Bindinglaw

US · guidance

CMS Pub. 100-16, ch. 21, § 50.2

Element II: Compliance Officer, Compliance Committee and

activein force · 2026-08-25 – presentas-observed

High Level Oversight

(Chapter 21 - Rev. 109, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07- 20-12)

(Chapter 9 - Rev. 15, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07-20- 12)

42 C.F.R. §§ 422.503(b)(4)(vi)(B), 423.504(b)(4)(vi)(B)

The sponsor must designate a compliance officer and a compliance committee who report

directly and are accountable to the sponsor’s chief executive or other senior management.

1. The compliance officer, vested with the day-to-day operations of the compliance

program, must be an employee of the sponsor, parent organization or corporate

affiliate. The compliance officer may not be an employee of an FDR.

2. The compliance officer and the compliance committee must periodically report

directly to the sponsor’s governing body on the activities and status of the

compliance program, including issues identified, investigated, and resolved by the

compliance program.

3. The sponsor’s governing body must be knowledgeable about the content and

operation of the compliance program and must exercise reasonable oversight with

respect to the implementation and effectiveness of the compliance program.

50.2.1 – Compliance Officer

(Chapter 21, Rev. 110, Issued:01-11-13, Effective:01-11-13; Implementation:01-11-13)

(Chapter 9, Rev. 16, Issued: 01-11-13, Effective: 01-11-13; Implementation: 01-11-13)

42 C.F.R. §§ 422.503(b)(4)(vi)(B), 423.504(b)(4)(vi)(B)

The compliance officer position should be full-time. The sponsor is not required to have a

separate compliance officer (“Medicare Compliance Officer”) dedicated only to its

Medicare Parts C and D business, although CMS strongly recommends a dedicated

Medicare compliance officer. Sponsors must assess the scope of the existing compliance

officer’s responsibilities, the size of the organization, and the organization’s resources

when determining whether a single compliance officer can effectively implement the

Medicare compliance program and the sponsor’s commercial or other governmental

business.

The compliance officer must be an employee of the sponsor (preferred) or of its parent

company or corporate affiliate. Sponsors may not delegate the compliance officer

position or compliance program functions to first tier or downstream entities. When the

compliance officer is not employed by the sponsor itself, but by the sponsor’s parent

company or corporate affiliate, the sponsor must ensure that the compliance officer has

detailed involvement in and familiarity with the sponsor’s operational and compliance

activities.

The sponsor must ensure that reports from the compliance officer reach the sponsor’s

senior-most leader (typically the CEO or President). The direct reporting relationship

between the compliance officer and the senior-most leadership refers to the direct

reporting of information, not necessarily to a supervisory reporting relationship. This can

be accomplished through a dotted line or matrix reporting.

The compliance officer must have express authority to provide unfiltered, in-person

reports to the sponsor’s senior-most leader. The compliance officer’s reports should not

be routed to the CEO or President through operational management such as the COO,

CFO, GC (General Counsel) or other executives responsible for operational areas. For

example, the compliance officer’s report to the CEO should not be filtered through the

CFO. However, the compliance officer’s reports may be relayed to the sponsor’s senior-most leader through divisional Presidents. For example, the compliance officer may

report directly to the President of the division that houses the Medicare program, who

then reports to the CEO of the sponsor on the status and activities of the Medicare

compliance program.

The compliance officer’s reports to the sponsor’s governing body must be made through

the compliance infrastructure. The compliance officer must have express authority to

provide unfiltered, in-person reports to the sponsor’s governing body at his/her

discretion.

The Medicare compliance officer may report compliance issues directly to the corporate

compliance officer and/or the compliance committee, who then provide compliance

reports directly to the sponsor’s governing body. The compliance officer, in his/her

discretion, need not await approval of the sponsor’s governing body to implement needed

compliance actions and activities, provided that those actions and activities, as

appropriate, are reported to the governing body or governing body committee at its next

scheduled meeting. It is a best practice for sponsors who have both a corporate

compliance officer and a Medicare compliance officer to allow the Medicare compliance

officer to regularly attend meetings of the sponsor’s governing body and to make in-person reports to the sponsor’s governing body. A related best practice is to allow the

compliance officer to meet in Executive Session with the governing body.

The compliance officer should be independent. The compliance officer should not serve

in both compliance and operational areas (e.g., where the compliance officer is also the

CFO, COO or GC). This leads to self-policing in the operational area(s) in which he/she

serves, which is a conflict of interest.

Because the compliance officer must be free to raise compliance issues without fear of

retaliation, it is a best practice to require governing body approval before the compliance

officer can be terminated from employment.

The compliance officer is responsible for the implementation of the compliance program.

The compliance officer defines the program structure, educational requirements,

reporting, and complaint mechanisms, response and correction procedures, and

compliance expectations of all personnel and FDRs.

The compliance officer should have training and/or experience working with MA, MA-PD or PDP programs and, with regulatory authorities. It is a best practice for the

compliance officer to be a member of senior management.

Duties of the compliance officer may include, but are not limited to:

• Ensuring that Medicare compliance reports are provided regularly to the sponsor’s

corporate compliance officer (if any), governing body, CEO, and compliance

committee. Reports should include the status of the sponsor’s Medicare

compliance program implementation, the identification and resolution of

suspected, detected or reported instances of noncompliance, and the sponsor’s

compliance oversight and audit activities;

• Being aware of daily business activity by interacting with the operational units of

the sponsor;

• Creating and coordinating, by appropriate delegation, if desired, educational

training programs to ensure that the sponsor’s officers, governing body,

managers, employees, FDRs, and other individuals working in the Medicare

program are knowledgeable about the sponsor’s compliance program, its written

Standards of Conduct, compliance policies and procedures, and all applicable

statutory and regulatory requirements;

• Developing and implementing methods and programs that encourage managers

and employees to report Medicare program noncompliance and potential FWA

without fear of retaliation;

• Maintaining the compliance reporting mechanism and closely coordinating with

the internal audit department and the SIU, where applicable;

• Responding to reports of potential FWA, including the coordination of internal

investigations with the SIU or internal audit department and the development of

appropriate corrective or disciplinary actions, if necessary. To that end, the

compliance officer should have the flexibility to design and coordinate internal

investigations;

• Ensuring that the DHHS OIG and Government Services Administration (“GSA”)

exclusion lists have been checked with respect to all employees, governing body

members, and FDRs monthly and coordinating any resulting personnel issues

with the sponsor’s Human Resources, Security, Legal or other departments as

appropriate;

• Maintaining documentation for each report of potential noncompliance or

potential FWA received from any source, through any reporting method (e.g.,

hotline, mail, or in-person);

• Overseeing the development and monitoring of the implementation of corrective

action plans;

• Coordinating potential fraud investigations/referrals with the SIU, where

applicable, and the appropriate NBI MEDIC. This includes facilitating any

documentation or procedural requests that the NBI MEDIC makes of the sponsor.

Similarly, the compliance officer should collaborate with other sponsors, State Medicaid

programs, Medicaid Fraud Control Units (MCFUs), commercial payers, and other

organizations, where appropriate, when a potential FWA issue is discovered that involves

multiple parties; and

• The compliance officer should have the authority to:

o Interview or delegate the responsibility to interview the sponsor’s employees

and other relevant individuals regarding compliance issues;

o Review company contracts and other documents pertinent to the Medicare

program;

o Review or delegate the responsibility to review the submission of data to CMS

to ensure that it is accurate and in compliance with CMS reporting

requirements;

o Independently seek advice from legal counsel;

o Report potential FWA to CMS, its designee or law enforcement;

o Conduct and/or direct audits and investigations of any FDRs;

o Conduct and/or direct audits of any area or function involved with Medicare

Parts C or D plans; and

o Recommend policy, procedure, and process changes.

History

(Chapter 21 - Rev. 109, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07- 20-12)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
92cc009b8207dce31fc2d013f3259859e5b872b92b7b5068f7e04b5ad28577ff
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.