector General, General Compliance Program Guidance, November 2023, 55, https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Staying Connected to a Network of Compliance Professionals

Originally Posted on: Compliance Cosmos

Being a compliance professional can be a very lonely experience. Many compliance professionals are in smaller organizations where they are the only team members in the compliance department. Additionally, operations may misunderstand compliance or be siloed from effective working relationships with operations’ leaders and managers. And because compliance professionals can be proverbial “unicorns” in a locale—meaning there may be few to no other healthcare compliance professionals in a town or region—it can be hard to know where to find like-minded colleagues.

Thankfully, some early healthcare compliance professionals in the late 1990s sensed this potential for isolation and desire for community and banded together to form HCCA in 1996. From the pragmatic need at the time—how can we leverage each other to figure out this new thing called compliance?—to today at 19,000 members, HCCA provides a way for us compliance professionals to connect and develop together, ultimately leading to more effective compliance programs. If you are reading this column, you are likely part of this camaraderie that we healthcare compliance professionals have, but are we fully leveraging HCCA and other modes of professional connection to enhance our careers?

Developing a professional network takes time and intentionality, and the payoff is worth it, as it provides thought partners, friends, and potential future job connections, all of which can be especially beneficial for those who work as solo compliance professionals. So, where to start? Explore and utilize HCCA networking resources. From in-person events to virtual networking events to the social platform HCCA.net, HCCA offers many ways to meet and meaningfully connect with other healthcare compliance professionals. Become more active and intentional with social media platforms like LinkedIn. Search for and connect to others where there are commonalities. Post content and comment on other’s posts. Be willing to share your expertise and experience with others in your network; when you need it, they will hopefully do the same. Be intentional with those you do find a significant connection with. Stay connected via email, even try to have lunch when in the same city or at a conference.

Compliance professionals need each other perhaps even more than other disciplines need a professional network. Prioritize making these connections; hopefully, your career and professional effectiveness will grow as your network grows.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Vendor Compliance Engagement

By Sarah Couture (Principal at Couture Consulting LLC in Indianapolis, IN.)

Originally Posted on: Compliance Cosmos

This column has been dedicated to the importance of compliance engagement for those within our organizations. While vendors and other third parties—those external to our organizations yet support our work through provision of supplies and a variety of services—may seem to be outside the circle of those with whom we should effectively engage, government guidance documents discuss the significance of vendor compliance management. Much of our vendor compliance strategy can be implemented through effective compliance engagement with vendors and our operations partners managing vendor relationships.

From the quantity and context of references to vendors and third parties in government guidance documents, it is clear that vendor compliance management should not be an afterthought.[1],[2] We must ensure a robust compliance approach, as vendor relationships carry risks, including, but not limited to, HIPAA Privacy and Security rules, the Anti-Kickback Statute, exclusions, beneficiary inducement, and the False Claims Act.

Consider these keys to ensure effective engagement with vendors and operations areas that manage vendor relationships.

First, prioritize a good working relationship with procurement/supply chain. Developing rapport will promote communication, reporting, and a line of sight with compliance.

Second, an effective vendor management plan must be ensured. Such plans outline provisions for diligence, including exclusion screening and credentials verification, and give compliance a seat at the table regarding vendor compliance concerns. Confirm there are appropriate operations controls, such as policies, training, and monitoring, regarding contract development, evaluation of business needs, fair market valuation, and payment terms. Ensure that the appropriate conflicts of interest process relative to the selection of vendors is in place and functioning. Implement vendor compliance requirements, including providing and requiring attestations related to the code of conduct, relevant policies and procedures such as those related to gifts and business courtesies, privacy and security requirements, and expectations regarding on-site access. Ensure vendors are informed about how to report concerns to compliance.

Third, include vendor compliance in your compliance strategy. This includes, but is not limited to, incorporating vendor and third-party risk in your risk assessment and, as needed, related compliance work plan. Consider auditing and monitoring the presence and sufficiency of controls in place to manage vendor risk. Include relevant vendor compliance content in the compliance education and training plan. Also, ensure procurement/supply chain department representation on your compliance committee.

Finally, keep leadership and the board updated regarding vendor risk, issues, and risk mitigation efforts.

1 HCCA–OIG Compliance Effectiveness Roundtable, Measuring Compliance Program Effectiveness: A Resource Guide, March 27, 2017, https://oig.hhs.gov/documents/toolkits/928/HCCA-OIG-Resource-Guide.pdf.

