River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Compliance Program and Monitoring Template

Four documents and three sheets that turn your audit cadence into a ledger, so a skipped cycle shows up as a row, not a broken promise.

Free download  ·  No account needed

Audit Schedule

One row per cycle, since the plan took effect

Illustrative preview. Every cycle the cadence calls for gets a row, including ones nobody ran.

CycleDue DateStatusCompleted
    
    

The status a policy sentence can't give you

Scheduled, Completed, or Not Performed. A due date with nothing after it is Not Performed, never blank and never "informal review done."

Remaining columns: Area/Scope, Cadence, Findings Count, Report Location.

Every compliance program template for a medical practice looks the same: a Compliance Plan, a Code of Conduct, and a line promising periodic audits. Fill it in and file it, and the practice can point to a document whenever anyone asks about its programme. Nothing in that document can be checked against anything else, which is why the audit it promises so often does not happen.

This pack turns that promise into a ledger. The Audit Schedule gets one row per cycle since the plan's effective date, backfilled rather than started at today, with a status of Scheduled, Completed, or Not Performed and nothing softer available. OIG's own compliance guidance names the failure mode directly: how a practice responds to what it finds is what separates a program that is real from one that is, in OIG's words, more form than substance.

Hartfield Family Medicine, a fictional single-location practice, wrote a semiannual audit cadence into its plan. Two of the four cycles it called for were never run, and the one that did run started 76 days past its own due date. That cycle flagged 5 of 32 sampled Medicare claims for a documentation gap and confirmed $310 in overpayment eleven days after fieldwork ended. 42 U.S.C. § 1320a-7k(d)(2)(A) starts the repayment clock 60 days from that confirmation date, not from the due date, which would already have passed before the finding was even confirmed.

Every document in the pack

The audit ledger, the finding log, and the corrective-action clock anchored to the right date.

Audit Schedule

Illustrative history for a fictional practice, Hartfield Family Medicine, semiannual cadence since January 15, 2024.

CycleDue DateStatusCompletedFindings
AC-2024-H22024-07-15Not Performed
AC-2025-H12025-01-15Completed2025-01-220
AC-2025-H22025-07-15Not Performed
AC-2026-H12026-01-15Completed, late2026-04-035
AC-2026-H22026-07-15Scheduled

2 of the 4 cycles due were never run at all. A 50% miss rate against the practice's own written cadence, the exact gap between a documented program and a performed one. The one cycle that did run still counts as Completed, not because it was on time, 76 days late, but because it has a completed date and a findings count on record.

Finding Register

One log for every finding, whether an audit found it or someone reported it.

FindingSourceRecordsDollar ImpactIdentified
FR-2026-01Audit AC-2026-H15 of 32$3102026-04-14
FR-2025-11Staff report2$02025-11-06

Fieldwork for AC-2026-H1 ended April 3. The coder and biller did not confirm the 5 claims as true overpayments until April 14, eleven days later. 2026-04-14, not April 3 and not the cycle's January 15 due date, is what the register records as Identified, since that is the date Hartfield actually determined it had received an overpayment.

Corrective Action Tracker

The clock starts from Identified. Nowhere else.

ActionFindingTypeDeadline BasisDeadlineStatus
CA-2026-01FR-2026-01Repayment60 days from Identified, 42 U.S.C. 1320a-7k(d)2026-06-13On Track
CA-2026-02FR-2026-01Process ChangeInternal target only2026-05-01On Track
CA-2025-03FR-2025-11Process ChangeNot an overpayment2025-11-20Closed

The anchor date moves the deadline in both directions. From fieldwork's April 1 start, the clock reads May 31, thirteen days early. From the cycle's own January 15 due date, it reads March 16, a full month before the finding was even confirmed. Only April 14, the date a person actually confirmed the overpayment, is the date the statute names.

What's in the pack

01

Compliance Plan

States who holds the compliance role, that they carry no billing or coding responsibility, and points to the Audit Schedule, Reporting Mechanism and Corrective Action Tracker by name rather than restating what each already tracks.

02

Code of Conduct

The one-to-two-page, all-staff version: the expectation of good-faith reporting, the nonretaliation commitment, and where to take a concern. Pairs with the HIPAA policy set rather than duplicating it.

