Compliance
Healthcare Compliance: A Career Path Built on HIPAA and the OIG Work Plan
Healthcare compliance runs on a different rulebook than corporate compliance elsewhere: HIPAA privacy and security rules, Stark Law, the Anti-Kickback Statute, and an annual OIG Work Plan that tells you exactly where enforcement is looking next. Here is what the job involves and how to get into it.

A hospital's compliance analyst gets a routine access report showing that a nurse looked up a patient's chart. Nothing unusual on its face — nurses look up charts constantly. Except this patient was never assigned to that nurse's unit, was admitted under a name that matches a local news story from the week before, and the nurse's access happened at 2 a.m., forty minutes after her shift ended. No data left the building. No one complained. The analyst still has to treat this as a probable HIPAA privacy breach, document the investigation, determine whether it triggers a reportable event under the Breach Notification Rule, and decide whether it goes to HR as a conduct issue, to the privacy officer as a disclosure risk, or both. That kind of judgment call, made against a specific federal statute rather than general good practice, is what separates healthcare compliance from compliance work in most other industries.
Why healthcare compliance is its own discipline
Corporate compliance programs in most industries are built around a mix of internal policy, general fraud and ethics law, and whatever sector-specific rules apply. Healthcare compliance is different because the underlying law is unusually dense, unusually specific, and enforced by an agency that publishes its enforcement priorities in advance. The Department of Health and Human Services' Office of Inspector General (OIG) issues an annual Work Plan naming the exact billing patterns, drug categories, and provider types it intends to audit that year, which means a healthcare compliance program is, in large part, a standing response to a public document telling you where the government is about to look.
The legal architecture is also unusually layered. The Health Insurance Portability and Accountability Act (HIPAA) governs patient privacy and data security. The Anti-Kickback Statute (AKS) criminalizes paying or receiving anything of value in exchange for referrals of federally reimbursed patients. The Stark Law (the Physician Self-Referral Law) separately restricts financial relationships between physicians and the entities they refer patients to, with a stricter, largely strict-liability standard than AKS. The False Claims Act (FCA) creates civil liability, including treble damages, for submitting false claims to Medicare or Medicaid — and because AKS and Stark violations can render a claim "false" under the FCA, a kickback or self-referral problem often becomes a billing-fraud problem by the time it reaches a courtroom. A compliance professional in this field has to hold several of these frameworks in mind at once, because the same arrangement — a hospital leasing office space to a referring physician at below-market rent, for instance — can implicate two or three of them simultaneously.
What the job actually involves
The center of most healthcare compliance roles is the seven-element compliance program the OIG has described as the baseline expectation since the 1990s: written policies, a compliance officer and committee, effective training, open communication lines, internal auditing and monitoring, consistent enforcement of standards, and a documented response to detected problems. In practice, that abstraction breaks down into recurring, concrete work.
- **HIPAA privacy and security administration.** Investigating access-log anomalies like the one above, managing breach risk assessments under the Breach Notification Rule, reviewing business associate agreements with vendors who touch patient data, and running the periodic risk analysis the Security Rule requires for electronic health information.
- **Billing and coding compliance.** Auditing a sample of claims against the medical record to confirm the documentation supports the billed code, a discipline close to internal audit work, done in partnership with certified coders and often surfacing upcoding, unbundling, or medically unnecessary service patterns before a payer or the OIG finds them first.
- **Fraud, waste, and abuse monitoring.** Reviewing referral relationships, physician compensation arrangements, and vendor contracts for AKS and Stark exposure, frequently working alongside legal counsel because the fair-market-value analysis behind a physician contract is as much a valuation question as a compliance one.
- **Exclusion screening.** Checking employees, contractors, and vendors monthly against the OIG's List of Excluded Individuals/Entities and the General Services Administration's exclusion list, because employing or contracting with an excluded person, even unknowingly, creates FCA exposure for every claim they touch.
- **Investigations and corrective action.** Working hotline reports, conducting root-cause review of a billing error or privacy incident, and documenting corrective action in a way that would hold up if the OIG or a payer's program integrity unit asks for it later.