2 U.S. Department of Justice, Criminal Division, Evaluation of Corporate Compliance Programs, updated March 2023, https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Effectiveness Through Investment in Compliance Program Team Members

By Sarah Couture (Principal at Couture Consulting LLC in Indianapolis, IN.)

Originally Posted on: Compliance Cosmos

In the June 2024 issue of Compliance Today, our column, “Successful engagement and integration of new compliance program staff,” discussed intentional assimilation and development of new compliance professionals and/or those new to our institutions.[1] While a meaningful approach to onboarding newer team members is obviously an essential component of an effective compliance program, it is also important to develop a strategy of ongoing investment in compliance program team members. No one has “arrived”; we all need to keep learning, growing, and developing for our own sake and for the health of our organizations.

Regarding the evaluation of a compliance program’s effectiveness, the U.S. Department of Justice’s Evaluation of Corporate Compliance Programs discusses compliance program staff experience, qualifications, and investment, as well as the turnover rate.[2] An intentional approach to team member growth will not only help promote compliance program effectiveness through having a more qualified team to implement the program but will also help safeguard the program through retention of great talent.[3]

Ensure you have a compliance program people strategy that outlines development goals and investment measures as well as communication approaches. First, make sure there is a clear career progression path for your team members. Communicate this to your team and regularly discuss progress toward goals. Good people are more likely to stay if they can see how they can grow in your organization over time. Second, secure budget money for continuing education and other development opportunities. This resource allocation communicates a commitment to compliance, and the organization values compliance team members. Third, expect, or even require, relevant certifications from your team members that will be beneficial to their specific roles. While all healthcare compliance team members should pursue a general certification like the CHC (Certified in Health Care Compliance), other function-specific or risk-specific compliance roles may benefit from additional certifications related to investigations, auditing, privacy, coding, research, etc. Finally, clear communication regarding team member expectations and performance should be prioritized. Promote transparency and ensure clear communication from the program’s leadership so that team members know what is expected of them. Develop a “clear but kind” communication approach that promotes personal development and team retention.[4] Address concerns in a thoughtful but straightforward way. This approach—rather than avoidance or negativity—promotes team member growth and prevents workarounds and other inefficiencies.

1 Sarah M. Couture, “Successful engagement and integration of new compliance program staff,” Compliance Today, June 2024, https://compliancecosmos.org/successful-engagement-and-integration-new-compliance-program-staff.

2 U.S. Department of Justice, Criminal Division, Evaluation of Corporate Compliance Programs, updated March 2023, https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl.

3 Chauncey Crail, “15 Effective Employee Retention Strategies In 2024,” Forbes Advisor, updated April 30, 2024, https://www.forbes.com/advisor/business/employee-retention-strategies/.

4 Brené Brown, “Clear Is Kind. Unclear Is Unkind,” Brené Brown, October 15, 2018, https://brenebrown.com/articles/2018/10/15/clear-is-kind-unclear-is-unkind/.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Compliance and HR Collaboration Can Drive Effectiveness

by Amanda Bates, MS; Sarah M. Couture, RN, CHC, CHRC, CHPC; and Kasie Ray, CHC, PHR, SHRM-CP

Originally Posted on: Compliance Cosmos

Scenario

It was a crisp fall night in West Texas. Ellen was one hour into her fifth night shift of the week, working overtime for Sandy, who wanted to watch her son’s high school football game. Football is legendary in West Texas, and the community was aflutter that a win tonight would seal their winning season and bode well as they readied for playoffs.

Ellen’s phone started buzzing with texts. Sandy’s son, Ryan, the star running back, had been injured on a tackle. They were taking Ryan off the field on a stretcher and headed for the hospital. All the neighbors wanted Ellen to check on Ryan and let them know if he’d be back next week.

Ellen was busy caring for a first-time mom in the mother–baby unit. Ellen felt bad for Sandy, a friend who was always worried about the rough and tumble of football. Out of concern and expectation, Ellen made a mental note to check the record on break. Two hours later, Ellen read in the electronic medical record that Ryan had a concussion. Ellen sent a text to Sandy expressing her support and asking if Sandy wanted her to do anything.

Unfortunately, situations like this happen in healthcare. Caring healthcare workers, wanting to be helpful, sometimes insert themselves in patient records for which they do not have a clinical or business reason. When these breaches or other issues related to noncompliance occur, successful organizations see the compliance and HR departments working in partnership and lockstep. When collaboration exists, addressing lapses in compliance goes much better. Without collaboration, an unfortunate situation can worsen, causing much more trouble than needed.

