Quality
Auditing, Corporate Compliance, Quality

The Cost of an Unchecked Policy

WHEN POLICY MEETS PRACTICE | A TWO-PART SERIES

How quality assurance and quality improvement audits keep policies alive and patients safe

Written by Robert Colon-Torres   

Every health system has policies. Far fewer can prove those policies are followed, or that they work. That gap is where preventable harm, financial penalties, and legal exposure live.

In nearly 25 years of healthcare compliance work, I have rarely investigated an adverse event where no policy existed. Far more often, the policy was there. It had been approved, posted, and acknowledged in an annual training. It simply was not what happened on the floor, and no one had checked.

This is the first of a two-part series on that gap between the policies health systems write and the care they actually deliver. My argument across both parts is straightforward: quality assurance (QA) and quality improvement (QI) audits are what turn a policy from a document into a practice, and compliance and CQI must operate as one team to make that happen. Part 1 examines what is at stake when the gap goes unchecked: for patients, for the organization's finances, and in front of regulators and courts. Part 2 explains why the gap opens and how to close it.

Harm is common, and much of it is preventable

The Institute of Medicine's To Err Is Human (1999) estimated that up to 98,000 hospitalized Americans die each year from preventable error.[1] Later estimates ranged far higher, including the widely cited 2016 claim that medical error is the third leading cause of death in the U.S.[2] Those higher figures have been sharply criticized on methodological grounds, and a 2020 meta-analysis put preventable inpatient deaths closer to 22,000 a year.[3][4] Compliance professionals should resist the temptation to lead with the most dramatic number; our credibility depends on precision.

But the debate over mortality obscures a point on which the evidence is consistent: harm itself is common. The HHS Office of Inspector General found that one in four hospitalized Medicare patients experienced harm, and that 43 percent of those events were preventable.[5] A 2023 New England Journal of Medicine study of eleven Massachusetts hospitals found adverse events in nearly one in four admissions, about a quarter of them preventable.[6] More than two decades after To Err Is Human, the problem has not been solved. In most of these cases, the evidence-based practice that would have prevented harm was already known.

Where policy and practice drift apart

Bar code medication administration (BCMA) shows how the drift happens. BCMA was designed to stop wrong-patient and wrong-dose errors, yet researchers documented fifteen distinct workarounds, including spare wristbands taped to carts and door frames, multiple patients' medications carried on one tray, and medications given first and scanned later.[7] None of this was sabotage. Each workaround was a rational response to workload, equipment placement, or a process that did not fit the real work.

Left alone, workarounds become what sociologist Diane Vaughan called the normalization of deviance: each shortcut that does not immediately cause harm makes the next one feel acceptable, until the unofficial procedure has replaced the official one.[8] By the time an adverse event exposes the gap, the deviation may have been routine for years. An audit is the only reliable way to see it sooner. A workaround is not just a staff behavior to correct; it is data showing exactly where the policy and the work have come apart.

Regulators now ask whether your program works

The compliance standard has shifted from “Do you have a policy?” to “Can you show that it works?” The HHS-OIG General Compliance Program Guidance (2023) treats auditing and monitoring as a core element of an effective program and expressly identifies quality and patient safety as compliance risks that boards should oversee.[9] The Department of Justice's Evaluation of Corporate Compliance Programs (updated 2024) asks prosecutors to judge not only whether a program is well designed, but whether it “works in practice,” including whether the organization tests its controls and learns from what it finds.[10]

The financial incentives point the same way. Since 2008, Medicare has declined to pay the added cost of certain hospital-acquired conditions, and the HAC Reduction Program reduces payments by one percent for the worst-performing quarter of hospitals.[11] Measurable medical errors were estimated to cost the U.S. economy $17.1 billion in a single year.[12] An unaudited policy is not a neutral gap. It is unpriced financial risk.

Your policies will be read in court

Courts in many states allow a health system's own policies to be admitted as evidence of the standard of care.[13] In Jutzi v. County of Los Angeles (1987), a county policy authorizing emergency physicians to treat orthopedic injuries helped establish that the hospital had met its standard of care.[14] In Heastie v. Roberts (2007), where a restrained patient was burned after the hospital's own contraband-search policy was not followed, the Illinois Supreme Court held that internal policies may be considered by the jury as evidence bearing on the standard of care, while a violation alone does not automatically establish negligence.[15]

The lesson for compliance is that a followed policy can protect you, and an unfollowed one can hurt you, sometimes more than having no policy at all. The only way to know which kind you have is to audit it.

A system problem, not a staff problem

When harm occurs, the instinct is to find the person who made the mistake. A just culture approach asks a better question: what in the system made the error likely?[16] Individuals remain accountable for reckless choices, but most errors and workarounds are system signals. Blaming the individual closes the file and leaves the conditions in place for the next event. QA and QI audits are how an organization turns systems thinking from a slogan into a practice.

About the Author

Robert Colon-Torres is a healthcare compliance executive with roughly 25 years of experience, most recently as a chief compliance officer for federally qualified health centers in California. He holds a degree in health law from Loyola University Chicago.


References

  1. Kohn LT, Corrigan JM, Donaldson MS, eds. To Err Is Human: Building a Safer Health System. Institute of Medicine; 2000.
  2. Makary MA, Daniel M. Medical error: the third leading cause of death in the US. BMJ. 2016;353:i2139.
  3. Shojania KG, Dixon-Woods M. Estimating deaths due to medical error: the ongoing controversy and why it matters. BMJ Qual Saf. 2017;26(5):423–428.
  4. Rodwin BA, et al. Rate of preventable mortality in hospitalized patients: a systematic review and meta-analysis. J Gen Intern Med. 2020;35(7):2099–2106.
  5. HHS Office of Inspector General. Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (OEI-06-18-00400). 2022.
  6. Bates DW, et al. The safety of inpatient health care. N Engl J Med. 2023;388(2):142–153.
  7. Koppel R, et al. Workarounds to barcode medication administration systems. J Am Med Inform Assoc. 2008;15(4):408–423.
  8. Banja J. The normalization of deviance in healthcare delivery. Bus Horiz. 2010;53(2):139–148.
  9. HHS Office of Inspector General. General Compliance Program Guidance. November 2023.
  10. U.S. Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs. Updated September 2024.
  11. Centers for Medicare & Medicaid Services. Hospital-Acquired Condition Reduction Program.
  12. Van Den Bos J, et al. The $17.1 billion problem: the annual cost of measurable medical errors. Health Aff. 2011;30(4):596–603.
  13. Bal BS. An introduction to medical malpractice in the United States. Clin Orthop Relat Res. 2009;467(2):339–347.
  14. Jutzi v. County of Los Angeles, 196 Cal. App. 3d 637 (1987).
  15. Heastie v. Roberts, 226 Ill. 2d 515 (2007).
  16. Marx D. Patient Safety and the “Just Culture”: A Primer for Health Care Executives. Columbia University; 2001.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Burnout, Boundaries, and Compliance
Corporate Compliance, Leadership

Building Employee Engagement

Through Meaningful Healthcare Compliance Training

Written by Misty Kelly, OHCC, HPOC with contributions from Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS and Joy Rose, MSA, RHIA, CCS, CHA, CHPS   

This article was developed through collaboration with AIHC Education Volunteer Committee compliance professionals who shared practical experiences and lessons learned related to employee engagement and compliance education.

Several years ago, our organization deployed annual compliance training through a learning management system. Completion rates were acceptable; however, employees frequently waited until the deadline to complete their assignments, and retention of key concepts remained difficult to assess. The experience reinforced an important lesson: compliance training should not simply be focused on completion. It should focus on understanding and application. 

Training can satisfy a requirement without changing behavior. A completed module or passing quiz may document participation but does not necessarily demonstrate that an employee understands the expectation, recognizes when it applies, or can incorporate it into daily decision making. 

Begin With the “Why”

Organizations use a variety of methods to deliver compliance education, including annual LMS (learning management system) assignments, in-person presentations, newsletters, microlearning modules, department meetings, and one-on-one coaching. What resonates with one workforce member may not be as effective with another. Compliance professionals should remain flexible and willing to adjust their approach based on employee needs and organizational culture.

Nancie Cummins noted, “I have found individual training has helped the most. You can go through a format that meets Compliance plan criteria and have individuals interact to answer their specific needs. This way, you can address the compliance requirements while still allowing individuals to engage directly, ask questions, and receive guidance that is specific to their role and needs.”

While individualized training may not always be practical on a large scale, the underlying principle remains important: employees are more engaged when training is relevant to their role and allows opportunities for interaction, questions, and clarification. Even when one-on-one training is not feasible, larger sessions can incorporate opportunities for questions, discussion, and role-specific examples.

One Size Does Not Fit All

The challenge for compliance professionals is determining which methods will resonate most effectively with their workforce. There is no single correct approach. What works well in one organization may not work in another, and a method that was successful last year may be less effective today. Organizational cultures evolve, workforce demographics change, and training needs shift. Compliance professionals must remain attentive to those changes and be willing to adjust the format, timing, and level of interaction. 

The concept that compliance programs are not one-size-fits-all also applies to training platforms and methods. My overall goal with this article is to provide practical information to help guide new compliance professionals and offer new perspectives to seasoned professionals. 

Compliance education should not be limited to annual training. Whether education is delivered through a formal module, an ad hoc session, targeted remediation, or a Compliance & Ethics Week activity, employees should understand why the information matters. Whenever possible, connect the training to one or more of the following: 

  • Patient care and safety
  • The employee’s individual role
  • Organizational integrity
  • Operational effectiveness
  • Reputation and trust
  • Prevention of avoidable compliance problems
  • Other organizational-specific priorities

Employees are more likely to retain and apply information when they can see its relevance to their work. 

“Employees are frequently completing a checkbox without understanding the ‘why’ behind what they are doing.” – Joy Rose. Joy Rose’s observation reflects a common challenge. Employees are more likely to engage when expectations are connected to their daily responsibilities and the organization’s broader mission. Meaningful engagement requires a clear connection between the requirement, the employee’s role, and the consequence the requirement is intended to prevent. 

Choose Methods That Encourage Participation

LMS platforms can be effective tools for delivering and tracking education. However, even the most sophisticated platform will struggle to engage employees if content is repetitive, not role or industry-specific, or lacks practical relevance.

Compliance professionals should avoid designing education solely around their own preferred learning style. A format that feels clear and engaging to the person developing the training may not connect with every employee. Varying the delivery method can improve accessibility and help sustain attention, but variety should have a purpose. The selected method should support the learning objective, the complexity of the topic, and the needs of the intended audience. 

In recent years, I have focused on redesigning annual and targeted training to connect employees with organizational policies and reinforce applicable regulatory requirements. This required more than transferring existing content into a new format. We reconsidered how information was presented, where interaction could be added, and how employees could be directed back to the policies and procedures governing their work. Working with our information technology team, we used an AI-enabled platform to develop modules incorporating videos and interactive quizzes. Employee participation improved, and the experience reinforced an important point: strong content is essential, but presentation, relevance, and interaction influence whether employees remain engaged with that content. Technology did not replace the need for compliance oversight. It gave us another way to deliver information in a more engaging format.

For brief reinforcement

  • Microlearning and short refreshers
  • Short quizzes
  • Email, newsletter, or intranet reminders
  • Workflow posts explaining the purpose behind a task

For interaction and clarification

  • Live or department-specific sessions
  • One-on-one coaching when individualized support is needed
  • Department visits and informal question and answer sessions

For practical application 

  • Real-world scenarios
  • Role-specific instruction
  • Sample documents and guided exercises
  • Targeted education following audit or inspection findings

For engagement and visibility

  • Videos and visually engaging presentations
  • Gamification
  • Modest incentives, when appropriate

The method should never overshadow the message. Select the format based on what employees need to understand or do differently after the training.

Use Real-World Scenarios Responsibly

Employees in our organization have responded positively to real-world scenarios. In a post-training survey, 32% of respondents requested additional scenario-based education. Scenarios can help employees translate policy language into practical decisions and understand how a requirement applies in daily work. 

Compliance professionals must nevertheless use internal examples carefully. Remove or alter identifying details, avoid information that could permit re-identification, and focus on the scenario purpose or decision rather than the individuals involved. Not every internal matter is appropriate for broad education. When used responsibly, de-identified incidents, near-misses, and recurring questions can become valuable learning opportunities. 

Make Creativity Serve the Learning Objective

A well-chosen theme can also help create visibility and momentum around an annual campaign. Our organization has used travel, Olympic, superhero, and scavenger-hunt themes to refresh the employee experience. When feasible, simple décor, intranet content, photographs, and internal announcements can keep the campaign visible.

A theme, however, should support the learning objective rather than compete with it. Creative presentation may attract attention, but the content must remain relevant, accurate, accessible, and connected to employees’ responsibilities.

Leadership Sets the Tone

Training is less likely to influence daily behavior if leadership treats it as an annual assignment or does not reinforce expectations afterward. Leadership involvement should include visible support, sufficient employee time, operational follow-through, and reinforcement within departments. Leadership buy-in is often one of the most significant factors in influencing the success of a compliance program. 

In a recent post-training survey conducted within our organization, 36% of respondents identified leadership encouragement as a motivating factor in completing their assigned training. 

This year, our organization took a different approach by asking senior leaders to complete the training before it was deployed across the organization. As a result, leaders were able to provide feedback on the learner experience, answer employee questions based on firsthand knowledge, and reinforce the importance of the training from an informed perspective. Employees are more likely to engage when leaders demonstrate that compliance education is a priority rather than simply another assigned task.

Reinforce Learning Throughout the Year

Annual training alone cannot carry the entire compliance education program. There must be reinforcement and other trainings throughout the year. Employees may revert to prior habits when a workflow changes, particularly if the new process is not reinforced or if employees do not understand why the change occurred. Here are suggested reinforcement methods to consider:

  • Brief department touchpoints
  • Compliance newsletters or compliance content in the company newsletter
  • Periodic reminders via email or Teams messaging
  • Short quizzes
  • Leadership talking points
  • Workflow-specific coaching
  • New-hire reinforcement
  • Targeted education following audit or inspection findings

Measuring What Matters

Completion rates remain necessary for monitoring assigned education, but they answer only one question: Did the employee complete the training? They do not establish whether the employee understood the content, retained it, or applied it correctly. A more meaningful evaluation may include:

  • Knowledge checks that require application, not simple recall
  • Post-training surveys regarding relevance, clarity, and preferred formats
  • Targeted audits or observations of the affected process
  • Trends in repeat findings, recurring questions, and reported concerns
  • Discussions with department leaders about whether expectations are being followed

Follow-up education when results identify gaps

No single measure will provide a complete answer. Compliance professionals should consider multiple indicators and allow sufficient time for the expected behavior or process change to become observable. When results do not improve, the appropriate response may not be more training. The organization may need to examine the policy, workflow, available resources, competing priorities, or leadership reinforcement. 

Meaningful compliance training is not defined by completion certificates, attendance records, or annual deadlines. Those elements document activity, but effectiveness is demonstrated through understanding, application, and behavior. 

There is no universal formula for employee engagement. Each organization must consider its workforce, culture, risks, resources, and learning objectives. The most successful approach may combine formal training, practical scenarios, leadership reinforcement, ongoing communication, and opportunities for employees to ask questions and provide feedback. 

Our responsibility as compliance professionals is not simply to deliver information. It is to help employees recognize why the information matters and how it applies to the decisions they make every day. When employees understand the purpose behind an expectation and view Compliance as a trusted resource, training becomes more than a requirement. It becomes part of how the organization protects its patients, its workforce, and its integrity. 

About the Author

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management. She serves as a volunteer on the AIHC Education Committee. This article was written in collaboration with the following AIHC Education Committee Members: Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS and Joy Rose, MSA, RHIA, CCS, CHA, CHPS

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 


Read More
Compliance in Healthcare
Corporate Compliance

Documentation Integrity Starts with Valid Authentication

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

This short article addresses a complex topic and is not intended as consulting or legal advice. The content is not all-inclusive. 

Introduction

Documentation integrity is the foundation of patient safety and legal protection, and it begins with the valid authentication of every medical record entry. By properly verifying a provider's identity, healthcare systems ensure accountability, prevent unauthorized alterations, and maintain the clinical trustworthiness required for high-quality care.

Medical documentation serves as the legal, clinical, and financial foundation of patient care. An entry in a patient's chart is much more than a routine administrative task; it is a legally binding testament to the care provided, the rationale behind clinical decisions, and the direct observations of a specific practitioner. Because clinical reasoning is unique to the individual practitioner who evaluates a patient, the integrity of that record relies entirely on traceability—the ability to definitively link clinical data to the exact individual who created it. Valid signatures and proper authorization of medical records serve as legal proof that a licensed provider performed, reviewed, or ordered the care documented.

  • Valid authentication is the fundamental anchor of medical documentation integrity. It transforms digital text into a legally binding, trustworthy medical artifact.
  • Without proof of exactly who authored an entry at a precise time, healthcare records lose their clinical reliability, legal defensibility, and billing compliance.

Strict authorship and authentication rules mandate that only the healthcare professional who performed a service, made an observation, or gave an order may authorize the entry. Delegating this responsibility by allowing one provider to authenticate or "sign off" on another's notes is a critical violation of medical record integrity and regulatory standard.

Why No One Can Authenticate a Note for Another

First-Hand Knowledge and Accountability - The provider who performed the assessment is the only person who can truly verify the accuracy, nuance, and medical necessity of the documented care. Signing a note without first-hand knowledge means the authenticator cannot legally or ethically swear to the validity of the observations, creating a falsified record of the encounter.

Fraud and Abuse Implication - In billing and compliance, authenticity concerns regarding the legitimacy of documentation can trigger severe penalties. If a physician authenticates a note for a mid-level practitioner or colleague whose work they did not observe, it artificially validates services that the signer cannot legally account for, frequently resulting in claim denial and accusations of healthcare fraud.

Legal Admissibility - In a court of law, medical records are routinely scrutinized under the business records exception to hearsay. If a record is printed, requested for a malpractice suit, and the metadata shows that Provider B signed Provider A's note without being in the room or evaluating the patient, the record’s legal admissibility is immediately jeopardized.

The Difference Between Countersigning and Authentic Authoring

It is a common misconception that "countersigning" is the same as authenticating another's note. While supervising or attending physicians are often required by hospital bylaws to countersign the documentation of residents, interns, or students, this countersignature serves as a verification of supervision or oversight, not a transfer of authorship.

The original author still maintains full responsibility for writing the note, and the countersignature simply proves the supervising physician reviewed the care, rather than replacing the original clinician's signature.

Authentication is the Non-Negotiable Foundation

Medical documentation integrity relies entirely on the accuracy and trustworthiness of the health record. It dictates that every diagnosis, treatment, and clinical observation is reliable enough to support patient safety and billing accuracy.

At the absolute center of this integrity lies authorship validation. Without secure authentication, it becomes impossible to prove who created or altered a specific piece of clinical data. Valid authentication guarantees that the provider who performed the care is definitively linked to the record of that care.

1.    Patient Safety and Continuity of Care

Clinical decision-making relies entirely on the history of previous treatments, medications, and diagnoses. If a provider cannot verify the identity of the clinician who entered a critical lab note or medication order, patient safety is severely compromised. Secure logins and electronic signatures establish clinical accountability, allowing care teams to trust the information they are acting upon.

2.    Legal Defensibility and Evidence

In medical malpractice lawsuits, the medical record acts as the definitive legal evidence. To be admissible in court, the record must be validated as an accurate and uncorrupted version of events. Robust authentication—such as a password protected electronic signature linked to comprehensive system metadata—proves that a specific clinician took responsibility for the information at a specific date and time.

3.    Reimbursement and Regulatory Compliance

Healthcare revenue cycles rely on billing for services that are strictly documented and verified by the practitioner. Guidelines from the Centers for Medicare & Medicaid Services (CMS) require that all services be authenticated by the author. Furthermore, HIPAA regulations mandate strict user identification and access controls to prevent fraudulent entries or data breaches. Proper authentication acts as an organization's proof of work and regulatory adherence.

Technology Enforcing Authentication Integrity

In modern Electronic Health Record (EHR) environments, verifying the author requires sophisticated digital controls rather than a simple typed name. The integrity of these digital records is enforced through:

  • Multi-Factor Authentication (MFA): Requires users to verify their identity through multiple methods (e.g., a password paired with a push notification or biometric scan).
  • Role-Based Access Control (RBAC): Ensures that clinicians only interact with and authenticate records that fall within their designated scope of practice and clinical responsibilities.
  • Tamper-Proof Audit Trails: Logs every single time a record is viewed, created, or modified, tracking exactly who made the entry, the exact time, and the device used.

EHR systems must use secure logins, digital certificates, or biometric scans to authenticate the author to comply with CMS, Joint Commission, State regulations, and FDA guidelines. For example:

  • The Joint Commission (TJC): TJC requires that all entries in the medical record be authenticated by the author, dated, and timed.
  • CMS Guidelines: CMS strictly prohibits "swoop and hoop" or auto-authentication practices where providers sign off on large batches of notes without individually reviewing them.
  • State Regulations: Individual state medical boards maintain specific laws regarding timeframes for record completion (e.g., dictating that notes must be signed within 24 to 48 hours).

Conclusion

Medical documentation is only as reliable as its source. By establishing a clear, verifiable link between the clinical event and the responsible provider, valid authentication prevents fraud, protects medical professionals, and above all, ensures patient safety. Without it, the entire foundation of healthcare data integrity collapses.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

American Institute of Healthcare Compliance - Clinical Documentation Improvement online training

https://dev-main.aihc-assn.org/product/clinical-documentation-improvement/

CMS

https://www.cms.gov/files/document/mln905364-complying-medicare-signature-requirements.pdf

https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/pim83c03.pdf

https://www.wpsgha.com/guides-resources/view/227

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

The Imperative of Documentation Integrity

Addressing the Healthcare Data Crisis 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

The information in this article primarily applies to providers when recording patient encounters in their office or other places of service. Content is for educational purposes only and is not intended as consulting or legal advice.

Introduction

Clinical documentation represents the foundational pillar of modern healthcare, ensuring patient safety, care continuity, accurate reimbursement, and the ethical use of medical data for research. However, the healthcare industry is currently grappling with a severe data crisis driven by the proliferation of historical documentation errors.

  • The transition from paper-based charts to Electronic Health Records (EHRs), while designed to streamline operations and reduce medical errors, has inadvertently introduced systemic vulnerabilities that compromise the integrity of clinical data.

The modern healthcare data crisis is not simply a matter of lost or misplaced files; it is a systemic degradation of data quality caused by the cumulative effect of historical documentation errors. At the center of this crisis is the phenomenon known as "chart lore" or "note bloat," where inaccuracies and redundancies are perpetuated across multiple patient encounters.

Several structural and behavioral factors drive this crisis:

  • Overuse of Copy/Paste and Cloning: The implementation of EHRs introduced time-saving functionalities such as the "copy-forward" or copy/paste features. Studies have revealed that over 50% of the text in inpatient and outpatient notes is duplicated. This practice often results in carrying over outdated, irrelevant, or entirely incorrect clinical information (e.g., documenting an allergy that was proven false years prior), creating information overload and increasing the risk of adverse events.
  • Template and Drop-Down Menu Errors: The reliance on pre-populated templates and drop-down menus can lead to "mouse-click errors," where a provider accidentally selects a normal finding for an abnormal condition. These errors obscure the true "patient story" and result in contradictory or missing clinical context.
  • Patient Matching and Interoperability Failures: Poor data entry and fragmented system integration contribute to patient misidentification. Industry surveys indicate that up to 20% of patients may not be correctly matched to their records, leading to scenarios where providers make treatment decisions based on another individual’s medical history.
  • Defensive and Billing-Driven Documentation: Because healthcare systems rely on Evaluation and Management (E/M) codes and reimbursement structures, clinicians are often pressured to document excessively to satisfy complex billing requirements, rather than focusing purely on clinical utility. This return-on-investment approach distorts the clinical record and leads to defensive medicine.
    • In light of Evaluation & Management guidelines allowing time or medical decision-making for many codes, providers must remember, when time is used, the complexity of the visit must be reflected to support longer visit times (higher reimbursed codes). Payers will question when high levels of service are billed but the note does not reflect the amount of work to support reimbursement.

Artificial Intelligence and the Physician/Provider Burden

Ironically, the tools intended to make documentation easier, EHR systems, have become a leading driver of clinician stress and burnout. The "cognitive load" of navigating drop-down menus and templating systems detracts from face-to-face patient time. And now with Artificial Intelligence (ambient scribes) being integrated into clinical documentation, the burden can become overwhelming due to time to ensure there are no errors in the record. AI is being built of historical information that is peppered with errors, inaccuracy, and omissions.

Despite promised efficiency gains, a large multi-center study found that AI ambient scribes saved a relatively modest 16 minutes of documentation time per eight hours of care. Because physicians are ultimately responsible for the accuracy of their medical records, they are forced to shift cognitive effort from typing to auditing—carefully reviewing AI-generated text to ensure no critical data has been omitted or misstated

Integrating artificial intelligence (AI) as ambient scribes in clinical settings reduces documentation time but yields distinct error profiles. Studies from the National Library of Medicine indicate that up to 70% of AI-generated notes contain at least one error, with an average of 2 to 3 errors per note. Omissions are the most common mistake, accounting for 71% to 83% of all errors.

Breakdown of AI Errors

Research shows that the types and frequencies of errors vary widely by system:

  • Omissions: Occurring in roughly 70-80% of recorded mistakes, this happens when AI leaves out critical details. Studies note that over 40% of these omissions carry moderate to significant clinical importance (e.g., omitting comorbidities or medication side effects).
  • Additions: Representing 4% to 11% of errors, this occurs when the AI fabricates or inserts information that was never discussed.
  • Hallucinations & Wrong Outputs: Fabricated or severely misidentified medical terminology.
  • Misplacements: Occurring in 6% to 25% of errors, where the AI correctly transcribes the info but places it in the wrong section of the chart.

Documentation Integrity & Accuracy Metrics

While traditional self-documentation by doctors can also be fragmented, ambient AI drafts often capture a much higher volume of the spoken interaction. However, this can sometimes lead to an inverse problem of information overload for the physician reviewing notes for accuracy.

Patient Safety and Clinical Continuity

The primary purpose of any clinical note is to support continuous, high-quality patient care. Outpatient practices frequently treat patients across extended timelines and involve diverse clinical staff. Therefore, documentation integrity is critical for several interconnected reasons:

  • Preventing Diagnostic and Medication Errors: When previous providers fail to update active problem lists, or when notes contain contradictory information, the risk of adverse events skyrockets.
    • Accurate documentation ensures that allergy lists, historical diagnoses, and ongoing treatment regimens are clear, preventing medication interactions and duplicative testing.
  • Facilitating Coordinated Care: In an era of team-based care and interoperability, patient notes are often referenced by external specialists, primary care physicians, and allied health professionals.
    • Complete, up-to-date clinical notes give care teams a holistic view of a patient’s health journey, allowing them to make informed, data-driven decisions.

Financial Sustainability and Revenue Cycle

Documentation dictates reimbursement and an organization’s ability to support compliant billing and reimbursement. In outpatient settings, practices rely on Evaluation and Management (E/M) coding guidelines established by the Centers for Medicare & Medicaid Services (CMS) and the American Medical Association (AMA).

  • Reducing Claim Denials: Payers use automated systems to verify that documented services match the billed codes. Incomplete or vague documentation leads to high rates of claim denials, requiring expensive and time-consuming rework for billing staff.
  • Combating the "Cloning" Risk: EHRs offer time-saving features like "copy-and-paste," "carry-forward," and auto-fill. While efficient, these features frequently lead to documentation cloning, where notes contain outdated or clinically irrelevant information.
    • Payers increasingly view cloned notes as a compliance risk, which can lead to delayed payments or allegations of upcoding, leading to allegations of violating the False Claims Act.

The Clinical and Legal Repercussions

The accumulation of these errors across vast databases has severe, real-world consequences for patient safety and institutional liability. Regulatory bodies, including the Department of Health and Human Services (HHS) Office of Inspector General (OIG), heavily scrutinize outpatient billing. Ensuring documentation integrity limits the financial and reputational damage of audits:

  • Demonstrating Medical Necessity: Every medical service must be justified by documented medical necessity. Documentation must clearly demonstrate why a course of action was taken and what alternatives were considered. Without this, practices are vulnerable to recoupment during post-payment audits.
  • Combating Fraud, Waste, and Abuse: Accurate charting protects both the provider and the organization. Attempting to add missing information or diagnoses to a chart after an audit has been initiated is a serious legal violation that carries civil and criminal penalties. Maintaining real-time, tamper-evident documentation is the best legal defense for providers.
  • Patient Harm and Medication Errors: Data integrity issues directly impact diagnostic accuracy and treatment planning. Studies indicate that a significant percentage of EHR-related events—sometimes cited as over one-third of cases—have life-threatening potential. When providers are forced to skim through bloated records, critical changes in a patient's condition or medication history are frequently missed.
  • Artificial Intelligence and Big Data Limitations: The current push toward integrating artificial intelligence (AI) and machine learning (ML) into healthcare relies entirely on the premise of data accuracy. However, because a high percentage of EHR records contain documentation errors, predictive models are frequently built on flawed or "missing" data indicators, which compromises their clinical reliability and introduces unconscious biases into algorithmic decision-making.
  • Malpractice Liability: Legal teams increasingly scrutinize EHR meta-data and documentation errors during litigation. Many EHR-related malpractice liabilities stem directly from documentation errors and omission, making inaccurate record-keeping a major risk management concern.

Strategies for Restoring Documentation Integrity

Addressing the healthcare data crisis requires a fundamental shift in how documentation is viewed, created, and audited. Organizations must move beyond billing-centric metrics and prioritize true Clinical Documentation Integrity (CDI). We simply need more documentation professionals, specifically in the outpatient setting where most care is rendered.

Implement Continuous CDI Programs - Healthcare facilities must establish dedicated CDI teams that routinely review and audit charts for clarity, completeness, and clinical accuracy. However, it is important that auditors and those training providers in CDI have structured training themselves first. Not all coding and billing auditors are qualified to conduct a documentation integrity audit. By educating all those involved on best practices and modern documentation guidelines, organizations can ensure that the patient's medical history accurately reflects their current clinical state.

Engage with organizations for online CDI training to improve the basic understanding of a compliant medical record. Registering qualified staff and/or providers with an organization which is a Licensing/Certification partner with CMS is recommended, such as the American Institute of Healthcare Compliance which offers online training with option to Certify as a Medical Documentation Professional.

EHR Usability and Design Overhaul - Software vendors and IT departments must collaborate to redesign EHR interfaces. This includes implementing strict limits on copy-paste functionalities, utilizing anomaly detection tools to flag duplicated or contradictory text, and enhancing interoperability to reduce patient matching errors.

Structured Data Capture - Shifting from unstructured narrative notes to standardized, structured data formats allow for better data reuse, less error-prone information exchange, and more effective clinical decision support systems.

Patient Engagement as a Verification Tool - Opening up EHRs to patients—allowing them to access their own health records and actively report discrepancies—has proven to be an effective strategy for identifying and resolving embedded "EHRrors" before they cause harm.

Conclusion

The historical degradation of healthcare data integrity poses a significant public health threat, turning patient records from life-saving tools into repositories of perpetuated errors.

To mitigate this crisis, the healthcare ecosystem must prioritize actionable, systemic reforms. By investing in enhanced EHR design, responsible implementation of integrating AI, rigorous auditing and compliance, and a culture of clinical clarity, the industry can restore trust in medical data and safeguard patient lives.

Outpatient practices can no longer treat clinical documentation as a mere administrative byproduct. Documentation integrity is the structural backbone of patient safety, financial compliance, and legal protection. By actively investing in CDI processes, ongoing provider education, and optimized EHR workflows, outpatient practices can safeguard patient outcomes, reduce audit vulnerabilities, and restore clinician satisfaction.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Navigating the Complexities of Medicare Cost Report Compliance

Navigating the Complexities of Medicare Cost Report Compliance

Written by the American Institute of Healthcare Compliance Education Department 

The American Institute of Healthcare Compliance (AIHC) is a non-profit training organization offering certification to become a Certified Cost Report Specialist (CCRSSM) and is a Licensing/Certification Partner with CMS.  The information below is not all inclusive, is not legal or consulting advice and is for educational purposes only.

Introduction

Filing Medicare Cost Reports (MCRs) is a highly complex, high-stakes process involving intricate, frequently changing CMS regulations, extensive data allocation, and strict documentation requirements.  Due to the complexity, errors are frequent, according to findings reported by the Office of Inspector General (OIG).

