When Regulatory Compliance Controls Exist but Still Fail 

When Regulatory Compliance Controls Exist but Still Fail youcompli blog image

A compliance control can exist, be documented and even be automated, yet still fail to prevent or detect a problem. That distinction matters as healthcare organizations add more policies, system edits, review procedures and reporting tools. The purpose of regulatory compliance control is to mitigate risk across the different operations and workflows in healthcare delivery.  

The presence of a control may give a false sense of security.  

The presence of a control may demonstrate that an organization recognized a risk. It doesn’t necessarily prove that the risk is being managed consistently. 

A recent audit from the U.S. Department of Health and Human Services Office of Inspector General offers a practical example of where controls can go wrong. 

What the OIG Audit Found 

The audit reviewed certain Medicare Part B payments made by Wisconsin Physicians Service (WPS) Insurance Corporation, a Medicare administrative contractor, for outpatient services during 2022 and 2023. 

Of 801 selected claim lines, OIG found that: 

  • 138 claim lines were incorrect, resulting in at least $140,182 in overpayments. 
  • 31 additional claim lines totaling $76,640 didn’t have supporting documentation. 
  • Providers attributed identified overpayments to clerical errors and issues with their billing systems. 
  • WPS had system edits in place but edits and review of flagged payments didn’t consistently identify claim lines that were in error. 

OIG recommended recovering identified overpayments and locating additional medical record documentation. Other recommendations included enhancing existing system edits and review processes and improving provider education. WPS agreed with all five recommendations. 

Read the official HHS-OIG audit summary and access the full report. 

Why Established Compliance Controls Still Fail 

Even though the audit focused on a specific contractor and set of Medicare payments, its findings illustrate a broader operational issue for healthcare compliance leaders

Having a control isn’t the same as knowing the control works. 

Most healthcare organizations don’t lack policies, procedures or controls. In fact, it may seem like there’s an abundance of those to some people.  

The more common challenge is that those controls operate across different people, departments and systems, and workflow can break down. A billing edit may identify a claim, but someone still needs to review it. A policy may require supporting documentation, but someone must still locate that documentation when it’s requested. An error may be corrected, but the organization still needs to verify the correction occurred. 

Each handoff creates an opportunity for the process to break down. 

Four Reasons for Control Failure 

As discussed in From Manual to Scalable: How to Manage Healthcare Compliance Risk, regulatory and compliance work becomes its own source of risk when it depends on individual effort, institutional memory and disconnected systems.  

In this environment, controls commonly fail for four reasons. 

1. The Process Depends on Manual Perfection 

Many compliance processes still rely on someone remembering to complete a step, notice an exception or follow up with another department. 

Manual work isn’t inherently ineffective. Human judgment is still essential to compliance. The problem arises when the process relies on individual memory without a reliable structure around it. 

Consider how often an organization depends on someone to: 

  • Recognize that an issue requires review 
  • Send an email to the appropriate person 
  • Remember to follow up 
  • Save supporting documentation 
  • Confirm that the issue was corrected 
  • Preserve evidence of the completed response 
regulatory compliance controls in healthcare image

A capable employee may perform those steps correctly most of the time. But a mature compliance program shouldn’t depend on perfect execution every time. The odds are against that long term. 

Instead, every regulatory change process should make the required next step clear, assign responsibility and show when work remains incomplete. 

2. A System Flag Is Mistaken for a Completed Control 

There are many reasons a system may successfully flag a potential error while the broader control still fails: 

  • The alert goes to the wrong person. 
  • No deadline is attached to the review. 
  • The reviewer lacks sufficient context. 
  • The alert is dismissed without documenting why. 
  • The issue is corrected but not verified. 
  • No one evaluates whether similar errors may exist elsewhere. 

This is the difference between detection and resolution

Automated edits and alerts can strengthen a compliance process, but an alert is only the beginning. 

A system edit can detect a possible problem. It can’t by itself ensure someone in the organization:  

  • Evaluates the issue  
  • Decides what action is required  
  • Completes that action  
  • Preserves evidence of the response 

Look at the full process surrounding an automated control, not just whether the technology generates an alert. 

3. Documentation Exists but Can’t Be Retrieved 

Supporting documentation is a recurring issue in audits, investigations and internal reviews. Sometimes the underlying work was completed, but the organization can’t produce any evidence.  

The organization may believe the record exists without actually knowing who owns it or where it can be found. Documentation could be stored in an individual inbox, a shared drive, a clinical system, a billing platform or a department-specific folder.  

For compliance purposes, documentation that can’t be retrieved may provide little practical protection. 

What Helpful Documentation Should Look Like 

A defensible process should make it possible to determine: 

  • What happened 
  • Who reviewed the issue 
  • What information was considered 
  • What decision was made 
  • Why that decision was reasonable 
  • What corrective action was assigned 
  • Whether the action was completed 
  • Where the supporting evidence is stored 

The goal isn’t about creating documentation for its own sake. The goal is to preserve a clear, trustworthy account of how the organization responded. 

