Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Common Compliance Risks in OB/GYN Medical Billing and How to Address Them

Written by Noah Smith for BillingFreedom

The article will help healthcare professionals identify common compliance risks that can arise in OB-GYN medical billing and understand practical approaches for addressing those risks through accurate documentation, coding, claim review, internal audits, and consistent billing workflows.

OB/GYN billing can get complicated quickly. During the same week, a practice may bill for preventive visits, ultrasounds, office procedures, prenatal care, surgery, delivery services, postpartum visits, and treatment for unrelated gynecologic conditions. Those services do not always follow the same documentation, coding, or payer rules. That leaves plenty of room for small mistakes to slip into the billing process.

Sometimes the problem is obvious. A claim is rejected because the subscriber number is wrong or a required field is missing. Other problems are harder to notice. A payer may process a claim even though the documentation is weak, a modifier has been used inconsistently, or staff are following an outdated billing process.

One paid claim does not necessarily tell a practice that everything behind the claim was handled correctly. A better way to think about compliance is to look at the entire path a claim takes:

  • Patient information has to be accurate.
  • Coverage needs to be checked.
  • The provider's note has to support the service.
  • Coding needs to match the record, and payer requirements have to be addressed before the claim goes out.

When one part of that chain breaks down repeatedly, the problem can spread across dozens of claims before anyone recognizes the pattern.

Where OB/GYN Billing Problems Usually Start

Many compliance issues begin before a coder ever looks at the chart. Consider a returning patient whose insurance changed since her last appointment. If the old plan is still listed in the system, the claim may be sent to the wrong payer. By the time the rejection comes back, staff may need to update the account, verify benefits again, rebill the service, and make sure a filing deadline has not been missed.

Authorization problems can develop in much the same way. A service may have been appropriate and clearly documented, yet the claim can still run into trouble if the payer required prior authorization and nobody confirmed it.

Then there is the medical record itself. A provider may remember exactly what was discussed or performed during a visit, but the billing team can only rely on what appears in the documentation. If the note does not clearly support the service being reported, defending the claim later becomes much more difficult.

The Centers for Medicare & Medicaid Services (CMS) provides guidance on electronic healthcare claims and the information needed for claims processing. The larger point for a practice is simple: compliance starts long before a denial or payer review arrives.

Documentation and Coding Need to Tell the Same Story

Documentation and coding are often discussed as separate tasks. In actual billing, they are difficult to separate. The code on the claim is supposed to represent what happened during the encounter. The medical record is what supports that representation.

Problems begin when the two tell different stories.

A common OB/GYN situation is a preventive visit in which the patient also brings up a new medical concern. Additional evaluation may take place during the same encounter. Whether separate reporting is appropriate depends on the services performed, the documentation, coding rules, and the payer's requirements. Similar questions come up with procedures, diagnostic testing, postoperative care, maternity services, and modifier use.

A diagnosis code may be valid in general but still fail to match what the provider actually documented. A procedure code may describe a service correctly but lack enough support in the chart. A modifier can also create problems when staff use it routinely instead of deciding whether the circumstances of that particular encounter justify it. These are not always dramatic errors. That is part of the problem.

When the same documentation habit or coding shortcut is repeated week after week, an isolated weakness can turn into a larger compliance concern.

Periodic chart-to-claim reviews can help uncover those patterns. Instead of asking only whether the claim was paid, the reviewer looks at whether the claim accurately reflects the record and whether the documentation is strong enough to support what was billed.

Some Claim Errors Have Nothing to Do with Complex Coding

Not every denied or rejected claim involves a difficult coding question. Sometimes the problem is a wrong date, an outdated insurance record, missing provider information, an incorrect subscriber ID, or a claim field that was left incomplete. These errors may sound minor, but they still consume staff time and slow down payment.

Electronic claims generally pass through automated edits during processing. Certain missing or inconsistent details can cause the claim to stop before it gets very far.

A short review before submission can catch many of those problems. Staff may want to verify:

  1. Patient and subscriber information.
  2. Current insurance coverage and coordination of benefits.
  3. Provider and practice identifiers.
  4. Diagnosis codes, procedure codes, and modifiers.
  5. Documentation supporting the billed service.
  6. Required authorization or referral information.
  7. Payer-specific claim requirements and missing fields.

The review does not have to turn into a lengthy approval process for every claim. What matters is that the practice has a reliable way to catch repeatable errors before the payer does.

Eligibility Deserves More Attention in OB/GYN Billing

Insurance information can change during the course of care, and OB/GYN practices are especially likely to encounter that issue because many patients receive services over an extended period.

Pregnancy is an obvious example. A patient may have one insurance plan early in the pregnancy and another later. Employment can change. A spouse's coverage can change. Coordination of benefits may need to be updated. Authorization rules may also be different under the new plan. If staff rely on an eligibility check performed months earlier, the billing team may not find out about the change until a claim is denied.

Eligibility problems can affect more than reimbursement. They may also result in the wrong amount being assigned to the patient or create confusion about who is financially responsible for the service.

Checking coverage at appropriate points throughout treatment gives staff a chance to address those issues before the claim has already gone through the billing cycle. It also makes financial conversations with patients more accurate.

A Denial May Be Pointing to a Workflow Problem

Correcting a denied claim is necessary. Correcting the same type of denial twenty times should raise a different question - Why does it keep happening?

Suppose claims for a particular procedure regularly come back because information is missing. Billing staff can add the information and resubmit each claim, but that does not explain why the original claims were incomplete.

Maybe the registration team is not collecting something the payer requires. Perhaps the authorization information exists but is not being transferred correctly. It could also be that staff misunderstood a payer policy. The denial itself is only the visible part of the problem.

This is why useful denial management goes beyond counting how many claims were denied. Practices can look at which reasons occur most often, which payers are involved, whether one service keeps appearing, and where in the workflow the original error began.

That kind of review can reveal patterns that would otherwise remain hidden. The CMS Medical Review and Education resources also discuss claims analysis and medical record review in the context of identifying improper billing and documentation issues. For an OB/GYN practice, denial data can serve as a practical warning system. It shows where the revenue cycle is struggling, not just where payment was delayed.

Internal Audits Can Be Small and Still Be Useful

An internal audit does not have to involve hundreds of charts. A practice can learn a great deal from a carefully chosen sample.

Maybe one modifier has been causing questions. Perhaps a particular payer has denied an unusually high number of claims. There may be concerns about preventive visits, maternity billing, surgery, medical necessity documentation, or another service that carries more risk. Those claims can be reviewed against the medical record.

The reviewer may find that everything was handled appropriately. If not, the next step is to determine whether the problem was isolated or whether it reflects a larger habit. That distinction matters. One coding mistake made on a single claim may require a simple correction. Finding the same mistake across several providers or multiple dates of service suggests that the practice may need education, a workflow change, or closer monitoring. The audit should not end when the error is identified.

If a change is made, the practice needs some way to determine whether it worked. Reviewing another sample later can show whether the same problem is still appearing. Without follow-up, the practice has documented a problem but has not necessarily solved it.

Compliance Works Better When It Is Part of Routine Operations

A compliance process does not need to be complicated to be useful. In many practices, consistency matters more than creating a large set of policies that nobody uses. Staff should know how registration is handled, when eligibility is checked, how authorization information is recorded, how claims are reviewed, what happens when a denial arrives, and who is responsible for following up on recurring problems.

Those processes should not exist only in one employee's memory. Training matters for the same reason. Payer policies change. Coding guidance changes. Internal workflows change. New employees arrive, and experienced employees sometimes continue using a process that made sense under an older rule.

Regular education gives the practice a chance to catch those gaps.

Billing data can also help determine where training is needed. If eligibility denials suddenly increase, the first response should not necessarily be a general coding seminar. The practice may need to look at registration and verification instead. If several claims involving the same modifier are being questioned, a focused review of those encounters is probably more useful than retraining the entire staff on every coding topic. Compliance becomes easier to manage when the response matches the actual problem.

Documentation Reviews Should Include the Claim

A chart can look complete on its own while the corresponding claim still contains a problem.

The opposite is also possible. A claim may appear technically correct until someone compares it with the medical record.

Looking at both together usually provides a clearer picture. This is particularly important for services where the circumstances of the encounter affect billing. Preventive care, problem-oriented visits, procedures, maternity care, and postoperative services can all raise questions that cannot be answered by looking at a code alone.

The reviewer needs to understand what actually happened during the visit, what the provider documented, and how that information was translated into the claim.

Preparing for Billing Changes Before They Reach the Claims Department

One of the easiest ways for a billing problem to spread is for a rule to change while the practice keeps following the old process. Changes may affect coding, documentation, payer policies, reimbursement, or the way certain services are reported.

The first sign should not have to be a wave of denials.

When a significant change is announced, the practice can identify which services will be affected and who needs to know about it. Providers may need different documentation. Billing staff may need revised procedures. Software settings or claim edits may also need to be updated. Testing the new process early is usually easier than correcting a backlog later. This becomes especially important when changes affect maternity services because the care and billing may span several months.

The Bigger Compliance Question

A claim can be paid and still come from a weak process. That is why payment should not be the only measure of whether an OB/GYN billing operation is working well. A better question is whether the practice could explain and support the claim if someone reviewed it later.

  • Was the patient's coverage checked?
  • Does the chart support the service?
  • Does the code match what was documented?
  • Were payer requirements addressed?
  • If a similar problem appeared last month, was anything changed afterward?

