Letter to Staff, Vendors, Consultants, and Board of Directors
Dear Hometown Health Team:
Artificial Intelligence (AI) and Presidential Executive Orders have changed the compliance landscape. Hometown is committed to meeting patient needs while complying with all State and Federal laws, regulations, and presidential directives. Of course, fighting fraud, waste, and abuse while providing quality, accessible care will always be a foundation to Hometown’s Compliance Program.
This year has seen the initiation of a designated Risk Management Committee. Risk and Quality, while overlapping, will be separated. The Compliance Officer will work with the Risk Manager to further identify opportunities to mitigate risk to patients and the organization.
Another important change is the expansion of Hometown’s Compliance Training Plan. Although Hometown has had training plans in the past, the proposed 2026-2027 plan is significantly expanded. Its comprehensive nature underscores Hometown’s commitment to learning and improving while monitoring changes to the State and Federal landscape.
As it always does, the Board’s Compliance Committee reviews compliance policies and procedures annually. It reflects a commitment to incorporate the latest changes to the law and identify and apply best practices. In the area of compliance, but as in all areas, Hometown’s Board of Directors always looks for ways to improve and be good stewards of limited resources.
Setting a high bar for conduct of Staff, Students, and Board Members while communicating ethical and training expectations to vendors is a pillar of Hometown’s Compliance Program. This is reflected, in part, in the Standards of Conduct. These standards also underscore the organization’s philosophy to go above and beyond what the law requires regarding ethics, being forthright, and always showing transparency.
As a valued member of this organization, you have an important role in effective, ongoing compliance. It is also a very important part of your job duties to be engaged with the Compliance Program.
This document is always a work in progress because identifying and applying best practices does not stop. Laws and regulations change. This Manual and the separate Standards of Conduct are your guides to make the Program a success. Together we make a difference.
Compliance cannot be successful without your active engagement. Please remember if you see or hear something, you must report it. It’s an expectation of every vendor, student, Board Director, and Staff Member.
Sincerely,
- Pedro Aviles, Board Committee Chair
- Christine Smoot Lowers, CEO
- Paul Jesep, Esq., MPS, MA, Compliance Officer
Executive Summary
Why HHC’s Compliance Program Is Necessary
HHC’s Compliance Program is necessary because it:
- Protects patient privacy;
- Nurtures an ethical culture;
- Promotes Quality Assurance;
- Prevents conflicts of interest;
- Ensures proper credentialing;
- Furthers accurate billing and coding;
- Educates staff and the Board of Directors;
- Assists in obeying State and Federal laws;
- Maintains and promotes high quality care;
- Defines, identifies and prevents fraud, waste, and abuse;
- Provides patients ready access to their health information;
- Strives to promote best practices in management and board governance; and
- Sets standards for vendors/consultants doing/seeking business with Hometown.
Who the Compliance Program Applies To
HHC’s Compliance Program applies to:
- Vendors;
- Volunteers;
- Contractors;
- Consultants;
- Supervisors;
- Interns/Students;
- Department heads;
- Board of Directors; and
- All staff no matter the title or position.
What You Must Do
- Act fairly;
- Act ethically;
- Act honestly;
- Act as a team;
- Be engaged with ethics and compliance;
- Promote Hometown’s Mission and Values;
- Report a conflict of interest that you may have;
- Treat patients and one another with respect at all times;
- Identify ways to do things better in your department and take action;
- Suggest ideas to your supervisor or the Corporate Ethics and Compliance Officer to better use resources and stop waste and fraud;
- Report problems immediately to your supervisor or directly to the Corporate Ethics and Compliance Officer; and
- Remind your team at meetings it must do regular Risk Assessments.
Compliance policies, manual, newsletters, and Standards of Conduct are located on the Staff Intranet.
I. Ethics and Compliance Introduction
Law, regulations, and presidential directives are an important part of this Compliance Program. In 2006, Hometown Health Centers implemented a Corporate Compliance Program (Ethics, Compliance, and Standards of Conduct). Everyone affiliated with HHC, including staff, contractors, consultants, volunteers, Business Associates, and Board Members is bound by the Program. Board Members, by virtue of voting on the document, are considered to have received the Manual; if a Member is absent during a vote, he or she is duty-bound to read Board Minutes and be aware of a revised Manual in place.
Compliance requires everyone to be involved. It is a team effort. It is a job requirement for everyone to report concerns and be engaged. See Something? You MUST say something. The law protects you if you report.
This includes not only Staff, but also Board Members, Vendors, Contractors, and anyone affiliated with Hometown.
Quality care, patient access, and fighting fraud, waste, and abuse are a hallmark of any effective compliance program. Patient wellbeing is always the focus. Quality is furthered, in part, by monitoring and documenting quality of care and customer service (see Appendix H).
Compliance must complement efforts to serve the patient with access and excellent care while never permitting fraud, waste, or abuse.
All staff, vendors, consultants, and Board Members are bound by Hometown Health Center’s (HHC) Compliance Program and Standards of Conduct.
Hometown is a designated Federally Qualified Health Center (FQHC). With this designation comes much responsibility fulfilled, in part, by having an effective Ethics and Compliance Program. The Program is reviewed and adopted by the Board of Directors on an annual basis.
New York State recommends several key elements to an effective compliance program. These elements parallel those outlined by the Federal government. Recent changes bring New York’s compliance elements more in line with the federal government. In doing so, however, there is no diminishment at the State or Federal level in the importance of protecting staff, vendors, and Board Members who raise compliance concerns. Whistleblower protections remain a foundation to Hometown’s compliance program.
Absence of an effective compliance strategy causes unnecessary abuses jeopardizing patient care and privacy while wasting resources and potentially defrauding the government. Very stiff fines are assessed against organizations and healthcare providers found in violation of State and Federal law. Penalties include criminal proceedings, significant fines in the tens of thousands of dollars, and potentially the loss by providers of their ability to bill for services under Medicare and Medicaid.
Hometown maintains its compliance program, in part, by having a Board designated Compliance Committee in addition to an Internal Staff Committee.
Several important State and Federal laws staff and Board Members should have a familiarity with:
- Federal False Claims Act (31 USC §§ 3729-3733)
- Federal Anti-Kickback Statute (42 USC § 1320a-7b(b))
- Federal Physician Self-Referral Law (42 USC §1395nn)
- Federal Exclusion Statute (42 USC §1320a-7)
- Federal Deficit Reduction Act (42 USC §1396a(a)(68))
- Federal Patient Protection and Affordable Care Act (42 USC §18001)
- New York False Claims Act (State Finance Law §§ 187-194)
- New York Social Services Law (§ 363-d – Effective Compliance Program)
- New York Social Services Law (§ 145-b – False Statements)
- New York Social Services Law (§ 145-c, 366-b – Penalties, Sanctions)
- New York Penal Law Article 175 (False Written Statements)
- New York Penal Law Article 176 (Insurance Fraud)
- New York Penal Law Article 177 (Healthcare Fraud)
- Part 521, Title 18, of the New York State Codes, Rules, and Regulations
Providers are required to read, before starting employment, A Road Map for New Physicians Avoiding Medicare and Medicaid Fraud and Abuse, issued by the US Department of Health and Human Services – Office of Inspector General. See https://oig.hhs.gov/compliance/physician-education/index.asp.
State and Federal laws also come with non-intimidation and non-retaliation (whistleblower) protections. This means you cannot be harassed for wanting to report a problem. Nor can you be fired after you report one in good faith.
There are 800 numbers you may call at the State and Federal offices of the Medicaid Inspector Generals to report issues of harassment or intimidation for reporting a problem. You are protected.
Your suggestions on how to make HHC’s Ethics and Compliance Program better are encouraged and would be valued and valuable. There are locked compliance boxes on Hometown sites. Only the Corporate Ethics and Compliance Officer or his/her designee has access to these boxes.
The Federal Government and New York State Office of Medicaid Inspector General outlined several key elements for an effective compliance program.