As a cornerstone of the Medicare program, the MCR serves as the annual mechanism for providers to report descriptive, financial, and statistical data to CMS. Pursuant to 42 CFR §413.20(b), Medicare-certified providers are mandated to submit this comprehensive financial record to determine the proper settlement of costs for services rendered to beneficiaries. Beyond ensuring that interim payments accurately reflect actual costs, the MCR is critical for establishing future reimbursement rates, including wage indices, disproportionate share hospital (DSH) adjustments, and graduate medical education (GME) payments. Failure to file, or inaccurate filing, carries significant financial risks, making an understanding of these reports crucial for regulatory compliance and financial stability.

While frequently viewed as a burdensome regulatory filing, the MCR constitutes one of the most comprehensive, standardized, and publicly available sources of institutional financial data in the United States. As Medicare moves toward greater fiscal accountability, the MCR allows providers to identify operational inefficiencies, manage financial performance, and ensure compliance in a complex reimbursement landscape.

Which Organizations File MCRs?

Medicare-certified institutional providers, typically Part A providers, must file annual Medicare cost reports (MCR) to determine reimbursement, usually within 5 months (or 150 days) after the end of their fiscal year. These reports, filed to a Medicare Administrative Contractor (MAC), are required for hospitals, skilled nursing facilities, home health agencies, hospices, FQHCs, RHCs, and ESRD providers.

Institutional Providers Required to File Medicare Cost Reports:

  • Hospitals: Including general, psychiatric, rehabilitation, long-term care, and children’s hospitals
  • Skilled Nursing Facilities (SNFs)
  • Home Health Agencies (HHAs)
  • Hospice Providers:
  • Federally Qualified Health Centers (FQHCs):
  • Rural Health Clinics (RHCs)
  • End-Stage Renal Disease (ESRD) Facilities
  • Organ Procurement Organizations (OPOs)
  • Community Mental Health Centers (CMHCs)

When are Cost Reports Due to be Filed?

Providers should use the Medicare Cost Report Electronic Filing (MCReF) system for submissions.  The cost report is due on or before the last day of the fifth month following the close of the provider's fiscal year and filed to the provider’s Medicare Administrative Contractor (MAC).

  • Example: For a fiscal year ending December 31, the report is due May 31.
  • Non-Month-End Closings: If the fiscal year does not end on the last day of the month, the report is due 150 days after the last day of the cost reporting period.

Failure to submit can result in the suspension of Medicare payments, increased audit risk, and loss of reimbursement.

Key 2026 Medicare Advantage (MA) Cost Reporting Requirements

CMS requires Medicare-certified acute care hospitals reimbursed under the IPPS (inpatient prospective payment system) to report median negotiated payment rates from Medicare Advantage (MA) plans by MS-DRG on their annual cost reports for cost reporting periods ending on or after January 1, 2026.

This mandate aims to collect market-based data to set future inpatient prospective payment system (IPPS) relative weights.  Data will be used to set future MS-DRG weights likely by Fiscal Year 2029.

This requirement adds significant complexity to an already error-ridden annual Cost Report process. Providers must ensure the accurate reporting of MA negotiated rates to avoid potential audit findings, as this data will influence future payment setting.

OIG Audits CMS Contractor Cost Report Compliance

Take a look at some recent Office of the Inspector General (OIG) audit reports to see how large the financial impacts of noncompliance can be for MACs, which falls back onto the provider.

A September 2025 audit by the U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) found that Novitas Solutions, Inc. (Novitas), a Medicare Administrative Contractor (MAC), failed to properly review 100% of the cost reports examined in a specific sample.

  • The errors caused by inadequate reviews led to a total of $9.4 million in corrected final settlements, consisting of $5 million in overpayments and $4.4 million in underpayments to providers.

A similar, separate OIG audit released in September 2025 also found that National Government Services, Inc. (NGS) had a 100% error rate (64 out of 64) in a sample of reopened cost reports, resulting in $5.6 million in corrected settlements.

  • The 64 cost report reopening's resulted in corrected final settlements to providers totaling $5.6 million (which consisted of $3.1 million in overpayments and $2.5 million in underpayments).

Key Findings on Cost Report Errors:

  • High Error Incidence: A 2025 OIG report revealed that 12 Medicare Administrative Contractors (MACs) failed to meet oversight requirements, with a 70% failure rate in reviewing filings.
  • Specific Errors: Common errors included misclassification of physician salaries, improper nursing/allied health program calculations, and improper bad debt reporting.
  • Financial Impact: These errors resulted in massive financial inaccuracies, including one case involving over $250,000 in improper overpayments.
  • Audit Surge Expected: Due to these findings, an increase in audits and oversight by MACs is expected.

Common Causes of Errors:

  • Inconsistent Data Sources: Failure to reconcile internal financial systems with patient data (e.g., midnight census, revenue usage files).
  • Complex Allocations: Miscalculating the allocation of costs between Medicare and non-Medicare patients.
  • Failure to Update: Carrying over errors from previous years instead of updating with current data.

Implications of Errors:

  • Overpayment Recovery: MACs can claw back funds, requiring repayment with interest.
  • Underpayments: Errors can lead to lower-than-earned reimbursements.
  • Increased Audit Risk: High error rates trigger more intensive reviews and potential civil monetary penalties.

Notable Cases of Noncompliant Medicare Cost Reporting

  • Non-Compliance with Medicare Cost Reporting Requirements

In 2018 the Office of Inspector General (OIG) reported that the National Institute of Transplantation (NIT), an independent histocompatibility lab, did not fully comply with Medicare’s cost-reporting requirements.  In the cost report in question, NIT had correctly reported only 177 of 186 cost transactions.  In total, the OIG estimated that NIT had received approximately $45,940 in overpayments from Medicare. 

OIG concluded their audit report by recommending that NIT work with the Medicare Administrative Contractor to return potential overpayments and identify any additional similar overpayments that may be related to cost reports.

  • Referring Medicare Cost Reports and Reconciling Outlier Payments

Several years ago, two organizations were cited by OIG as not always correctly referring their Medicare cost reports to CMS.  For example, Cahaba Government Benefit Administrators, LLC (Cahaba GBA) had only referred 5 out of 13 cost reports with outlier payments that were qualified for reconciliation to CMS.  The financial impact of this noncompliance was estimated to be over $9,700,000 in total, of which just over $601,000 was due to Medicare. 

Another organization, CGS Administrators, a healthcare administrator operating as a Part A, Part B, and Home Health & Hospice (HH&H) MAC for Jurisdiction 15, had referred 15 of 18 qualified cost reports to CMS for reconciliation, but of those 15 referred reports, they had neglected to reconcile the outlier payments for 14 reports.  The financial impact of these affected reports was estimated at about $39,000,000 combined, with over $16,000,000 due to Medicare.

  • Non-Compliance with Medicare Organ Statistic Requirements

In 2012, LifeCenter Northwest, a federally designated independent organ procurement organization, was reported to have not fully complied with Medicare requirements for reporting organ statistics.  In the affected cost report, LifeCenter had reported incorrect organ statistics for 15 different organs. 

If was found that Medicare’s share of organ procurement costs was overstated by about $88,000.  OIG recommended that LifeCenter submit a revised cost report to correct the overstatement and work to ensure that future reports followed Medicare requirements.

Implement Strategies Now for Compliance

  1. Internal Routine Auditing: Implement proactive monitoring to verify that data—especially payroll and equipment costs—is accurate before submission.
  2. Incorporate Prior Audit Results: Avoid repeating adjustments from previous years, as recurring errors act as "red flags" for fiscal intermediaries.
  3. Rigorous Documentation: Maintain granular support for "allowable" costs, such as marketing (informational vs. promotional) and bad debt collection efforts.

Start by addressing critical high-risk components of the report.  CMS Auditors and the Office of Inspector General (OIG) focus on several key items within the cost report.  Your organization should also focus on these same areas when conducting internal compliance audits:

  • Graduate Medical Education (GME) & Indirect Medical Education (IME):
    • Inaccurate reporting of Graduate Medical Education (GME) payments, indirect medical education (IME) costs, and Medicare bad debts.  These involve complex resident counts and are frequent targets for in-depth audits.
  • Medicare Bad Debts:
    • Facilities must prove they used "reasonable" collection efforts for non-collectible deductibles and coinsurance. Improperly documented Medicare bad debts are a frequent source of audit findings.
  • Disproportionate Share Hospital (DSH) Payments:
    • Disproportionate Share Hospital (DSH) calculations are considered high-risk audit areas on the Medicare Cost Report. Due to the complexity of the regulations and the significant financial impact on reimbursements, these calculations frequently lead to errors, underpayments, or overpayments, according to the OIG.
  • Schedule S-10 (uncompensated care UCC):
    • Worksheet S-10 is a major audit trigger as it directly affects reimbursement rates.  Auditors target improper documentation of uncompensated care on Schedule S-10, which impacts UCC/DSH payments.  As of 2026, Medicare Administrative Contractors (MACs) are scrutinizing these filings, focusing heavily on documentation that supports charity care and bad debt, according to CMS.
    • The UCC and DSH go hand-in-hand as an add-on to the DRG reimbursement, but are calculated separately. 
  • Wage Index Data:
    • This data is used to set future prospective payment rates; inaccuracies can lead to billions in misapplied funds.
  • Operational Deficiencies:
    • Late submissions, inadequate training of staff, and poor oversight of third-party contractors can lead to compliance issues.
  • Vaccinations: 
    • Vaccinations are considered a high-risk error area on Medicare cost reports for Rural Health Clinics (RHCs) and Federally Qualified Health Centers (FQHCs). Errors often arise from failing to reconcile interim payments with actual costs, lacking proper documentation (logs, invoices, time studies), and missing or incorrect coding (e.g., Condition Code A6) on claims.

Conclusion - Include Cost Report Audits in Your Compliance Program

Because Compliance Officers often overlook the high-risk area of cost reporting, it is important to implement internal routine auditing and monitoring to ensure data submitted is accurate and timely.

Your Compliance Department should be overseeing areas which can pose a high financial or legal risk to the organization.  Cost reporting falls into both categories, requiring internal auditing and monitoring of this function to ensure accuracy and timeliness is observed.

Inaccurate filing or late submissions can result in immediate payment suspension, civil monetary penalties, or exclusion from the Medicare program.  All this can be avoided through appropriate preparation and accurate training.

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

American Institute of Healthcare Compliance (AIHC®)

CMS

Code of Federal Regulations

Noridian Healthcare Solutions

Office of Inspector General

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Why Every Healthcare Facility Needs a Smart Hospital Security System

Written by Peter Lee, MSc, CIPP/US and Arif Khan researcher specializing in AI-driven security systems and healthcare compliance

The information provided is for educational purposes only and is not legal, consulting or IT advice.

Introduction

Healthcare facilities operate in one of the most complex and high-risk environments of any industry. Hospitals are open 24/7, manage large volumes of patients and visitors, and handle sensitive data, controlled substances, and critical care operations all at the same time. This combination creates a unique set of security and compliance challenges that cannot be addressed with traditional systems alone.

The scale of the issue is significant. According to healthcare safety data, incidents involving workplace violence, unauthorized access, and theft are rising across hospitals and care facilities. In addition, regulatory requirements such as the Health Insurance Portability and Security Act (HIPAA) place strict obligations on how patient data and physical access must be controlled. Even a single breach can lead to severe financial penalties, legal consequences, and reputational damage, which is enforced by the Office of Civil Rights (OCR).

At the same time, many healthcare facilities still rely on outdated surveillance and access systems that are limited to recording events rather than actively preventing them. These systems often fail to provide real-time visibility, making it difficult for administrators and compliance officers to respond quickly when incidents occur.

This is why modern hospital security systems are becoming essential rather than optional. A smart security system does more than monitor activity. It integrates surveillance, access control, and intelligent alerts into a unified platform that helps healthcare organizations protect patients, staff, and sensitive information while maintaining compliance.

The Complexity of Healthcare Environments Demands Smarter Security

Unlike typical commercial spaces, hospitals are highly dynamic environments. Emergency departments, patient wards, pharmacies, operating rooms, and administrative offices all operate simultaneously, each with different levels of access and risk.

Managing security in such an environment requires more than basic surveillance. It requires systems that can adapt to constant movement and provide clear visibility across all areas.

For example, a visitor entering a general waiting area may be appropriate, but the same individual entering a restricted ICU or medication storage area presents a serious risk. Without intelligent monitoring, distinguishing between normal and suspicious activity becomes difficult.

Modern hospital security systems address this by combining video surveillance with access control and real-time monitoring. This allows healthcare administrators to not only control who can enter specific areas but also verify and track activity as it happens.

The result?  A more controlled and transparent environment, which is critical for both safety and compliance.

Protecting Patient Safety and Staff Well-Being

Patient safety is the top priority in any healthcare facility. However, safety risks are not limited to medical issues alone. Security incidents such as unauthorized access, aggressive behavior, or theft can directly impact patient care.

Healthcare workers are also at increased risk - Studies have shown that healthcare professionals face higher rates of workplace violence compared to many other industries. This makes it essential for hospitals to have systems in place that can detect and respond to potential threats quickly.

Smart hospital security systems help mitigate these risks by providing continuous monitoring and real-time alerts. For instance, if unusual activity is detected in a restricted area or if a situation begins to escalate in a waiting room, security teams can be notified immediately.

This ability to respond quickly can prevent incidents from escalating and ensures a safer environment for both patients and staff.

Supporting HIPAA Compliance and Data Protection

Compliance is a critical concern for healthcare organizations. Regulations such as the Health Insurance Portability and Accountability Act (HIPAA) require strict control over access to patient information and sensitive areas.

Physical security plays a major role in compliance. Unauthorized access to records rooms, server areas, or administrative offices can lead to data breaches, which carry significant legal and financial consequences.

A modern hospital security system supports compliance by providing controlled access, detailed activity logs, and audit trails. These features allow organizations to track who accessed specific areas and when, which is essential for audits and investigations. This integrated approach helps ensure that compliance requirements are met while improving overall operational efficiency.

Preventing Unauthorized Access to Critical Areas

Hospitals contain several high-risk zones that require strict access control. These include pharmacies, operating rooms, ICUs, data centers, and storage areas for medical equipment.

Unauthorized access to these areas can result in serious consequences, including theft of controlled substances, tampering with equipment, or exposure of sensitive information.

Traditional systems often rely on static access permissions, which can become outdated as roles change. This creates gaps where individuals may retain access they no longer need.

Smart hospital security systems address this issue by enabling dynamic access control. Permissions can be updated in real time, ensuring that access is always aligned with current roles and responsibilities.

In addition, integrating access control with video surveillance provides an added layer of verification. Administrators can not only see who accessed a door but also confirm the activity visually, reducing the risk of misuse.

Improving Incident Response and Emergency Management

In healthcare settings, response time is critical. Whether it is a security incident, a medical emergency, or an environmental issue, delays can have serious consequences.

Smart security systems improve response time by providing real-time alerts and centralized monitoring. Instead of relying on manual reporting, incidents can be detected automatically and communicated to the appropriate teams immediately.

For example, if an unauthorized entry occurs in a restricted area or if environmental sensors detect abnormal conditions, alerts can be triggered instantly. Security and medical teams can then coordinate their response more effectively.

This level of coordination is especially important in large facilities where multiple departments must work together during emergencies.

Enhancing Operational Efficiency

Beyond safety and compliance, hospital security systems also contribute to operational efficiency.

Manual processes such as maintaining access logs, issuing credentials, and monitoring multiple systems can be time-consuming and prone to errors. As healthcare facilities grow, these inefficiencies become more pronounced.

A centralized security system streamlines these processes by integrating surveillance, access control, and alerts into a single platform. This reduces administrative workload and allows staff to focus on patient care rather than managing systems.

Additionally, data collected from security systems can provide valuable insights into facility usage, helping administrators optimize workflows and resource allocation.

Adapting to Modern Healthcare Challenges

Healthcare is evolving rapidly, and security systems must evolve with it.

Facilities are expanding, patient volumes are increasing, and technology is becoming more integrated into daily operations. At the same time, threats are becoming more sophisticated, requiring a more proactive approach to security.

Smart hospital security systems are designed to adapt to these challenges. They provide scalability, allowing facilities to expand without overhauling their infrastructure. They also support integration with other systems, creating a unified approach to security and operations.

This adaptability is essential for healthcare organizations that want to remain secure and compliant in a constantly changing environment.

FAQs

What are hospital security systems?

  • Hospital security systems are integrated solutions that combine surveillance, access control, and monitoring tools to protect patients, staff, and sensitive areas within healthcare facilities.

Why are smart security systems important in hospitals?

  • They provide real-time monitoring, improve response times, and support compliance with healthcare regulations, making them more effective than traditional systems.

How do these systems support HIPAA compliance?

  • They control access to sensitive areas, maintain detailed logs, and provide audit trails that help meet regulatory requirements.

Can hospitals use existing infrastructure?

  • Yes. Many modern systems are designed to work with existing IP cameras and infrastructure, reducing the need for costly replacements.

Do these systems improve patient safety?

  • Yes. By detecting and responding to risks quickly, they help create a safer environment for patients and healthcare staff.

Conclusion

Healthcare facilities face unique challenges that require more than basic security measures. The combination of high patient volumes, sensitive data, and strict regulatory requirements makes security a critical component of daily operations.

Modern hospital security systems provide the intelligence, integration, and real-time visibility needed to address these challenges effectively. They help protect patients, support staff, ensure compliance, and improve overall efficiency.  Solutions like Coram demonstrate how this can be implemented effectively. Coram’s hospital security platform works with existing IP cameras and integrates with access control systems and environmental sensors. It provides high-definition video monitoring, intelligent alerts, and centralized management, allowing healthcare facilities to maintain visibility and control without replacing their current infrastructure.

As healthcare environments continue to evolve, investing in smarter security systems is not just a technological upgrade. It is a necessary step toward safer, more resilient, and compliant healthcare operations.

About the Authors

Arif Khan is a writer and researcher specializing in AI-driven security systems, healthcare compliance, and modern surveillance technologies. He holds a B.Tech degree in Computer Science and works as a freelance writer covering topics related to AI, physical security, access control, and intelligent monitoring systems. His work focuses on helping organizations understand emerging security technologies and their role in improving safety, compliance, and operational efficiency.

Peter Lee is a writer and researcher specializing in AI-driven security systems and healthcare compliance. His work focuses on topics such as hospital security, HIPAA requirements, and modern surveillance technologies, helping organizations understand and implement effective security solutions.

References

American Institute of Healthcare Compliance (AIHC)

National Library of Medicine (NLM)

Occupational Safety and Health Administration (OSHA)

U.S. Department of Health & Human Services (HHS)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
Corporate Compliance, HIPAA

The Hidden Risk in Multi Site Healthcare

When Visibility Fails, Compliance Follows 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

This article is for reference regarding risk management in healthcare, which is a complex topic and posted for educational purposes only. It is not intended as consulting or legal advice.

Introduction

Managing multiple healthcare facilities within a single organization has evolved from an operational responsibility to a complex enterprise risk function. As organizations expand across regions, states, and service lines, the ability to maintain consistent compliance, ensure patient safety, and protect financial performance becomes increasingly difficult without structured oversight.

For compliance and risk leaders, multi-site operations present a unique challenge. The risk is not limited to regulatory requirements or operational variability. The greatest risk is the loss of visibility. When leadership cannot clearly see what is occurring across sites in real time, issues are often identified only after they have already impacted patient care, compliance status, or revenue.

Recent federal guidance and national studies reinforce that multi-site risk is driven less by geographic dispersion and more by the absence of standardized oversight, integrated data, and structured accountability.¹ To manage multi-site healthcare environments effectively, organizations must move beyond decentralized oversight and adopt systems that promote accountability, visibility, and coordinated enterprise governance. Without these elements, growth introduces fragmentation rather than scalability.

The Risk Profile of Multi Site Healthcare Organizations

Multi-site healthcare organizations operate within a heightened risk environment driven by scale, variability, and complexity. While these risks are often described broadly, they consistently concentrate on specific operational and compliance areas that require targeted oversight. A primary risk is inconsistent application of regulatory requirements. Organizations governed by entities such as the Centers for Medicare & Medicaid Services and the Health Resources and Services Administration must ensure that standards related to documentation, billing, scope of services, and program integrity are applied uniformly across all locations. Variability in interpretation or execution increases the likelihood of audit findings, repayment exposure, and regulatory scrutiny.

Operational fragmentation is another critical concern. When sites operate with varying processes, undocumented workarounds, or informal practices, organizations lose the ability to ensure consistency and control. Over time, these inconsistencies evolve into systemic risk. Data fragmentation further compounds this issue. Without integrated systems, leadership lacks a reliable, centralized source of truth. This limits the organization’s ability to identify trends, monitor performance, and detect emerging risks before they escalate. Workforce variability also contributes to risk exposure. Differences in training, leadership capability, and staffing stability across sites directly affect compliance adherence, documentation quality, and patient safety outcomes.

Recent patient safety research demonstrates that breakdowns in communication, leadership engagement, and reporting culture are directly associated with lower safety performance and reduced incident reporting across healthcare organizations.²  In multi-site environments, these risks are amplified when leadership relies on inconsistent or anecdotal reporting rather than standardized enterprise data. Finally, delayed escalation of issues remains a persistent vulnerability. Without clear reporting structures and accountability, compliance concerns, incidents, and near misses may remain localized rather than addressed at the enterprise level.

High Risk Areas and Required Compliance Controls

Effective organizations do not manage multi-site risk at a high-level. They identify specific exposure areas and implement structured controls tied directly to those risks.

Documentation, Coding, and Billing Integrity - Variability in documentation and coding practices is one of the most significant sources of compliance exposure. Even with established policies, differences in provider behavior and oversight result in inconsistent application of requirements. Common risk patterns include insufficient documentation to support medical necessity, inconsistent use of modifiers, and failure to accurately capture services rendered. Across multiple sites, these inconsistencies increase audit vulnerability and repayment risk.

