HIPAA, DEA, OSHA, CLIA, and OIG Compliance Resources for Healthcare Practices

Medical Compliance Center

HIPAA, DEA, OSHA & CLIA
Compliance Resources

Comprehensive compliance guides for healthcare businesses. Build a compliance program that protects your patients, your license, and your practice.

What this page coversHealthcare compliance covers five core areas: HIPAA Privacy and Security Rules (patient data protection), DEA compliance (controlled substance prescribing), OSHA requirements (workplace safety), CLIA certification (in-office testing), and OIG compliance programs (fraud and abuse prevention). This guide covers all five with checklists and action items.
Who this is for: Clinic owners, telehealth operators, med spa directors, healthcare entrepreneurs, and practice administrators building or auditing their compliance programs.
Disclaimer: This guide is for educational purposes only and does not constitute legal advice. Healthcare compliance requirements vary by state, practice type, and specialty. Consult a qualified healthcare attorney and compliance professional for guidance specific to your situation.

HIPAA Privacy and Security Rules: The Foundation

HIPAA establishes national standards for the protection of Protected Health Information (PHI). Every covered entity (healthcare provider, health plan, healthcare clearinghouse) and their business associates must comply.

The Privacy Rule governs the use and disclosure of PHI. Key requirements: Notice of Privacy Practices (NPP), minimum necessary standard, patient rights (access, amendment, accounting of disclosures), and restrictions on marketing uses of PHI.

The Security Rule establishes standards for protecting electronic PHI (ePHI). Key requirements: Security Risk Analysis (SRA), administrative safeguards (policies, training, workforce management), physical safeguards (facility access controls, workstation security), and technical safeguards (access controls, audit controls, encryption, transmission security).

The Breach Notification Rule requires covered entities to notify affected individuals, HHS, and (for large breaches) the media within 60 days of discovering a breach of unsecured PHI.

  • Notice of Privacy Practices (NPP) posted and provided to patients
  • Business Associate Agreements (BAAs) signed with all vendors handling PHI
  • Annual Security Risk Analysis (SRA) completed and documented
  • HIPAA Privacy and Security policies and procedures documented
  • Workforce HIPAA training completed and documented annually
  • Breach notification procedures documented and tested
  • Patient rights procedures implemented (access, amendment, accounting)
  • Minimum necessary standard applied to PHI use and disclosure
Enforcement Note: The OCR (Office for Civil Rights) has significantly increased HIPAA enforcement activity. Practices without a current Security Risk Analysis are among the most common enforcement targets.

DEA Compliance for Healthcare Providers

DEA compliance is required for all providers who prescribe, dispense, or administer controlled substances. The DEA Diversion Control Division enforces the Controlled Substances Act and has broad authority to investigate, audit, and sanction providers.

Key DEA Compliance Requirements: - Valid DEA registration in each state of practice - Compliance with DEA record-keeping requirements (Schedule II records: 2 years; Schedule III–V: 2 years) - Proper storage of controlled substances (Schedule II: locked cabinet; Schedule III–V: locked cabinet or dispersed among non-controlled stock) - Compliance with prescription requirements (patient name, date, drug, quantity, directions, prescriber signature) - Reporting of theft or significant loss (DEA Form 106) within 1 business day of discovery - Biennial inventory of all controlled substances

Telehealth Prescribing: The Ryan Haight Act and DEA Special Registration rules govern controlled substance prescribing via telemedicine. Consult current DEA guidance before prescribing controlled substances via telehealth.

Schedule a Healthcare Strategy Session

Get Started

OSHA Requirements for Medical Practices

OSHA establishes workplace safety standards that apply to healthcare settings. Medical practices are subject to OSHA inspection and can face significant penalties for violations.

Bloodborne Pathogens Standard (29 CFR 1910.1030): The most important OSHA standard for medical practices. Requires: written Exposure Control Plan, hepatitis B vaccination offered to at-risk employees, personal protective equipment (PPE), sharps injury log, post-exposure evaluation and follow-up, and annual training.

Hazard Communication Standard (HazCom/GHS): Requires: Safety Data Sheets (SDS) for all hazardous chemicals, chemical inventory, employee training on chemical hazards, and proper labeling.

General Duty Clause: Requires employers to provide a workplace free from recognized hazards. Applies to any workplace hazard not covered by a specific OSHA standard.

OSHA Recordkeeping: Practices with 10+ employees must maintain OSHA 300 Log of Work-Related Injuries and Illnesses and post the OSHA 300A Summary annually.

CLIA Compliance for In-Office Testing

The Clinical Laboratory Improvement Amendments (CLIA) regulate all laboratory testing performed on humans. Medical practices that perform in-office laboratory testing must obtain CLIA certification and comply with ongoing requirements.

Certificate of Waiver Requirements: Even the simplest CLIA certificate requires: following manufacturer instructions for each test, using quality control materials as specified, maintaining records of test results and QC, and reporting to CMS upon request.

Moderate and High Complexity Requirements: Add: personnel qualifications, proficiency testing (PT) enrollment and participation, quality assessment program, and more extensive documentation.

CLIA Inspections: CMS and state health departments conduct CLIA inspections. Deficiencies can result in civil monetary penalties, suspension of CLIA certificate, or cancellation of Medicare/Medicaid billing privileges.

OIG Compliance Programs: Building Your Framework

The Office of Inspector General (OIG) has published compliance program guidance for various healthcare settings. An effective compliance program is the best defense against fraud and abuse allegations.

The Seven Elements of an Effective Compliance Program (OIG): 1. Written policies and procedures 2. Compliance officer and compliance committee 3. Effective training and education 4. Effective lines of communication 5. Internal monitoring and auditing 6. Response to detected problems 7. Enforcement of disciplinary standards

For small practices, a scaled-down compliance program is appropriate — but the core elements must be present. At minimum: written compliance policies, annual training, a mechanism for reporting concerns, and a process for responding to identified problems.

