Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Common Compliance Risks in OB/GYN Medical Billing and How to Address Them

Written by Noah Smith for BillingFreedom

The article will help healthcare professionals identify common compliance risks that can arise in OB-GYN medical billing and understand practical approaches for addressing those risks through accurate documentation, coding, claim review, internal audits, and consistent billing workflows.

OB/GYN billing can get complicated quickly. During the same week, a practice may bill for preventive visits, ultrasounds, office procedures, prenatal care, surgery, delivery services, postpartum visits, and treatment for unrelated gynecologic conditions. Those services do not always follow the same documentation, coding, or payer rules. That leaves plenty of room for small mistakes to slip into the billing process.

Sometimes the problem is obvious. A claim is rejected because the subscriber number is wrong or a required field is missing. Other problems are harder to notice. A payer may process a claim even though the documentation is weak, a modifier has been used inconsistently, or staff are following an outdated billing process.

One paid claim does not necessarily tell a practice that everything behind the claim was handled correctly. A better way to think about compliance is to look at the entire path a claim takes:

  • Patient information has to be accurate.
  • Coverage needs to be checked.
  • The provider's note has to support the service.
  • Coding needs to match the record, and payer requirements have to be addressed before the claim goes out.

When one part of that chain breaks down repeatedly, the problem can spread across dozens of claims before anyone recognizes the pattern.

Where OB/GYN Billing Problems Usually Start

Many compliance issues begin before a coder ever looks at the chart. Consider a returning patient whose insurance changed since her last appointment. If the old plan is still listed in the system, the claim may be sent to the wrong payer. By the time the rejection comes back, staff may need to update the account, verify benefits again, rebill the service, and make sure a filing deadline has not been missed.

Authorization problems can develop in much the same way. A service may have been appropriate and clearly documented, yet the claim can still run into trouble if the payer required prior authorization and nobody confirmed it.

Then there is the medical record itself. A provider may remember exactly what was discussed or performed during a visit, but the billing team can only rely on what appears in the documentation. If the note does not clearly support the service being reported, defending the claim later becomes much more difficult.

The Centers for Medicare & Medicaid Services (CMS) provides guidance on electronic healthcare claims and the information needed for claims processing. The larger point for a practice is simple: compliance starts long before a denial or payer review arrives.

Documentation and Coding Need to Tell the Same Story

Documentation and coding are often discussed as separate tasks. In actual billing, they are difficult to separate. The code on the claim is supposed to represent what happened during the encounter. The medical record is what supports that representation.

Problems begin when the two tell different stories.

A common OB/GYN situation is a preventive visit in which the patient also brings up a new medical concern. Additional evaluation may take place during the same encounter. Whether separate reporting is appropriate depends on the services performed, the documentation, coding rules, and the payer's requirements. Similar questions come up with procedures, diagnostic testing, postoperative care, maternity services, and modifier use.

A diagnosis code may be valid in general but still fail to match what the provider actually documented. A procedure code may describe a service correctly but lack enough support in the chart. A modifier can also create problems when staff use it routinely instead of deciding whether the circumstances of that particular encounter justify it. These are not always dramatic errors. That is part of the problem.

When the same documentation habit or coding shortcut is repeated week after week, an isolated weakness can turn into a larger compliance concern.

Periodic chart-to-claim reviews can help uncover those patterns. Instead of asking only whether the claim was paid, the reviewer looks at whether the claim accurately reflects the record and whether the documentation is strong enough to support what was billed.

Some Claim Errors Have Nothing to Do with Complex Coding

Not every denied or rejected claim involves a difficult coding question. Sometimes the problem is a wrong date, an outdated insurance record, missing provider information, an incorrect subscriber ID, or a claim field that was left incomplete. These errors may sound minor, but they still consume staff time and slow down payment.

Electronic claims generally pass through automated edits during processing. Certain missing or inconsistent details can cause the claim to stop before it gets very far.

A short review before submission can catch many of those problems. Staff may want to verify:

  1. Patient and subscriber information.
  2. Current insurance coverage and coordination of benefits.
  3. Provider and practice identifiers.
  4. Diagnosis codes, procedure codes, and modifiers.
  5. Documentation supporting the billed service.
  6. Required authorization or referral information.
  7. Payer-specific claim requirements and missing fields.

The review does not have to turn into a lengthy approval process for every claim. What matters is that the practice has a reliable way to catch repeatable errors before the payer does.

