• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Updated DOJ Guidance and 6 Takeaways for Compliance Officers

Updated DOJ Guidance and 6 Takeaways for Compliance Officers

June 10, 2020/in Blog, DOJ, General Compliance

Updated DOJ Guidance and 6 Takeaways for Compliance Officers
On June 1, 2020, the Department of Justice’s (DOJ) Criminal Division released revisions to its Evaluation of Corporate Compliance Programs guidance for use with federal prosecutors when investigating corporations for criminal misconduct. This guidance updates the 2019 version that was covered in a previous blog post and provides insight into the DOJ’s expectations for corporate compliance programs.  This guidance is particularly useful for healthcare providers and their compliance officers and should be used to evaluate and improve current compliance measures and controls. Here we highlight the new areas that DOJ prosecutors will consider when investigating compliance programs and the main takeaways for improving compliance program effectiveness.

1. Compliance Programs Should Be Adequately Resourced and Function Effectively

The DOJ revised one of the three fundamental questions that prosecutors ask when evaluating compliance programs to guide an investigation⎯ is the program being applied earnestly and in good faith? In answering this question, prosecutors are directed to evaluate whether the compliance program is adequately resourced and empowered to function effectively. The guidance states that even a well-designed compliance program may be unsuccessful in practice if it is under-resourced. In addition, the guidance includes the following clarifications for this fundamental question:

  • An effective compliance program requires the involvement of senior and middle management. Fostering a culture of ethics and compliance at all levels within an organization is critical and requires a high-level commitment by company leadership to implement a culture of compliance from the middle and the top.
  • Organizations should invest in training and development of personnel charged with a compliance program’s day-to-day oversight. And compliance personnel should have access to relevant sources of data to allow for purposes of effective monitoring and/or testing of policies, controls, and transactions.
  • Investigations and resulting discipline should be monitored to ensure they have been fairly and consistently applied across the organization.

2. Compliance Programs Should Evolve Over Time

In order to evaluate whether an organization has a well-designed compliance program, the DOJ guidance directs prosecutors to understand why the company has chosen to set up the compliance program the way that it has, and why and how the company’s compliance program has evolved over time. The guidance highlights the importance of an ongoing risk assessment that is subject to periodic review and directs prosecutors to evaluation whether the periodic review is based upon continuous access to operational data and information across functions rather than limited to a snapshot in time. Additionally, prosecutors will consider whether there is a process to track and incorporate lessons learned into an organization’s risk assessment from its own issues as well as issues within its industry/ geographical region.

3. Maintain a Process for Accessing and Tracking Compliance Policies and Training

The DOJ emphasizes the importance of updating compliance policies and procedures. The guidance instructs prosecutors to evaluate if the organization: 1) publishes its policies and procedures in a searchable format for easy reference; and 2) tracks access to various policies and procedures to understand what policies are attracting more attention from relevant employees.
The DOJ guidance highlights the importance of providing effective workforce training.  Whether online or in-person trainings, an organization should provide a process by which employees can ask questions arising out of the trainings. And organizations are expected to evaluate the extent to which the training has an impact on employee behavior or operations.

4. Establish an Effective Hotline/Confidential Reporting Mechanism

The DOJ expects organizations to have a hotline/ effective reporting mechanisms that can be used to anonymously or confidentiality report breaches and misconduct. The DOJ guidance includes the following lines of inquiries:

  • Is the hotline publicized to both employees and third parties?
  • Does the organization take measures to test whether employees are aware of the hotline and feel comfortable using it?
  • Does the organization periodically test the effectiveness of the hotline, for example by tracking a report from start to finish?

5. Manage Compliance Risks Posed by Third Party Partners Throughout the Lifespan of the Relationship

Organizations are expected to continuously manage compliance risks presented by third parties. Language added to the guidance asks prosecutors to assess: 1) whether the organization knows the business rationale for needing the third party in the transaction and the risks posed by third-party partners; and 2) whether the organization engages in risk management of third parties throughout the lifespan of the relationship, or primarily during the onboarding process.

6. Conduct Comprehensive Compliance Due Diligence of Acquisition Targets and Timely Integrate Compliance Functions

The DOJ guidance focuses on comprehensive compliance due diligence and post-closing integration for mergers and acquisitions. Organizations are expected to have a process that allows for the timely and orderly integration of the acquired entity into the organization’s existing compliance program structures and internal controls. Prosecutors are directed to ask if the organization completed pre-acquisition due diligence and post-acquisition audits at newly acquired entities.
The DOJ guidance serves as an insightful resource for compliance officers. In addition, incorporating appropriate software tools into your compliance strategy will help streamline processes and serve as your first line of defense against these significant risk areas.  First Healthcare Compliance’s cloud-based software offers solutions to fit your organization. Contact us today for a quick demonstration of our compliance management software solution.

Tags: compliance officer, Compliance Program, Department of Justice, healthcare compliance
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2020/06/doj_guidance_ft.jpg 758 1200 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2020-06-10 10:59:362025-04-15 12:46:22Updated DOJ Guidance and 6 Takeaways for Compliance Officers
You might also like
What is OSHA Compliance Training? What is OSHA Compliance Training?
Protecting Your Practice is Smart Business
7 Fast Facts about the False Claims Act
A Harassment-Free Workplace vs the Right to Engage in Concerted Activity
Q&A: Compliant Coding and Billing For TeleHealth During COVID-19 Q&A: Compliant Coding and Billing For TeleHealth During COVID-19
The Role of Boards in Healthcare Compliance

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only