Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: General Compliance Program Guidance

General Compliance Program Guidance, or GCPG is a program created from Office of the Inspector General (OIG) and Health and Human Services (HHS).

The GCPG is a reference guide for the health care compliance community and other health care stakeholders. The GCPG provides information about relevant Federal laws, compliance program infrastructure, OIG resources, and other information useful to understanding health care compliance.

The GCPG is voluntary guidance that discusses general compliance risks and compliance programs. The GCPG is not binding on any individual or entity. Of note, OIG uses the word “should” in the GCPG to present voluntary, nonbinding guidance.

Key Aspects of the GCPG:

  • Voluntary Framework: It is not binding law, but it outlines best practices for healthcare entities.
  • 7 Core Elements Updated: Reaffirms and updates the seven elements, including written policies, compliance leadership, training, communication, enforcement, monitoring, and corrective action.
  • .Industry-Specific Focus: The GCPG replaces old, fragmented guidance. It is followed by new Industry-Segment Specific Compliance Program Guidance (ICPGs) for specific subsectors.
  • Key Focus Areas: Emphasizes the need for dedicated compliance personnel (separated from legal functions), incentivizing compliant behavior, and implementing robust risk assessment processes.
  • Applicability: Applies to all healthcare stakeholders, including providers, managed care plans, and suppliers

HHS-OIG General Compliance Program Guidance (Full Document)

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.