Administrative complexity and reliance on inconsistent workflows further increase risk and inefficiency across organizations. To mitigate this risk, organizations should implement centralized revenue integrity oversight, supported by routine pre and post billing audits. Documentation standards must be clearly defined and reinforced through targeted education tied directly to audit findings. Coding accuracy should be monitored through both random and focused audits, particularly in high-risk service lines. Transparent reporting of audit results reinforces accountability at both the provider and site level.

Sliding Fee Scale and Program Eligibility - For federally funded organizations, sliding fee scale compliance remains a critical risk area. Inconsistent eligibility determinations, failure to conduct required reevaluations, and inadequate documentation create exposure during audits and operational site visits. Organizations should implement standardized eligibility workflows supported by system controls that prevent incomplete processing. Routine audits should validate both documentation and application of discounts. Staff responsible for eligibility should receive structured training with defined competency expectations, and monitoring should include both process adherence and outcome accuracy.

Credentialing, Licensure, and Enrollment - Maintaining accurate credentialing and enrollment across multiple sites is operationally complex and highly regulated. Risks include expired licenses, services rendered prior to enrollment approval, and misalignment between credentialing records and payer systems. National credentialing standards emphasize ongoing monitoring, sanction checks, and oversight of delegated credentialing activities, particularly in multi-state environments.³

Centralized credentialing systems with automated alerts are essential. Organizations should maintain a single, validated source of provider data that is routinely reconciled with payer enrollment records. Pre-service verification processes should confirm that providers are eligible to render services. Routine audits should ensure alignment across credentialing, privileging, and enrollment data.

Patient Safety and Incident Reporting - Inconsistent reporting of incidents and near misses across sites creates significant patient safety and compliance risk. When reporting varies by location, organizations lose the ability to identify systemic issues. Recent studies highlight that organizations with stronger reporting cultures and leadership engagement demonstrate improved safety outcomes and increased event reporting.²

Centralized incident reporting systems should be implemented across all sites, with clearly defined expectations for reporting. Leadership must reinforce a culture that supports transparency and non-punitive reporting. Data should be trended at the enterprise level, and corrective actions should be tracked to completion. Regular leadership review ensures accountability and sustained improvement.

Data Integrity and Reporting - Reliable data is essential for effective oversight. In multi-site environments, inconsistent data definitions, delayed reporting, and lack of validation undermine decision making. Organizations should establish formal data governance structures that define standards, ownership, and validation processes. Standardized dashboards should be implemented across sites to ensure consistency in reporting. Data should be routinely reconciled across systems, and key risk indicators should be monitored consistently. Research indicates that dashboards are most effective when designed to drive action rather than simply display information.⁶

Workforce Competency and Training - Variability in workforce training directly impacts compliance and operational performance. Inconsistent onboarding, lack of role specific education, and high turnover create gaps in knowledge and execution. Standardized onboarding programs with defined competencies should be implemented across all sites. Ongoing training should be required and tracked, with reinforcement tied to identified risk areas. Competency should be validated through assessments and audit results to ensure effective application.

Vendor and Third-Party Oversight - Reliance on third party vendors introduces additional compliance and operational risk. Lack of visibility into vendor practices and misalignment with regulatory requirements can create exposure. Organizations should implement formal vendor risk management programs that include due diligence, clear contractual expectations, and ongoing performance monitoring. Vendors should be evaluated against defined compliance standards and subject to periodic audits. Contracts should clearly define accountability and regulatory obligations.

Enterprise Visibility and Remote Oversight

The most significant risk in multi-site operations is not complexity but lack of visibility. In organizations where leadership is remote or geographically dispersed, reliance on informal updates creates delayed awareness of risk. Federal compliance guidance emphasizes structured oversight, including risk assessments, auditing, monitoring, and board level reporting.¹ Organizations should establish a single enterprise view of risk that includes credentialing status, billing trends, patient safety events, training compliance, and corrective action tracking. Visibility must be standardized, real time, and actionable.

Accountability as an Enterprise Expectation - Accountability must be clearly defined and embedded at every level of the organization. Each site should have designated leadership responsible for compliance, quality, and operational performance, with measurable expectations aligned to enterprise standards. Research demonstrates that leadership structure and accountability directly influence safety culture, communication, and organizational performance. ⁵ Performance management should incorporate compliance metrics alongside operational goals. Enterprise leadership must maintain oversight through routine review of site performance, clear escalation pathways, and enforcement of corrective actions.

Systems, Monitoring, and Enterprise Oversight - Systems function as the infrastructure that supports compliance and risk management across multiple sites. Centralized platforms for audit tracking, incident reporting, credentialing, and performance monitoring provide the foundation for effective oversight. Monitoring should be continuous and risk based. Routine audits, data validation, and trend analysis allow organizations to identify patterns across sites and intervene proactively. Early warning indicators should be established to trigger action before risks escalate. Effective oversight requires translating data into action through structured governance and consistent follow through.

Addressing Blind Spots Through Validation and Culture

Blind spots represent one of the most significant risks in multi-site environments. These include underreported incidents, undocumented workarounds, and gaps in training that are not captured through standard reporting. Organizations must validate reported data through independent audits, direct observation, and cross site comparison. Identifying outliers often reveals underlying risk. Equally important is fostering a culture of transparency. Staff must feel supported in reporting concerns, and leadership must respond consistently to reinforce trust in reporting mechanisms.

Supporting Organizational Growth While Managing Risk

Growth must be supported by infrastructure and oversight. Research suggests that organizations that standardize core processes before expansion achieve more sustainable outcomes. ⁷ Organizations should ensure that systems, processes, and staffing models are scalable prior to expansion. Centralized governance should remain intact while allowing for controlled local execution. Data driven decision making should guide expansion, resource allocation, and performance improvement.

Conclusion

Managing multiple healthcare facilities requires a structured and deliberate approach to risk, compliance, and operational oversight. Multi-site environments introduce significant exposure across regulatory, clinical, operational, and financial domains. Across federal guidance and recent healthcare research, a consistent theme emerges. Multi-site success is driven by standardized visibility, structured accountability, integrated compliance controls, and proactive monitoring.¹ ² ³

Organizations that succeed invest in visibility, enforce accountability, and implement integrated systems that allow leadership to monitor performance in real time. By identifying specific risk areas and implementing targeted controls, organizations can reduce compliance exposure, strengthen patient safety, and support sustainable growth. In multi-site healthcare operations, risk is not created by scale alone. It is created by the absence of structure. Visibility, accountability, and systems remain the foundation of effective governance and long-term success.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Ms. Bertholette Pardieu, MPH, CCEP, OHCC is an accomplished compliance and risk leader with over a decade of experience developing and strengthening enterprise-wide compliance, governance, and risk programs across highly regulated healthcare sectors, including FQHCs, PBMs, and Medicare/Medicaid organizations. She currently serves as the Director of Risk Management & Corporate Compliance Officer for Broward Community & Family Health Centers, Inc. (the largest Federally Qualified Health Center in Broward County), overseeing risk, compliance and governance for a $16.4M multi-site FQHC system serving more than 13,000 patients. Previously, she led enterprise compliance risk initiatives at Convey Health Solutions, where she built the company’s first compliance risk program, directed effectiveness audits, and enhanced vendor oversight for national health plans.

A trusted advisor to executives and boards, Ms. Pardieu is known for her strategic mindset, collaborative leadership, and ability to embed compliance into organizational culture to protect against regulatory and operational risk. She holds a Master of Public Health from Florida International University and a Bachelor of Science from Barry University. Ms. Pardieu is a Certified Healthcare Compliance Officer (OHCC), with additional credentials including certifications in Corporate Compliance & Ethics and Healthcare Risk Management; and is a recent graduate of the Women’s Executive Leadership Accelerator Program through the Inclusion Learning Lab.

References

1. U.S. Department of Health and Human Services, Office of Inspector General
    General Compliance Program Guidance (2023)
    * Direct PDF (Full Guidance):
      
https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf
    * Official OIG Overview Page:
      
https://oig.hhs.gov/compliance/general-compliance-program-guidance/
2. Agency for Healthcare Research and Quality (AHRQ)
    Patient Safety Culture and Workforce Safety
    * 
https://psnet.ahrq.gov/perspective/ensuring-patient-and-workforce-safety-culture-healthcare
3. National Committee for Quality Assurance (NCQA)
    Credentialing Standards
    * 
https://www.ncqa.org/programs/health-plans/credentialing/benefits-support/standards/
4. Council for Affordable Quality Healthcare (CAQH)
    2023 CAQH Index Report
    * 
https://www.caqh.org/hubfs/43908627/drupal/2024-01/2023_CAQH_Index_Report.pdf
5. National Library of Medicine (PubMed)
    Leadership and Patient Safety Culture Systematic Review
    * 
https://pubmed.ncbi.nlm.nih.gov/41507881/
6. Journal of the American Medical Informatics Association (JAMIA Open)
    Healthcare Dashboard Effectiveness Study
    * 
https://academic.oup.com/jamiaopen/article/8/4/ooaf078/8214040
7. National Institutes of Health (PubMed Central)
    Healthcare Leadership Complexity and System Growth
    * 
https://pmc.ncbi.nlm.nih.gov/articles/PMC11223336/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Vendor Compliance – Old Problem, New Risks

Written by Susan Lee Walberg, JD MPA CHC 

Compliance Officers are always stretched thin with many responsibilities, and those duties seem to constantly grow with each year and every new law or regulation. One of the more challenging areas to monitor is the compliance of our vendors and Business Associates.

I believe this is now more important than ever. Why? Because cybercrime, hacking, phishing, and impersonation schemes are rampant, and the cyber-crooks are now using AI to circumvent our (and our vendor’s) security measures.

How many times have we heard about a major breach, and the root cause was a failure to conduct a Security Risk Assessment or apply patches or software updates timely? A failure of routine training is also often to blame. Over 60% of breaches are caused by Business Associates, so this is an area of risk that I believe needs more attention.

Over the years, I have found that prevention is the best cure. There are several steps we can take on the front end to reduce the risk of non-compliance during the term of the Agreement.

1.  Compliance needs to be at the table BEFORE arrangements are entered into. It’s not unheard of, in a large health system, for the compliance officer to not even know about every joint venture or acquisition, but, when there’s a compliance problem at that entity, they are on the hook. It’s critical to build trust with leadership, and educate them as to why Compliance needs to be at the table. We need to understand what the arrangement is about, why we are doing it, and who is paying what to who. If Compliance isn’t informed and engaged, some of these other steps likely won’t happen.

2.  Due diligence is critical for new business partners. While the finance team reviews the balance sheet, Compliance needs to be reviewing the organization’s compliance program, culture and reputation. There should be a document list the Compliance reviews for acquisitions and partnerships, but even for contracted services, we want to take a peek and do some basic reviews.

  • Review their Compliance Plan (and how often it’s been reviewed and updated)
  • Have a conversation with their compliance, privacy, and/or security officer to get a better sense of how they operate
  • Find out if they’ve been subject to any investigations
  • Run a List of Excluded Individuals and Entities (LEIE) OIG check
  • Ask to see their most recent Security Risk Assessment, if ePHI is going to be involved

Pay careful attention to any referrals that are considered as part of the contract. These are not only for physicians, but they can also be an IT vendor or other provider of goods or services-there have been plenty of cases where companies, such as Electronic Medical Record (EMR) companies have been found in violation of the Anti-Kickback statute. Have an attorney review it if this isn’t your area of expertise. The bottom line is to ask yourself if the arrangement itself is appropriate.

