Compliance and safety
What Is a Corporate Integrity Agreement? What an OIG CIA Requires for Five Years
Overview
A corporate integrity agreement (CIA) is a five-year contract a health care provider signs with the HHS Office of Inspector General, often while settling a False Claims Act case, in exchange for OIG agreeing not to seek its exclusion from Medicare and Medicaid. It requires a compliance officer, written policies, training, outside claims reviews, exclusion screening, and yearly reports to OIG.
- OIG trades a CIA for its promise not to seek exclusion, and a material breach of the agreement can bring exclusion anyway.
- Every CIA runs five years, and OIG typically does not end one early for good performance.
- In a CIA OIG signed on September 30, 2025, missed duties cost up to $2,500 a day each and a false certification up to $50,000.
- OIG presumes it will not require integrity obligations when a provider self-discloses in good faith and cooperates.
- A CIA binds whoever buys the business unless OIG agrees in writing that it will not.
What a corporate integrity agreement is
A corporate integrity agreement is a contract between a health care provider and the HHS Office of Inspector General (OIG). OIG negotiates one as part of settling a federal health program investigation under the civil false claims laws, such as the False Claims Act. In a typical settlement the government alleges fraud and the provider does not admit liability.
The trade is simple. The provider takes on five years of compliance duties, and OIG agrees not to seek to exclude it from Medicare, Medicaid, and other federal health programs. Exclusion would end the business for most NEMT companies. No federal health program pays for anything an excluded person furnishes, and OIG’s 2013 bulletin on the effect of exclusion names transportation paid by a federal health program among the services an excluded person may not provide. See the OIG exclusion list.
Individual practitioners, small group practices, and small providers sign a version called an integrity agreement (IA). OIG publishes its agreements online and removes each listing 10 years after it takes effect.
When OIG asks for one
OIG does not seek a CIA in every case. Under its criteria dated April 18, 2016, OIG presumes that anyone who defrauded a federal health program should face some period of exclusion, then decides where the provider falls on a risk spectrum:
- Exclusion, for the highest risk.
- Heightened scrutiny, such as monitoring a provider that refused a CIA OIG thought it needed. OIG lists those providers publicly.
- Integrity obligations, meaning a CIA or IA.
- No further action.
- A release with no integrity obligations, usually after a good faith, cooperative self-disclosure.
Some facts push a provider toward the top of that list: harm to patients, a large loss, conduct that went on for a long time or kept going after the provider learned of the investigation, owners or managers who planned it, hiding it, and a prior CIA. Others push it down: an internal investigation started before the government arrived, a self-disclosure, cooperation, discipline of the people responsible, and more money spent on compliance. Having no compliance program built on the seven standard elements counts as higher risk.
Size matters too. When there was no patient harm or intentional fraud, a low loss compared with the size of the provider weighs against requiring a CIA. OIG treats an entity with 50 or fewer employees or independent contractors as small.
Self-disclosure carries the strongest presumption. OIG’s Self-Disclosure Protocol, as amended November 8, 2021, presumes no integrity agreement for a party that discloses potential fraud in good faith and cooperates. Of the 330 self-disclosure cases OIG settled from 2016 through 2020, none required integrity measures. The NEMT fraud guide covers when a refund is enough and when to disclose.
What a corporate integrity agreement requires
OIG tailors each agreement to the case, but most share the same parts:
- A compliance officer and a compliance committee
- Written standards and policies
- A training program for staff
- An outside review firm, which the agreement calls an IRO, hired to review claims
- A confidential way for staff to report problems, called a disclosure program
- No employment of or contracting with excluded or otherwise ineligible people
- Reports to OIG of overpayments, reportable events, and investigations or lawsuits
- An implementation report and a report every year
The deadlines are tight. In the CIA with an Indiana laboratory that took effect on September 30, 2025, the provider had 90 days to appoint a compliance officer from senior management, form the committee, adopt written standards, write a training plan, hire the IRO, and screen everyone against the exclusion lists. Screening then repeats every month. Reportable events go to OIG within 30 days, the implementation report is due within 120 days, and records stay available for six years.
The claims review
Most CIAs make the IRO review a sample of paid claims every year. OIG’s FAQ describes two formats:
- Newer CIAs review a random sample of 100 paid claims. You repay any overpayment found in the sample within 60 days, then decide under the federal overpayment rule whether more sampling or an extrapolated repayment is required.
- Older CIAs start with 50 claims. A net error rate of 5 percent or more triggers a full sample, a systems review, and repayment of the extrapolated overpayment.
A sampled claim with no supporting record counts as an error, and the whole payment counts as the overpayment. For a NEMT company, a sampled trip with no trip log means paying back everything you were paid for it. See NEMT trip documentation.
OIG also visits providers under agreements, ambulance companies among them, and says a visit usually lasts 1.5 to 2 days.
A CIA in medical transportation
On March 28, 2018, the Justice Department announced that Medical Transport, LLC, an ambulance company in Virginia Beach, would pay $9 million to resolve False Claims Act allegations. The government alleged claims to Medicare, Medicaid, and TRICARE for transports that were not medically necessary, did not qualify as specialty care transports, or should have been billed to other payers. The company signed a five-year CIA, which OIG lists as running from March 26, 2018 to June 15, 2023.
The CIA’s reporting duty then came into play. Medical Transport disclosed conduct to OIG under its CIA, and on April 15, 2021 OIG announced an $86,856.35 settlement over non-emergency ambulance claims that OIG alleged did not meet Medicare’s physician certification rules.
That is what a reportable event looks like. OIG’s FAQ defines one as a substantial overpayment, a potential violation of law tied to a federal health program, hiring or contracting with an ineligible person, or a bankruptcy filing. For a van company under a CIA, finding a run of ambulatory trips billed at the wheelchair rate could be one, with 30 days to report it.
What a breach costs
Each agreement sets stipulated penalties for each day a duty goes undone. The laboratory agreement that took effect September 30, 2025 sets up to $2,500 a day for each of 14 kinds of failure, such as a missing compliance officer, late screening, or a late report, and up to $50,000 for each false certification. If you need more time, OIG’s FAQ says to ask in writing at least 5 days before the deadline.
A material breach, such as never hiring the IRO or repeated violations, is grounds for exclusion on its own. A CIA also follows the business: OIG says it binds a buyer unless OIG agrees in writing that it will not. If you plan to sell, read how to sell a NEMT business before you sign anything.
How to keep your company out of one
- Run a real compliance program with all seven elements. Not having one counts against you.
- Screen owners, drivers, and office staff against the exclusion lists before hire and every month.
- Audit your own claims against trip logs, and refund what you find through the 60-day overpayment rule.
- Call a health care attorney the day you suspect fraud, and ask about OIG’s Self-Disclosure Protocol before the government comes to you.
- Cooperate fully with any investigation. Obstruction and slow subpoena responses raise your risk.
- Read a published integrity agreement. OIG’s compliance guidance (November 2023) says IAs are a useful compliance resource for small providers that do not know where to begin.
Frequently asked questions
Does every provider that settles a fraud case sign a corporate integrity agreement?
No. OIG weighs the risk of each case and can choose exclusion, heightened scrutiny, integrity obligations, no further action, or a release, under criteria it published on April 18, 2016. Low financial harm compared with the size of the provider weighs against a CIA when there was no patient harm or intentional fraud. OIG counts 50 or fewer employees and contractors as a small entity.
What is the difference between a CIA and an integrity agreement?
Size. OIG uses the name integrity agreement (IA) for the version an individual practitioner, small group practice, or small provider signs as part of a civil settlement. OIG's compliance guidance describes IAs as compliance measures scaled to a small provider's size. OIG says many of its IAs require a review of 30 paid claims every quarter instead of a yearly claims review.
Can a corporate integrity agreement end early?
Rarely. OIG says it typically does not end a CIA before its five years are up because a provider did well under it. A provider can ask its OIG monitor for changes in writing, such as doing claims reviews with its own auditors instead of an outside firm. A CIA can end early if the provider stops billing federal health programs or stops operating altogether, such as after a closure or bankruptcy.
Can I sell a NEMT company that is under a corporate integrity agreement?
Yes, but the agreement usually goes with the business. OIG says a CIA binds the buyer unless the seller gets a written determination from OIG that the buyer and the business will not be bound. To ask for one, you notify OIG in writing at least 30 days before the sale, with a description of the business, the terms, and the buyer.
Is a corporate integrity agreement the same as a corrective action plan?
No. A corrective action plan is a fix a broker, health plan, or state asks for after you miss a contract standard. A CIA comes from HHS OIG after a fraud settlement, runs five years, and puts your claims under an outside reviewer with penalties for every missed deadline.