Eligibility Deserves More Attention in OB/GYN Billing

Insurance information can change during the course of care, and OB/GYN practices are especially likely to encounter that issue because many patients receive services over an extended period.

Pregnancy is an obvious example. A patient may have one insurance plan early in the pregnancy and another later. Employment can change. A spouse's coverage can change. Coordination of benefits may need to be updated. Authorization rules may also be different under the new plan. If staff rely on an eligibility check performed months earlier, the billing team may not find out about the change until a claim is denied.

Eligibility problems can affect more than reimbursement. They may also result in the wrong amount being assigned to the patient or create confusion about who is financially responsible for the service.

Checking coverage at appropriate points throughout treatment gives staff a chance to address those issues before the claim has already gone through the billing cycle. It also makes financial conversations with patients more accurate.

A Denial May Be Pointing to a Workflow Problem

Correcting a denied claim is necessary. Correcting the same type of denial twenty times should raise a different question - Why does it keep happening?

Suppose claims for a particular procedure regularly come back because information is missing. Billing staff can add the information and resubmit each claim, but that does not explain why the original claims were incomplete.

Maybe the registration team is not collecting something the payer requires. Perhaps the authorization information exists but is not being transferred correctly. It could also be that staff misunderstood a payer policy. The denial itself is only the visible part of the problem.

This is why useful denial management goes beyond counting how many claims were denied. Practices can look at which reasons occur most often, which payers are involved, whether one service keeps appearing, and where in the workflow the original error began.

That kind of review can reveal patterns that would otherwise remain hidden. The CMS Medical Review and Education resources also discuss claims analysis and medical record review in the context of identifying improper billing and documentation issues. For an OB/GYN practice, denial data can serve as a practical warning system. It shows where the revenue cycle is struggling, not just where payment was delayed.

Internal Audits Can Be Small and Still Be Useful

An internal audit does not have to involve hundreds of charts. A practice can learn a great deal from a carefully chosen sample.

Maybe one modifier has been causing questions. Perhaps a particular payer has denied an unusually high number of claims. There may be concerns about preventive visits, maternity billing, surgery, medical necessity documentation, or another service that carries more risk. Those claims can be reviewed against the medical record.

The reviewer may find that everything was handled appropriately. If not, the next step is to determine whether the problem was isolated or whether it reflects a larger habit. That distinction matters. One coding mistake made on a single claim may require a simple correction. Finding the same mistake across several providers or multiple dates of service suggests that the practice may need education, a workflow change, or closer monitoring. The audit should not end when the error is identified.

If a change is made, the practice needs some way to determine whether it worked. Reviewing another sample later can show whether the same problem is still appearing. Without follow-up, the practice has documented a problem but has not necessarily solved it.

Compliance Works Better When It Is Part of Routine Operations

A compliance process does not need to be complicated to be useful. In many practices, consistency matters more than creating a large set of policies that nobody uses. Staff should know how registration is handled, when eligibility is checked, how authorization information is recorded, how claims are reviewed, what happens when a denial arrives, and who is responsible for following up on recurring problems.

Those processes should not exist only in one employee's memory. Training matters for the same reason. Payer policies change. Coding guidance changes. Internal workflows change. New employees arrive, and experienced employees sometimes continue using a process that made sense under an older rule.

Regular education gives the practice a chance to catch those gaps.

Billing data can also help determine where training is needed. If eligibility denials suddenly increase, the first response should not necessarily be a general coding seminar. The practice may need to look at registration and verification instead. If several claims involving the same modifier are being questioned, a focused review of those encounters is probably more useful than retraining the entire staff on every coding topic. Compliance becomes easier to manage when the response matches the actual problem.

Documentation Reviews Should Include the Claim

A chart can look complete on its own while the corresponding claim still contains a problem.

The opposite is also possible. A claim may appear technically correct until someone compares it with the medical record.

Looking at both together usually provides a clearer picture. This is particularly important for services where the circumstances of the encounter affect billing. Preventive care, problem-oriented visits, procedures, maternity care, and postoperative services can all raise questions that cannot be answered by looking at a code alone.

The reviewer needs to understand what actually happened during the visit, what the provider documented, and how that information was translated into the claim.

