Based on the 2026 OIG ICPG

How Prepared Is Your
MA Compliance Program?

OIG released its first Medicare Advantage-specific compliance guidance in 26 years. Every law firm says “conduct a gap assessment.” This free tool does it in 10 minutes — 44 questions across 8 domains, scored and weighted for your organization type.

No account required · Results in 10 minutes

How It Works

Three steps to a comprehensive compliance gap assessment

Step 1

Select Your Org Type

Choose from 6 organization types — MAO, RA vendor, UM vendor, marketing, provider, or other. This customizes scoring weights to match your risk profile.

Step 2

Answer 44 Questions

Work through 8 compliance domains, answering Yes, Partial, or No for each question derived directly from the OIG ICPG.

Step 3

Get Your Scored Report

Receive an overall compliance score, domain-by-domain breakdown, priority gap analysis, red flag alerts, and a downloadable PDF report.

8 ICPG Compliance Domains

Seven risk areas from ICPG Section II plus the Seven Elements compliance framework from Section III — covering every dimension of MA compliance.

Domain 1

Access to Care

Network adequacy, provider directory accuracy, prior authorization safeguards, utilization management oversight, and enrollee grievance trend analysis.

6 questions
Domain 2

Marketing & Enrollment

Pre-distribution material review, agent/broker oversight, compensation compliance, special enrollment monitoring, and TPMO/lead generation controls.

5 questions
Domain 3

Risk Adjustment & Data Integrity

Coding accuracy audits, chart review vendor oversight, in-home health assessment safeguards, unsupported diagnosis deletion, 60-day overpayment returns, and RADV readiness.

7 questions
Domain 4

Quality of Care

Excluded provider screening, Star Ratings data integrity, provider credentialing verification, and quality data accuracy monitoring.

4 questions
Domain 5

Oversight of Third Parties (FDRs)

FDR inventory and risk tiering, pre-delegation due diligence, contractual compliance provisions, ongoing monitoring and audits, exclusion screening, and downstream delegation oversight.

6 questions
Domain 6

Vertically Integrated Organizations & Ownership

Subsidiary compliance officer independence, data access firewalls, medical loss ratio safeguards, and investor/PE governance considerations.

4 questions
Domain 7

Submission of Accurate Data

Encounter data accuracy and completeness, Part D prescription drug event validation, bid and pricing data integrity, and claims payment accuracy monitoring.

4 questions
Domain 8

Compliance Program Effectiveness

The seven elements of an effective compliance program: written policies, qualified CO, board oversight, specialized training, anonymous reporting, risk assessments, disciplinary framework, and prompt investigation.

8 questions

Ready to Assess Your Compliance Program?

The OIG expects every MA organization to evaluate its compliance program against the new ICPG. Start your free gap assessment now.

Third-party oversight is our specialty.

Harper automates FDR compliance — contract analysis, delegation oversight, exclusion screening, and downstream monitoring. We help MA organizations build auditable, defensible third-party oversight programs.

See how Harper handles FDR oversight