Healthcare Compliance Auditing Training Course
| Course code | SD-A-038 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Healthcare organisations face overlapping audit pressures: inaccurate claims, unsupported charges, duplicate payments, weak vendor controls, incomplete exclusions screening, and inconsistent handling of protected health information can create repayment obligations, civil penalties, and damaged payer relationships. Finance, compliance, and internal audit teams need to test high-risk processes before a government reviewer, commercial payer, or external auditor identifies the issue. This course focuses on building audit work that is evidence-based, risk-led, and capable of producing defensible findings.
Participants learn to plan and execute healthcare compliance audits across revenue cycle, billing, coding support, accounts payable, procurement, and third-party arrangements. They apply risk assessment methods, develop audit objectives and test plans, select samples, analyse transactional data, document evidence, assess control design and operating effectiveness, and distinguish isolated errors from systemic control failures. The course uses healthcare-specific requirements including HIPAA Privacy and Security Rules, CMS program-integrity guidance, Office of Inspector General priorities, and exclusion-screening expectations.
Instructor-led sessions combine worked examples with audit-file exercises using claims, payment, vendor, and access-log scenarios. Participants build an audit planning memorandum, risk-and-control matrix, sampling approach, test sheets, exception log, root-cause analysis, and management report for a simulated healthcare provider. They leave with a reusable healthcare compliance audit toolkit and an action plan for applying it to a live area of responsibility.
The programme is designed for experienced professionals who already understand their organisation’s financial, compliance, or operational processes and now need a structured method for auditing healthcare risk.
Course objectives
By the end of this course, participants will be able to:
- Construct a healthcare compliance audit plan using a risk assessment, scope statement, objectives, criteria, and resource estimate
- Map revenue-cycle, procurement, and payment processes into a risk-and-control matrix
- Test control design and operating effectiveness using walkthroughs, evidence requests, and attribute-based test sheets
- Apply HIPAA, CMS program-integrity, OIG, and exclusion-screening criteria to audit observations
- Develop statistically informed and judgemental sampling approaches for claims, invoices, and payment populations
- Analyse transactional data in Excel and ACL Analytics to identify duplicate payments, outliers, and control exceptions
- Document audit evidence, exceptions, root causes, and corrective actions in a defensible working-paper file
- Present a healthcare compliance audit report with prioritised findings, management actions, owners, and due dates
Benefits of attending
For you
- Build a portfolio-quality healthcare audit file that demonstrates planning, testing, and reporting capability
- Gain practical confidence in auditing claims, payment, vendor, and privacy-control risks
- Learn to translate healthcare regulations into testable control criteria rather than relying on policy review alone
- Strengthen credibility when challenging control owners with documented evidence and root-cause analysis
- Prepare for broader internal audit, compliance audit, revenue-integrity, or healthcare finance assurance responsibilities
For your organisation
- Improve early detection of unsupported billing, duplicate payments, exclusion-screening gaps, and weak approvals
- Create more consistent audit planning, sampling, working papers, and reporting across assurance teams
- Reduce repayment, payer-dispute, regulatory-enforcement, and reputational exposure through stronger control testing
- Give management prioritised findings linked to accountable owners, corrective actions, and implementation dates
- Increase the value of audit data by applying repeatable exception tests to claims and payment populations
Target competencies
Who should attend
- Healthcare Internal Auditors — who need repeatable methods for testing financial and compliance controls
- Healthcare Compliance Officers — who must independently validate whether high-risk obligations are operating effectively
- Revenue Cycle Managers — who need to identify billing, charge-capture, and claims-control weaknesses before payer review
- Finance Managers and Controllers — who oversee payment, reconciliation, and financial-control environments in provider organisations
- Medical Billing and Coding Audit Professionals — who need stronger audit planning, sampling, and evidence-documentation skills
- Procurement and Accounts Payable Managers — who must reduce vendor, duplicate-payment, conflict-of-interest, and approval risks
Requirements and prerequisites
Participants should have working experience in a healthcare provider, payer, pharmacy, health system, or related healthcare-services environment, plus familiarity with basic financial transactions such as claims, invoices, payments, reconciliations, or general-ledger entries. The course assumes that participants can use Excel for sorting, filtering, formulas, and pivot tables, and can read a process flow or policy. Prior internal-audit certification, formal accounting qualification, coding credential, statistical training, or ACL Analytics experience is not required. Participants do not need to be legal specialists, but should be prepared to work with HIPAA and payer-compliance scenarios.
Training methodology
The five-day programme uses instructor-led briefings to establish audit criteria, followed by hands-on work with realistic provider data and audit documents. Participants complete process walkthroughs, create risk-and-control matrices, test claims and invoice samples, and use Excel and ACL Analytics demonstrations to investigate anomalies. Small groups challenge each other’s findings in management-review simulations, requiring clear evidence and proportionate recommendations. Each day adds to a single audit case file, and the final session converts that work into a practical 90-day application plan for the participant’s own audit universe.
Course outline
Day 1: Healthcare compliance audit foundations
- Healthcare audit universe and risk-based assurance planning
- HIPAA Privacy Rule and Security Rule audit criteria
- CMS program-integrity oversight and payer audit expectations
- OIG Work Plan priorities and exclusion-screening risk
- Audit charter, independence, and scope boundaries
- Healthcare process walkthroughs and narrative documentation
- Risk scoring using likelihood, impact, velocity, and control maturity
Workshop: Participants assess a simulated hospital audit universe and produce a ranked risk register with proposed audit scopes.
Day 2: Planning controls and audit tests
- Audit planning memoranda and measurable audit objectives
- Revenue-cycle risk points from registration through remittance
- Procure-to-pay controls for vendors, invoices, and approvals
- Risk-and-control matrix construction
- Control design versus operating-effectiveness testing
- Evidence request lists and audit trail preservation
- Attribute sampling and sample-size considerations
Workshop: Participants create a risk-and-control matrix and detailed test plan for a claims and payment process.
Day 3: Healthcare data testing and exception analysis
- Defining complete and reliable claims and payment populations
- Excel pivot tables, filters, and conditional formatting for audit tests
- ACL Analytics joins, stratification, duplicate testing, and exception extraction
- Duplicate-payment and split-invoice detection logic
- Claims outlier analysis by provider, procedure, modifier, and payer
- Exclusions, sanction, and vendor-master screening controls
- Investigating exceptions without overstating audit conclusions
Workshop: Participants analyse a supplied claims and accounts-payable dataset and produce an exception log with supporting evidence.
Day 4: Findings root cause and corrective action
- Working-paper standards for evidence, cross-referencing, and review notes
- Assessing condition, criteria, cause, consequence, and corrective action
- Root-cause analysis using five whys and fishbone diagrams
- Quantifying financial exposure, extrapolation limits, and qualitative risk
- Severity rating using regulatory, financial, and patient-impact factors
- Corrective action design, ownership, milestones, and validation criteria
- Issue follow-up testing and closure evidence
Workshop: Participants convert tested exceptions into a root-cause analysis and corrective-action plan for management review.
Day 5: Reporting and audit application
- Writing concise healthcare compliance audit observations
- Executive reporting with risk ratings and dashboard measures
- Communicating disputed findings and management responses
- Audit committee reporting considerations
- Quality assurance review of audit files
- Building a rolling healthcare compliance audit plan
- Ninety-day implementation planning for live audit assignments
Workshop: Participants present a final audit report and 90-day application plan based on the week-long healthcare provider case.
Tools & standards covered
Microsoft Excel, ACL Analytics, CMS Medicare Program Integrity Manual, HHS Office of Inspector General Work Plan
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
05 – 09 Oct 2026Book
Nairobi · USD 3,000 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Cape Town · USD 4,200 -
26 – 30 Oct 2026Book
Mombasa · USD 3,200
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Auditing
IIA Global Internal Audit Standards Implementation Training Course
The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…
Strategic Internal Audit Leadership for Chief Audit Executives Training Course
Chief Audit Executives are expected to provide more than assurance over completed transactions. They must help the board and executive team …
IIA Three Lines Model Assurance Mapping Training Course
Boards, audit committees and executives need a defensible view of whether material risks are covered by reliable assurance—not simply a list…
Insurance Premium and Claims Auditing Training Course
Premium leakage, inaccurate earned-premium calculations, duplicate claim payments, weak reserving evidence, and inconsistent authority contr…