WHEN POLICY MEETS PRACTICE | A TWO-PART SERIES
How quality assurance and quality improvement audits keep policies alive and patients safe
Written by Robert Colon-Torres
Every health system has policies. Far fewer can prove those policies are followed, or that they work. That gap is where preventable harm, financial penalties, and legal exposure live.
In nearly 25 years of healthcare compliance work, I have rarely investigated an adverse event where no policy existed. Far more often, the policy was there. It had been approved, posted, and acknowledged in an annual training. It simply was not what happened on the floor, and no one had checked.
This is the first of a two-part series on that gap between the policies health systems write and the care they actually deliver. My argument across both parts is straightforward: quality assurance (QA) and quality improvement (QI) audits are what turn a policy from a document into a practice, and compliance and CQI must operate as one team to make that happen. Part 1 examines what is at stake when the gap goes unchecked: for patients, for the organization's finances, and in front of regulators and courts. Part 2 explains why the gap opens and how to close it.
Harm is common, and much of it is preventable
The Institute of Medicine's To Err Is Human (1999) estimated that up to 98,000 hospitalized Americans die each year from preventable error.[1] Later estimates ranged far higher, including the widely cited 2016 claim that medical error is the third leading cause of death in the U.S.[2] Those higher figures have been sharply criticized on methodological grounds, and a 2020 meta-analysis put preventable inpatient deaths closer to 22,000 a year.[3][4] Compliance professionals should resist the temptation to lead with the most dramatic number; our credibility depends on precision.
But the debate over mortality obscures a point on which the evidence is consistent: harm itself is common. The HHS Office of Inspector General found that one in four hospitalized Medicare patients experienced harm, and that 43 percent of those events were preventable.[5] A 2023 New England Journal of Medicine study of eleven Massachusetts hospitals found adverse events in nearly one in four admissions, about a quarter of them preventable.[6] More than two decades after To Err Is Human, the problem has not been solved. In most of these cases, the evidence-based practice that would have prevented harm was already known.
Where policy and practice drift apart
Bar code medication administration (BCMA) shows how the drift happens. BCMA was designed to stop wrong-patient and wrong-dose errors, yet researchers documented fifteen distinct workarounds, including spare wristbands taped to carts and door frames, multiple patients' medications carried on one tray, and medications given first and scanned later.[7] None of this was sabotage. Each workaround was a rational response to workload, equipment placement, or a process that did not fit the real work.
Left alone, workarounds become what sociologist Diane Vaughan called the normalization of deviance: each shortcut that does not immediately cause harm makes the next one feel acceptable, until the unofficial procedure has replaced the official one.[8] By the time an adverse event exposes the gap, the deviation may have been routine for years. An audit is the only reliable way to see it sooner. A workaround is not just a staff behavior to correct; it is data showing exactly where the policy and the work have come apart.
Regulators now ask whether your program works
The compliance standard has shifted from “Do you have a policy?” to “Can you show that it works?” The HHS-OIG General Compliance Program Guidance (2023) treats auditing and monitoring as a core element of an effective program and expressly identifies quality and patient safety as compliance risks that boards should oversee.[9] The Department of Justice's Evaluation of Corporate Compliance Programs (updated 2024) asks prosecutors to judge not only whether a program is well designed, but whether it “works in practice,” including whether the organization tests its controls and learns from what it finds.[10]
The financial incentives point the same way. Since 2008, Medicare has declined to pay the added cost of certain hospital-acquired conditions, and the HAC Reduction Program reduces payments by one percent for the worst-performing quarter of hospitals.[11] Measurable medical errors were estimated to cost the U.S. economy $17.1 billion in a single year.[12] An unaudited policy is not a neutral gap. It is unpriced financial risk.
Your policies will be read in court
Courts in many states allow a health system's own policies to be admitted as evidence of the standard of care.[13] In Jutzi v. County of Los Angeles (1987), a county policy authorizing emergency physicians to treat orthopedic injuries helped establish that the hospital had met its standard of care.[14] In Heastie v. Roberts (2007), where a restrained patient was burned after the hospital's own contraband-search policy was not followed, the Illinois Supreme Court held that internal policies may be considered by the jury as evidence bearing on the standard of care, while a violation alone does not automatically establish negligence.[15]
The lesson for compliance is that a followed policy can protect you, and an unfollowed one can hurt you, sometimes more than having no policy at all. The only way to know which kind you have is to audit it.
A system problem, not a staff problem
When harm occurs, the instinct is to find the person who made the mistake. A just culture approach asks a better question: what in the system made the error likely?[16] Individuals remain accountable for reckless choices, but most errors and workarounds are system signals. Blaming the individual closes the file and leaves the conditions in place for the next event. QA and QI audits are how an organization turns systems thinking from a slogan into a practice.
About the Author
Robert Colon-Torres is a healthcare compliance executive with roughly 25 years of experience, most recently as a chief compliance officer for federally qualified health centers in California. He holds a degree in health law from Loyola University Chicago.
References
- Kohn LT, Corrigan JM, Donaldson MS, eds. To Err Is Human: Building a Safer Health System. Institute of Medicine; 2000.
- Makary MA, Daniel M. Medical error: the third leading cause of death in the US. BMJ. 2016;353:i2139.
- Shojania KG, Dixon-Woods M. Estimating deaths due to medical error: the ongoing controversy and why it matters. BMJ Qual Saf. 2017;26(5):423–428.
- Rodwin BA, et al. Rate of preventable mortality in hospitalized patients: a systematic review and meta-analysis. J Gen Intern Med. 2020;35(7):2099–2106.
- HHS Office of Inspector General. Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (OEI-06-18-00400). 2022.
- Bates DW, et al. The safety of inpatient health care. N Engl J Med. 2023;388(2):142–153.
- Koppel R, et al. Workarounds to barcode medication administration systems. J Am Med Inform Assoc. 2008;15(4):408–423.
- Banja J. The normalization of deviance in healthcare delivery. Bus Horiz. 2010;53(2):139–148.
- HHS Office of Inspector General. General Compliance Program Guidance. November 2023.
- U.S. Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs. Updated September 2024.
- Centers for Medicare & Medicaid Services. Hospital-Acquired Condition Reduction Program.
- Van Den Bos J, et al. The $17.1 billion problem: the annual cost of measurable medical errors. Health Aff. 2011;30(4):596–603.
- Bal BS. An introduction to medical malpractice in the United States. Clin Orthop Relat Res. 2009;467(2):339–347.
- Jutzi v. County of Los Angeles, 196 Cal. App. 3d 637 (1987).
- Heastie v. Roberts, 226 Ill. 2d 515 (2007).
- Marx D. Patient Safety and the “Just Culture”: A Primer for Health Care Executives. Columbia University; 2001.
Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved






