
By Sarah Couture (Principal at Couture Consulting LLC in Indianapolis, IN.)
Originally Posted on: Compliance Cosmos
This column has been dedicated to the importance of compliance engagement for those within our organizations. While vendors and other third parties—those external to our organizations yet support our work through provision of supplies and a variety of services—may seem to be outside the circle of those with whom we should effectively engage, government guidance documents discuss the significance of vendor compliance management. Much of our vendor compliance strategy can be implemented through effective compliance engagement with vendors and our operations partners managing vendor relationships.
From the quantity and context of references to vendors and third parties in government guidance documents, it is clear that vendor compliance management should not be an afterthought.[1],[2] We must ensure a robust compliance approach, as vendor relationships carry risks, including, but not limited to, HIPAA Privacy and Security rules, the Anti-Kickback Statute, exclusions, beneficiary inducement, and the False Claims Act.
Consider these keys to ensure effective engagement with vendors and operations areas that manage vendor relationships.
First, prioritize a good working relationship with procurement/supply chain. Developing rapport will promote communication, reporting, and a line of sight with compliance.
Second, an effective vendor management plan must be ensured. Such plans outline provisions for diligence, including exclusion screening and credentials verification, and give compliance a seat at the table regarding vendor compliance concerns. Confirm there are appropriate operations controls, such as policies, training, and monitoring, regarding contract development, evaluation of business needs, fair market valuation, and payment terms. Ensure that the appropriate conflicts of interest process relative to the selection of vendors is in place and functioning. Implement vendor compliance requirements, including providing and requiring attestations related to the code of conduct, relevant policies and procedures such as those related to gifts and business courtesies, privacy and security requirements, and expectations regarding on-site access. Ensure vendors are informed about how to report concerns to compliance.
Third, include vendor compliance in your compliance strategy. This includes, but is not limited to, incorporating vendor and third-party risk in your risk assessment and, as needed, related compliance work plan. Consider auditing and monitoring the presence and sufficiency of controls in place to manage vendor risk. Include relevant vendor compliance content in the compliance education and training plan. Also, ensure procurement/supply chain department representation on your compliance committee.
Finally, keep leadership and the board updated regarding vendor risk, issues, and risk mitigation efforts.
1 HCCA–OIG Compliance Effectiveness Roundtable, Measuring Compliance Program Effectiveness: A Resource Guide, March 27, 2017, https://oig.hhs.gov/documents/toolkits/928/HCCA-OIG-Resource-Guide.pdf.
2 U.S. Department of Justice, Criminal Division, Evaluation of Corporate Compliance Programs, updated March 2023, https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl.
Copyright 2024 Compliance Today, a publication of the Health Care Compliance Association (HCCA)