Compliance

Building a compliance program for a NEMT company: OIG's seven elements at small scale

Updated 9 min read

For a NEMT company, a compliance program is a written routine for preventing, spotting, and correcting billing and conduct problems. HHS OIG's voluntary 2023 guidance builds it from seven parts: written standards, a person in charge, training, a safe way to raise concerns, discipline, audits guided by a yearly risk review, and a response plan. New York requires one from providers claiming or receiving $1 million a year.

On this page

Think of compliance as the routine that stops a small billing mistake from turning into a recoupment, a termination, or a fraud case. HHS OIG’s General Compliance Program Guidance, published November 6, 2023, is the standard reference, and it includes a section on how small entities can meet all seven elements with limited staff. This guide turns that section into a working program for a NEMT company with a handful of vans and one office, as of September 2026.

The fraud prevention guide covers the schemes investigators find and the daily trip controls. This page covers the structure around those controls: who owns compliance, what gets written down, how often you look, and how you respond to what you find.

Who requires a compliance program

For most NEMT companies, a compliance program is expected rather than mandated. OIG calls its guidance voluntary and nonbinding. Several other sources turn parts of it into requirements.

SourceCoversRequirement
42 U.S.C. 1395cc(j)(9)Providers in an industry the Secretary of HHS designatesA compliance program with core elements set by the Secretary, as a condition of Medicare, Medicaid, or CHIP enrollment, starting on a date the Secretary chooses for that industry
42 U.S.C. 1396a(a)(68)Entities paid $5 million or more each year through a state Medicaid planWritten policies for employees, contractors, and agents covering federal and state false claims laws and whistleblower protections, plus a discussion of them in the employee handbook
New York, 18 NYCRR Part 521Any provider for whom Medicaid is a substantial portion of its business, meaning $1 million or more claimed or received, or reasonably expected, in any 12 consecutive monthsAn effective compliance program with eight elements, certification at enrollment and every year after, and compliance records kept at least six years
Broker contractsCompanies in a broker networkTraining, attestations, audits, and record retention (examples below)

Broker requirements are where most small companies meet compliance first. On Modivcare’s attestation form, an authorized representative signs for the whole company: every owner and driver on its trips has taken Modivcare’s code of conduct and a course on general Medicare and Medicaid compliance, FWA, HIPAA, the ADA, and cultural competency. Anyone hired later has 30 days to finish, and the rosters stay on file for at least 10 years. The MTM provider agreement that Pennsylvania’s Department of Human Services posts goes further: driver training must include FWA and HIPAA, the provider takes part in MTM’s quality and compliance programs, inspections can happen unannounced, and operating records stay on file for 10 years.

Oversight is active. On May 28, 2026, OIG opened an audit series on NEMT payments, checking whether chosen states followed Medicaid payment rules, with results expected in fiscal year 2028. The announcement lays out the rules states are measured against: prior authorization generally rests on a medical practitioner’s order, and providers must be legally authorized to transport riders and must keep records that support each service they bill.

Element 1: Written standards people can follow

Start with a one-page code of conduct and a short set of policies written for your actual operation. OIG says small entities may start from templates supplied by a consultant, a professional group, or the internet, but should review them carefully and adapt them to their own business and risks.

The policies that matter most in NEMT work:

  • Trip records. The fields a finished leg needs, such as the rider, service date, both addresses with actual arrival and departure times, the driver and van, and a signature where the payer wants one. See NEMT documentation requirements.
  • Mileage. Bill loaded miles from GPS or odometer readings, never estimates.
  • Service level. Charge for the service the rider actually received, even when a higher one was booked.
  • No-shows and cancellations. What proves a no-show, and when one is billable under each payer’s rules.
  • Credentials. No driver, attendant, or vehicle runs a trip without current credentials.
  • Exclusion screening. Who is checked, against which lists, and how often.
  • Gifts and inducements. Under the beneficiary inducement rules, OIG caps “nominal value” at $15 an item and $75 in a year.
  • Subcontracting. Under MTM’s agreement, no service may be handed to a subcontractor unless MTM agrees in writing. Copy that rule for every broker whose contract has one.
  • Record retention. Match the longest retention period in any of your contracts. Ten years satisfies the MTM and Modivcare terms above.

Review the set once a year and date each version. Writing NEMT policies and procedures covers format and staff sign-off.

Element 2: One named compliance contact

A small company does not need a full-time compliance officer. OIG suggests naming one person as the compliance contact, responsible for making sure compliance tasks get done. Three conditions come with the role:

  1. The contact has no responsibility for the company’s legal services.
  2. Whenever possible, the contact is not involved in billing, coding, or submitting claims.
  3. A company with no board has the contact report to the owner or CEO, no less often than once a quarter.

The owner remains ultimately responsible. In a company where the owner also does the billing, a dispatcher or office manager can serve as the contact and review billing work the owner cannot review impartially. Put the quarterly report on the calendar and keep a copy.

Element 3: Training for new hires and a yearly refresher

Everyone who touches trips or claims gets compliance training when hired and a refresher at least annually. OIG’s broader guidance calls for an annual training plan listing topics and audiences, built partly from what the last audits found.

A practical plan for a small fleet has three layers:

  • Everyone: the code of conduct, who the compliance contact is, how to raise a concern, and the rule against retaliation.
  • Drivers and attendants: trip records, signatures, no-show steps, HIPAA basics, and the broker’s required courses. See NEMT driver training.
  • Dispatch and billing staff: payer billing rules, level of service coding, mileage, and the overpayment process.

OIG says small entities can share compliance information at staff meetings, by email, on a website, or on posters in shared spaces. It also maintains a series of compliance training videos. Record every session with the date, topic, and a signature or completion record, because a signed broker attestation means little without the roster that backs it up.

Element 4: A way to raise concerns without fear

OIG says a formal disclosure program, such as a hotline, may not be necessary for a small organization, but it should still have policies that require good-faith reporting of possible violations, lay out how reports get investigated, and prohibit retaliation. For small companies, its ideas include:

  • A stated open-door policy, so anyone can walk in and talk to the owner or the compliance contact.
  • A simple reporting route, such as an anonymous drop box.
  • A policy that failing to report improper conduct is itself a violation.
  • Keeping the reporter’s identity private where possible, while being clear it may come out in some cases.

Because anonymity is hard in a company of ten people, OIG suggests posting how to reach the OIG hotline in shared physical or online spaces. Put the poster in the break room and the driver handbook.

Element 5: Consequences decided in advance

Write the discipline scale before anyone breaks a rule. OIG wants the rules set before any problem arises, with enough room that staff still feel safe asking questions and owning up to errors. Apply the same scale to a new driver and a senior dispatcher. A driver who admits entering the wrong drop-off time and fixes it deserves a different response from one who invents a trip, and your policy should say so.

OIG also says a company may tell staff that failing to report a violation can lead to discipline, and may reward good compliance work.

Element 6: A yearly risk review, audits, and monitoring

This element is where a small program earns its keep. OIG’s small-entity section sets three expectations:

  • A compliance risk assessment at least once a year. Look at your denials, rider and facility complaints, and OIG’s Work Plan, and ask your team at a staff meeting where things go wrong.
  • An annual audit, at minimum, pointed at whatever the risk review ranked highest. Fixes can include repaying overpayments, changing a process, or retraining staff.
  • Routine monitoring of OIG’s exclusion list, the state Medicaid exclusion lists that apply, and licenses and certifications. Because OIG refreshes its list every month, checking on the same cycle keeps exposure lowest.

For a NEMT company, the risk list usually starts here:

RiskWhat to check
Billed miles above actual milesBilled miles against GPS or odometer miles for the same leg
Level of service billed above what was providedThe vehicle and service actually used against the code billed
Trips billed without a completed recordEvery billed leg against its trip log and signature
No-shows billed where the payer does not pay themNo-show claims against each payer’s rule
Drivers or vehicles without current credentialsTrip dates against license, inspection, and training dates
An excluded owner, employee, or contractorMonthly results for everyone, kept on file
Work passed to an unapproved subcontractorTrips run by anyone outside your roster

An example audit for a six-van company: each month, pull 10 paid legs at random and match each to its trip log, miles, signature, and the driver’s credentials on that date. Once a year, run a larger sample from the highest-risk area. Keep the worksheet, the findings, and the fixes together. Screening results belong in an exclusion screening log.

Element 7: Responding when you find a problem

Plan the response before you need it. OIG tells small entities to expect that their program may turn up violations, and to decide in advance who determines whether one happened and what fixes it.

  1. Stop and secure. End the practice, and protect trip logs, GPS data, claims, and messages from deletion. OIG suggests removing staff under investigation from the work involved when their presence could compromise the review.
  2. Investigate and document. OIG’s list for the investigation record: the allegation, the steps taken, interview notes and key documents, a log of witnesses and records reviewed, the results, and any discipline or corrective action.
  3. Return overpayments on time. A Medicaid overpayment goes back, with a written explanation, within 60 days of being identified. After that deadline, the unreturned amount counts as an obligation for False Claims Act purposes (42 U.S.C. 1320a-7k(d)). The guide to the 60-day rule covers when the clock starts.
  4. Report when the law may have been broken. OIG’s general guideline is to notify the right government authority within 60 days of determining that credible evidence of a violation exists. Where fraud is possible, OIG’s Self-Disclosure Protocol usually asks for one and a half times single damages or more, and never less than $20,000 (kickback matters start at $100,000). Have a health care attorney handle any disclosure.
  5. Fix the cause. Change the process, retrain, apply the discipline policy, and note the change in your next risk assessment.

A first-year calendar

WhenTask
Month 1Name the compliance contact. Adopt the code of conduct and core policies. Post the reporting routes and the OIG hotline.
Month 2Train every current employee and file the rosters. Screen everyone against the exclusion lists.
Every monthExclusion screening, the 10-leg audit sample, and credential expiration checks
QuarterlyWritten update from the compliance contact to the owner
Once a yearRisk assessment, full audit of the top risk, refresher training, policy review, and broker attestations

The compliance calendar template lays out every recurring date on a single page.

Keeping the records behind the program

Most of the monthly audit is matching claims to trip records and checking credential dates. In HealthRide, each leg carries its GPS-recorded miles, stop times, and the signature captured on the driver’s screen, and the trip log in reports downloads as a CSV or PDF, ready for a monthly sample. The fleet page tracks license and registration dates, sends reminders ahead of each one, and warns dispatch when someone with an expired credential is about to get a trip.

Frequently asked questions

Does federal law force NEMT companies to have a compliance program?
Not yet, for most. OIG's guidance is voluntary. A federal statute lets the Secretary of HHS tie Medicaid enrollment to having one, industry by industry, starting on dates the Secretary picks. Some states and contracts already require one. New York requires an effective program from any provider for whom Medicaid is a substantial portion of its business, which its rule sets at $1 million or more claimed or received, or expected, in any 12 consecutive months. Brokers also require training and signed attestations.
Who can run compliance in a five-van company?
OIG suggests a small entity that cannot fund a compliance officer name one person as its compliance contact. Pick someone who does not handle legal work for the company and, when possible, does not bill or submit claims. An operations or office manager often fits. That person briefs the owner every quarter or more often, but final responsibility for following program rules never leaves the owner.
What audit schedule fits a small NEMT company?
Once a year at minimum, according to OIG's guidance for small entities, with a compliance risk assessment at least annually to choose what to audit. A small monthly sample on top of that catches problems sooner, while drivers still remember the day. Exclusion screening is separate and runs every month, because OIG adds and removes names on that cycle.
What happens if our audit finds we were overpaid?
Under federal law you have 60 days from identifying a Medicaid overpayment to send it back, along with a written explanation of why it happened. Holding it longer turns it into a False Claims Act obligation. When the facts point to possible fraud, bring in a health care attorney before choosing a path; OIG's Self-Disclosure Protocol sets minimum settlements of $20,000 for most matters and $100,000 where kickbacks are involved.
Do brokers check whether we have a compliance program?
They check parts of it. Modivcare has each transportation company sign an attestation covering its code of conduct and required courses, with new hires trained inside their first 30 days and rosters kept for a decade. MTM's agreement makes driver training include fraud, waste and abuse (FWA) and HIPAA, commits the provider to quality and compliance programs, and allows audits without notice.
Does OIG publish compliance guidance specific to transportation companies?
Not a current one. OIG is replacing its older guides with industry segment guides, and the ones published so far cover nursing facilities (November 2024) and Medicare Advantage (February 2026). Its 2003 guidance for ambulance suppliers sits in the archive. A NEMT company uses the General Compliance Program Guidance, including its section on small entities.

Official resources

Keep reading

HealthRide plans the whole day in one click and bills every ride.