E.2 - Scenario 1 - Compliance Plan.docx
DOCX document 34 KB Posted
- Attached to
- State Medicaid Program Integrity Audits Federal contract opportunity
- Solicitation number
- 75FCMC24RJ002
About this file
This document is a Compliance Plan for a Medicaid Managed Care contract. The plan outlines the compliance program designed to prevent, detect, and correct non-compliant operational practices, improper conduct, and Medicaid fraud, waste, and abuse. Key elements include:
The compliance program focuses on communication, coordination with the enterprise compliance department, internal reviews and monitoring, policy and procedure updates, database tracking, regular meetings with health plan and enterprise areas, and remediation as needed. Areas of review include marketing, onsite premises, regulatory reporting, operations, pharmacy, provider relations, enrollee-specific issues, vendor management, program integrity, payment integrity, risk management, call centers, auditing and monitoring, encounters, and utilization management. The compliance department will administer trainings, report findings to leadership, and enforce compliance through investigations and disciplinary actions.
The related federal contract opportunity is for State Medicaid Program Integrity (PI) Audits to assist CMS in reviewing state Medicaid and CHIP program integrity oversight functions, including compliance with regulations and beneficiary eligibility requirements.
View the file
Other files for this federal contract opportunity
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
E.2 Scenario 1 – Compliance Plan 75FCMC24RJ002 E.2 Scenario 1 - Compliance Plan
Introduction The Medicaid Managed Care Compliance Program is designed to prevent, detect, and correct non-compliant operational practices and improper or unethical conduct impacting Medicaid plans. It is further designed to detect, prevent, and correct incidents of Medicaid fraud, waste and abuse (FWA).
Federal False Claims Act
The Federal Civil False Claims Act (“FCA”) prohibits certain activities including, but not limited to, (i) knowingly submitting, or causing to be submitted, a false or fraudulent claim for payment or approval, (ii) the making or use of a false record or statement in support of a false or fraudulent claim, (iii) concealing, avoiding, or reducing an obligation to pay or transmit money or property to the government, or (iv) conspiring to commit a violation of a subsection of the FCA, including conspiring to commit any of the activities described in parts (i), (ii) or (iii) of this paragraph. ‘Knowingly’ means a person has actual knowledge of information but acts in deliberate ignorance or reckless disregard of whether the information is true or false; no proof that a person had a specific intent to defraud is needed. A “claim” includes requests or demands for money or property to the government or to a contractor, grantee or other recipient if the money is to be used on behalf of the government or to promote a government program, and if the government will provide or reimburse any portion of the funds being requested. The Medicaid program is funded by state and federal government money, which means the FCA applies to claims from providers submitted to health plans for payment as well as the claims or encounters submitted by health plans to government agencies, which are based on the underlying claims received from providers, Violators are liable for three times the government’s damages plus civil monetary penalties of $5,500 to $11,000 per false claim. Many states also have their own FCA or FWA provisions and, in addition to the civil penalties, there are possible criminal penalties, including imprisonment, and other penalties including disqualification from future state or federal government contracts.
Whistleblower Protection
The whistleblower provisions of the Federal False Claims Act protect entities and individuals, including employees, who file a lawsuit under the FCA, report suspected misconduct and/or assist in investigations or prosecution, from retaliation for their lawful acts under the FCA. Employees are made aware of these protections through the Code of Conduct.
Anti-Kickback Statute
The Federal Anti-Kickback Statute prohibits knowingly or willingly offering, paying, soliciting, or receiving anything of value to induce or reward referrals of items or services payable by a federal health care program or to otherwise generate Federal health care program business. Violations are considered felonies, punishable by criminal fines and imprisonment. A violation may also lead to the imposition of civil monetary penalties and possible exclusion from participation in federal health care programs. Many states also have their own anti-kickback laws. These laws can vary widely and, in contrast to the federal statute, may not be restricted to federal health care programs.
Health Information Portability and Accountability Act of 1996 (“HIPAA”)
HIPAA established, among other things, standards for certain electronic transactions and minimum privacy and security requirements for individually identifiable health information. The protection of individual information may reduce chances of misuse of the information for fraudulent purposes and may reduce the risk of identity theft.
The Managed Care Entity (MCE) maintains clear written policies and procedures that address the elements of an effective compliance program with specific federal and state fraud, waste, and abuse laws. Maintain a code of conduct to inform all employees of their responsibilities. Develop oversight and monitoring programs to ensure employees adhere to MCEs policies, procedures, and code of conduct.
Other objectives of the Compliance Program include:
· Ensure compliance with all applicable requirements, maintain, and improve communication between the project manager and other departments and associates, and ensure that continual improvements are made to strengthen the compliance program.