03

Auditing and Monitoring Procedure

States the cadence, the sample method, and the routine monitoring list run between cycles, including licensure and exclusion-list checks cross-referenced against the staff training pack's Gap Report rather than re-tracked here.

04

Reporting Mechanism

How a concern gets raised without a formal hotline: a named contact, a stated method, and a written nonretaliation commitment, plus where the practice sits on anonymity rather than a promise it cannot keep. A report that turns out to involve patient data itself may also need the breach-notification clock running in parallel.

05

Audit Schedule

One row per audit cycle since the plan's effective date, backfilled rather than started today. Status can only be Scheduled, Completed, or Not Performed, so the practice's real miss rate is a number, not an impression.

06

Finding Register

Every finding in one place, audit-discovered or staff-reported, each with its own confirmed Identified date kept separate from the fieldwork date that produced it.

07

Corrective Action Tracker and Audit Cycle Watch

Computes a statutory repayment deadline only from the Identified date, never the audit date, and a weekly read flags any cycle past due and any deadline inside 14 days. Findings caught here are the ones a payer or RAC audit would otherwise catch first.

How to use it

  1. 1

    Open in River, or download it

    Open the pack in River and let the agent backfill your real audit history against your plan's own cadence, or download the blank Word and CSV files instantly and work through them yourself.

  2. 2

    Send the cadence and the effective date, not just the next cycle

    How often the plan calls for an audit, and when the plan took effect. Without both, the schedule starts counting from today and the miss-rate history is lost before it begins.

  3. 3

    Say which cycles actually happened

    Most practices answer this differently than their own written cadence predicts. A cycle with no completed date and no findings count is Not Performed, regardless of what an informal review might have covered.

  4. 4

    Log the confirmation date, not the audit date

    When a finding involves money, the statutory clock runs from the day your coder or biller actually confirmed it, typically a week or two after fieldwork ends, never from the fieldwork dates themselves.

Frequently asked questions

Is this template free?

Yes. Download the four documents and three sheets as Word and CSV files with no signup and no card. "Edit with AI" is a separate, optional path for practices that want the agent to backfill the Audit Schedule against their real cadence and history. The rest of the library is at the template library.

Why does a due date with no completed date count as "Not Performed" instead of just staying blank?

Because a blank row reads as not-yet-relevant, and a due date that has already passed is not that. OIG's own guidance for small entities describes a program that documents a cadence and does not perform it as one that is "more form than substance." A blank cell hides that finding; a Not Performed status states it.

What is the difference between the audit date and the Identified date?

The audit or fieldwork date is when a sample was pulled and reviewed. The Identified date is when your coder or biller finished confirming a flagged claim as a true overpayment, typically a week or two later. 42 U.S.C. § 1320a-7k(d)(2)(A) starts the 60-day clock from Identified specifically, and only for Medicare or Medicaid; a private payer's refund runs on its own contract terms instead.

We don't have a formal disclosure hotline. Does that disqualify our reporting mechanism?

No. OIG's guidance for small entities does not require a formal hotline; it expects a named contact, a stated method, and a written nonretaliation commitment, which the Reporting Mechanism document provides. Posting how to reach the HHS OIG Hotline as an external option covers the case a staff member does not want to report internally.

How is this different from the HIPAA security risk assessment's annual reassessment reminder?

That pack re-triggers on an environmental or operational change to systems holding patient data, which is a security-specific clock. This pack's Audit Schedule runs on the practice's own stated billing-audit cadence, a different obligation with its own dates, tracked here rather than folded into the security review.

Does this pack decide whether a claim was actually overpaid?

No. A certified coder or biller makes that determination from the documentation. This pack tracks whether the audit that surfaces the question ran on schedule, and once a finding is confirmed, whether the corrective action stays on track against the deadline that finding actually carries.

What format are the downloaded files?

Word documents for the Compliance Plan, Code of Conduct, Auditing and Monitoring Procedure, and Reporting Mechanism, plus CSV for the Audit Schedule, Finding Register, and Corrective Action Tracker, zipped into one download. They open in Word, Pages, Google Docs, Excel, Numbers and Sheets without a conversion step.

Find out what your own audit cadence actually delivered

Send your compliance plan's stated cadence and effective date. Every cycle since then comes back as a row, marked Completed only where a date and a finding count back it up.

Edit with AI