Most readers have undoubtedly experienced some version of this scenario. How this breach plays out from organization to organization is largely a function of cooperation, alignment, and shared goals of the compliance and HR functions. This article makes a case for taking the time and effort to build collaborative partnerships between two key departments that can synergistically influence the organization’s culture and compliance mindset.

Collaborative partnership

Compliance and HR are essential strategic functions in every healthcare organization. While each has distinct responsibilities, compliance and HR have significant touchpoints in many areas, including culture, accountability, discipline and enforcement, education, training, communication, investigations, job descriptions, performance evaluations and promotions, incentives, exit interviews, hotline and reporting, and exclusion screening—to name a few.

With so many common areas of focus, it makes sense that compliance and HR should collaborate and that leaders and team members from each department should have strong working relationships. In fact, compliance will be more effective at its primary goal—prevention and detection of fraud, waste, and abuse—as it more successfully works in partnership with HR. The U.S. Department of Health and Human Services Office of Inspector General’s (OIG) Compliance Program Guidance discusses how collaboration drives effectiveness: “Coordination and communication are the compliance officer’s key tools for planning, implementing, and monitoring an effective compliance program. The compliance officer should strive to develop, and the entity should strive to promote, productive working relationships with organizational leaders. Coordinating work and sharing information with leaders of other support functions, including (as applicable), Legal, Internal Audit, IT and Health Information Management (HIM), Human Resources, Quality, Risk Management, and Security will enhance the strength and success of the compliance program.”[1]

However, this meaningful collaboration is not always the case. In some healthcare organizations, compliance and HR function in silos with little or no interaction or communication on what areas of alignment and partnership should be. In other organizations, there may be turf wars, where compliance program leadership and HR leadership do not understand the functional distinctions. One or both may attempt to “own” what the other department should be responsible for.

Success for the effectiveness of the compliance program and HR function—and the organization as a whole—starts with intentionality and a relationship. The following section will describe why compliance and HR should collaborate and how they should work together more productively, and it will provide tips and recommendations for specific areas of cooperation. By improving collaboration, both compliance and HR stand to broaden their influence, mitigate potential risks, and increase their strategic impact within the organization.

Foundation for collaboration

While collaboration between compliance and HR might seem like a matter of common sense, government guidance underscores this expectation. OIG’s Practical Guidance for Health Care Governing Boards on Compliance Oversight discusses the roles and relationships of various functions, including compliance and HR, and the importance of establishing functional boundaries between functions “while also setting an expectation of cooperation and collaboration among those functions.”[2] The expectation of collaboration is not limited to HR and compliance; however, it extends to legal, internal audit, and other departments, emphasizing the importance of a shared framework and definitions around “governance concepts, such as accountability, risk, compliance, auditing, and monitoring.” This guidance indicates that “[t]he compliance function promotes the prevention, detection, and resolution of actions that do not conform to legal, policy, or business standards. This responsibility includes the obligation to develop policies and procedures that provide employees guidance, the creation of incentives to promote employee compliance, the development of plans to improve or sustain compliance, the development of metrics to measure execution (particularly by management) of the program and implementation of corrective actions, and the development of reports and dashboards that help management and the Board evaluate the effectiveness of the program.”

The guidance addresses some key HR focus areas; “[t]he human resources function manages the recruiting, screening, and hiring of employees; coordinates employee benefits; and provides employee training and development opportunities.”

Considerations

There are several distinctions between compliance and HR. The first is regarding how differently each function operates within the organization. HR plays a crucial strategic role in shaping the organization’s culture, utilizing data and people analytics to drive business growth, and developing talent to meet changing needs within the industry. While the strategic component of HR is critical, HR has several primary activities that are more operational than strategic. As the guidance highlights, core HR operations include recruiting employees, managing benefits and compensation, and ensuring training and development. These activities—along with payroll, employee relations, and employee engagement—are undeniably vital for the organization, and HR is primarily responsible for their planning and execution. Compliance, on the other hand, does not perform any operations for the organization. Compliance is by nature independent of operations, so it can be objective in its responsibilities, including investigating and auditing the various functions and operations of the rest of the organization.

Compliance approaches its work by applying the seven elements of an effective compliance program to the organization’s risk profile:[3]

Responding to detected offenses and developing corrective action initiatives, HR utilizes many of the types of elements to achieve its strategic and operational objectives in talent acquisition, employee relations, payroll, compensation, benefits, etc.

Another area of distinction is the kind of risk with which each function is concerned. Compliance is concerned primarily with fraud, waste, and abuse risks arising from healthcare regulations (i.e., compliance with regulations). These include, but are not limited to, the False Claims Act, Anti-Kickback Statute, Stark Law, HIPAA Privacy and Security rules, the exclusion statute, beneficiary inducement, and the Emergency Medical Treatment and Labor Act. HR risks arise out of legal and regulatory mandates governing their operational activities. These include the Fair Labor Standards Act, Americans with Disabilities Act, Family Medical Leave Act, Pregnant Workers Fairness Act, National Labor Relations Act, Equal Employment Opportunities Act, Affirmative Action Planning, Employee Retirement Income Security Act, Title VII of the Civil Rights Act, and more. In addition to these regulatory concerns, HR contends with organizational risks beyond legal requirements, such as employee turnover, development, and organizational culture management. Compliance and HR similarly address many of these risks through education and accountability regarding an organization’s code of conduct and its policies and procedures. While compliance and HR have distinct risk profiles, they leverage their functional expertise to ensure that the organization and its operational leaders effectively manage their relevant risks and work to ensure these risks and their mitigation approaches are understood by both leadership and the board of directors.

Working together

Compliance and HR are distinct functions that help mitigate risk for the organization in different ways. While separate and distinct, the departments should not work in silos, nor should there be disagreement over “turf.” It is critical that HR and compliance understand how each function works differently and capitalize on the areas they can work together to improve their impact on the health and operation of the organization.

As previously discussed and to promote “‘speaking the same language” to leaders and the rest of the organization, it is imperative for HR, compliance, and other control functions to work together on a framework and definitions around these areas of commonality or alignment, including but not limited to, governance concepts, risk, accountability, and auditing and monitoring.[4] Each department will be stronger and work more efficiently and effectively by prioritizing good working relationships and identifying where and how to collaborate. HR and compliance should work together to understand each side’s risks and how the approach to addressing those risks can be aligned.

When HR and compliance are not aligned, it increases risk to the organization. Many of the negative effects appear to be minor, such as duplication of work, missed opportunities to be involved in initiatives or investigations, and inconsistencies in processes. However, when examined more closely, these seemingly minor effects can greatly increase the risk of a compliance issue getting out of hand, as our case in West Texas illustrates. Duplication of work may present conflicting information or guidance between HR and compliance training, policies, or procedures—potentially leading to noncompliance. HR is often the first contact individuals make at an organization and the first contact who comes to mind when employees consider raising concerns. It is important that each leader is aware of the other departments’ general risk profiles and how to identify them. HR should be able to recognize not only clear compliance risks but also the potential downstream effects on organizational compliance from seemingly benign issues. Lastly, inconsistencies in processes—especially when it comes to disciplinary action associated with noncompliance—can undermine the compliance program’s effectiveness.

Start with a conversation about whether your HR and compliance departments collaborate well. Reach out to the HR leader and/or team to start the conversation. Explore the relationship and collaboration to date, noting any barriers or challenges that either group has identified. Discuss what collaboration could look like and how to get there. It may help to discover, even document, where the functional responsibilities lie and where there are areas of touchpoint and potential partnership, such as in a Venn diagram. Decide what the path should look like to more intentional and effective collaboration. This should include deciding on which types of matters collaboration is needed, dividing responsibility for areas of collaboration, and defining ongoing communication, to name a few.

There are many specific areas where HR and compliance overlap and/or have natural touchpoints. In these areas, it is vital that the two functions understand one another, derive roles and responsibilities, and collaborate to ensure both efficiency and ongoing effectiveness.

Culture

Both HR and compliance are concerned with the health of the organization’s culture. Culture starts with top leadership and impacts everything: the way decisions are made, what is prioritized, what behavior is appropriate, and how team members communicate with one another. Healthy organizations focus on ensuring healthy cultures. A healthy culture is one where team members can report issues without fear of retaliation, where leaders promote transparency and open communication, and where individuals are held accountable for their behavior. HR and compliance can help drive the culture of compliance; they can focus on culture in communications and actions and educate leadership about culture. They can also ensure perceptions about the culture are measured via employee surveys and then work together to plan for addressing survey findings.

Written standards, policies, and procedures

While the content of compliance and HR standards may differ, the approach to development, implementation, and communication should be aligned. It is critical not only that policies and procedures are written appropriately but that they are effectively implemented and understood by employees. HR and compliance should ensure there is no confusion about where to find policies, how they are rolled out, or what expectations exist regarding employees utilizing them.

Nonretaliation

Like culture, HR and compliance are active promoters of an organization’s nonretaliation policy through communication, education and training, and discipline and enforcement. Nonretaliation flows from a healthy culture and is imperative to successful compliance program effectiveness. If employees fear retaliation, they are much less likely to report suspected noncompliance, preventing the compliance program from knowing about and investigating the issue. Both HR and compliance must be promoted in word form and then supported in action so that retaliation will not be tolerated.

Reporting

Many reports that come to a compliance hotline/compliance department may not be compliance issues but HR issues. Compliance will need to have a triage process to identify reports that do not seem to have a compliance component and are for HR, then have a process to “hand off” the report to HR for further investigation (or have a process for a dual investigation into an issue with both compliance and HR components). Both departments should have a role in socializing the reporting mechanisms—how to report a concern and what issues should be reported. Communication and transparency are needed to help prevent duplication of effort or omissions and promote healthy collaboration instead of turf issues.

Risk assessment and compliance committee

Compliance should include HR in the ongoing compliance risk assessment process, ensuring that HR perspectives on potential compliance risks and their likelihood and impact are considered. This may be done via interview or survey or could be part of the ongoing work of the compliance committee, where HR should be included in the membership.

Investigations

Both HR and compliance functions conduct investigations. Sometimes, HR and compliance are both involved in an investigation and may work together on interviews, document review, etc., as needed. It is essential that investigators—whether for HR or compliance—have appropriate training, appropriately scope the investigation, and ensure thorough documentation.

Accountability, discipline, and enforcement

As previously mentioned, holding individuals accountable for noncompliant behavior helps preserve the culture of compliance. When individuals are not held accountable, it erodes the culture of compliance, sending the message that noncompliance is not a big deal and/or that certain individuals are above the rules. Accountability is generally carried out through education, monitoring, enforcement, and discipline. Discipline and enforcement are among the seven elements of an effective compliance program, but compliance does not “own” discipline and enforcement; it is HR’s responsibility. Because of this, both HR and compliance must understand their roles regarding discipline and enforcement and prioritize transparency, communication, and respect for one another’s professional perspectives. Compliance should ensure thorough communication to HR regarding noncompliance and may make recommendations to HR regarding discipline and enforcement. Compliance should also confirm the implementation of the disciplinary measures and document them. Based on risk assessment, compliance may perform a review of discipline and enforcement action documentation regarding noncompliance to confirm fairness and consistency. The disciplinary policy should specifically include the potential for discipline for failing to report, discipline for retaliation, and, in concert with the March 2023 updates to the U.S. Department of Justice (DOJ) Evaluation of Corporate Compliance Programs, that bonuses or other financial incentives may be “clawed back” in cases of noncompliance.[5]

Incentives, job descriptions, performance evaluations

While incentives have long been part of the suite of the seven elements canon, the previously mentioned Evaluation of Corporate Compliance Programs put even more emphasis on the importance and expectations of having robust compliance incentives to drive the program’s effectiveness. This may be an area where many healthcare organizations are under-focused, so initiating a fresh and proactive collaboration and working relationship with HR could be a good area. The organization should have a documented approach to compliance incentives. This should start with job descriptions documenting specific compliance expectations that increase with role responsibility. Compliance should also, therefore, be an element of performance evaluations and have a tangible impact on promotions, pay increases, and bonuses. There are other ways to incentivize compliance, including small tokens for achieving compliance milestones (i.e., a department having a 100% education completion by a deadline) and recognizing compliant actions in newsletters and other communications. HR and compliance should work together with leadership to brainstorm, develop, document, and implement the organization’s approach to compliance incentives.

Exit interviews

While HR has traditionally been responsible for exit interviews in most organizations, it has become a best practice for compliance to also have a role. Exiting employees may be willing to share their experiences, including those regarding retaliation, culture, and any potential compliance issues of which they may be aware. Compliance involvement is fundamental for the recognition and exploration of these compliance-specific concerns.

Other considerations

In some smaller organizations, HR and compliance may exist within the same department, often under the leadership of a single individual. While it is crucial to delineate the functions within this integrated department to ensure the proper execution of HR and compliance responsibilities while maintaining the required compliance independence, the collaborative opportunities highlighted earlier in the “Working together“ section may allow for a more effective approach. Another significant consideration is that individuals throughout the organization may not clearly understand each function’s distinct roles and responsibilities, exacerbating the potential risk of missed opportunities to identify the previously discussed issues. Effective communication from leadership—as well as coordinated efforts from both the HR and compliance functions—is imperative. This approach helps define the functions, ensuring that employees and leaders alike are well informed about where to direct specific issues or concerns.

Conclusion

The effort it will take to build a relationship, define distinctions and areas of collaboration, and lay a solid foundation for ongoing collaboration will be worth it. This collaboration will increase both departments’ efficiency and effectiveness. For compliance, it will increase the effectiveness of its ability to prevent and detect fraud, waste, and abuse. Collaboration on culture, reporting and investigations, enforcement and discipline, incentives, and other specific areas will result in better outcomes for each department, the organization, and patients.

If there is currently no working relationship or communication between HR and compliance, or if there have been barriers to working together, start with a conversation. Set up a call to discuss where the departments have been, where they need to go, and how to get there. Spend time getting to know the leaders from HR, how the group functions, and how they may have worked (or struggled) with compliance in the past. Discuss the specific areas where collaboration is essential for the effectiveness of each function, and work on a plan to enhance cooperation and partnership over time. Inform organizational leadership of the plans and progress in collaboration and how it drives effectiveness.

Takeaways

1 U.S. Department of Health and Human Services, Office of Inspector General, General Compliance Program Guidance, November 2023, https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf.

2 U.S. Department of Health and Human Services, Office of Inspector General, Association of Healthcare Internal Auditors, American Health Lawyers Association, Health Care Compliance Association, Practical Guidance for Health Care Governing Boards on Compliance Oversight, Practical Guidance for Health Care Governing Boards on Compliance Oversight, April 2015, https://oig.hhs.gov/documents/root/162/Practical-Guidance-for-Health-Care-Boards-on-Compliance-Oversight.pdf.

3 U.S. Department of Health and Human Services, Office of Inspector General, General Compliance Program Guidance.

4 Practical Guidance for Health Care Governing Boards on Compliance Oversight, Practical Guidance for Health Care Governing Boards on Compliance Oversight.

5 U.S. Department of Justice, Criminal Division, Evaluation of Corporate Compliance Programs, updated March 2023, https://www.justice.gov/criminal-fraud/page/file/937501/download.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)

Successful Engagement and Integration of New Compliance Program Staff

By Sarah Couture (Principal at Couture Consulting LLC in Indianapolis, IN.)

Originally Posted on: Compliance Cosmos

A compliance program can increase effectiveness by intentionally developing compliance program staff. This is especially true for those compliance program staff who are new to our teams and/or who may be new to compliance. When we successfully engage, onboard, and develop our staff, they will be better prepared to perform their roles more quickly and effectively within our compliance programs and organizations. In addition to better implementation of the program, prioritization of new team member engagement and development also contributes to staff retention and satisfaction, further enhancing program effectiveness.

Develop and document an intentional approach for onboarding new compliance team members. Start with an onboarding plan template for consistency. Each personalized plan should first include getting to know the new hire. Where have they been? Where do they want to go? Do they know what they need to get there?

Continue having personal connections with new hires. Depending on the size of the compliance program, this may involve assigning work buddies or mentors to participate (which also helps this person develop) and at least quarterly touchpoints with the chief compliance officer. These regular conversations continue to establish rapport, gauge progress, adjust the development plan, and get feedback on the compliance program and the onboarding approach.

Formulate and implement an onboarding and integration plan based on the person’s experience, new role, and goals. Routinely document the plan and include specific milestones to ensure everyone is on the same page. Expose the new hire to a variety of personnel around the organization. Based on the role, this may include risk area leaders, managers, and/or department team members. Set up introductions where appropriate, and begin inviting the new hires to meetings where they can observe and learn about the players and how the organization works. From the start, involve the new hire in a wide variety of program efforts that are germane to their roles. This will help promote an early understanding of how the compliance program works and how it functions in the organization—balancing the pace of exposure and integration for all new staff, particularly those new to our organization and who may also be new to compliance.

Provide enough work and new experiences to engage and integrate, but not so many as to overwhelm. Prioritize ongoing communication to strike this balance. After onboarding, engage this person to help assimilate a future new hire.

Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)