← Back to blog

What the 2026 OIG Work Plan Means for Compliance Officers

August 28, 2026
What the 2026 OIG Work Plan Means for Compliance Officers

The 2026 HHS-OIG Work Plan lists the audits, evaluations, and reviews the agency has approved or has underway, and each new entry is a public signal of where federal scrutiny is headed. When a topic tied to your practice shows up, that's your cue to run a targeted self-audit now, not after a demand letter arrives. Compliance teams that treat the Work Plan as a live risk map, anchored by the HHS-OIG Work Plan page and its Browse Work Plan Projects portal, catch problems months before an auditor does.


TL;DR:

  • The 2026 Work Plan emphasizes audits of evaluation and management coding, telehealth billing, high-cost drugs, and Medicare Advantage review, which are highly relevant to independent practices.
  • Monitoring the continuous updates on the browse portal and setting bi-weekly reminders helps practices stay ahead of new OIG scrutiny rather than reacting after an audit notice.
  • Focused self-audits on high-risk areas like modifier 25 use, telehealth visits, and GLP-1 prescribing can reduce coding errors and document gaps before the OIG detects them.
  • Practices should assign ownership of ongoing Work Plan monitoring, document findings, and implement automated review tools to proactively identify and correct issues.
  • Smaller practices are at a disadvantage due to limited resources, so utilizing tools like Himshield's free revenue leakage report can quickly identify claims at risk without disrupting patient care.

Table of Contents

What Does the OIG Work Plan for 2026 Actually Include?

Each entry in the Work Plan follows a consistent format: a project title, a stated objective, the OIG component running it, and a label marking it mandatory or discretionary. Some entries stand alone. Others belong to a "series," meaning the OIG is running the same review across multiple states, provider types, or years, and updates get posted under that series as work progresses. A handful of titles arrive redacted, usually because the review touches an active investigation or sensitive enforcement matter that OIG isn't ready to disclose publicly.

Reading an entry well means looking past the headline. Before you decide an item is irrelevant to your practice, check these details:

  • Objective language: does it name a specific service, code set, or billing pattern that matches what your practice bills?
  • Population and setting: is the review aimed at hospitals, Medicare Advantage plans, or independent practices specifically?
  • Timeframe: does the review cover claims from a period your practice's records still fall within?
  • Mandatory vs. discretionary tag: mandatory work is happening regardless; discretionary work reflects where OIG chose to spend limited audit hours, which often says more about perceived risk.

A project titled generically, like a review of "evaluation and management coding patterns," can still apply directly to your specialty even without your practice type in the title. Independent groups get swept into national samples more often than most administrators assume.

How Does the OIG Decide and Update Its Projects?

Projects don't appear on the Work Plan by accident. The OIG's Engagement Committee, a body of senior officials across the agency's audit, evaluation, and investigative units, reviews proposed projects and votes to approve them before they go public. That committee weighs several inputs when deciding what earns a spot:

  1. Claims data analytics flagging unusual billing patterns, spikes in specific codes, or outlier reimbursement trends.
  2. Stakeholder referrals, including complaints from patients, whistleblowers, or other federal agencies.
  3. Statutory mandates that require OIG to conduct certain audits regardless of risk scoring.
  4. Emerging programmatic trends, such as new payment models or drug categories drawing federal spending.

That mandatory-versus-discretionary split matters because it tells you which projects OIG is legally obligated to run, similar to how the Department of Labor's FY 2026 OIG Audit Workplan separates required engagements from risk-selected ones, and which reflect a deliberate bet on where fraud or waste is most likely hiding.

The HHS-OIG Work Plan page itself confirms the list is dynamic. The agency posts an annual PDF for reference, but that document is a snapshot the day it's published. The browseable portal updates continuously, adding new projects, closing finished ones, and revising objectives as reviews evolve.

Pro Tip: Don't bookmark the PDF and call it done. Set a recurring calendar reminder to check the browse portal every two weeks. Q1 and Q2 updates in past cycles have shown the OIG isn't shy about pivoting focus mid-year.

Which 2026 Priorities Should Compliance Teams Watch Closely?

Five themes dominate the 2026 Work Plan's footprint for physician practices, and each one maps to a specific documentation or billing behavior worth checking internally before an auditor checks it for you.

  • Medicare billing integrity, particularly evaluation and management coding and modifier 25 use, where OIG has long suspected upcoding tied to same-day procedures.
  • Telehealth coding, since expanded virtual care access created new opportunities for place-of-service errors and documentation shortcuts.
  • High-cost drug oversight, with GLP-1 medications drawing particular attention given their reimbursement volume and off-label prescribing patterns.
  • Prior authorization and managed care practices, focused on whether denials and approvals in Medicare Advantage plans follow medical necessity standards.
  • Hospice and home health payment integrity, where certification documentation and eligibility criteria remain chronic weak points.

For each theme, the audit focus tends to follow a pattern: medical necessity documentation, coding consistency across similar visits, and whether claims edits caught what they should have caught before submission. The OIG's own strategic plan priorities for 2026 through 2030 echo this, emphasizing fraud risk areas and oversight modernization that feed directly into which Work Plan topics get discretionary attention.

The Work Plan's scale reinforces why filtering matters. The browse portal has shown numerous results for a single fiscal year, split between standalone projects and ongoing series, meaning nobody has time to review every entry manually. Practices that skim the full list and stop there miss updates buried in a series they never opened.

How Should You Align Internal Audits to Work Plan Priorities?

Turning a public list into an internal defense plan takes structure, not just awareness. Start with the moves you can make this week, then build the cadence that keeps you current.

  1. Subscribe to updates. Follow the OIG "What's New" feed for monthly postings, since relying on annual reviews alone means you'll learn about a relevant project months after it's already public.
  2. Run a focused self-audit for every named risk area that overlaps your specialty or billing mix, pulling a defensible sample rather than a token handful of charts.
  3. Document findings and corrective action in writing, with dates, responsible staff, and remediation deadlines, because that paper trail is what protects you if OIG ever asks.

Assign ownership clearly: someone on your compliance or HIM team should own Work Plan monitoring as a standing responsibility, reporting monthly signals to leadership and reserving quarterly time for deeper dives tied to fresh Work Plan updates. A risk-based audit approach helps you decide sample sizes without wasting hours reviewing low-risk charts.

Pro Tip: Map every Work Plan entry that applies to your practice against your internal risk register the same week it posts. Waiting for the full report to publish means you're reacting to findings instead of getting ahead of them.

This is where automated review tools earn their place. Instead of manually cross-referencing hundreds of chart notes against a growing list of OIG focus areas, a platform that scans your EHR data can flag coding and documentation gaps tied to those exact themes and produce a per-provider Revenue Leakage Report your team can act on immediately, giving you evidence you'd otherwise spend weeks assembling by hand.

Hands with dark tablet on medical desk

Why Independent Practices Can't Afford to Wait on This

Why Independent Practices Can't Afford to Wait on This — overview diagram

Independent physician practices face a structural disadvantage here: no dedicated compliance department, no in-house audit team, and limited bandwidth to track a list that grows every quarter. That gap is exactly why so many small practices only discover a coding pattern was flagged nationally after their own claims already reflect it.

The highest-value move for the next few months is narrow and specific: pull charts tied to E/M coding with modifier 25, telehealth visits, and any GLP-1 prescribing, and correct documentation gaps you find immediately. Over the following two quarters, formalize that review into a repeatable process, ideally with periodic automated monitoring rather than an annual scramble, and track your progress with concrete numbers: fewer coding exceptions per audit cycle, shorter time between finding an issue and fixing it, and a governance record you could hand an auditor without notice. Practices that build this rhythm stop treating the Work Plan as an annual news event and start treating it as an operating input, which is the only version of compliance that actually holds up under scrutiny.

— Elena

Get Ahead of 2026 Work Plan Risk Before an Audit Letter Arrives

Reading the Work Plan tells you where the risk is. Closing the gap before OIG finds it requires actually checking your own claims data, and that's the part for which most independent practices don't have staff hours. Himshield connects to your EHR, scans your coding and documentation against the exact patterns OIG is watching in 2026, from modifier 25 use to telehealth place-of-service errors, and quantifies what's at risk in a per-provider, per-payer report you can act on immediately.

Himshield

You don't need a new hire or a six-month rollout to get a clear picture. Himshield's free 30-day Revenue Leakage Report shows you exactly where coding and documentation gaps could turn into denials or audit exposure, with a performance guarantee before you commit to anything paid. See how Himshield's platform works to connect your EHR and get evidence-ready findings without pulling your staff off patient care for a manual chart review.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources