07_Exports data, cross-linked. DRAFT for review; public-source, personal-capacity. Generated 2026-08-04.Pick your operational problem below. Each answer is powered by the same connected control model underneath — every recommendation traces back to COSO, the Green Book, the Fraud Risk Management Guide, OIG guidance and the CFR. You work the problem; the framework does the bookkeeping.
Under the hood — the control library that powers the answers
Updates from the entries you make on the Assessment and Maturity tabs (starts at 0 until you answer). Saved in your browser.
One self-contained file over the whole platform — the control library, the data sources that feed each control, the diagnosis matrix, the enforcement-case evidence, the interactive assessment & maturity model, and the intelligence graph that connects them. Every number is read from the shared 07_Exports data, so the views can't drift apart.
All controls from every module. Click a control to expand its regulatory basis, workflow detail, the data sources that feed it (click to jump), and the diagnosis families it fixes.
The external data each control consumes. "Consumed by" control IDs are clickable — jump straight to the control.
A detection flag your system raised → the implied scheme → the HPI-CT control that fixes it (click the control chip to jump).
Recurring fraud patterns from the coded DOJ case base, each mapped to the control area that closes the loophole.
A separate layer (kept out of the DOJ-coded universe by design). Each 2026 state case drove a new control — click the control chip to jump to it.
The actual questionnaire your organization completes — all questions across the eight HPI-CT modules. Answer each with the option that matches reality (you never pick a score); a hidden key maps your answer to 0–3. Pick a Scoring mode at the top of the questionnaire: Self-reported (answer-first) scores your answers as given and keeps the evidence fields hidden until you want them; Evidence-validated then caps each score by how verifiable your basis is — a self-produced document supports at most 2; only system-generated, independent, or re-performable evidence reaches 3, and only when its provenance is source-obtained or re-performable (or a subject-provided document that is independently verified); an unverified verbal assertion caps at 1. Don't know scores 0. Your entity profile scopes questions in/out and sets targets. Answers save in your browser. Draft — confirm framework mappings against primary sources.
Weighted 0–3 maturity per module, colored by band, from your answers.
Your answers rolled up to the five COSO / Green Book components.
Grouped by module → sub-area. Choose which modules to assess and optionally hide questions that don't apply to your profile. Answers auto-save in this browser.
Score each domain's requirements 0–3 (same weighted model as the module Assessment sheets: 0 None · 1 Ad hoc · 2 Partial · 3 Full). Domain % = Σ(score×weight) ÷ Σ(3×weight); the overall rollup weights every domain by its own maximum. Bands: 1 Initial <30% · 2 Developing 30–49% · 3 Defined 50–69% · 4 Managed 70–89% · 5 Optimized ≥90%. Scores save in your browser. Draft — confirm against the module workbooks.
Weighted maturity % per module, colored by band.
The same 0–3 scores, re-aggregated onto the COSO 2013 / GAO Green Book 17-principle spine and the FRMG and OIG 7-element overlays the v3 modules carry. Fraud-risk readiness = weighted maturity over FRMG-tagged questions; OIG-readiness = over OIG-element-tagged questions. Updates live as you score below. Draft — mappings mirror the module workbooks; confirm against primary sources.
Governance-level principles with no operational-module question (e.g. P5, P6) live in the Module 00 hub.
Rolled up to the five COSO components.
Combines the baseline assessment, the maturity model, and your biggest gaps — each gap linked to the controls that close it. Everything reads live from your saved answers. Draft — self-reported unless evidence-validated mode is on; confirm before external use.
Lowest-scoring answered modules first. Recommended controls are drawn from the same module (preventive first) and respect your entity profile. Click a control to open it in the library.
Scoped to your entity profile and, once you have answered anything, ordered by where you scored weakest. Preventive controls first — the case base puts 63.6% of alleged dollars in the enrollment and authorization stages, so that is where a starting set earns its keep.
The toolkit runs beside existing systems as controls, reports and checklists — no data migration, no core-system change. Pick the cheapest tier that fits what you already own; most organizations start at Tier 0 or 1 and move up only when a specific need justifies it. Draft — confirm figures against primary sources.
| Tier | Model | What it uses | New cost | Legacy impact |
|---|---|---|---|---|
| 0 | Run-as-is (start here) | Excel modules + this HTML, opened locally or on a shared drive | ~none | None |
| 1 | Microsoft 365 overlay | SharePoint/Teams + Excel Online + Power BI + Power Automate | ~none if M365 already licensed | None |
| 2 | Read-only analytics overlay | Existing claims/EHR extracts + existing BI/SQL tools; turns the "Analytics: Yes" controls on | Low | Read-only, no write-back |
| 3 | Workflow attach | Existing ticketing/GRC/EHR tasks + connectors/RPA | Low–moderate | Additive only |
| 4 | Import into owned GRC platform | Archer / AuditBoard / MetricStream already in house | Sunk cost | None |
Days 1–30 (Tier 0): pick the highest-risk domain, run the assessment, review applicable controls & gaps with compliance.
Days 31–60 (Tier 1): move assessment & dashboard into M365; assign control owners; start collecting evidence.
Days 61–90 (Tier 2): stand up 2–3 analytics-driven controls as read-only reports on existing extracts; expand to the next module.
A natural extension of Tier 2: run an actual claim, a provider/KYC package, or a documentation upload through the codifiable controls and return a per-control pass / fail / needs-review scorecard — flagging exactly which controls are missing. Deterministic controls (NCCI PTP/MUE edits, PA/UTN-on-claim, proof-of-delivery present, signature/order on file, exclusion-list & enrollment screening, coverage code vs NCD/LCD applicability) can be checked automatically. Judgment controls (documentation sufficiency, cloned notes) can be flagged for review but not hard-passed. Kept as a pre-payment / pre-submission advisory overlay — not an inline blocking edit — preserving the no-overhaul, low-liability posture.
The same controls, requirements, processes, risks, frameworks and evidence — seen as one connected graph instead of tabs. This is the Healthcare Control Intelligence layer: it answers questions a document library can't. Click one of the questions in the “Ask the graph” panel below (e.g. “which regulatory requirements have no preventive control?”), then click any node to inspect it. These are curated questions for now; free-text natural-language querying is a planned enhancement. Runs in the browser; no server, no PHI. Draft — confirm mappings against primary sources.
One connected model over data that already exists: Requirements → Controls → Process · Risk · Framework · Evidence. Ask questions a document library can't — e.g. "which regulatory requirements have no preventive control?" Runs in the browser; no server, no PHI.
Companion analytics that live beside the graph — public data, no PHI. Opens in a new tab; the interactive version is a Power BI report published into this tab (swap the link when built).
What actually gets providers excluded (OIG List of Excluded Individuals/Entities), each cause mapped to the HPI-CT control that screens for it — plus the Power BI deployment path. Prototype; illustrative figures until the live LEIE file is bound.
Open the LEIE view →