Preparing for Billing Changes Before They Reach the Claims Department

One of the easiest ways for a billing problem to spread is for a rule to change while the practice keeps following the old process. Changes may affect coding, documentation, payer policies, reimbursement, or the way certain services are reported.

The first sign should not have to be a wave of denials.

When a significant change is announced, the practice can identify which services will be affected and who needs to know about it. Providers may need different documentation. Billing staff may need revised procedures. Software settings or claim edits may also need to be updated. Testing the new process early is usually easier than correcting a backlog later. This becomes especially important when changes affect maternity services because the care and billing may span several months.

The Bigger Compliance Question

A claim can be paid and still come from a weak process. That is why payment should not be the only measure of whether an OB/GYN billing operation is working well. A better question is whether the practice could explain and support the claim if someone reviewed it later.

  • Was the patient's coverage checked?
  • Does the chart support the service?
  • Does the code match what was documented?
  • Were payer requirements addressed?
  • If a similar problem appeared last month, was anything changed afterward?

Those questions bring compliance into the normal revenue-cycle process instead of treating it as something that matters only during an audit.

Most billing problems do not begin as major compliance failures. They usually start much smaller: an insurance detail that was not updated, documentation that was a little too vague, a modifier applied out of habit, or a denial that was corrected without asking why it happened.

The risk grows when the same issue becomes routine.

Finding those patterns early is what gives a practice the best chance to correct them before they affect more claims, more patients, or more revenue.

About the Author Noah Smith

This article is written by Noah Smith on behalf of BillingFreedom. Noah is a medical biller, SEO and Content Outreach Specialist.

Additional Resources

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
General Compliance, HIPAA

Before PHI Enters a SaaS Workflow

Building a Vendor Evidence Register 

Written by Coco Yang 

Introduction

A clinic can approve a scheduling platform and still miss the place where patient information leaves the approved path. An intake form may pass data to the scheduler, which sends a notification through an email service, creates a record in a customer relationship management system, and copies details into an analytics tool. The vendor review may have covered the scheduling platform. The actual workflow contains four or five services.

That is why a product name and a "HIPAA compliant" statement are not enough to document a SaaS decision. The review needs to identify the exact service, plan, configuration, integrations, users, and data flow. It also needs a record of what each source supports, what it does not support, and what still requires an answer from the vendor.

A vendor evidence register provides that record. It is not a certification score and should not replace legal, privacy, security, procurement, or clinical review. It is a practical way to keep the evidence behind a decision visible before protected health information (PHI) enters a software workflow.

Start With the Workflow, Not the Vendor Name

The first question is not simply, "Does this vendor support HIPAA?" A more useful starting question is, "What will this organization do with this exact service?"

Write down the product edition and paid plan, the features that will be enabled, the people who will have access, and the systems that will send or receive data. Include support tools, exports, backups, browser extensions, mobile applications, application programming interfaces, automation services, and optional artificial intelligence features. Then identify where PHI is expected to be created, received, maintained, or transmitted.

This boundary matters. A vendor may make a business associate agreement (BAA) available only for certain products, plans, customers, or configurations. An integration may be provided by another company. A feature may use a separate sub-processor or different retention setting. HHS guidance on cloud computing advises covered entities and business associates to understand the cloud environment they are using so they can conduct their own risk analysis and enter into appropriate agreements.

A simple workflow sentence helps anchor the review. For example: "Patients submit contact and appointment information through Form A; the data is stored in Scheduler B; staff members access it through managed accounts; appointment reminders are sent through Service C; no PHI is sent to analytics." If the team cannot write that sentence with confidence, it is too early to approve the workflow.

Keep Different Kinds of Evidence Separate

Vendor material often arrives as a mixed folder of contracts, reports, help-center pages, questionnaires, and sales statements. These sources do not answer the same questions.

A BAA is contractual evidence. HHS explains that a business associate contract establishes permitted and required uses and disclosures, requires safeguards, addresses incident reporting, applies restrictions to relevant subcontractors, and covers return or destruction of PHI at termination when feasible. The review still needs to confirm that the agreement applies to the exact legal entity and service being purchased.

A SOC 2 report is security-assurance evidence. It can help a reviewer understand the systems, controls, time period, exceptions, and subservice organizations described in the report. It does not establish that the vendor will sign a BAA, that the intended product is included in the BAA, or that the customer's configuration is appropriate.

Product documentation explains how features work. It may describe access controls, audit logs, retention settings, encryption, data regions, or deletion behavior. Marketing language is a weaker source. It can point the team toward a question, but it should not be treated as proof that a contract, report, or technical control covers the planned workflow.

Keeping these evidence types separate prevents one familiar logo or badge from doing more work than it should.

What to Record

The register does not need to be elaborate. A spreadsheet, ticket, or procurement record can work if it preserves enough context for another reviewer to reconstruct the decision. For each item, record:

  1. The source title, owner, and location.
  2. The date it was retrieved and, when applicable, its effective period or report period.
  3. The legal entity, product, plan, feature, and region it covers.
  4. The conclusion the source supports.
  5. Conditions and limitations stated in the source.
  6. Questions that remain open and the person responsible for resolving them.
  7. The date or event that will trigger another review.

Short conclusions are more useful than broad labels. "Vendor says HIPAA compliant" is difficult to act on. "BAA offered for the Enterprise plan; analytics add-on not named; vendor confirmation pending" tells the next reviewer what is known and where the uncertainty sits.

The same discipline should be used for security evidence. Instead of recording "SOC 2 available," note the report type, review period, system description, relevant exceptions, complementary customer controls, and whether important subservice organizations are included or carved out.

Check the Operational Questions

Contracts and assurance reports are only part of the review. The intended use also depends on routine operational details.

Ask which sub-processors may create, receive, maintain, or transmit PHI. Confirm how administrators and support personnel obtain access, whether that access is logged, and how emergency support is handled. Review default retention, backup retention, deletion timing, export behavior, account termination, and the process for returning or destroying data.

Incident language deserves the same attention. Identify where the vendor describes security incidents and breach notification, who receives notice, and whether the timing and cooperation terms match the organization's requirements. Customer-side safeguards should also be explicit: identity management, multifactor authentication, role design, device controls, logging, staff training, approved integrations, and procedures for offboarding users.

A signed BAA does not configure the product. HHS risk-analysis guidance makes clear that regulated organizations must identify potential risks and vulnerabilities to all electronic PHI they create, receive, maintain, or transmit. The vendor's evidence informs that work; it does not perform the organization's risk analysis for it.

Use Evidence States Instead of a Single Verdict

A binary field labeled "compliant" hides too much. Evidence is often conditional, incomplete, inconsistent, or old. A small set of evidence states makes the record more honest:

  • Supported: the source directly supports the conclusion for the identified scope.
  • Conditional: the conclusion depends on a plan, configuration, contract, location, or customer action.
  • Missing: the needed source has not been obtained.
  • Conflicting: two sources disagree or describe different scopes.
  • Stale: the source no longer reflects the current product, contract, report period, or workflow.

These are evidence states, not compliance determinations. They help the organization route questions to the right owner and avoid treating silence as approval.

Review Again When Something Changes

An annual vendor review is useful, but a change in the workflow can make last month's evidence incomplete. Set event-based review triggers for a new contract or BAA, a plan change, a new integration, a material sub-processor update, revised retention terms, a new artificial intelligence feature, a security incident, or a change in the type of PHI being handled.

The register should also have an owner. Procurement may hold contracts, security may review assurance reports, privacy or compliance may assess uses and disclosures, and the operational team may know the actual configuration. Someone must be responsible for assembling those pieces and recording the final conditions of use.

Conclusion

A SaaS review is easier to defend when another person can see exactly what was reviewed, when it was reviewed, and which workflow the decision covered. Begin with the data path. Separate contractual, assurance, product, and marketing evidence. Record scope and dates. Preserve unresolved questions. Reopen the review when the service or workflow changes.

The purpose of a vendor evidence register is not to produce a universal badge. It is to make the reasoning behind a decision inspectable before PHI enters the workflow. Final decisions should remain with the organization's qualified legal, privacy, security, compliance, procurement, and operational professionals.

About the Author

Coco Yang is the Founder of ComplySaaS, an educational SaaS vendor compliance research project that organizes public HIPAA, BAA, PHI, and SOC 2 signals, source dates, workflow conditions, and verification questions. Her work is limited to documented vendor-research practice; she is not presenting herself as an attorney, auditor, healthcare provider, or compliance certifier. Company website: https://www.complysaas.com/

References

U.S. Department of Health and Human Services. "Guidance on HIPAA & Cloud Computing."

U.S. Department of Health and Human Services. "Business Associate Contracts."

