Quality
Auditing, Corporate Compliance, Quality

The Cost of an Unchecked Policy

WHEN POLICY MEETS PRACTICE | A TWO-PART SERIES

How quality assurance and quality improvement audits keep policies alive and patients safe

Written by Robert Colon-Torres   

Every health system has policies. Far fewer can prove those policies are followed, or that they work. That gap is where preventable harm, financial penalties, and legal exposure live.

In nearly 25 years of healthcare compliance work, I have rarely investigated an adverse event where no policy existed. Far more often, the policy was there. It had been approved, posted, and acknowledged in an annual training. It simply was not what happened on the floor, and no one had checked.

This is the first of a two-part series on that gap between the policies health systems write and the care they actually deliver. My argument across both parts is straightforward: quality assurance (QA) and quality improvement (QI) audits are what turn a policy from a document into a practice, and compliance and CQI must operate as one team to make that happen. Part 1 examines what is at stake when the gap goes unchecked: for patients, for the organization's finances, and in front of regulators and courts. Part 2 explains why the gap opens and how to close it.

Harm is common, and much of it is preventable

The Institute of Medicine's To Err Is Human (1999) estimated that up to 98,000 hospitalized Americans die each year from preventable error.[1] Later estimates ranged far higher, including the widely cited 2016 claim that medical error is the third leading cause of death in the U.S.[2] Those higher figures have been sharply criticized on methodological grounds, and a 2020 meta-analysis put preventable inpatient deaths closer to 22,000 a year.[3][4] Compliance professionals should resist the temptation to lead with the most dramatic number; our credibility depends on precision.

But the debate over mortality obscures a point on which the evidence is consistent: harm itself is common. The HHS Office of Inspector General found that one in four hospitalized Medicare patients experienced harm, and that 43 percent of those events were preventable.[5] A 2023 New England Journal of Medicine study of eleven Massachusetts hospitals found adverse events in nearly one in four admissions, about a quarter of them preventable.[6] More than two decades after To Err Is Human, the problem has not been solved. In most of these cases, the evidence-based practice that would have prevented harm was already known.

Where policy and practice drift apart

Bar code medication administration (BCMA) shows how the drift happens. BCMA was designed to stop wrong-patient and wrong-dose errors, yet researchers documented fifteen distinct workarounds, including spare wristbands taped to carts and door frames, multiple patients' medications carried on one tray, and medications given first and scanned later.[7] None of this was sabotage. Each workaround was a rational response to workload, equipment placement, or a process that did not fit the real work.

Left alone, workarounds become what sociologist Diane Vaughan called the normalization of deviance: each shortcut that does not immediately cause harm makes the next one feel acceptable, until the unofficial procedure has replaced the official one.[8] By the time an adverse event exposes the gap, the deviation may have been routine for years. An audit is the only reliable way to see it sooner. A workaround is not just a staff behavior to correct; it is data showing exactly where the policy and the work have come apart.

Regulators now ask whether your program works

The compliance standard has shifted from “Do you have a policy?” to “Can you show that it works?” The HHS-OIG General Compliance Program Guidance (2023) treats auditing and monitoring as a core element of an effective program and expressly identifies quality and patient safety as compliance risks that boards should oversee.[9] The Department of Justice's Evaluation of Corporate Compliance Programs (updated 2024) asks prosecutors to judge not only whether a program is well designed, but whether it “works in practice,” including whether the organization tests its controls and learns from what it finds.[10]

The financial incentives point the same way. Since 2008, Medicare has declined to pay the added cost of certain hospital-acquired conditions, and the HAC Reduction Program reduces payments by one percent for the worst-performing quarter of hospitals.[11] Measurable medical errors were estimated to cost the U.S. economy $17.1 billion in a single year.[12] An unaudited policy is not a neutral gap. It is unpriced financial risk.

Your policies will be read in court

Courts in many states allow a health system's own policies to be admitted as evidence of the standard of care.[13] In Jutzi v. County of Los Angeles (1987), a county policy authorizing emergency physicians to treat orthopedic injuries helped establish that the hospital had met its standard of care.[14] In Heastie v. Roberts (2007), where a restrained patient was burned after the hospital's own contraband-search policy was not followed, the Illinois Supreme Court held that internal policies may be considered by the jury as evidence bearing on the standard of care, while a violation alone does not automatically establish negligence.[15]

The lesson for compliance is that a followed policy can protect you, and an unfollowed one can hurt you, sometimes more than having no policy at all. The only way to know which kind you have is to audit it.

A system problem, not a staff problem

When harm occurs, the instinct is to find the person who made the mistake. A just culture approach asks a better question: what in the system made the error likely?[16] Individuals remain accountable for reckless choices, but most errors and workarounds are system signals. Blaming the individual closes the file and leaves the conditions in place for the next event. QA and QI audits are how an organization turns systems thinking from a slogan into a practice.

About the Author

Robert Colon-Torres is a healthcare compliance executive with roughly 25 years of experience, most recently as a chief compliance officer for federally qualified health centers in California. He holds a degree in health law from Loyola University Chicago.


References

  1. Kohn LT, Corrigan JM, Donaldson MS, eds. To Err Is Human: Building a Safer Health System. Institute of Medicine; 2000.
  2. Makary MA, Daniel M. Medical error: the third leading cause of death in the US. BMJ. 2016;353:i2139.
  3. Shojania KG, Dixon-Woods M. Estimating deaths due to medical error: the ongoing controversy and why it matters. BMJ Qual Saf. 2017;26(5):423–428.
  4. Rodwin BA, et al. Rate of preventable mortality in hospitalized patients: a systematic review and meta-analysis. J Gen Intern Med. 2020;35(7):2099–2106.
  5. HHS Office of Inspector General. Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (OEI-06-18-00400). 2022.
  6. Bates DW, et al. The safety of inpatient health care. N Engl J Med. 2023;388(2):142–153.
  7. Koppel R, et al. Workarounds to barcode medication administration systems. J Am Med Inform Assoc. 2008;15(4):408–423.
  8. Banja J. The normalization of deviance in healthcare delivery. Bus Horiz. 2010;53(2):139–148.
  9. HHS Office of Inspector General. General Compliance Program Guidance. November 2023.
  10. U.S. Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs. Updated September 2024.
  11. Centers for Medicare & Medicaid Services. Hospital-Acquired Condition Reduction Program.
  12. Van Den Bos J, et al. The $17.1 billion problem: the annual cost of measurable medical errors. Health Aff. 2011;30(4):596–603.
  13. Bal BS. An introduction to medical malpractice in the United States. Clin Orthop Relat Res. 2009;467(2):339–347.
  14. Jutzi v. County of Los Angeles, 196 Cal. App. 3d 637 (1987).
  15. Heastie v. Roberts, 226 Ill. 2d 515 (2007).
  16. Marx D. Patient Safety and the “Just Culture”: A Primer for Health Care Executives. Columbia University; 2001.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance, Quality

From National Patient Safety Goals to National Performance Goals

Executive Accountability, Accreditation Readiness, and Outcome-Based Compliance in 2026 Written by Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

As healthcare organizations enter 2026, regulatory oversight continues to shift away from task-based compliance toward measurable outcomes, leadership accountability, and system-level performance. A defining example of this evolution is the Joint Commission’s replacement of National Patient Safety Goals (NPSGs) with National Performance Goals (NPGs), effective January 1, 2026.