  • Written compliance policies and procedures documented
  • Compliance officer designated (can be the owner/physician in small practices)
  • Annual compliance training completed and documented for all staff
  • Billing and coding audit conducted annually
  • Mechanism for reporting compliance concerns established (hotline, email, or open-door policy)
  • Process for investigating and responding to compliance concerns documented
  • OIG Exclusion List checked for all new hires and contractors
  • Compliance program reviewed and updated annually

Need a Medical Director?

Get Started

Billing and Coding Compliance

Billing and coding compliance is one of the highest-risk areas for healthcare practices. False Claims Act violations, Anti-Kickback Statute violations, and Stark Law violations can result in exclusion from Medicare and Medicaid, civil monetary penalties, and criminal prosecution.

Key Billing Compliance Areas: - Accurate CPT and ICD-10 coding that reflects documented services - Medical necessity documentation for all billed services - Compliance with payer-specific billing rules and frequency limits - Proper use of modifiers - Compliance with incident-to billing rules for mid-level providers - Compliance with split/shared visit rules - Proper handling of overpayments (60-day repayment rule)

Annual Billing Audit: Conduct an annual internal billing audit — or hire an external auditor — to identify coding errors, documentation gaps, and compliance risks before a payer audit does.

Build the infrastructure behind your clinic.

AJ Pakpour advises physicians, NPs, PAs, clinic owners, and healthcare entrepreneurs on compliance, operations, and growth.

Frequently Asked Questions

What is a HIPAA Business Associate Agreement?

A Business Associate Agreement (BAA) is a HIPAA-required contract between a covered entity and a vendor that handles Protected Health Information (PHI) on their behalf. BAAs are required with EMR vendors, billing companies, cloud storage providers, and telehealth platforms.

What are the penalties for HIPAA violations?

HIPAA violations can result in civil monetary penalties ranging from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category. Criminal penalties can include fines up to $250,000 and imprisonment.

Does my telehealth practice need a compliance program?

Yes. All healthcare providers, including telehealth practices, should have a compliance program. Telehealth practices face specific compliance risks including state licensure compliance, prescribing regulations, billing and coding compliance, HIPAA compliance for telehealth technology, and DEA compliance.

What is the OIG Exclusion List?

The OIG Exclusion List (LEIE — List of Excluded Individuals and Entities) contains individuals and entities excluded from participation in Medicare, Medicaid, and other federal healthcare programs. Practices must check the LEIE before hiring any employee or contractor and monthly thereafter. Employing an excluded individual can result in significant civil monetary penalties.

What is the Anti-Kickback Statute?

The Anti-Kickback Statute (AKS) prohibits offering, paying, soliciting, or receiving anything of value to induce or reward referrals of items or services covered by federal healthcare programs. Violations can result in criminal prosecution, civil monetary penalties, and exclusion from Medicare and Medicaid.

What is the Stark Law?

The Stark Law (Physician Self-Referral Law) prohibits physicians from referring patients for certain designated health services (DHS) to entities with which the physician or an immediate family member has a financial relationship, unless an exception applies. Violations can result in denial of payment, refund of payments received, and civil monetary penalties.

How often should I conduct a HIPAA Security Risk Analysis?

HIPAA requires a Security Risk Analysis (SRA) to be conducted periodically — at minimum annually, and whenever there are significant changes to your practice environment (new technology, new locations, new workflows). The SRA must be documented and used to drive your security program.

What is the False Claims Act?

The False Claims Act (FCA) imposes liability on individuals and entities that submit false or fraudulent claims to the federal government, including Medicare and Medicaid. Penalties include treble damages (3x the amount of the false claim) plus per-claim penalties. The FCA also has a whistleblower (qui tam) provision that allows private individuals to file suits on behalf of the government.

Do I need a compliance officer?

The OIG recommends that all healthcare practices designate a compliance officer. For small practices, this can be the owner, physician, or office manager. The compliance officer is responsible for implementing and overseeing the compliance program, conducting training, and responding to compliance concerns.

What should I do if I discover a billing error?

If you discover a billing error that resulted in an overpayment from Medicare or Medicaid, you are required to report and return the overpayment within 60 days of identification. Failure to do so can result in False Claims Act liability. For commercial payer overpayments, follow the payer's specific refund procedures.

Recommended Professional References

The following authoritative resources are recommended for healthcare professionals, clinic owners, compliance officers, and entrepreneurs working in this area. Links open official external websites.

Office of Inspector General

Federal oversight resources for healthcare fraud, abuse, and compliance.

ComplianceFree

Best for: OIG guidance and exclusion screening

Centers for Medicare & Medicaid Services

Federal program rules, provider requirements, and billing guidance.

RegulationFree

Best for: Medicare and Medicaid compliance

HHS Office for Civil Rights

Official HIPAA privacy, security, and enforcement information.

HIPAAFree

Best for: Privacy and security compliance

Drug Enforcement Administration

Controlled-substance registration and diversion-control resources.

DEA complianceFree

Best for: Controlled-substance compliance

Occupational Safety and Health Administration

Workplace safety standards and healthcare employer guidance.

Workplace safetyFree

Best for: OSHA program requirements

Federal Trade Commission

Consumer-protection and advertising compliance guidance.

AdvertisingFree

Best for: Marketing and consumer-protection rules

Food and Drug Administration

Federal information on regulated products, labeling, and promotion.

Product regulationFree

Best for: FDA-regulated product guidance

ABA Health Law Section

Professional legal education and healthcare law resources.

Legal educationFree + Paid

Best for: Healthcare legal developments

Healthcare Compliance Services Book a Strategy Session