Healthcare Compliance Auditing Training Course

5 days Auditing Certificate on completion
Course codeSD-A-038
Duration5 days
LevelIntermediate
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Healthcare organisations face overlapping audit pressures: inaccurate claims, unsupported charges, duplicate payments, weak vendor controls, incomplete exclusions screening, and inconsistent handling of protected health information can create repayment obligations, civil penalties, and damaged payer relationships. Finance, compliance, and internal audit teams need to test high-risk processes before a government reviewer, commercial payer, or external auditor identifies the issue. This course focuses on building audit work that is evidence-based, risk-led, and capable of producing defensible findings.

Participants learn to plan and execute healthcare compliance audits across revenue cycle, billing, coding support, accounts payable, procurement, and third-party arrangements. They apply risk assessment methods, develop audit objectives and test plans, select samples, analyse transactional data, document evidence, assess control design and operating effectiveness, and distinguish isolated errors from systemic control failures. The course uses healthcare-specific requirements including HIPAA Privacy and Security Rules, CMS program-integrity guidance, Office of Inspector General priorities, and exclusion-screening expectations.

Instructor-led sessions combine worked examples with audit-file exercises using claims, payment, vendor, and access-log scenarios. Participants build an audit planning memorandum, risk-and-control matrix, sampling approach, test sheets, exception log, root-cause analysis, and management report for a simulated healthcare provider. They leave with a reusable healthcare compliance audit toolkit and an action plan for applying it to a live area of responsibility.

The programme is designed for experienced professionals who already understand their organisation’s financial, compliance, or operational processes and now need a structured method for auditing healthcare risk.

Course objectives

By the end of this course, participants will be able to:

  • Construct a healthcare compliance audit plan using a risk assessment, scope statement, objectives, criteria, and resource estimate
  • Map revenue-cycle, procurement, and payment processes into a risk-and-control matrix
  • Test control design and operating effectiveness using walkthroughs, evidence requests, and attribute-based test sheets
  • Apply HIPAA, CMS program-integrity, OIG, and exclusion-screening criteria to audit observations
  • Develop statistically informed and judgemental sampling approaches for claims, invoices, and payment populations
  • Analyse transactional data in Excel and ACL Analytics to identify duplicate payments, outliers, and control exceptions
  • Document audit evidence, exceptions, root causes, and corrective actions in a defensible working-paper file
  • Present a healthcare compliance audit report with prioritised findings, management actions, owners, and due dates

Benefits of attending

For you

  • Build a portfolio-quality healthcare audit file that demonstrates planning, testing, and reporting capability
  • Gain practical confidence in auditing claims, payment, vendor, and privacy-control risks
  • Learn to translate healthcare regulations into testable control criteria rather than relying on policy review alone
  • Strengthen credibility when challenging control owners with documented evidence and root-cause analysis
  • Prepare for broader internal audit, compliance audit, revenue-integrity, or healthcare finance assurance responsibilities

For your organisation

  • Improve early detection of unsupported billing, duplicate payments, exclusion-screening gaps, and weak approvals
  • Create more consistent audit planning, sampling, working papers, and reporting across assurance teams
  • Reduce repayment, payer-dispute, regulatory-enforcement, and reputational exposure through stronger control testing
  • Give management prioritised findings linked to accountable owners, corrective actions, and implementation dates
  • Increase the value of audit data by applying repeatable exception tests to claims and payment populations

Target competencies

Healthcare risk assessmentControl effectiveness testingAudit sampling designClaims data analysisEvidence documentationCorrective action reporting

Who should attend

  • Healthcare Internal Auditors — who need repeatable methods for testing financial and compliance controls
  • Healthcare Compliance Officers — who must independently validate whether high-risk obligations are operating effectively
  • Revenue Cycle Managers — who need to identify billing, charge-capture, and claims-control weaknesses before payer review
  • Finance Managers and Controllers — who oversee payment, reconciliation, and financial-control environments in provider organisations
  • Medical Billing and Coding Audit Professionals — who need stronger audit planning, sampling, and evidence-documentation skills
  • Procurement and Accounts Payable Managers — who must reduce vendor, duplicate-payment, conflict-of-interest, and approval risks

Requirements and prerequisites

Participants should have working experience in a healthcare provider, payer, pharmacy, health system, or related healthcare-services environment, plus familiarity with basic financial transactions such as claims, invoices, payments, reconciliations, or general-ledger entries. The course assumes that participants can use Excel for sorting, filtering, formulas, and pivot tables, and can read a process flow or policy. Prior internal-audit certification, formal accounting qualification, coding credential, statistical training, or ACL Analytics experience is not required. Participants do not need to be legal specialists, but should be prepared to work with HIPAA and payer-compliance scenarios.

Training methodology

The five-day programme uses instructor-led briefings to establish audit criteria, followed by hands-on work with realistic provider data and audit documents. Participants complete process walkthroughs, create risk-and-control matrices, test claims and invoice samples, and use Excel and ACL Analytics demonstrations to investigate anomalies. Small groups challenge each other’s findings in management-review simulations, requiring clear evidence and proportionate recommendations. Each day adds to a single audit case file, and the final session converts that work into a practical 90-day application plan for the participant’s own audit universe.