This article is for educational purposes only to provide an executive and auditor-facing analysis of the NPG framework, examining regulatory intent, accreditation implications, and alignment with the Centers for Medicare & Medicaid Services (CMS) Conditions of Participation (CoPs). Practical guidance is offered to support governing boards, executive leadership, and compliance professionals in integrating NPG expectations into enterprise compliance, quality, and risk management programs.

Introduction

Healthcare compliance oversight in 2026 reflects a decisive regulatory transformation. Accrediting bodies and federal regulators are increasingly emphasizing outcome accountability, leadership engagement, and sustained performance improvement rather than episodic documentation compliance. Within this context, the Joint Commission’s transition from National Patient Safety Goals (NPSGs) to National Performance Goals (NPGs) represents a structural and philosophical shift with significant implications for hospitals and critical access hospitals.

As highlighted by the American Institute of Healthcare Compliance (AIHC), the NPG framework consolidates elevated Joint Commission requirements into a unified, outcomes-focused chapter aligned with CMS Conditions of Participation. While the underlying requirements largely pre-existed, the NPG structure reframes how organizations are evaluated, increasing scrutiny of governance, leadership oversight, and data-informed decision-making.

Regulatory Evolution: From Prescriptive Safety Tasks to Performance Outcomes

National Patient Safety Goals historically served as targeted mechanisms to address discrete safety risks, such as medication errors, healthcare-associated infections, and communication failures. Over time, however, organizations frequently approached NPSGs as checklist items tied to survey cycles rather than as drivers of continuous improvement.

The National Performance Goal framework addresses this limitation by organizing fourteen measurable performance domains that emphasize outcomes rather than task completion. This evolution aligns with value-based care models and reinforces expectations that organizations demonstrate sustained, system-level performance rather than episodic compliance.

Alignment with CMS Conditions of Participation

A defining feature of the NPG framework is its intentional alignment with Centers for Medicare & Medicaid Services (CMS) Conditions of Participation (CoPs). CMS CoPs establish baseline federal requirements for participation in Medicare and Medicaid programs. The Joint Commission’s NPGs clarify expectations that exceed these minimum standards, thereby signaling areas of heightened regulatory and accreditation focus.

For compliance leaders, this alignment underscores the necessity of integrating accreditation readiness with CMS survey preparedness.

  • Performance deficiencies identified through NPG evaluation may expose organizations to downstream risk during CMS audits, enforcement actions, or corrective action reviews.

Elevated Focus Areas and Sustained Regulatory Oversight

Although the NPG framework emphasizes flexibility in achieving outcomes, certain high-risk domains retain explicit regulatory requirements. Goals addressing suicide risk reduction and care planning and evaluation continue to require prescriptive safeguards due to their association with patient harm and regulatory enforcement history.

This dual structure reinforces that outcome-based compliance does not eliminate the need for evidence-based controls in high-risk areas. Executive leadership must ensure these domains receive sustained oversight, resource allocation, and performance monitoring.

Executive and Board Accountability Under the NPG Framework

The transition to National Performance Goals elevates accountability beyond frontline operations to executive leadership and governing bodies. Surveyors increasingly assess how boards and senior leaders oversee quality metrics, respond to performance trends, and allocate resources to address identified gaps.

Organizations unable to demonstrate leadership engagement in performance oversight may face accreditation findings related to leadership standards, regardless of whether direct patient harm has occurred.

Compliance Risks of Superficial Implementation

A significant compliance risk during the NPG transition is treating the framework as a rebranding exercise. Organizations that update policies without strengthening data analytics, governance structures, and continuous monitoring mechanisms may fail to meet survey expectations. Effective NPG implementation requires interdisciplinary collaboration, integration with enterprise risk management, and routine evaluation of performance outcomes.

Survey Readiness in an Outcome-Driven Accreditation Environment

Survey readiness under the NPG framework requires a departure from document-centric preparation models. Surveyors are expected to evaluate how organizations use performance data to identify trends, implement corrective actions, and sustain improvements.

Best practices include outcome-focused mock surveys, alignment of dashboards with NPG domains, and leadership preparedness to articulate how performance data informs strategic decisions.

Conclusion

The replacement of National Patient Safety Goals with National Performance Goals represents a pivotal shift in accreditation and compliance oversight. By prioritizing outcomes, leadership accountability, and alignment with CMS Conditions of Participation, the Joint Commission has elevated expectations for organizational performance.

Healthcare organizations that proactively integrate NPG expectations into governance, compliance, and quality frameworks will be best positioned to mitigate regulatory risk and demonstrate sustained accountability in 2026 and beyond. 

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Quality Meets Sustainability

A Rising Imperative in Healthcare Compliance 

Written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 


This article explores the relationship between healthcare quality and sustainability, presents the rationale for adopting a “Triple Bottom Line” approach, and offers strategies for embedding ecological and social responsibility into compliance-driven quality improvement.

Introduction

Healthcare quality has long been measured through the lens of clinical outcomes, patient safety, and regulatory compliance. Yet, a new imperative has emerged—one that integrates environmental stewardship and social responsibility into the very definition of quality. This paradigm shift recognizes that sustainable healthcare is no longer a peripheral concern, but rather a fundamental component of ethical, compliant, and effective care delivery.

For healthcare organizations and compliance professionals, the integration of sustainability into quality frameworks represents both a timely opportunity and a professional responsibility. 

Defining Sustainable Healthcare

The healthcare sector is responsible for an estimated 8.5% of total greenhouse gas emissions in the United States (Health Care Without Harm, 2020). Hospitals are resource-intensive, operating 24/7 with significant consumption of energy, water, pharmaceuticals, and plastics. 

Sustainable healthcare is the practice of meeting present health needs without compromising the ability of future generations to meet theirs. It requires balancing three interdependent domains:

1. Economic sustainability – managing healthcare resources efficiently to ensure affordability and equity of access.

2. Social sustainability – promoting health equity, reducing disparities, and strengthening community partnerships.

3. Environmental sustainability – reducing the healthcare sector’s ecological footprint by minimizing waste, energy use, and emissions (Sustainable Healthcare, 2025).

Embedding sustainability within quality initiatives is both an ethical and a compliance imperative.

Quality and the Triple Bottom Line

Traditional quality improvement models—such as Donabedian’s framework of structure, process, and outcomes—have largely focused on clinical performance and patient safety. While essential, this lens is incomplete in today’s context of global health challenges. The Triple Bottom Line (TBL) expands quality assessment to include three metrics:

  • Clinical outcomes (health, safety, compliance)
  • Environmental outcomes (carbon footprint, waste reduction, resource efficiency)
  • Social outcomes (equity, workforce well-being, community health impact)

By incorporating the TBL into compliance frameworks, healthcare organizations can ensure that quality improvement is not only patient-centered, but also community-centered and planet-centered. This expanded view aligns with both ethical principles and federal regulatory trends that increasingly emphasize population health, social determinants of health (SDoH), and health equity.

Why Sustainability Matters for Healthcare Compliance

Regulatory and Policy Drivers

Recent policy developments underscore the growing expectation for healthcare organizations to consider sustainability:

  • Centers for Medicare & Medicaid Services (CMS) has prioritized health equity and community impact in value-based care models, indirectly encouraging sustainable practices.
  • The Joint Commission has begun incorporating sustainability questions into accreditation surveys, particularly in areas of waste management, climate preparedness, and resilience planning.
  • World Health Organization (WHO) emphasizes planetary health and urges member states to align healthcare delivery with environmental responsibility (WHO, 2021).

Compliance specialists can anticipate that sustainability metrics may eventually intersect with reimbursement, accreditation, and public reporting; similar to how quality measures evolved from voluntary to mandatory over the past two decades.

Risk Management and Cost Savings

Ignoring sustainability can increase compliance risk in areas such as waste disposal, pharmaceutical management, and energy inefficiency. Conversely, organizations that integrate sustainability often realize cost savings. Studies show that hospitals implementing energy efficiency programs save an average of $3 per square foot annually (Practice Greenhealth, 2022). These savings can be reinvested into quality improvement, creating a positive feedback loop between sustainability and compliance.

Integrating Sustainability into Quality Frameworks

1. Governance and Leadership Oversight

Boards and compliance officers should embed sustainability goals into governance structures. Policies must explicitly address environmental stewardship, community engagement, and equity. Leadership buy-in is essential for aligning sustainability with compliance and risk management functions.

2. Data, Metrics, and Reporting

Compliance professionals are uniquely positioned to integrate sustainability metrics into existing reporting systems. For example:

  • Environmental metrics: energy usage, emissions, recycling rates, pharmaceutical waste reduction.
  • Social metrics: staff wellness, equity initiatives, community partnerships.
  • Compliance metrics: adherence to environmental regulations and safety standards.

These metrics can be incorporated into existing dashboards, ensuring sustainability is monitored alongside clinical outcomes.

3. Workforce and Education

Staff education is critical. Training programs should link sustainability to ethical obligations and compliance standards. For instance, reducing unnecessary printing or improving medication disposal practices are not just “green initiatives”—they are compliance measures with real quality implications.

4. Partnerships and Community Engagement

Healthcare organizations cannot achieve sustainability in isolation. Collaborations with local agencies, waste management companies, and community health organizations create pathways for shared impact. Professional associations and educators can support this by curating best practices, facilitating dialogue, and providing compliance guidance.

The Role of Compliance Professionals in Leading the Movement

Compliance professionals and healthcare leaders are uniquely positioned to champion the integration of sustainability into quality frameworks. Potential initiatives include:

  • Developing training modules on sustainable compliance practices.
  • Publishing white papers that articulate the compliance case for sustainability.
  • Creating model policies that align environmental responsibility with regulatory requirements.
  • Advocating nationally for recognition of sustainability as a dimension of healthcare quality.

By doing so, compliance specialists reinforce their leadership in shaping healthcare education and practice, while also positioning themselves as stewards of ethical, socially responsible, and ecologically sustainable healthcare.

Challenges and Considerations

While the case for sustainability is strong, healthcare organizations will face several challenges:

  • Resource limitations: Upfront investments in energy efficiency or waste management may strain budgets.
  • Measurement complexity: Defining and standardizing sustainability metrics across diverse healthcare settings can be difficult.
  • Cultural change: Shifting mindsets from a narrow focus on clinical outcomes to a holistic view of quality requires strong leadership and sustained education.

Compliance professionals must be prepared to address these barriers while emphasizing the long-term value of sustainability for patients, organizations, and society.

Conclusion

Quality and sustainability are no longer parallel pursuits; they are intertwined imperatives.

Healthcare organizations that fail to integrate environmental and social responsibility into quality improvement risk falling behind in compliance, accreditation, and ethical standards. Conversely, those that embrace the Triple Bottom Line will be positioned as leaders in an era where patients, payers, and policymakers demand accountability beyond clinical outcomes.

For healthcare leaders, educators, and compliance professionals, this is an opportunity to advance the field by positioning sustainability as a core dimension of compliance and quality. By doing so, they can help reshape the healthcare quality movement into one that is not only clinically effective but also socially equitable and environmentally responsible; a legacy that benefits patients today and generations to come.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Health Care Without Harm. (2020). Healthcare’s climate footprint. Retrieved from https://noharm.org
  • Practice Greenhealth. (2022). The business case for environmental sustainability in healthcare. Retrieved from https://practicegreenhealth.org
  • Sustainable healthcare. (2025). In Wikipedia. Retrieved from https://en.wikipedia.org/wiki/Sustainable_healthcare
  • World Health Organization (WHO). (2021). WHO Manifesto for a healthy recovery from COVID-19: Prescriptions for a healthy and green recovery. Geneva: WHO.
  • Donabedian, A. (1988). The quality of care: How can it be assessed? JAMA, 260(12), 1743–1748.
  • The Joint Commission. (2023). Sustainability and accreditation: Environmental and emergency preparedness considerations. Oakbrook Terrace, IL.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Monitoring Claims for Accuracy

Addressing Coding Discrepancies and CAC Limitations to Strengthen Quality and Compliance 

Written By Dr. Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

Computer-Assisted Coding (CAC) can expedite your process, but is it accurate?  This article discusses the limitations of CAC and how to strengthen documentation and compliance to improve quality of care and improve the accuracy of your claims.

Introduction

As healthcare delivery becomes increasingly data-driven, the integrity of clinical documentation and billing practices directly impacts provider reimbursement, compliance with federal and state regulations, and ultimately, patient outcomes. Monitoring claims for accuracy is a vital process within revenue cycle management, serving as both a quality assurance tool and a compliance safeguard. A critical area of concern is the rise of discrepancies in coding, particularly when documentation appears clinically accurate, but coding errors—often exacerbated by overreliance on Computer-Assisted Coding (CAC)—compromise claim validity. This article explores the importance of proactive claim review processes, discusses the limitations of CAC, and outlines evidence-based strategies to ensure documentation and coding alignment. Emphasis is placed on quality as the foundation of compliance, with practical suggestions for mitigating discrepancies, even amid the time pressures faced by providers.

The Link Between Coding Accuracy, Quality, and Compliance

Accurate clinical coding is essential for several reasons: it ensures appropriate reimbursement, supports population health analytics, and reflects the true acuity and complexity of patient care. According to the Office of Inspector General (OIG), improper payments in Medicare and Medicaid programs continue to cost billions annually, often stemming from coding errors rather than fraud (OIG, 2022). Compliance programs in healthcare are thus required not only to prevent intentional misconduct but also to detect and correct unintentional inaccuracies in claims data.

The Centers for Medicare & Medicaid Services (CMS) stress that quality documentation alone is insufficient; it must be accurately translated into billing codes to meet compliance standards (CMS, 2021). When documentation is thorough but coding does not reflect that detail—whether due to human error, insufficient training, or flawed automation—the result is inaccurate reimbursement, potential audits, and regulatory penalties.