Independent of legal requirements, HHC fosters an ethical culture. A law or policy does not need to be in place to be ethical at all times. Hence, act with fairness and integrity. Go above and beyond the law when given the opportunity.
II. Elements of an Effective Compliance Program
1. Use of Written Policies & Procedures
HHC reviews policies on an ongoing basis and expects department managers and supervisors to be proactive by identifying areas for improved compliance practices.
HHC has adopted Standards of Conduct, a Conflict of Interest Disclosure Statement, and uses the National Association of Community Health Centers (NACHC) Corporate Compliance Toolkit to develop individual policies. These are accessible to staff on the Staff Intranet, along with whistleblower protections.
HHC must act with a sense of ethics, be fair, and be proactive – even if no clear rule is in place for an unforeseen issue – and put patient safety first.
Standards of Conduct
All Managers and Board Members must demonstrate exemplary conduct for Staff, Vendors, and Contractors affiliated with Hometown.
Standards of Conduct set policies and procedures ranging from declining gifts, to billing and coding, to documenting medical treatment, and are reviewed by the Corporate Ethics and Compliance Officer.
Organization’s Compliance Responsibility
Managers, Board Members, and Staff, Vendors, and Contractors affiliated with Hometown are responsible for monitoring compliance efforts and enforcing practice standards; providing training and education on compliance policies; developing effective lines of communication and allowing anonymous reporting mechanisms; enforcing standards for employees through disciplinary guidelines; detecting offenses; and developing corrective action plans.
Good Faith Reporting
Staff, vendors, volunteers, contractors/consultants, and Board Members are obligated to report to the Corporate Ethics and Compliance Officer any activity inconsistent with HHC policies or state and federal law.
It is illegal to retaliate against someone for reporting a concern. If someone is being intimidated or harassed, he or she can contact the Office of Medicaid Inspector General (OMIG) at the State and Federal level. Or the vendor, employee, or Board Member may contact any State agency.
Other Written Policies and Procedures
Additional written policies and procedures supporting the Compliance Program are maintained and made accessible to Staff, Vendors, Contractors, and Board Members on the Staff Intranet.
Annual Work Plan
HHC maintains an Annual Compliance Work Plan that is reviewed and evaluated by the Board Compliance Committee and the Internal HHC Compliance Committee.
Exit Interview
Employees may request an Exit Interview with the Compliance Officer. Paul Jesep is the staff member present. He attends the weekly Senior Management meetings.
1a. Non-Intimidation and Non-Retaliation Policies
State and Federal laws provide non-intimidation and non-retaliation (whistleblower) protections to discourage a vendor, employee, or Board Member from reporting a problem. It is illegal to retaliate against someone for reporting one. If someone is intimidated, he or she can contact the Office of Medicaid Inspector General (OMIG) or contact the Compliance & Privacy Officer.
Hometown maintains a strict non-intimidation and non-retaliation policy to protect anyone who in good faith makes a report – anonymously or otherwise.
You cannot lose your job for acting in good conscience to report a concern. Confidentiality will be maintained in most cases. Your job is protected in all cases when reporting a concern in good faith.
Members of the Board of Directors also have a duty to report concerns to the Corporate Ethics and Compliance Officer and to the Board’s Compliance Standing Committee. This includes, but is not limited to, concerns a Board Member has not disclosed a conflict of interest or failed to recuse him- or herself from discussions about the matter where a conflict arises.
2. Designated Corporate Ethics and Compliance Officer and HIPAA Privacy Officer
The Corporate Ethics and Compliance Officer serves as HIPAA Privacy Officer for patient or staff concerns.
- Internal Extension: 4168
- Compliance Hotline: (*67) 518-688-3460
- Compliance Email: [email protected]
- HIPAA Email: [email protected]
Accountability to CEO and Board of Directors
The Corporate Ethics and Compliance Officer reports to the CEO and the Board of Directors. The Corporate Ethics and Compliance Officer is empowered to go directly to the Board and the CEO.
Board Compliance Committee/Internal HHC Compliance Committee
The Board Compliance Committee and Internal HHC Compliance Committee:
- Maintain an Incident Log.
