Corporate Integrity Agreement: Triggers, OIG Monitoring, and Penalties

A Corporate Integrity Agreement is a five-year contract between a healthcare entity and the U.S. Department of Health and Human Services Office of Inspector General (OIG) that sets out detailed compliance obligations the entity must meet to remain in Medicare, Medicaid, and other federal healthcare programs.1U.S. Department of Health and Human Services. About Corporate Integrity Agreements It almost always accompanies a financial settlement resolving fraud allegations: the entity pays to close the underlying case and then lives under the agreement’s requirements for the next five years.

Why an Entity Signs One

The OIG has authority to exclude individuals and entities from federal healthcare programs for conduct such as submitting false claims, patient abuse, or healthcare fraud convictions.2Office of the Law Revision Counsel. 42 U.S. Code 1320a-7 – Exclusion of Certain Individuals and Entities For most providers, losing access to Medicare and Medicaid reimbursement would end the business. A Corporate Integrity Agreement (CIA) is the alternative. Instead of barring the entity, the OIG negotiates compliance obligations, and in exchange the OIG agrees not to seek exclusion for the settled conduct during the agreement’s term.3Office of Inspector General. Corporate Integrity Agreements

Every CIA runs for five years.3Office of Inspector General. Corporate Integrity Agreements There is no shortened track. The bargain only holds as long as the entity performs; a material breach reopens the door to exclusion.

What Conduct Triggers a CIA

The OIG negotiates CIAs as part of settlements resolving investigations under federal civil false claims statutes.1U.S. Department of Health and Human Services. About Corporate Integrity Agreements The most common path is a False Claims Act case alleging that a healthcare entity submitted fraudulent or inflated claims to Medicare or Medicaid. Cases can originate from government investigations, whistleblower lawsuits, or audits that surface billing irregularities.

The conduct varies. It can include billing for services never provided, upcoding procedures to inflate reimbursement, paying kickbacks for patient referrals, prescribing medically unnecessary treatments, or misrepresenting the qualifications of staff. The common thread is that federal healthcare program dollars were involved and the OIG concluded that continued participation needed safeguards.

What the Entity Has to Do

Each CIA is tailored to the specific fraud that prompted the investigation, but most agreements share a common framework.1U.S. Department of Health and Human Services. About Corporate Integrity Agreements Standard obligations include:

  • Hiring a dedicated compliance officer and forming a compliance committee whose primary focus is overseeing the agreement.
  • Developing written standards of conduct and detailed compliance policies addressing the risks that led to the settlement.
  • Providing comprehensive compliance training, usually annual, for all employees, contractors, and agents who interact with federal healthcare programs.
  • Operating a confidential disclosure program, often a hotline, that lets employees report potential violations without retaliation.
  • Screening all employees and contractors against the OIG’s List of Excluded Individuals and Entities (LEIE) and removing anyone ineligible from roles that touch federal healthcare programs.3Office of Inspector General. Corporate Integrity Agreements

The practical weight is considerable. Entities under CIAs often hire additional compliance staff, invest in new reporting systems, and restructure internal workflows. For large hospital systems or national providers, the compliance infrastructure alone can cost millions of dollars over five years, on top of whatever financial settlement resolved the underlying case.

How the OIG Monitors Compliance

Monitoring is continuous throughout the term, and most of the reporting burden sits with the entity.

Independent Review Organization

Nearly every CIA requires the entity to hire an Independent Review Organization (IRO) at its own expense. The IRO conducts periodic audits, typically reviewing a sample of claims to determine whether billing complies with federal program rules, and reports findings directly to the OIG rather than to the entity’s management.1U.S. Department of Health and Human Services. About Corporate Integrity Agreements

The entity selects its own IRO, but the OIG retains veto power. Most CIAs give the OIG 30 days after receiving written notice of the IRO’s identity to reject the choice. If the OIG later develops concerns about the IRO’s qualifications or independence, it can require the entity to terminate the relationship and hire a replacement.4Office of Inspector General. Corporate Integrity Agreement FAQs

Reporting Obligations

The entity submits an implementation report early in the term and annual reports thereafter, detailing the status of every compliance activity the agreement requires. Beyond scheduled reports, the entity must notify the OIG of certain events as they occur, including the discovery of overpayments to federal programs, reportable compliance events, and any ongoing government investigations or legal proceedings involving the entity.3Office of Inspector General. Corporate Integrity Agreements The OIG also retains direct access rights, so it can conduct on-site inspections or request documents at any time during the term.

What Non-Compliance Costs

CIAs include breach and default provisions with real financial teeth, spelled out in the agreement itself so the entity knows the cost of each type of failure before signing.5U.S. Department of Health and Human Services Office of Inspector General. About Enforcement Actions

Stipulated penalties accrue per day for each unmet obligation. Common tiers in recent CIAs include $2,500 per day for failing to hire a compliance officer, establish required policies, implement training programs, or retain an IRO. Failing to submit required reports also triggers $2,500 per day. Submitting a false certification carries a flat penalty of $50,000 per occurrence. A catch-all provision covers any other CIA violation at $1,000 per day after the entity receives notice and fails to correct the problem within ten days.

Between 2005 and 2017, the OIG imposed monetary penalties under CIAs 41 times, with amounts ranging from $1,000 to more than $3 million and a median of $18,000. During that same period, the OIG excluded four entities from federal healthcare programs entirely for material breaches.6Government Accountability Office. Office of Inspector General’s Use of Agreements to Protect the Integrity of Federal Health Care Programs Exclusion is the outer edge of the penalty range and the reason most entities take the agreement’s requirements seriously from day one.

Individual Providers and Small Practices

When the entity involved is an individual practitioner or a small group practice rather than a large healthcare organization, the OIG uses a lighter-weight version called an Integrity Agreement (IA). An IA serves the same basic purpose, and the obligations are scaled to the size of the practice, so a solo physician won’t face the same committee structure as a hospital chain.4Office of Inspector General. Corporate Integrity Agreement FAQs Both CIAs and IAs are publicly available on the OIG’s website.

What Happens at the End of the Five Years

A CIA closes after the OIG receives and reviews the entity’s final annual report at the end of the five-year term.3Office of Inspector General. Corporate Integrity Agreements Once closed, the formal obligations end and the OIG’s commitment not to seek exclusion based on the original conduct becomes permanent for that settled matter. The OIG has shown a willingness to impose a second CIA on entities that fall back into problematic conduct, which is why most organizations keep much of the compliance infrastructure in place after the agreement expires.