- **Training and attestation.** Delivering role-specific training, most obviously on HIPAA and coding, and maintaining the completion records that become the first thing an auditor asks for.
Where these roles sit
Hospitals and health systems typically have a dedicated compliance department led by a Chief Compliance Officer who reports to the board's audit or compliance committee, structurally separate from legal and often from the general counsel's office, a separation the OIG explicitly recommends to preserve independent authority. Physician practices and smaller provider groups often fold compliance into an office manager or practice administrator's responsibilities until the group reaches a size where a dedicated role becomes worthwhile. Health insurers (payers) run compliance functions focused more heavily on claims processing accuracy, Medicare Advantage and Medicaid managed care requirements, and program integrity — a meaningfully different day-to-day than the provider side. Pharmaceutical and medical device companies run compliance programs centered on AKS exposure in sales and marketing, the Physician Payments Sunshine Act's reporting requirements, and interactions with health care professionals, which pulls in people with a regulatory affairs or life sciences background more than a clinical one. Health tech and digital health companies increasingly need people who understand HIPAA's application to software and data platforms, a track that overlaps with privacy work more than with billing compliance.
How people actually get into it
Clinical background is common but not required, and hiring managers are explicit that they need compliance judgment more than clinical credentials. Nurses, health information management (HIM) professionals, and medical coders move in because they already read clinical documentation fluently and can spot a coding pattern that does not match the chart. Internal auditors and accountants move in from the audit side, particularly into billing compliance and program-integrity roles, because sampling, testing, and finding-writing transfer directly. Health law paralegals and attorneys move into compliance officer and investigator roles, especially in organizations where the compliance function sits close to legal. Privacy professionals from outside healthcare move in specifically for HIPAA-focused roles, bringing a data-protection mindset that the sector increasingly needs as electronic health records and health apps expand the attack surface. The realistic entry point for someone without a clinical or health-law background is usually a compliance analyst or coding/billing compliance auditor role focused on one workstream, most often claims auditing or HIPAA administration, rather than a compliance officer seat.
Certifications worth having
The Health Care Compliance Association's Certified in Healthcare Compliance (CHC) credential is the closest thing to a recognized standard for the generalist role, covering the full seven-element program, fraud and abuse law, and privacy basics. HCCA also offers the Certified in Healthcare Privacy Compliance (CHPC) for HIPAA-focused roles and the Certified in Healthcare Research Compliance (CHRC) for organizations running clinical research, both narrower and useful if that is where the actual work sits. AHIMA's Certified in Healthcare Privacy and Security (CHPS) is a comparable option that leans more heavily into health information management. For the billing and coding side, AAPC's Certified Professional Coder (CPC) credential, or AHIMA's Certified Coding Specialist (CCS), is frequently treated as close to a prerequisite for claims-auditing roles, because those roles depend on being able to independently code a chart, not just review someone else's coding. As with financial-crime and privacy credentials elsewhere, none of these substitute for being able to describe an actual investigation you ran or an audit finding you wrote.
Where the career goes
A compliance analyst who is reliable at claims auditing or HIPAA case management typically moves toward owning a full workstream — coding compliance, privacy, or exclusion and vendor screening — within two to three years, including direct interaction with the OIG Work Plan cycle and the organization's annual risk assessment. From there, the path splits in a few directions. Some move toward a Compliance Officer or Chief Compliance Officer track, eventually reporting to a board compliance committee and owning the full seven-element program. Others move into healthcare-focused consulting or Corporate Integrity Agreement (CIA) monitoring, working with organizations that have settled OIG enforcement actions and now operate under mandated, externally reviewed compliance obligations, which trades a single organization's context for breadth across engagements. A smaller group moves toward health law itself, using compliance experience as the practical foundation for a law degree or a shift into a paralegal or investigator role at a firm that represents providers.
The throughline across all of it is the density of the underlying law. A healthcare compliance career rewards people who are comfortable reading a statute or a Work Plan entry closely enough to apply it to a specific chart, contract, or access log — not people who prefer to operate at the level of general ethical principle. That is a narrower skill than compliance work elsewhere demands, and it is exactly why the field keeps hiring people who already know how to read evidence closely, whether they learned that at a nursing station, in an audit file, or in a courtroom.