· Application of all states specific requirements to functions outside of the health plan as well as, including enterprise and vendor activities as they relate to the states market.
· Monitor and assist with moving activities or areas currently out of compliance into compliance, as well as improving metrics or areas that are frequently in compliance by only a small margin.
· Report findings, remediation plans, and progress to the MCEs project manager and the operations integrity team.
· Ensure open communication with all levels of health plan departments, including distribution of up-to-date information, notice of compliance issues, open communication and ensuring associates view compliance as a resource.
Areas of Focus
· Case Management engagement percentage
· Certified Business Enterprise spend
· Early and Periodic Screening, Diagnosis and Treatment (EPSDT) adherence among qualified enrollees
· Metric attainment for health plan, corporate departments, and vendors, including but not limited to appeal and grievance timeframes, claims adjudication timeframes, encounter accuracy and timeliness, and call center statistics.
· Vendor performance and vendor management coordination
· Balance billing of Medicaid enrollees Program Elements and Strategies The following elements comprise the core of the compliance program:
The compliance program will focus on communication with all areas, both at the health plan and enterprise level, in gathering and monitoring information, assessing compliance risks, monitoring improvement, and implementing strategies for compliance.
Coordination with the enterprise compliance department to execute on goals and programs at the enterprise level, while tailoring those programs to meet the needs of the health plan. Other enterprise departments will be engaged to ensure coordination and compliance.
Ensure compliance through internal reviews, monitoring, and audits of existing practices, enrollee and provider materials, provider contracts, safeguards, and other activities.
Review and update policies and procedures, including review of the adequacy of the existing policy and/or the need to enact new policies.
Internal database monitoring and recordation. Track trends, record performance, and track Protected Health Information (PHI) breaches and Corrective Action Plans (CAPs).
Conduct regular meetings with health plan and enterprise functional areas.
Create and receive, then review metric reports from functional areas to track direct performance measures, including vendor performance.
Remediation action as the situation necessitates.
Health Plan Areas of Review The compliance program will tailor communication and monitoring to the individual areas of the health plan. Many topics below fall into multiple areas and/or contain both local and enterprise components but are arranged under the primary topic.
Marketing
· Collateral reviews: Review and approve or disapprove and suggest edits for all new enrollee and provider material.
· Review existing enrollee collaterals, including the enrollee handbook.
· Marketing Practice Reviews: Ensure that marketing practices adhere to federal and state standards.
· Review corporate-led secret shopper calls to verify provider directory accuracy.
Onsite Premises
· HIPAA auditing of desks and workspaces: To be conducted quarterly. Review work areas to ensure that there is no unattended PHI, that computers are locked and physically secured when unattended, and that common areas such as printers or conference rooms do not have PHI material left.
Regulatory Reporting
· Regulatory Reporting processes will be reviewed and monitored throughout the year. This includes the report schedule, integrity of reported data, and report specifications as outlined by the state.
· Attestation Process Review: Ensure that attested reviews are occurring and are reviewing an appropriate sample size of the report (depending on the size and complexity of the report, this could include the entire report).
· Technical aspects of reports and adherence to the states manual’s requirements must also be reviewed and attested.
· Development of a regulatory reporting grid and tracker to capture report information, frequency, due dates, and ownership.
Operations
· General operations reviews and monitoring, including claim denial reason monthly reports. Trends in reports will be tracked to ensure denial logic is proper and volume is as expected.
· Denial reviews to track denial volume, types, and trends, to ensure that denials are as expected, and no spikes or erroneous groups of denials occur. Ensure denials and related complaints are handled through the established process and periodically verify that the states provider enrollment files are loaded into MCEs system properly.
· EVV implementation: Monitor for compliance both before and after go-live
· Advise on and assist with efforts to employ the state’s residents at or above the 54% requirement, monitor compliance with the requirement.
Pharmacy
· Denial and partial denial rationale reviews.
· Grievance and appeal reviews.
· Monitoring authorization, claim, appeal, and grievance metrics.
· Review of PerformRX policies and procedures and make recommended edits.
· Review of any enrollee complaints to the state regarding pharmacy performance.
Provider Relations
· Denials: Review monthly denial reason report, ensure trends are consistent and in compliance. Review denial process, including the process to adjudicate provider complaints related to denials.
· Provider Disputes: Review the administrative process and letter templates.
· Contracting: Ensure provider contract templates meet federal and state requirements, including regulatory flow-down language as necessary.
· Collateral reviews: Review and approve or disapprove and suggest edits for all new provider material.
· Review existing provider collaterals, including the provider handbook.
