{"@context":"https://schema.org","@type":"Article","headline":"Compliance program","description":"Learn how an ABA practice builds a risk-based compliance program with accountable leadership, policies, training, reporting, audits, and corrective action.","url":"https://finnihealth.com/resources/glossary/compliance-program","datePublished":"2026-08-14T00:00:00.000Z","dateModified":"2026-08-14T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Compliance program","item":"https://finnihealth.com/resources/glossary/compliance-program"}]}}
Glossary term

Compliance program

Learn how an ABA practice builds a risk-based compliance program with accountable leadership, policies, training, reporting, audits, and corrective action.

7
min read
Updated
August 13, 2026
Sources checked
August 13, 2026
· View sources
Also called

health care compliance program organizational compliance plan

What is Compliance program, and what should an ABA practice owner know before applying it? A compliance program is an organized system for identifying legal, contractual, ethical, quality, and operational duties; preventing and detecting problems; receiving concerns; investigating facts; correcting issues; and testing effectiveness. An owner should give qualified leaders authority, resources, direct reporting access, clear decision rights, and evidence that the program works in daily practice.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

A program is an operating system

A code of conduct, policy binder, annual training, hotline, outside audit, or named compliance contact can be one component. None describes the whole program. The program connects obligations to owners, controls, evidence, reporting, review, response, and improvement.

The HHS-OIG compliance guidance index lists the November 2023 General Compliance Program Guidance (GCPG), newer industry-specific guidance, and older sector guidance. OIG has not published ABA-specific compliance program guidance. An ABA practice should use applicable primary law, payer and program sources, state requirements, and qualified advice rather than treating guidance for another sector as a ready-made ABA standard.

OIG describes seven program elements

The OIG GCPG presents voluntary, nonbinding guidance and organizes compliance infrastructure around seven elements:

  1. written policies and procedures.
  2. compliance leadership and oversight.
  3. training and education.
  4. effective lines of communication with the compliance officer and disclosure programs.
  5. enforcing standards through consequences and incentives.
  6. risk assessment, auditing, and monitoring.
  7. responding to detected offenses and developing corrective action initiatives.

Use the elements as a connected design. Training should teach current controls. Reports should reach someone able to act. Audits should test identified risks. Findings should produce accountable correction and remeasurement. A quiet hotline or perfect training percentage cannot establish effectiveness by itself.

Right-size leadership without weakening accountability

Owners and governing bodies set expectations, fund the program, receive risk information, challenge management, and verify follow-through. In its voluntary GCPG, OIG says a compliance officer should have authority, stature, access, resources, and direct, independent access to the board.

OIG offers a smaller model for an entity that cannot support a full-time or part-time officer. It suggests naming one compliance contact, keeping that person out of legal-service responsibility and, when possible, billing, coding, or claims submission. Without a board, the contact should report to the owner or CEO at least quarterly. Those are OIG suggestions, while a law, payer contract, state program, grant, or settlement may impose its own structure.

Compliance staff coordinate the system within their competence. A compliance title grants no clinical, legal, privacy, security, employment, coding, or payer authority. Qualified clinicians retain case-specific judgment; counsel interprets law; and domain leaders act within assigned authority.

OIG's compliance resources for health care boards emphasize engaged oversight, risk information, program structure, and effectiveness. Their materials offer ideas for boards of varied sizes; they do not create one governance structure for every ABA practice.

Build one versioned risk and obligation register

Record each material risk with:

  • governing source, scope, effective dates, products, locations, roles, and owner.
  • prohibited or required conduct, current control, evidence, and testing method.
  • likelihood, impact, detectability, priority, and approval rationale.
  • monitoring cadence, audit population, sample rule, and escalation threshold.
  • issue history, open action, deadline, validation, and recheck trigger.

ABA risk domains may include enrollment and licensing; credentialing and roster status; exclusions; referrals and financial relationships; benefits and authorization; coding, documentation, claims, refunds, and overpayments; privacy and security; records; quality and safety; clinical scope and supervision; accessibility; employment; facilities; vendors; and marketing.

Current oversight can help prioritize that list. A 2026 OIG audit of Colorado Medicaid ABA payments identified issues involving documentation, billing, credentials, diagnostic evaluations, and treatment referrals. Those state-specific findings are risk signals to compare with the practice's governing requirements, rather than national ABA rules.

For a small practice, OIG suggests at least an annual compliance risk assessment and annual audit. A new high-priority risk can call for earlier review. Document why a population, sample, control, or cadence fits the identified risk.

A risk register does not transfer decision authority. For example, software may flag conflicting clinical and authorization data, while an appropriately qualified clinician decides whether clinical content should change. Billing staff address the claim route. The payer decides its coverage state.

Reporting and investigations need safe routes

Offer usable ways for workforce members, clients, families, contractors, and vendors to raise concerns. Define confidentiality limits, anti-retaliation policy, anonymous options where available, accessibility, intake ownership, urgent routes, conflict handling, and status communication. Emergency, medical, protective-service, and mandated-reporting duties use their authorized paths immediately.

An investigation record should identify the allegation, source, preservation steps, reviewer authority, conflicts, facts, interviews, governing sources, findings, actions, and closure basis. A “privileged” label does not create legal privilege. Counsel should determine whether and how privilege, reporting, self-disclosure, repayment, notice, or legal holds apply.

Apply standards consistently while considering role, knowledge, conduct, severity, and governing employment rules. Protect reporters and participants from prohibited retaliation. Avoid publishing facts beyond the audience that needs them.

Monitoring, auditing, and correction answer different questions

Monitoring is recurring oversight of controls or operations. An audit is a defined, independent or objective test against criteria. An investigation resolves an allegation or event. Corrective action addresses cause, impact, and recurrence. Keep the purposes, populations, owners, and evidence distinct.

The OIG compliance page describes its resources as educational and says official information remains in relevant laws and regulations. Its compliance toolkits page includes a broad menu for measuring program effectiveness. Select measures that match the practice's risks and size, then test whether controls work in practice.

A fictional quarter shows connected controls

A fictional practice locks 12 compliance actions due during the quarter. Nine close by their approved deadline, so on-time closure is 9 of 12, or 75%. Three remain open with risk, owner, age, next step, and escalation date.

The same quarter includes eight billing edits identified by monitoring. All eight receive review; five are configuration errors, two are documentation-to-claim conflicts, and one is a training case. These categories describe reviewed findings. They do not establish fraud, quantify an overpayment, or prove the monitoring found every issue.

The practice tests each correction against its root cause. A configuration fix requires a controlled release and sample recheck. A clinical-record question returns to the qualified clinician. A claim, refund, disclosure, or self-reporting decision goes to the role authorized under the governing source. Closure requires evidence of implementation and validation.

Measures should show effectiveness and blind spots

Useful measures include:

  • risks with a current owner, control, and test divided by risks due for review.
  • role-specific training completed by deadline divided by people required to complete it.
  • reports triaged within target divided by reports due for triage.
  • mature audit populations tested divided by populations scheduled.
  • corrective actions validated by deadline divided by actions due.
  • repeated findings divided by items exposed to the same control version.
  • open issues by severity, owner, and age.

Define the cohort, unit, source, cutoff, maturity rule, numerator, denominator, exclusions, owner, and evidence. Preserve late, missing, and inconclusive items. Pair metrics with interviews, transaction testing, accessible reporting, independent challenge, and governing-body review. More reports can reflect greater awareness and trust, so count alone should not be labeled success or failure.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni