Skip to content
complianceofficer

Healthcare compliance software for the OIG compliance program and its seven elements

Healthcare compliance software has to carry a program, not a certificate. The seven elements are the structure regulators, prosecutors and monitors all read against, and OIG renamed and reordered them in November 2023. Most vendor pages still list the 1998 version. Complianceofficer holds the register against the current names, maps each element to the policy, training record and audit that satisfies it, and flags the line that moved when OIG, CMS or a state licensure board publishes.

Every claim on this page was read this month from the OIG General Compliance Program Guidance itself and from oig.hhs.gov, not from a vendor summary. Verified 5 August 2026.

Scan your organization's obligations now

Pick healthcare below. The scan returns the register of federal obligations that applies to an organization of your type and size, with the last 12 months of regulatory movement and every source linked. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 36 What the market gets wrong

The seven elements changed in 2023, and most published lists did not

OIG published its General Compliance Program Guidance on 6 November 2023. Section III of that document names the seven elements, and the names are not the ones circulating in training decks and vendor collateral. Two differences are substantive rather than cosmetic, and both change what your software has to hold.

First, enforcement is now Element 5, Enforcing Standards: Consequences and Incentives. The older framing covered discipline only. OIG's text is explicit that incentives belong alongside consequences, saying an organization should establish appropriate consequences for noncompliance as well as incentives for compliance, and that both are important to enforcing compliance. A program that can evidence sanctions but not incentives is answering half of the element.

Second, risk assessment is now inside a named element. Element 6 is Risk Assessment, Auditing, and Monitoring. In the older seven-element lists, risk assessment was an implied prerequisite rather than something you had to show. It is now on the face of the list, which is why an annual audit plan with no documented risk assessment driving its scope is the most common structural gap we see.

The ordering moved too. Enforcement used to sit after auditing in most published lists; in the GCPG it comes before it. If your compliance committee minutes are organized against the old numbering, the mapping to what OIG now expects is not one-to-one.

The seven elements, as OIG words them, and what software has to hold for each

The element names below are OIG's own, from Section III of the General Compliance Program Guidance. The right-hand columns are the practical translation: what an auditor, a monitor or a government counterparty will ask you to produce.

Element OIG's name Evidence it produces Where it usually breaks
1 Written Policies and Procedures Approved versions, effective dates, attestations Code of conduct never re-issued after a merger
2 Compliance Leadership and Oversight Reporting line, board minutes, committee charter Compliance officer reports to the general counsel
3 Training and Education Completion by role, content version, dates One generic course for clinicians and billing alike
4 Effective Lines of Communication and Disclosure Programs Hotline log, intake to closure timeline, anonymity Reports tracked in an inbox with no disposition record
5 Enforcing Standards: Consequences and Incentives Published consequence framework, applied consistently Incentives absent entirely, which is half the element
6 Risk Assessment, Auditing, and Monitoring Dated risk assessment driving a scoped audit plan Audit plan copied forward each year, risk-blind
7 Responding to Detected Offenses and Corrective Action Investigation file, remediation, repayment decision Root cause never closed, so the issue recurs

A longer walk through each element, including how the current names differ from the Federal Sentencing Guidelines version most training decks still use, is in the seven elements of an effective compliance program.

§ 37 Guidance status

Which OIG guidance applies to you, and where to stop reading the old documents

OIG restructured how it publishes compliance guidance. It stated in the GCPG that it will no longer publish updated or new compliance program guidance in the Federal Register, and that all current, updated and new guidance lives on its website instead. That is why searching the Federal Register for current healthcare compliance guidance returns increasingly stale results.

The structure now has two layers. The GCPG applies to everyone in the healthcare industry. On top of it sit Industry Segment-Specific Compliance Program Guidances, tailored to the fraud and abuse risks of one segment. Existing CPGs, some dating to 1998, are archived but remain readable once an ICPG covers their segment.

  • § 01 General Compliance Program Guidance, applies to all 6 November 2023
  • § 02 Nursing Facility ICPG 20 November 2024
  • § 03 Medicare Advantage ICPG 3 February 2026
  • § 04 Segment CPGs from 1998 onward archived on issue
  • § 05 Federal Register as the publication channel no longer used
  • § 06 Further ICPGs, segment by segment expected

The practical consequence for a nursing facility or a Medicare Advantage organization is that two documents govern, not one. The ICPG sits on top of the GCPG rather than replacing it, so a program built only against the segment guidance will be missing the infrastructure chapter, and a program built only against the GCPG will be missing the segment risk areas. Watching for the next ICPG is the same problem as watching any other regulator, which is what regulatory change management software is for.