U.S. Department of Health and Human Services. "Guidance on Risk Analysis."

National Institute of Standards and Technology. "SP 800-66 Rev. 2: Implementing the HIPAA Security Rule."

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

HCC Coding in 2026

Navigating Risk Adjustment in a Changing Healthcare Landscape 

Written by: Joy Rose, MSA, RHIA, CCS, CHA, CHPS 

In 2026, Hierarchical Condition Category (HCC) coding continues to evolve as a central pillar of risk adjustment in value-based care. Initially introduced by the Centers for Medicare & Medicaid Services (CMS) to project healthcare costs and determine payments for Medicare Advantage (MA) plans, HCC coding has become a strategic necessity across multiple payers and care settings.

Medicare Advantage Organizations (MAOs) are paid at a higher rate for patients who have conditions with greater levels of severity and multiple conditions, as their RAF scores and anticipated costs of care will be higher.

Key 2026 Medicare Advantage (MA) Cost Reporting Requirements

CMS requires Medicare-certified acute care hospitals reimbursed under the IPPS (inpatient prospective payment system) to report median negotiated payment rates from Medicare Advantage (MA) plans by MS-DRG on their annual cost reports for cost reporting periods ending on or after January 1, 2026.

This mandate aims to collect market-based data to set future inpatient prospective payment system (IPPS) relative weights.

  • Data will be used to set future MS-DRG weights likely by Fiscal Year 2029.
  • This requirement adds significant complexity to an already error-ridden annual Cost Report process.

Providers must ensure the accurate reporting of MA negotiated rates to avoid potential audit findings, as this data will influence future payment setting.

New in 2026 - Full transition to V28 Model has occurred

One of the biggest updates in 2026 is the full implementation of the CMS-HCC V28 model, which was first introduced in 2023. This model includes significant changes:

  • More clinically relevant or accurate groupings, especially for chronic conditions like diabetes and congestive heart failure.
  • Expanded but refined HCC categories: V28 increases the number of HCC categories from 86 to 115, creating more granular groupings while reducing additive combinations.
  • Renumbering and changing HCC categories.
  • Removal of some condition codes that were found to be less predictive of future healthcare costs.
  • Reduction in the number of ICD-10-CM codes from 9,797 to 7,770 (approximately 2294 codes deleted and 268 codes added)
  • More accurate clinical data and the use of data-drive results with the use of 2018 ICD-10-CM codes and 2019 payment information.

Healthcare providers must now re-map workflows for diagnosis coding processes and re-educate coding staff to ensure accurate code assignment based on the documentation provided by clinicians.

Greater Emphasis on Documentation Integrity - With more sophisticated audits by CMS and private payers, clinical documentation improvement (CDI) remains a top priority. Inaccurate or unsupported codes now carry steeper compliance risks, and real-time documentation tools are being widely adopted to assist clinicians. Clinicians must be educated and trained about the new model which will require even greater specificity in documentation and code assignment to ensure that the true level of the Medicare Advantage patients’ illness severity is captured and transmitted to CMS for appropriate costs analysis.

AI and NLP Integration - Natural Language Processing (NLP) and artificial intelligence (AI) tools are increasingly embedded in EHR systems to assist in identifying undocumented HCCs and improving capture rates. These tools help flag missed conditions, identify hierarchical overlaps, and ensure that chronic conditions are properly documented and reported annually. AI has its limitations according to a colleague managing denials.

Important Note - The AI tool that is being tested a major Boston medical facility is not intelligent enough to find HCCs, or even ICD-10 codes to ensure a robust denial can be created.  The medical team working with the denials team does not approve the AI findings in about 80% of the AI suggestions.

Key Challenges - Training and education remain critical as coding teams and clinicians adjust to new rules and technology.  In addition, there is coding fatigue from increased workload and regulatory pressure may affect coder accuracy and job satisfaction.

Providers must also balance HCC optimization with ethical standards and compliance, avoiding aggressive or unsupported upcoding practices. It is important for organizations to realize there is increased CMS scrutiny, by flagging providers as high-volume billing outliers or submitting claims with unusually high severity levels.

Opportunities:

  • Risk-adjustment data analytics now allow organizations to benchmark performance and track documentation trends in real time.
  • Proactive condition management enabled by accurate HCC coding allows payers and providers to better target care management and reduce preventable costs.
  • Interoperability and FHIR-based data exchange in 2026 enable smoother sharing of clinical data across systems, improving longitudinal risk tracking.
  • Increased focus on severity of patient diagnosis and claims by CMS

Real World Impact

As CMS moves further into outcome-based models and enhances its oversight of MA payments, the role of HCC coding will only grow in significance. Health systems that invest in robust CDI programs, AI-assisted coding tools, and clinician training will be better positioned to thrive in this value-based future.

Some analysts warn the shift could lower RAF scores 10-20% for providers still relying on V24-era documentation habits, since patients whose only qualifying condition was deleted in V28 effectively disappear from risk registries. Plans with large diabetic populations that previously captured a lot of complication-related detail are seeing the steepest declines, though expanding documentation breadth across different disease families can partly offset this.

Because of the revenue pressure, CMS/OIG have signaled they'll be watching closely for organizations overcompensating with inflated severity coding.

About the Author

Joy Rose, MSA, RHIA, CCS, CHA, CHPS is a member of the American Institute of Healthcare Compliance (AIHC) and serves as a subject matter expert on the AIHC Volunteer Education Committee.

References:

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Why Every Healthcare Facility Needs a Smart Hospital Security System

Written by Peter Lee, MSc, CIPP/US and Arif Khan researcher specializing in AI-driven security systems and healthcare compliance

The information provided is for educational purposes only and is not legal, consulting or IT advice.

Introduction

Healthcare facilities operate in one of the most complex and high-risk environments of any industry. Hospitals are open 24/7, manage large volumes of patients and visitors, and handle sensitive data, controlled substances, and critical care operations all at the same time. This combination creates a unique set of security and compliance challenges that cannot be addressed with traditional systems alone.

The scale of the issue is significant. According to healthcare safety data, incidents involving workplace violence, unauthorized access, and theft are rising across hospitals and care facilities. In addition, regulatory requirements such as the Health Insurance Portability and Security Act (HIPAA) place strict obligations on how patient data and physical access must be controlled. Even a single breach can lead to severe financial penalties, legal consequences, and reputational damage, which is enforced by the Office of Civil Rights (OCR).

At the same time, many healthcare facilities still rely on outdated surveillance and access systems that are limited to recording events rather than actively preventing them. These systems often fail to provide real-time visibility, making it difficult for administrators and compliance officers to respond quickly when incidents occur.

This is why modern hospital security systems are becoming essential rather than optional. A smart security system does more than monitor activity. It integrates surveillance, access control, and intelligent alerts into a unified platform that helps healthcare organizations protect patients, staff, and sensitive information while maintaining compliance.

The Complexity of Healthcare Environments Demands Smarter Security

Unlike typical commercial spaces, hospitals are highly dynamic environments. Emergency departments, patient wards, pharmacies, operating rooms, and administrative offices all operate simultaneously, each with different levels of access and risk.

Managing security in such an environment requires more than basic surveillance. It requires systems that can adapt to constant movement and provide clear visibility across all areas.

For example, a visitor entering a general waiting area may be appropriate, but the same individual entering a restricted ICU or medication storage area presents a serious risk. Without intelligent monitoring, distinguishing between normal and suspicious activity becomes difficult.

Modern hospital security systems address this by combining video surveillance with access control and real-time monitoring. This allows healthcare administrators to not only control who can enter specific areas but also verify and track activity as it happens.

The result?  A more controlled and transparent environment, which is critical for both safety and compliance.

Protecting Patient Safety and Staff Well-Being

Patient safety is the top priority in any healthcare facility. However, safety risks are not limited to medical issues alone. Security incidents such as unauthorized access, aggressive behavior, or theft can directly impact patient care.

Healthcare workers are also at increased risk - Studies have shown that healthcare professionals face higher rates of workplace violence compared to many other industries. This makes it essential for hospitals to have systems in place that can detect and respond to potential threats quickly.

Smart hospital security systems help mitigate these risks by providing continuous monitoring and real-time alerts. For instance, if unusual activity is detected in a restricted area or if a situation begins to escalate in a waiting room, security teams can be notified immediately.

This ability to respond quickly can prevent incidents from escalating and ensures a safer environment for both patients and staff.

Supporting HIPAA Compliance and Data Protection

Compliance is a critical concern for healthcare organizations. Regulations such as the Health Insurance Portability and Accountability Act (HIPAA) require strict control over access to patient information and sensitive areas.