Enrollee-Specific Issues and Activities
· State Fair Hearings: Compliance will seek additional engagement and communication with areas impacted by each Fair Hearing, including medical management, legal, provider relations, and pharmacy, as well as researching the potential of relocating some of the Fair Hearing processes to departments closer to the issues.
· Case Management Engagement Percentage: Assist with activities and staffing and/or contracting efforts to continually increase the ratio of enrollees engaged in case management, with the goal of (1) illustrating continual improvement, (2) bringing the ratio to the required 4%, and (3) creation of a sustainable model that will maintain a compliant ratio.
· EPSDT adherence among qualified enrollees: This is an ongoing issue that has high visibility. Prioritize efforts to increase the percentage of members receiving required EPSDT care, with focus on ensuring that all applicable members are captured, all applicable provider visits are counted, and continual efforts are made from various areas to drive the ratio to the required 81% level.
· PHI and Personally Identifiable Information (PII) reviews to ensure that policies pertaining to HIPAA compliance are being followed and appropriate steps are taken to guard against HIPAA violations.
· Review and enforcement of all other contractually mandated member standards and actions (for example, completion of health risk assessments).
State
· Compliance will serve as one of MCEs primary contacts with the state.
· Compliance will attend the states program integrity meetings, leadership meetings, and other meetings as needed.
Other Areas and Activities
· PHI/HIPAA Monitoring and Remediation: Track all inappropriate PHI disclosures and HIPAA violations, including any such disclosures/violations that impact the MCE but occurred at the corporate level or with a contracted provider or vendor. Remediate any such issues. Track issues to address repeat offenders or trends that indicate a process, policy, or system may need revisited to avoid continued disclosures/violations.
· Quarterly fraud, waste, and abuse training: Associates are required to take four trainings each year on fraud, waste, and abuse. Compliance will administer and distribute trainings and track completion.
Enterprise Areas of Review Vendor Management
· Increase communication with vendor management with the goals of: (1) establishing clear lines of communication for questions or concerns between the health plan and vendor management, (2) providing compliance with an opportunity to review existing contracts for accuracy and inclusion of the state’s specific needs, (3) establishing a clear picture of which vendors provide services for the states market and what the scope of those services are, (4) upon vendor termination, ensure vendor services are (a) covered internally, (b) covered by another vendor, or (c) are unnecessary for the compliant function of the MCEs business.
· Initiate pre-engagement reviews of proposed vendors, including subcontract review to ensure the states requirements are included and met.
· Review current subcontracts and subcontract templates to ensure appropriate language that captures all states requirements are not negatively impacted by any subcontract provisions. Ensure appropriate and effective flow-down language to capture any/all state requirements that are not directly addressed in the subcontract.
· Vendor collateral reviews: Review all new collaterals to ensure compliance with state and federal regulations. Conduct annual reviews of existing collaterals and update as necessitated by new or altered requirements.
· Receive and review key metric report for all vendors at least monthly. Meet at least monthly with the vendor management team to review vendor performance, both within direct metrics and general performance and actions.
· Track vendor management-issued CAPs and ensure MCE needs are prioritized.
Program Integrity The MCE maintains cross-functional teams which support activities to ensure the accuracy, completeness, and truthfulness of claims and payment data. The teams responsible for conducting specified program integrity activities include the Special Investigations Unit (SIU), the prospective and retrospective client and Vendor Data Management team, and the Internal Claims Cost Management team.
· Coordinate with SIU and coordinate efforts between SIU and health plan departments such as Provider Relations. Track SIU activities.
· Track and coordinate efforts of the Prospective and Retrospective Client and Vendor Data Management team and the Internal Claims Cost Management team.
· Review front-end edits and claim lookbacks to ensure compliance with state requirements. Investigates improvements or areas to address with additional edits or lookbacks.
· Monitor and assist in provider-focused efforts as necessitated by the situation, including provider education, retraining, recovery, and/or removal from network.
Payment Integrity
· Review fee schedules and payment types to ensure required rates are being met.
· Collaborate with provider relations and vendor management to ensure that contracted rates are coded appropriately in the system.
· Ensure logic is coded correctly to account for items frequently mistaken by providers or errors in claim submissions, such as codes requiring readmission, inpatient or outpatient status, enrollee age, and other factors.
· Claim integrity efforts, including telehealth claims and emergency room claim analysis and establishment or review of a process for referral to emergency room diversion programs if needed.
Risk Management
· Maintain periodic review of internal processes and assess risk associated with each.
· Coordinate with SIU, operations, and other areas to assess risk (as monitored by state) and ensure measures exist to both mitigate current risk and preemptively take steps to eliminate or reduce risk areas before they manifest.
Policies and Procedures
· Conduct annual review of compliance policies.
· Conduct annual review of health plan policies.
