Compliance Operations

Compliance Committee Meeting Agenda

Build a quarterly agenda that covers all seven OIG compliance program elements — standing items, open-issues log, training status, audit results, hotline log, and action items with owners. Print it as the agenda before the meeting and as the minutes after.

Cyanotype vignette of a meeting table ringed with empty chairs and blank padsFIG · 01
A meeting table ringed with empty chairs and blank pads.

Companion: Committee Charter Checklist

An agenda only works if the committee behind it has real authority. Tick what your charter already covers. Anything unchecked is a gap an OIG reviewer or a plaintiff's lawyer will find first.

0 of 10 charter elements in place

0%

What Is a Compliance Committee Meeting Agenda?

A compliance committee agenda is the standing order of business for the group that oversees your compliance program. In OIG's General Compliance Program Guidance (November 2023), the compliance committee is part of element two — compliance leadership and oversight — and OIG recommends it meet at least quarterly, with an agenda circulated before each meeting and minutes kept of what the committee did and decided.

The template above does both jobs with one document: the same standing items become the agenda before the meeting and the minutes after it. Every item is tagged to one of the seven elements, so a year of minutes proves the committee actually oversaw the whole program — not just whatever was on fire that quarter. It pairs naturally with an annual compliance work plan, which feeds each quarter's audit and training topics.

Why Quarterly Meetings (and Minutes) Matter

A compliance program that exists only on paper is worse than none in front of a jury. When OCR or OIG investigates, the first documents requested are policies, training records, and committee minutes. Minutes showing quarterly review of audits, hotline reports, and corrective actions are the cheapest evidence of an effective program you can produce.

Quarterly is the floor, not the ceiling. The cadence works because it matches the natural rhythm of the program: quarterly audit cycles, annual training requirements, and the annual security risk analysis whose findings the committee tracks to closure. A committee that meets monthly but keeps no minutes documents less than one that meets quarterly and writes everything down.

How to Use This Agenda Template

  1. 1

    Fill in the meeting details

    Organization, quarter, date, chair, recorder, and who is invited. The quorum line matters — minutes that never state quorum are a common audit finding.

  2. 2

    Adjust the standing items

    The default agenda covers all seven OIG elements in 75 minutes. Rename items, change presenters and time boxes, or add items for your specialty (Stark/AKS review, 340B, lab compliance).

  3. 3

    Update the open-issues log

    Carry forward anything not closed last quarter: risk-analysis findings, expired BAAs, audit exceptions, hotline reports. Each issue keeps its source, owner, due date, and status.

  4. 4

    Assign action items

    One named owner and one date per action. Review them first thing next meeting — that follow-through loop is what OIG means by an "effective" program.

  5. 5

    Print the agenda, then print the minutes

    Circulate the Agenda view before the meeting. During or after, type discussion notes into each item and switch to the Minutes view — it adds decisions, signature lines, and the retention note.

Who Sits on the Committee?

Small practice (1–10 providers)

Compliance officer (often the practice manager wearing the hat), a physician owner, billing lead, and whoever owns IT. Three to five people is enough — the discipline matters more than the headcount.

Group or clinic (10–50 providers)

Dedicated compliance officer as chair, medical director, HR, revenue cycle, IT/security officer, and a rotating department seat. Six to eight voting members.

Hospital / health system

Senior leaders from legal, quality, HIM, pharmacy, and finance, with the compliance officer reporting independently to the board audit and compliance committee.

Whatever the size, the compliance officer should not report through billing or legal, and at least one member should carry clinical authority — corrective actions that touch Stark and Anti-Kickback exposure or documentation practices go nowhere without a physician champion.

Mapping the Agenda to the OIG Seven Elements

The default standing items map one-to-one onto the seven elements from OIG's General Compliance Program Guidance. The output above prints a coverage line — [1] [2] [3] [4] [5] [6] [7] — so a reviewer can see at a glance that nothing was skipped.

#OIG elementStanding agenda itemWhat the committee looks at
1Written policies & proceduresPolicy reviewWhich policies passed annual review; which were revised and why; code-of-conduct attestations.
2Compliance leadership & oversightCompliance Officer reportProgram metrics, budget and staffing, regulatory changes, board reporting.
3Training & educationTraining statusCompletion percentage, overdue staff by name, new-hire onboarding within 30 days.
4Effective lines of communicationHotline & reporting logReports received, categories and trends, response time, anonymity preserved.
5Auditing & monitoringAudit resultsChart and billing audit samples, error rates vs. last quarter, EHR access-log reviews.
6Enforcement & disciplineSanctions appliedDisciplinary actions this quarter and whether they were consistent across roles.
7Response & corrective actionIncidents & CAPsIncidents and breach assessments, corrective action plans, repayment or self-disclosure decisions.

Feed element five from your HIPAA audit checklist results, element three from the training log, and element seven from your incident reports and any breach notification assessments from the quarter.

Writing Minutes That Hold Up

Minutes are legal documents. In an OCR investigation or a False Claims Act case, they are read years later by people looking for either diligence or negligence. Five rules keep them on the right side:

  • 1.

    Record decisions and votes, not conversation. "Committee approved the revised sanctions policy 5-0" beats a paragraph of who said what.

  • 2.

    State quorum at the top and note anyone who recused (for example, a billing manager during a billing-audit discussion).

  • 3.

    Give every finding a disposition: closed, carried to the open-issues log, or escalated to the board or counsel.

  • 4.

    If counsel attends for a specific matter, mark that discussion privileged and keep it in a separate memo, not the general minutes.

  • 5.

    Approve last quarter's minutes as the first order of business — unapproved minutes are drafts, and drafts carry less weight as evidence.

Retain approved minutes for at least six years — that matches the HIPAA documentation retention rule at 45 CFR § 164.316(b)(2) and covers most payer lookback windows. Recurring findings in the minutes (the same common violations quarter after quarter) are a signal to change the control, not just re-train.

One Committee, the Whole Program

In a small or mid-size practice, one committee should own everything compliance touches: HIPAA privacy and security, billing and coding accuracy, Stark and Anti-Kickback arrangements, OSHA, and credentialing. Splitting these into separate meetings quadruples the administrative load and lets issues fall between chairs. Use the element tags on each agenda item to keep the mix honest, and pull next quarter's audit topics straight from your annual work plan. A quick quarterly spot-check with the HIPAA compliance checklist makes a ready-made element-five report when the audit calendar is light.

Related Tools & Guides