For a deeper look at this issue, read How Healthcare Compliance Teams Can Turn Documentation Into Defensible Proof

4. Ownership Ends at the First Handoff 

Compliance teams rarely perform every operational task required to address a risk. They may identify the issue and send it to Revenue Cycle, Coding, Clinical Operations, Privacy, Legal, Quality or another department. Those handoffs are necessary, but they don’t complete the compliance process. 

Someone must remain responsible for determining whether the requested work was completed and whether the result adequately addressed the original risk. 

Without that accountability, a process becomes a series of disconnected activities: 

  1. Compliance identifies a concern. 
  2. The issue is sent to another department. 
  3. The department begins reviewing it. 
  4. A correction may or may not occur. 
  5. The outcome is never reported back. 
  6. Compliance can’t confirm completion or produce evidence later. 

Activity occurred, but the organization can’t demonstrate resolution. That’s why clear ownership means defining responsibility for both the operational action and the final verification. 

Three Questions to Test Whether a Control Works 

Healthcare compliance leaders can use three practical questions to evaluate a control. 

1. Does the Control Reliably Detect Exceptions? 

Don’t just ask whether a policy, edit or review procedure exists. 

Every time, the compliance leader should ask: 

  • What specific risk is the control designed to identify? 
  • What information does it evaluate? 
  • Are there circumstances it may miss? 
  • How often is its effectiveness tested? 
  • What happens when the control identifies a potential exception? 

A control should have a clearly defined purpose and recognized limitations. It’s another job for compliance.  

regulatory compliance controls in healthcare image

2. Can We Retrieve the Supporting Evidence? 

Select a completed compliance action and attempt to reconstruct it. 

Can your organization quickly show: 

  • Original issue or requirement 
  • Analysis that occurred 
  • People involved 
  • Decision and rationale 
  • Actions assigned 
  • Completion records 
  • Final verification 

This is a useful test because it evaluates the process from the perspective of an auditor, regulator or new compliance leader who wasn’t involved in the original work. 

3. Who Owns Correction and Verification? 

The person completing the corrective action may not be the person responsible for verifying it. Both roles should be clear. 

For example, an operational department may correct a billing process, while Compliance verifies that the correction addresses the identified concern and that evidence has been preserved. 

Without defined ownership, issues can remain open even after everyone believes someone else completed the work. 

From Individual Controls to Regulatory Operationalization 

The broader challenge isn’t simply building more controls but connecting them to repeatable operational processes. 

Then, when an issue or regulatory requirement is identified, the organization should be ready to: 

  1. Assess its relevance and potential impact. 
  2. Determine which departments and processes are affected. 
  3. Define the required operational response. 
  4. Assign clear owners and deadlines. 
  5. Communicate expectations to the people completing the work. 
  6. Track implementation and escalation. 
  7. Verify that the required action occurred. 
  8. Preserve documentation of the organization’s response. 

YouCompli refers to this discipline as Regulatory Operationalization: turning regulatory change into assigned, completed, verified and defensible action. This isn’t a one-off fix, but a scalable solution that adapts to health system needs. 

Technology can support this process but shouldn’t replace human judgment. The strongest approach combines structured workflows and automation with knowledgeable human review. 

Organizations evaluating whether their current technology supports that full process can use the six capabilities outlined in What to Look for in Regulatory Change Management Software for Healthcare Compliance

Metrics That Show Whether Controls Are Working 

Executive leadership and the Board of Directors may already receive compliance reports showing how many reviews, audits or corrective actions occurred. 

Those activity metrics are useful, but don’t necessarily demonstrate control effectiveness. 

Compliance leaders should also consider measures such as: 

  • Percentage of flagged exceptions reviewed by the deadline 
  • Average time from detection to resolution 
  • Number of overdue corrective actions 
  • Percentage of completed actions with supporting evidence 
  • Recurrence rate of previously identified issues 
  • Number of controls tested for effectiveness 
  • Percentage of corrective actions independently verified 
  • Time required to retrieve audit-ready documentation 

These measures help move the conversation from “Do we have a control?” to “Can we demonstrate that the control works?” 

For additional guidance on choosing useful measures and communicating them effectively, read Beyond the Penalty: What Metrics Should Healthcare Compliance Officers Track?

Compliance reporting should also help leaders identify overdue work, understand ownership and confirm what was completed and verified. Learn more about healthcare compliance reporting and verification

The Bottom Line 

The lesson from the OIG audit isn’t that automated edits, manual reviews or provider education are ineffective. The lesson is that no individual control should be evaluated in isolation. 

A system audit needs a reliable review process. A review needs an owner. An owner needs a deadline. A completed action needs verification. The entire response needs documentation that the organization can retrieve when challenged. 

Healthcare compliance programs have matured, and expectations have increased with them. It’s no longer enough to show that a policy was written, an alert was generated, or an email was sent. 

Organizations increasingly need to prove that risks were identified, evaluated, assigned, addressed and verified. 

That’s the difference between having compliance controls and operating a defensible compliance process. 

Can Your Documentation Prove the Work? 

Take the Compliance Documentation Readiness Check to evaluate whether your current process can demonstrate ownership, action, evidence and verification. 

The assessment takes approximately three to four minutes and provides a personalized result with access to the Prove-It Compliance Playbook. 

Download our Latest Whitepaper
Sign-up for our Weekly Newsletter
Schedule a quick overview