OIG Issues New Medicare Advantage Compliance Program Guidance: 15 Compliance Risk Areas
On February 3, 2026, the U.S. Department of Health and Human Services Office of Inspector General (OIG) issued updated Medicare Advantage Industry Segment-Specific Compliance Program Guidance (ICPG). As with other OIG compliance program guidance, the ICPG is recommended, not mandatory. It uses advisory language such as โshould,โ rather than โmust.โ Although it does not carry the force of law, it reflects government expectations and may be referenced in audits, investigations, and enforcement actions (e.g., Corporate Integrity Agreements). Compliance officers for Medicare Advantage (MA) plans should review the ICPG to align their programs with the OIGโs current views on fraud, waste, and abuse (FWA) risk trends. The guidance outlines compliance program expectations and industry โbest practices,โ focusing on risk areas specific to MA and broader managed care operations. It helps plans identify key compliance risk areas, suggests practical mitigation strategies, and offers practical steps on structuring effective compliance and quality programs.
Consistent with the General Compliance Program Guidance (GCPG), the ICPG emphasizes the seven standard elements of an effective compliance program, tailored to the managed care environment, including risks involving capitated payments, utilization management, network oversight, and benefit design. The ICPG identifies specific risk areas that compliance officers should prioritize, including the following:
- Evaluate the compliance program against the GCPG and ICPG to identify areas needing enhancement.
- Ensure the compliance officer reports directly to the CEO and/or the board.
- Update compliance policies and ensure they are accessible and understood by covered parties.
- Assess referral patterns, data accuracy, payment integrity, and care management activities.
- Implement annual, roleโspecific compliance training addressing identified risks and expectations.
- Strengthen the compliance hotline and other reporting channels for suspected nonโcompliance.
- Review marketing practices to prevent misleading conduct and compliance violations.
- Verify that contracts with vendors and providers include robust compliance obligations.
- Conduct due diligence, monitoring, and auditing of firstโtier, downstream, and related entities.
- Ensure timely investigation, reporting, rootโcause analysis, and remediating of compliance issues.
- Conduct annual risk assessments and tailor audit plans to the highest risk areas.
- Enhance monitoring and auditing of high-risk operational functions.
- Document and evidence good-faith implementation of recommended practices.
- Maintain thorough documentation evidencing compliance efforts.
- Provide reports to leadership and the board on identified risks, audit findings, corrective actions, training completion, and emerging issues.
In addition, organizations should consider having an independent effectiveness evaluation of their Compliance Program. An external review can help document and evidence program strengths, identify opportunities for improvement, and support ongoing enhancement efforts.
Interested in hearing more from Richard Kusserow on OIG matters and learning how his expertise can support your organization?ย Link to his bio here or email him at [email protected].
Subscribe to blog