- Prepare Compliance Reports.
- Maintain an anonymous outside Hotline.
- Conduct a periodic organization-wide Compliance survey.
- Train new staff with Compliance fundamentals.
- Have staff fill out an Annual Conflict of Interest Survey.
- Meet with Board and Internal Compliance Committees.
- Facilitate Board training with webinars and in-person presentations.
- Conduct Audits/Risk Assessments.
- Maintain locked compliance boxes for anonymous reporting.
- Conduct Exit Interviews.
- Review and update Forms, Compliance Policies, the Compliance Manual, and Standards of Conduct.
- Maintain a visible presence, including posters, as time permits.
- Use online tools, conduct departmental training, and issue a monthly newsletter, including for National Ethics and Compliance Week.
- Work with the COO and CFO to determine if HHC has passed the Medicaid threshold under the Federal Deficit Reduction Act (DRA) and the NYS OMIG site.
- Monitor websites of HRSA, OMIG, NACHC, and CHCANYS.
Specific Duties and Functions
Lauren Nodonly is Corporate Ethics and Compliance Officer duties include training staff in laws, regulations, and Standards of Conduct, Mission and Values, and State and Federal laws, and is available for interviews with the Corporate Ethics and Compliance Officer.
Designated Cyber Security Officer
Hometown maintains a Designated Cyber Security Officer role, coordinated with the Corporate Ethics and Compliance Officer, to oversee cybersecurity training, phishing and ransomware awareness, and reporting of suspected cyber incidents.
3. Education Program
Components to Education Program
Five key components make up the Education Program, reaching Staff, Vendors, Contractors, and Board Members. Questions requiring clarification on laws or regulations are referred to the Corporate Ethics and Compliance Officer.
Compliance and Quality Assurance Committee
The Compliance and Quality Assurance Committee works alongside the Board Compliance Committee and Internal HHC Compliance Committee to review education needs and outcomes.
New Employee Training
New employees receive Compliance training as part of onboarding, including a meeting with the Corporate Ethics and Compliance Officer (see Appendix B).
Demonstrating Compliance in the Workplace
It is imperative that all employees: maintain confidentiality of patient information, conduct routine Risk Assessments, evaluate security measures, examine privacy measures, and collaborate with colleagues to sustain a limited-risk work environment.
Print/Electronic Newsletters/Webinars
The Compliance Program will include a monthly newsletter and educational emails. All staff are required to read emails and the Compliance Newsletter.
Training by Your Supervisor/Corporate Ethics and Compliance Officer
Supervisors and Department heads train staff regarding ethics and compliance issues specific to their respective areas of care and service. They may use resources found online and the monthly Newsletter.
During the course of their employment, employees are expected to be proactive in seeking ongoing training and to be responsive to training provided by the Corporate Ethics and Compliance Officer throughout the year, which may include, but not be limited to, reading the monthly newsletter and any electronic e-newsletters.
Conflict of Interest Disclosure Survey
The survey is used to identify potential or actual conflicts before an individual begins a formal affiliation with HHC. New staff and Board Members must complete a Disclosure Survey and must fill out a Conflict of Interest Statement, and must be proactive and report a potential conflict (see Appendix A).
HIPAA Access, Privacy, and Security
HIPAA governs privacy and security, and limits the conditions under which uses and disclosures of information may be made without patient authorization. Even if you know someone at Hometown who is a patient, you must abide by HIPAA and privacy requirements.
Do not look in the patient record of a friend, neighbor, relative, or co-worker. Access must have a work-related reason; verbal authorization is not sufficient – written authorization must be on file and all established procedures must be followed.
If YOU are a patient at Hometown, you may not look at your own chart or record without following all established procedures. If in doubt, discuss with a supervisor.
HIPAA works in tandem with the Health Information Technology for Economic and Clinical Health Act (HITECH), a government initiative promoting Electronic Health Record (EHR) systems. HITECH requires Hometown to report data breaches involving unsecure or unencrypted PHI being disclosed.
HITECH promotes safety, quality, and efficiency for patients electronically. Breach notifications must be sent to patients and to state and federal governments when there is a high risk that disclosure of private health information constitutes a breach. HIV-status disclosure is treated as a reportable breach.
4. Open Line of Communications to the Corporate Ethics and Compliance Officer
Access to the Corporate Ethics and Compliance Officer
Employees have the choice, if he or she chooses, to contact the Ethics and Compliance Officer directly about an issue.
24 Hour Hotline/Confidential and Anonymous
Confidentiality does not require disclosure of a reporter’s name; the name will not be shared. An employee may report a concern anonymously, including by leaving a note.
Employees are required to report directly or anonymously to a supervisor or the Ethics and Compliance Officer any concerns about waste, fraud, or wrongdoing. If the employee elects to make a good faith anonymous report, call:
- Internal Extension: 4195, or
- 24-hour anonymous hotline: (*67) 518-688-3460.
Hometown maintains a strict non-intimidation and non-retaliation policy to protect anyone who in good faith makes a report – anonymously or otherwise. You cannot lose your job for acting in good conscience to report a concern. Confidentiality will be maintained in most cases. Your job is protected in all cases when reporting a concern in good faith.
Members of the Board of Directors also have a duty to report concerns to the Corporate Ethics and Compliance Officer and information for patients about reporting fraud, waste, and abuse shall be posted in public areas. Board Members have direct access because as a matter of fiduciary duty they must review and vote on Compliance Policies, Whistleblower Protections, and the Standards of Conduct.
Locked Compliance Boxes
There are locked compliance boxes where anonymous notes may be left. Staff should keep in mind this is different from the Employee Suggestion Box. Only the Corporate Ethics and Compliance Officer or his/her designee has access to the compliance boxes.
Board of Directors Access
As a matter of routine, the Board of Directors shall meet with the Compliance Officer in Executive Session no less than twice a year. No other member of staff shall be in attendance.
Staff Access to Policies and Patient Information on Reporting Fraud, Waste, and Abuse
Compliance Policies, Newsletters, Work Plans, Whistleblower Protections, and other items supporting the overall Compliance Program are posted on the Staff Intranet. Information for patients about reporting fraud, waste, and abuse shall be posted in public areas. Documents requiring a Board vote are posted on the Boardable website.
5. Evaluations/Corrective Policies/Mandatory Participation
HHC has an array of policies and their effectiveness is based in part on enforcement by supervisors and Human Resources. Corrective action may include: warnings, reprimands, probation, demotion, temporary suspension, termination, restitution of damages, and referral for criminal prosecution. These sanctions apply to employees, Board Members, and persons associated with Hometown Health Centers including vendors and consultants. Retraining or greater education also is an option. All compliance incidences must be reported, logged, and investigated.
A Board Member may be removed, suspended, or censured for failing to disclose any personal or family conflict of interest during a Board or Committee discussion and before a vote. He or she can be removed, suspended, or censured for misusing resources of the organization. The Board shall consider the seriousness of the conflict and how it was discovered in determining whether to impose a penalty of removal, suspension, or censure of the Board Member. Actions and discussion shall be reflected in Board minutes.
Staff Evaluations Include Compliance Engagement
All members of staff, regardless of position, are mandated to adhere to the Compliance Program. Annual Employment Evaluations overseen by Human Resources may reflect, in part, how an individual was engaged and participated in compliance. Depending on an employee’s position, this may include, but not be limited to, Risk Assessments, fulfilling online training requirements, participation in compliance competitions, and immediately reporting ethical or compliance concerns that may have been observed.
6. Ongoing Identification of Risk Areas – This Applies to Everyone
Compliance through systematic, self-initiated Risk Assessments is the responsibility of every HHC Department. They are mandated by HHC’s Board of Directors and the New York State Office of Medicaid Inspector General (OMIG). Managers and department leaders who fail to work with their staff to conduct Risk Assessments on an ongoing basis are subject to corrective action up to and including termination.
Risk assessments identify problems before they occur or determine weaknesses in providing care, governance, or charging for services.
Department managers, supervisors, and sometimes the Board of Directors are all called to initiate Risk Assessments, develop and implement action plans, and measure progress. Risk Assessments protect patients and stop fraud, waste, and abuse. Risk Assessments are expected by the Federal government to qualify for Federal Tort Claims Act (FTCA) coverage and the New York State Office of Medicaid Inspector General (OMIG). Departments must do them.
Although risk areas include billing, credentialing, medical necessity, and quality of care, they also involve “other risk areas that are or should with due diligence be identified.”
In conducting a Risk Assessment, ask several key questions. They include, but are not limited to:
- Does the Department have a system to routinely identify compliance risk areas specific to its work?
- Does the Department have a system for self-evaluation of the risk areas identified in the previous question, including internal audits and, as appropriate, external audits?
- Does the Department have a system in place for evaluation of potential or actual non-compliance as a result of self-evaluations and audits?
- Does the Department keep the Corporate Ethics and Compliance Officer informed of the Risk Assessments planned, being conducted, and once they are concluded?
See Appendix D for more information on how to conduct Risk Assessments.
Billing
Compliance issues that may result in fines or criminal investigation include, but are not limited to:
- Billing for services not done;
- Billing for unnecessary services;
- Improper oversight of revenue cycle;
- Duplicate billing (billing two or more times for the same service);
- Up coding – billing for a higher level of service than actually provided;
- Unbundling two or more services that must be billed together under applicable reimbursement rules;
- Billing for more than a single visit on the same day, to the extent prohibited by applicable reimbursement rules;
- Failure to refund credit balances that are due to clients;
- Failure to maintain sufficient documentation to demonstrate that services were performed and to support third party reimbursement;
- Billing for services provided by personnel not properly supervised, not recognized as qualified by the government, or lacking the level of licensure required by appropriate law;
- Absent, forged, or untimely physician certifications;
- Inadequate management and oversight of subcontracted services, which results in improper billing;
- Duplication of services provided by physicians and other mental health providers; and
- Failure to return overpayments once HHC becomes aware of them.
Knowingly submitting false or fraudulent claims for payment to a government agency violates the Civil False Claims Act, 31 USC Sec. 3729(a).
A person acts “knowingly” under the law not only if they have actual knowledge of a false or fraudulent claim, but also if they act with deliberate ignorance or reckless disregard for the law. Civil damages are substantial with the potential for criminal liability.
Exclusion Lists
HHC will monitor government exclusion lists for those affiliated with the organization to verify they have not violated the public trust and become ineligible to participate in the Medicaid program or any other State or Federally funded program. This will include staff, Board Members, prospective employees, and outside vendors and consultants.
Current Exclusion Lists include:
- NYS Office of Medicaid Inspector General (OMIG) – all staff, board members, and vendors are checked every month.
- Federal Office of Inspector General List of Excluded Individual/Entities (OIG-LEIE) – all staff, board members, and vendors are checked every month.
- Federal System for Award Management (SAM) – all staff, board members, and vendors are checked every month.
- Specially Designated National and Blocked Persons List/Office of Foreign Assets Control (SDN/OFAC) – all staff and board members are checked on a rotating basis (15+ per month).
- National Plan and Provider Enumeration System (NPPES) – all staff and board members are checked on a rotating basis (15+ a month).
- Social Security Death Master Index (SSDM) – all staff and board members checked on a rotating basis (15+ per month).
- Google Ratings – vendors only, on a rotating basis (15+ monthly).
- NYS Sex Offender Registry – all staff and board members checked on a rotating basis (15+ monthly).
- National Sex Offender Registry – all staff and board members checked on a rotating basis (15+ monthly).
If an employee is found on an Exclusion List, HR will handle the resolution. If a vendor is found on an Exclusion List, Finance will handle the resolution. If a Board Member is found on an Exclusion List, it will be referred to the full Board for resolution. Resolution shall mean termination of all affiliation with Hometown.
Compliance also conducts criminal background checks for arrests/child abuse through a company for staff going into homes. All school-based staff go to the Sheriff’s Office for fingerprinting and a background check. Compliance also conducts staff background checks specific to the sex offender registry.
Medical Necessity and Quality of Care
Assessments must be done on an ongoing basis. These departmental self-initiatives will have a direct impact on the excellence HHC strives to bring to patient-consumer care while being good stewards of all resources.
Compliance Log
HHC shall document incidences and the progress and follow-up to address problems or system weaknesses. Issues arise, and it is important to track and monitor them to further quality improvement, best practices, and be good stewards of resources.
7. Timely Corrective Actions When Risks Identified or Problems Occur
Departments must show the initiative and leadership in responding to compliance issues in a timely, committed manner, including working with the Corporate Ethics and Compliance Officer. Independent of Risk Assessments and quality improvement initiatives, issues brought to the Corporate Ethics and Compliance Officer’s attention require they be logged, investigated, and depending on seriousness reported to the Board immediately, with corrective action suggested and the situation monitored for improvement and resolution. This process will include whether violations must be promptly reported to State and Federal authorities.
Hometown shall utilize an active internal Risk Management Committee. Its members shall include, but not be limited to, the Chief Medical Officer, the Nursing Director, Quality Assurance Manager, and the Compliance Officer. The Committee shall identify clinical risk areas and create a work plan.
III. NYS OMIG Guide for Uploading Audit Documents
Attachments 1 – Written Policies and Procedures
| Code | Documentation Required |
|---|---|
| 1-1a | Who is Impacted by Policies (implementation dates, revisions, persons impacted) |
| 1-1b | Employee Handbook (implementation dates, revisions, show employees bound by policies) |
| 1-2 | Annual Review of Policies |
Attachments 2 – Designated Compliance Officer
| Code | Documentation Required |
|---|---|
| 2-1a | Designated Compliance Officer (name, board designation, job offer/letter of appointment) |
| 2-1b | Work Plans & Work Plan Evaluations |
| 2-1c | Quarterly Reports – Board of Directors; Chief Executive Officer; Senior Management; Internal Compliance Committee |
| 2-2 | Reporting to CEO (documentation showing direct report to CEO) |
| 2-3 | Other Duties Assigned to CO (assessment that other duties didn’t interfere with compliance duties) |
| 2-4 | Sufficient Resources for CO (assessment) |
| 2-5 | Access to Info, Files by CO (documentation access was given) |
| 2-6a | Committee Members (Board Committee & Internal Compliance Committees with dates of appointment) |
| 2-6b | Charters with Annual Reviews (Board Committee Charter, Internal Committee Charter) |
| 2-6c | Minutes/Reporting (Board & Internal Committee Minutes, Org Chart, CEO reports, and Compliance Chart) |
Attachments 3 – Education and Training
| Code | Documentation Required |
|---|---|
| 3-1 | Dated Compliance Training and Education Plans & Documentation Accessible/Understandable |
| 3-2 | Proof of Training Completion by Affected Individuals |
Attachments 4 – Lines of Communication
| Code | Documentation Required |
|---|---|
| 4-1 | Ways to Contact CO (lines of communication with effective dates) |
| 4-2 | Anonymous Reporting by Staff, Vendors, Patients, Board Members (ways to do it) |
| 4-3a | Maintaining Confidentiality (evidence it was kept when reported and how, policies to protect) |
| 4-3b | Public Access to Compliance Program (availability on website) |
Attachments 5 – Disciplinary Standards
| Code | Documentation Required |
|---|---|
| 5-1 | Published and Disseminated Access to Policies/Disciplinary Standard (Intranet, CSEA Contract) |
| 5-2 | Fair Enforcement of Policies (list of disciplinary actions taken, how fairness kept, names, titles) |
Attachments 6 – Audits
| Code | Documentation Required |
|---|---|
| 6-1 | Audits (Risk Assessments) Conducted (meeting minutes discussing RAs, results summary) |
| 6-2a | Evidence Audits Reviewed (updates to Work Plan, Summary of Internal/External audits) |
| 6-2b | How Audits Designed and Implemented |
| 6-2c | Audits Shared with Board and Committees (dates, memos, minutes) |
| 6-3a | Overpayments (identified, dates of service, dollar value, reasons for overpayment) |
| 6-4 | Annual Review of Compliance Program with Work Plan Evaluations (report, meeting to discuss) |
| 6-5 | Exclusion Lists (minutes discussing, Contracts with requirement to comply, audited contracts) |
| 6-6 | Audits Shared with Compliance Officer |
Attachments 7 – Response to Compliance Issues
| Code | Documentation Required |
|---|---|
| 7-1 | Compliance Issues Detected |
| 7-2 | OMIG Audit Finalized in the Review Period |
| 7-3 | Self-Disclosure and Compliance Agreements with OMIG |
IV. Federal Tort Claims Act (FTCA) – Liability Coverage for Providers
Anyone holding a medical or healthcare related license in New York State must take an active role in seeing their respective departments conduct ongoing Risk Assessments (RAs). RAs are directly linked to liability coverage through the Federal government.
FTCA Coverage
Health center staff “may be deemed to be Federal Employees qualified for protection under FTCA.”
If annual program requirements are met, health centers save millions of dollars that can be invested into health services and to care and fund quality improvement initiatives.
According to the US Department of Health and Human Services, “As Federal employees, the employees of qualified health centers are immune from lawsuits. The Federal government acts as their primary insurer.” In addition, legal representation is provided without charge to the health center.
In order for health centers to benefit from this coverage, the government expects every effort to maintain the highest standard of care. Failure to do so risks losing FTCA coverage. Measuring the standard of care can be achieved, in part, through RAs. RAs are mandatory. Departments, especially Clinical, Dental, and Behavioral Health, must do them on an ongoing basis.
Risk Assessments (RAs)
RAs serve two functions: assisting in identifying risk in departments not clinical in nature, and identifying clinical risks/standard of care which directly impacts FTCA coverage. Clinically driven RAs limit the potential of malpractice. See Appendix D.
V. Doing Business with Hometown Health Centers
Hometown Health Centers sometimes requires the services of carefully screened vendors and consultants. They are selected through a competitive bidding process to provide needed quality products and services at a fair price. In working with Hometown, vendors and consultants cannot be listed on any government Exclusion List. Expectations of doing business with Hometown shall be posted on its website and vendors and consultants shall receive an annual letter regarding expectations in meeting New York State Social Services Law.
Exclusion List
As noted earlier, anyone doing or wishing to do business with Hometown will be checked against government Exclusion Lists before being retained and during the period in which a service or product is used. It is illegal for any vendor or consultant listed on a State or Federal Exclusion List to do business with an entity participating in the Medicare, Medicaid, or other State or Federal healthcare programs.
Abiding by Ethics and Compliance
In addition, each vendor and consultant must be committed to the highest ethical standards. This includes abiding by Hometown’s Compliance Program. All vendors or consultants are required to report any compliance concerns regarding waste, fraud, or abuse at Hometown Health Centers to the Compliance Officer by emailing [email protected] or calling the Compliance Hotline (*67) 518-688-3460.
Business Associate Agreement (BAA)
No vendor handling or having access to Hometown’s Protected Health Information (PHI) or Electronic Health Information (EHI) on behalf of Hometown may do so without a Business Associate Agreement (BAA) in place. See Appendix G.
VI. NYS Social Services Law Summary
Staff, interns, vendors, contractors, and Board Directors must be committed to fighting fraud, waste, and abuse. All entities or persons affiliated with Hometown must adhere to New York Social Services Law § 363-d, which requires a Provider Compliance Program built on the following elements:
- Written Policies and Procedures describing compliance expectations.
- Designate an individual with responsibility for the day-to-day operation of compliance.
- Employees have access to the Compliance Officer.
- Disciplinary policies for not reporting possible problems, participating in non-compliant behavior, and encouraging, directing, facilitating, or permitting non-compliant behavior.
- Routine identification of compliance Risk Areas (clinical, billing, revenue cycle, etc.).
- A process to respond to compliance issues.
- Whistleblower protections.