Healthcare compliance is not HIPAA compliance, and buying as if it were is expensive

A large share of healthcare compliance software budget gets spent on information security tooling because HIPAA is the word everyone knows. HIPAA privacy and security matter, but they are one workstream. The enforcement risk that produces settlements, corporate integrity agreements and exclusions is overwhelmingly fraud and abuse: billing accuracy, referral relationships, and who you are allowed to employ or contract with.

The distinction is easy to test in a demo. Ask whether the platform can hold a monthly exclusion screening record against the OIG List of Excluded Individuals and Entities, tie a physician arrangement to the compensation terms that keep it inside a safe harbor, and show the audit that checked coding accuracy last quarter. Security posture tools do none of those, and none of those are optional.

The right split is usually two systems doing different jobs, not one system doing both badly. Security and privacy work belongs in HIPAA compliance software. The program itself, its policies, training, audits and corrective actions, belongs where the obligation register lives, alongside policy compliance software and audit management software.

§ 38 Who it is for

Who buys this, and what they are actually solving

Health systems and hospitals

Many entities, many state licensure regimes, and a compliance committee that needs one view. The recurring failure is that each facility runs its own policy set, so nobody can answer which version of a rule any given site is operating under.

Medicare Advantage organizations

Now covered by a dedicated ICPG published in February 2026, layered on CMS program requirements and delegated entity oversight. The hard part is evidencing oversight of downstream entities you do not control.

Skilled nursing and long-term care

The first segment OIG addressed, in November 2024, with quality of care treated as a compliance risk rather than a separate discipline. Staffing, infection control and adverse events all land in the compliance register.

Physician groups and MSOs

Referral and compensation arrangements are the dominant risk, and they change whenever the group acquires a practice. Arrangement inventories go stale faster than any other record in healthcare compliance.

Digital health and healthtech

Usually arrive through a security certification and discover fraud and abuse exposure later, often at the first enterprise health system diligence. Both workstreams then have to exist at once.

Payers and TPAs

Multi-state licensure, delegated vendor oversight and claims accuracy in one register. Vendor oversight is the element most often documented as a contract clause and never as a tested control, which is covered on vendor risk management software.

Questions healthcare compliance teams ask

What is healthcare compliance software?

Healthcare compliance software is the system a provider, payer or vendor uses to run the seven elements of a compliance program: policies, leadership, training, reporting channels, enforcement, risk assessment and auditing, and corrective action. It differs from HIPAA tooling because most healthcare compliance risk is billing and referral risk, not information security.

Is a healthcare compliance program required by law?

OIG's guidance is voluntary and non-binding. The pressure is elsewhere: program adequacy shapes settlement terms and corporate integrity agreements, Medicare Advantage organizations face CMS program requirements, and skilled nursing facilities carry a statutory obligation under the Affordable Care Act. Voluntary does not mean optional in practice.

What is the difference between HIPAA compliance and healthcare compliance?

HIPAA compliance covers privacy and security of protected health information under 45 CFR parts 160 and 164. Healthcare compliance is broader and centers on fraud and abuse: the Anti-Kickback Statute, the physician self-referral law, the False Claims Act, exclusion screening and billing accuracy. HIPAA is one workstream inside the program.

How often should a compliance risk assessment be done?

At least annually is the working standard, and OIG now treats risk assessment as part of a named element rather than an optional exercise. The more useful trigger is change: a new service line, payer contract, acquisition or referral relationship shifts the risk profile more than twelve months passing does.

Who should the compliance officer report to?

OIG's guidance is direct that the compliance officer needs authority, stature, access and resources, should be independent of other functions, and should not simultaneously provide legal or financial advice or supervise anyone who does. A compliance officer reporting into the general counsel is the arrangement most often questioned.

How much does healthcare compliance software cost?

Exclusion screening and attestation tools are commonly priced per employee or per provider and land in the low five figures for a mid-sized group. Broad GRC suites used by health systems run from roughly $12,000 to $136,000 a year on recorded purchase data. Full ranges are on compliance software pricing.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.