Call Centers
· Review call center metrics at least monthly. Administer any corrective action plans needed should missed metrics occur. Track trends to ensure that performance improvement efforts are undertaken should trends indicate worsening metrics.
· Act as a point of contact with call center directors to enable timely notification to the health plan in the event of any outage or potential issues to minimize the impact of the issues as well as enable notification to the state if necessary and enable the health plan departments to take any actions needed.
· Review and ensure that mitigation plans in the case of outage, increased call volume, or similar events are prepared and effective.
· Review call center scripts to ensure compliance with federal and state requirements.
· Ensure maintenance of a do not call list in accordance with federal Telephone Consumer Protection Act standards.
Auditing and Monitoring
· Monitor and update the following databases:
· New or amended privacy laws.
· SharePoint: Accounting of disclosure requests; PHI disclosure issues.
· OIG/LEIE exclusion lists: Periodic audits to ensure barred providers are prevented from doing business with the MCE; ensuring provider contracting and credentialing/recredentialing efforts take such lists into account; ensuring vendors are monitoring as well.
· Review plan member and provider websites for compliance.
· Internal and external CAPs
· Conduct and support internal audits as required by the state.
Encounters
· Monitor encounter timeliness and accuracy.
· Investigate and remediate any issues such as rejections, duplicative encounter submissions, or inaccurate encounter data.
· Ensure vendor encounters are within contractual levels of accuracy and timeliness.
Utilization Management Letter and Process Reviews
· Review existing letter templates to ensure that mandated language is present, such as full appeal rights in adverse benefit determination letters.
Administration of Ongoing Reporting and Communication The MCE Compliance Department will continually monitor performance metrics at the health plan, enterprise, and vendor levels. This review includes but is not limited to performance metrics submitted to the state in the form of regulatory reporting, internal metric measures, and metrics and indicators that are promulgated by enterprise-level departments. Should a need be identified, new ad hoc or regular internal reports will be developed to track needed areas not captured elsewhere.
Regulatory reporting sent to the state will be reviewed by the MCEs compliance department, in addition to the business owners, for additional verification of technical requirements as set forth by the state reporting guidelines. This includes file type, format, name, and the proper formatting of data within the file. Compliance will ensure a process exists to communicate changes to regulatory reporting from the state to the necessary MCE and enterprise associates.
The MCE compliance program will strive to maintain and increase communication to and engagement with all health plan departments and enterprise areas. Compliance concerns and activities will be regularly reported to the MCE project manager. The compliance program will ensure that all associates have access to the states specific requirements and will distribute those requirements to the impacted areas, as well as maintain a playbook that outlines the states specific requirements.
Regular meetings will be held with the health plan and enterprise departments in order to discuss compliance concerns, update requirements, track progress of any remediation plans or CAPs, and provide a forum for departmental leaders to raise any areas of concern with compliance. Monthly meetings with the health plan departments include quality, pharmacy, member services, operations, provider relations, and marketing. Enterprise meetings include vendor management, SIU, program integrity, communications, procurement, and enterprise compliance.
The Executive Medicare Compliance Committee is comprised of senior leadership from a variety of business units which oversee the overall compliance program.
The MCE compliance program will hold quarterly compliance committee meetings with health plan leadership and representation from internal audit, SIU, and corporate compliance. Compliance committee meetings will cover key metrics and compliance activities from the previous quarter, current activities, and compliance concerns, and provide a forum for discussion.
Updates, metrics and data, initiative progress, and remediation efforts will be communicated to the MCE project manager and to the market president through regular meetings or more frequently, as needed.
Trainings The compliance program strives to ensure all associates that work with the states line of business are trained on important topics that impact our membership and pertinent laws and regulations. Regular trainings and reminders are distributed to the MCEs associates, enterprise associates working with the states line of business, and vendors.
Trainings and communications include, but are not limited to:
· Monthly all-associate meeting notices and reminders regarding pertinent compliance topics.
· Quarterly fraud, waste, and abuse training.
· Quarterly notices regarding handling of PHI, securing workspaces, the minimum necessary information rule, and other topics within HIPAA.
· Biannual notices regarding cybersecurity threats and phishing.
· Annual enterprise trainings on handling of PHI, cybersecurity, fraud, waste, and abuse, enrollee rights and responsibilities, and business associate responsibilities.
Enforcement and Response to Violations Any violation of a law, regulation, policy, or misconduct, or an indication or allegation thereof, will be investigated by the compliance department. Leadership and the market president will be notified, and ongoing communication will occur. Other areas will be engaged as necessitated by the violation.
After investigation, any associate actions taken will be consistent with corporate compliance and ethics policies and practices.
File details come from the government source that posted it. Updated .