Compliance Program and Monitoring Template
Four documents and three sheets that turn your audit cadence into a ledger, so a skipped cycle shows up as a row, not a broken promise.
Free download · No account needed
Audit Schedule
One row per cycle, since the plan took effect
Illustrative preview. Every cycle the cadence calls for gets a row, including ones nobody ran.
| Cycle | Due Date | Status | Completed |
|---|---|---|---|
The status a policy sentence can't give you
Scheduled, Completed, or Not Performed. A due date with nothing after it is Not Performed, never blank and never "informal review done."
Remaining columns: Area/Scope, Cadence, Findings Count, Report Location.
Every compliance program template for a medical practice looks the same: a Compliance Plan, a Code of Conduct, and a line promising periodic audits. Fill it in and file it, and the practice can point to a document whenever anyone asks about its programme. Nothing in that document can be checked against anything else, which is why the audit it promises so often does not happen.
This pack turns that promise into a ledger. The Audit Schedule gets one row per cycle since the plan's effective date, backfilled rather than started at today, with a status of Scheduled, Completed, or Not Performed and nothing softer available. OIG's own compliance guidance names the failure mode directly: how a practice responds to what it finds is what separates a program that is real from one that is, in OIG's words, more form than substance.
Hartfield Family Medicine, a fictional single-location practice, wrote a semiannual audit cadence into its plan. Two of the four cycles it called for were never run, and the one that did run started 76 days past its own due date. That cycle flagged 5 of 32 sampled Medicare claims for a documentation gap and confirmed $310 in overpayment eleven days after fieldwork ended. 42 U.S.C. § 1320a-7k(d)(2)(A) starts the repayment clock 60 days from that confirmation date, not from the due date, which would already have passed before the finding was even confirmed.
What's in the pack
Compliance Plan
States who holds the compliance role, that they carry no billing or coding responsibility, and points to the Audit Schedule, Reporting Mechanism and Corrective Action Tracker by name rather than restating what each already tracks.
Code of Conduct
The one-to-two-page, all-staff version: the expectation of good-faith reporting, the nonretaliation commitment, and where to take a concern. Pairs with the HIPAA policy set rather than duplicating it.
Auditing and Monitoring Procedure
States the cadence, the sample method, and the routine monitoring list run between cycles, including licensure and exclusion-list checks cross-referenced against the staff training pack's Gap Report rather than re-tracked here.
Reporting Mechanism
How a concern gets raised without a formal hotline: a named contact, a stated method, and a written nonretaliation commitment, plus where the practice sits on anonymity rather than a promise it cannot keep. A report that turns out to involve patient data itself may also need the breach-notification clock running in parallel.
Audit Schedule
One row per audit cycle since the plan's effective date, backfilled rather than started today. Status can only be Scheduled, Completed, or Not Performed, so the practice's real miss rate is a number, not an impression.
Finding Register
Every finding in one place, audit-discovered or staff-reported, each with its own confirmed Identified date kept separate from the fieldwork date that produced it.
Corrective Action Tracker and Audit Cycle Watch
Computes a statutory repayment deadline only from the Identified date, never the audit date, and a weekly read flags any cycle past due and any deadline inside 14 days. Findings caught here are the ones a payer or RAC audit would otherwise catch first.
How to use it
- 1
Open in River, or download it
Open the pack in River and let the agent backfill your real audit history against your plan's own cadence, or download the blank Word and CSV files instantly and work through them yourself.
- 2
Send the cadence and the effective date, not just the next cycle
How often the plan calls for an audit, and when the plan took effect. Without both, the schedule starts counting from today and the miss-rate history is lost before it begins.
- 3
Say which cycles actually happened
Most practices answer this differently than their own written cadence predicts. A cycle with no completed date and no findings count is Not Performed, regardless of what an informal review might have covered.
- 4
Log the confirmation date, not the audit date
When a finding involves money, the statutory clock runs from the day your coder or biller actually confirmed it, typically a week or two after fieldwork ends, never from the fieldwork dates themselves.
Frequently asked questions
Is this template free?
Yes. Download the four documents and three sheets as Word and CSV files with no signup and no card. "Edit with AI" is a separate, optional path for practices that want the agent to backfill the Audit Schedule against their real cadence and history. The rest of the library is at the template library.
Why does a due date with no completed date count as "Not Performed" instead of just staying blank?
Because a blank row reads as not-yet-relevant, and a due date that has already passed is not that. OIG's own guidance for small entities describes a program that documents a cadence and does not perform it as one that is "more form than substance." A blank cell hides that finding; a Not Performed status states it.
What is the difference between the audit date and the Identified date?
The audit or fieldwork date is when a sample was pulled and reviewed. The Identified date is when your coder or biller finished confirming a flagged claim as a true overpayment, typically a week or two later. 42 U.S.C. § 1320a-7k(d)(2)(A) starts the 60-day clock from Identified specifically, and only for Medicare or Medicaid; a private payer's refund runs on its own contract terms instead.
We don't have a formal disclosure hotline. Does that disqualify our reporting mechanism?
No. OIG's guidance for small entities does not require a formal hotline; it expects a named contact, a stated method, and a written nonretaliation commitment, which the Reporting Mechanism document provides. Posting how to reach the HHS OIG Hotline as an external option covers the case a staff member does not want to report internally.
How is this different from the HIPAA security risk assessment's annual reassessment reminder?
That pack re-triggers on an environmental or operational change to systems holding patient data, which is a security-specific clock. This pack's Audit Schedule runs on the practice's own stated billing-audit cadence, a different obligation with its own dates, tracked here rather than folded into the security review.
Does this pack decide whether a claim was actually overpaid?
No. A certified coder or biller makes that determination from the documentation. This pack tracks whether the audit that surfaces the question ran on schedule, and once a finding is confirmed, whether the corrective action stays on track against the deadline that finding actually carries.
What format are the downloaded files?
Word documents for the Compliance Plan, Code of Conduct, Auditing and Monitoring Procedure, and Reporting Mechanism, plus CSV for the Audit Schedule, Finding Register, and Corrective Action Tracker, zipped into one download. They open in Word, Pages, Google Docs, Excel, Numbers and Sheets without a conversion step.
Find out what your own audit cadence actually delivered
Send your compliance plan's stated cadence and effective date. Every cycle since then comes back as a row, marked Completed only where a date and a finding count back it up.
Edit with AI