Computer-Assisted Coding (CAC): Promise and Pitfalls

CAC systems, designed to improve coding efficiency, use natural language processing (NLP) to extract clinical concepts from documentation and assign appropriate codes. While they can reduce manual workload and improve turnaround times, CAC tools are not infallible. Studies show that CAC accuracy varies widely depending on clinical domain and documentation quality (Dai et al., 2020). A major concern is that CAC tools may suggest incorrect codes if the software misinterprets nuanced clinical information or lacks the specificity required for precise classification.

A 2021 Journal of AHIMA study found that while CAC tools reduced average coding time, they introduced a 12–15% increase in coding discrepancies when not accompanied by robust human review (AHIMA, 2021). This “automation bias” can lead coders to accept system-suggested codes without sufficient validation. Moreover, CAC limitations are particularly evident in complex cases involving chronic conditions, behavioral health diagnoses, or overlapping comorbidities, where documentation subtleties are critical to proper code selection.

Encounter Discrepancies: Causes and Consequences

Encounter discrepancies arise when the documentation recorded by providers does not align with the diagnosis, procedure, or service codes submitted on a claim. Common causes include:

  • Overgeneralization by CAC tools, which may default to unspecified codes.
  • Provider time constraints, limiting detailed note-taking or code validation.
  • Inadequate coder training, particularly in emerging or specialty service lines.
  • Misalignment between clinical terminology and coding nomenclature.

These discrepancies may be flagged as errors during internal audits or external reviews, resulting in claim denials, delayed payments, or post-payment recoupments. Additionally, persistent discrepancies can trigger focused audits by entities such as Recovery Audit Contractors (RACs) or Unified Program Integrity Contractors (UPICs).

Evidence-Based Models for Monitoring and Review

To mitigate discrepancies and ensure accurate claims, healthcare organizations must adopt evidence-based quality assurance models that include routine claim review, coder education, and collaborative documentation practices.

  1. Plan-Do-Check-Act (PDCA) Cycle: This quality improvement framework can be applied to the coding process. Regular monitoring (Check), followed by targeted interventions (Act), and process refinement (Plan/Do), can drive measurable improvements in claim accuracy (Deming, 1986).
  2. Clinical Documentation Improvement (CDI) Programs: These initiatives promote ongoing dialogue between providers and coders to clarify ambiguities and ensure specificity in documentation. Studies have shown that robust CDI programs can increase coding accuracy by 20–30% (Garza et al., 2019).
  3. Concurrent Coding Audits: Instead of retrospective reviews, concurrent audits allow for real-time identification and correction of errors before claims are submitted. When coders or compliance specialists are embedded in the clinical workflow, they can flag discrepancies early and reduce downstream issues (AHIMA, 2022).
  4. Root Cause Analysis (RCA): When high-error claims are identified, RCA can be used to trace the source of errors—be it documentation gaps, CAC misinterpretation, or coder oversight—and develop targeted solutions.

Mitigation Strategies for Busy Clinical Environments

One of the persistent barriers to accuracy is the limited time that providers have with each patient. This pressure often leads to documentation shortcuts, copy-forward behaviors, or lack of specificity in notes, which in turn affects coding quality. The following strategies can help:

  • Leverage pre-visit planning tools that prompt providers on key documentation elements based on the patient’s problem list or chronic conditions.
  • Implement coder-provider feedback loops, where recurring discrepancies are discussed in monthly or quarterly forums.
  • Provide microlearning sessions or just-in-time training for coders, especially after major code set updates (e.g., ICD-10-CM changes each October).
  • Develop encounter-specific documentation templates that guide providers to document with the level of specificity required for accurate code assignment.
  • Use dashboards and KPIs to track claim denial reasons, coding error rates, and CAC override frequency. This enables continuous improvement monitoring.

The Role of Compliance Officers and Risk Management

Compliance professionals must view coding accuracy as a risk management issue. When errors go unchecked, they may result in False Claims Act (FCA) violations, whistleblower reports, and reputational damage. In fact, over 85% of healthcare compliance settlements involve allegations of inaccurate billing and coding (DOJ, 2023).

It is imperative that compliance teams collaborate closely with HIM (Health Information Management), billing, and clinical operations to:

  • Establish routine coding audits.
  • Analyze error trends and provider outliers.
  • Develop corrective action plans and re-education strategies.
  • Ensure CAC systems are updated and monitored for performance drift.

By embedding compliance into everyday workflows rather than viewing it as a retrospective function, organizations can create a culture of accountability that enhances both care and claim accuracy.

Conclusion

Coding accuracy is not merely a technical function—it is a linchpin of healthcare quality, financial integrity, and regulatory compliance. While documentation remains a critical starting point, coding must accurately reflect that documentation to meet standards of care and legal expectations.

As CAC tools become more prevalent, healthcare organizations must remain vigilant about their limitations and ensure human oversight remains central to coding decisions. With the implementation of quality improvement frameworks, clinical collaboration, and robust audit practices, encounter discrepancies can be mitigated—improving not only claims accuracy but also compliance resilience in an increasingly scrutinized healthcare landscape.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • AHIMA. (2021). Impact of Computer-Assisted Coding on Coding Accuracy and Productivity. Journal of AHIMA.
  • AHIMA. (2022). Concurrent Coding Audits in Clinical Workflows. American Health Information Management Association.
  • Centers for Medicare & Medicaid Services (CMS). (2021). Medicare Fee-for-Service 2020 Improper Payments Report.
  • Dai, H., et al. (2020). Evaluating the accuracy of computer-assisted coding systems in healthcare. Health Informatics Journal, 26(4), 2765-2778.
  • Deming, W. E. (1986). Out of the Crisis. MIT Press.
  • Department of Justice (DOJ). (2023). False Claims Act Settlements and Judgments: Annual Update.
  • Garza, H., Spivak, C., & Daniels, M. (2019). Documentation improvement and compliance outcomes. Journal of Healthcare Compliance, 41(3), 45-52.
  • Office of Inspector General (OIG). (2022). Top Management and Performance Challenges Facing HHS.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Coding Integrity and CAC

Why Quality Must Precede Compliance in Healthcare Documentation   

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE   

Computer-Assisted Coding, better known as “CAC” has become the norm over the past decade, but are we producing compliant, accurate results?  Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less, which is the reason for this article.

Introduction

In today’s fast-paced healthcare environment, coding accuracy is often caught in the crossfire between compliance pressures, productivity demands, and evolving technology. While documentation may be clinically sound, coding associated with documentation can be misaligned or inaccurate, particularly when it is generated by CAC tools.  CAC can trigger regulatory scrutiny, revenue cycle inefficiencies, and reputational risk without verification by an experienced coding first. As a compliance specialist and educator, I contend that quality cannot be compromised for speed or convenience. In fact, quality is the cornerstone of compliance.

Healthcare consultants recently noted that “documentation is often accurate, but the coding is not,” underscoring a critical gap in the way organizations approach their revenue cycle and risk management. This article explores the current landscape of coding discrepancies, the limitations and risks of CAC, and the essential need for robust internal review processes.

The Disconnect Between Documentation and Coding

In many provider organizations, clinical documentation accurately reflects the patient’s story—diagnoses, treatments, and provider decision-making—but coding processes fall short. Coders may misinterpret documentation, overlook nuances, or rely too heavily on automation, leading to miscoded encounters that can have ripple effects across billing, audit, and quality reporting systems. When errors go undetected, the result can be upcoded services, denied claims, compliance violations, and patient safety concerns. According to the Office of Inspector General (OIG), improper payments stemming from inaccurate coding continue to plague the Medicare program, costing billions annually (OIG, 2023).

CAC: A Double-Edged Sword

Computer-assisted coding (CAC) software, designed to improve speed and efficiency, is now a common fixture in health information management. While these systems can process large volumes of data quickly, their reliance on algorithms rather than clinical reasoning poses significant challenges.

Research has shown that CAC tools may struggle to interpret context, such as distinguishing between active and historical conditions, or differentiating provider impressions from definitive diagnoses (AHIMA, 2022). Without skilled human oversight, these limitations result in critical coding inaccuracies. Unfortunately, some healthcare systems mistakenly treat CAC outputs as final codes without sufficient validation.

Quality needs to be the focus to meet compliance standards. CAC should be a tool to enhance human accuracy—not replace it.

Compliance Risks from Coding Discrepancies

Coding discrepancies—particularly those uncorrected in CAC workflows—are not simply operational issues; they are compliance risks. Auditors from CMS, OIG, and commercial payers increasingly target mismatches between documentation and billing codes. These discrepancies may be flagged as potential fraud, waste, or abuse.  Examples of common coding problems that trigger scrutiny include:

  • Upcoding or down coding visits that do not align with documentation
  • Inaccurate diagnosis coding affecting risk adjustment
  • Use of unspecified or non-supported codes
  • Failure to reflect clinical severity accurately

The DOJ's increased enforcement under the False Claims Act often centers on patterns of poor coding oversight. Healthcare entities must demonstrate that they are taking proactive steps to ensure coding integrity.

Quality as a Compliance Imperative

Ensuring the integrity of clinical coding isn’t just about reimbursement—it’s about compliance, patient care quality, and data accuracy. As healthcare moves toward value-based models, accurate coding supports correct risk adjustment, patient attribution, and performance measurement.

Implementing regular coding reviews, especially of CAC-assisted encounters, is a best practice that healthcare experts recommend. These reviews should be multidisciplinary, involving coding professionals, clinicians, and compliance officers. They help:

  • Identify patterns of misinterpretation or misclassification
  • Provide targeted coder education and clinical documentation improvement (CDI)
  • Verify whether CAC algorithms need adjustment or replacement

Quality assurance activities are not optional—they are essential to both ethical billing and regulatory compliance.

Balancing Productivity Pressures with Accuracy

It is well understood that providers are under immense pressure to manage high volumes of patients while fulfilling extensive documentation requirements. These constraints often lead to documentation fatigue and over-reliance on templated language or CAC tools.  However, automation cannot replace clinical judgment or attention to detail. Coders must be trained to spot subtle inconsistencies and to understand that their role is pivotal in compliance integrity. Likewise, providers need CDI support that makes documentation more efficient and accurate—not more burdensome.

Healthcare leaders should prioritize investments in coder training, CDI collaboration, and coding audits rather than shortcutting review processes for the sake of productivity.

Recommendations for Compliance-Driven Coding Integrity

To address the systemic risks tied to coding discrepancies and CAC errors, organizations should implement the following:

  1. Routine Internal Coding Audits: Conduct monthly or quarterly reviews of randomly selected encounters, with particular focus on high-risk services.
  2. Coder & Provider Education: Offer ongoing training on documentation standards, code selection, and regulatory updates.
  3. Review of CAC Outputs: Routinely validate CAC-generated codes against documentation. Never treat CAC outputs as final.
  4. Real-Time Feedback Loops: Encourage communication between CDI specialists, coders, and providers to resolve discrepancies quickly.
  5. Compliance-Focused KPI Tracking: Monitor error rates, denial trends, and audit findings to identify areas needing improvement.

Conclusion

Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less.

Automation cannot replace accountability.

Compliance leaders must treat quality assurance and coding integrity as non-negotiable pillars of risk management. Let us not allow convenience to compromise compliance. Instead, let quality lead the way.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  1. American Health Information Management Association (AHIMA). (2022). The Realities of Computer-Assisted Coding. Retrieved from https://www.ahima.org
  2. Office of Inspector General (OIG). (2023). Medicare Improper Payment Reports. Retrieved from https://oig.hhs.gov
  3. Centers for Medicare & Medicaid Services (CMS). (2024). Evaluation and Management Services Guide. Retrieved from https://www.cms.gov
  4. U.S. Department of Justice. (2023). False Claims Act Settlements and Judgments Exceed $2 Billion in Fiscal Year 2023. Retrieved from https://www.justice.gov/opa/pr

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Culture of Safety is based on Prevention, not Punishment

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS  

This article emphasizes the need of healthcare institutions to focus on building a culture of safety through Root Cause Analysis (RCA) to Manage Clinical Risk is an important management tool.  Read Part 1: Building a Culture of Patient Safety Starts with Reducing Staff Burnout posted December 3, 2024 and Part 2:  An Approach to Reduce Patient and Workforce Harm.

Introduction

Keeping patients safe requires an organizational culture of safety based on the commitment from Directors and C-Suite Executives.  Creating a patient safety environment includes complex interventions that involve the need for variations in individual work routines and healing processes as well as behavioral changes to be made on the part of the team or the individual for maximum acceptance from others.

Patient safety is a framework of organized activities that creates cultures, processes, procedures, behaviors, technologies and environments in health care that consistently and sustainably lower risks, reduce the occurrence of avoidable harm, make error less likely and reduce its impact when it does occur.

Every point in the process of care-giving contains a certain degree of inherent unsafety.

Clear policies, organizational leadership capacity, data to drive safety improvements, skilled health care professionals and effective involvement of patients and families in the care process, are all needed to ensure sustainable and significant improvements in the safety of health care.

Root Cause Analysis & Patient Safety

Most healthcare organizations use RCA as a tool to find out what happened, why it happened, and how to prevent it from happening again. The process is a tool for identifying prevention strategies. It is a process that is part of the effort to build a culture of safety and move beyond the culture of blame.

In a Root Cause Analysis Program, basic and contributing causes are discovered in a process similar to diagnosis of disease - with the goal always in mind of preventing recurrence.  The following information breaks this complex process down into basic bullet points and serves as an introduction to this topic only. 

What the RCA process is:

  • An inter-disciplinary, involving experts from the frontline services;
  • Successful when you involve those who are the most familiar with the situation;
  • A process which requires diligence - continually digging deeper by asking why, why, why at each level of cause and effect;
  • A process that requires your organization to identify changes that need to be made to systems; and
  • A process that must be performed with objectivity and as impartial as possible.

What RCA Should Encompass:

  • Determination of:
    • human and other factors;
    • Related processes and systems
    • potential improvement in processes or systems
  • Analysis of underlying cause and effect systems through a series of why questions
  • Identification of risks and their potential contributions

For Your Program to be Credible, an RCA must:

  • Adopt a top-down approach
    • Include participation by the leadership of the organization and those most closely involved in the processes and systems
  • Be internally consistent
  • Include consideration of relevant literature

The Safety Assessment Code (SAC)

The Safety Assessment Code (SAC) can be used to determine whether or not an RCA must be conducted, based on the severity of a specific incident and its probability of occurrence.  It is a method for determining whether any further definitive action is required concerning a particular incident based on the severity of the incident and its probability of occurrence.

