Client Alert: When to Use the OIG’s Self-Disclosure Protocol
Executive Summary
Health care providers that identify potential compliance issues involving federal health care programs should carefully evaluate whether disclosure through the HHS Office of Inspector General’s Provider Self-Disclosure Protocol (“SDP”) is appropriate. The SDP permits eligible providers, suppliers, and other entities subject to Civil Monetary Penalty authorities to voluntarily disclose self-discovered evidence of potential fraud and may help avoid the cost and disruption of a government-directed investigation or civil or administrative litigation.
Use of the SDP, however, is not appropriate in every circumstance. The decision requires a fact-specific assessment of the conduct, the applicable legal authorities, the timing of any actual or imputed knowledge, and the availability of other disclosure or repayment processes.
Key Takeaways
- The SDP is generally available for matters involving potential violations of federal criminal, civil, or administrative laws for which Civil Monetary Penalties are authorized.
- The SDP is not the appropriate process for Stark Law-only matters unless the conduct also potentially implicates the Anti-Kickback Statute.
- Potential overpayments and billing issues should be assessed promptly because the timing of actual or imputed knowledge may affect exposure under the 60-day repayment rule and the False Claims Act.
- Routine billing errors may often be resolved through ordinary repayment channels, but matters involving potential knowing conduct or enhanced penalty exposure may warrant consideration of the SDP.
- A documented internal investigation is critical to support the provider’s disclosure decision and any subsequent resolution strategy.
When the SDP May Be Appropriate
The SDP is limited to matters involving potential violations of federal criminal, civil, or administrative laws for which Civil Monetary Penalties are authorized. A disclosing party must identify the specific legal provisions that may have been violated and acknowledge that the underlying conduct may violate those provisions. The OIG does not use the SDP to issue advisory opinions or determine whether the conduct described in a disclosure constitutes a violation of law.
Matters That May Require a Different Process
The SDP is not available to disclose and resolve Stark Law violations unless the conduct also potentially implicates the Anti-Kickback Statute. Stark Law-only matters generally should be evaluated under the separate disclosure process maintained by the Centers for Medicare & Medicaid Services. The OIG protocols are typically implicated where there is a potential Anti-Kickback Statute violation, an overpayment that may give rise to liability under the 60-day repayment rule, or another matter that may involve Civil Monetary Penalty authorities.
Why the Disclosure Decision Is Often Difficult
The decision whether to use the SDP is often difficult because the relevant legal and factual issues may be uncertain. Billing requirements and regulatory standards may be subject to interpretation, and it may not be clear whether particular conduct violates a Civil Monetary Penalty law. Nevertheless, an incorrect determination can create substantial exposure. Providers therefore may consider the SDP as a risk-mitigation measure even where the existence of a violation has not been conclusively established.
Knowledge and the 60-Day Repayment Rule
Enhanced penalties may apply where a provider “knows or should know” that a regulation has been violated or that an overpayment exists. Determining when actual or imputed knowledge arose can be difficult, and that timing is often central to the disclosure analysis.
For example, the failure to report and return an overpayment within 60 days of identification may substantially increase potential exposure, including False Claims Act risk. Although actual knowledge may be tied to a particular date, it is often more difficult to determine when the provider should have known of the overpayment through compliance program activity, audit findings, or other credible information.
If imputed knowledge arose more than 60 days before disclosure, the provider may face increased liability even if actual knowledge was obtained within the repayment period. In that circumstance, the SDP may assist in mitigating potential enhanced damages and provide a structured path for resolution with the OIG.
Distinguishing Routine Billing Errors from Potential Fraud
Not every billing error warrants self-disclosure to the OIG. Many overpayments identified through routine auditing may be addressed through ordinary repayment or intermediary channels.
The analysis becomes more complex where an internal investigation raises questions regarding whether incorrect claims were submitted knowingly or whether the provider should have identified the issue earlier. In such circumstances, the SDP may reduce potential exposure and provide a more predictable framework for resolving the matter.
Recommended Next Steps for Providers
When potential errors are identified, providers should act promptly to preserve facts, assess potential exposure, and determine the appropriate path for resolution. Delaying review or assuming that the matter will remain undiscovered is generally not prudent, particularly because compliance concerns may arise through audits, whistleblower activity, payer inquiries, or other unexpected channels.
Providers should conduct a reasonable and appropriately documented investigation to determine the nature, scope, and potential legal significance of the issue. The investigation should support a reasoned determination regarding whether the conduct creates exposure under Civil Monetary Penalty authorities, the False Claims Act, the Anti-Kickback Statute, or related laws.
Where the investigation identifies potential enhanced penalty exposure, the SDP may provide an appropriate mechanism to mitigate damages, demonstrate cooperation, and pursue resolution with the OIG.
