Building a Compliance Program From Scratch

Launch week: the new Compliance Plan Toolkit is here. Use code LAUNCH50 for 50% off through July 5.
Get the compliance plan toolkit →
Welcome! If you are a practice owner, you’ve likely spent years: if not decades: focusing on the clinical side of your craft. You took the Hippocratic Oath to do no harm, but in 2026, the definition of "harm" has expanded. It isn’t just about a missed diagnosis; it’s about the fiscal and regulatory health of your business. Most small and mid-sized practices operate on a philosophy of "we try to be careful." We hire good people, we use reputable software, and we hope for the best. This post pairs with a ready-to-use toolkit that makes implementation faster — the Compliance Plan Toolkit, built directly on the seven elements of the OIG General Compliance Program Guidance.
But hope is not a strategy. That "careful" approach works perfectly: until it doesn’t. It fails the moment a surprise audit letter arrives, a disgruntled former employee files a whistleblower complaint, or the OIG comes knocking because of a data outlier. The good news? Building a real, defensible compliance program is not as complex as the legal-industrial complex makes it sound. It doesn't require a seven-figure budget or a 50-person department. It comes down to seven core elements, codified by the Office of Inspector General (OIG) and recently refreshed in November 2023. As a physician who is also a certified coder and auditor, I’m here to tell you: you can actually do this. This post is your framework for standing up a program that protects your license, your revenue, and your peace of mind without hiring a Chief Compliance Officer.
Building this from scratch takes time most practices do not have. The compliance plan toolkit gives you the entire program — Master Plan, Code of Conduct, risk assessment, audit checklist, monitoring calendar, and every log — ready to customize and adopt in an afternoon. Use code LAUNCH50 for 50% off through July 5. Get the compliance plan toolkit →
Why a Compliance Program Is No Longer Optional
For a long time, small practices felt like they were "under the radar." We assumed the OIG and CMS were too busy chasing multi-hospital systems to worry about a five-physician orthopedic group. That era is over. In November 2023, the HHS-OIG released the General Compliance Program Guidance (GCPG), and it was a wake-up call for the entire industry. This guidance applies to all healthcare entities, regardless of size.
Whether you are navigating telehealth billing in 2026 or managing complex surgical cases, the federal government now expects a documented, active compliance program. Payers are following suit. Malpractice carriers are starting to ask for compliance manuals during the credentialing process. The cost of non-compliance isn't just a "slap on the wrist" anymore. We are talking about civil monetary penalties that can reach six figures per claim, exclusion from federal programs (a death sentence for most practices), and extreme qui tam exposure. A formal program serves as your primary defense. It demonstrates "good faith." If an error occurs: and in medicine, they will: having a program in place can mean the difference between a simple refund and a devastating fraud investigation.
The Seven Elements of an Effective Compliance Program
The OIG has laid out seven elements that form the "gold standard" of compliance. For a small practice, the key is "right-sizing" these elements. You don't need a 500-page manual; you need a functional system.

1. Written Policies and Procedures
You need a "Code of Conduct" that explicitly states your practice’s commitment to ethical billing and clinical care. Beyond that, you need specific policies for your highest risk areas. For most of us, that means ICD-10 coding accuracy, HIPAA privacy, and modifier usage rules.
- Small Practice Example: A 3-page document outlining how you handle overpayments, how you verify insurance, and your policy on "waiving" co-pays (spoiler: don't do it).
2. Designated Compliance Officer and Committee
In a large hospital, this is a C-suite executive. In a 5-physician practice, this is a "Compliance Contact." This person must have the authority to review records and report directly to the owners. Crucially, the OIG now emphasizes that this person should not be the one who does the billing or the legal work. You need a separation of duties to avoid conflicts of interest.
3. Effective Training and Education
Training is not a "one and done" event during new-hire orientation. It must be periodic. Your staff needs to understand NCCI bundling rules and how to document medical decision making to support the levels billed.
- Small Practice Example: A 15-minute "Compliance Minute" during your monthly staff meeting, where you review one specific coding update or a recent OIG newsletter.
4. Effective Lines of Communication
Your staff must have a way to report potential issues without fear of retaliation. While you might not need a fancy third-party hotline, you do need a "compliance suggestion box" or a dedicated, confidential email address. The OIG 2023 guidance is very clear: the door must be open.
5. Enforcing Standards Through Disciplinary Guidelines
Compliance has to have teeth. If an employee is found intentionally upcoding or ignoring HIPAA protocols, there must be a documented disciplinary process: and it must be applied consistently. This protects you by showing that you do not tolerate non-compliance.
6. Internal Monitoring and Auditing
This is where most practices fall short. You cannot wait for a payer to audit you. You must perform your own. Review 10-15 charts per provider annually. Look for errors before payers find them — the same patterns that show up in surviving a payer audit are exactly what your internal audits should catch first.
- Small Practice Example: Every quarter, pull five random charts from your highest-volume codes and verify that the documentation supports the service rendered.
7. Prompt Response to Detected Offenses and Corrective Action
If you find an error, you must fix it. This means refunding overpayments (usually within 60 days of identification) and creating a corrective action plan (like more training) to ensure it doesn't happen again. Documenting this response is your "get out of jail free" card because it proves you are self-policing.
Common Compliance Pitfalls and How the Compliance Plan Toolkit Prevents Them
In my 21 years of compliance program consulting, I see the same five mistakes over and over.
1. The "Dusty Binder" Syndrome: Many practices buy a generic compliance manual online, change the name on the cover, and stick it on a shelf. If your policies don't match your actual workflow, they are worthless in an audit. The toolkit's Master Plan and Code of Conduct templates are designed to be customized to your actual workflow instead of sitting on a shelf. 2. The Powerless Compliance Officer: Naming your youngest front-desk staffer as the "Compliance Officer" because they have "extra time" is a mistake. If that person doesn't have the authority to tell a senior partner their documentation is lacking, the program isn't effective. The toolkit includes a Compliance Officer Charter that documents authority and reporting line so the role carries real weight. 3. Training Amnesia: Training once at hire and never again is a massive red flag. Regulations change every year. Your training must be ongoing. The toolkit includes a quarterly training calendar and "Compliance Minute" templates to keep education alive year-round. 4. Ghost Audits: Saying you "check things periodically" isn't an audit. If it isn't written down, it didn't happen. You need documented audit results and documented follow-up. The toolkit's audit checklists and monitoring log create the written record auditors look for — if it is not written down, it did not happen. 5. Shooting the Messenger: If a coder brings you a concern and is met with "just code what I tell you," you have just created a whistleblower. Encourage the report, investigate it fairly, and thank them for protecting the practice. The toolkit's reporting channel policy templates include non-retaliation protections to safeguard whistleblowers and encourage transparency.
Your 90-Day Startup Plan
You don't have to build Rome in a day. Here is a realistic roadmap to go from "zero" to "compliant" in one quarter.

Days 1–30: The Foundation
- Designate your Compliance Contact.
- Draft written policies for your "Top 5" risk areas (E/M coding, modifiers, telehealth, controlled substances, and HIPAA).
- Schedule a confidential compliance program assessment to identify your biggest gaps.
Days 31–60: The Rollout
- Hold a staff meeting to introduce the Code of Conduct.
- Establish your reporting channel (e.g., an anonymous drop box).
- Begin basic staff training. For a structured approach, I recommend the documentation standardization framework on Amazon Kindle. It's available for $9.99 on Kindle or $29.99 in paperback for those who like a physical reference in the office.
Days 61–90: The Verification
- Conduct your first internal mini-audit (5-10 charts per provider).
- Document your findings.
- Create a corrective action plan for any errors found. This shows you are active and engaged.
Conclusion: Compliance as a Competitive Advantage
I know what you're thinking: this sounds like more administrative work. And you're right. But in the current healthcare climate, a robust compliance program is actually a competitive advantage. It makes your practice more attractive for mergers, more resilient against audits, and more profitable because you aren't constantly losing money to preventable denials.
Building a program from scratch feels daunting, but you don't have to do it alone. We’ve built the tools to make this "plug and play" for busy clinicians.
If you are ready to move beyond "hoping for the best," the compliance plan toolkit is your next step. A complete, customizable compliance program for the independent and small medical practice, built on the seven elements of the 2023 HHS-OIG General Compliance Program Guidance. For $97, you get the Master Plan, Code of Conduct, risk assessment templates, audit checklists, monitoring calendar, and every log you need.
Launch week: use code LAUNCH50 for 50% off through July 5.
Get the ready-to-use compliance program →
Thank you for the work you do every day. Now let's make sure your practice is as protected as the patients you treat.
Dr. Dreama Sloan-Kelly, MD, CCS, CPC CEO/President, Dr. Sloan-Kelly Consulting LLC
Don't miss the next update. Each month I send The DocsDoc Brief : clinical documentation, coding, compliance, and AI insights : straight to your inbox. 👉 Subscribe to The DocsDoc Brief here
