Compliance in Healthcare
Corporate Compliance

Documentation Integrity Starts with Valid Authentication

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

This short article addresses a complex topic and is not intended as consulting or legal advice. The content is not all-inclusive. 

Introduction

Documentation integrity is the foundation of patient safety and legal protection, and it begins with the valid authentication of every medical record entry. By properly verifying a provider's identity, healthcare systems ensure accountability, prevent unauthorized alterations, and maintain the clinical trustworthiness required for high-quality care.

Medical documentation serves as the legal, clinical, and financial foundation of patient care. An entry in a patient's chart is much more than a routine administrative task; it is a legally binding testament to the care provided, the rationale behind clinical decisions, and the direct observations of a specific practitioner. Because clinical reasoning is unique to the individual practitioner who evaluates a patient, the integrity of that record relies entirely on traceability—the ability to definitively link clinical data to the exact individual who created it. Valid signatures and proper authorization of medical records serve as legal proof that a licensed provider performed, reviewed, or ordered the care documented.

  • Valid authentication is the fundamental anchor of medical documentation integrity. It transforms digital text into a legally binding, trustworthy medical artifact.
  • Without proof of exactly who authored an entry at a precise time, healthcare records lose their clinical reliability, legal defensibility, and billing compliance.

Strict authorship and authentication rules mandate that only the healthcare professional who performed a service, made an observation, or gave an order may authorize the entry. Delegating this responsibility by allowing one provider to authenticate or "sign off" on another's notes is a critical violation of medical record integrity and regulatory standard.

Why No One Can Authenticate a Note for Another

First-Hand Knowledge and Accountability - The provider who performed the assessment is the only person who can truly verify the accuracy, nuance, and medical necessity of the documented care. Signing a note without first-hand knowledge means the authenticator cannot legally or ethically swear to the validity of the observations, creating a falsified record of the encounter.

Fraud and Abuse Implication - In billing and compliance, authenticity concerns regarding the legitimacy of documentation can trigger severe penalties. If a physician authenticates a note for a mid-level practitioner or colleague whose work they did not observe, it artificially validates services that the signer cannot legally account for, frequently resulting in claim denial and accusations of healthcare fraud.

Legal Admissibility - In a court of law, medical records are routinely scrutinized under the business records exception to hearsay. If a record is printed, requested for a malpractice suit, and the metadata shows that Provider B signed Provider A's note without being in the room or evaluating the patient, the record’s legal admissibility is immediately jeopardized.

The Difference Between Countersigning and Authentic Authoring

It is a common misconception that "countersigning" is the same as authenticating another's note. While supervising or attending physicians are often required by hospital bylaws to countersign the documentation of residents, interns, or students, this countersignature serves as a verification of supervision or oversight, not a transfer of authorship.

The original author still maintains full responsibility for writing the note, and the countersignature simply proves the supervising physician reviewed the care, rather than replacing the original clinician's signature.

Authentication is the Non-Negotiable Foundation

Medical documentation integrity relies entirely on the accuracy and trustworthiness of the health record. It dictates that every diagnosis, treatment, and clinical observation is reliable enough to support patient safety and billing accuracy.

At the absolute center of this integrity lies authorship validation. Without secure authentication, it becomes impossible to prove who created or altered a specific piece of clinical data. Valid authentication guarantees that the provider who performed the care is definitively linked to the record of that care.

1.    Patient Safety and Continuity of Care

Clinical decision-making relies entirely on the history of previous treatments, medications, and diagnoses. If a provider cannot verify the identity of the clinician who entered a critical lab note or medication order, patient safety is severely compromised. Secure logins and electronic signatures establish clinical accountability, allowing care teams to trust the information they are acting upon.

2.    Legal Defensibility and Evidence

In medical malpractice lawsuits, the medical record acts as the definitive legal evidence. To be admissible in court, the record must be validated as an accurate and uncorrupted version of events. Robust authentication—such as a password protected electronic signature linked to comprehensive system metadata—proves that a specific clinician took responsibility for the information at a specific date and time.

3.    Reimbursement and Regulatory Compliance

Healthcare revenue cycles rely on billing for services that are strictly documented and verified by the practitioner. Guidelines from the Centers for Medicare & Medicaid Services (CMS) require that all services be authenticated by the author. Furthermore, HIPAA regulations mandate strict user identification and access controls to prevent fraudulent entries or data breaches. Proper authentication acts as an organization's proof of work and regulatory adherence.

Technology Enforcing Authentication Integrity

In modern Electronic Health Record (EHR) environments, verifying the author requires sophisticated digital controls rather than a simple typed name. The integrity of these digital records is enforced through:

  • Multi-Factor Authentication (MFA): Requires users to verify their identity through multiple methods (e.g., a password paired with a push notification or biometric scan).
  • Role-Based Access Control (RBAC): Ensures that clinicians only interact with and authenticate records that fall within their designated scope of practice and clinical responsibilities.
  • Tamper-Proof Audit Trails: Logs every single time a record is viewed, created, or modified, tracking exactly who made the entry, the exact time, and the device used.

EHR systems must use secure logins, digital certificates, or biometric scans to authenticate the author to comply with CMS, Joint Commission, State regulations, and FDA guidelines. For example:

  • The Joint Commission (TJC): TJC requires that all entries in the medical record be authenticated by the author, dated, and timed.
  • CMS Guidelines: CMS strictly prohibits "swoop and hoop" or auto-authentication practices where providers sign off on large batches of notes without individually reviewing them.
  • State Regulations: Individual state medical boards maintain specific laws regarding timeframes for record completion (e.g., dictating that notes must be signed within 24 to 48 hours).

Conclusion

Medical documentation is only as reliable as its source. By establishing a clear, verifiable link between the clinical event and the responsible provider, valid authentication prevents fraud, protects medical professionals, and above all, ensures patient safety. Without it, the entire foundation of healthcare data integrity collapses.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

American Institute of Healthcare Compliance - Clinical Documentation Improvement online training

https://dev-main.aihc-assn.org/product/clinical-documentation-improvement/

CMS

https://www.cms.gov/files/document/mln905364-complying-medicare-signature-requirements.pdf

https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/pim83c03.pdf

https://www.wpsgha.com/guides-resources/view/227

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Why Every Healthcare Facility Needs a Smart Hospital Security System

Written by Peter Lee, MSc, CIPP/US and Arif Khan researcher specializing in AI-driven security systems and healthcare compliance

The information provided is for educational purposes only and is not legal, consulting or IT advice.

Introduction

Healthcare facilities operate in one of the most complex and high-risk environments of any industry. Hospitals are open 24/7, manage large volumes of patients and visitors, and handle sensitive data, controlled substances, and critical care operations all at the same time. This combination creates a unique set of security and compliance challenges that cannot be addressed with traditional systems alone.

The scale of the issue is significant. According to healthcare safety data, incidents involving workplace violence, unauthorized access, and theft are rising across hospitals and care facilities. In addition, regulatory requirements such as the Health Insurance Portability and Security Act (HIPAA) place strict obligations on how patient data and physical access must be controlled. Even a single breach can lead to severe financial penalties, legal consequences, and reputational damage, which is enforced by the Office of Civil Rights (OCR).

At the same time, many healthcare facilities still rely on outdated surveillance and access systems that are limited to recording events rather than actively preventing them. These systems often fail to provide real-time visibility, making it difficult for administrators and compliance officers to respond quickly when incidents occur.

This is why modern hospital security systems are becoming essential rather than optional. A smart security system does more than monitor activity. It integrates surveillance, access control, and intelligent alerts into a unified platform that helps healthcare organizations protect patients, staff, and sensitive information while maintaining compliance.

The Complexity of Healthcare Environments Demands Smarter Security

Unlike typical commercial spaces, hospitals are highly dynamic environments. Emergency departments, patient wards, pharmacies, operating rooms, and administrative offices all operate simultaneously, each with different levels of access and risk.

Managing security in such an environment requires more than basic surveillance. It requires systems that can adapt to constant movement and provide clear visibility across all areas.

For example, a visitor entering a general waiting area may be appropriate, but the same individual entering a restricted ICU or medication storage area presents a serious risk. Without intelligent monitoring, distinguishing between normal and suspicious activity becomes difficult.

Modern hospital security systems address this by combining video surveillance with access control and real-time monitoring. This allows healthcare administrators to not only control who can enter specific areas but also verify and track activity as it happens.

The result?  A more controlled and transparent environment, which is critical for both safety and compliance.

Protecting Patient Safety and Staff Well-Being

Patient safety is the top priority in any healthcare facility. However, safety risks are not limited to medical issues alone. Security incidents such as unauthorized access, aggressive behavior, or theft can directly impact patient care.

Healthcare workers are also at increased risk - Studies have shown that healthcare professionals face higher rates of workplace violence compared to many other industries. This makes it essential for hospitals to have systems in place that can detect and respond to potential threats quickly.

Smart hospital security systems help mitigate these risks by providing continuous monitoring and real-time alerts. For instance, if unusual activity is detected in a restricted area or if a situation begins to escalate in a waiting room, security teams can be notified immediately.

This ability to respond quickly can prevent incidents from escalating and ensures a safer environment for both patients and staff.

Supporting HIPAA Compliance and Data Protection

Compliance is a critical concern for healthcare organizations. Regulations such as the Health Insurance Portability and Accountability Act (HIPAA) require strict control over access to patient information and sensitive areas.

Physical security plays a major role in compliance. Unauthorized access to records rooms, server areas, or administrative offices can lead to data breaches, which carry significant legal and financial consequences.

A modern hospital security system supports compliance by providing controlled access, detailed activity logs, and audit trails. These features allow organizations to track who accessed specific areas and when, which is essential for audits and investigations. This integrated approach helps ensure that compliance requirements are met while improving overall operational efficiency.

Preventing Unauthorized Access to Critical Areas

Hospitals contain several high-risk zones that require strict access control. These include pharmacies, operating rooms, ICUs, data centers, and storage areas for medical equipment.

Unauthorized access to these areas can result in serious consequences, including theft of controlled substances, tampering with equipment, or exposure of sensitive information.

Traditional systems often rely on static access permissions, which can become outdated as roles change. This creates gaps where individuals may retain access they no longer need.

Smart hospital security systems address this issue by enabling dynamic access control. Permissions can be updated in real time, ensuring that access is always aligned with current roles and responsibilities.

In addition, integrating access control with video surveillance provides an added layer of verification. Administrators can not only see who accessed a door but also confirm the activity visually, reducing the risk of misuse.

Improving Incident Response and Emergency Management

In healthcare settings, response time is critical. Whether it is a security incident, a medical emergency, or an environmental issue, delays can have serious consequences.

Smart security systems improve response time by providing real-time alerts and centralized monitoring. Instead of relying on manual reporting, incidents can be detected automatically and communicated to the appropriate teams immediately.

For example, if an unauthorized entry occurs in a restricted area or if environmental sensors detect abnormal conditions, alerts can be triggered instantly. Security and medical teams can then coordinate their response more effectively.

This level of coordination is especially important in large facilities where multiple departments must work together during emergencies.

Enhancing Operational Efficiency

Beyond safety and compliance, hospital security systems also contribute to operational efficiency.

Manual processes such as maintaining access logs, issuing credentials, and monitoring multiple systems can be time-consuming and prone to errors. As healthcare facilities grow, these inefficiencies become more pronounced.

A centralized security system streamlines these processes by integrating surveillance, access control, and alerts into a single platform. This reduces administrative workload and allows staff to focus on patient care rather than managing systems.

Additionally, data collected from security systems can provide valuable insights into facility usage, helping administrators optimize workflows and resource allocation.

Adapting to Modern Healthcare Challenges

Healthcare is evolving rapidly, and security systems must evolve with it.

Facilities are expanding, patient volumes are increasing, and technology is becoming more integrated into daily operations. At the same time, threats are becoming more sophisticated, requiring a more proactive approach to security.

Smart hospital security systems are designed to adapt to these challenges. They provide scalability, allowing facilities to expand without overhauling their infrastructure. They also support integration with other systems, creating a unified approach to security and operations.

This adaptability is essential for healthcare organizations that want to remain secure and compliant in a constantly changing environment.

FAQs

What are hospital security systems?

  • Hospital security systems are integrated solutions that combine surveillance, access control, and monitoring tools to protect patients, staff, and sensitive areas within healthcare facilities.

Why are smart security systems important in hospitals?

  • They provide real-time monitoring, improve response times, and support compliance with healthcare regulations, making them more effective than traditional systems.

How do these systems support HIPAA compliance?

  • They control access to sensitive areas, maintain detailed logs, and provide audit trails that help meet regulatory requirements.

Can hospitals use existing infrastructure?

  • Yes. Many modern systems are designed to work with existing IP cameras and infrastructure, reducing the need for costly replacements.

Do these systems improve patient safety?

  • Yes. By detecting and responding to risks quickly, they help create a safer environment for patients and healthcare staff.

Conclusion

Healthcare facilities face unique challenges that require more than basic security measures. The combination of high patient volumes, sensitive data, and strict regulatory requirements makes security a critical component of daily operations.

Modern hospital security systems provide the intelligence, integration, and real-time visibility needed to address these challenges effectively. They help protect patients, support staff, ensure compliance, and improve overall efficiency.  Solutions like Coram demonstrate how this can be implemented effectively. Coram’s hospital security platform works with existing IP cameras and integrates with access control systems and environmental sensors. It provides high-definition video monitoring, intelligent alerts, and centralized management, allowing healthcare facilities to maintain visibility and control without replacing their current infrastructure.

As healthcare environments continue to evolve, investing in smarter security systems is not just a technological upgrade. It is a necessary step toward safer, more resilient, and compliant healthcare operations.

About the Authors

Arif Khan is a writer and researcher specializing in AI-driven security systems, healthcare compliance, and modern surveillance technologies. He holds a B.Tech degree in Computer Science and works as a freelance writer covering topics related to AI, physical security, access control, and intelligent monitoring systems. His work focuses on helping organizations understand emerging security technologies and their role in improving safety, compliance, and operational efficiency.

Peter Lee is a writer and researcher specializing in AI-driven security systems and healthcare compliance. His work focuses on topics such as hospital security, HIPAA requirements, and modern surveillance technologies, helping organizations understand and implement effective security solutions.

References

American Institute of Healthcare Compliance (AIHC)

National Library of Medicine (NLM)

Occupational Safety and Health Administration (OSHA)

U.S. Department of Health & Human Services (HHS)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

The Importance of Statistical Significance

Auditing for Compliance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of audit sampling used when Auditing for Compliance, specifically chart or billing audits. It is not intended as being comprehensive, legal, or consulting advice.

Introduction

A statistically significant chart audit in healthcare is a structured, randomized review of medical records designed to project findings onto an entire population of claims (the "universe") with measurable reliability.

The Office of Inspector General (OIG) states these audits be random, unbiased, and sufficiently large to be representative of the population. A common misconception is that a fixed percentage (e.g., 10%) of charts is always sufficient. The OIG does not set a fixed percentage. The sample size must be large enough to provide a reliable estimate of the universe's overpayment amount. A statistically significant chart audit, compliant with OIG guidelines, is a scientifically rigorous process.

In healthcare, audit sampling is crucial when auditing the entire population (100% of claims) is impractical due to high volume. A "statistically valid" sample differs from a simple "probe" or arbitrary sample (e.g., 10 charts) because it allows for the projection of error rates onto the larger population. A statistically valid sample is necessary for:

  • Provider Self-Disclosure Protocol: Submitting self-audits to the OIG.
  • Corporate Integrity Agreements (CIAs): Mandatory compliance for providers under investigation.
  • External Audits: Rebutting audits from Unified Program Integrity Contractors (UPICs) or Medicare Administrative Contractors (MACs).

Even your routine audits should be grounded as statistically significant, which is fundamental when auditing a healthcare organization for compliance. Taking this approach transforms subjective chart reviews into defensible, objective, and scalable evidence that can be used to prove compliance. government agencies.

Statistical significance provides the necessary confidence, typically 90% or higher, that findings from a small sample accurately represent the entire population, minimizing the risk of false positives. Experts often check if the auditor used an appropriate one-sided 90% confidence level, which is a common standard in these audits.

The confidence level defines how often the true population value (e.g., total overpayment) falls within the range calculated from the sample. The precision (Margin of Error) defines the range of accuracy around the point estimate (e.g., +/- $10,000). The trade-off is a higher confidence level (e.g., 99%) which usually requires a wider range of precision, or a significantly higher sample size to maintain precision.

Legal and Regulatory Defensibility

  • Mandatory for Extrapolation - Government contractors, such as Recovery Audit Contractors (RACs), Unified Program Integrity Contractors (UPICs) and Department of Health and Human Services (HHS) Office of Inspector General (OIG) Office of Audit Services, require statistical sampling for projecting overpayment amounts. If an audit lacks statistical significance, it cannot be legally extrapolated to the total claim population.
  • Rebuttal of Audit Findings - Organizations can use statistical expert testimony to challenge improper sampling methods used by auditors, as flawed sampling often leads to inflated repayment demands. Core areas challenged by experts are:
    • Improper Audit Universe/Frame: Auditors may fail to define the correct population of claims, including irrelevant claims or excluding relevant, paid-in-full claims that would balance the error rate.
    • Lack of Randomization/Bias: Experts look for patterns showing the sample was not truly random, such as a sample mean paid amount dramatically higher than the universe mean, indicating a biased selection.
    • Failure to Account for Underpayments: A common, frequently successfully challenged error is the failure of auditors to include underpayments, which skews the audit and "significantly" overstates the overpayment.
    • Imprecise Extrapolation: Even if a sample is random, it may be too small or produce a wide confidence interval (high imprecision), making the projection highly unreliable.
    • Failure to Replicate: Government auditors often fail to document their work sufficiently, making it impossible to reproduce the sample or calculations.
  • Lower Bound Calculation - Statistical methods (like Rat-Stats) calculate the lower limit of a 90% confidence interval, ensuring that recoupment amounts are statistically defensible and conservative.
    • OIG RAT-STATS is a free statistical software package created by the Office of Inspector General (OIG) that provides a "rock-solid," defensible foundation for auditing healthcare claims. It is used to generate random samples, determine sample sizes, and extrapolate error rates to entire populations. It is widely used by auditors, and often by providers in corporate integrity agreements.
    • While RAT-STATS is user-friendly, it requires a thorough understanding of statistics and the software itself to use it properly and to challenge, if necessary, the findings of an audit.

Ensuring Accuracy in Large Datasets

Statistical tools calculate the minimum required sample size (often at least 30 but higher depending on variance) to ensure that the audit has enough power to detect errors without wasting resources on excessive, manual review.

It is important to mitigate potential bias. Statistical sampling prevents "judgmental sampling," where auditors might only select high-dollar or potentially erroneous claims, which would falsely inflate the error rate. To achieve this, we need to address the confidence interval.

Key Components of an Audit Confidence Interval

We strive to reduce "false positives." A 95% confidence level indicates that there is only a 5% chance that observed deviations in documentation or billing were due to random chance, rather than a systematic compliance failure. Let’s dive a little deeper into the confidence level and margins of error.

  • A confidence level (e.g., 95%) is the reliability of the sampling method. A 95% confidence level means that if the audit were repeated 100 times, 95 of the resulting intervals would contain the true population value. Applying a 90% confidence level is a common requirement for CMS contractors to use as a basis for extrapolation.
  • Precision refers to the margin of error or the width of the interval. A tighter (narrower) interval means more precise results, often requiring a larger sample size. Larger samples shrink the confidence interval, providing higher precision. A higher confidence level (e.g., 99% instead of 95%) makes the interval wider (less precise) because you are trying to be more certain.
  • Upper/Lower Limits are the boundaries of the interval, providing the "best-case" and "worst-case" scenario for errors. In healthcare audits, particularly those involving billing compliance, overpayment extrapolation, and quality of care, upper and lower limits define the range of plausible values for a population parameter (such as total overpayment) with a set level of confidence (typically 90% or 95%).
    • Lower Limit (LL): The lowest expected value of the confidence interval. In many CMS audits, the lower limit of a one-sided 90% confidence interval is used to determine the minimum amount of overpayment to be recouped.
    • Upper Limit (UL): The highest expected value of the confidence interval. It represents the worst-case scenario for error rates.
    • Confidence Interval (CI): The full range between the Lower and Upper Limit. A narrower interval indicates higher precision.

Key Statistical Concepts for Auditors

Confidence Levels: The percentage of times (e.g., 90% or 95%) that the true value of an error is expected to fall within the calculated confidence interval.

Null Hypothesis (H0): The assumption that there is no meaningful difference between the audited sample and the expected (compliant) standard.

P-Value: The probability that results were produced by chance. A low p-value (typically $p<0.05$) allows the auditor to reject the null hypothesis and conclude a real, significant error pattern exists.

Randomized & Unbiased: Every claim in the universe must have an equal chance of selection.

Representative: The sample must reflect the characteristics of the entire population.

Standard Deviation: Measures the variation in the data; higher variance in claims requires a larger sample size to achieve statistical significance.

Statistically Valid & Replicable: Another auditor using the same methodology should arrive at similar results.

Universe Definition: The specific time period, the provider, and types of claims being audited (CPT code range 99212-99215 from Jan-Dec 2025).

Limitations to Consider

  • Not Always Meaningful: A statistically significant result (due to a large sample size) does not always mean the error is clinically or financially important.
  • Small Populations: When auditing small departments, high variation may lead to non-significant results, even if errors are present.
  • Requires Expertise: Misapplication of statistical formulas can create misleading conclusions; statistical literacy is crucial for compliance officers.

General Rules of Thumb - When full statistical calculation is not possible, industry guidelines offer the following benchmarks:

  • Small Populations (<100): Audit all records (100% sampling).
  • Large Populations: 10% of the total eligible charts, up to a maximum of 1000, is often sufficient.
  • Rapid Cycle Sampling: Small, consecutive samples (e.g., 5-10 charts) can be used to track changes over time in quality improvement projects and for monitoring purposes.

Conclusion

It’s all about measuring the effectiveness of your compliance program

The effectiveness of the compliance program must identify high-risk patterns. Organizations use statistical significance to track if voluntary changes to coding or billing procedures resulted in significant, measurable reductions in error rates. Taking this approach allows the organization to determine if corrective actions, such as training, efforts to correct Electronic Health Record systems, conducting pre-billing targeted audits, etc. are making the expected improvements required for compliance.

Statistical techniques allow internal auditors to identify trends in data, such as high-frequency billing of complex codes, which indicate potential risk for future external audits.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

CDC

National Library of Medicine

Strategic Management Services

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
Corporate Compliance, HIPAA

The Hidden Risk in Multi Site Healthcare

When Visibility Fails, Compliance Follows 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

This article is for reference regarding risk management in healthcare, which is a complex topic and posted for educational purposes only. It is not intended as consulting or legal advice.

Introduction

Managing multiple healthcare facilities within a single organization has evolved from an operational responsibility to a complex enterprise risk function. As organizations expand across regions, states, and service lines, the ability to maintain consistent compliance, ensure patient safety, and protect financial performance becomes increasingly difficult without structured oversight.

For compliance and risk leaders, multi-site operations present a unique challenge. The risk is not limited to regulatory requirements or operational variability. The greatest risk is the loss of visibility. When leadership cannot clearly see what is occurring across sites in real time, issues are often identified only after they have already impacted patient care, compliance status, or revenue.

Recent federal guidance and national studies reinforce that multi-site risk is driven less by geographic dispersion and more by the absence of standardized oversight, integrated data, and structured accountability.¹ To manage multi-site healthcare environments effectively, organizations must move beyond decentralized oversight and adopt systems that promote accountability, visibility, and coordinated enterprise governance. Without these elements, growth introduces fragmentation rather than scalability.

The Risk Profile of Multi Site Healthcare Organizations

Multi-site healthcare organizations operate within a heightened risk environment driven by scale, variability, and complexity. While these risks are often described broadly, they consistently concentrate on specific operational and compliance areas that require targeted oversight. A primary risk is inconsistent application of regulatory requirements. Organizations governed by entities such as the Centers for Medicare & Medicaid Services and the Health Resources and Services Administration must ensure that standards related to documentation, billing, scope of services, and program integrity are applied uniformly across all locations. Variability in interpretation or execution increases the likelihood of audit findings, repayment exposure, and regulatory scrutiny.

Operational fragmentation is another critical concern. When sites operate with varying processes, undocumented workarounds, or informal practices, organizations lose the ability to ensure consistency and control. Over time, these inconsistencies evolve into systemic risk. Data fragmentation further compounds this issue. Without integrated systems, leadership lacks a reliable, centralized source of truth. This limits the organization’s ability to identify trends, monitor performance, and detect emerging risks before they escalate. Workforce variability also contributes to risk exposure. Differences in training, leadership capability, and staffing stability across sites directly affect compliance adherence, documentation quality, and patient safety outcomes.

Recent patient safety research demonstrates that breakdowns in communication, leadership engagement, and reporting culture are directly associated with lower safety performance and reduced incident reporting across healthcare organizations.²  In multi-site environments, these risks are amplified when leadership relies on inconsistent or anecdotal reporting rather than standardized enterprise data. Finally, delayed escalation of issues remains a persistent vulnerability. Without clear reporting structures and accountability, compliance concerns, incidents, and near misses may remain localized rather than addressed at the enterprise level.

High Risk Areas and Required Compliance Controls

Effective organizations do not manage multi-site risk at a high-level. They identify specific exposure areas and implement structured controls tied directly to those risks.

Documentation, Coding, and Billing Integrity - Variability in documentation and coding practices is one of the most significant sources of compliance exposure. Even with established policies, differences in provider behavior and oversight result in inconsistent application of requirements. Common risk patterns include insufficient documentation to support medical necessity, inconsistent use of modifiers, and failure to accurately capture services rendered. Across multiple sites, these inconsistencies increase audit vulnerability and repayment risk.

Administrative complexity and reliance on inconsistent workflows further increase risk and inefficiency across organizations. To mitigate this risk, organizations should implement centralized revenue integrity oversight, supported by routine pre and post billing audits. Documentation standards must be clearly defined and reinforced through targeted education tied directly to audit findings. Coding accuracy should be monitored through both random and focused audits, particularly in high-risk service lines. Transparent reporting of audit results reinforces accountability at both the provider and site level.

Sliding Fee Scale and Program Eligibility - For federally funded organizations, sliding fee scale compliance remains a critical risk area. Inconsistent eligibility determinations, failure to conduct required reevaluations, and inadequate documentation create exposure during audits and operational site visits. Organizations should implement standardized eligibility workflows supported by system controls that prevent incomplete processing. Routine audits should validate both documentation and application of discounts. Staff responsible for eligibility should receive structured training with defined competency expectations, and monitoring should include both process adherence and outcome accuracy.

Credentialing, Licensure, and Enrollment - Maintaining accurate credentialing and enrollment across multiple sites is operationally complex and highly regulated. Risks include expired licenses, services rendered prior to enrollment approval, and misalignment between credentialing records and payer systems. National credentialing standards emphasize ongoing monitoring, sanction checks, and oversight of delegated credentialing activities, particularly in multi-state environments.³

Centralized credentialing systems with automated alerts are essential. Organizations should maintain a single, validated source of provider data that is routinely reconciled with payer enrollment records. Pre-service verification processes should confirm that providers are eligible to render services. Routine audits should ensure alignment across credentialing, privileging, and enrollment data.

Patient Safety and Incident Reporting - Inconsistent reporting of incidents and near misses across sites creates significant patient safety and compliance risk. When reporting varies by location, organizations lose the ability to identify systemic issues. Recent studies highlight that organizations with stronger reporting cultures and leadership engagement demonstrate improved safety outcomes and increased event reporting.²

Centralized incident reporting systems should be implemented across all sites, with clearly defined expectations for reporting. Leadership must reinforce a culture that supports transparency and non-punitive reporting. Data should be trended at the enterprise level, and corrective actions should be tracked to completion. Regular leadership review ensures accountability and sustained improvement.

Data Integrity and Reporting - Reliable data is essential for effective oversight. In multi-site environments, inconsistent data definitions, delayed reporting, and lack of validation undermine decision making. Organizations should establish formal data governance structures that define standards, ownership, and validation processes. Standardized dashboards should be implemented across sites to ensure consistency in reporting. Data should be routinely reconciled across systems, and key risk indicators should be monitored consistently. Research indicates that dashboards are most effective when designed to drive action rather than simply display information.⁶

Workforce Competency and Training - Variability in workforce training directly impacts compliance and operational performance. Inconsistent onboarding, lack of role specific education, and high turnover create gaps in knowledge and execution. Standardized onboarding programs with defined competencies should be implemented across all sites. Ongoing training should be required and tracked, with reinforcement tied to identified risk areas. Competency should be validated through assessments and audit results to ensure effective application.

Vendor and Third-Party Oversight - Reliance on third party vendors introduces additional compliance and operational risk. Lack of visibility into vendor practices and misalignment with regulatory requirements can create exposure. Organizations should implement formal vendor risk management programs that include due diligence, clear contractual expectations, and ongoing performance monitoring. Vendors should be evaluated against defined compliance standards and subject to periodic audits. Contracts should clearly define accountability and regulatory obligations.

Enterprise Visibility and Remote Oversight

The most significant risk in multi-site operations is not complexity but lack of visibility. In organizations where leadership is remote or geographically dispersed, reliance on informal updates creates delayed awareness of risk. Federal compliance guidance emphasizes structured oversight, including risk assessments, auditing, monitoring, and board level reporting.¹ Organizations should establish a single enterprise view of risk that includes credentialing status, billing trends, patient safety events, training compliance, and corrective action tracking. Visibility must be standardized, real time, and actionable.

Accountability as an Enterprise Expectation - Accountability must be clearly defined and embedded at every level of the organization. Each site should have designated leadership responsible for compliance, quality, and operational performance, with measurable expectations aligned to enterprise standards. Research demonstrates that leadership structure and accountability directly influence safety culture, communication, and organizational performance. ⁵ Performance management should incorporate compliance metrics alongside operational goals. Enterprise leadership must maintain oversight through routine review of site performance, clear escalation pathways, and enforcement of corrective actions.

Systems, Monitoring, and Enterprise Oversight - Systems function as the infrastructure that supports compliance and risk management across multiple sites. Centralized platforms for audit tracking, incident reporting, credentialing, and performance monitoring provide the foundation for effective oversight. Monitoring should be continuous and risk based. Routine audits, data validation, and trend analysis allow organizations to identify patterns across sites and intervene proactively. Early warning indicators should be established to trigger action before risks escalate. Effective oversight requires translating data into action through structured governance and consistent follow through.

Addressing Blind Spots Through Validation and Culture

Blind spots represent one of the most significant risks in multi-site environments. These include underreported incidents, undocumented workarounds, and gaps in training that are not captured through standard reporting. Organizations must validate reported data through independent audits, direct observation, and cross site comparison. Identifying outliers often reveals underlying risk. Equally important is fostering a culture of transparency. Staff must feel supported in reporting concerns, and leadership must respond consistently to reinforce trust in reporting mechanisms.

Supporting Organizational Growth While Managing Risk

Growth must be supported by infrastructure and oversight. Research suggests that organizations that standardize core processes before expansion achieve more sustainable outcomes. ⁷ Organizations should ensure that systems, processes, and staffing models are scalable prior to expansion. Centralized governance should remain intact while allowing for controlled local execution. Data driven decision making should guide expansion, resource allocation, and performance improvement.

Conclusion

Managing multiple healthcare facilities requires a structured and deliberate approach to risk, compliance, and operational oversight. Multi-site environments introduce significant exposure across regulatory, clinical, operational, and financial domains. Across federal guidance and recent healthcare research, a consistent theme emerges. Multi-site success is driven by standardized visibility, structured accountability, integrated compliance controls, and proactive monitoring.¹ ² ³

Organizations that succeed invest in visibility, enforce accountability, and implement integrated systems that allow leadership to monitor performance in real time. By identifying specific risk areas and implementing targeted controls, organizations can reduce compliance exposure, strengthen patient safety, and support sustainable growth. In multi-site healthcare operations, risk is not created by scale alone. It is created by the absence of structure. Visibility, accountability, and systems remain the foundation of effective governance and long-term success.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Ms. Bertholette Pardieu, MPH, CCEP, OHCC is an accomplished compliance and risk leader with over a decade of experience developing and strengthening enterprise-wide compliance, governance, and risk programs across highly regulated healthcare sectors, including FQHCs, PBMs, and Medicare/Medicaid organizations. She currently serves as the Director of Risk Management & Corporate Compliance Officer for Broward Community & Family Health Centers, Inc. (the largest Federally Qualified Health Center in Broward County), overseeing risk, compliance and governance for a $16.4M multi-site FQHC system serving more than 13,000 patients. Previously, she led enterprise compliance risk initiatives at Convey Health Solutions, where she built the company’s first compliance risk program, directed effectiveness audits, and enhanced vendor oversight for national health plans.

A trusted advisor to executives and boards, Ms. Pardieu is known for her strategic mindset, collaborative leadership, and ability to embed compliance into organizational culture to protect against regulatory and operational risk. She holds a Master of Public Health from Florida International University and a Bachelor of Science from Barry University. Ms. Pardieu is a Certified Healthcare Compliance Officer (OHCC), with additional credentials including certifications in Corporate Compliance & Ethics and Healthcare Risk Management; and is a recent graduate of the Women’s Executive Leadership Accelerator Program through the Inclusion Learning Lab.

References

1. U.S. Department of Health and Human Services, Office of Inspector General
    General Compliance Program Guidance (2023)
    * Direct PDF (Full Guidance):
      
https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf
    * Official OIG Overview Page:
      
https://oig.hhs.gov/compliance/general-compliance-program-guidance/
2. Agency for Healthcare Research and Quality (AHRQ)
    Patient Safety Culture and Workforce Safety
    * 
https://psnet.ahrq.gov/perspective/ensuring-patient-and-workforce-safety-culture-healthcare
3. National Committee for Quality Assurance (NCQA)
    Credentialing Standards
    * 
https://www.ncqa.org/programs/health-plans/credentialing/benefits-support/standards/
4. Council for Affordable Quality Healthcare (CAQH)
    2023 CAQH Index Report
    * 
https://www.caqh.org/hubfs/43908627/drupal/2024-01/2023_CAQH_Index_Report.pdf
5. National Library of Medicine (PubMed)
    Leadership and Patient Safety Culture Systematic Review
    * 
https://pubmed.ncbi.nlm.nih.gov/41507881/
6. Journal of the American Medical Informatics Association (JAMIA Open)
    Healthcare Dashboard Effectiveness Study
    * 
https://academic.oup.com/jamiaopen/article/8/4/ooaf078/8214040
7. National Institutes of Health (PubMed Central)
    Healthcare Leadership Complexity and System Growth
    * 
https://pmc.ncbi.nlm.nih.gov/articles/PMC11223336/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Measuring Audit Results

Why Statistical Literacy is Crucial for Auditors 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of common statistical terminology used when Auditing for Compliance and not intended as being comprehensive, legal or consulting advice.  Please consult a professional for more information regarding the importance of using statistical measures for your healthcare organization. 

Why Is This Important When Software Generates the Statistics?

It is essential for chart auditors to understand statistical terms even when software generates the statistics because automated tools cannot interpret context, detect hidden biases, or make judgment calls regarding data quality.

While software speeds up the analysis of large datasets, an auditor's understanding of statistics is required to validate that the results are meaningful, accurate, and truly answer the audit's objective rather than just identifying coincidental correlations.

Advantages of Using AI - Artificial intelligence (AI) and software tools are transforming medical chart audits from infrequent, retrospective sampling into continuous, comprehensive, and automated processes. These tools primarily utilize Natural Language Processing (NLP) and Machine Learning (ML). AI integrates with electronic health records (EHRs) to analyze 100% of patient records continuously, rather than relying on limited retrospective samples, providing the ability to identify documentation gaps (such as missing signatures, late entries, unsupported coding), coding errors, and compliance risks in real-time.

Advanced, AI-enabled health information systems can now analyze raw, disparate data from Electronic Health Records (EHR)—including clinical notes, lab results, and patient-reported metrics—to automatically calculate complex health scores like Metabolic Equivalents (METs) and identify declining kidney function.

AI-driven tools identify patterns of documentation errors, allowing auditors to proactively manage risks related to payer audits and recoupments or situations which can trigger investigative external audits.

Human Review is Necessary

Statistical software works on the principle "garbage in, garbage out" (GIGO). Auditors must know if the data was collected properly, if there are missing values, and if the data is skewed, as automated tools may process flawed data without flagging it.

Auditors ensure data integrity – that the data accurately reflects the patient encounter or financial transaction before software analyzes it. Understanding statistical distribution helps auditors know when a simple "average" is misleading and when they need to look at the median or standard deviation.

Then there is the importance of contextual interpretation. Human auditors are better at interpreting the context and intent of a clinical note, such as differentiating "CTA" (clear to auscultation) from "CTA" (CT-angiogram) based on the surrounding narrative. Also, auditors can integrate information not explicitly written together in a single section. It is important to insert the human factor because auditors can spot subtle indicators or nuance not easily quantifiable by algorithms.

Risk Oversight - Ethical and Regulatory Accountability

Human oversight is crucial to prevent the "black box" problem where AI makes decisions without transparency, mitigating potential bias in automated audit systems. It prevents algorithmic bias and "automation complacency" where humans over-rely on AI.

By keeping human judgment in the loop, especially when auditing complex datasets or making critical decisions, the integrated process ensures the logic behind a decision is interpretable, transparent, and legally sound.

Importance of Statistical Literacy

Compliance should be the focus of all your audit functions. Measuring where you are now and improvements achieved is accomplished by applying statistics to understand data collected during the baseline audit and subsequent audits over time.

In healthcare chart audits, statistics are primarily used to summarize coding, billing and documentation compliance as well as clinical performance, identify variations in care, and determine if quality improvement (QI) initiatives are successful. These audits rely on both basic descriptive measures and more specialized tools for monitoring trends.

Auditors use descriptive statistics to summarize data and describe the basic features of a set of patient records. Instead of reading hundreds of individual charts, auditors use these "snapshots" to see the big picture—like how well a clinic is following safety rules or what the "typical" patient looks like. Common techniques include frequency distribution, percentages, and proportions to assess compliance with rules, regulations and reimbursement standards. Visual tools such as bar charts, histograms, and run charts analyze trends over time, providing a visual illustration of the data.

Key Statistical Measures Auditors Should Know

Statistics provide a "snapshot" of performance, helping to identify areas for improvement in clinical care, documentation accuracy, and compliance without making broad generalizations about the entire population. Here are the most common descriptive statistics used in healthcare audits explained in simple terms:

Finding the Middle or Central Tendency (the “typical”)

Used to find the average or typical value in audit data. Auditors use these to identify the most common or "average" value in a group of charts. These statistics help identify the center or "middle" of the data set. Terminology associated with central tendency are:

  • Mean (average): The average value, calculated by adding all values and dividing by the total count. The sum of all values divided by the number of cases. It helps identify the average performance, such as the average length of stay.
  • Median (middle value): The middle value, often used to avoid skewing data with extreme outliers, especially in run charts. For instance, let’s say you have 5 patients waiting 10, 15, 20, 25, and 100 minutes to see the provider. The mean is 34 ((10+15+20+25+100)/5), but the median is 20. The median is better for spotting typical patient experience when a few outliers (like the 100-minute patient) skew the average.
  • Mode (most common value in the data set): The most frequently occurring data point. The mode helps auditors identify anomalies. If a provider's billing pattern shows a "mode" that differs significantly from peers (e.g., almost all visits are coded as complex), it serves as a red flag for review.

Measures of Dispersion (Variability or Spread)

Measures of Dispersion (also known as variability or spread) in a chart audit tell you how consistent or scattered your data is. While the average (mean) tells you where the center of the data is, the dispersion tells you if most records are close to that average or wildly different.

In a chart audit, high dispersion often means high variability in clinical practice, which might suggest a need for better standardization (e.g., in documentation, timing of care, or drug dosages).

  • Standard Deviation (SD): Measures the spread of data; a small standard deviation indicates data is tightly clustered around the mean. – An example – if the average audit score was 90% with an SD of 5% means most charts fall between 85% and 95%. SD is the most common, precise measure, but best used when data is roughly bell-shaped (normally distributed).
    • Low SD = Data is consistent (most nurses/doctors documenting similarly).
    • High SD = Data is inconsistent (wide variation in practice).
  • Range & Interquartile Range (IQR): Identifies the highest/lowest values and the spread of the middle 50% of the data. Excellent for skewed data or when you have outliers, as it ignores the extreme top and bottom, focusing on the "typical" records. It is a robust method identify the "normal" range of data while excluding extreme outliers that might skew results.

In a chart audit, high dispersion often means high variability in clinical practice, which might suggest a need for better standardization (e.g., in documentation, timing of care, or drug dosages). In summary, dispersion tells you if your performance is reliable (low spread) or unreliable (high spread).

Frequency & Proportions

Frequency and Proportions are the two primary, simple statistics used to turn raw medical record data into actionable information. Frequency measures how often a specific event, behavior, or error occurs in a set of charts. It is a simple raw number or count. Proportions (often presented as percentages) measure the frequency relative to the whole. It tells you what part of the total population or sample had the characteristic, rather than just the raw count.

  • Frequency Distribution (Raw Count): Illustrates how often specific criteria are met. Frequency is simply counting how many times something happened. It tells you the total volume.
    • Example: You audit 50 charts to see if doctors signed their notes. You find that 40 charts have signatures. The frequency? 40.
  • Proportion (Percentages): Used to define compliance rates (e.g., % of charts with documented allergies). Proportion puts that count into context by comparing it to the total. It tells you the "score" or the rate of success.
    • The Formula: (Number of times it happened) ÷ (Total number of charts checked). Example: Using the same 50 charts, you take the frequency (40) and divide it by the total (50). The Proportion? 0.80 or 80%.
  • Why use both?
    • Frequency is great for understanding workload (e.g., "We had 100 falls this month").
    • Proportion is better for measuring quality (e.g., "Only 2% of our patients had falls").

If you check 10 charts and find 5 errors, the frequency is low (only 5), but the proportion can be horrifying (50%).

Conclusion

Compliance auditors must understand audit statistics to ensure their findings are defensible, accurate, and scalable. A firm grasp of statistical concepts allows auditors to identify high-risk patterns of non-conformance while minimizing the risk of "false positives".

Furthermore, when regulatory bodies like CMS or the OIG perform audits, they often use extrapolation to project error rates into massive financial recoupments; an auditor who understands the underlying math can effectively validate or challenge these high-stakes calculations

For more information, consider enrolling in the Auditing for Compliance online course. Tuition includes online, proctored certification to earn your Certified Healthcare Auditor (CHASM) credential.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with  Officer of the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor and investigator in the healthcare field.

References

American Institute of Healthcare Compliance

National Library of Medicine – Descriptive Statistics

Purdue University – Descriptive Statistics

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Burnout, Boundaries, and Compliance
Leadership

Beyond Burnout

Workforce Ethics as Enterprise Risk and the Compliance Cost of Moral Injury 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

Introduction 

Workforce ethics, moral injury, and sustainability have emerged as critical compliance, governance, and patient safety concerns across the healthcare industry. Persistent staffing shortages, increased demand for services, and constrained resources have shifted workforce wellbeing from a human resources issue to an enterprise risk with direct implications for regulatory compliance, quality of care, and organizational stability.

For healthcare compliance and ethics leaders, understanding the relationship between workforce ethics and system performance is essential. Ethical strain within the workforce undermines reporting mechanisms, weakens compliance controls, and increases the likelihood of patient safety events. Addressing these challenges requires structured, organization-wide strategies that are deliberately integrated into governance, ethics, and risk management frameworks rather than addressed through isolated or informal efforts.

The Ongoing Workforce Crisis in Healthcare

Healthcare professionals across clinical and administrative roles continue to face escalating pressures. Chronic staffing shortages, burnout, high turnover, and increasing productivity expectations have become widespread across healthcare settings. These pressures are often accompanied by ethical conflicts that arise when professionals are unable to provide the level of care they believe patients require due to systemic constraints such as limited staffing, time pressures, or resource scarcity.

When healthcare workers repeatedly encounter situations where organizational limitations conflict with professional values, moral distress develops. If unaddressed, moral distress can progress into moral injury, which manifests as emotional exhaustion, disengagement, loss of trust in leadership, and withdrawal from organizational values. These outcomes directly affect workforce stability and compromise compliance processes, quality oversight, and patient safety initiatives.

Why Workforce Ethics Matters to Compliance and Risk

From a compliance and risk management perspective, workforce instability creates cascading organizational risk. Burnout and disengagement increase the likelihood of patient safety events, documentation errors, incomplete reporting, and breakdowns in adherence to policies and procedures. A workforce under sustained ethical strain is also less likely to participate meaningfully in compliance training, reporting mechanisms, and quality improvement activities.

Regulators and accrediting bodies increasingly assess organizational culture, leadership responsiveness, and staff engagement as part of broader evaluations of compliance effectiveness. As a result, compliance programs that fail to account for workforce ethics risk overlooking a key driver of regulatory exposure and patient harm.

To address this risk, compliance leaders should formally incorporate workforce ethics and moral injury into compliance risk assessments. Indicators such as turnover trends, vacancy duration, overtime utilization, safety event patterns, and ethics reporting activity provide valuable insight into ethical strain and emerging compliance vulnerabilities. Presenting these risks to executive leadership and boards alongside traditional compliance risks reinforces accountability and ensures appropriate mitigation strategies are implemented.

Workforce Sustainability as an Enterprise Risk

Workforce sustainability reflects an organization’s ability to maintain a stable, engaged, and ethically supported workforce over time. It extends beyond recruitment and retention efforts and encompasses leadership accountability, governance oversight, and organizational culture. Persistent workforce instability leads to diminished productivity, loss of institutional knowledge, increased reliance on temporary staffing, and escalating recruitment and onboarding costs. These challenges create financial strain and operational disruption, reinforcing the need to integrate workforce sustainability into enterprise risk management and governance structures.

Treating workforce ethics as an enterprise risk enables organizations to assign risk ownership, monitor trends over time, and implement corrective actions before issues escalate into regulatory or patient safety events.

Ethical Obligations and Moral Injury in Healthcare Compliance

Healthcare compliance programs are grounded in ethical principles that emphasize integrity, accountability, transparency, and patient-centered care. Moral injury represents a significant ethical risk because it undermines the ability of healthcare professionals to uphold these principles consistently. Compliance and ethics leaders have an obligation to recognize moral injury as an organizational issue rather than an individual failing. Ethical standards and regulatory expectations require healthcare organizations to foster environments where ethical concerns can be raised without fear of retaliation and where leadership responds meaningfully to those concerns. When ethical distress is ignored or minimized, trust in reporting mechanisms erodes, weakening compliance effectiveness and increasing organizational risk.

To strengthen ethical oversight, compliance leaders should establish clear ethics escalation pathways that are distinct from human resources or disciplinary processes. Providing staff with trusted avenues to raise ethical concerns outside of traditional human resources channels reinforces psychological safety and supports early identification of systemic issues that may impact compliance and patient care.

Ethical Support Structures That Strengthen Compliance

Healthcare organizations are increasingly implementing structured mechanisms to address workforce ethics and moral injury. When designed intentionally, these supports function as preventive and detective controls within compliance and quality frameworks. Moral distress rounds provide facilitated opportunities for staff to discuss ethically challenging situations in psychologically safe settings. When formalized through policy, documented appropriately, and reviewed at an aggregate level, these sessions help identify systemic challenges, promote consistent and ethical decision making, and inform leadership responses aligned with organizational values and regulatory expectations.

Ethics consultation services support staff and leadership in navigating complex ethical dilemmas related to patient care, resource allocation, or conflicting obligations. These services promote thoughtful decision making, consistent documentation, and alignment with ethical and regulatory standards. Wellbeing and resilience initiatives also contribute to workforce sustainability when they are integrated with ethics, compliance, and quality efforts. Effective programs address structural drivers of distress such as workload, staffing models, and leadership support rather than placing responsibility solely on individual coping strategies.

The Role of Compliance and Ethics Leadership

Compliance and ethics leaders play a critical role in elevating workforce ethics and moral injury from individual experiences to enterprise risk indicators. This includes integrating workforce ethics into compliance risk assessments, monitoring trends related to turnover, reporting activity, and safety events, and embedding ethical workforce considerations into auditing and monitoring activities. By doing so, compliance programs can identify early warning signs of ethical strain before they result in patient harm or regulatory exposure.

Leadership accountability is essential to sustaining ethical workforce support. Compliance leaders should partner closely with human resources, clinical leadership, quality, and safety teams to ensure workforce ethics risks are addressed through coordinated and sustainable interventions rather than isolated initiatives. This collaboration supports alignment between operational realities and ethical expectations.

In addition, compliance and ethics leaders should ensure workforce ethics risks are elevated through formal governance channels. Regular reporting to executive leadership and boards should include workforce-related risk trends, mitigation efforts, and outcomes. Providing leadership with clear, actionable data reinforces accountability and supports informed decision making. By reinforcing non-retaliation protections, promoting psychological safety, and modeling transparency, compliance leaders help sustain trust in reporting mechanisms and ensure workforce ethics remains an organizational priority.

Ethical Workforce Wellbeing and Safer Patient Care

Ethical workforce wellbeing is a critical driver of patient safety and compliance effectiveness. When healthcare professionals feel supported in navigating ethical challenges, they are more likely to report concerns, document accurately, and adhere to policies. Sustained ethical strain increases the risk of errors, underreporting, disengagement, and regulatory exposure.

Compliance leaders should treat ethical workforce wellbeing as an enterprise risk rather than an individual resilience issue.

Integrating workforce ethics indicators into compliance and patient safety monitoring allows organizations to identify systemic drivers of risk. Trusted reporting mechanisms, leadership accountability, and alignment of wellbeing initiatives with compliance and patient safety objectives ensure ethical workforce wellbeing functions as a protective control that supports safer patient care and long-term organizational sustainability.

Conclusion

Workforce ethics, moral injury, and sustainability represent one of the most significant risk areas facing healthcare organizations today. Staffing shortages, burnout, and ethical conflict threaten compliance effectiveness, patient safety, and financial performance. By integrating workforce ethics into compliance risk assessments, governance structures, and ethical support mechanisms, healthcare organizations can proactively address moral injury, support their workforce, protect patients, and strengthen long-term organizational resilience.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Bertholette Pardieu, MPH, CCEP, OHCC is the Director of Risk Management and Corporate Compliance Officer at Broward Community and Family Health Centers, Inc., the largest Federally Qualified Health Center in Broward County. She has over a decade of experience leading enterprise-wide healthcare compliance, risk management, privacy, and governance programs across highly regulated environments, including FQHCs and Medicare and Medicaid systems. Her work focuses on integrating ethics, workforce sustainability, and patient safety into compliance and enterprise risk management frameworks. She regularly advises executive leadership and boards on regulatory strategy, organizational risk, and ethical governance. Bertholette earned her Office of Healthcare Compliance, Certified (OHCC) through the American Institute of Healthcare Compliance, a licensing/certification partner w/CMS.

References

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

42 CFR Part 2 HIPAA Alignment Update

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

By February 16, 2026, all HIPAA-covered entities—including healthcare providers, health plans, and healthcare clearinghouses—that create, receive, or maintain Substance Use Disorder (SUD) records subject to 42 CFR Part 2 must update their Notice of Privacy Practices (NPP). The update requires clearly detailing enhanced protections for SUD records. The information in this AIHC update is not legal or consulting advice, but for educational purposes to prompt compliance.

Does this new rule apply to my organization?

Yes, it can, but this requirement is specifically targeted at those handling Part 2 records. Entities must ensure their websites and privacy policies reflect these changes by February 16, 2026. Covered entities, including health plan sponsors and providers, must align their notices with the new, stricter privacy rules for sensitive SUD information by this date.

Tips to Update Your NPP

The NPP must contain the elements, information and statements specified in 45 CFR 164.520 and must include a specific header, a description of permitted uses/disclosures (treatment, payment, operations), individual rights, covered entity duties, and contact information for complaints.

It must be provided by the first service date and, as of February 16, 2026, align with updated substance use records regulations.

Key elements mandated by 45 CFR 164.520 include: 

  • Required Header: A specific statement regarding how medical information is used and the patient's rights.
    • i.e., “THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.”1
  • Permitted Uses and Disclosures: A detailed description of how the covered entity may use or disclose Protected Health Information (PHI) without the patient’s written authorization,2 including for treatment, payment, and healthcare operations.
  • Individual Rights: Information on the right to access, amend, request restrictions, receive confidential communications, and receive an accounting of disclosures.
    • A statement that other uses or disclosures will only be made with the individual’s authorization, and that the individual has the right to revoke her/his authorization subject to certain limitations.3
    • A summary of certain specified rights the individual has concerning his/her information.4
  • Covered Entity Duties: Statements confirming the entity's responsibility to protect privacy, provide notice of privacy practices, and abide by the terms of the notice.
  • Complaints Procedure: Instructions on how individuals can file complaints with the covered entity or the Secretary of Health and Human Services (HHS).
  • Contact Information: A designated person or office to contact for further information.
  • Effective Date: The NPP’s effective date.5
  • Special Considerations: Specific language regarding the restriction of uses/disclosures for underwriting purposes, the sale of PHI, and marketing, as well as updated, clearer descriptions regarding substance use disorder records.
  • Posting the Notice: The NPP must be prominently posted on the entity's website and physically at the service location by February 16, 2026 and, for plans without a website, distributed to participants by April 17, 2026 (within 60 days of the change).

Key Considerations:

Update Policies & Retrain Workforce - Organizations should act promptly to review their existing notices and implement the required changes before the deadline. Review and update internal privacy policies, procedures, and training materials to comply with the final rule.

Review your BAAs - Business Associate Agreements should be reviewed to ensure they account for the enhanced protections of SUD information.

For more information, check the updated Fact Sheet 42 CFR Part 2 Final Rule:

https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html.

References:

https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520

1 45 CFR 164.520(b)(1)(i)

2 45 CFR 164.520(b)(1)(ii)

3 45 CFR 164.520(b)(1)(ii)

4 45 CFR 164.520(b)(1)(iv)-(vii)

5 45 CFR 164.520(b)(1)(viii)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance, HIPAA

Privacy, Interoperability, and Trust in 2026

HIPAA Notice of Privacy Practices, 42 CFR Part 2, and USCDI v3 Compliance Risk 

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE 

Healthcare organizations entering 2026 face a convergence of heightened privacy enforcement and expanded interoperability obligations. Two major regulatory developments drive this shift:

  1. The February 16, 2026 deadline to update HIPAA Notices of Privacy Practices (NPPs) to reflect revised 42 CFR Part 2 requirements, and
  2. The January 1, 2026 mandate to comply with United States Core Data for Interoperability (USCDI) Version 3 standards. 

This article provides an executive and auditor-facing analysis of these intersecting requirements, examining enforcement risk, patient rights, data governance challenges, and operational compliance implications. Practical guidance is offered to support governing boards, executive leaders, and compliance professionals in aligning privacy, interoperability, and health IT strategies.

The information in this article is not intended as legal or consulting advice and should be used for educational purposes only.

Introduction

The healthcare compliance environment in 2026 reflects a deliberate regulatory emphasis on transparency, data access, and accountability balanced against strengthened privacy protections. Federal agencies have clearly signaled that interoperability and privacy are no longer siloed compliance domains but interdependent elements of patient trust and regulatory oversight.

As highlighted in the January 2026 Compliance Newsletter published by the American Institute of Healthcare Compliance, healthcare organizations must simultaneously address expanded HIPAA privacy obligations and mandatory interoperability standards. This convergence significantly elevates compliance risk for entities that fail to align governance, policy, and operational workflows.

HIPAA Notice of Privacy Practices: February 16, 2026 Enforcement Deadline

February 16, 2026 marks the enforcement deadline for updates to HIPAA Notices of Privacy Practices required under the February 2024 Final Rule modifying 42 CFR Part 2. These revisions align substance use disorder (SUD) privacy protections with HIPAA and subject violations to civil monetary penalties and corrective action plans.

Historically, Part 2 violations carried limited enforcement risk. Under the revised framework, failure to update NPPs or operationalize revised patient rights may be interpreted as systemic noncompliance.

Expanded Patient Rights Under Revised 42 CFR Part 2

The revised Part 2 framework introduces significant patient rights that must be clearly disclosed through updated NPPs. These include single-consent authorization for future disclosures, enhanced rights to request privacy protections, and explicit restrictions on the use of SUD records in legal proceedings. Compliance programs must ensure alignment across registration, consent management, EHR configuration, and workforce training to avoid inadvertent violations.

USCDI Version 3: Mandatory Interoperability in 2026

Already in effect, as of January 1, 2026, compliance with USCDI Version 3 became mandatory for certified EHR systems and health IT vendors.

This requirement expands the scope of standardized data exchange to include social determinants of health, health equity data, and expanded insurance information.  Failure to meet USCDI v3 standards may expose organizations to information blocking allegations, certification issues, and contractual noncompliance with payers and federal programs.

Intersection of Privacy and Interoperability

The intersection of privacy and interoperability represents one of the most complex compliance challenges facing healthcare organizations in 2026. Federal policy has deliberately accelerated health information exchange to improve care coordination, reduce administrative burden, and advance health equity. Simultaneously, regulators have strengthened patient privacy rights—particularly for sensitive data such as substance use disorder (SUD) information—recognizing that trust is foundational to patient engagement and data accuracy.

USCDI Version 3 expands the categories of data eligible for exchange, including social determinants of health, health equity stratifiers, and expanded clinical and insurance data elements. While these data sets are critical to population health and value-based care initiatives, they also increase the likelihood of inappropriate disclosure if consent and access controls are not precisely aligned. The revised 42 CFR Part 2 framework reinforces that interoperability does not negate privacy obligations; rather, it heightens the expectation that organizations implement granular, enforceable safeguards.

A Dual-Risk Environment - From an enforcement perspective, regulators have made clear that information blocking prohibitions do not override privacy protections. Organizations that indiscriminately share data without honoring consent restrictions—particularly for Part 2-protected information—may face simultaneous exposure under HIPAA, Part 2, and information blocking regulations. This creates a dual-risk environment in which both over-restriction and over-disclosure may trigger regulatory scrutiny.

To navigate this tension, healthcare organizations must adopt a privacy-by-design approach to interoperability, ensuring that consent management, data segmentation, and role-based access controls are embedded into health IT workflows. Interoperability initiatives that proceed without explicit privacy governance risk eroding patient trust and undermining regulatory compliance objectives.

Ensuring Trust Through Privacy-Centered Interoperability

Trust is not an abstract concept in healthcare compliance; it is an operational outcome shaped by transparency, consistency, and respect for patient autonomy. As data exchange expands, patients are increasingly aware of how their information is used, shared, and protected.

Failure to demonstrate meaningful privacy protections may result in patients withholding information, declining treatment, or disengaging from care altogether—particularly in behavioral health and substance use contexts.

Practical, trust-building strategies include:

Transparent and Understandable NPPs - Updated Notices of Privacy Practices should move beyond regulatory minimums to clearly explain how sensitive information is shared through interoperable systems, what choices patients have, and how consent is honored across care settings. Plain-language explanations reinforce trust and reduce confusion at registration and intake.

Consent Integrity Across Systems - Organizations should validate that consent decisions captured at intake are consistently enforced across EHRs, health information exchanges, and third-party platforms. Inconsistent application of consent restrictions is a frequent source of patient complaints and audit findings.

Data Minimization and Purpose Limitation - Even when data sharing is permitted, organizations should limit disclosures to the minimum necessary to achieve clinical or operational objectives. Demonstrating restraint reinforces patient confidence that interoperability serves care—not convenience.

Patient Access and Engagement - Providing patients timely access to their own records, including disclosures and consent history, supports transparency and aligns with broader federal access initiatives. Patients who understand how their data moves through the system are more likely to trust it.

Workforce Accountability - Trust is undermined when staff lack clarity regarding privacy obligations. Targeted training that addresses real-world scenarios—such as responding to data requests involving SUD information—helps prevent inadvertent violations and reinforces organizational commitment to privacy.

These practices position privacy not as a barrier to interoperability, but as a prerequisite for sustainable data exchange.

Governance, Audit, and Enforcement Risk

Regulators increasingly evaluate privacy and interoperability compliance through a governance lens. Surveyors and auditors may assess leadership awareness of regulatory changes, oversight of data-sharing activities, and the effectiveness of training and monitoring programs.

Failure to demonstrate executive oversight may result in enforcement actions by OCR or CMS.

Operationalizing Compliance: Best Practices

To mitigate compliance risk, organizations should:

  • Update NPPs well in advance of enforcement deadlines;
  • Align consent workflows with interoperability requirements;
  • Validate EHR configurations; and
  • Conduct targeted workforce training.

Routine audits of data-sharing practices and consent management processes are critical to sustaining compliance.

Conclusion

The convergence of revised HIPAA privacy requirements strengthened 42 CFR Part 2 protections, and mandatory USCDI Version 3 interoperability standards reflects a broader regulatory recalibration of healthcare data governance. Federal agencies have signaled that access, transparency, and accountability must advance in parallel—not in competition. In this environment, privacy failures are no longer isolated compliance issues; they represent systemic governance risks with direct implications for patient trust, enforcement exposure, and organizational credibility.

Healthcare organizations entering 2026 must recognize that interoperability initiatives amplify privacy obligations rather than dilute them. Updated Notices of Privacy Practices, consent management workflows, and health IT configurations serve as visible indicators of organizational integrity. Regulators and auditors increasingly assess not only whether policies exist, but whether leadership understands how privacy and interoperability intersect operationally.

Organizations that proactively integrate privacy-by-design principles into interoperability strategies will be best positioned to navigate enforcement risk, avoid information blocking missteps, and sustain patient trust. This requires active governing body oversight, cross-functional collaboration between compliance, IT, legal, and clinical leaders, and continuous monitoring of evolving regulatory guidance.

Ultimately, trust is the currency of interoperable healthcare. Organizations that demonstrate respect for patient autonomy while advancing responsible data exchange will not only meet regulatory expectations but also strengthen care quality, engagement, and resilience in an increasingly data-driven healthcare system.

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • American Institute of Healthcare Compliance. (2026). January 2026 compliance newsletter. https://dev-main.aihc-assn.org
  • U.S. Department of Health and Human Services, Office for Civil Rights. (2024). Final rule modifying 42 CFR Part 2. https://www.hhs.gov/ocr
  • Centers for Medicare & Medicaid Services. (2025). United States Core Data for Interoperability (USCDI) Version 3. https://www.cms.gov

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Quality
Leadership, Quality

An Approach to Reduce Patient and Workforce Harm

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS  

This article emphasizes the need of healthcare institutions to focus on building a culture of safety through improving care of the workforce.  Read Part 1: Building a Culture of Patient Safety Starts with Reducing Staff Burnout posted December 3, 2024.

New Dashboard to Track Progress

On December 5, 2024, the National Action Alliance for Patient and Workforce Safety (NAA) at the U.S. Department of Health and Human Services (HHS) launched the National Healthcare Safety Dashboard, an online resource that aggregates hospital safety data from four primary measurement sources. Thus, the dashboard creates one comprehensive resource for understanding the current state of patient and workforce safety.

The Agency for Healthcare Research and Quality (AHRQ) works under the Department of Health and Human Services.  AHRQ sponsors the National Action Alliance for Patient and Workforce Safety and now offers a resource for national patient and workforce safety data dashboard. The goal of data collection is to improve safety of patients and your healthcare workforce.

The National Healthcare Safety Dashboard makes national safety data more transparent, allowing for a comprehensive understanding of healthcare safety by care setting, beginning with hospital care. It opens doors to information and best practices to empower healthcare provider organizations, patient advocates, policymakers, professional associations and others to monitor national safety progress and make informed decisions to improve safety nationwide.

The National Action Alliance goals, listed below, are intended to help all healthcare systems strengthen their patient and workforce safety outcomes.


1.  Advance Healthcare Organization Safety Strategies Using Safety Self-Assessments

  • Encourage healthcare organizations to perform safety self-assessments focused on the NAP’s foundational elements.
  • Support healthcare organizations in their efforts to enact safety strategies based on identified gaps.

2.  Empower the Patient's Voice in Safety Strategy

  • Allow patients and families to submit safety concerns into healthcare organization event reporting systems.
  • Encourage healthcare organizations to implement communication and resolution programs.
  • Engage patients and families in safety event reviews and in safety initiative planning.

3.  Support the Healthcare Workforce by Making Healthcare Safer by Design

  • Identify and address five high-priority safety engineering needs.

4.  Support the Healthcare Workforce by Strengthening Healthcare Safety Competencies

  • Ensure all healthcare team members, from administrators to clinical and non-clinical staff, receive training in fundamental safety competencies.

5.  Facilitate a Learning and Research Network

  • Encourage learning and sharing across network.
  • Spotlight change leaders.
  • Promote robust safety measurement locally and nationally.
  • Support research to address high-priority needs in patient and workforce safety.

The initial version of the dashboard offers access to hospital safety data and will expand to include other healthcare settings, such as ambulatory clinics and nursing homes.  The data sources listed on the Dashboard include:

Resources and Tools on Patient and Healthcare Workforce Safety

Resources are listed on the AHRQ website by type of harm. These tools and resources include active federally sponsored implementation initiatives and funding opportunities and can help you address safety needs that you identify in your safety self-assessment.

  • Diagnostic Safety
  • Falls
  • Hospital-Associated Infections
  • Maternal Safety
  • Medication Safety
  • Never Events
  • Opioid Safety
  • Pressure Ulcers
  • Readmissions
  • Sepsis
  • Surgical Safety
  • Transitions in Care
  • Venous Thromboembolism

The AHRQ recommended Self-Assessment Tool is an essential resource designed to help health care organizations evaluate their safety readiness, identify opportunities for improvement, and track progress over time. The 2024 updated version of the tool aligns with the recommendations in Safer Together: A National Action Plan to Advance Patient Safety (National Action Plan) and incorporates the latest insights and best practices from global safety initiatives.

Conclusion

Healthcare is not safe until it is safe for all.  As healthcare organizations implement these initiatives and work collectively across the NAA, the National Healthcare Safety Dashboard becomes an essential tool that allows the healthcare community to monitor progress and offers insights to guide further action.  Workforce safety recognizes the imperative to protect workforce members from physical harm so that they can deliver high-quality care, and recognizes the vital importance of psychological and emotional safety for engaging, communicating, and collaborating effectively to safely deliver patient care.

The National Healthcare Safety Dashboard is now live and accessible to the public:

About the Author and AIHC

The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair and overseeing the AIHC Volunteer Education Committee. She is also a volunteer hospice nurse, hospice hands-on-care volunteer and End of Life Doula.

The American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS. Please visit our online store listing current training and certification offerings.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Compliance Considerations when Treating Gender Identity and Gender Diverse Patients

Written by Gabriella Neff, RHIA, CHA, CHC, CHRC, CHPC 

It is all about respect. Transgender individuals are protected under HIPAA, the Affordable Care Act (ACA) and standards outlined for hospital accreditation under Medicare and Medicaid as well as Joint Commission. Hospitals may not have specific requirements for training staff on LGBTQ+ cultural competency and non-discrimination policies to be compliant to applicable rules and regulations. AIHC recommends referencing the National Library of Medicine’s Gender Inclusive Care Toolkit for Hospitals in addition to reading this article and references.  This article is an introduction to this complex topic and not intended as consulting or legal advice.

What Should Compliance Officers Know

Gender identity reflects one's personal and internal sense of self as male or female or other. Gender-diverse refers to persons whose self-identity differs from the male or female assignment at birth. Below is a list of the most common gender identity terms used to identify individuals who do not identify with their gender assignment at birth (male/female).   

  • Trans:  Describes a person who does not identify with their assignment of male/female at birth and may include a range of identities such as trans-woman and trans-man.
  • Nonbinary: Describes a person whose gender identity does not traditionally fit into the gender of male or female.
  • Agender: Describes someone who identifies as having no gender.
  • Bigender: Describes a person whose identity combines two genders or who may sometimes be male and sometimes female.
  • Cisgender: Describes a person whose gender identity matches the sex assigned to them at birth.
  • GenderQueer: An umbrella term for those who think of their gender identity or sexual orientation as being outside of the social norms.

For clinicians to treat our gender-diverse population appropriately, we must consider the following: 

  1. Create an inclusive environment. Use environmental signage to create an environment where all individuals can recognize that staff know and care about them equally as patients. Acknowledge and respect individuals who may self-identify outside of the norms of male or female by training staff on how to collect information on gender identity and sex assigned at birth sensitively and confidentially. Utilize the same self-identification terms and preferred pronouns and names. Consider creating gender-neutral bathrooms and care rooms, or at least designate one option and have it clearly marked as gender-neutral.
  2. Ensure we are compliant with the regulations affecting gender-diverse patients. These include the regulations that prohibit discrimination and employment based on sex or gender identity, the general regulations addressing the ethical treatment of all patients, regardless of gender identity, and the protection of their information. [i]
  3. Educate staff and create awareness. Engage and educate the Board and Senior Management to "set the tone" to provide resources for change and build inclusiveness as part of a commitment to equitable patient care. Educate all staff on diversity and inclusiveness.
  4. Create policies and procedures to address equitable and sensitive processes in admitting/registration, treatment, the collection of gender identity data, compliance with regulations, and insurance issues.
  5. Ensure clinicians have the tools needed to address multiple and complicated conditions that sometimes coincide with treating gender-diverse patients, such as gender-affirming hormone therapy and its effects on current treatment, medication dosing issues, understanding and interpreting lab references outside of the male/female binary, and utilizing a team-based approach to improve upon patient-centered care.
  6. Ensure a process is in place to address billing and claims denials by ensuring that the name and gender provided to the insurer match the name and gender on the claims submitted and that staff utilize the special billing codes created by CMS to prevent inappropriately denied claims.
  7. We should create an inclusive environment within our clinical trials by including gender-diverse subjects. The protocol should be diverse to address deviations, medication administration, cohorts, and adverse event reporting related to gender-diverse subjects.
  8. And finally, be an advocate by practicing culturally and linguistically inclusive activities.

Understanding a person's gender identity and sex assigned at birth enables clinicians to provide better and more appropriate care, along with meeting the health needs of gender-diverse patients respectfully.

About the Author

Gabriella Neff, RHIA, CHA, CHC, CHRC, CHPC is a Research Compliance Officer for H. Lee Moffit Cancer Center and also serves as a Board Member for the American Institute of Healthcare Compliance.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

[i] Equality Act - prohibits discrimination based on an individual’s sexual orientation or gender identity in employment, housing, credit, education, jury service, federally funded programs (including health care), and businesses that serve the public.
Title VII of the Civil Rights Act of 1964 – protects employees from discrimination based on race, color, religion, sex, sexual orientation, or gender identity.
Executive Order 13672 – extended protection against discrimination in employment in the federal workforce on the basis of gender identity or gender expression.
Affordable Care Act – Sec. 1557 – prohibits discrimination on the basis of race, color, national origin, sex, age, or disability in any health program or activity receiving Federal Funds.
Joint Commission Standard R1.01.01.01, EP 29 – prohibits discrimination on the basis of gender identity to maintain accreditation.
AMA Opinion 9.123 –derogatory language or actions on the part of physicians that cause psychological harm to patients is unethical - Principles of Medical Ethics.
HIPAA –Gender Identity is considered PHI – the minimum necessary standard.



Read More