
If you run a healthcare organization, you likely already have a compliance program: written policies, a designated compliance officer, training, a hotline. That's a good start. But both the Department of Justice (DOJ) and the HHS Office of Inspector General (OIG) have made clear that having a program on paper isn't the same as having one that actually works, and the way you prove the difference is through independent, objective review.
DOJ's Evaluation of Corporate Compliance Programs guidance directs prosecutors to ask whether a company's compliance efforts are "adequately resourced and empowered" and whether the program is actually tested, not just designed. DOJ specifically looks at whether a company conducts periodic reviews, updates its program based on lessons learned, and uses audits to find problems before regulators do.
OIG's General Compliance Program Guidance (GCPG), released in November 2023, builds this expectation directly into the seven elements of an effective compliance program under "Risk Assessment, Auditing, and Monitoring." OIG recommends that organizations conduct a formal compliance risk assessment at least annually, and that the information behind it come from both internal and external sources. OIG doesn't require external auditors, but it's explicit that outside perspective strengthens the credibility and completeness of the assessment.
An internal team reviewing its own work has blind spots. This is not from bad intent but rather because familiarity breeds assumptions. People stop questioning the things they built. An independent assessor has no stake in defending prior decisions, no political relationships to protect, and no incentive to soften findings. That's precisely the objectivity both DOJ and OIG are pointing to when they distinguish a "paper program" from one that's effective.
Independent review also does something practical: it creates a defensible record. If your organization is ever investigated, having documented, third-party validation that you took your compliance obligations seriously — and acted on what you found — is far more persuasive than internal memos saying everything looked fine.
A meaningful independent assessment typically includes:
Regulators aren't asking whether you have a compliance program. They're asking whether you know if it works and whether you can prove it. An independent assessment answers both questions, and it does so in a way that internal self-review simply can't replicate.
If it's been a while since your program had an outside look, that's worth changing before, not after, you need to explain yourself to a regulator.
CohesiveIQ provides independent compliance program assessments across compliance, data privacy and information security for healthcare organizations. Contact us to discuss a review of your program.
.avif)