Revenue Cycle Insider

Practice Management:

Design Effective, Ongoing Healthcare Compliance Training, Part 2

Hint: Prioritize sustainability in your approach.

An effective and strong healthcare compliance curriculum is a continuous rather than a one-time occurrence. It starts with onboarding, uses annual training as its foundation, is reinforced throughout the year, and responds quickly when organizational risks change.

The goal of effective compliance training is to ensure that employees understand their responsibilities, recognize common risks, know where to find guidance, and feel safe escalating concerns before they turn into larger problems.

Teach the 4 Core Areas of Risk

The core risk areas affecting any healthcare organization include HIPAA, the False Claims Act, Stark law, and anti-kickback statutes (AKS). While it’s true many other risks should be addressed during training, any robust onboarding program should include these four.

HIPAA education should cover privacy and security. During HIPAA privacy training, you can explain permissible uses of protected health information (PHI), HIPAA’s minimum necessary standard, patient rights, and appropriate access to records. For instance, when it comes to appropriate access to records, address the issues with an employee accessing medical records for themselves or family members. When it comes to the minimum necessary standard, the employee should know about proper disclosure of medical records to payers, other departments within the organization, and even disclosure to law enforcement as the result of a subpoena.

Cropped shot of African American man in blue scrubs keeping records of meeting on clipboard

HIPAA security training should address behavior that protects electronic PHI (ePHI). This would include recognizing phishing scams, using a robust authentication process, reporting suspected and actual incidents, and following procedures for access control. A strong authentication process could include using safe, organization-approved apps to verify the identity of the user, along with best practices for creating strong passwords. Additionally, employees will need to know what to do if they see suspicious emails.

The False Claims Act is a federal law forbidding the knowing submission of false or fraudulent claims to the government. Organizations and individuals violating this law can face stiff penalties, confinement, and a requirement to pay back three times the damage caused by submitting such claims. This law covers issues such as upcoding, unbundling, billing for services not rendered, and/or billing for services not documented. Therefore, training in this area should help employees understand the importance of submitting accurate, well-supported claims to government healthcare programs. For coding and billing teams, training can use scenarios involving unsupported documentation, duplicate claims, cloned notes, incorrect code selection, or failure to report and correct identified errors.

Stark law is a federal civil regulation prohibiting physicians from referring Medicare and Medicaid patients for healthcare services to an entity with which that physician has a financial relationship. This prohibition also covers an immediate family member of the physician. This means that even if the physician does not have a financial relationship with the healthcare entity, but their brother or brother-in-law does, the physician would be in violation if they refer a patient to that relative’s entity. The AKS is a federal criminal law that prohibits the knowing receipt, offering, soliciting, or paying remuneration to induce referrals for services reimbursable by federal healthcare programs such as Medicare.

Education and training programs should clearly distinguish between Stark law and the AKS — they aren’t the same — and should be tailored to the organization’s referral and financial relationship risks. Relevant personnel — physicians for Stark law and all organization members for AKS — should be trained to recognize when things such as physician compensation, ownership interests, gifts, free services, referral incentives, and the like require review. Staff members should be trained to understand that they should not decide complex legal questions independently. All training in these areas should clearly explain to organization employees and staff when and how to escalate concerns of this nature.

Use Scenarios, Not Only Definitions

Compliance concepts are best understood when employees can see how they arise in everyday work situations. A front desk employee might better understand HIPAA through a scenario in which a family member asks for patient information. A coder or biller might better understand coding and billing integrity through a scenario in which documentation does not support a proposed code. A physician liaison might be able to better understand Stark law and AKS using scenarios involving an arrangement with a referral source or an offer from a vendor.

During training, instead of simply asking, “Is this compliant?” scenario-based training allows employees to stop, avoid acting on uncertain arrangements, and contact the appropriate compliance, privacy, security, or legal personnel in the organization. This type of training allows the organization to teach the expected response to these types of situations. The Office of Inspector General (OIG) has long described effective compliance training as more than just a binder of written policies. An organization would do well to consult these OIG resources when designing their own onboarding and ongoing training programs.

Maintain Accountability Through Documentation

Training accountability starts with clear ownership. Supervisors, managers, directors, and leadership within the organization should all be aware of who assigns training and monitors course completion. Follow-up should include things such as keeping track of what’s overdue and providing remedial training when needed. To do this effectively, organizations will want to keep reliable records. Such records should show the employee, the course assigned to them, the topic, completion date, method of delivery, an acknowledgement or attestation that the course was taken, and course assessment results. Documentation provides evidence of an effective compliance program.

It must be noted that course completion alone does not establish comprehension. The organization will need to know that the employees understand and are retaining the required knowledge taught. This is achieved through ongoing short knowledge checks, manager discussions, and audits. When knowledge gaps or repeat errors are identified, corrective education should be prompt, targeted, and documented. As a last resort, when corrective action is needed, this should also be documented with the prior steps taken.

Employees are also responsible for upholding accountability. Employees need to know that reporting a concern is not only a part of their job but is expected. Training should identify the channels available for reporting and resources on how to use such channels in the organization. An organization’s non-retaliation policy should be explained, and examples should be provided illustrating issues worth reporting.

Measure Whether Training Is Working

While training completion reports are useful, organizations will want to go deeper. Training can be evaluated by reviewing course completion rates, the results of knowledge checks, findings on audits, repeat errors, privacy and/or security incidents, and hotline reports, along with employee feedback.

An increase in reports does not necessarily mean the organization is being less compliant. In fact, this should sometimes be viewed as a positive thing. It could indicate that employees have a better understanding of how and when to raise concerns and that they are comfortable doing so. The more meaningful question to ask is: What is the organization doing to investigate and correct the confirmed issues raised? Only then can training and policies be improved.

Alvin R. Cureton, Jr., CPC, COC, CPMA,
AAPC Approved Instructor, Contributing Writer

Other Articles of

October 2026

View All
Subscribe to newsletter