Course outline

Day 1: Healthcare compliance audit foundations

  • Healthcare audit universe and risk-based assurance planning
  • HIPAA Privacy Rule and Security Rule audit criteria
  • CMS program-integrity oversight and payer audit expectations
  • OIG Work Plan priorities and exclusion-screening risk
  • Audit charter, independence, and scope boundaries
  • Healthcare process walkthroughs and narrative documentation
  • Risk scoring using likelihood, impact, velocity, and control maturity

Workshop: Participants assess a simulated hospital audit universe and produce a ranked risk register with proposed audit scopes.

Day 2: Planning controls and audit tests

  • Audit planning memoranda and measurable audit objectives
  • Revenue-cycle risk points from registration through remittance
  • Procure-to-pay controls for vendors, invoices, and approvals
  • Risk-and-control matrix construction
  • Control design versus operating-effectiveness testing
  • Evidence request lists and audit trail preservation
  • Attribute sampling and sample-size considerations

Workshop: Participants create a risk-and-control matrix and detailed test plan for a claims and payment process.

Day 3: Healthcare data testing and exception analysis

  • Defining complete and reliable claims and payment populations
  • Excel pivot tables, filters, and conditional formatting for audit tests
  • ACL Analytics joins, stratification, duplicate testing, and exception extraction
  • Duplicate-payment and split-invoice detection logic
  • Claims outlier analysis by provider, procedure, modifier, and payer
  • Exclusions, sanction, and vendor-master screening controls
  • Investigating exceptions without overstating audit conclusions

Workshop: Participants analyse a supplied claims and accounts-payable dataset and produce an exception log with supporting evidence.

Day 4: Findings root cause and corrective action

  • Working-paper standards for evidence, cross-referencing, and review notes
  • Assessing condition, criteria, cause, consequence, and corrective action
  • Root-cause analysis using five whys and fishbone diagrams
  • Quantifying financial exposure, extrapolation limits, and qualitative risk
  • Severity rating using regulatory, financial, and patient-impact factors
  • Corrective action design, ownership, milestones, and validation criteria
  • Issue follow-up testing and closure evidence

Workshop: Participants convert tested exceptions into a root-cause analysis and corrective-action plan for management review.

Day 5: Reporting and audit application

  • Writing concise healthcare compliance audit observations
  • Executive reporting with risk ratings and dashboard measures
  • Communicating disputed findings and management responses
  • Audit committee reporting considerations
  • Quality assurance review of audit files
  • Building a rolling healthcare compliance audit plan
  • Ninety-day implementation planning for live audit assignments

Workshop: Participants present a final audit report and 90-day application plan based on the week-long healthcare provider case.

Tools & standards covered

Microsoft Excel, ACL Analytics, CMS Medicare Program Integrity Manual, HHS Office of Inspector General Work Plan

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand at least one healthcare process involving claims, billing, coding support, payments, vendors, compliance, or financial controls. Previous audit training is helpful but not required; the course teaches the audit planning, testing, and reporting method from the ground up.

A laptop with Excel is strongly recommended for the data-testing exercises. ACL Analytics is demonstrated using course materials, and prior access or installation is not required to complete the programme.

Yes, provided participants have responsibility for reviewing or improving process controls. The casework is focused on financially significant compliance risks, including billing, payments, vendors, exclusions, and protected health information controls.

General audit courses teach transferable assurance concepts, while this programme applies them to healthcare claims, revenue-cycle, procurement, payer, and regulatory-risk scenarios. It also goes beyond HIPAA awareness by showing how to turn requirements into audit criteria, tests, evidence, and findings.

Participants leave with reusable templates for an audit plan, risk-and-control matrix, test sheet, exception log, finding form, and corrective-action tracker. These can be adapted to a current claims, payment, vendor, privacy, or exclusion-screening audit.

You leave with a completed simulated healthcare compliance audit file, including planning documents, data exceptions, tested controls, root-cause analysis, and a management report. You also create a 90-day plan identifying how to use the approach in your own organisation.

Upcoming sessions

  • 21 – 25 Sep 2026
    Nairobi · USD 3,000
    Book
  • 28 Sep – 02 Oct 2026
    Nairobi · USD 3,000
    Book
  • 05 – 09 Oct 2026
    Nairobi · USD 3,000
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 19 – 23 Oct 2026
    Nairobi · USD 3,000
    Book
  • 19 – 23 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Cape Town · USD 4,200
    Book
  • 26 – 30 Oct 2026
    Mombasa · USD 3,200
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

IIA Global Internal Audit Standards Implementation Training Course

The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…

5 Days Certificate

Strategic Internal Audit Leadership for Chief Audit Executives Training Course

Chief Audit Executives are expected to provide more than assurance over completed transactions. They must help the board and executive team …

5 Days Certificate

IIA Three Lines Model Assurance Mapping Training Course

Boards, audit committees and executives need a defensible view of whether material risks are covered by reliable assurance—not simply a list…

5 Days Certificate

Insurance Premium and Claims Auditing Training Course

Premium leakage, inaccurate earned-premium calculations, duplicate claim payments, weak reserving evidence, and inconsistent authority contr…