Those are just some suggestions, but at least these activities would give you a sense of how much they tend to compliance. Also, it never hurts to do a basic Google search. If they aren’t a new organization, and if they have any ethical or legal issues, you will likely find reviews on the Better Business Bureau site and/or sites where employees and customers can give a rating/review. That activity alone can speak volumes if the organization has a culture problem.

3. Contract provisions need to include compliance. Although bad actors sign contracts all the time, it still helps protect       your organization and does show that you take compliance and ethics seriously. Some suggested provisions:

  • The vendor agrees to comply with all applicable laws, rules, and regulations, including False Claims Act, Stark, HIPAA, and any other that are key for your business and the type of services.
  • The vendor agrees that you are allowed to audit their processes and records that pertain to the services under the contract
  • The vendor agrees that all their employees are checked for disbarment and that none of their employees or contractors are disqualified to participate in government health care programs; and to notify you immediately if that changes.
  • The vendor agrees and attests that they have a compliance, privacy, and security program that meets or exceeds industry and regulatory standards, and that they maintain stringent security standards to protect the integrity of ePHI.
  • Breach notification and remediation procedures need to be detailed. How long after a breach is identified must you be notified? Who notifies clients? Review the breach response requirements under HIPAA and make sure you address those.
  • Data use is an important provision. Review your contract or Business Associate Agreement, keeping in mind that data is now as valuable as gold. Can your business partners sell your data? What if it’s de-identified? Are you comfortable with them doing so, and does your agreed-upon rate take that into account? The advent of AI makes data much more valuable.
  • Adherence and compliance to all Medicare regulations, especially if this is a contract for any business office, documentation, coding, or record review service.

4. Training requirements are not optional. Privacy, Security, and Compliance training should be provided to the vendor’s   employees, or they can take training you provide, if you have that option. If they have their own program, it’s totally acceptable to ask to see it. Ongoing data security training, in particular, is important due to the constantly evolving phishing and other schemes.

5. Make sure you have tight controls on granting access to your information. Your business partner can’t just get one log-in that everyone uses. That should be a core requirement for data access-unique user IDs and passwords.

Those are some key front-end steps. Once the agreement is in place, if the previous activities are completed there shouldn’t really be a heavy load of monitoring, absent some incident or breach. Here are a few things to consider:

  • Stay in contact with the process/contract owner and ask how things are going. If there are problems, that person is likely the first to know. Make sure they know to call you if something starts to go sideways.
  • Conduct any audits or monitoring you included in the contract, if you’re able to (it’s a resource issue, for sure)
  • Send occasional surveys to your vendors inquiring about their compliance, privacy, or security measures. This at least lets them know you are paying attention.
  • Touch base with their compliance, privacy, or security officers
  • Monitor training logs, if they receive training from you (or ask them to provide that information)
  • Look them up online now and then to see if there are any new complaints out there.
  • Get an audit of what information their employees are viewing-make sure it’s appropriate.

Monitoring your vendors can seem like just one too many things to do, and most of the time you will find that there are no red flags. Most businesses try to do the right thing. But it’s important to keep in mind how much of a risk they could pose to your organization, especially if they are handling patient information and/or billing functions. You don’t want to be looking back and wishing you had done it and having to explain that to your leadership!

About the Author Susan Lee Walberg, JD MPA CHC

Ms. Walberg is an author, attorney and healthcare compliance consultant. She is available to help anyone work through these processes and provides a full range of compliance-related services and books, including serving as a fractional Compliance or Privacy Officer, or in an interim role. She can be contacted by email at swalberg@compliancealacarte.com, or find more about services and books on her website at susanwalberg.com or on LinkedIn!

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance, HIPAA

Privacy, Interoperability, and Trust in 2026

HIPAA Notice of Privacy Practices, 42 CFR Part 2, and USCDI v3 Compliance Risk 

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE 

Healthcare organizations entering 2026 face a convergence of heightened privacy enforcement and expanded interoperability obligations. Two major regulatory developments drive this shift:

  1. The February 16, 2026 deadline to update HIPAA Notices of Privacy Practices (NPPs) to reflect revised 42 CFR Part 2 requirements, and
  2. The January 1, 2026 mandate to comply with United States Core Data for Interoperability (USCDI) Version 3 standards. 

This article provides an executive and auditor-facing analysis of these intersecting requirements, examining enforcement risk, patient rights, data governance challenges, and operational compliance implications. Practical guidance is offered to support governing boards, executive leaders, and compliance professionals in aligning privacy, interoperability, and health IT strategies.

The information in this article is not intended as legal or consulting advice and should be used for educational purposes only.

Introduction

The healthcare compliance environment in 2026 reflects a deliberate regulatory emphasis on transparency, data access, and accountability balanced against strengthened privacy protections. Federal agencies have clearly signaled that interoperability and privacy are no longer siloed compliance domains but interdependent elements of patient trust and regulatory oversight.

As highlighted in the January 2026 Compliance Newsletter published by the American Institute of Healthcare Compliance, healthcare organizations must simultaneously address expanded HIPAA privacy obligations and mandatory interoperability standards. This convergence significantly elevates compliance risk for entities that fail to align governance, policy, and operational workflows.

HIPAA Notice of Privacy Practices: February 16, 2026 Enforcement Deadline

February 16, 2026 marks the enforcement deadline for updates to HIPAA Notices of Privacy Practices required under the February 2024 Final Rule modifying 42 CFR Part 2. These revisions align substance use disorder (SUD) privacy protections with HIPAA and subject violations to civil monetary penalties and corrective action plans.

Historically, Part 2 violations carried limited enforcement risk. Under the revised framework, failure to update NPPs or operationalize revised patient rights may be interpreted as systemic noncompliance.

Expanded Patient Rights Under Revised 42 CFR Part 2

The revised Part 2 framework introduces significant patient rights that must be clearly disclosed through updated NPPs. These include single-consent authorization for future disclosures, enhanced rights to request privacy protections, and explicit restrictions on the use of SUD records in legal proceedings. Compliance programs must ensure alignment across registration, consent management, EHR configuration, and workforce training to avoid inadvertent violations.

USCDI Version 3: Mandatory Interoperability in 2026

Already in effect, as of January 1, 2026, compliance with USCDI Version 3 became mandatory for certified EHR systems and health IT vendors.

This requirement expands the scope of standardized data exchange to include social determinants of health, health equity data, and expanded insurance information.  Failure to meet USCDI v3 standards may expose organizations to information blocking allegations, certification issues, and contractual noncompliance with payers and federal programs.

Intersection of Privacy and Interoperability

The intersection of privacy and interoperability represents one of the most complex compliance challenges facing healthcare organizations in 2026. Federal policy has deliberately accelerated health information exchange to improve care coordination, reduce administrative burden, and advance health equity. Simultaneously, regulators have strengthened patient privacy rights—particularly for sensitive data such as substance use disorder (SUD) information—recognizing that trust is foundational to patient engagement and data accuracy.

USCDI Version 3 expands the categories of data eligible for exchange, including social determinants of health, health equity stratifiers, and expanded clinical and insurance data elements. While these data sets are critical to population health and value-based care initiatives, they also increase the likelihood of inappropriate disclosure if consent and access controls are not precisely aligned. The revised 42 CFR Part 2 framework reinforces that interoperability does not negate privacy obligations; rather, it heightens the expectation that organizations implement granular, enforceable safeguards.

A Dual-Risk Environment - From an enforcement perspective, regulators have made clear that information blocking prohibitions do not override privacy protections. Organizations that indiscriminately share data without honoring consent restrictions—particularly for Part 2-protected information—may face simultaneous exposure under HIPAA, Part 2, and information blocking regulations. This creates a dual-risk environment in which both over-restriction and over-disclosure may trigger regulatory scrutiny.

To navigate this tension, healthcare organizations must adopt a privacy-by-design approach to interoperability, ensuring that consent management, data segmentation, and role-based access controls are embedded into health IT workflows. Interoperability initiatives that proceed without explicit privacy governance risk eroding patient trust and undermining regulatory compliance objectives.

Ensuring Trust Through Privacy-Centered Interoperability

Trust is not an abstract concept in healthcare compliance; it is an operational outcome shaped by transparency, consistency, and respect for patient autonomy. As data exchange expands, patients are increasingly aware of how their information is used, shared, and protected.

Failure to demonstrate meaningful privacy protections may result in patients withholding information, declining treatment, or disengaging from care altogether—particularly in behavioral health and substance use contexts.

Practical, trust-building strategies include:

Transparent and Understandable NPPs - Updated Notices of Privacy Practices should move beyond regulatory minimums to clearly explain how sensitive information is shared through interoperable systems, what choices patients have, and how consent is honored across care settings. Plain-language explanations reinforce trust and reduce confusion at registration and intake.

Consent Integrity Across Systems - Organizations should validate that consent decisions captured at intake are consistently enforced across EHRs, health information exchanges, and third-party platforms. Inconsistent application of consent restrictions is a frequent source of patient complaints and audit findings.

Data Minimization and Purpose Limitation - Even when data sharing is permitted, organizations should limit disclosures to the minimum necessary to achieve clinical or operational objectives. Demonstrating restraint reinforces patient confidence that interoperability serves care—not convenience.

Patient Access and Engagement - Providing patients timely access to their own records, including disclosures and consent history, supports transparency and aligns with broader federal access initiatives. Patients who understand how their data moves through the system are more likely to trust it.

Workforce Accountability - Trust is undermined when staff lack clarity regarding privacy obligations. Targeted training that addresses real-world scenarios—such as responding to data requests involving SUD information—helps prevent inadvertent violations and reinforces organizational commitment to privacy.

These practices position privacy not as a barrier to interoperability, but as a prerequisite for sustainable data exchange.

Governance, Audit, and Enforcement Risk

Regulators increasingly evaluate privacy and interoperability compliance through a governance lens. Surveyors and auditors may assess leadership awareness of regulatory changes, oversight of data-sharing activities, and the effectiveness of training and monitoring programs.

Failure to demonstrate executive oversight may result in enforcement actions by OCR or CMS.

Operationalizing Compliance: Best Practices

To mitigate compliance risk, organizations should:

  • Update NPPs well in advance of enforcement deadlines;
  • Align consent workflows with interoperability requirements;
  • Validate EHR configurations; and
  • Conduct targeted workforce training.

Routine audits of data-sharing practices and consent management processes are critical to sustaining compliance.

Conclusion

The convergence of revised HIPAA privacy requirements strengthened 42 CFR Part 2 protections, and mandatory USCDI Version 3 interoperability standards reflects a broader regulatory recalibration of healthcare data governance. Federal agencies have signaled that access, transparency, and accountability must advance in parallel—not in competition. In this environment, privacy failures are no longer isolated compliance issues; they represent systemic governance risks with direct implications for patient trust, enforcement exposure, and organizational credibility.

Healthcare organizations entering 2026 must recognize that interoperability initiatives amplify privacy obligations rather than dilute them. Updated Notices of Privacy Practices, consent management workflows, and health IT configurations serve as visible indicators of organizational integrity. Regulators and auditors increasingly assess not only whether policies exist, but whether leadership understands how privacy and interoperability intersect operationally.

Organizations that proactively integrate privacy-by-design principles into interoperability strategies will be best positioned to navigate enforcement risk, avoid information blocking missteps, and sustain patient trust. This requires active governing body oversight, cross-functional collaboration between compliance, IT, legal, and clinical leaders, and continuous monitoring of evolving regulatory guidance.

Ultimately, trust is the currency of interoperable healthcare. Organizations that demonstrate respect for patient autonomy while advancing responsible data exchange will not only meet regulatory expectations but also strengthen care quality, engagement, and resilience in an increasingly data-driven healthcare system.

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • American Institute of Healthcare Compliance. (2026). January 2026 compliance newsletter. https://dev-main.aihc-assn.org
  • U.S. Department of Health and Human Services, Office for Civil Rights. (2024). Final rule modifying 42 CFR Part 2. https://www.hhs.gov/ocr
  • Centers for Medicare & Medicaid Services. (2025). United States Core Data for Interoperability (USCDI) Version 3. https://www.cms.gov

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Compliance in Healthcare
Corporate Compliance

Nurse Staffing as National Performance Goal 12

Executive Oversight, Patient Safety, and Compliance Risk in 2026

Written by: Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE 

Abstract 

Effective January 1, 2026, the Joint Commission elevated nurse staffing to National Performance Goal (NPG) 12, establishing staffing adequacy as a measurable accreditation and patient safety requirement. This article provides an executive- and auditor-facing analysis of NPG 12, examining regulatory intent, alignment with CMS Conditions of Participation, leadership accountability, and compliance risk. Practical guidance is offered to assist governing boards, executive leaders, and compliance professionals in operationalizing staffing oversight within enterprise risk, quality, and accreditation frameworks.

Introduction

Healthcare organizations entering 2026 face intensified scrutiny related to workforce adequacy, patient safety, and leadership accountability. Persistent staffing shortages, clinician burnout, and adverse patient outcomes have driven regulators and accrediting bodies to elevate staffing oversight as a core compliance priority. The Joint Commission’s designation of nurse staffing as National Performance Goal 12 represents a formal shift from treating staffing as an operational concern to recognizing it as a governance and accreditation imperative.

This shift requires healthcare leaders to reevaluate staffing policies, oversight structures, and performance measurement methodologies to ensure alignment with accreditation standards and federal regulatory expectations.

Regulatory Evolution and Rationale for NPG 12

Historically, nurse staffing requirements were embedded across leadership, human resources, and patient care standards and often evaluated indirectly through quality outcomes or adverse event investigations. However, evidence consistently demonstrates a direct relationship between inadequate nurse staffing and increased mortality, preventable harm, staff turnover, and regulatory findings.

By establishing staffing as NPG 12, the Joint Commission underscores the necessity of proactive oversight, data-driven decision-making, and executive accountability in maintaining safe staffing levels.

Scope and Applicability of NPG 12

NPG 12 applies broadly across hospital settings and clinical departments. Requirements extend beyond bedside nursing to include interdisciplinary clinical support essential to patient care. Key expectations include 24/7 registered nurse coverage, designated nurse executive oversight, and staffing models responsive to patient acuity, complexity, and care demands.

Organizations must demonstrate that staffing decisions are grounded in clinical need rather than solely financial or administrative considerations.

Executive and Governing Body Accountability

A defining feature of NPG 12 is its explicit emphasis on leadership oversight. Executive leaders and governing boards are expected to actively monitor staffing metrics, understand staffing-related risks, and ensure appropriate resource allocation. Surveyors may evaluate whether leadership receives regular staffing reports, responds to trends, and integrates staffing considerations into strategic planning.

Failure to demonstrate leadership engagement may result in accreditation findings related to leadership and governance standards, even in the absence of sentinel events.

Ethical and Professional Practice Implications

Beyond regulatory compliance, NPG 12 reinforces ethical obligations embedded in nursing professional standards and organizational duty of care. Chronic understaffing places nurses in ethically untenable positions, increasing moral distress and undermining professional judgment. Accrediting bodies increasingly assess whether organizations acknowledge and mitigate moral injury and burnout as patient safety risks.

Labor, Workforce, and Employment Law Intersections

NPG 12 intersects with labor law, whistleblower protections, and occupational safety standards. Inadequate staffing has been cited in retaliation claims, union grievances, and OSHA-related complaints alleging unsafe working conditions. Documentation demonstrating proactive staffing oversight may mitigate regulatory and legal exposure.

Alignment with CMS Conditions of Participation

NPG 12 closely aligns with CMS Conditions of Participation related to nursing services, patient rights, and quality assessment and performance improvement. Deficiencies may result in immediate jeopardy findings, amplifying compliance risk when accreditation and CMS enforcement converge.

Data-Driven Staffing Models and Performance Metrics

Compliance with NPG 12 requires data-driven staffing methodologies beyond static ratios. Surveyors may assess acuity-based tools, staffing variance analysis, and correlations between staffing levels and quality indicators. Organizations must demonstrate how staffing data informs corrective actions and continuous improvement.

Compliance with NPG 12 requires data-driven staffing methodologies beyond static nurse-to-patient ratios. Consistent with NPG.12.06.01 EPs 1–4, surveyors assess whether staffing adequacy is evaluated when undesirable patterns, trends, or variations in quality or safety are identified and whether findings are escalated through performance improvement and governance structures.

Real-world, setting-specific examples

Critical Access and Rural Hospitals:

A rural critical access hospital identified repeated patient flow delays and increased transfer times during seasonal surges. Although staffing numbers met minimum coverage requirements, leadership incorporated staffing effectiveness indicators into QAPI reviews, revealing gaps in skill mix during high-acuity presentations.

Corrective actions included cross-training nursing staff and implementing an escalation protocol requiring nurse executive review when acuity thresholds were exceeded. Findings and actions were documented and reported to governance, consistent with NPG.12.06.01 EP 3–4.

Psychiatric and Behavioral Health Settings:

In an inpatient psychiatric unit, analysis of restraint and seclusion events revealed correlations with staffing shortages during overnight shifts. Leadership included staffing adequacy in the root cause analysis, adjusted staffing models to ensure appropriate competency and coverage, and monitored outcomes through ongoing performance improvement activities. Annual staffing analysis results were provided to the patient safety program and governing body, aligning with NPG.12.06.01 EP 1–2.

Emergency and Mixed-Acuity Rural Facilities:

A rural emergency department experiencing increased left-without-being-seen rates evaluated staffing data alongside throughput and acuity metrics. Leadership implemented targeted staffing adjustments during peak hours and tracked improvements through QAPI dashboards. Staffing analyses and corrective actions were formally reviewed by executive leadership and incorporated into governance reports, demonstrating compliance with NPG.12.06.01 EP requirements.

These examples illustrate that staffing data must be actively analyzed, escalated, and integrated into performance improvement activities. Surveyors may evaluate whether leaders can articulate how staffing analyses influence corrective actions and how results are communicated to the hospital wide patient safety program and governing body.

Documentation, Evidence, and Surveyor Expectations

Surveyors may request evidence of leadership review, board discussion, action plans, and integration of staffing metrics into QAPI activities. Absence of such documentation may result in findings even when staffing ratios appear acceptable.

Compliance, Legal, and Operational Risk

Inadequate staffing presents compounded risk across accreditation, regulatory, legal, and operational domains. NPG 12 codifies staffing adequacy as an enterprise compliance risk requiring sustained mitigation strategies.

Survey Readiness and Best Practices

Survey readiness under NPG 12 requires staffing-focused mock surveys, compliance dashboards, and leadership preparedness to articulate how staffing decisions support patient safety and quality outcomes.

Conclusion

The elevation of nurse staffing to National Performance Goal 12 reflects a deliberate regulatory shift toward recognizing workforce adequacy as a foundational patient safety requirement rather than an operational afterthought. By formally linking staffing oversight to accreditation, performance improvement, and governance accountability, the Joint Commission has clarified expectations that safe staffing is inseparable from leadership responsibility and organizational culture.

Healthcare organizations entering 2026 must demonstrate that staffing adequacy is actively monitored, analyzed, and escalated through established quality and compliance structures. Static staffing policies and retrospective justification are no longer sufficient. Instead, leaders are expected to use data-driven methodologies, integrate staffing considerations into QAPI activities, and ensure governing bodies receive meaningful, actionable information related to staffing risk and performance.

Organizations that proactively embed staffing oversight into enterprise risk management, accreditation readiness, and strategic planning will be best positioned to mitigate regulatory exposure, support workforce sustainability, and achieve measurable improvements in patient safety outcomes. In this evolving regulatory environment, effective nurse staffing oversight is not only a compliance obligation—it is a defining indicator of organizational resilience, leadership effectiveness, and commitment to high-quality care in 2026 and beyond.

Appendix A: NPG 12 Compliance Crosswalk (Effective January 2026)

The following table maps National Performance Goal 12 Elements of Performance to corresponding sections of this article using Joint Commission survey-oriented language to support accreditation readiness.

NPG / EP

Joint Commission Expectation

Article Section(s)

Survey-Ready Language

NPG 12.01.01

Leadership ensures adequate number and mix of qualified staff based on patient needs.

Leadership ensures adequate number and mix of qualified staff based on patient needs.

Staffing decisions are based on patient acuity, complexity, and clinical demand rather than solely financial considerations.

NPG 12.02.01 EP 1–2

Nurse executive directs staffing plans and participates in governance decision-making.

Nurse executive directs staffing plans and participates in governance decision-making.

The nurse executive maintains authority and accountability for nursing staffing models in collaboration with senior leadership.

NPG 12.02.01 EP 4–5

Registered nursing oversight is available 24/7.

Registered nursing oversight is available 24/7.

Registered nursing services are available 24 hours per day, seven days per week, consistent with deemed-status requirements.

NPG 12.04.01

Staff practice within scope of licensure and competency requirements.

Staff practice within scope of licensure and competency requirements.

Staffing adequacy includes verification of licensure, scope of practice, supervision, and competency.

NPG 12.05.01

Staff receive education, training, and competency evaluation

Ethical and Professional Practice Implications

Workforce education and competency are treated as patient safety safeguards.

NPG 12.06.01 EP 1–4

Staffing is evaluated during QAPI and reported to leadership and governance.

Data-Driven Staffing Models; Documentation and Surveyor Expectations

Staffing adequacy is incorporated into performance improvement analyses and reported to executive leadership and governing bodies.


About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • American Institute of Healthcare Compliance. (2026). January 2026 compliance newsletter.
  • The Joint Commission. (2025). National performance goals effective January 1, 2026: Hospital program.
  • Centers for Medicare & Medicaid Services. (2025). Medicare conditions of participation.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More