Corporate integrity agreements: what OIG requires after a fraud settlement

Updated 3 min read

Overview

Under a corporate integrity agreement, a health care provider that settled fraud allegations, usually under the False Claims Act, accepts five years of compliance duties overseen by HHS OIG. In return, OIG agrees not to seek its exclusion from Medicare and Medicaid. The provider must name a compliance officer, train staff, hire an independent reviewer, screen for excluded people, and report every year, with daily penalties for missed duties.

On this page

Why OIG asks for one

A CIA is OIG’s alternative to exclusion. When a provider settles fraud allegations, often under the False Claims Act and usually without admitting liability, OIG still holds the power to exclude it from federal health programs. In exchange for the provider taking on the agreement’s duties, OIG agrees not to use that power.

OIG does not ask for a CIA in every case. Its 2016 criteria place each settling provider on a scale: exclusion for the highest risk, then heightened scrutiny when a provider refuses an agreement OIG thinks is needed, then integrity obligations, then no further action, and finally a release for providers that disclosed the problem themselves. A CIA takes the structure of a compliance program and puts it under federal oversight, with deadlines and penalties attached.

What the agreement makes you do

OIG lists the elements most agreements share, each tailored to the facts of the case:

  • A compliance officer, supported by a compliance committee.
  • Written policies and standards, plus staff training.
  • An independent review organization (IRO) to review claims or systems.
  • A confidential way for staff to report concerns.
  • No employment of ineligible people, which means screening against the exclusion list.
  • Reports of overpayments, reportable events, and investigations or legal proceedings.
  • An implementation report, then annual reports on the compliance work.

The deadlines come fast. In a CIA OIG signed with a lab company effective September 30, 2025, the compliance officer, committee, written standards, training plan, IRO, risk assessment, and disclosure program were each due within 90 days, and the implementation report within 120 days. Records had to be kept for six years.

Reporting, penalties, and breach

A reportable event goes to OIG within 30 days. It includes a substantial overpayment, a likely violation of law that carries penalties or exclusion, and hiring or contracting with an ineligible person.

Missed duties draw stipulated penalties, charged per day. The 2025 lab agreement allows up to $2,500 a day for many failures and gives 15 business days after a demand letter to pay or request a hearing. Some failures count as a material breach, such as not engaging an IRO or repeated violations, and a material breach is an independent basis for exclusion.

Ambulance companies under CIAs

OIG’s public list keeps an agreement for 10 years after its effective date. As of October 2026 it holds four agreements with ambulance providers and none with a wheelchair van, ambulette, or taxi company. All four followed False Claims Act settlements and are now closed.

CompanySettlementAgreement in force
Medstar Ambulance, Leominster, Massachusetts$12.7 millionJanuary 2017 to December 2022
AmeriCare Ambulance Service and Americare ALS, Seffner, Florida$5,496,817January 2018 to August 2023
Medical Transport, LLC, Virginia Beach, Virginia$9 millionMarch 2018 to June 2023
Liberty Ambulance Service, Jacksonville, Florida$1.2 millionJune 2018 to January 2024

The Medical Transport agreement shows reporting at work. After the company disclosed a problem under its CIA, it paid $86,856.35 in an April 2021 settlement with OIG over non-emergency ambulance claims that did not meet Medicare’s physician certification requirements.

An IRO claims review checks each sampled claim against its records. HealthRide keeps GPS-recorded miles, pickup and drop-off times, and the rider’s on-screen signature with every trip, and reports exports them for any date range.

Frequently asked questions

Can a small transportation company end up with a corporate integrity agreement?
Yes, though OIG weighs size. Its 2016 criteria say that, without egregious conduct such as patient harm or intentional fraud, a small financial loss relative to the company's size weighs against integrity obligations, and they define a small entity as 50 or fewer employees or independent contractors. Smaller providers who do sign get an integrity agreement (IA), the version OIG uses for solo practitioners, small group practices, and other small providers.
What happens if I buy a company that is under a CIA?
The agreement binds the buyer unless OIG decides in writing that it will not. The seller must notify OIG at least 30 days before the sale, describing the business, the deal terms, and the buyer. Ask about any CIA, IA, or open settlement in due diligence, and see the guide to buying a NEMT business for the rest of the checklist.
Does self-disclosing a problem lead to a CIA?
Usually not. OIG's 2016 criteria name two situations where it will usually release its exclusion authority without integrity obligations, and the first is a cooperative, good-faith self-disclosure to OIG. The second is when the provider agrees to strong integrity obligations with a state or the Justice Department instead.

Official resources

Keep reading

HealthRide plans the whole day in one click and bills every ride.