Those questions bring compliance into the normal revenue-cycle process instead of treating it as something that matters only during an audit.

Most billing problems do not begin as major compliance failures. They usually start much smaller: an insurance detail that was not updated, documentation that was a little too vague, a modifier applied out of habit, or a denial that was corrected without asking why it happened.

The risk grows when the same issue becomes routine.

Finding those patterns early is what gives a practice the best chance to correct them before they affect more claims, more patients, or more revenue.

About the Author Noah Smith

This article is written by Noah Smith on behalf of BillingFreedom. Noah is a medical biller, SEO and Content Outreach Specialist.

Additional Resources

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Healthcare Revenue Cycle Compliance

Common Risks and How Practices Can Address Them 

Written by: Zara Ahmad 

A revenue cycle rarely breaks because of one dramatic mistake. More often, the problem begins with something ordinary: an insurance card was updated but the old plan stayed in the system, a provider’s note lacked enough detail for coding, or a denied claim was resubmitted before anyone checked the first one.

Compliance is not limited to the billing office. It starts when patient information is collected and continues through documentation, coding, claim submission, payment posting, denials, and follow-up.

Where Compliance Risks Can Enter the Revenue Cycle

Consider a routine office visit. The front desk enters the patient’s demographic and insurance information. If the member number is wrong, or the payer on file is outdated, the claim may already be inaccurate.

The next risk may appear in the medical record. A provider knows what happened during the visit, but a coder can only rely on what is documented. If a note is vague, staff should not fill in missing details from habit or assumption.

Charge capture creates another point of exposure. A service can be missed, entered twice, or attached to the wrong date. Later, a biller may resend a denied claim without confirming whether the original is still processing. Payment posting and accounts receivable follow-up can create problems too, especially when adjustments or corrections receive little review.

Common Revenue Cycle Compliance Risks

One familiar risk is a mismatch between the medical record and the claim. The service billed should be supported by the documentation. CMS guidance for Medicare makes documentation part of determining whether applicable coverage, coding, billing, and payment requirements are supported.

Incomplete documentation is often less obvious. A note may show that care occurred but still omit information needed to support a code, modifier, or service level. If that happens regularly, the issue is no longer just one troublesome claim.

Administrative mistakes matter as well. Incorrect patient details, insurance information, provider identifiers, and dates of service can cause denials and repeated corrections. Duplicate claims are another example. When payment is delayed, resubmitting the same claim may feel harmless, but claims-processing rules include duplicate edits.

Corrections need a consistent approach – contingent upon the payer and circumstances, the right step may be a corrected claim, replacement claim, appeal, or another defined process.

Why Documentation and Coding Accuracy Matter

Documentation, coding, and billing are different jobs, but they should describe the same encounter.

Suppose a coder returns the same type of note to the same provider several times each month because one detail is routinely missing. Correcting each claim solves the immediate problem, not the workflow problem.

A short, focused discussion with the provider may be more useful than another round of individual corrections. The aim is simply to make sure the record clearly reflects the service provided and gives coding staff the information they need.

Using Internal Audits to Identify Compliance Risks

Internal audits are most useful when they answer a specific question.

A manager might sample claims involving a frequently used modifier, one provider, a service with rising denials, or a payer that has generated repeated corrections. The review can compare claims with medical records, check key fields, examine adjustments, and see whether staff followed internal procedures.

Patterns often tell the real story. Several eligibility denials traced to the same registration step suggest a front-end workflow problem. Repeated coding questions may point to training or documentation habits instead.

An audit should lead somewhere. Someone needs to own the follow-up, record what changed, and later check whether the change helped.

Building a Stronger Compliance Culture

Compliance works better when people see how their own work affects the claim. Front-office staff influence patient and insurance information. Providers influence documentation. Coders and billers influence what reaches the payer. Managers decide whether recurring problems are investigated or simply worked around.

OIG’s General Compliance Program Guidance discusses written policies, education, communication, auditing and monitoring, and corrective action as parts of a compliance program. In everyday practice, those ideas are more useful when connected to real problems rather than treated as an annual checklist.

Training should follow the same principle. If an audit finds repeated modifier errors, train on that issue. If registration mistakes are driving denials, review that workflow with the people who perform it.

Practical Steps Healthcare Practices Can Take

  1. Review a representative sample of claims regularly.
  2. Compare billed codes with the supporting medical record.
  3. Track denials and claim corrections by reason.
  4. Review write-offs, refunds, adjustments, and claim changes for consistency.
  5. Use recurring errors to guide staff and provider education.
  6. Keep billing and compliance procedures current and easy to find.
  7. Document corrective actions and check whether they worked.
  8. Follow relevant CMS, OIG, and other authoritative guidance as requirements change.

Keeping Compliance Part of Everyday Work

No revenue cycle will be completely free of errors. What matters is what happens after a mistake is found. Comply with overpayment rules. Submit appropriate claims adjustments, credit balance reports, or self-reported refunds directly to your assigned Medicare contractor.

Investigate. Correct the affected account, but do not stop there. Ask where the error entered the process, why it was not caught earlier, and whether the same thing is happening elsewhere. That turns compliance from a periodic exercise into part of ordinary revenue cycle work. Over time, it can reduce avoidable rework, support more accurate billing, and leave a practice better prepared when claims are reviewed.

About the Author

Zara Ahmad is a healthcare industry professional and Marketing Team Lead at MedsIT Nexus, with a focus on healthcare revenue cycle management, healthcare operations, and industry education. Her work involves developing educational resources on healthcare administration, revenue cycle processes, and operational challenges affecting healthcare organizations.

Resources – obtain training in conducting internal audits and investigations from the American Institute of Healthcare Compliance, a Licensing/Certification partner w/CMS.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

HCC Coding in 2026

Navigating Risk Adjustment in a Changing Healthcare Landscape 

Written by: Joy Rose, MSA, RHIA, CCS, CHA, CHPS 

In 2026, Hierarchical Condition Category (HCC) coding continues to evolve as a central pillar of risk adjustment in value-based care. Initially introduced by the Centers for Medicare & Medicaid Services (CMS) to project healthcare costs and determine payments for Medicare Advantage (MA) plans, HCC coding has become a strategic necessity across multiple payers and care settings.

Medicare Advantage Organizations (MAOs) are paid at a higher rate for patients who have conditions with greater levels of severity and multiple conditions, as their RAF scores and anticipated costs of care will be higher.

Key 2026 Medicare Advantage (MA) Cost Reporting Requirements

CMS requires Medicare-certified acute care hospitals reimbursed under the IPPS (inpatient prospective payment system) to report median negotiated payment rates from Medicare Advantage (MA) plans by MS-DRG on their annual cost reports for cost reporting periods ending on or after January 1, 2026.

This mandate aims to collect market-based data to set future inpatient prospective payment system (IPPS) relative weights.

  • Data will be used to set future MS-DRG weights likely by Fiscal Year 2029.
  • This requirement adds significant complexity to an already error-ridden annual Cost Report process.

Providers must ensure the accurate reporting of MA negotiated rates to avoid potential audit findings, as this data will influence future payment setting.

New in 2026 - Full transition to V28 Model has occurred

One of the biggest updates in 2026 is the full implementation of the CMS-HCC V28 model, which was first introduced in 2023. This model includes significant changes:

  • More clinically relevant or accurate groupings, especially for chronic conditions like diabetes and congestive heart failure.
  • Expanded but refined HCC categories: V28 increases the number of HCC categories from 86 to 115, creating more granular groupings while reducing additive combinations.
  • Renumbering and changing HCC categories.
  • Removal of some condition codes that were found to be less predictive of future healthcare costs.
  • Reduction in the number of ICD-10-CM codes from 9,797 to 7,770 (approximately 2294 codes deleted and 268 codes added)
  • More accurate clinical data and the use of data-drive results with the use of 2018 ICD-10-CM codes and 2019 payment information.

Healthcare providers must now re-map workflows for diagnosis coding processes and re-educate coding staff to ensure accurate code assignment based on the documentation provided by clinicians.

Greater Emphasis on Documentation Integrity - With more sophisticated audits by CMS and private payers, clinical documentation improvement (CDI) remains a top priority. Inaccurate or unsupported codes now carry steeper compliance risks, and real-time documentation tools are being widely adopted to assist clinicians. Clinicians must be educated and trained about the new model which will require even greater specificity in documentation and code assignment to ensure that the true level of the Medicare Advantage patients’ illness severity is captured and transmitted to CMS for appropriate costs analysis.

AI and NLP Integration - Natural Language Processing (NLP) and artificial intelligence (AI) tools are increasingly embedded in EHR systems to assist in identifying undocumented HCCs and improving capture rates. These tools help flag missed conditions, identify hierarchical overlaps, and ensure that chronic conditions are properly documented and reported annually. AI has its limitations according to a colleague managing denials.

Important Note - The AI tool that is being tested a major Boston medical facility is not intelligent enough to find HCCs, or even ICD-10 codes to ensure a robust denial can be created.  The medical team working with the denials team does not approve the AI findings in about 80% of the AI suggestions.

Key Challenges - Training and education remain critical as coding teams and clinicians adjust to new rules and technology.  In addition, there is coding fatigue from increased workload and regulatory pressure may affect coder accuracy and job satisfaction.

Providers must also balance HCC optimization with ethical standards and compliance, avoiding aggressive or unsupported upcoding practices. It is important for organizations to realize there is increased CMS scrutiny, by flagging providers as high-volume billing outliers or submitting claims with unusually high severity levels.

Opportunities:

  • Risk-adjustment data analytics now allow organizations to benchmark performance and track documentation trends in real time.
  • Proactive condition management enabled by accurate HCC coding allows payers and providers to better target care management and reduce preventable costs.
  • Interoperability and FHIR-based data exchange in 2026 enable smoother sharing of clinical data across systems, improving longitudinal risk tracking.
  • Increased focus on severity of patient diagnosis and claims by CMS

Real World Impact

As CMS moves further into outcome-based models and enhances its oversight of MA payments, the role of HCC coding will only grow in significance. Health systems that invest in robust CDI programs, AI-assisted coding tools, and clinician training will be better positioned to thrive in this value-based future.

Some analysts warn the shift could lower RAF scores 10-20% for providers still relying on V24-era documentation habits, since patients whose only qualifying condition was deleted in V28 effectively disappear from risk registries. Plans with large diabetic populations that previously captured a lot of complication-related detail are seeing the steepest declines, though expanding documentation breadth across different disease families can partly offset this.

Because of the revenue pressure, CMS/OIG have signaled they'll be watching closely for organizations overcompensating with inflated severity coding.

About the Author

Joy Rose, MSA, RHIA, CCS, CHA, CHPS is a member of the American Institute of Healthcare Compliance (AIHC) and serves as a subject matter expert on the AIHC Volunteer Education Committee.

References:

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

The Imperative of Documentation Integrity

Addressing the Healthcare Data Crisis 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

The information in this article primarily applies to providers when recording patient encounters in their office or other places of service. Content is for educational purposes only and is not intended as consulting or legal advice.

Introduction

Clinical documentation represents the foundational pillar of modern healthcare, ensuring patient safety, care continuity, accurate reimbursement, and the ethical use of medical data for research. However, the healthcare industry is currently grappling with a severe data crisis driven by the proliferation of historical documentation errors.

  • The transition from paper-based charts to Electronic Health Records (EHRs), while designed to streamline operations and reduce medical errors, has inadvertently introduced systemic vulnerabilities that compromise the integrity of clinical data.

The modern healthcare data crisis is not simply a matter of lost or misplaced files; it is a systemic degradation of data quality caused by the cumulative effect of historical documentation errors. At the center of this crisis is the phenomenon known as "chart lore" or "note bloat," where inaccuracies and redundancies are perpetuated across multiple patient encounters.

Several structural and behavioral factors drive this crisis:

  • Overuse of Copy/Paste and Cloning: The implementation of EHRs introduced time-saving functionalities such as the "copy-forward" or copy/paste features. Studies have revealed that over 50% of the text in inpatient and outpatient notes is duplicated. This practice often results in carrying over outdated, irrelevant, or entirely incorrect clinical information (e.g., documenting an allergy that was proven false years prior), creating information overload and increasing the risk of adverse events.
  • Template and Drop-Down Menu Errors: The reliance on pre-populated templates and drop-down menus can lead to "mouse-click errors," where a provider accidentally selects a normal finding for an abnormal condition. These errors obscure the true "patient story" and result in contradictory or missing clinical context.
  • Patient Matching and Interoperability Failures: Poor data entry and fragmented system integration contribute to patient misidentification. Industry surveys indicate that up to 20% of patients may not be correctly matched to their records, leading to scenarios where providers make treatment decisions based on another individual’s medical history.
  • Defensive and Billing-Driven Documentation: Because healthcare systems rely on Evaluation and Management (E/M) codes and reimbursement structures, clinicians are often pressured to document excessively to satisfy complex billing requirements, rather than focusing purely on clinical utility. This return-on-investment approach distorts the clinical record and leads to defensive medicine.
    • In light of Evaluation & Management guidelines allowing time or medical decision-making for many codes, providers must remember, when time is used, the complexity of the visit must be reflected to support longer visit times (higher reimbursed codes). Payers will question when high levels of service are billed but the note does not reflect the amount of work to support reimbursement.

Artificial Intelligence and the Physician/Provider Burden

Ironically, the tools intended to make documentation easier, EHR systems, have become a leading driver of clinician stress and burnout. The "cognitive load" of navigating drop-down menus and templating systems detracts from face-to-face patient time. And now with Artificial Intelligence (ambient scribes) being integrated into clinical documentation, the burden can become overwhelming due to time to ensure there are no errors in the record. AI is being built of historical information that is peppered with errors, inaccuracy, and omissions.

Despite promised efficiency gains, a large multi-center study found that AI ambient scribes saved a relatively modest 16 minutes of documentation time per eight hours of care. Because physicians are ultimately responsible for the accuracy of their medical records, they are forced to shift cognitive effort from typing to auditing—carefully reviewing AI-generated text to ensure no critical data has been omitted or misstated

Integrating artificial intelligence (AI) as ambient scribes in clinical settings reduces documentation time but yields distinct error profiles. Studies from the National Library of Medicine indicate that up to 70% of AI-generated notes contain at least one error, with an average of 2 to 3 errors per note. Omissions are the most common mistake, accounting for 71% to 83% of all errors.

Breakdown of AI Errors

Research shows that the types and frequencies of errors vary widely by system:

  • Omissions: Occurring in roughly 70-80% of recorded mistakes, this happens when AI leaves out critical details. Studies note that over 40% of these omissions carry moderate to significant clinical importance (e.g., omitting comorbidities or medication side effects).
  • Additions: Representing 4% to 11% of errors, this occurs when the AI fabricates or inserts information that was never discussed.
  • Hallucinations & Wrong Outputs: Fabricated or severely misidentified medical terminology.
  • Misplacements: Occurring in 6% to 25% of errors, where the AI correctly transcribes the info but places it in the wrong section of the chart.

Documentation Integrity & Accuracy Metrics

While traditional self-documentation by doctors can also be fragmented, ambient AI drafts often capture a much higher volume of the spoken interaction. However, this can sometimes lead to an inverse problem of information overload for the physician reviewing notes for accuracy.

Patient Safety and Clinical Continuity

The primary purpose of any clinical note is to support continuous, high-quality patient care. Outpatient practices frequently treat patients across extended timelines and involve diverse clinical staff. Therefore, documentation integrity is critical for several interconnected reasons:

  • Preventing Diagnostic and Medication Errors: When previous providers fail to update active problem lists, or when notes contain contradictory information, the risk of adverse events skyrockets.
    • Accurate documentation ensures that allergy lists, historical diagnoses, and ongoing treatment regimens are clear, preventing medication interactions and duplicative testing.
  • Facilitating Coordinated Care: In an era of team-based care and interoperability, patient notes are often referenced by external specialists, primary care physicians, and allied health professionals.
    • Complete, up-to-date clinical notes give care teams a holistic view of a patient’s health journey, allowing them to make informed, data-driven decisions.

Financial Sustainability and Revenue Cycle

Documentation dictates reimbursement and an organization’s ability to support compliant billing and reimbursement. In outpatient settings, practices rely on Evaluation and Management (E/M) coding guidelines established by the Centers for Medicare & Medicaid Services (CMS) and the American Medical Association (AMA).

  • Reducing Claim Denials: Payers use automated systems to verify that documented services match the billed codes. Incomplete or vague documentation leads to high rates of claim denials, requiring expensive and time-consuming rework for billing staff.
  • Combating the "Cloning" Risk: EHRs offer time-saving features like "copy-and-paste," "carry-forward," and auto-fill. While efficient, these features frequently lead to documentation cloning, where notes contain outdated or clinically irrelevant information.
    • Payers increasingly view cloned notes as a compliance risk, which can lead to delayed payments or allegations of upcoding, leading to allegations of violating the False Claims Act.

The Clinical and Legal Repercussions

The accumulation of these errors across vast databases has severe, real-world consequences for patient safety and institutional liability. Regulatory bodies, including the Department of Health and Human Services (HHS) Office of Inspector General (OIG), heavily scrutinize outpatient billing. Ensuring documentation integrity limits the financial and reputational damage of audits:

  • Demonstrating Medical Necessity: Every medical service must be justified by documented medical necessity. Documentation must clearly demonstrate why a course of action was taken and what alternatives were considered. Without this, practices are vulnerable to recoupment during post-payment audits.
  • Combating Fraud, Waste, and Abuse: Accurate charting protects both the provider and the organization. Attempting to add missing information or diagnoses to a chart after an audit has been initiated is a serious legal violation that carries civil and criminal penalties. Maintaining real-time, tamper-evident documentation is the best legal defense for providers.
  • Patient Harm and Medication Errors: Data integrity issues directly impact diagnostic accuracy and treatment planning. Studies indicate that a significant percentage of EHR-related events—sometimes cited as over one-third of cases—have life-threatening potential. When providers are forced to skim through bloated records, critical changes in a patient's condition or medication history are frequently missed.
  • Artificial Intelligence and Big Data Limitations: The current push toward integrating artificial intelligence (AI) and machine learning (ML) into healthcare relies entirely on the premise of data accuracy. However, because a high percentage of EHR records contain documentation errors, predictive models are frequently built on flawed or "missing" data indicators, which compromises their clinical reliability and introduces unconscious biases into algorithmic decision-making.
  • Malpractice Liability: Legal teams increasingly scrutinize EHR meta-data and documentation errors during litigation. Many EHR-related malpractice liabilities stem directly from documentation errors and omission, making inaccurate record-keeping a major risk management concern.

Strategies for Restoring Documentation Integrity

Addressing the healthcare data crisis requires a fundamental shift in how documentation is viewed, created, and audited. Organizations must move beyond billing-centric metrics and prioritize true Clinical Documentation Integrity (CDI). We simply need more documentation professionals, specifically in the outpatient setting where most care is rendered.

Implement Continuous CDI Programs - Healthcare facilities must establish dedicated CDI teams that routinely review and audit charts for clarity, completeness, and clinical accuracy. However, it is important that auditors and those training providers in CDI have structured training themselves first. Not all coding and billing auditors are qualified to conduct a documentation integrity audit. By educating all those involved on best practices and modern documentation guidelines, organizations can ensure that the patient's medical history accurately reflects their current clinical state.

Engage with organizations for online CDI training to improve the basic understanding of a compliant medical record. Registering qualified staff and/or providers with an organization which is a Licensing/Certification partner with CMS is recommended, such as the American Institute of Healthcare Compliance which offers online training with option to Certify as a Medical Documentation Professional.

EHR Usability and Design Overhaul - Software vendors and IT departments must collaborate to redesign EHR interfaces. This includes implementing strict limits on copy-paste functionalities, utilizing anomaly detection tools to flag duplicated or contradictory text, and enhancing interoperability to reduce patient matching errors.

Structured Data Capture - Shifting from unstructured narrative notes to standardized, structured data formats allow for better data reuse, less error-prone information exchange, and more effective clinical decision support systems.

Patient Engagement as a Verification Tool - Opening up EHRs to patients—allowing them to access their own health records and actively report discrepancies—has proven to be an effective strategy for identifying and resolving embedded "EHRrors" before they cause harm.

Conclusion

The historical degradation of healthcare data integrity poses a significant public health threat, turning patient records from life-saving tools into repositories of perpetuated errors.

To mitigate this crisis, the healthcare ecosystem must prioritize actionable, systemic reforms. By investing in enhanced EHR design, responsible implementation of integrating AI, rigorous auditing and compliance, and a culture of clinical clarity, the industry can restore trust in medical data and safeguard patient lives.

Outpatient practices can no longer treat clinical documentation as a mere administrative byproduct. Documentation integrity is the structural backbone of patient safety, financial compliance, and legal protection. By actively investing in CDI processes, ongoing provider education, and optimized EHR workflows, outpatient practices can safeguard patient outcomes, reduce audit vulnerabilities, and restore clinician satisfaction.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Auditing and Standard Deviation

The Importance of Statistical Significance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of standard deviation when Auditing for Compliance and quality standards. It is not intended as being comprehensive, legal or consulting advice. You may be interested in other auditing articles – click here. 

Introduction

In an increasingly data-driven corporate healthcare environment, auditing has moved beyond traditional spot-checking to advanced analytics. Standard deviation, a statistical measure of dispersion, has become an essential tool for auditors to assess risk and operational performance. By quantifying how data points, such as transaction amounts, process times, or product quality metrics deviate from the mean, auditors can identify anomalies, measure volatility, and evaluate the consistency of operational processes.

This paper explores how standard deviation helps audit financial risk by identifying outliers and market volatility, and how it improves operational efficiency by highlighting process variations.

Why Standard Deviation (SD) is Vital

In simpler terms, standard deviation measures the variation in the data. A higher variance requires a larger sample size to achieve statistical significance. It represents the average amount of variation or dispersion of data points from the mean.

Standard deviation is another measure of dispersion that complements variance. Standard deviation indicates how spread out the data points are in relation to the mean. Just like variance, standard deviation helps us understand the consistency and reliability of the data.

  • SD helps to identify outliers and anomalies. Auditors use standard deviation to pinpoint unusual data points that fall far from the mean to flag potential fraud, waste, billing errors, patient waiting times and quality measures.
  • SD is used to assess consistency. In auditing, a small standard deviation indicates consistent performance, while a high one suggests unreliable processes or high variability.
  • Calculating SD is vital when used in evaluating treatment/clinical variation. It helps determine if outcomes are consistent across a population. High standard deviation in medical data indicates inconsistent patient responses, which may signal a need for audits on clinical quality.

Understanding Risk and Performance

Financial risk management requires understanding volatility and uncertainty. Standard deviation serves as a proxy for this risk, helping auditors and financial analysts determine the potential for loss or unpredictability.

Auditors are tasked with providing assurance on financial statements and improving business processes. While averages (means) provide a central reference point, they often disguise underlying inconsistencies or high-risk outliers.

Standard deviation (SD) is essential because it measures the spread of data; a small standard deviation indicates consistency, while a high standard deviation indicates high variability. For auditors, this variability is synonymous with risk and potential inefficiency.

It is essential for auditing financial risk and operational efficiency because it permits auditors to see if "average" performance is due to uniform, acceptable results, or a mix of excellent and failing results.

Standard deviation is particularly useful for auditors due to its specific mathematical properties:

  • Sensitivity to Outliers: Because standard deviation squares the variance, it heavily impacts outliers, making it an effective tool for surfacing extreme cases.
  • Comparability (Scale Invariance): Auditors can directly compare the volatility of different datasets, even if they are in different units, allowing for comprehensive risk assessment across diverse business units.
  • The Normal Curve (Bell Curve): In a normal distribution, roughly 68% of data falls within one SD, 95% within two, and 99.7% within three. Auditors can use these intervals to define "normal" transactions and immediately identify the 5% that are outliers.

While powerful, standard deviation has limitations that auditors must recognize:

  • Assumes Normal Distribution: It works best with normal, bell-shaped curves. If data is heavily skewed or has fat tails, standard deviation might underestimate tail risk (rare but extreme events).
  • Backward-Looking: It is based on historical data, which may not repeat in the future.
  • Treats Volatility Equally: It treats positive and negative deviations equally, whereas auditors are primarily concerned with downside risk.

Steps to Calculate Sample Standard Deviation (SD)

Calculating standard deviation for a health care audit measures how much individual data points (e.g., patient wait times, billing errors) differ from the average, showing consistency in care. To calculate, find the average (mean), calculate each data point’s distance from the mean, square them, average those squares, and find the square root.

1.  Calculate the Mean

  • This is calculating the average by adding all audit data points and then dividing by the total number of items.

2.  Calculate Deviations

  • Subtract the mean from each individual data point.

3.  Square the Deviations

  • Square each result from step 2 to remove negative values.

4.  Sum of Squares

  • Add all squared values together.

5.  Calculate Variance

  • Divide the sum of squares (sample size minus one).

6.  Calculate Standard Deviation

  • Take the square root of the variance.
Square Root Formula

 σ is the standard deviation, xi is each individual data point in the set, µ is the mean, and N is the total number of data points. In the equation, xi, represents each individual data point. The results are then summed (symbolized as Σ), which is the numerator of the fraction from the equation.

Example: Audit of Patient Wait Times (Minutes)

Data (patient wait times): 10, 15, 20, 25, 30

Mean is 20:         (10 + 15 + 20 + 25 + 30) ÷ 5 = 100 ÷ 5 = 20

1.  Deviations:

  • 10 - 20 = -10
  • 15 - 20 = -5
  • 20 - 20 = 0
  • 25 - 20 = 5
  • 30 - 20 = 10

2.  Squared Deviations:

  • (-10)2 = 100
  • (-5)2 = 25
  • (0)2 = 0
  • (5)2 = 25
  • (10)2 = 100

3.  Sum of Squares: 100 + 25 + 0 + 25 + 100 = 250

4.  Variance: 250 ÷ (5 - 1) = 250 ÷ 4 = 62.5

5.  Standard Deviation: 62.5 ~ 7.90569 (round to 7.91)

6.  Audit Conclusion: The average wait time is 20 minutes with a standard deviation of 7.91 minutes

Conclusion

Understanding the significance of standard deviation is essential for modern auditing. It allows auditors to shift from a focus on the average to a focus on the variation. By providing a clear, quantified metric for variability, standard deviation allows auditors to quickly pinpoint financial risks and compliance issues that require investigation. Used alongside other audit tools, it ensures that companies can better manage risk, maintain control over processes, and optimize performance.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

National Library of Medicine

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Nurse Staffing as National Performance Goal 12

Executive Oversight, Patient Safety, and Compliance Risk in 2026

Written by: Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE 

Abstract 

Effective January 1, 2026, the Joint Commission elevated nurse staffing to National Performance Goal (NPG) 12, establishing staffing adequacy as a measurable accreditation and patient safety requirement. This article provides an executive- and auditor-facing analysis of NPG 12, examining regulatory intent, alignment with CMS Conditions of Participation, leadership accountability, and compliance risk. Practical guidance is offered to assist governing boards, executive leaders, and compliance professionals in operationalizing staffing oversight within enterprise risk, quality, and accreditation frameworks.

Introduction

Healthcare organizations entering 2026 face intensified scrutiny related to workforce adequacy, patient safety, and leadership accountability. Persistent staffing shortages, clinician burnout, and adverse patient outcomes have driven regulators and accrediting bodies to elevate staffing oversight as a core compliance priority. The Joint Commission’s designation of nurse staffing as National Performance Goal 12 represents a formal shift from treating staffing as an operational concern to recognizing it as a governance and accreditation imperative.

This shift requires healthcare leaders to reevaluate staffing policies, oversight structures, and performance measurement methodologies to ensure alignment with accreditation standards and federal regulatory expectations.

Regulatory Evolution and Rationale for NPG 12

Historically, nurse staffing requirements were embedded across leadership, human resources, and patient care standards and often evaluated indirectly through quality outcomes or adverse event investigations. However, evidence consistently demonstrates a direct relationship between inadequate nurse staffing and increased mortality, preventable harm, staff turnover, and regulatory findings.

By establishing staffing as NPG 12, the Joint Commission underscores the necessity of proactive oversight, data-driven decision-making, and executive accountability in maintaining safe staffing levels.

Scope and Applicability of NPG 12

NPG 12 applies broadly across hospital settings and clinical departments. Requirements extend beyond bedside nursing to include interdisciplinary clinical support essential to patient care. Key expectations include 24/7 registered nurse coverage, designated nurse executive oversight, and staffing models responsive to patient acuity, complexity, and care demands.

Organizations must demonstrate that staffing decisions are grounded in clinical need rather than solely financial or administrative considerations.

Executive and Governing Body Accountability

A defining feature of NPG 12 is its explicit emphasis on leadership oversight. Executive leaders and governing boards are expected to actively monitor staffing metrics, understand staffing-related risks, and ensure appropriate resource allocation. Surveyors may evaluate whether leadership receives regular staffing reports, responds to trends, and integrates staffing considerations into strategic planning.

Failure to demonstrate leadership engagement may result in accreditation findings related to leadership and governance standards, even in the absence of sentinel events.

Ethical and Professional Practice Implications

Beyond regulatory compliance, NPG 12 reinforces ethical obligations embedded in nursing professional standards and organizational duty of care. Chronic understaffing places nurses in ethically untenable positions, increasing moral distress and undermining professional judgment. Accrediting bodies increasingly assess whether organizations acknowledge and mitigate moral injury and burnout as patient safety risks.

Labor, Workforce, and Employment Law Intersections

NPG 12 intersects with labor law, whistleblower protections, and occupational safety standards. Inadequate staffing has been cited in retaliation claims, union grievances, and OSHA-related complaints alleging unsafe working conditions. Documentation demonstrating proactive staffing oversight may mitigate regulatory and legal exposure.

Alignment with CMS Conditions of Participation

NPG 12 closely aligns with CMS Conditions of Participation related to nursing services, patient rights, and quality assessment and performance improvement. Deficiencies may result in immediate jeopardy findings, amplifying compliance risk when accreditation and CMS enforcement converge.

Data-Driven Staffing Models and Performance Metrics

Compliance with NPG 12 requires data-driven staffing methodologies beyond static ratios. Surveyors may assess acuity-based tools, staffing variance analysis, and correlations between staffing levels and quality indicators. Organizations must demonstrate how staffing data informs corrective actions and continuous improvement.

Compliance with NPG 12 requires data-driven staffing methodologies beyond static nurse-to-patient ratios. Consistent with NPG.12.06.01 EPs 1–4, surveyors assess whether staffing adequacy is evaluated when undesirable patterns, trends, or variations in quality or safety are identified and whether findings are escalated through performance improvement and governance structures.

Real-world, setting-specific examples

Critical Access and Rural Hospitals:

A rural critical access hospital identified repeated patient flow delays and increased transfer times during seasonal surges. Although staffing numbers met minimum coverage requirements, leadership incorporated staffing effectiveness indicators into QAPI reviews, revealing gaps in skill mix during high-acuity presentations.

Corrective actions included cross-training nursing staff and implementing an escalation protocol requiring nurse executive review when acuity thresholds were exceeded. Findings and actions were documented and reported to governance, consistent with NPG.12.06.01 EP 3–4.

Psychiatric and Behavioral Health Settings:

In an inpatient psychiatric unit, analysis of restraint and seclusion events revealed correlations with staffing shortages during overnight shifts. Leadership included staffing adequacy in the root cause analysis, adjusted staffing models to ensure appropriate competency and coverage, and monitored outcomes through ongoing performance improvement activities. Annual staffing analysis results were provided to the patient safety program and governing body, aligning with NPG.12.06.01 EP 1–2.

Emergency and Mixed-Acuity Rural Facilities:

A rural emergency department experiencing increased left-without-being-seen rates evaluated staffing data alongside throughput and acuity metrics. Leadership implemented targeted staffing adjustments during peak hours and tracked improvements through QAPI dashboards. Staffing analyses and corrective actions were formally reviewed by executive leadership and incorporated into governance reports, demonstrating compliance with NPG.12.06.01 EP requirements.

These examples illustrate that staffing data must be actively analyzed, escalated, and integrated into performance improvement activities. Surveyors may evaluate whether leaders can articulate how staffing analyses influence corrective actions and how results are communicated to the hospital wide patient safety program and governing body.

Documentation, Evidence, and Surveyor Expectations

Surveyors may request evidence of leadership review, board discussion, action plans, and integration of staffing metrics into QAPI activities. Absence of such documentation may result in findings even when staffing ratios appear acceptable.

Compliance, Legal, and Operational Risk

Inadequate staffing presents compounded risk across accreditation, regulatory, legal, and operational domains. NPG 12 codifies staffing adequacy as an enterprise compliance risk requiring sustained mitigation strategies.

Survey Readiness and Best Practices

Survey readiness under NPG 12 requires staffing-focused mock surveys, compliance dashboards, and leadership preparedness to articulate how staffing decisions support patient safety and quality outcomes.

Conclusion

The elevation of nurse staffing to National Performance Goal 12 reflects a deliberate regulatory shift toward recognizing workforce adequacy as a foundational patient safety requirement rather than an operational afterthought. By formally linking staffing oversight to accreditation, performance improvement, and governance accountability, the Joint Commission has clarified expectations that safe staffing is inseparable from leadership responsibility and organizational culture.

Healthcare organizations entering 2026 must demonstrate that staffing adequacy is actively monitored, analyzed, and escalated through established quality and compliance structures. Static staffing policies and retrospective justification are no longer sufficient. Instead, leaders are expected to use data-driven methodologies, integrate staffing considerations into QAPI activities, and ensure governing bodies receive meaningful, actionable information related to staffing risk and performance.

Organizations that proactively embed staffing oversight into enterprise risk management, accreditation readiness, and strategic planning will be best positioned to mitigate regulatory exposure, support workforce sustainability, and achieve measurable improvements in patient safety outcomes. In this evolving regulatory environment, effective nurse staffing oversight is not only a compliance obligation—it is a defining indicator of organizational resilience, leadership effectiveness, and commitment to high-quality care in 2026 and beyond.

Appendix A: NPG 12 Compliance Crosswalk (Effective January 2026)

The following table maps National Performance Goal 12 Elements of Performance to corresponding sections of this article using Joint Commission survey-oriented language to support accreditation readiness.

NPG / EP

Joint Commission Expectation

Article Section(s)

Survey-Ready Language

NPG 12.01.01

Leadership ensures adequate number and mix of qualified staff based on patient needs.

Leadership ensures adequate number and mix of qualified staff based on patient needs.

Staffing decisions are based on patient acuity, complexity, and clinical demand rather than solely financial considerations.

NPG 12.02.01 EP 1–2

Nurse executive directs staffing plans and participates in governance decision-making.

Nurse executive directs staffing plans and participates in governance decision-making.

The nurse executive maintains authority and accountability for nursing staffing models in collaboration with senior leadership.

NPG 12.02.01 EP 4–5

Registered nursing oversight is available 24/7.

Registered nursing oversight is available 24/7.

Registered nursing services are available 24 hours per day, seven days per week, consistent with deemed-status requirements.

NPG 12.04.01

Staff practice within scope of licensure and competency requirements.

Staff practice within scope of licensure and competency requirements.

Staffing adequacy includes verification of licensure, scope of practice, supervision, and competency.

NPG 12.05.01

Staff receive education, training, and competency evaluation

Ethical and Professional Practice Implications

Workforce education and competency are treated as patient safety safeguards.

NPG 12.06.01 EP 1–4

Staffing is evaluated during QAPI and reported to leadership and governance.

Data-Driven Staffing Models; Documentation and Surveyor Expectations

Staffing adequacy is incorporated into performance improvement analyses and reported to executive leadership and governing bodies.


About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • American Institute of Healthcare Compliance. (2026). January 2026 compliance newsletter.
  • The Joint Commission. (2025). National performance goals effective January 1, 2026: Hospital program.
  • Centers for Medicare & Medicaid Services. (2025). Medicare conditions of participation.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance, Quality

From National Patient Safety Goals to National Performance Goals

Executive Accountability, Accreditation Readiness, and Outcome-Based Compliance in 2026 Written by Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

As healthcare organizations enter 2026, regulatory oversight continues to shift away from task-based compliance toward measurable outcomes, leadership accountability, and system-level performance. A defining example of this evolution is the Joint Commission’s replacement of National Patient Safety Goals (NPSGs) with National Performance Goals (NPGs), effective January 1, 2026.

This article is for educational purposes only to provide an executive and auditor-facing analysis of the NPG framework, examining regulatory intent, accreditation implications, and alignment with the Centers for Medicare & Medicaid Services (CMS) Conditions of Participation (CoPs). Practical guidance is offered to support governing boards, executive leadership, and compliance professionals in integrating NPG expectations into enterprise compliance, quality, and risk management programs.

Introduction

Healthcare compliance oversight in 2026 reflects a decisive regulatory transformation. Accrediting bodies and federal regulators are increasingly emphasizing outcome accountability, leadership engagement, and sustained performance improvement rather than episodic documentation compliance. Within this context, the Joint Commission’s transition from National Patient Safety Goals (NPSGs) to National Performance Goals (NPGs) represents a structural and philosophical shift with significant implications for hospitals and critical access hospitals.

As highlighted by the American Institute of Healthcare Compliance (AIHC), the NPG framework consolidates elevated Joint Commission requirements into a unified, outcomes-focused chapter aligned with CMS Conditions of Participation. While the underlying requirements largely pre-existed, the NPG structure reframes how organizations are evaluated, increasing scrutiny of governance, leadership oversight, and data-informed decision-making.

Regulatory Evolution: From Prescriptive Safety Tasks to Performance Outcomes

National Patient Safety Goals historically served as targeted mechanisms to address discrete safety risks, such as medication errors, healthcare-associated infections, and communication failures. Over time, however, organizations frequently approached NPSGs as checklist items tied to survey cycles rather than as drivers of continuous improvement.

The National Performance Goal framework addresses this limitation by organizing fourteen measurable performance domains that emphasize outcomes rather than task completion. This evolution aligns with value-based care models and reinforces expectations that organizations demonstrate sustained, system-level performance rather than episodic compliance.

Alignment with CMS Conditions of Participation

A defining feature of the NPG framework is its intentional alignment with Centers for Medicare & Medicaid Services (CMS) Conditions of Participation (CoPs). CMS CoPs establish baseline federal requirements for participation in Medicare and Medicaid programs. The Joint Commission’s NPGs clarify expectations that exceed these minimum standards, thereby signaling areas of heightened regulatory and accreditation focus.

For compliance leaders, this alignment underscores the necessity of integrating accreditation readiness with CMS survey preparedness.

  • Performance deficiencies identified through NPG evaluation may expose organizations to downstream risk during CMS audits, enforcement actions, or corrective action reviews.

Elevated Focus Areas and Sustained Regulatory Oversight

Although the NPG framework emphasizes flexibility in achieving outcomes, certain high-risk domains retain explicit regulatory requirements. Goals addressing suicide risk reduction and care planning and evaluation continue to require prescriptive safeguards due to their association with patient harm and regulatory enforcement history.

This dual structure reinforces that outcome-based compliance does not eliminate the need for evidence-based controls in high-risk areas. Executive leadership must ensure these domains receive sustained oversight, resource allocation, and performance monitoring.

Executive and Board Accountability Under the NPG Framework

The transition to National Performance Goals elevates accountability beyond frontline operations to executive leadership and governing bodies. Surveyors increasingly assess how boards and senior leaders oversee quality metrics, respond to performance trends, and allocate resources to address identified gaps.

Organizations unable to demonstrate leadership engagement in performance oversight may face accreditation findings related to leadership standards, regardless of whether direct patient harm has occurred.

Compliance Risks of Superficial Implementation

A significant compliance risk during the NPG transition is treating the framework as a rebranding exercise. Organizations that update policies without strengthening data analytics, governance structures, and continuous monitoring mechanisms may fail to meet survey expectations. Effective NPG implementation requires interdisciplinary collaboration, integration with enterprise risk management, and routine evaluation of performance outcomes.

Survey Readiness in an Outcome-Driven Accreditation Environment

Survey readiness under the NPG framework requires a departure from document-centric preparation models. Surveyors are expected to evaluate how organizations use performance data to identify trends, implement corrective actions, and sustain improvements.

Best practices include outcome-focused mock surveys, alignment of dashboards with NPG domains, and leadership preparedness to articulate how performance data informs strategic decisions.

Conclusion

The replacement of National Patient Safety Goals with National Performance Goals represents a pivotal shift in accreditation and compliance oversight. By prioritizing outcomes, leadership accountability, and alignment with CMS Conditions of Participation, the Joint Commission has elevated expectations for organizational performance.

Healthcare organizations that proactively integrate NPG expectations into governance, compliance, and quality frameworks will be best positioned to mitigate regulatory risk and demonstrate sustained accountability in 2026 and beyond. 

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

OIG’s Focus on Nursing Home Engagement of Medical Directors

Written by Kirsten Taylor-Billups, JD, RN, CHC 

The Nursing Facility Industry Specific Compliance Guidance was published by the Office of Inspector General (OIG) in November 2024 as the first industry-specific guidance since the November 2023 updated general compliance guidance was published. Improving the quality of care and safety of residents within nursing facilities is a top priority for OIG. This educational article is provided for educational purposes only and is not intended as legal or consulting advice.

In June 2025, the OIG workplan was updated to include the Monitoring and Engagement of Medical Directors in Nursing Homes and CMS will begin conducting their reviews in 2026. The scope of the OIG’s focus will be in three areas:

  1. the extent in which medical directors performed required duties in nursing homes,
  2. the extent in which pay-rolled based journal data on medical director’s hours are accurate and useful for oversight, and
  3. opportunities to improve oversight and transparency of nursing homes engagement and funding of medical directors through existing data or other monitoring mechanisms.

Given the up-and-coming medical director reviews by CMS this article will review the regulatory requirements for medical directors in nursing homes, the barriers nursing homes have faced when implementing the regulations and proactive takeaways to consider when analyzing your medical director’s arrangements and the documentation required to quantify the effectiveness of medical director services.

The governing regulations on medical directors in nursing homes we will be reviewing is United States Code of Federal Regulations Title 42 Public Health Chapter IV CMS Part 483-Requirements for States and Long-Term Care (LTC) Facilities section 483.75 Administration. The Administration section requires LTC facilities to be administered in a manner that enables it to use its resources effectively and efficiently to attain or maintain the highest practicable, physical, mental, and psychosocial well-being of each resident. The requirements for medical directors are listed under section 42 CFR 483.75 (i) which indicates the facility must designate a physician to serve as a medical director who will be responsible for implementing resident care policies and coordination of medical care in the nursing facility. The intention of this regulation is to not only provide medical care in the facility but to also provide clinical guidance and clinical oversight on the implementation of resident policies and procedures to help with promoting quality of care and services to nursing homes residents.

The development, implementation and evaluation of resident care policies and procedures must be based on current evidence-based standards of practice and resolve medical and clinical concerns that affect residents’ quality of care and services. This is achieved when the medical director collaborates with the facility leadership (Administrator/ Director of Nursing/ Clinical Staff), attending physicians, physician extenders (nurse practitioners/ physician assistants), and consultants.

Documentation is key - The facility documentation which demonstrates the medical director’s level of involvement will need to be evident within the nursing homes facility assessments and quality assurance and performance improvement meetings. The medical director should be actively involved in the facility assessment process and not just be listed as a participant.

  • The facility documentation should show the medical director’s input in evaluating resident needs, staffing and resources.
  • Document the medical director’s attendance and contributions in meetings updating the facility assessment, during quality assurance and performance improvement (QAPI) meetings, policy reviews, and administrative decisions with the facility leadership team.
  • Record instances where the director intervenes in clinical care such as reviewing diagnoses, prescribing practices, or addressing issues with attending physicians.
  • Documentation should also show that the medical directors’ interventions are based upon current standards of practice.

Despite CMS regulations on Medical Directorships within nursing homes, the OIG has also provided ongoing guidance to medical directors’ roles within nursing homes. Initially in 2000 OIG Compliance Program Guidance for Nursing Facilities, which historically emphasized the risks of physician arrangements and medical director contracts being in violation of Anti-Kickback Statute (AKS), Physician Self-Referral and Stark Laws. In 2008 the Supplemental OIG Compliance Program Guidance for nursing homes and medical directorship expanded to the need for these arrangements to have documentation to show the arrangement was fair market value, document the services being provided, and they’re not sham for resident referrals.

Recently in 2024 OIG Nursing Facility Industry Segment-Specific Compliance Guidance (ICPG), medical directors are explicitly considered a compliance risk when it comes to their contracts, services, and likelihood for kickbacks for referrals. OIG also has enhanced their focus on the clinical and administrative responsibilities of medical directors when it comes to resident care policies and procedures, and quality of care and services and the billing for the services.

In addition to regulatory and operational responsibilities, it is essential for nursing homes to ensure that medical director arrangements comply with federal laws governing physician compensation and referrals. Specifically, the medical director’s role and compensation must be carefully structured and monitored to avoid violations of the physician self-referral law (commonly known as the Stark Law), the Anti-Kickback Statute, and related federal regulations.

  • Stark Law: The Stark Law prohibits physicians from making referrals for certain designated health services payable by Medicare or Medicaid to entities with which they (or an immediate family member) have a financial relationship unless an exception applies. Medical director’s agreements must be in writing reflect fair market value for bona fide services provided and not be based on the volume or value of referrals.
  • Anti-Kickback Statute: This statute makes it illegal to knowingly and willfully offer, pay, solicit, or receive any remuneration to induce or reward referrals of items or services reimbursable by federal health care programs. Medical director’s compensation arrangements must not serve as an incentive for directing referrals to the facility.
  • Physician Self-Referral Law: Overlapping with the Stark Law, this law restricts physician referrals when there is a financial relationship with the facility, unless specific safe harbors or exceptions are met.

OIG and Department of Justice (DOJ) have aggressively pursued nursing homes and related entities for sham medical director arrangements that violated the Anti-Kickback Statute and False Claim Act.

Sham arrangements typically involve payments for referrals rather than bona fide administrative or clinical services, with little or no documentation of actual work performed. There have been several settlements involving sham medical director arrangements for not only nursing homes but for other healthcare entities such as hospitals, home care, and assisted living entities. Here are a few healthcare entities who were in violation and entered into settlement agreements with the DOJ.

  • Prema Thekkek, Paksn Inc., and Six California Skilled Nursing Facilities (2023) entered into a $45.6 million consent judgement with a 5-year Corporate Integrity Agreement (CIA) with HHS-OIG where the settlement resolved allegations of False Claims Act and Antikickback Statute violations from 2009-2021. The basis for the settlement was medical director contracts were not used to pay for legitimate administrative services but pay for patient referrals, physicians were paid monthly stipends ($1,500-$10,000) regardless of actual services provided, physicians hired based on promises of patient refers minimums were met and if the minimum referrals weren’t provided the physician was terminated and the nursing homes documentation requirements for the services provided were not enforced.
  • Village Home Care LLC, CEO and Two Doctors (2023) the collective settlement amount was about half a million dollars for allegedly violating the false claims act and anti-kickback statute. The alleged violations involved sham medical director and sublease agreements used to pay physician for patient referrals with no actual services or use of the subleased space.
  • Phillip Esformes/Esformes Nursing Home Network (2019) settlement for violation of AKS and Fraud that resulted in criminal charges and imprisonment. Alleged large-scale kickback scheme where physicians, marketers, and others (Medical directors and consultants) were paid to refer patients to Esformes skilled and assisted living facilities.

Common themes in OIG/DOJ “sham medical director” cases

Across these and similar nursing home cases, the government tends to focus on a fairly consistent pattern:

  • Little or no documented services: Medical director agreements exist on paper, but there are few agendas, minutes, work product, QAPI deliverables, or time records to back up the payments.
  • Compensation not tied to FMV or effort: Physicians receive flat monthly fees that don’t match any reasonable estimate of hours or complexity, or that are unusually high given the size/acuity of the facility.
  • Referral‑driven motive: Evidence (emails, internal comments, timing of contracts) suggests the purpose of the arrangement was to secure or retain admissions, certifications, or orders, not to obtain genuine medical director services.
  • Duplicative or vague roles: Multiple physicians hold overlapping “medical director” or “quality consultant” titles for the same facility or service lines without clear differentiation of duties.
  • Weak compliance oversight: Compliance is either not reviewing these arrangements or is ignored; there’s no systematic FMV analysis, conflict review, or monitoring of actual performance.

The 2024 Nursing Facility ICPG essentially solidified these concerns for SNFs and are calling out medical director arrangements are being typically used by facilities to disguise kickbacks. Therefore, nursing homes compliance teams are encouraged to rigorously scrutinize the medical director’s contracts for their scope of work, fair market value, and services with quantifiable documentation to support the arrangement.

  • For instance, develop a medical director checklist that can be utilized to determine the essential elements of every medical director contract to determine whether there’s documentation to support fair market value, the amount of hours monthly the medical director spends performing medical director tasks and how to track their hours so their time in the facility as an attending isn’t added to their medical director task and duties.
  • Confirm the medical director is getting compensated for their medical director contracted hours only and not receiving additional compensation or financial incentives (a majority of the assigned residents, below market goods and services, bonuses for patient referrals or not providing the required number of hours and duties as a medical director before receiving their monthly stipend).

In 2025-2026 OIG workplan CMS implemented the requirement that nursing homes report medical director hours in the Payroll Based Journal (PBJ) system whether the medical director is an employee or an independent contractor. PBJ work hours only applies to hours work onsite for medical director roles which means only report the hours the medical directors spend performing medical director duties physically onsite. Therefore, any remote or offsite medical director tasks such as consulting, chart or policy reviews or monitoring performed cannot be reported by the nursing home in PBJ. The PBJ reporting system doesn’t have a separate code for medical directors.

Code 17 - The PBJ code that will have to be used is code 17 for Physician/MD/DO and reports the hours worked in the facility only. So, if a medical director is paid a flat monthly stipend, the facility must determine the actual on site hours worked.

When to Report 0 - If the medical director doesn’t do any onsite medical director duty within a quarter the facility must report a “0” zero on PBJ.

Based upon CMS review of the PBJ system, only 36% of nursing homes have reported PBJ hours for their medical directors. Therefore, the OIG is actively evaluating whether medical directors are performing their duties, whether PBJ date on medical directors is accurate and how to improve transparency and oversight of the medical directors in nursing homes. So, nursing homes can expect to see increased scrutiny of PBJ and reported medical director hours, potential audits comparing medical director contracts, invoices, and PBJ submissions as well as tightening of CMS guidance.

Therefore, nursing home administration, compliance and legal teams should incorporate into their medical director arrangements the following:

  • Maintain detailed logs of onsite medical director time.
  • Ensure the contract specifies onsite expectations.
  • Align invoices with documented onsite hours.
  • Avoid reporting offsite administrative time.
  • Audit PBJ submissions quarterly for accuracy.

Conclusion and Key Takeaways

The upcoming OIG and CMS scrutiny of nursing home medical director arrangements underscore the critical need for compliance, transparency, and robust documentation. Nursing homes must ensure their medical director contracts are clearly defined, reflect fair market value, and are supported by thorough records of onsite services. Avoiding sham arrangements and ensuring adherence to federal laws such as the Stark Law and Anti-Kickback Statute are essential to mitigate legal risks.

Key takeaways include:

  • Maintain detailed, contemporaneous documentation of medical director activities, especially onsite work.
  • Ensure contracts specify the scope of responsibilities and compensation aligns with actual services rendered.
  • Regularly audit Payroll Based Journal (PBJ) submissions for accuracy and compliance, reporting only onsite medical director hours as required.
  • Separate medical director’s duties from other physician roles to avoid duplicative or vague arrangements.
  • Engage compliance and legal teams in ongoing monitoring and evaluation of medical director arrangements to address regulatory risks and prevent enforcement actions.

By proactively addressing these areas, nursing homes can better withstand regulatory review, foster quality resident care, and mitigate any costly enforcement actions for noncompliance with the regulations.

About the Author Kirsten Taylor-Billups, JD, RN, CHC

Blog Kirsten

Kirsten Taylor-Billups is the owner and operator of Legal Healthcare Consulting, with 35 years of experience in acute and post-acute care. She holds the qualifications of Registered Nurse (RN), Juris Doctorate Degree (JD), and Certification in Healthcare Compliance (CHC). Over her 30-year tenure in healthcare, Kirsten has undertaken various roles, including Director of Nursing, Quality Assurance Consultant, Risk Manager, and Corporate Compliance Officer at multi-facility healthcare organizations such as University Hospitals, HCR ManorCare, Common Spirit Health, and Catholic Healthcare Initiatives.

Legal Healthcare Consulting, founded by Kirsten 30 years ago, offers expert services to government contractors and acute and post-acute care facilities in capacities including Chief Compliance Officer, Risk Manager, Quality Assurance Consultant and Mediation services. Kirsten’s extensive expertise and experience are invaluable assets.

If your nursing facility needs assistance with auditing, monitoring, or implementing effective medical director arrangements email a request to Ktaylor7284@legalhealthcareconsulting.com

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 3: The Pros and Cons of Interoperability Frameworks in Health Care

Written by: Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC and Dr. Tami M. Harris, DM, PMP, LSSBB 

Introduction 

Interoperability frameworks are the connective tissue of modern healthcare data exchange, defining how systems communicate, the structure of the data, and how information flows securely across organizations.

As healthcare organizations – including hospitals, payers, clinicians, and technology vendors – face significant challenges to deliver care in an environment dominated by fragmented data, siloed and competing systems, the push to standardize how information is exchanged has taken center stage. These frameworks offer a pathway toward a more connected healthcare ecosystem—one where patient medical records are transmitted securely, providers have timely access to essential information, and organizations can reduce the inefficiencies that drive patient care, increased costs, lost or duplication of data, and delays.

In the AIHC Part 1 Article on Interoperability: CMS Interoperability Framework Project: Should We Be Concerned?  A comprehensive overview dives into  the Problem with System Fragmentation in Healthcare and Security Concerns in the CMS Interoperability Framework Project (Part 1).

In the AIHC Part 2 Article: Interoperability and System Fragmentation in Healthcare, the contributing writers discuss Communication, Compliance, and Strategies for Successful Integration Interoperability and System Fragmentation in Healthcare (Part 2).

In this AIHC Part 3 Article, we will now walk the readers through the Pros and Cons of Interoperability Frameworks in Healthcare. As AI, Revenue Cycle Management (RCM) automation, payer auditing, and value-based care accelerate, these frameworks are rapidly becoming the backbone of national healthcare operations.

But like any key technology standard, these frameworks come with real advantages—and real trade-offs. Below is a practical, balanced breakdown that leaders should understand before deciding to adopt or move forward with how they will integrate these systems.

Pros & Cons - Let’s Start with the Pros

1. Exchange of Data Between Systems

Data Exchange interoperability frameworks, such as Health Level 7 (HL7), Fast Healthcare Interoperability Resources (FHIR), and Trusted Exchange Framework and Common Agreement (TEFCA), will help reduce fragmentation by providing a common language for AI-Powered Electronic Medical Record (EMR) systems, RCM platforms, and payer applications.

According to the Centers for Medicare & Medicaid Services (CMS), the Voluntary Interoperability Frameworks are designed to enhance manual back-and-forth, enable faster claims processing, reduce denials, and improve clinical decision-making.

Why it matters - Unconnected systems, duplicate documentation, and lost data cost hospitals millions of dollars every year. Current CMS estimates indicate that interoperability frameworks can shrink those losses by streamlining data exchange and minimizing manual errors. Integrating data into EHRs demonstrates the growing impact of interoperability frameworks on reducing fragmentation.

2. Stronger Clinical Quality and Patient Safety

With data flowing unimpeded, clinicians have a complete picture of labs, meds, allergies, imaging, and histories—regardless of where care was delivered. This improves the accuracy of care, reduces avoidable errors, and supports real-time decision-support tools.

A Forward-Thinking Angle - AI-enabled audits in Clinical Documentation Improvement (CDI) and RCM are most effective when built on interoperable data. Interoperability should be the prerequisite for advanced analytics and real-time clinical decision support.

3. Reduce Operational Waste and Administrative Burden

Implementing CMS Voluntary Frameworks, such as CMS 9115-f , automates and streamlines much of the documentation exchange, eliminating repetitive reconciliation, data entry, and faxing.

The CMS Interoperability and Patient Access Final Rule require payers to use FHIR-based APIs for data exchange, which has proven to reduce prior authorization response times and administrative costs for providers.

Impact - Minimize human touchpoints → fewer mistakes → shorter AR cycles → more cash collected faster.

4. Better Compliance with Federal Requirements

The goal is to minimize risk by leveraging the Assistant Secretary for Technology Policy and the Office of the National Coordinator for HealthIT’s (ASTP/ONC) Interoperability Frameworks, such as HL7, FHIR, CMS interoperability rules, and TEFCA, by aligning organizations with regulatory expectations for data access, patient API rights, and cross-network exchange.

TEFCA, launched in 2024, establishes a nationwide framework for secure health information exchange, connecting providers, payers, and public health agencies. Compliance with TEFCA and FHIR standards is now required for participation in federal programs and for avoiding penalties.

Bottom line - Staying compliant now avoids future penalties and positions organizations to participate in larger national data networks.

5. Fuel for AI, Predictive Analytics, and RCM Algorithms

AI models thrive on clean, structured, standardized data (Federal Register, Health Data).
Interoperability frameworks give organizations the quality inputs needed for:

  • Automated Claims Integrity Checks
  • Audit Ready Data Pipelines
  • Predictive RCM Drift Alerts
  • CDI optimization
  • Denials Prediction

The FDA and CMS are piloting FHIR-based submissions for real-world data, enabling advanced analytics and predictive modeling for population health and revenue cycle management.

Forward-Looking Reality - Organizations that implement interoperable data models today are better positioned to lead tomorrow’s AI-enhanced revenue cycle and clinical innovation.

The Cons

1. High Upfront Cost and Long Implementation Time

Implementing interoperability is not a simple upgrade. Many organizations underestimate the scale and cost, leading to project delays and budget overruns. Interoperability initiatives require:

  • API Integration
  • Data Mapping
  • Security Upgrades
  • Staff Training
  • Vendor coordination
  • Workflow Redesign

Truth - Interoperability is not a plug-and-play upgrade—it will be transformational.

2. Legacy System Limitations

Legacy systems often; lack support for modern APIs, contemporary data formats, or real-time exchange. These outdated platforms create bottlenecks, limit adoption, and increased maintenance costs.

Real-World Impact - Even if one part of the RCM process is modernized, the weakest legacy interface can undermine the entire process.

3. Cybersecurity Risks Rise with Connectivity

Expanding connectivity through APIs and cross-organizational networks increases the risk of cyber threats. The U.S. Department of Health & Human Services (HHS) emphasizes that interoperability must be paired with robust cybersecurity measures to protect sensitive health information.

Forward risk - AI-powered cyberattacks target health care's interconnected data ecosystems. Interoperability without hardened defenses is dangerous.

Organizations will need to ensure stronger access controls, encryption, and incident response plans are in place for threat prevention.

4. Vendor Resistance and Proprietary Barriers

Some vendors still rely on closed or proprietary systems to “lock in” clients, making interoperability expensive or technically challenging. This practice can significantly hinder the seamless exchange of health information across organizations.

The ONC has repeatedly identified proprietary interfaces and lack of standardized APIs as major obstacles to nationwide interoperability. Proprietary health IT systems continue to present significant challenges to data sharing. These systems often require organizations to invest in costly custom integrations, which can result in persistent information silos.

Result - Organizations can get stuck negotiating costly interface fees or dealing with partial data exchange, which not only increases operational expenses but also limits the ability to provide coordinated, high-quality care.

5. Variation in Standards and Inconsistent Adoption

Even with frameworks like FHIR (HL7 FHIR) or TEFCA (TEFCA Governance), vendor implement differently.  There are variations in:

  • API Maturity
  • Profiles
  • Optional Fields Versioning
  • Create Ongoing Friction

Reality - Interoperability is only as strong as the weakest implementation in the network. The ONC Interoperability Standards Advisory underscores the need for consistent implementation and highlights gaps in adoption across the industry.

Summary: A High-Level Strategic View

Interoperability frameworks are rapidly becoming the backbone of a modern, connected healthcare ecosystem, offering benefits that extend well beyond simple data exchange —yet their impact is far from one-dimensional. Throughout this three-part AIHC series, we have explored the real and persistent challenges of system fragmentation, the security vulnerabilities exposed by national initiatives such as the CMS Interoperability Framework Project, and the practical strategies organizations can use to navigate and overcome communication and compliance barriers.

In this Part 3 article, we explored the significant advantages and real trade-offs that interoperability frameworks bring. These standards promise faster access to patient information, improved care coordination, and greater operational efficiency.  At the same time, it is important to realize that these benefits of interoperability in healthcare require rigorous governance, robust security, disciplined integration planning, and adaptability to evolving federal and state requirements, including market pressures Understand Interoperability in Healthcare.

As AI in RCM automation, payer oversight, and value-based care continue to accelerate, interoperability will become increasingly critical. Operational leadership that succeeds will be those who embrace connectivity with strategic foresight—leveraging the advantages while proactively managing the associated risks. 

Interoperability should be viewed not just as a technology requirement; it should be considered the de facto strategy and standard that will shape how healthcare delivers value, safeguards patients, and competes in a data-driven future.

About the Authors

Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC, is the Founder, Principal & Managing AI Consultant of P3 Quality, a Healthcare Tech Consulting Company. She is a Certified Artificial Intelligence Professional (CAIP) and a Certified Artificial Intelligence Medical Coder (CAIMC). In her current leadership role, she extracts and diagnoses core Drift in AI Medical Coding Models, thereby closing AI-Driven financial, quality, and compliance gaps. Corliss is also a published author of Artificial Intelligence, Rise, Survive, & Thrive In An AI-Powered World. She also serves on the AIHC Volunteer Education Committee.

Dr. Tami M. Harris, DM, PMP, LSSBB, is the Founder & Chief Operating Officer of H & H Consulting Group, Inc. With a doctorate in Management, she is recognized as a certified Lean Six Sigma Black Belt and Project Management Professional, reflecting a commitment to operational excellence and continuous improvement. In her current capacity as Portfolio Director for Middle and Back-office Revenue Cycle Management (RCM) AI Automation and Transformation, she leads strategic advisory initiatives, oversees practice leadership, and drives client engagement delivery to generate new value-streams through technology.

References:

  1. American Health Information Management Association. (2024). TEFCA Overview. AHIMA. https://www.ahima.org/
  2. Centers for Medicare & Medicaid Services (CMS). Interoperability and Patient Access Final Rule (CMS-9115-F). https://www.cms.gov/cms-9115-f
  3. Food and Drug Administration. (2025). Exploration of Health Level Seven Fast Healthcare Interoperability Resources for Use in Study Data Created From Real-World Data Sources for Submission to the Food and Drug Administration; Establishment of a Public Docket; Request for Comments. Federal Register, 90(77), 17067–17069. https://www.federalregister.gov/documents/2025/04/23/2025-06967/exploration-of-health-level-seven-fast-healthcare-interoperability-resources-for-use-in-study-data
  4. HL7 International. FHIR Overview. https://www.hl7.org/fhir/
  5. National Academy of Medicine. Proposing Interoperability Standards for Healthcare. https://www.federalregister.gov/algoritm-transparency
  6. Office of the National Coordinator for Health Information Technology (ONC). Interoperability Standards Advisory (ISA). https://www.healthit.gov/isa
  7. The Sequoia Project. TEFCA Framework and Common Agreement. https://sequoiaproject.org/tefca/
  8. Understand the four levels of Interoperability in Healthcare. www.wolterskluwer.com
  9. U.S. Department of Health & Human Services. (2024). Cybersecurity Program. https://www.hhs.gov/about/agencies/asa/ocio/cybersecurity/index.html

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More