A "SAC score" is also of value for incidents that did not result in an adverse event but may also lead to an RCA; i.e., a close call. Close calls occur far more frequently than adverse events and can provide an exceptional opportunity for learning. Close calls afford the chance to develop preventive strategies and actions before a patient may be harmed.

The SAC Matrix is a tool for combining severity and probability. While either the severity or probability of occurrence could be determined first, it is usually more productive to assess the severity first.

When you pair a severity category with a probability category for either an actual event or close call, you will get a ranked matrix score.  These ranks, or Safety Assessment Codes (SAC), can then be used for doing comparative analysis.  There are various SAC matrix tables available, the one below uses 3 severity and 4 probability categories. 

SAC Decision Making Matrix

While either the severity or probability of occurrence could be determined first, it is usually more productive to assess the severity first. This is true since until one has determined the severity of an incident it would be difficult if not impossible to assess an appropriate probability level.  Intersect the 2 categories to determine the SAC score.  For example, if the probability of the adverse event happening if frequent and it is determined by the team that it ranks a severity of “3”, then result would be mapped in the table below.

3 = highest risk

2 =  intermediate risk

1 =  lowest risk

probability severity

The utility of the SAC is at the start of the process so that resources are applied where they have the greatest opportunity to improve the level of safety from a systems perspective.

Root Cause Analysis (RCA) Versus Healthcare Failure Mode & Effects Analysis (HFMEA™)

HFMEA™ is a technique that is usually performed on a system to assess and prioritize the risks associated with that system in the hopes of reducing the risks through re-design as a proactive measure.  Both Root Cause Analysis (RCA) and Healthcare Failure Mode and Effects Analysis (HFMEA™) possess the following elements:

  • Both are non-statistical methods of analysis
  • The goal of both is to reduce patient harm
  • Both involve identifying conditions that lead to harm
  • Both are team activities

Many people confuse these terms and believe that they compete against each other when in fact neither of these two techniques can accomplish what the other can. They are complementary to each other.  A “root cause” is the most fundamental reason for a failure or situation where performance does not meet expectations.

  • Root cause analysis is routinely conducted reactively – to probe the reason for a poor or unexpected outcome or failure which has already occurred.
  • A recent use of root cause is to conduct such analysis as part of a proactive risk reduction effort using Healthcare Failure Mode and Effects Analysis (HFMEA™).

The table below provides a side-by-side comparison of these two analytical tools used in health care.



RCA

Required by Joint Commission after a sentinel event

HFMEA™

Proactive approach to prevent system-related failures

Similarities

  • Non-statistical methods of analysis;
  • Goal is to reduce possibility of harm to patients in the future;
  • Involves identifying conditions that lead to harm;
  • Requires experienced and trained quality managers to lead analysis efforts; and
  • Activity which requires people, time, materials and upper-level management support.

Differences

                            RCA                                                             HFMEA™

Reactive

Proactive

Focuses on an event

Focuses on entire process

Hindsight bias

Unbiased

Fear, resistance

Openness

Asks: “Why?”

Asks: “What if?”

Summary

Organizational culture refers to the shared beliefs, values, and behaviors within a healthcare organization. A lack of emphasis on patient safety in organizational culture can hinder initiatives that aim to ensure patient safety. It may manifest itself as a lack of commitment, inadequate support, or insufficient prioritization of safety measures by the hospital's leadership and staff. This can result in a higher likelihood of medical errors and adverse events occurring. A weak organizational culture can also discourage staff from reporting incidents or speaking out about potential safety concerns further compromising patient safety.

Building a culture of safety starts with educating your Board of Directors, a C-Suite Executives.  The Compliance Department should oversee internal audits that not only include typical compliance risks related to fraud, waste and abuse, but measuring compliance to safety standards as well.  Producing reports to present to high-level executives can help support the budget needed to mitigate patient risk of an adverse event.

To learn more about RCA, I recommend registering for the Certified Healthcare Auditor online certification training program which includes not only auditing, but using RCA for corrective action after the audit.  To learn more about training as a healthcare Compliance Officer, I highly recommend the online Corporate Compliance certification program. 

About the Author and AIHC

The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair and overseeing the AIHC Volunteer Education Committee. She is also a volunteer hospice nurse, hospice hands-on-care volunteer and End of Life Doula.

The American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS. Please visit our online store listing current training and certification offerings.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Leadership, Quality

An Approach to Reduce Patient and Workforce Harm

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS  

This article emphasizes the need of healthcare institutions to focus on building a culture of safety through improving care of the workforce.  Read Part 1: Building a Culture of Patient Safety Starts with Reducing Staff Burnout posted December 3, 2024.

New Dashboard to Track Progress

On December 5, 2024, the National Action Alliance for Patient and Workforce Safety (NAA) at the U.S. Department of Health and Human Services (HHS) launched the National Healthcare Safety Dashboard, an online resource that aggregates hospital safety data from four primary measurement sources. Thus, the dashboard creates one comprehensive resource for understanding the current state of patient and workforce safety.

The Agency for Healthcare Research and Quality (AHRQ) works under the Department of Health and Human Services.  AHRQ sponsors the National Action Alliance for Patient and Workforce Safety and now offers a resource for national patient and workforce safety data dashboard. The goal of data collection is to improve safety of patients and your healthcare workforce.

The National Healthcare Safety Dashboard makes national safety data more transparent, allowing for a comprehensive understanding of healthcare safety by care setting, beginning with hospital care. It opens doors to information and best practices to empower healthcare provider organizations, patient advocates, policymakers, professional associations and others to monitor national safety progress and make informed decisions to improve safety nationwide.

The National Action Alliance goals, listed below, are intended to help all healthcare systems strengthen their patient and workforce safety outcomes.


1.  Advance Healthcare Organization Safety Strategies Using Safety Self-Assessments

  • Encourage healthcare organizations to perform safety self-assessments focused on the NAP’s foundational elements.
  • Support healthcare organizations in their efforts to enact safety strategies based on identified gaps.

2.  Empower the Patient's Voice in Safety Strategy

  • Allow patients and families to submit safety concerns into healthcare organization event reporting systems.
  • Encourage healthcare organizations to implement communication and resolution programs.
  • Engage patients and families in safety event reviews and in safety initiative planning.

3.  Support the Healthcare Workforce by Making Healthcare Safer by Design

  • Identify and address five high-priority safety engineering needs.

4.  Support the Healthcare Workforce by Strengthening Healthcare Safety Competencies

  • Ensure all healthcare team members, from administrators to clinical and non-clinical staff, receive training in fundamental safety competencies.

5.  Facilitate a Learning and Research Network

  • Encourage learning and sharing across network.
  • Spotlight change leaders.
  • Promote robust safety measurement locally and nationally.
  • Support research to address high-priority needs in patient and workforce safety.

The initial version of the dashboard offers access to hospital safety data and will expand to include other healthcare settings, such as ambulatory clinics and nursing homes.  The data sources listed on the Dashboard include:

Resources and Tools on Patient and Healthcare Workforce Safety

Resources are listed on the AHRQ website by type of harm. These tools and resources include active federally sponsored implementation initiatives and funding opportunities and can help you address safety needs that you identify in your safety self-assessment.

  • Diagnostic Safety
  • Falls
  • Hospital-Associated Infections
  • Maternal Safety
  • Medication Safety
  • Never Events
  • Opioid Safety
  • Pressure Ulcers
  • Readmissions
  • Sepsis
  • Surgical Safety
  • Transitions in Care
  • Venous Thromboembolism

The AHRQ recommended Self-Assessment Tool is an essential resource designed to help health care organizations evaluate their safety readiness, identify opportunities for improvement, and track progress over time. The 2024 updated version of the tool aligns with the recommendations in Safer Together: A National Action Plan to Advance Patient Safety (National Action Plan) and incorporates the latest insights and best practices from global safety initiatives.

Conclusion

Healthcare is not safe until it is safe for all.  As healthcare organizations implement these initiatives and work collectively across the NAA, the National Healthcare Safety Dashboard becomes an essential tool that allows the healthcare community to monitor progress and offers insights to guide further action.  Workforce safety recognizes the imperative to protect workforce members from physical harm so that they can deliver high-quality care, and recognizes the vital importance of psychological and emotional safety for engaging, communicating, and collaborating effectively to safely deliver patient care.

The National Healthcare Safety Dashboard is now live and accessible to the public:

About the Author and AIHC

The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair and overseeing the AIHC Volunteer Education Committee. She is also a volunteer hospice nurse, hospice hands-on-care volunteer and End of Life Doula.

The American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS. Please visit our online store listing current training and certification offerings.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Leadership, Quality

Building a Culture of Patient Safety Starts with Reducing Staff Burnout

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS

Patient safety directly relates to reducing mistakes. Increased job-related stress contributes to workforce burnout, a major contributing factor to unsafe practices. Unfortunately, our healthcare workforce faces unprecedented challenges: incidence of violence in the workplace, accelerated rates of burnout, and exposure to dangerous hazards.  This article emphasizes the need to improve patient safety and outcomes through reducing staff burnout.

Introduction

Providing a safe environment instills confidence not only to the patients we serve, but for our workforce as well.  According to the National Institutes of Health, a strong link exists between workforce wellness and patient safety.  When healthcare workers are physically and mentally well, they are more likely to have the ability to focus and deliver safe and quality patient care.  Therefore, we can conclude that a healthy workforce is necessary for a safe patient environment. 

A positive patient and workforce safety culture has been shown to significantly improve a number of patient outcomes, including lower rates of surgical site infections, falls, and medication errors, according to the Patient Safety Network. In addition to specific health outcomes, patients report having better experiences with their care when the culture of patient safety is strong.

Although most healthcare organizations agree on the importance of safety culture, research this year focused heavily on the psychological factors surrounding culture, such as psychological safety, how to support healthcare workforce staff after an adverse event, and burnout. This is a challenge in today’s world.

Work Overload as a Contributing Factor

Causes of work overload in healthcare include time constraints; alert or alarm fatigue; new and hard-to-use technology, including EHRs; and cognitive strain, which, according to the American Medical Association (AMA), directly or indirectly causes 87.1% of medical errors—even though most safety interventions focus on training clinicians, whose knowledge and skill is responsible for only 12.8% of medical errors.

Assaults, Violence Contribute to Burnout

The passion most healthcare workers have can be overridden by the threat of on-the-job violence. And this doesn’t even account for the threats encountered getting to and from work!

According to the Bureau of Labor Statistics, there is a 63% increase in the rate of injuries from violent attacks against medical professionals from 2011 to 2018. And, according to a report by the Centers for Disease Control (CDC) and the Bureau of Labor Statistics (BLS), it is reported that:

  • In 2020, health care and social assistance workers overall had an incidence rate of 10.3 (out of 10,000 full-time workers) for injuries resulting from assaults and violent acts by other persons.
  • The rate for nursing and personal care facility workers was 21.8 per 10,000 full time workers for injuries caused by assaults and violent acts by others.
    • This means that for every 10,000 full-time employees in nursing and personal care facilities, there were an average of 21.8 reported incidents of workplace violence.
  • Data obtained from nurses (RNs/LPNs) in a major population-based study showed a rate of physical assaults at 13.2 per 100 nurses per year and at a rate of 38.8 per 100 nurses per year for non-physical violent events (threat, sexual harassment, verbal abuse).

As you can see, it is difficult to work your best under these circumstances.  And even though some institutions may have a proper formal incident reporting system, there are still many incidents, especially in the forms of bullying, verbal abuse, and harassment that are never reported.

Most Vulnerable Workforce

The most vulnerable healthcare workers victimized are staff at emergency departments, especially nurses and paramedics, and staff directly involved with in-patient care.

What Patient Safety Is

When discussing “patient safety” in the context of this article, it may be helpful to quote definitions, examples and descriptions of what a safety culture is. 

According to the American Nurses Association, a culture of safety describes the core values and behaviors that come about when there is collective and continuous commitment by organizational leadership, managers, and healthcare workers to emphasize safety over competing goals.   The Joint Commission defines Safety Culture as the sum of what an organization is and does in the pursuit of safety.

From a global perspective, the World Health Organization states that patient safety is defined as “the absence of preventable harm to a patient and reduction of risk of unnecessary harm associated with health care to an acceptable minimum." Within the broader health system context, it is “a framework of organized activities that creates cultures, processes, procedures, behaviors, technologies and environments in health care that consistently and sustainably lower risks, reduce the occurrence of avoidable harm, make error less likely and reduce impact of harm when it does occur."

Is Burnout a Still Problem Now that COVID-19 is Behind Us?

The COVID pandemic is a major contributing factor to the overall burnout of health care workers. And, COVID continues to be a current infectious disease stressor to the healthcare workforce.  According to the Centers for Disease Control (CDC), “Health worker jobs in the U.S. involve demanding and sometimes dangerous duties, including exposure to infectious diseases and violence from patients and their families. The COVID-19 pandemic presented even more stressors. These included a surge of patients, longer working hours, and shortages of supplies and protective equipment. Health workers are reporting feeling fatigue, loss, and grief at levels higher than before the pandemic.”  The CDC reports:

Individuals who choose to work in healthcare often make personal sacrifices for their work. While the work can be rich with purpose and meaning, the demands on time and attention can be relentless to the point of being unhealthy for the healthcare worker.  Leadership’s approach and commitment to patient safety has a significant impact on your organization’s culture. If leaders do not prioritize or actively foster a culture of safety, it can negatively affect staff engagement and commitment to patient safety practices. Strong and supportive leadership is crucial for implementing and maintaining a culture that prioritizes patient safety.  Lack of support from upper management contributes to clinical staff burnout.

Burnout related to work stress is mainly seen as emotional exhaustion, depersonalization, and diminished sense of accomplishment.  This manifests itself with mental and physical exhaustion and is demonstrated as a lack of commitment, inadequate support, or insufficient prioritization of safety measures by leadership and staff. This can result in a higher likelihood of medical errors and adverse events occurring.

In healthcare organizations, patient and workforce safety culture are founded on how well teams work together, how supportive leadership and managers are of patient and workforce safety, how staff report events and near misses, and how teams and leaders respond to events. A weak organizational culture can also discourage staff from reporting incidents or speaking out about potential safety concerns further compromising patient safety.

Focusing efforts on a sound and sustained safety culture will lead to and support better outcomes in patient healthcare and safer working conditions for healthcare workers.

Address Patient Safety and Volunteer Staff Burnout

Don’t overlook the important role of your volunteers! Volunteers have a potential negative impact on patient care when these important members of your team experience high levels of burnout.  This can lead to decreased attention to detail, potential errors, and compromised quality of care due to exhaustion and reduced motivation. Although they are unpaid staff, they still require orientation and training.  When their importance is overlooked and minimized, it can contribute to burnout, making them more prone to mistakes, overlook important details, or have reduced responsiveness, potentially affecting patient safety.  Factors like unclear expectations, excessive workload, lack of support from leadership, inadequate training, and feeling undervalued can contribute to volunteer burnout. 

Emotional exhaustion, decreased engagement, increased absenteeism, irritability, and feeling overwhelmed are common signs of volunteer burnout. Implement systems to identify early signs of burnout in volunteers and provide necessary support or adjustments to their roles. Routine skills testing, annual HIPAA and compliance training should be included in your volunteer program.

Conclusion

The purpose of patient safety is to reduce risks, errors and harm that can occur to patients while receiving medical care, which is part of the huge patient quality emphasis currently stressed in the United States and globally. As the world faces evolving and new challenges, it can be difficult to provide an infrastructure to respond with consistent, effective practices deployed by a workforce that is properly equipped, financially and emotionally supported.

The most effective approach to envision the promotion of a patient safety culture is a multifaceted approach of interventions established at the top.  Additional reading and resources to review are:

About the Author and AIHC

The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair and overseeing the AIHC Volunteer Education Committee.  She is also a volunteer hospice nurse, hospice hands-on-care volunteer and End of Life Doula. 

American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS.  Please visit our online store listing current training and certification offerings.


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved


Read More
Quality
HIPAA, Quality

Quality, Safety & Confidentiality

PSQIA, PSWP & HIPAA Compliance

Written by: AIHC Blogger   


This article addresses patient confidentiality and security related to patient safety evaluations systems, investigations, root cause analysis and compliance to rules and regulations.  It is a basic introduction to help understand the importance of appropriately managing this type of privileged information.

The goal of achieving quality and patient safety is to improve patient safety outcomes by creating an environment where providers can report and examine patient safety events without fear of increased liability risk.  Greater reporting and analysis of patient safety events will help gain a better understanding of patient safety events and result in improvements from lessons learned.

Health care is like “alphabet soup” – filled with acronyms, abbreviations and terms unique to our profession.  Let’s define the 3 acronyms used in the title of this article and how these three rules interact from a compliance perspective.

PSQIA - the Patient Safety and Quality Improvement Act

PSQIA established a voluntary reporting system with the government’s intent to enhance the data available to assess and resolve patient safety and health care quality issues.

On July 29, 2005, the President signed the Patient Safety and Quality Improvement Act of 2005 (Patient Safety Act, 42 U.S.C. sections 299b-21 to 299b-26) into law. The Patient Safety Act amended Title IX of the Public Health Service Act to provide for the improvement of patient safety and to reduce the incidence of events that adversely affect patient safety by authorizing the creation of patient safety organizations (PSOs).

The Agency for Healthcare Research and Quality (AHRQ) lists patient safety organizations which work with providers to improve quality and safety through the collection and analysis of aggregated, confidential data on patient safety events.

PSQIA authorizes our government’s Health & Human Services (HHS) to impose civil money penalties (CMPs) for violations of patient safety confidentiality.  The Office for Civil Rights (OCR) has been delegated the responsibility for interpretation and implementation of the confidentiality protections and enforcement provisions.  When OCR is unable to achieve an informal resolution of an indicated violation through such voluntary compliance, the Secretary may impose a CMP of up to $11,000 for each knowing and reckless disclosure of PSWP that is in violation of the confidentiality provisions.

To encourage the reporting and analysis of medical errors, PSQIA provides Federal privilege and confidentiality protections for patient safety information, called patient safety work product (PSWP).

PSWP - the Patient Safety Work Product

PSWP includes patient, provider and reporter identifying information that is collected, created or used for patient safety activities.

The PSWP is both privileged and confidential under the PSQIA.  PSWP is confidential and may only be disclosed in certain very limited situations where civil money penalties (CMPs) for impermissible disclosures of this information can be imposed.

What it Includes

PSWP is considered any data, reports, records, memoranda, analyses (such as root cause analyses), gap analysis, 8D approach, written or oral statements that are: assembled for reporting to a Patient Safety Organization (PSO); reported to a PSO; or developed by a PSO for the conduct of patient safety activities that could result in improved patient safety, health care quality, or health care outcomes.  It also applies to data used in a patient safety evaluation system (PSES).

PSWP may also include patient information that is protected health information as defined by the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (see 45 CFR 160.103).

What PSWP Is Not

PSWP differs from HIPAA as PSWP does not include a patient’s medical record, billing and discharge information, or any other original patient or provider record. It does not include information that is collected, maintained, or developed separately, or exists separately, from a patient safety evaluation system.

HIPAA- the Health Insurance Portability and Accountability Act

According to the final PSQIA rule, the HIPAA Privacy Rule does not require covered providers to obtain patient authorizations to disclose patient safety work product containing protected health information to PSOs. This is because patient safety activities are considered healthcare operations, typically addressed in the Covered Entity’s Notice of Privacy Practices (NOPP).  PSOs are business associates and should be operating under a Business Associate Agreement or BAA to be compliant under HIPAA rules.

As a Covered Entity (CE) or Business Associate (BA) under HIPAA, regulated entities are required to implement a security management process to prevent, detect, contain, and correct security violations.  This process includes conducting a risk analysis to assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI and implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

A regulated entity that has weak cybersecurity practices makes itself an attractive soft target.  Hackers can penetrate a regulated entity’s network and gain access to ePHI by exploiting known vulnerabilities.  Malicious cyber-attacks targeting the health care sector continue to increase. 

Conclusion

PSQIA, PSWP and HIPAA are government regulations working together to link health care quality, patient safety with privacy and security of privileged information.

All health care providers are expected to investigate any patient safety issues and stay HIPAA compliant while doing so. Sharing information to improve quality and safety in our health care environment is needed to mitigate risk and promote improved reimbursement. 


Online Training:

  • CEs and BAs are encouraged to have C-Suite and management teams trained in HIPAA privacy. Register for the online HIPAA Privacy course worth 12 AHIMA/AIHC CEUs.

Quality and Patient Safety Resources

  • For tips on preventing medical errors and promoting patient safety, measuring health care quality, consumer assessment of health plans, evaluation software, report tools, and case studies, visit the Agency for Healthcare Research and Quality (AHRQ) website and sign up for email updates.
  • The National Advisory Council (NAC) for Healthcare Research and Quality provides advice and recommendations to AHRQ's director and to the Secretary of the Department of Health and Human Services (HHS) on priorities for a national health services research agenda.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More