HHS Office of Inspector General
The HHS Office of Inspector General (OIG) is a federal oversight body within the U.S. Department of Health and Human Services that works to protect the integrity of HHS programs such as Medicare and Medicaid. It fights waste, fraud, and abuse by conducting investigations and promoting the economy, efficiency, and effectiveness of these programs. It also issues legal guidance to help parties understand how fraud and abuse laws apply to their arrangements.
The HHS Office of Inspector General (OIG) is the oversight component of the U.S. Department of Health and Human Services whose mission is to promote the economy, efficiency, effectiveness, and integrity of HHS programs and the health and welfare of the people they serve. OIG conducts investigations into fraud, waste, and abuse involving HHS programs, contracts, and grants, including Medicare, Medicaid, and more than 100 other HHS programs. Among its functions, OIG issues advisory opinions, which are legal opinions to one or more requesting parties concerning the application of OIG's fraud and abuse authorities to a specific proposed or existing arrangement. Note that OIG's oversight and fraud-and-abuse authorities are distinct from HIPAA's privacy and security requirements, which are enforced by HHS Office for Civil Rights (OCR); the specific scope of OIG's authorities, penalties, and processes should be verified against current HHS guidance.
Why it matters
The HHS Office of Inspector General plays a central role in protecting the integrity of federal healthcare programs. As the office at the forefront of the nation's efforts to fight waste, fraud, and abuse in Medicare, Medicaid, and more than 100 other HHS programs, OIG's investigations and oversight activities carry significant consequences for healthcare organizations, providers, and vendors that participate in these programs. For compliance professionals, understanding OIG's role helps clarify where fraud-and-abuse risk originates and how the government pursues program integrity concerns.
It is important to keep OIG's authorities distinct from HIPAA's privacy and security requirements. HIPAA's Privacy, Security, and Breach Notification Rules are enforced by the HHS Office for Civil Rights (OCR), not by OIG. OIG's oversight instead focuses on the economy, efficiency, effectiveness, and integrity of HHS programs, and on fraud, waste, and abuse involving HHS programs, contracts, and grants. Conflating these two offices can lead compliance teams to misattribute risk or misunderstand which authority governs a given issue.
OIG also issues advisory opinions, legal opinions to one or more requesting parties about how OIG's fraud and abuse authorities apply to a specific proposed or existing arrangement. These opinions can help organizations understand their exposure before entering into arrangements that might implicate fraud-and-abuse laws. The specific scope of OIG's authorities, penalties, and processes changes over time and should be verified against current HHS guidance rather than assumed.
Who it's relevant to
Inside OIG
Common questions
Answers to the questions practitioners most commonly ask about OIG.