Accountable Health Partners Compliance Plan
Accountable Health Partners Compliance Plan
01.0 – Compliance Plan
AHP’s Compliance Policy established the framework for maintaining compliance with all Federal and New York State laws, requirements, and standards for Medicare program participation as a Medicare Advantage plan sponsor, Accountable Care Organization (ACO), or otherwise contracted entity with the Center for Medicare and Medicaid Services (CMS) and as required by contract with a Medicare Advantage plan as a First Tier, Downstream, and Related Entity (FDR). This policy defines the current Compliance Plan that operationalizes the Compliance Policy.
The following areas will be covered in the Compliance Plan:
01.01 Scope and Applicability
01.02 Governance and Oversight
01.03 Core Compliance Plan Elements
01.04 Compliance Plan Operations
01.05 Non-Retaliation Policy
01.06 Training and Education
01.07 Documentation and Record Retention
01.08 Annual Review and Updates
01.10 Appendices
01.01 Scope and Applicability
Objective: To ensure the policy establishes the scope, roles, and responsibilities in the Compliance Plan.
The Compliance Plan applies to all AHP employees whose responsibilities include any Medicare program or program participant. The Compliance Plan also applies to providers and contractors who provide Medicare plan-covered health care services to AHP-attached members through direct contract with CMS or as a delegate of another Medicare Advantage plan. The Compliance Plan is made available to all Medicare participants attributed to AHP.
Health Insurance Portability and Accountability Act (HIPAA) compliance is excluded from the scope of this policy and managed under a separate set of Privacy Policies; however, compliance with privacy policies may be referenced in the Standards of Conduct and Compliance Training.
01.02 Governance and Oversight
Objective: To ensure the Compliance Plan establishes the roles and responsibilities for implementing and managing the activities that fall within legal and regulatory requirements for participation with Federal Medicare health programs in New York State.
AHP Board of Managers
The AHP Board of Managers has the ultimate responsibility for the Compliance Plan. These are the specific responsibilities of the Board of Managers:
- Appoints the Compliance Officer; the Compliance Officer reports administratively to the AHP Chief Executive Officer but can only be appointed to or removed from the position by the AHP Board of Managers.
- Receives and reviews the quarterly reports from the Compliance Officer, including the status of all identified or reported potential compliance incidents.
- Reviews the Compliance Plan annually; approves the plan or returns it to the Compliance Committee through the Compliance Office for additional information or revision.
- Reviews and approves the Standards of Conduct.
- Requests an investigation or audit related to compliance through the Compliance Officer at their discretion.
- Ensures there is adequate funding and resources to implement the Compliance Plan.
- Appoints a new Compliance Officer promptly in the event of staff turnover; ensures continuity in the administration of the Compliance Plan by appointing a replacement within 14 days of vacancy or delegating to the AHP CEO the appointment of an interim Compliance Officer to serve until the next regular meeting of the Board.
Individual Members are responsible to:
- Serve as role models for the Standards of Conduct.
- Recuse themselves from any discussion or voting when a conflict of interest may exist; seek or receive counsel from the Compliance Officer on potential conflicts of interest.
Compliance Officer
The Compliance Officer has expressed authority to provide unfiltered, in-person reports to the CEO or to the Board of Managers.
Requirements for the position of Compliance Officer include, but are not limited to:
- Must be an employee of AHP or an affiliate organization.
- May not be an attorney serving as legal counsel to AHP.
- May not be an employee of an FDR.
- May have responsibilities in addition to the Compliance Officer role.
The Compliance Officer’s responsibilities include:
- Provides leadership for the Compliance Plan.
- Acts as a resource and provides guidance on laws, regulations, and policies applicable to the Compliance Plan.
- Chairs Compliance Committee meetings.
- Reports on identified, in process, or resolved compliance issues to the Compliance Committee.
- Establishes monitoring mechanisms such as audits and routine reporting.
- Oversight of the development of compliance training, including updates when indicated. Compliance training will include, at a minimum, what constitutes program violations, how to identify program violations, examples of Fraud, Waste, and Abuse, and how to report potential compliance issues or concerns.
- Oversight of the completion of compliance training of employees at least annually; and completion of compliance training by delegates, contractors, and other individuals or entities performing functions or services related to activities as between the AHP and frequently as defined in service contracts or as determined necessary by the Compliance Officer.
- Makes compliance training accessible to Medicare beneficiaries/participants.
- Maintains a method for employees or contractors, Medicare beneficiaries/participants, providers/suppliers, and other individuals or entities performing functions or services related to contracted activities to anonymously report suspected problems to the compliance officer.
- Acts directly, or delegates to the appropriate party, to address all potential compliance issues, and reports on the same to the Compliance Committee.
- Evaluates the effectiveness of the Compliance Plan.
- Facilitates the report of probable violations of law to an appropriate law enforcement agency.
In addition, the Compliance Officer supports all FDR compliance responsibilities and addresses any audit findings or concerns presented by CMS or a Medicare Advantage organization with whom AHP contracts.
Compliance Committee
The Compliance Committee operates under the authority of AHP’s Board of Managers. It has the authority to investigate compliance concerns, request information from management or participants, establish an ad hoc committee to assist with the investigation, make recommendations for corrective action, and oversee ongoing monitoring of activities and the effectuation of corrective actions. The Compliance Plan shall be regularly reviewed by the Compliance Committee and updated by the AHP Board of Managers via a formal, documented process.
The Committee shall be comprised of employees with authority and knowledge to understand compliance requirements, assess risks, and facilitate recommendations to reduce or eliminate risk and maintain compliance. Employees with specialized expertise may be invited as advisory/non-voting members. The committee shall meet quarterly or more often as required, with an established quorum. Committee minutes shall be recorded, approved at the next meeting, and retained for at least 10 years. Committee recommendations flow to the Board of Managers through the Compliance Officer’s reports. The Committee shall maintain a charter that describes the membership, quorum required for meetings, responsibilities, and reporting.
01.03 Core Compliance Plan Elements
Objective: To ensure AHP operates a compliance program as defined in Federal regulations at 42 C.F.R. §§422.503 and 423.504, applicable New York’s Public Health Law, and high ethical standards.
AHP operates a compliance program with the following core elements:
Written Compliance Plan
AHP maintains a compliance plan, evaluated and updated annually, and approved by the Board of Managers. AHP also periodically reviews and approves, as required, companion policies, procedures, job and role descriptions, committee charters, training materials, and reports to provide guidance, implement, and evaluate the annual Compliance Plan.
Designated Compliance Officer
The Compliance Officer reports administratively to the AHP Chief Executive Officer but can only be appointed to or removed from the position by the AHP Board of Managers. The Compliance Officer has expressed authority to provide unfiltered, in-person reports to the CEO or to the Board of Managers. The Compliance Officer appointed for 2026 is Joshua Miller.
The Compliance Officer is supported by the Compliance Committee as described above in the governance section.
Compliance Training and Education
AHP administers required training on the compliance program using established effective training modalities as part of employee orientation to new staff and on appointment of a new chief executive, compliance officer, manager, and board members, and annually thereafter for all staff.
Mechanisms for Identifying and Reporting Potential Compliance Issues
Potential compliance issues and incidents can be identified through internal monitoring and audits and, as appropriate, external audits, to evaluate AHP and its FDR partners for compliance with CMS requirements and the AHP compliance program. AHP department leaders are required to perform periodic risk assessments of their own operational areas, but each assessment will be reviewed by the Compliance Officer and may be returned for additional assessment or documentation or may be repeated by the Compliance Officer or his/her delegate. Routine reporting is reviewed by the Compliance Officer to identify patterns of potential fraud, waste, or abuse, or other types of compliance incidents. The Compliance Officer, his/her delegate or external vendor maintains a schedule of internal audits of AHP departments and FDRs. The schedule may be aligned to those areas with the highest potential risk. The overall results of monitoring and audits drive the evaluation of the AHP compliance program’s effectiveness.
AHP ensures that persons can report potential compliance issues. The reporting options by cohort are described below.
- Employees’ annual compliance training includes the name, email address, and phone number of the Compliance Officer. In addition, AHP maintains a helpline (585-756-8888) for anonymous reports. The Compliance Helpline is available 24 hours a day, 7 days a week, 365 days a year, and is monitored by the Compliance Officer. In addition, AHP has an “open door” policy that allows employees to approach any member of management with a compliance concern.
- Contractors and Vendors: AHP requires contractors and vendors (FDRs) to complete the annual compliance training, and therefore, they have the same mechanisms of contacting the Compliance Office or calling the Compliance helpline as employees.
- Medicare Participants and other external stakeholders, such as conservators, family members, caregivers, and clergy, are advised of compliance reporting options on the AHP website. These options include, but are not limited to, contacting the Compliance Officer, contacting the customer or billing representative, and calling the Compliance helpline. Medicare beneficiaries retain all rights to report any concern directly to CMS.
Handling of Potential Compliance Issues
AHP promptly responds to potential compliance issues as they are identified or otherwise raised. Depending on the issue, the investigation may require data reporting, auditing, interviews with key employees, providers, or participants, or engaging an external auditor. Any investigation is focused on timely verification if an issue exists or an incident has occurred, action to reduce the potential for recurrence, and ensure ongoing compliance with CMS requirements.
If the investigation reveals evidence of misconduct related to payment or delivery of items or services under the contract, AHP will implement corrective actions. (e.g., repayment of overpayments, disciplinary actions against responsible employees). The Compliance Officer will voluntarily self-report to CMS any verified fraud or misconduct related to a Medicare Advantage product contracted by CMS to AHP. The Compliance Officer will report other compliance issues, including the inappropriate prescribing of opioids and concerning investigations and credible evidence of suspicious activities of a provider of services, as required in CFR 42 IV § 422.503 (b)(4)(vi)(G). The Compliance Officer documents all potential issues and incidents for follow-up, trending, and reporting to the Compliance Committee.
01.04 Compliance Program Operations
Policy and Procedures Management
Compliance policies and procedures are maintained by the Compliance Officer, with review and approval by the Board of Managers. Policies are updated at least every two years, with more frequent updates as indicated by changes in Medicare regulations or guidance, audits, or the annual program effectiveness evaluation.
Risk Assessment and Monitoring
Every department head with staff engaged in a CMS-contracted Medicare program will prepare an audit tool for self-assessment of compliance risk. The Compliance Officer must approve each assessment tool for completeness and may offer recommendations on the tool design. Required components of each assessment tool are:
- Date assessment completed
- Name and title of the employee who completed the assessment
- Description of each responsibility or task assessed
- Risk level on a scale of 1 to 4 (1 low risk, 2 moderate risk, 3 high risk, 4 out of compliance)
- Review documentation for accuracy and completeness in patient records.
Self-assessment must occur regularly based on the overall risk identified, but no less than every 2 years. Self-assessments are delivered to the Compliance Officer.
The results of self-assessments may trigger an internal audit and may influence the frequency of internal audits.
Internal Audit Program
The Compliance Officer oversees an internal audit program that includes a schedule of audits across all departments engaged with the Medicare program; this schedule may be updated more frequently to address higher-risk areas. Audit results are documented and reported to the Compliance Committee at least annually.
Corrective Action Plans
If a compliance issue is identified in the audit process, the Compliance Officer prepares a corrective action plan (CAP), which is documented as part of the audit results. All CAPs are specific in describing what must occur, the time frame, and how the correction will be verified. In addition to the audit schedule, the Compliance Officer may conduct or oversee an ad hoc audit to ensure corrections remain in effect and compliance is maintained.
01.05 Non-Retaliation Policy
Objective: To ensure all employees and FDRs can follow the Standards of Contact without concern for retaliation.
AHP supports those who raise concerns and never tolerates retaliation in any form.
01.06 Training and Education
Objective: To ensure AHP provides training and education as to the structure and operation of the compliance program.
The Compliance Officer shall provide content to Human Resources or Training staff and approve Compliance Training prepared for employees, FDRs, and covered Medicare beneficiaries. This training shall include:
- Compliance Plan Structure and Components
- AHP Standards of Conduct
- Identification of Fraud, Waste, and Abuse (FWA)
- Responsibility and Mechanisms to report potential incidents of non-compliance or FWA
- Policy against non-retaliation
- Responsibility to comply with internal and external investigations or audits related to compliance
- Requirement to comply with all applicable laws, including:
- The False Claims Act (31 U.S.C. 3729et seq.).
- The anti-kickback statute (42 U.S.C. 1320a–7b(b)).
- The civil monetary penalties law (42 U.S.C. 1320a–7a).
- The physician self-referral law (42 U.S.C. 1395nn).
- Health Insurance Portability and Accountability Act and the Health Information Technology for Economic and Clinical Health Act.
- Patient Protection and Affordable Care Act
Training shall be delivered within 90 days of hire or contract effectuation and annually thereafter. Training records shall be maintained. Failure to complete compliance training on schedule may result in limitation of duties and/or progressive discipline up to and including termination.
01.07 Documentation and Record Retention
All documents related to the compliance program shall be archived and retained for 10 years. Documents include but are not limited to updated policies and procures; provider/supplier lists; agenda and minutes of board meetings; records of compliance training and background checks; conflict of interest policies and disclosure statements; shared savings/lost distribution methodologies; beneficiary forms (notification and data opt out); root cause analyses and corrective action; provider/supplier agreements; marketing materials; TIN/NPI lists and organizational chart.
01.08 Annual Review and Updates
Objective: To ensure timely updates to the Compliance Plan
This compliance plan is in effect following approval by the Board of Managers. Annually, the Compliance Officer reviews the totality of program activities and evaluates the effectiveness of the plan. The Compliance Officer may create an evaluation tool or use one provided by CMS, such as the HCCA-OIG-Resource-Guide (Microsoft Word - HCCA OIG Resource Guide (002)). The plan may be updated off-cycle when required due to CMS guidance, rule changes, or other business drivers.
The Board of Managers conducts an annual review and approves the plan, including any revisions recommended by the Compliance Officer.
Please address any questions or concerns regarding the policies set forth in this document to the Compliance Officer.
Name: Joshua Miller
Main Office Phone: (585) 275-1609
Office Phone: (585) 275-1912
Email: Joshua_miller@urmc.rochester.edu