Quality
Auditing, Corporate Compliance, Quality

The Cost of an Unchecked Policy

WHEN POLICY MEETS PRACTICE | A TWO-PART SERIES

How quality assurance and quality improvement audits keep policies alive and patients safe

Written by Robert Colon-Torres   

Every health system has policies. Far fewer can prove those policies are followed, or that they work. That gap is where preventable harm, financial penalties, and legal exposure live.

In nearly 25 years of healthcare compliance work, I have rarely investigated an adverse event where no policy existed. Far more often, the policy was there. It had been approved, posted, and acknowledged in an annual training. It simply was not what happened on the floor, and no one had checked.

This is the first of a two-part series on that gap between the policies health systems write and the care they actually deliver. My argument across both parts is straightforward: quality assurance (QA) and quality improvement (QI) audits are what turn a policy from a document into a practice, and compliance and CQI must operate as one team to make that happen. Part 1 examines what is at stake when the gap goes unchecked: for patients, for the organization's finances, and in front of regulators and courts. Part 2 explains why the gap opens and how to close it.

Harm is common, and much of it is preventable

The Institute of Medicine's To Err Is Human (1999) estimated that up to 98,000 hospitalized Americans die each year from preventable error.[1] Later estimates ranged far higher, including the widely cited 2016 claim that medical error is the third leading cause of death in the U.S.[2] Those higher figures have been sharply criticized on methodological grounds, and a 2020 meta-analysis put preventable inpatient deaths closer to 22,000 a year.[3][4] Compliance professionals should resist the temptation to lead with the most dramatic number; our credibility depends on precision.

But the debate over mortality obscures a point on which the evidence is consistent: harm itself is common. The HHS Office of Inspector General found that one in four hospitalized Medicare patients experienced harm, and that 43 percent of those events were preventable.[5] A 2023 New England Journal of Medicine study of eleven Massachusetts hospitals found adverse events in nearly one in four admissions, about a quarter of them preventable.[6] More than two decades after To Err Is Human, the problem has not been solved. In most of these cases, the evidence-based practice that would have prevented harm was already known.

Where policy and practice drift apart

Bar code medication administration (BCMA) shows how the drift happens. BCMA was designed to stop wrong-patient and wrong-dose errors, yet researchers documented fifteen distinct workarounds, including spare wristbands taped to carts and door frames, multiple patients' medications carried on one tray, and medications given first and scanned later.[7] None of this was sabotage. Each workaround was a rational response to workload, equipment placement, or a process that did not fit the real work.

Left alone, workarounds become what sociologist Diane Vaughan called the normalization of deviance: each shortcut that does not immediately cause harm makes the next one feel acceptable, until the unofficial procedure has replaced the official one.[8] By the time an adverse event exposes the gap, the deviation may have been routine for years. An audit is the only reliable way to see it sooner. A workaround is not just a staff behavior to correct; it is data showing exactly where the policy and the work have come apart.

Regulators now ask whether your program works

The compliance standard has shifted from “Do you have a policy?” to “Can you show that it works?” The HHS-OIG General Compliance Program Guidance (2023) treats auditing and monitoring as a core element of an effective program and expressly identifies quality and patient safety as compliance risks that boards should oversee.[9] The Department of Justice's Evaluation of Corporate Compliance Programs (updated 2024) asks prosecutors to judge not only whether a program is well designed, but whether it “works in practice,” including whether the organization tests its controls and learns from what it finds.[10]

The financial incentives point the same way. Since 2008, Medicare has declined to pay the added cost of certain hospital-acquired conditions, and the HAC Reduction Program reduces payments by one percent for the worst-performing quarter of hospitals.[11] Measurable medical errors were estimated to cost the U.S. economy $17.1 billion in a single year.[12] An unaudited policy is not a neutral gap. It is unpriced financial risk.

Your policies will be read in court

Courts in many states allow a health system's own policies to be admitted as evidence of the standard of care.[13] In Jutzi v. County of Los Angeles (1987), a county policy authorizing emergency physicians to treat orthopedic injuries helped establish that the hospital had met its standard of care.[14] In Heastie v. Roberts (2007), where a restrained patient was burned after the hospital's own contraband-search policy was not followed, the Illinois Supreme Court held that internal policies may be considered by the jury as evidence bearing on the standard of care, while a violation alone does not automatically establish negligence.[15]

The lesson for compliance is that a followed policy can protect you, and an unfollowed one can hurt you, sometimes more than having no policy at all. The only way to know which kind you have is to audit it.

A system problem, not a staff problem

When harm occurs, the instinct is to find the person who made the mistake. A just culture approach asks a better question: what in the system made the error likely?[16] Individuals remain accountable for reckless choices, but most errors and workarounds are system signals. Blaming the individual closes the file and leaves the conditions in place for the next event. QA and QI audits are how an organization turns systems thinking from a slogan into a practice.

About the Author

Robert Colon-Torres is a healthcare compliance executive with roughly 25 years of experience, most recently as a chief compliance officer for federally qualified health centers in California. He holds a degree in health law from Loyola University Chicago.


References

  1. Kohn LT, Corrigan JM, Donaldson MS, eds. To Err Is Human: Building a Safer Health System. Institute of Medicine; 2000.
  2. Makary MA, Daniel M. Medical error: the third leading cause of death in the US. BMJ. 2016;353:i2139.
  3. Shojania KG, Dixon-Woods M. Estimating deaths due to medical error: the ongoing controversy and why it matters. BMJ Qual Saf. 2017;26(5):423–428.
  4. Rodwin BA, et al. Rate of preventable mortality in hospitalized patients: a systematic review and meta-analysis. J Gen Intern Med. 2020;35(7):2099–2106.
  5. HHS Office of Inspector General. Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (OEI-06-18-00400). 2022.
  6. Bates DW, et al. The safety of inpatient health care. N Engl J Med. 2023;388(2):142–153.
  7. Koppel R, et al. Workarounds to barcode medication administration systems. J Am Med Inform Assoc. 2008;15(4):408–423.
  8. Banja J. The normalization of deviance in healthcare delivery. Bus Horiz. 2010;53(2):139–148.
  9. HHS Office of Inspector General. General Compliance Program Guidance. November 2023.
  10. U.S. Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs. Updated September 2024.
  11. Centers for Medicare & Medicaid Services. Hospital-Acquired Condition Reduction Program.
  12. Van Den Bos J, et al. The $17.1 billion problem: the annual cost of measurable medical errors. Health Aff. 2011;30(4):596–603.
  13. Bal BS. An introduction to medical malpractice in the United States. Clin Orthop Relat Res. 2009;467(2):339–347.
  14. Jutzi v. County of Los Angeles, 196 Cal. App. 3d 637 (1987).
  15. Heastie v. Roberts, 226 Ill. 2d 515 (2007).
  16. Marx D. Patient Safety and the “Just Culture”: A Primer for Health Care Executives. Columbia University; 2001.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Common Compliance Risks in OB/GYN Medical Billing and How to Address Them

Written by Noah Smith for BillingFreedom

The article will help healthcare professionals identify common compliance risks that can arise in OB-GYN medical billing and understand practical approaches for addressing those risks through accurate documentation, coding, claim review, internal audits, and consistent billing workflows.

OB/GYN billing can get complicated quickly. During the same week, a practice may bill for preventive visits, ultrasounds, office procedures, prenatal care, surgery, delivery services, postpartum visits, and treatment for unrelated gynecologic conditions. Those services do not always follow the same documentation, coding, or payer rules. That leaves plenty of room for small mistakes to slip into the billing process.

Sometimes the problem is obvious. A claim is rejected because the subscriber number is wrong or a required field is missing. Other problems are harder to notice. A payer may process a claim even though the documentation is weak, a modifier has been used inconsistently, or staff are following an outdated billing process.

One paid claim does not necessarily tell a practice that everything behind the claim was handled correctly. A better way to think about compliance is to look at the entire path a claim takes:

  • Patient information has to be accurate.
  • Coverage needs to be checked.
  • The provider's note has to support the service.
  • Coding needs to match the record, and payer requirements have to be addressed before the claim goes out.

When one part of that chain breaks down repeatedly, the problem can spread across dozens of claims before anyone recognizes the pattern.

Where OB/GYN Billing Problems Usually Start

Many compliance issues begin before a coder ever looks at the chart. Consider a returning patient whose insurance changed since her last appointment. If the old plan is still listed in the system, the claim may be sent to the wrong payer. By the time the rejection comes back, staff may need to update the account, verify benefits again, rebill the service, and make sure a filing deadline has not been missed.

Authorization problems can develop in much the same way. A service may have been appropriate and clearly documented, yet the claim can still run into trouble if the payer required prior authorization and nobody confirmed it.

Then there is the medical record itself. A provider may remember exactly what was discussed or performed during a visit, but the billing team can only rely on what appears in the documentation. If the note does not clearly support the service being reported, defending the claim later becomes much more difficult.

The Centers for Medicare & Medicaid Services (CMS) provides guidance on electronic healthcare claims and the information needed for claims processing. The larger point for a practice is simple: compliance starts long before a denial or payer review arrives.

Documentation and Coding Need to Tell the Same Story

Documentation and coding are often discussed as separate tasks. In actual billing, they are difficult to separate. The code on the claim is supposed to represent what happened during the encounter. The medical record is what supports that representation.

Problems begin when the two tell different stories.

A common OB/GYN situation is a preventive visit in which the patient also brings up a new medical concern. Additional evaluation may take place during the same encounter. Whether separate reporting is appropriate depends on the services performed, the documentation, coding rules, and the payer's requirements. Similar questions come up with procedures, diagnostic testing, postoperative care, maternity services, and modifier use.

A diagnosis code may be valid in general but still fail to match what the provider actually documented. A procedure code may describe a service correctly but lack enough support in the chart. A modifier can also create problems when staff use it routinely instead of deciding whether the circumstances of that particular encounter justify it. These are not always dramatic errors. That is part of the problem.

When the same documentation habit or coding shortcut is repeated week after week, an isolated weakness can turn into a larger compliance concern.

Periodic chart-to-claim reviews can help uncover those patterns. Instead of asking only whether the claim was paid, the reviewer looks at whether the claim accurately reflects the record and whether the documentation is strong enough to support what was billed.

Some Claim Errors Have Nothing to Do with Complex Coding

Not every denied or rejected claim involves a difficult coding question. Sometimes the problem is a wrong date, an outdated insurance record, missing provider information, an incorrect subscriber ID, or a claim field that was left incomplete. These errors may sound minor, but they still consume staff time and slow down payment.

Electronic claims generally pass through automated edits during processing. Certain missing or inconsistent details can cause the claim to stop before it gets very far.

A short review before submission can catch many of those problems. Staff may want to verify:

  1. Patient and subscriber information.
  2. Current insurance coverage and coordination of benefits.
  3. Provider and practice identifiers.
  4. Diagnosis codes, procedure codes, and modifiers.
  5. Documentation supporting the billed service.
  6. Required authorization or referral information.
  7. Payer-specific claim requirements and missing fields.

The review does not have to turn into a lengthy approval process for every claim. What matters is that the practice has a reliable way to catch repeatable errors before the payer does.

Eligibility Deserves More Attention in OB/GYN Billing

Insurance information can change during the course of care, and OB/GYN practices are especially likely to encounter that issue because many patients receive services over an extended period.

Pregnancy is an obvious example. A patient may have one insurance plan early in the pregnancy and another later. Employment can change. A spouse's coverage can change. Coordination of benefits may need to be updated. Authorization rules may also be different under the new plan. If staff rely on an eligibility check performed months earlier, the billing team may not find out about the change until a claim is denied.

Eligibility problems can affect more than reimbursement. They may also result in the wrong amount being assigned to the patient or create confusion about who is financially responsible for the service.

Checking coverage at appropriate points throughout treatment gives staff a chance to address those issues before the claim has already gone through the billing cycle. It also makes financial conversations with patients more accurate.

A Denial May Be Pointing to a Workflow Problem

Correcting a denied claim is necessary. Correcting the same type of denial twenty times should raise a different question - Why does it keep happening?

Suppose claims for a particular procedure regularly come back because information is missing. Billing staff can add the information and resubmit each claim, but that does not explain why the original claims were incomplete.

Maybe the registration team is not collecting something the payer requires. Perhaps the authorization information exists but is not being transferred correctly. It could also be that staff misunderstood a payer policy. The denial itself is only the visible part of the problem.

This is why useful denial management goes beyond counting how many claims were denied. Practices can look at which reasons occur most often, which payers are involved, whether one service keeps appearing, and where in the workflow the original error began.

That kind of review can reveal patterns that would otherwise remain hidden. The CMS Medical Review and Education resources also discuss claims analysis and medical record review in the context of identifying improper billing and documentation issues. For an OB/GYN practice, denial data can serve as a practical warning system. It shows where the revenue cycle is struggling, not just where payment was delayed.

Internal Audits Can Be Small and Still Be Useful

An internal audit does not have to involve hundreds of charts. A practice can learn a great deal from a carefully chosen sample.

Maybe one modifier has been causing questions. Perhaps a particular payer has denied an unusually high number of claims. There may be concerns about preventive visits, maternity billing, surgery, medical necessity documentation, or another service that carries more risk. Those claims can be reviewed against the medical record.

The reviewer may find that everything was handled appropriately. If not, the next step is to determine whether the problem was isolated or whether it reflects a larger habit. That distinction matters. One coding mistake made on a single claim may require a simple correction. Finding the same mistake across several providers or multiple dates of service suggests that the practice may need education, a workflow change, or closer monitoring. The audit should not end when the error is identified.

If a change is made, the practice needs some way to determine whether it worked. Reviewing another sample later can show whether the same problem is still appearing. Without follow-up, the practice has documented a problem but has not necessarily solved it.

Compliance Works Better When It Is Part of Routine Operations

A compliance process does not need to be complicated to be useful. In many practices, consistency matters more than creating a large set of policies that nobody uses. Staff should know how registration is handled, when eligibility is checked, how authorization information is recorded, how claims are reviewed, what happens when a denial arrives, and who is responsible for following up on recurring problems.

Those processes should not exist only in one employee's memory. Training matters for the same reason. Payer policies change. Coding guidance changes. Internal workflows change. New employees arrive, and experienced employees sometimes continue using a process that made sense under an older rule.

Regular education gives the practice a chance to catch those gaps.

Billing data can also help determine where training is needed. If eligibility denials suddenly increase, the first response should not necessarily be a general coding seminar. The practice may need to look at registration and verification instead. If several claims involving the same modifier are being questioned, a focused review of those encounters is probably more useful than retraining the entire staff on every coding topic. Compliance becomes easier to manage when the response matches the actual problem.

Documentation Reviews Should Include the Claim

A chart can look complete on its own while the corresponding claim still contains a problem.

The opposite is also possible. A claim may appear technically correct until someone compares it with the medical record.

Looking at both together usually provides a clearer picture. This is particularly important for services where the circumstances of the encounter affect billing. Preventive care, problem-oriented visits, procedures, maternity care, and postoperative services can all raise questions that cannot be answered by looking at a code alone.

The reviewer needs to understand what actually happened during the visit, what the provider documented, and how that information was translated into the claim.

Preparing for Billing Changes Before They Reach the Claims Department

One of the easiest ways for a billing problem to spread is for a rule to change while the practice keeps following the old process. Changes may affect coding, documentation, payer policies, reimbursement, or the way certain services are reported.

The first sign should not have to be a wave of denials.

When a significant change is announced, the practice can identify which services will be affected and who needs to know about it. Providers may need different documentation. Billing staff may need revised procedures. Software settings or claim edits may also need to be updated. Testing the new process early is usually easier than correcting a backlog later. This becomes especially important when changes affect maternity services because the care and billing may span several months.

The Bigger Compliance Question

A claim can be paid and still come from a weak process. That is why payment should not be the only measure of whether an OB/GYN billing operation is working well. A better question is whether the practice could explain and support the claim if someone reviewed it later.

  • Was the patient's coverage checked?
  • Does the chart support the service?
  • Does the code match what was documented?
  • Were payer requirements addressed?
  • If a similar problem appeared last month, was anything changed afterward?

Those questions bring compliance into the normal revenue-cycle process instead of treating it as something that matters only during an audit.

Most billing problems do not begin as major compliance failures. They usually start much smaller: an insurance detail that was not updated, documentation that was a little too vague, a modifier applied out of habit, or a denial that was corrected without asking why it happened.

The risk grows when the same issue becomes routine.

Finding those patterns early is what gives a practice the best chance to correct them before they affect more claims, more patients, or more revenue.

About the Author Noah Smith

This article is written by Noah Smith on behalf of BillingFreedom. Noah is a medical biller, SEO and Content Outreach Specialist.

Additional Resources

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Mitigating Compliance Risks in Genetic Testing Billing and Medical Necessity Claims

Written by: Ricky Bell 

Having spent a decade advising clinical laboratories and health systems on revenue cycle management, I can tell you that molecular diagnostics remains one of the most volatile operational areas in healthcare. Federal spending on genetic testing under Medicare Part B now sits above $3.6 billion every year. That rapid financial growth brought aggressive oversight from the U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) and the Department of Justice.

In the complex arena of medical billing, molecular diagnostic testing sits right in the crosshairs of federal auditors. Regulators no longer rely on random sampling. Instead, they deploy advanced data analytics to flag billing anomalies instantly. For compliance officers and practice managers, ensuring every claim meets strict coverage standards isn't just a recommendation—it is a survival strategy that lab executives cannot afford to sleep on. Rules change overnight. When billing protocols lack internal controls, financial penalties and False Claims Act liability follow quickly behind.


Where Labs Usually Get Burned

When reviewing Federal enforcement actions, one may find specific aspects of operations that lead to regulatory setbacks, including clawbacks and fines. For example, OIG has on multiple occasions published fraud alerts with the primary goal of targeting genetic testing practices and has pointed out that claims that result in financial penalties most often stem from major failure of the system's processes rather than from honest error.

Common High-Risk Testing Behaviors:

  • High-Risk Testing Behaviors.
  • Billing unbundled molecular CPT codes.
  • Bill a panel without a chart proof.
  • No signature by the doctor on the order.

Use of non-compliant lead-generation practices that may violate healthcare marketing regulations. Incorrect use of unlisted codes that relate to the genome.

Examine billing of multi-gene panels for cancer. Legal consequences come immediately when multi-gene hereditary cancer or pharmacogenomic panels are billed without showing the medical necessity of each individual gene target. Paying entities do not generally accept that a broadly screening panel is a medical necessity simply because a patient has a family history of disease. In addition, laboratory-marketing relationship set-ups frequently breach the Eliminating Kickbacks in Recovery Act (EKRA) and the Anti-Kickback Statute. When labs pay for marketing services in proportion to volume or claim value, they open themselves up to the possibility of being investigated by the Department of Justice, a common compliance issue that many lab managers face.

Navigating Medical Necessity and Coverage Controls

Defining medical necessity in genetics testing is really about finding a middle ground between clinical utility and coverage criteria determined by payers. An example is when a physician thinks a 50-gene panel is the ideal choice for giving the right diagnosis. Still, if the local coverage policy (LCD) lists just five genes as the only ones that are covered and the patient's condition is consistent with only these genes, then the doctor will be referring to the patient for the other testing that the insurance is not covering.

Maintaining billing compliance, organizations must master the requirements set by the Molecular Diagnostic Services (MolDX) program and commercial utilization management policies. Commercial payers and state Medicaid programs frequently diverge on prior authorization rules, creating administrative friction for billing staff. Truth is, what works for Medicare might fail completely with a commercial plan.

Key Operational Checks for Coverage:

  • Review local coverage rules monthly.
  • Get prior approval before testing.
  • Document clinical rationale in charts.
  • Verify specific CPT code coverage.
  • Check doctor order signatures daily.

A pre-test verification procedure is a compulsory setup. If a lab gets referrals from community physicians outside, it will be wrong to assume that the requesting provider already wrote medical necessity notes in their EMR. The lab on its own has to verify that clinical records back up the selected test panel before carrying out the test and presenting the charge. Not checking the chart papers exposes the lab to risks during an after-payment review of billing practices. So, you don't ever want to end up having that as your big error.

How to Build an Audit Framework That Works

To prevent improper payments, progressive health systems are moving away from passive retro-audits. Implementing an active Genetic Testing Stewardship Program (GTSP) provides a proven operational blueprint. For example, Nemours Children’s Health successfully curtailed unnecessary genetic testing orders by placing certified genetic counselors directly into the ordering workflow and embedding hard-stops in their Electronic Health Record (EHR) systems.

A solid internal audit framework evaluates claims both before submission and after payment. Health systems must establish routine internal controls that evaluate coding accuracy, physician intent, and documentation completeness.

Essential Audit Program Controls:

  • Add decision support in EHR.
  • Audit high-risk codes monthly.
  • Use genetic counselors as gatekeepers.
  • Track payer denial codes weekly.
  • Check fair market value rates.

Concurrently, compliance teams should conduct random quarterly audits on claims utilizing unlisted CPT® codes (such as CPT® 81479). Unlisted codes attract automatic payer scrutiny. If your team uses unlisted codes to bypass prior authorization or LCD restrictions, auditors will flag those claims for recoupment. Training billing personnel to double-check local coverage policies ensures that claims align precisely with current billing guidelines.

Real Exposure Under Federal Statutes

The risks linked to statutory non-compliance are not just limited to denial of claims.  Compliance risks related to molecular diagnostic services can have far-reaching consequences, including the imposition of heavy statutory penalties under the False Claims Act, Stark Law, and EKRA. Pursuant to the False Claims Act, if one submits claims for tests that do not have a documented medical necessity, this may result in the payment of triple damages plus the imposition of compulsory civil money penalties per claim.

Labs need to figure out as well, how they relate their working relationships, if any, with ordering physicians, and clinical consultants. It is a federal crime under anti-kickback laws to distribute free point-of-care testing devices, offer lavish consulting arrangements, or to provide generous collection fees to ordering clinics. Basically speaking, financial arrangements between you and a referrer should only be as much as the Fair Market Value (FMV) of the service actually done. Besides, having clear and complete documentation of FMV determinations and legal opinions is another defense measure that every lab board should definitely work on.

About the Author

Ricky Bell (https://www.dastifysolutions.com/team/rickybell/) is Head of Operations at Dastify Solutions, where he oversees healthcare operations, revenue cycle management, and compliance initiatives for physician practices, clinical laboratories, and healthcare organizations across the United States. With extensive experience in medical billing, coding compliance, denial management, and revenue cycle optimization, he helps healthcare providers strengthen operational efficiency while maintaining regulatory compliance.

Resources

  1. U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG): Fraud Alert: Genetic Testing Scam.
    https://oig.hhs.gov/fraud/consumer-alerts/fraud-alert-genetic-testing-scam/
  2. American Health Law Association (AHLA): Fraud and Abuse Issues in Diagnostic and Molecular Testing.
    https://www.healthlawyers.org
  3. Centers for Medicare & Medicaid Services (CMS): MolDX: Molecular Diagnostic Tests (LCD L35025).
    https://www.cms.gov/medicare-coverage-database/view/lcd.aspx?lcdid=35025
  4. Kaiser Family Foundation (KFF): Coverage of Breast Cancer Screening and Prevention Services.
    https://www.kff.org/womens-health-policy/coverage-of-breast-cancer-screening-and-prevention-services/
  5. National Center for Biotechnology Information (NCBI / PMC): The Genetic Testing Stewardship Program: A Bridge to Precision Diagnostics for the Non-genetics Medical Provider.
    https://pmc.ncbi.nlm.nih.gov/articles/PMC9124555/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Healthcare Revenue Cycle Compliance

Common Risks and How Practices Can Address Them 

Written by: Zara Ahmad 

A revenue cycle rarely breaks because of one dramatic mistake. More often, the problem begins with something ordinary: an insurance card was updated but the old plan stayed in the system, a provider’s note lacked enough detail for coding, or a denied claim was resubmitted before anyone checked the first one.

Compliance is not limited to the billing office. It starts when patient information is collected and continues through documentation, coding, claim submission, payment posting, denials, and follow-up.

Where Compliance Risks Can Enter the Revenue Cycle

Consider a routine office visit. The front desk enters the patient’s demographic and insurance information. If the member number is wrong, or the payer on file is outdated, the claim may already be inaccurate.

The next risk may appear in the medical record. A provider knows what happened during the visit, but a coder can only rely on what is documented. If a note is vague, staff should not fill in missing details from habit or assumption.

Charge capture creates another point of exposure. A service can be missed, entered twice, or attached to the wrong date. Later, a biller may resend a denied claim without confirming whether the original is still processing. Payment posting and accounts receivable follow-up can create problems too, especially when adjustments or corrections receive little review.

Common Revenue Cycle Compliance Risks

One familiar risk is a mismatch between the medical record and the claim. The service billed should be supported by the documentation. CMS guidance for Medicare makes documentation part of determining whether applicable coverage, coding, billing, and payment requirements are supported.

Incomplete documentation is often less obvious. A note may show that care occurred but still omit information needed to support a code, modifier, or service level. If that happens regularly, the issue is no longer just one troublesome claim.

Administrative mistakes matter as well. Incorrect patient details, insurance information, provider identifiers, and dates of service can cause denials and repeated corrections. Duplicate claims are another example. When payment is delayed, resubmitting the same claim may feel harmless, but claims-processing rules include duplicate edits.

Corrections need a consistent approach – contingent upon the payer and circumstances, the right step may be a corrected claim, replacement claim, appeal, or another defined process.

Why Documentation and Coding Accuracy Matter

Documentation, coding, and billing are different jobs, but they should describe the same encounter.

Suppose a coder returns the same type of note to the same provider several times each month because one detail is routinely missing. Correcting each claim solves the immediate problem, not the workflow problem.

A short, focused discussion with the provider may be more useful than another round of individual corrections. The aim is simply to make sure the record clearly reflects the service provided and gives coding staff the information they need.

Using Internal Audits to Identify Compliance Risks

Internal audits are most useful when they answer a specific question.

A manager might sample claims involving a frequently used modifier, one provider, a service with rising denials, or a payer that has generated repeated corrections. The review can compare claims with medical records, check key fields, examine adjustments, and see whether staff followed internal procedures.

Patterns often tell the real story. Several eligibility denials traced to the same registration step suggest a front-end workflow problem. Repeated coding questions may point to training or documentation habits instead.

An audit should lead somewhere. Someone needs to own the follow-up, record what changed, and later check whether the change helped.

Building a Stronger Compliance Culture

Compliance works better when people see how their own work affects the claim. Front-office staff influence patient and insurance information. Providers influence documentation. Coders and billers influence what reaches the payer. Managers decide whether recurring problems are investigated or simply worked around.

OIG’s General Compliance Program Guidance discusses written policies, education, communication, auditing and monitoring, and corrective action as parts of a compliance program. In everyday practice, those ideas are more useful when connected to real problems rather than treated as an annual checklist.

Training should follow the same principle. If an audit finds repeated modifier errors, train on that issue. If registration mistakes are driving denials, review that workflow with the people who perform it.

Practical Steps Healthcare Practices Can Take

  1. Review a representative sample of claims regularly.
  2. Compare billed codes with the supporting medical record.
  3. Track denials and claim corrections by reason.
  4. Review write-offs, refunds, adjustments, and claim changes for consistency.
  5. Use recurring errors to guide staff and provider education.
  6. Keep billing and compliance procedures current and easy to find.
  7. Document corrective actions and check whether they worked.
  8. Follow relevant CMS, OIG, and other authoritative guidance as requirements change.

Keeping Compliance Part of Everyday Work

No revenue cycle will be completely free of errors. What matters is what happens after a mistake is found. Comply with overpayment rules. Submit appropriate claims adjustments, credit balance reports, or self-reported refunds directly to your assigned Medicare contractor.

Investigate. Correct the affected account, but do not stop there. Ask where the error entered the process, why it was not caught earlier, and whether the same thing is happening elsewhere. That turns compliance from a periodic exercise into part of ordinary revenue cycle work. Over time, it can reduce avoidable rework, support more accurate billing, and leave a practice better prepared when claims are reviewed.

About the Author

Zara Ahmad is a healthcare industry professional and Marketing Team Lead at MedsIT Nexus, with a focus on healthcare revenue cycle management, healthcare operations, and industry education. Her work involves developing educational resources on healthcare administration, revenue cycle processes, and operational challenges affecting healthcare organizations.

Resources – obtain training in conducting internal audits and investigations from the American Institute of Healthcare Compliance, a Licensing/Certification partner w/CMS.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Why Every Healthcare Facility Needs a Smart Hospital Security System

Written by Peter Lee, MSc, CIPP/US and Arif Khan researcher specializing in AI-driven security systems and healthcare compliance

The information provided is for educational purposes only and is not legal, consulting or IT advice.

Introduction

Healthcare facilities operate in one of the most complex and high-risk environments of any industry. Hospitals are open 24/7, manage large volumes of patients and visitors, and handle sensitive data, controlled substances, and critical care operations all at the same time. This combination creates a unique set of security and compliance challenges that cannot be addressed with traditional systems alone.

The scale of the issue is significant. According to healthcare safety data, incidents involving workplace violence, unauthorized access, and theft are rising across hospitals and care facilities. In addition, regulatory requirements such as the Health Insurance Portability and Security Act (HIPAA) place strict obligations on how patient data and physical access must be controlled. Even a single breach can lead to severe financial penalties, legal consequences, and reputational damage, which is enforced by the Office of Civil Rights (OCR).

At the same time, many healthcare facilities still rely on outdated surveillance and access systems that are limited to recording events rather than actively preventing them. These systems often fail to provide real-time visibility, making it difficult for administrators and compliance officers to respond quickly when incidents occur.

This is why modern hospital security systems are becoming essential rather than optional. A smart security system does more than monitor activity. It integrates surveillance, access control, and intelligent alerts into a unified platform that helps healthcare organizations protect patients, staff, and sensitive information while maintaining compliance.

The Complexity of Healthcare Environments Demands Smarter Security

Unlike typical commercial spaces, hospitals are highly dynamic environments. Emergency departments, patient wards, pharmacies, operating rooms, and administrative offices all operate simultaneously, each with different levels of access and risk.

Managing security in such an environment requires more than basic surveillance. It requires systems that can adapt to constant movement and provide clear visibility across all areas.

For example, a visitor entering a general waiting area may be appropriate, but the same individual entering a restricted ICU or medication storage area presents a serious risk. Without intelligent monitoring, distinguishing between normal and suspicious activity becomes difficult.

Modern hospital security systems address this by combining video surveillance with access control and real-time monitoring. This allows healthcare administrators to not only control who can enter specific areas but also verify and track activity as it happens.

The result?  A more controlled and transparent environment, which is critical for both safety and compliance.

Protecting Patient Safety and Staff Well-Being

Patient safety is the top priority in any healthcare facility. However, safety risks are not limited to medical issues alone. Security incidents such as unauthorized access, aggressive behavior, or theft can directly impact patient care.

Healthcare workers are also at increased risk - Studies have shown that healthcare professionals face higher rates of workplace violence compared to many other industries. This makes it essential for hospitals to have systems in place that can detect and respond to potential threats quickly.

Smart hospital security systems help mitigate these risks by providing continuous monitoring and real-time alerts. For instance, if unusual activity is detected in a restricted area or if a situation begins to escalate in a waiting room, security teams can be notified immediately.

This ability to respond quickly can prevent incidents from escalating and ensures a safer environment for both patients and staff.

Supporting HIPAA Compliance and Data Protection

Compliance is a critical concern for healthcare organizations. Regulations such as the Health Insurance Portability and Accountability Act (HIPAA) require strict control over access to patient information and sensitive areas.

Physical security plays a major role in compliance. Unauthorized access to records rooms, server areas, or administrative offices can lead to data breaches, which carry significant legal and financial consequences.

A modern hospital security system supports compliance by providing controlled access, detailed activity logs, and audit trails. These features allow organizations to track who accessed specific areas and when, which is essential for audits and investigations. This integrated approach helps ensure that compliance requirements are met while improving overall operational efficiency.

Preventing Unauthorized Access to Critical Areas

Hospitals contain several high-risk zones that require strict access control. These include pharmacies, operating rooms, ICUs, data centers, and storage areas for medical equipment.

Unauthorized access to these areas can result in serious consequences, including theft of controlled substances, tampering with equipment, or exposure of sensitive information.

Traditional systems often rely on static access permissions, which can become outdated as roles change. This creates gaps where individuals may retain access they no longer need.

Smart hospital security systems address this issue by enabling dynamic access control. Permissions can be updated in real time, ensuring that access is always aligned with current roles and responsibilities.

In addition, integrating access control with video surveillance provides an added layer of verification. Administrators can not only see who accessed a door but also confirm the activity visually, reducing the risk of misuse.

Improving Incident Response and Emergency Management

In healthcare settings, response time is critical. Whether it is a security incident, a medical emergency, or an environmental issue, delays can have serious consequences.

Smart security systems improve response time by providing real-time alerts and centralized monitoring. Instead of relying on manual reporting, incidents can be detected automatically and communicated to the appropriate teams immediately.

For example, if an unauthorized entry occurs in a restricted area or if environmental sensors detect abnormal conditions, alerts can be triggered instantly. Security and medical teams can then coordinate their response more effectively.

This level of coordination is especially important in large facilities where multiple departments must work together during emergencies.

Enhancing Operational Efficiency

Beyond safety and compliance, hospital security systems also contribute to operational efficiency.

Manual processes such as maintaining access logs, issuing credentials, and monitoring multiple systems can be time-consuming and prone to errors. As healthcare facilities grow, these inefficiencies become more pronounced.

A centralized security system streamlines these processes by integrating surveillance, access control, and alerts into a single platform. This reduces administrative workload and allows staff to focus on patient care rather than managing systems.

Additionally, data collected from security systems can provide valuable insights into facility usage, helping administrators optimize workflows and resource allocation.

Adapting to Modern Healthcare Challenges

Healthcare is evolving rapidly, and security systems must evolve with it.

Facilities are expanding, patient volumes are increasing, and technology is becoming more integrated into daily operations. At the same time, threats are becoming more sophisticated, requiring a more proactive approach to security.

Smart hospital security systems are designed to adapt to these challenges. They provide scalability, allowing facilities to expand without overhauling their infrastructure. They also support integration with other systems, creating a unified approach to security and operations.

This adaptability is essential for healthcare organizations that want to remain secure and compliant in a constantly changing environment.

FAQs

What are hospital security systems?

  • Hospital security systems are integrated solutions that combine surveillance, access control, and monitoring tools to protect patients, staff, and sensitive areas within healthcare facilities.

Why are smart security systems important in hospitals?

  • They provide real-time monitoring, improve response times, and support compliance with healthcare regulations, making them more effective than traditional systems.

How do these systems support HIPAA compliance?

  • They control access to sensitive areas, maintain detailed logs, and provide audit trails that help meet regulatory requirements.

Can hospitals use existing infrastructure?

  • Yes. Many modern systems are designed to work with existing IP cameras and infrastructure, reducing the need for costly replacements.

Do these systems improve patient safety?

  • Yes. By detecting and responding to risks quickly, they help create a safer environment for patients and healthcare staff.

Conclusion

Healthcare facilities face unique challenges that require more than basic security measures. The combination of high patient volumes, sensitive data, and strict regulatory requirements makes security a critical component of daily operations.

Modern hospital security systems provide the intelligence, integration, and real-time visibility needed to address these challenges effectively. They help protect patients, support staff, ensure compliance, and improve overall efficiency.  Solutions like Coram demonstrate how this can be implemented effectively. Coram’s hospital security platform works with existing IP cameras and integrates with access control systems and environmental sensors. It provides high-definition video monitoring, intelligent alerts, and centralized management, allowing healthcare facilities to maintain visibility and control without replacing their current infrastructure.

As healthcare environments continue to evolve, investing in smarter security systems is not just a technological upgrade. It is a necessary step toward safer, more resilient, and compliant healthcare operations.

About the Authors

Arif Khan is a writer and researcher specializing in AI-driven security systems, healthcare compliance, and modern surveillance technologies. He holds a B.Tech degree in Computer Science and works as a freelance writer covering topics related to AI, physical security, access control, and intelligent monitoring systems. His work focuses on helping organizations understand emerging security technologies and their role in improving safety, compliance, and operational efficiency.

Peter Lee is a writer and researcher specializing in AI-driven security systems and healthcare compliance. His work focuses on topics such as hospital security, HIPAA requirements, and modern surveillance technologies, helping organizations understand and implement effective security solutions.

References

American Institute of Healthcare Compliance (AIHC)

National Library of Medicine (NLM)

Occupational Safety and Health Administration (OSHA)

U.S. Department of Health & Human Services (HHS)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Measuring Effectiveness of Your CDI Program

Mitigating Risk and Improving Quality of Care 

Co-authored by Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 

This paper outlines the basics related to key steps, metrics, and best practices for implementing an effective CDI audit program. The information below is for educational purposes only and not intended as consulting or legal advice.

Introduction

Clinical Documentation Improvement (CDI) is a vital process that ensures medical records are accurate, complete, and compliant, directly impacting patient care quality, severity-of-illness tracking, and reimbursement. As CDI departments mature, establishing a robust, routine auditing process—both internal and external—is essential to validate the accuracy of CDI staff queries, identify educational gaps for physicians, and ensure compliance with regulatory standards.

Effective CDI audits identify gaps in diagnostic specificity, medical necessity, and coding accuracy which must support documentation (like histories and exam findings), and appropriate, non-leading queries.

OIG Guidance and Regulatory Support for Your Audit

To control risk, your internal auditors will benefit from a clearer understanding of healthcare compliance guidance, statutory and regulatory provisions that are related to CMS reimbursement.   The HHS Office of Inspector General’s (OIG) General Compliance Program Guidance (2023) calls for a proactive approach that emphasizes preventing errors rather than relying on post-submission rationalizations. The OIG guidance implicates several key documentation safeguards:  documentation must accurately reflect the services provided; patient records must be unique to the specific clinical encounter documented; and an effective risk mitigation playbook should address systemic documentation errors before they lead to overpayment demands or other matters. 

Grounded in statutory frameworks, Title XVIII of the Social Security Act sets forth a principle of “no documentation, no payment.”  All diagnostic and therapeutic interventions must meet the “reasonable and necessary” standard.  Medical records that provide insufficient information to justify the conditions for CMS payment could result in claim denials or a subsequent recoupment of funds.

Checklist for Clinical Documentation Improvement Audits

A CDI audit is a structured review designed to measure the effectiveness of the CDI program in capturing the full clinical picture of a patient. It serves as a check-and-balance system, evaluating not only the accuracy of coding but also the appropriateness of queries sent to providers.  A CDI audit also ensures that the medical record reflects real-time clinical practices rather than functioning as a retrospective cost justification.

The process involves a continuous, four-stage cycle which should have a Lead Auditor to guide the team to: 1) Prepare and plan (set goals), 2) Execute – collect and analyze records, validate findings, 3) Report audit findings 4) Provide education to implement change, and re-audit to ensure changes are sustained.

1.  Preparing for the Audit
     Success in auditing requires careful planning and preparation.

  • Define Scope and Goals: Identify specific areas of focus, such as high-risk diagnoses (e.g., sepsis), high-volume, or high-cost areas.
  • Select Samples: Utilize a representative sample of records, including those with queries and those without, to assess both CDI activity and documentation gaps.
  • Determine Audit Frequency: Establish a regular schedule (e.g., monthly or quarterly).
  • Identify Reviewers: Use a mix of internal staff for ongoing monitoring and external auditors for unbiased, independent assessments.

2.  Execute the Audit
     An effective CDI audit follows a standard quality improvement cycle (Plan, Do, Study, Act):

  • Data Collection
    Use random sampling of patient records to get a representative view or targeted sampling for specific providers or types of documentation. Reviewers gather patient records, specifically examining:
    • Specificity to ensure documentation is accurate, thorough, and detailed.
    • Medical necessity - Confirm that the documentation justifies the care provided.
    • The principal diagnosis assigned.
    • Secondary diagnoses (comorbidities and complications).
    • Present on Admission (POA) indicators.
    • Query compliance, ensuring queries are evidence-based and not leading, with best practices focused on clarifying ambiguities in the medical record
  • Analysis and Validation 
    Auditors compare the documentation against evidence-based standards. Key questions include:
    • Did the documentation support the queried diagnosis through objective clinical indicators, e.g., vitals, labs, treatment?
    • Was the query necessary, or was the information already in the record?
    • Are there missed opportunities where documentation was insufficient?

3.  Reporting Audit Findings
     Audit findings should be reported through actionable metrics.

  • Query response rates and agreement percentages. Report if providers respond to queries and if those queries improve the record.
  • DRG shifts (change in Diagnosis Related Group).
  • Denial reduction rates.

4.  Provide Education to Implement Change
    The results are used to provide targeted feedback to clinicians and CDI staff.

  • Develop educational sessions based on recurring documentation gaps (e.g., chronic condition management).
  • Update templates and checklists for improved accuracy.
  • Re-audit to ensure improvements are sustained.

Key Metrics/Key Performance Indicators (KPIs) to Audit

To measure the success of a CDI program, organizations should track specific key performance indicators (KPIs):

CDI KPI

Conclusion 

Best practices for successful CDI audits involve the providers. After all – it is their documentation being audited! Ensure the CDI team creates processes that minimize administrative burden.

Leverage technology and streamline the audit process by using computer-assisted coding (CAC) and AI-powered analytics to scan for gaps and prioritize reviews. Ensure documentation is accurate across all patient encounters, not just for higher reimbursement.

Share feedback. Collaborate with the coding and billing departments to ensure documentation aligns with ICD-10/CPT guidelines. Create a closed feedback loop where findings are shared with clinicians and coders for ongoing training.

Remember, auditing for CDI is a continuous cycle of improvement, moving beyond simply chasing revenue to establishing a sustainable, compliant, and accurate record-keeping process. By focusing on regular reviews, actionable metrics, and ongoing education, organizations can improve the quality of clinical documentation, leading to better patient care and optimal financial outcomes.

About the Authors

Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC, is a member of the AIHC Volunteer Education Committee. Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS, is the Chief Executive Officer at the American Institute of Healthcare Compliance.

References 

American Institute of Healthcare Compliance

National Library of Medicine

Office of Inspector General, U.S. Department of Health and Human Services. (2023). General Compliance Program Guidance.

Social Security Act § 1815(a), 42 U.S.C. § 1395g(a)

Social Security Act § 1862(a)(1)(A), 42 U.S.C. § 1395y(a)(1)(A)

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Auditing and Standard Deviation

The Importance of Statistical Significance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of standard deviation when Auditing for Compliance and quality standards. It is not intended as being comprehensive, legal or consulting advice. You may be interested in other auditing articles – click here. 

Introduction

In an increasingly data-driven corporate healthcare environment, auditing has moved beyond traditional spot-checking to advanced analytics. Standard deviation, a statistical measure of dispersion, has become an essential tool for auditors to assess risk and operational performance. By quantifying how data points, such as transaction amounts, process times, or product quality metrics deviate from the mean, auditors can identify anomalies, measure volatility, and evaluate the consistency of operational processes.

This paper explores how standard deviation helps audit financial risk by identifying outliers and market volatility, and how it improves operational efficiency by highlighting process variations.

Why Standard Deviation (SD) is Vital

In simpler terms, standard deviation measures the variation in the data. A higher variance requires a larger sample size to achieve statistical significance. It represents the average amount of variation or dispersion of data points from the mean.

Standard deviation is another measure of dispersion that complements variance. Standard deviation indicates how spread out the data points are in relation to the mean. Just like variance, standard deviation helps us understand the consistency and reliability of the data.

  • SD helps to identify outliers and anomalies. Auditors use standard deviation to pinpoint unusual data points that fall far from the mean to flag potential fraud, waste, billing errors, patient waiting times and quality measures.
  • SD is used to assess consistency. In auditing, a small standard deviation indicates consistent performance, while a high one suggests unreliable processes or high variability.
  • Calculating SD is vital when used in evaluating treatment/clinical variation. It helps determine if outcomes are consistent across a population. High standard deviation in medical data indicates inconsistent patient responses, which may signal a need for audits on clinical quality.

Understanding Risk and Performance

Financial risk management requires understanding volatility and uncertainty. Standard deviation serves as a proxy for this risk, helping auditors and financial analysts determine the potential for loss or unpredictability.

Auditors are tasked with providing assurance on financial statements and improving business processes. While averages (means) provide a central reference point, they often disguise underlying inconsistencies or high-risk outliers.

Standard deviation (SD) is essential because it measures the spread of data; a small standard deviation indicates consistency, while a high standard deviation indicates high variability. For auditors, this variability is synonymous with risk and potential inefficiency.

It is essential for auditing financial risk and operational efficiency because it permits auditors to see if "average" performance is due to uniform, acceptable results, or a mix of excellent and failing results.

Standard deviation is particularly useful for auditors due to its specific mathematical properties:

  • Sensitivity to Outliers: Because standard deviation squares the variance, it heavily impacts outliers, making it an effective tool for surfacing extreme cases.
  • Comparability (Scale Invariance): Auditors can directly compare the volatility of different datasets, even if they are in different units, allowing for comprehensive risk assessment across diverse business units.
  • The Normal Curve (Bell Curve): In a normal distribution, roughly 68% of data falls within one SD, 95% within two, and 99.7% within three. Auditors can use these intervals to define "normal" transactions and immediately identify the 5% that are outliers.

While powerful, standard deviation has limitations that auditors must recognize:

  • Assumes Normal Distribution: It works best with normal, bell-shaped curves. If data is heavily skewed or has fat tails, standard deviation might underestimate tail risk (rare but extreme events).
  • Backward-Looking: It is based on historical data, which may not repeat in the future.
  • Treats Volatility Equally: It treats positive and negative deviations equally, whereas auditors are primarily concerned with downside risk.

Steps to Calculate Sample Standard Deviation (SD)

Calculating standard deviation for a health care audit measures how much individual data points (e.g., patient wait times, billing errors) differ from the average, showing consistency in care. To calculate, find the average (mean), calculate each data point’s distance from the mean, square them, average those squares, and find the square root.

1.  Calculate the Mean

  • This is calculating the average by adding all audit data points and then dividing by the total number of items.

2.  Calculate Deviations

  • Subtract the mean from each individual data point.

3.  Square the Deviations

  • Square each result from step 2 to remove negative values.

4.  Sum of Squares

  • Add all squared values together.

5.  Calculate Variance

  • Divide the sum of squares (sample size minus one).

6.  Calculate Standard Deviation

  • Take the square root of the variance.
Square Root Formula

 σ is the standard deviation, xi is each individual data point in the set, µ is the mean, and N is the total number of data points. In the equation, xi, represents each individual data point. The results are then summed (symbolized as Σ), which is the numerator of the fraction from the equation.

Example: Audit of Patient Wait Times (Minutes)

Data (patient wait times): 10, 15, 20, 25, 30

Mean is 20:         (10 + 15 + 20 + 25 + 30) ÷ 5 = 100 ÷ 5 = 20

1.  Deviations:

  • 10 - 20 = -10
  • 15 - 20 = -5
  • 20 - 20 = 0
  • 25 - 20 = 5
  • 30 - 20 = 10

2.  Squared Deviations:

  • (-10)2 = 100
  • (-5)2 = 25
  • (0)2 = 0
  • (5)2 = 25
  • (10)2 = 100

3.  Sum of Squares: 100 + 25 + 0 + 25 + 100 = 250

4.  Variance: 250 ÷ (5 - 1) = 250 ÷ 4 = 62.5

5.  Standard Deviation: 62.5 ~ 7.90569 (round to 7.91)

6.  Audit Conclusion: The average wait time is 20 minutes with a standard deviation of 7.91 minutes

Conclusion

Understanding the significance of standard deviation is essential for modern auditing. It allows auditors to shift from a focus on the average to a focus on the variation. By providing a clear, quantified metric for variability, standard deviation allows auditors to quickly pinpoint financial risks and compliance issues that require investigation. Used alongside other audit tools, it ensures that companies can better manage risk, maintain control over processes, and optimize performance.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

National Library of Medicine

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

The Importance of Statistical Significance

Auditing for Compliance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of audit sampling used when Auditing for Compliance, specifically chart or billing audits. It is not intended as being comprehensive, legal, or consulting advice.

Introduction

A statistically significant chart audit in healthcare is a structured, randomized review of medical records designed to project findings onto an entire population of claims (the "universe") with measurable reliability.

The Office of Inspector General (OIG) states these audits be random, unbiased, and sufficiently large to be representative of the population. A common misconception is that a fixed percentage (e.g., 10%) of charts is always sufficient. The OIG does not set a fixed percentage. The sample size must be large enough to provide a reliable estimate of the universe's overpayment amount. A statistically significant chart audit, compliant with OIG guidelines, is a scientifically rigorous process.

In healthcare, audit sampling is crucial when auditing the entire population (100% of claims) is impractical due to high volume. A "statistically valid" sample differs from a simple "probe" or arbitrary sample (e.g., 10 charts) because it allows for the projection of error rates onto the larger population. A statistically valid sample is necessary for:

  • Provider Self-Disclosure Protocol: Submitting self-audits to the OIG.
  • Corporate Integrity Agreements (CIAs): Mandatory compliance for providers under investigation.
  • External Audits: Rebutting audits from Unified Program Integrity Contractors (UPICs) or Medicare Administrative Contractors (MACs).

Even your routine audits should be grounded as statistically significant, which is fundamental when auditing a healthcare organization for compliance. Taking this approach transforms subjective chart reviews into defensible, objective, and scalable evidence that can be used to prove compliance. government agencies.

Statistical significance provides the necessary confidence, typically 90% or higher, that findings from a small sample accurately represent the entire population, minimizing the risk of false positives. Experts often check if the auditor used an appropriate one-sided 90% confidence level, which is a common standard in these audits.

The confidence level defines how often the true population value (e.g., total overpayment) falls within the range calculated from the sample. The precision (Margin of Error) defines the range of accuracy around the point estimate (e.g., +/- $10,000). The trade-off is a higher confidence level (e.g., 99%) which usually requires a wider range of precision, or a significantly higher sample size to maintain precision.

Legal and Regulatory Defensibility

  • Mandatory for Extrapolation - Government contractors, such as Recovery Audit Contractors (RACs), Unified Program Integrity Contractors (UPICs) and Department of Health and Human Services (HHS) Office of Inspector General (OIG) Office of Audit Services, require statistical sampling for projecting overpayment amounts. If an audit lacks statistical significance, it cannot be legally extrapolated to the total claim population.
  • Rebuttal of Audit Findings - Organizations can use statistical expert testimony to challenge improper sampling methods used by auditors, as flawed sampling often leads to inflated repayment demands. Core areas challenged by experts are:
    • Improper Audit Universe/Frame: Auditors may fail to define the correct population of claims, including irrelevant claims or excluding relevant, paid-in-full claims that would balance the error rate.
    • Lack of Randomization/Bias: Experts look for patterns showing the sample was not truly random, such as a sample mean paid amount dramatically higher than the universe mean, indicating a biased selection.
    • Failure to Account for Underpayments: A common, frequently successfully challenged error is the failure of auditors to include underpayments, which skews the audit and "significantly" overstates the overpayment.
    • Imprecise Extrapolation: Even if a sample is random, it may be too small or produce a wide confidence interval (high imprecision), making the projection highly unreliable.
    • Failure to Replicate: Government auditors often fail to document their work sufficiently, making it impossible to reproduce the sample or calculations.
  • Lower Bound Calculation - Statistical methods (like Rat-Stats) calculate the lower limit of a 90% confidence interval, ensuring that recoupment amounts are statistically defensible and conservative.
    • OIG RAT-STATS is a free statistical software package created by the Office of Inspector General (OIG) that provides a "rock-solid," defensible foundation for auditing healthcare claims. It is used to generate random samples, determine sample sizes, and extrapolate error rates to entire populations. It is widely used by auditors, and often by providers in corporate integrity agreements.
    • While RAT-STATS is user-friendly, it requires a thorough understanding of statistics and the software itself to use it properly and to challenge, if necessary, the findings of an audit.

Ensuring Accuracy in Large Datasets

Statistical tools calculate the minimum required sample size (often at least 30 but higher depending on variance) to ensure that the audit has enough power to detect errors without wasting resources on excessive, manual review.

It is important to mitigate potential bias. Statistical sampling prevents "judgmental sampling," where auditors might only select high-dollar or potentially erroneous claims, which would falsely inflate the error rate. To achieve this, we need to address the confidence interval.

Key Components of an Audit Confidence Interval

We strive to reduce "false positives." A 95% confidence level indicates that there is only a 5% chance that observed deviations in documentation or billing were due to random chance, rather than a systematic compliance failure. Let’s dive a little deeper into the confidence level and margins of error.

  • A confidence level (e.g., 95%) is the reliability of the sampling method. A 95% confidence level means that if the audit were repeated 100 times, 95 of the resulting intervals would contain the true population value. Applying a 90% confidence level is a common requirement for CMS contractors to use as a basis for extrapolation.
  • Precision refers to the margin of error or the width of the interval. A tighter (narrower) interval means more precise results, often requiring a larger sample size. Larger samples shrink the confidence interval, providing higher precision. A higher confidence level (e.g., 99% instead of 95%) makes the interval wider (less precise) because you are trying to be more certain.
  • Upper/Lower Limits are the boundaries of the interval, providing the "best-case" and "worst-case" scenario for errors. In healthcare audits, particularly those involving billing compliance, overpayment extrapolation, and quality of care, upper and lower limits define the range of plausible values for a population parameter (such as total overpayment) with a set level of confidence (typically 90% or 95%).
    • Lower Limit (LL): The lowest expected value of the confidence interval. In many CMS audits, the lower limit of a one-sided 90% confidence interval is used to determine the minimum amount of overpayment to be recouped.
    • Upper Limit (UL): The highest expected value of the confidence interval. It represents the worst-case scenario for error rates.
    • Confidence Interval (CI): The full range between the Lower and Upper Limit. A narrower interval indicates higher precision.

Key Statistical Concepts for Auditors

Confidence Levels: The percentage of times (e.g., 90% or 95%) that the true value of an error is expected to fall within the calculated confidence interval.

Null Hypothesis (H0): The assumption that there is no meaningful difference between the audited sample and the expected (compliant) standard.

P-Value: The probability that results were produced by chance. A low p-value (typically $p<0.05$) allows the auditor to reject the null hypothesis and conclude a real, significant error pattern exists.

Randomized & Unbiased: Every claim in the universe must have an equal chance of selection.

Representative: The sample must reflect the characteristics of the entire population.

Standard Deviation: Measures the variation in the data; higher variance in claims requires a larger sample size to achieve statistical significance.

Statistically Valid & Replicable: Another auditor using the same methodology should arrive at similar results.

Universe Definition: The specific time period, the provider, and types of claims being audited (CPT code range 99212-99215 from Jan-Dec 2025).

Limitations to Consider

  • Not Always Meaningful: A statistically significant result (due to a large sample size) does not always mean the error is clinically or financially important.
  • Small Populations: When auditing small departments, high variation may lead to non-significant results, even if errors are present.
  • Requires Expertise: Misapplication of statistical formulas can create misleading conclusions; statistical literacy is crucial for compliance officers.

General Rules of Thumb - When full statistical calculation is not possible, industry guidelines offer the following benchmarks:

  • Small Populations (<100): Audit all records (100% sampling).
  • Large Populations: 10% of the total eligible charts, up to a maximum of 1000, is often sufficient.
  • Rapid Cycle Sampling: Small, consecutive samples (e.g., 5-10 charts) can be used to track changes over time in quality improvement projects and for monitoring purposes.

Conclusion

It’s all about measuring the effectiveness of your compliance program

The effectiveness of the compliance program must identify high-risk patterns. Organizations use statistical significance to track if voluntary changes to coding or billing procedures resulted in significant, measurable reductions in error rates. Taking this approach allows the organization to determine if corrective actions, such as training, efforts to correct Electronic Health Record systems, conducting pre-billing targeted audits, etc. are making the expected improvements required for compliance.

Statistical techniques allow internal auditors to identify trends in data, such as high-frequency billing of complex codes, which indicate potential risk for future external audits.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

CDC

National Library of Medicine

Strategic Management Services

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
Corporate Compliance, HIPAA

The Hidden Risk in Multi Site Healthcare

When Visibility Fails, Compliance Follows 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

This article is for reference regarding risk management in healthcare, which is a complex topic and posted for educational purposes only. It is not intended as consulting or legal advice.

Introduction

Managing multiple healthcare facilities within a single organization has evolved from an operational responsibility to a complex enterprise risk function. As organizations expand across regions, states, and service lines, the ability to maintain consistent compliance, ensure patient safety, and protect financial performance becomes increasingly difficult without structured oversight.

For compliance and risk leaders, multi-site operations present a unique challenge. The risk is not limited to regulatory requirements or operational variability. The greatest risk is the loss of visibility. When leadership cannot clearly see what is occurring across sites in real time, issues are often identified only after they have already impacted patient care, compliance status, or revenue.

Recent federal guidance and national studies reinforce that multi-site risk is driven less by geographic dispersion and more by the absence of standardized oversight, integrated data, and structured accountability.¹ To manage multi-site healthcare environments effectively, organizations must move beyond decentralized oversight and adopt systems that promote accountability, visibility, and coordinated enterprise governance. Without these elements, growth introduces fragmentation rather than scalability.

The Risk Profile of Multi Site Healthcare Organizations

Multi-site healthcare organizations operate within a heightened risk environment driven by scale, variability, and complexity. While these risks are often described broadly, they consistently concentrate on specific operational and compliance areas that require targeted oversight. A primary risk is inconsistent application of regulatory requirements. Organizations governed by entities such as the Centers for Medicare & Medicaid Services and the Health Resources and Services Administration must ensure that standards related to documentation, billing, scope of services, and program integrity are applied uniformly across all locations. Variability in interpretation or execution increases the likelihood of audit findings, repayment exposure, and regulatory scrutiny.

Operational fragmentation is another critical concern. When sites operate with varying processes, undocumented workarounds, or informal practices, organizations lose the ability to ensure consistency and control. Over time, these inconsistencies evolve into systemic risk. Data fragmentation further compounds this issue. Without integrated systems, leadership lacks a reliable, centralized source of truth. This limits the organization’s ability to identify trends, monitor performance, and detect emerging risks before they escalate. Workforce variability also contributes to risk exposure. Differences in training, leadership capability, and staffing stability across sites directly affect compliance adherence, documentation quality, and patient safety outcomes.

Recent patient safety research demonstrates that breakdowns in communication, leadership engagement, and reporting culture are directly associated with lower safety performance and reduced incident reporting across healthcare organizations.²  In multi-site environments, these risks are amplified when leadership relies on inconsistent or anecdotal reporting rather than standardized enterprise data. Finally, delayed escalation of issues remains a persistent vulnerability. Without clear reporting structures and accountability, compliance concerns, incidents, and near misses may remain localized rather than addressed at the enterprise level.

High Risk Areas and Required Compliance Controls

Effective organizations do not manage multi-site risk at a high-level. They identify specific exposure areas and implement structured controls tied directly to those risks.

Documentation, Coding, and Billing Integrity - Variability in documentation and coding practices is one of the most significant sources of compliance exposure. Even with established policies, differences in provider behavior and oversight result in inconsistent application of requirements. Common risk patterns include insufficient documentation to support medical necessity, inconsistent use of modifiers, and failure to accurately capture services rendered. Across multiple sites, these inconsistencies increase audit vulnerability and repayment risk.

Administrative complexity and reliance on inconsistent workflows further increase risk and inefficiency across organizations. To mitigate this risk, organizations should implement centralized revenue integrity oversight, supported by routine pre and post billing audits. Documentation standards must be clearly defined and reinforced through targeted education tied directly to audit findings. Coding accuracy should be monitored through both random and focused audits, particularly in high-risk service lines. Transparent reporting of audit results reinforces accountability at both the provider and site level.

Sliding Fee Scale and Program Eligibility - For federally funded organizations, sliding fee scale compliance remains a critical risk area. Inconsistent eligibility determinations, failure to conduct required reevaluations, and inadequate documentation create exposure during audits and operational site visits. Organizations should implement standardized eligibility workflows supported by system controls that prevent incomplete processing. Routine audits should validate both documentation and application of discounts. Staff responsible for eligibility should receive structured training with defined competency expectations, and monitoring should include both process adherence and outcome accuracy.

Credentialing, Licensure, and Enrollment - Maintaining accurate credentialing and enrollment across multiple sites is operationally complex and highly regulated. Risks include expired licenses, services rendered prior to enrollment approval, and misalignment between credentialing records and payer systems. National credentialing standards emphasize ongoing monitoring, sanction checks, and oversight of delegated credentialing activities, particularly in multi-state environments.³

Centralized credentialing systems with automated alerts are essential. Organizations should maintain a single, validated source of provider data that is routinely reconciled with payer enrollment records. Pre-service verification processes should confirm that providers are eligible to render services. Routine audits should ensure alignment across credentialing, privileging, and enrollment data.

Patient Safety and Incident Reporting - Inconsistent reporting of incidents and near misses across sites creates significant patient safety and compliance risk. When reporting varies by location, organizations lose the ability to identify systemic issues. Recent studies highlight that organizations with stronger reporting cultures and leadership engagement demonstrate improved safety outcomes and increased event reporting.²

Centralized incident reporting systems should be implemented across all sites, with clearly defined expectations for reporting. Leadership must reinforce a culture that supports transparency and non-punitive reporting. Data should be trended at the enterprise level, and corrective actions should be tracked to completion. Regular leadership review ensures accountability and sustained improvement.

Data Integrity and Reporting - Reliable data is essential for effective oversight. In multi-site environments, inconsistent data definitions, delayed reporting, and lack of validation undermine decision making. Organizations should establish formal data governance structures that define standards, ownership, and validation processes. Standardized dashboards should be implemented across sites to ensure consistency in reporting. Data should be routinely reconciled across systems, and key risk indicators should be monitored consistently. Research indicates that dashboards are most effective when designed to drive action rather than simply display information.⁶

Workforce Competency and Training - Variability in workforce training directly impacts compliance and operational performance. Inconsistent onboarding, lack of role specific education, and high turnover create gaps in knowledge and execution. Standardized onboarding programs with defined competencies should be implemented across all sites. Ongoing training should be required and tracked, with reinforcement tied to identified risk areas. Competency should be validated through assessments and audit results to ensure effective application.

Vendor and Third-Party Oversight - Reliance on third party vendors introduces additional compliance and operational risk. Lack of visibility into vendor practices and misalignment with regulatory requirements can create exposure. Organizations should implement formal vendor risk management programs that include due diligence, clear contractual expectations, and ongoing performance monitoring. Vendors should be evaluated against defined compliance standards and subject to periodic audits. Contracts should clearly define accountability and regulatory obligations.

Enterprise Visibility and Remote Oversight

The most significant risk in multi-site operations is not complexity but lack of visibility. In organizations where leadership is remote or geographically dispersed, reliance on informal updates creates delayed awareness of risk. Federal compliance guidance emphasizes structured oversight, including risk assessments, auditing, monitoring, and board level reporting.¹ Organizations should establish a single enterprise view of risk that includes credentialing status, billing trends, patient safety events, training compliance, and corrective action tracking. Visibility must be standardized, real time, and actionable.

Accountability as an Enterprise Expectation - Accountability must be clearly defined and embedded at every level of the organization. Each site should have designated leadership responsible for compliance, quality, and operational performance, with measurable expectations aligned to enterprise standards. Research demonstrates that leadership structure and accountability directly influence safety culture, communication, and organizational performance. ⁵ Performance management should incorporate compliance metrics alongside operational goals. Enterprise leadership must maintain oversight through routine review of site performance, clear escalation pathways, and enforcement of corrective actions.

Systems, Monitoring, and Enterprise Oversight - Systems function as the infrastructure that supports compliance and risk management across multiple sites. Centralized platforms for audit tracking, incident reporting, credentialing, and performance monitoring provide the foundation for effective oversight. Monitoring should be continuous and risk based. Routine audits, data validation, and trend analysis allow organizations to identify patterns across sites and intervene proactively. Early warning indicators should be established to trigger action before risks escalate. Effective oversight requires translating data into action through structured governance and consistent follow through.

Addressing Blind Spots Through Validation and Culture

Blind spots represent one of the most significant risks in multi-site environments. These include underreported incidents, undocumented workarounds, and gaps in training that are not captured through standard reporting. Organizations must validate reported data through independent audits, direct observation, and cross site comparison. Identifying outliers often reveals underlying risk. Equally important is fostering a culture of transparency. Staff must feel supported in reporting concerns, and leadership must respond consistently to reinforce trust in reporting mechanisms.

Supporting Organizational Growth While Managing Risk

Growth must be supported by infrastructure and oversight. Research suggests that organizations that standardize core processes before expansion achieve more sustainable outcomes. ⁷ Organizations should ensure that systems, processes, and staffing models are scalable prior to expansion. Centralized governance should remain intact while allowing for controlled local execution. Data driven decision making should guide expansion, resource allocation, and performance improvement.

Conclusion

Managing multiple healthcare facilities requires a structured and deliberate approach to risk, compliance, and operational oversight. Multi-site environments introduce significant exposure across regulatory, clinical, operational, and financial domains. Across federal guidance and recent healthcare research, a consistent theme emerges. Multi-site success is driven by standardized visibility, structured accountability, integrated compliance controls, and proactive monitoring.¹ ² ³

Organizations that succeed invest in visibility, enforce accountability, and implement integrated systems that allow leadership to monitor performance in real time. By identifying specific risk areas and implementing targeted controls, organizations can reduce compliance exposure, strengthen patient safety, and support sustainable growth. In multi-site healthcare operations, risk is not created by scale alone. It is created by the absence of structure. Visibility, accountability, and systems remain the foundation of effective governance and long-term success.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Ms. Bertholette Pardieu, MPH, CCEP, OHCC is an accomplished compliance and risk leader with over a decade of experience developing and strengthening enterprise-wide compliance, governance, and risk programs across highly regulated healthcare sectors, including FQHCs, PBMs, and Medicare/Medicaid organizations. She currently serves as the Director of Risk Management & Corporate Compliance Officer for Broward Community & Family Health Centers, Inc. (the largest Federally Qualified Health Center in Broward County), overseeing risk, compliance and governance for a $16.4M multi-site FQHC system serving more than 13,000 patients. Previously, she led enterprise compliance risk initiatives at Convey Health Solutions, where she built the company’s first compliance risk program, directed effectiveness audits, and enhanced vendor oversight for national health plans.

A trusted advisor to executives and boards, Ms. Pardieu is known for her strategic mindset, collaborative leadership, and ability to embed compliance into organizational culture to protect against regulatory and operational risk. She holds a Master of Public Health from Florida International University and a Bachelor of Science from Barry University. Ms. Pardieu is a Certified Healthcare Compliance Officer (OHCC), with additional credentials including certifications in Corporate Compliance & Ethics and Healthcare Risk Management; and is a recent graduate of the Women’s Executive Leadership Accelerator Program through the Inclusion Learning Lab.

References

1. U.S. Department of Health and Human Services, Office of Inspector General
    General Compliance Program Guidance (2023)
    * Direct PDF (Full Guidance):
      
https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf
    * Official OIG Overview Page:
      
https://oig.hhs.gov/compliance/general-compliance-program-guidance/
2. Agency for Healthcare Research and Quality (AHRQ)
    Patient Safety Culture and Workforce Safety
    * 
https://psnet.ahrq.gov/perspective/ensuring-patient-and-workforce-safety-culture-healthcare
3. National Committee for Quality Assurance (NCQA)
    Credentialing Standards
    * 
https://www.ncqa.org/programs/health-plans/credentialing/benefits-support/standards/
4. Council for Affordable Quality Healthcare (CAQH)
    2023 CAQH Index Report
    * 
https://www.caqh.org/hubfs/43908627/drupal/2024-01/2023_CAQH_Index_Report.pdf
5. National Library of Medicine (PubMed)
    Leadership and Patient Safety Culture Systematic Review
    * 
https://pubmed.ncbi.nlm.nih.gov/41507881/
6. Journal of the American Medical Informatics Association (JAMIA Open)
    Healthcare Dashboard Effectiveness Study
    * 
https://academic.oup.com/jamiaopen/article/8/4/ooaf078/8214040
7. National Institutes of Health (PubMed Central)
    Healthcare Leadership Complexity and System Growth
    * 
https://pmc.ncbi.nlm.nih.gov/articles/PMC11223336/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More