Guide

The OIG's small-practice guidance: seven elements, right-sized

Summary

A practice of one is not required to run a formal compliance program, but the OIG's 2023 General Compliance Program Guidance scales its seven elements down to your size: written standards, a designated point person (you), training, a way to raise concerns, enforced discipline, auditing, and prompt correction. Right-sized, that means a short policy binder, a periodic self-audit of your own claims, exclusion screening, and a written record when you fix something.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

What compliance program does a small practice need?

No statute orders a solo practice to adopt a specific compliance program, and for most private-pay clinicians one is voluntary. But the OIG's 2023 General Compliance Program Guidance lays out seven elements of an effective program and explicitly scales them to small practices, and OCR and payers increasingly expect to see them 1. The goal is not a binder for its own sake; it is a documented habit of catching your own mistakes before an auditor does.

Think of the program as insurance you build, not paperwork you buy. Each element answers a question an investigator or payer will eventually ask — who was accountable, how did you check your own work, what did you do when you found a problem. A practice that can answer those in writing is in a different posture than one that cannot, regardless of the underlying error.

The seven elements, right-sized for one

The seven elements are the same for a hospital and for you; only the scale changes. For a practice of one, the OIG's small-practice guidance is explicit that the program should fit your resources rather than mimic a health system's 1. The table below maps each element to what it realistically looks like when you are the clinician, the biller, and the compliance officer at once.

ElementWhat it looks like for a practice of one
Written standards of conductA short policy binder — coding, refunds, privacy — you actually follow
Compliance oversightYou are the compliance contact; name yourself in writing
Training and educationAn annual, dated read-through of coding and privacy updates
Lines of communicationA simple way for staff, contractors, or patients to raise a concern
Enforced disciplineWritten consequences that apply even when the only employee is you
Auditing and monitoringA periodic self-audit of a sample of your own claims
Responding to problemsCorrect, refund, and record — with a route to disclose when warranted

The element that earns its keep: auditing your own claims

Of the seven elements, auditing and monitoring is the one that actually catches money before it becomes a false claim. For a solo practice that means pulling a small random sample of your own claims each quarter and checking that the note supports the code, the code matches the service, and the service was medically necessary. Finding and fixing your own error is far cheaper than having a payer extrapolate it across every claim you filed 1.

Keep the method simple: choose the claims by chance, not by comfort, so you are not only reviewing the ones you already trust. Score each against the note, the code, and medical necessity, then write down what you found and what you changed. That written trail is itself an element of the program — proof the monitoring actually happened.

Screening for excluded parties

One monitoring task is not optional if you touch any federal program dollar: exclusion screening. No federal health program payment may be made for items or services furnished by a person the OIG has excluded, so you must check the List of Excluded Individuals and Entities before you hire, contract with, or refer to anyone — and screen yourself and your own vendors on a recurring basis 2. The LEIE is a free public search.

exclusion screening is cheap and its failure mode is expensive: paying an excluded contractor can itself become an overpayment you have to return. Put a recurring calendar reminder on it and keep the dated search results, because the search itself is the proof that you looked 2.

The fraud laws the program is built around

A compliance program exists to keep you clear of three federal fraud laws, and the useful move is to know what each prohibits — not to have anyone bless your specific arrangement. The Anti-Kickback Statute bars paying or receiving anything of value to induce federal-program referrals, with safe harbors that protect defined arrangements when every element is met 3. Stark imposes strict liability on certain physician self-referrals unless an exception fits 4. The False Claims Act penalizes knowingly false claims 5.

Because none of these turns on a rule of thumb, the honest way to test a real arrangement — an office sublease, a marketing deal, a 1099 relationship — is to compare it against the safe-harbor or exception elements in the regulation, and, where a specific deal is genuinely uncertain, to use the OIG's advisory-opinion process, which issues binding opinions on whether an arrangement implicates the Anti-Kickback Statute 6. This is also where the fca and the solo practice meet: a single relator, often a former contractor, can bring a qui tam case, so the program's job is to make sure there is nothing to find.

When your program finds a problem

The seventh element — responding to detected offenses — is what separates a real program from a binder. When a self-audit turns up a miscoded pattern, the response is a sequence: stop the behavior, quantify the affected claims, correct the coding going forward, and refund what was overpaid. A genuine, promptly corrected mistake handled as an overpayment is a fundamentally different posture than the same error left in place once you knew 1.

The same auditable habit pays off across your whole compliance surface. The HIPAA Security Rule's required risk analysis has a free tool sized for small practices — the ONC/OCR Security Risk Assessment Tool — so the analysis is a guided afternoon rather than a consultant's invoice 7. The records that answer a payer audit are the same ones that answer irs audit triggers, and a documented breach-response plan is what turns the small-practice breach from a scramble into a checklist.

Common questions

For most private practices it is voluntary, not mandated by a single statute. But the OIG publishes its seven elements precisely so small practices can adopt them, and payers, Medicare enrollment, and OCR increasingly treat a functioning program as the baseline. Voluntary does not mean optional in practice: an undocumented practice is the one that cannot show it tried to get things right.

Yes, in substance. The oversight element does not require a separate hire; it requires that someone is accountable for compliance in writing. In a practice of one, that someone is you, and naming yourself the compliance contact in your own policies satisfies the element. What matters is that the responsibility is assigned and documented, not that a new title sits on a new person.

There is no fixed legal interval, so treat it as a practice norm: many solo practices pull a small random sample of claims each quarter and review a larger set annually. The point is regularity and a written record, not volume. A handful of claims checked consistently against the note and the code will surface a systematic error long before it compounds into an extrapolated repayment.

Exclusion screening is checking that a person or entity has not been barred from federal health programs before you pay, hire, contract, or refer. Because no federal program will pay for anything an excluded person touches, the obligation is real even for a solo practice. The check is a free public search of the OIG's exclusion list, and screening yourself, any hire, and your billing vendor on a recurring schedule is the safe cadence.

You can, through the OIG's advisory-opinion process, which issues binding opinions on whether a specific arrangement implicates the Anti-Kickback Statute — and all opinions are published. It is the honest alternative to guessing or to having anyone simply declare a deal fine. For most routine arrangements, comparing them against the safe-harbor elements in the regulation, with counsel where the stakes warrant it, is enough.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office of Inspector General (2023). General Compliance Program Guidance. HHS Office of Inspector General (OIG). linkOIG's 2023 General Compliance Program Guidance and its seven elements of an effective compliance program scaled to small practices, plus its framing of AKS, Stark, and the FCA.
  2. 2.HHS Office of Inspector General (2026). Exclusions Program. HHS Office of Inspector General (OIG). linkThat no federal program payment may be made for items or services furnished by an excluded person, and that the LEIE is the public check — the basis for exclusion-screening obligations.
  3. 3.Office of the Federal Register (2026). 42 CFR 1001.952 — Exceptions (Anti-Kickback Safe Harbors). eCFR. linkThe anti-kickback safe-harbor regulation text — the defined arrangements protected when every required element is met.
  4. 4.Centers for Medicare & Medicaid Services (2026). Physician Self-Referral. Centers for Medicare & Medicaid Services (CMS). linkThat the Stark law imposes strict liability on certain physician self-referrals of designated health services unless an exception applies, with CMS the administering agency.
  5. 5.U.S. Department of Justice (2026). The False Claims Act. U.S. Department of Justice. linkThat the FCA penalizes knowingly submitting false claims, that 'knowingly' includes reckless disregard, and that qui tam relators can sue.
  6. 6.HHS Office of Inspector General (2026). Advisory Opinions. HHS Office of Inspector General (OIG). linkThat OIG issues binding advisory opinions on whether a specific arrangement implicates the AKS, and publishes them — the honest way to check an uncertain arrangement.
  7. 7.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC/OCR publish a free Security Risk Assessment tool sized for small practices to conduct the risk analysis the Security Rule requires.

https://www.gale.care/for-providers/fa-compliance-program-seven-elements · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)