Compliance for Governing Boards
A Governing Board is a committee that leads a health care organization’s compliance and quality oversight efforts. Governing Boards have a critical oversight role to play in ensuring that health care organizations operate in compliance with Federal health care program requirements and provide high quality care. Governing Boards are often required for an organization to receive Federal health care payments.
Course Objectives
By the end of this course, you will be able to:
- explain the role of Governing Boards in providing compliance oversight and
- describe OIG’s four recommendations to Governing Boards for effectively exercising their oversight responsibilities.
Resources to Help You
In this course, you will find links to a job aid and helpful resources. If you miss a resource as you go through the training, you can find them all in the Helpful Resources lesson of the course.
What are Governing Boards?
What are Governing Boards?
A Governing Board is a committee that leads a health care organization’s compliance and quality oversight efforts. Tribes, Tribal organizations, Indian Health Service (IHS), and nonprofit corporations, such as Urban Indian Health programs, provide health care to American Indian and Alaska Native (AI/AN) communities. As such, these providers’ Governing Boards may consist of elected Tribal leaders, civil servants, individuals appointed by elected officials, volunteers, and community leaders. For example, IHS Area Offices lead Governing Boards that consist of IHS leaders, IHS hospital executives, and local Tribal Leaders. These Governing Boards oversee compliance and quality of care at IHS hospitals.
Are Governing Boards Required?
The Centers for Medicare & Medicaid Services (CMS) has standards with which health care facilities must comply to receive Medicare and Medicaid payments. These standards, called Conditions of Participation (CoPs), apply to IHS and tribally operated hospitals which bill Medicare and Medicaid. The CoPs require that providers have a governing body that assumes responsibility for the entity’s compliance with Federal health care program requirements. The CoPs can be met through a Governing Board’s exercise of its oversight responsibilities. Similar requirements for other types of facilities may be found elsewhere in statutes or regulation. Below, and at the end of this course, is a list of references to governance-related requirements for a variety of types of health care organizations.
Other types of facilities, such as clinics run by tribes, are often subject to other sets of regulations, such as those for Tribal Medicare Federally Qualified Health Centers, that may not require governing boards, but which still establish minimum governance requirements.
Governing Board Roles and OIG Recommended Actions
What do Governing Boards Do?
Governing Boards take an oversight role to ensure that health care organizations operate in compliance with Federal health care program requirements and provide high-quality care.
A Governing Board carries what is called the duty of care in its oversight of its facility. In order to satisfy the duty of care, a Governing Board must engage in reasonable inquiry by asking questions of the leaders of the organization. For example, a Governing Board may ask a department that oversees quality of care about its reporting system for adverse events to ensure the system collects the appropriate data.
Reasonable inquiry also ensures that appropriate information regarding compliance with applicable laws, including Federal health care program laws, will come to the Governing Board’s attention in a timely manner. Members of Governing Board can, in good faith, rely on leaders in whom the Governing Board has confidence. However, at the same time, members cannot be passive recipients of information. Asking thoughtful questions and inquiring further when presented with information that causes or should cause concern enables Governing Boards to exercise their duty of care. OIG recommends that all health care oversight bodies take this approach.
OIG Recommended Actions to Help Governing Boards in Their Oversight Duties
The OIG recommends four actions that Governing Boards can take to help them in their oversight duties, and to assist them in their reasonable inquiries to meet their duty of care. These are:
The next few pages will describe each action in more detail.
Recommended Action #1: Regularly Meet with the Compliance Officer
OIG recommends that Governing Boards regularly meet publicly and privately with the Compliance Officer.
Click the tabs to learn more...
OIG recommends Governing Boards have a regular time on
their meeting agendas for the Compliance Officer to provide
a report on the compliance program and specific compliance
matters that the Compliance Officer believes the Governing
Board should know.
OIG also recommends that Governing Boards set aside time at every
meeting to meet privately with the Compliance Officer. This provides
the Compliance Officer an opportunity to speak freely with Governing
Board members.
During this time, the Governing Board can ask questions designed to
ensure that the Compliance Officer has sufficient resources to fulfill
their responsibilities and give the Compliance Officer the opportunity to
inform the Governing Board of any sensitive details that the
Compliance Officer may not wish to reveal in front of the other
non-member meeting attendees.
Below and at the end of this course, we provide a list of sample
questions that Governing Boards may wish to ask Compliance Officers
during these private sessions.
These two activities—regularly hearing from the Compliance Officer during Governing Board meetings and meeting with the Compliance Officer privately—accomplish several goals, which include:
- enabling the Governing Board to hear about the organization’s compliance program from the person responsible for operating it and
- conveying to other organization leaders the importance both of compliance generally and the Compliance Officer as a leader within the organization.
The job aid below contains sample questions the Governing Boards can ask the Compliance Officer.
Job Aid
Recommended Action #2: Routinely Ask Other Organizational Leaders About Compliance
Although operating the compliance program is the Compliance Officer’s responsibility, other organizational leaders should incorporate compliance into their decisions. Therefore, OIG recommends that Governing Board members routinely ask leaders in the organization, such as facility administrators, and leaders of other health care organizations, such as heads of Tribal departments of health and human services as well as Tribal councils, questions about compliance requirements and risks in their area.
OIG believes that asking other leaders in the organization how they ensure their actions are compliant conveys the importance that the Governing Board places on compliance throughout the organization. If the Governing Board routinely asks leaders about the compliance risks of the organization’s actions, leaders are more likely to regularly ask these questions of their staff and incorporate a compliance analysis into their decision-making.
Recommended Action #3: Obtain Information from Multiple Sources
OIG recommends that Governing Boards obtain information from as many sources as possible, with a focus on information from the leaders who support the organization and protect it from risk. OIG recommends that this include information from departments such as those listed below.
Legal departments might provide information such as new Federal regulations that apply to the health care organization or require a change in operations.
Audit departments might provide information such as fiscal risk reports, yearly budgets, and suggestions for monetary improvements.
Quality of Care departments might provide information such as trends resulting from Patient Satisfaction Surveys, or high-risk adverse events areas.
Human Resource departments might provide information such as percentage of all nurses who have advanced certifications, and the percentage of those who are at risk of losing those certifications if they do not retake the recertification course.
Information Technology departments might provide information such as opportunities to improve electronic medical records and secure data.
Security and Privacy departments might provide information such as the extent to which the organization faces data breaches of personally identifiable information.
Obtaining information from multiple sources will enable the Governing Board to form a more comprehensive picture of the risks the organization faces. It will also enable the Governing Board to determine whether the leaders and departments that have a responsibility to identify risk areas and potential harm to the organization are collaborating appropriately and whether organizational leaders are being appropriately informed of potential harm and taking appropriate action to prevent or mitigate the harm.
Recommended Action #4: Regularly Review Organizational Risk Data and Information
OIG recommends that Governing Boards regularly review how the entity is performing in key areas, and what the trends are over time. Ideally, such a review would examine data covering financial strength, operational effectiveness, clinical quality, and patient satisfaction. A balance of metrics can show the links between quality, compliance, and financial performance.
OIG recommends that the Governing Board ensures:
- it understands how the metrics were chosen,
- it understands what the metrics measure, and
- that the organization is setting ambitious quality targets
Course Summary
A Governing Board is a committee that leads a health care organization’s compliance and quality oversight efforts. AI/AN Governing Boards may consist of elected Tribal leaders, civil servants, and individuals appointed by elected officials.
OIG believes that Governing Boards of health care organizations have a vital oversight role to ensure compliance with Federal health care requirements and the provision of high-quality care.
The OIG recommends four actions that Governing Boards can take to help them in their oversight duties. These are:
- regularly meet with the Compliance Officer,
- routinely ask other leaders about compliance,
- obtain information from multiple sources, and
- regularly review organizational risk data and information.
Resources to Help You
OIG provides guidance to health care entities on the oversight role of Governing Boards in compliance. Although the guidance focuses on the role of Governing Boards in a corporate context, Governing Bodies of tribal and other public health care entities may also find the guidance useful because they serve a similar oversight role for compliance and quality. Download the PDF below to access the links to these resources.
Additional Trainings
After you complete this training, consider taking our additional compliance related trainings that can be found on our website. Below are three courses in which you may be interested.
Compliance 101: This training gives an overview of compliance, what it is, why it is important, who is responsible for it, where and when it happens, and how to get started with a compliance program for your organization. If you have not thought about compliance before, this training is a great place to start.
Compliance 201 courses: These two trainings—one for health care providers and one for grantees— go into greater depth than Compliance 101. They focus on the Seven Fundamentals of Compliance; important Federal health care, grants, and contract fraud and abuse laws; and the remedies available to the Government if an entity commits violations.
Job Aids
Knowledge Check
Please take the short knowledge check assessment by clicking the link below. After you answer questions about what you’ve learned, you’ll be asked a few questions that can help us improve this course in the future. After you click submit, you’ll receive your Certificate of Completion. Let’s evaluate your learning!