Physical security plays a major role in compliance. Unauthorized access to records rooms, server areas, or administrative offices can lead to data breaches, which carry significant legal and financial consequences.

A modern hospital security system supports compliance by providing controlled access, detailed activity logs, and audit trails. These features allow organizations to track who accessed specific areas and when, which is essential for audits and investigations. This integrated approach helps ensure that compliance requirements are met while improving overall operational efficiency.

Preventing Unauthorized Access to Critical Areas

Hospitals contain several high-risk zones that require strict access control. These include pharmacies, operating rooms, ICUs, data centers, and storage areas for medical equipment.

Unauthorized access to these areas can result in serious consequences, including theft of controlled substances, tampering with equipment, or exposure of sensitive information.

Traditional systems often rely on static access permissions, which can become outdated as roles change. This creates gaps where individuals may retain access they no longer need.

Smart hospital security systems address this issue by enabling dynamic access control. Permissions can be updated in real time, ensuring that access is always aligned with current roles and responsibilities.

In addition, integrating access control with video surveillance provides an added layer of verification. Administrators can not only see who accessed a door but also confirm the activity visually, reducing the risk of misuse.

Improving Incident Response and Emergency Management

In healthcare settings, response time is critical. Whether it is a security incident, a medical emergency, or an environmental issue, delays can have serious consequences.

Smart security systems improve response time by providing real-time alerts and centralized monitoring. Instead of relying on manual reporting, incidents can be detected automatically and communicated to the appropriate teams immediately.

For example, if an unauthorized entry occurs in a restricted area or if environmental sensors detect abnormal conditions, alerts can be triggered instantly. Security and medical teams can then coordinate their response more effectively.

This level of coordination is especially important in large facilities where multiple departments must work together during emergencies.

Enhancing Operational Efficiency

Beyond safety and compliance, hospital security systems also contribute to operational efficiency.

Manual processes such as maintaining access logs, issuing credentials, and monitoring multiple systems can be time-consuming and prone to errors. As healthcare facilities grow, these inefficiencies become more pronounced.

A centralized security system streamlines these processes by integrating surveillance, access control, and alerts into a single platform. This reduces administrative workload and allows staff to focus on patient care rather than managing systems.

Additionally, data collected from security systems can provide valuable insights into facility usage, helping administrators optimize workflows and resource allocation.

Adapting to Modern Healthcare Challenges

Healthcare is evolving rapidly, and security systems must evolve with it.

Facilities are expanding, patient volumes are increasing, and technology is becoming more integrated into daily operations. At the same time, threats are becoming more sophisticated, requiring a more proactive approach to security.

Smart hospital security systems are designed to adapt to these challenges. They provide scalability, allowing facilities to expand without overhauling their infrastructure. They also support integration with other systems, creating a unified approach to security and operations.

This adaptability is essential for healthcare organizations that want to remain secure and compliant in a constantly changing environment.

FAQs

What are hospital security systems?

  • Hospital security systems are integrated solutions that combine surveillance, access control, and monitoring tools to protect patients, staff, and sensitive areas within healthcare facilities.

Why are smart security systems important in hospitals?

  • They provide real-time monitoring, improve response times, and support compliance with healthcare regulations, making them more effective than traditional systems.

How do these systems support HIPAA compliance?

  • They control access to sensitive areas, maintain detailed logs, and provide audit trails that help meet regulatory requirements.

Can hospitals use existing infrastructure?

  • Yes. Many modern systems are designed to work with existing IP cameras and infrastructure, reducing the need for costly replacements.

Do these systems improve patient safety?

  • Yes. By detecting and responding to risks quickly, they help create a safer environment for patients and healthcare staff.

Conclusion

Healthcare facilities face unique challenges that require more than basic security measures. The combination of high patient volumes, sensitive data, and strict regulatory requirements makes security a critical component of daily operations.

Modern hospital security systems provide the intelligence, integration, and real-time visibility needed to address these challenges effectively. They help protect patients, support staff, ensure compliance, and improve overall efficiency.  Solutions like Coram demonstrate how this can be implemented effectively. Coram’s hospital security platform works with existing IP cameras and integrates with access control systems and environmental sensors. It provides high-definition video monitoring, intelligent alerts, and centralized management, allowing healthcare facilities to maintain visibility and control without replacing their current infrastructure.

As healthcare environments continue to evolve, investing in smarter security systems is not just a technological upgrade. It is a necessary step toward safer, more resilient, and compliant healthcare operations.

About the Authors

Arif Khan is a writer and researcher specializing in AI-driven security systems, healthcare compliance, and modern surveillance technologies. He holds a B.Tech degree in Computer Science and works as a freelance writer covering topics related to AI, physical security, access control, and intelligent monitoring systems. His work focuses on helping organizations understand emerging security technologies and their role in improving safety, compliance, and operational efficiency.

Peter Lee is a writer and researcher specializing in AI-driven security systems and healthcare compliance. His work focuses on topics such as hospital security, HIPAA requirements, and modern surveillance technologies, helping organizations understand and implement effective security solutions.

References

American Institute of Healthcare Compliance (AIHC)

National Library of Medicine (NLM)

Occupational Safety and Health Administration (OSHA)

U.S. Department of Health & Human Services (HHS)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Measuring Effectiveness of Your CDI Program

Mitigating Risk and Improving Quality of Care 

Co-authored by Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 

This paper outlines the basics related to key steps, metrics, and best practices for implementing an effective CDI audit program. The information below is for educational purposes only and not intended as consulting or legal advice.

Introduction

Clinical Documentation Improvement (CDI) is a vital process that ensures medical records are accurate, complete, and compliant, directly impacting patient care quality, severity-of-illness tracking, and reimbursement. As CDI departments mature, establishing a robust, routine auditing process—both internal and external—is essential to validate the accuracy of CDI staff queries, identify educational gaps for physicians, and ensure compliance with regulatory standards.

Effective CDI audits identify gaps in diagnostic specificity, medical necessity, and coding accuracy which must support documentation (like histories and exam findings), and appropriate, non-leading queries.

OIG Guidance and Regulatory Support for Your Audit

To control risk, your internal auditors will benefit from a clearer understanding of healthcare compliance guidance, statutory and regulatory provisions that are related to CMS reimbursement.   The HHS Office of Inspector General’s (OIG) General Compliance Program Guidance (2023) calls for a proactive approach that emphasizes preventing errors rather than relying on post-submission rationalizations. The OIG guidance implicates several key documentation safeguards:  documentation must accurately reflect the services provided; patient records must be unique to the specific clinical encounter documented; and an effective risk mitigation playbook should address systemic documentation errors before they lead to overpayment demands or other matters. 

Grounded in statutory frameworks, Title XVIII of the Social Security Act sets forth a principle of “no documentation, no payment.”  All diagnostic and therapeutic interventions must meet the “reasonable and necessary” standard.  Medical records that provide insufficient information to justify the conditions for CMS payment could result in claim denials or a subsequent recoupment of funds.

Checklist for Clinical Documentation Improvement Audits

A CDI audit is a structured review designed to measure the effectiveness of the CDI program in capturing the full clinical picture of a patient. It serves as a check-and-balance system, evaluating not only the accuracy of coding but also the appropriateness of queries sent to providers.  A CDI audit also ensures that the medical record reflects real-time clinical practices rather than functioning as a retrospective cost justification.

The process involves a continuous, four-stage cycle which should have a Lead Auditor to guide the team to: 1) Prepare and plan (set goals), 2) Execute – collect and analyze records, validate findings, 3) Report audit findings 4) Provide education to implement change, and re-audit to ensure changes are sustained.

1.  Preparing for the Audit
     Success in auditing requires careful planning and preparation.

  • Define Scope and Goals: Identify specific areas of focus, such as high-risk diagnoses (e.g., sepsis), high-volume, or high-cost areas.
  • Select Samples: Utilize a representative sample of records, including those with queries and those without, to assess both CDI activity and documentation gaps.
  • Determine Audit Frequency: Establish a regular schedule (e.g., monthly or quarterly).
  • Identify Reviewers: Use a mix of internal staff for ongoing monitoring and external auditors for unbiased, independent assessments.

2.  Execute the Audit
     An effective CDI audit follows a standard quality improvement cycle (Plan, Do, Study, Act):

  • Data Collection
    Use random sampling of patient records to get a representative view or targeted sampling for specific providers or types of documentation. Reviewers gather patient records, specifically examining:
    • Specificity to ensure documentation is accurate, thorough, and detailed.
    • Medical necessity - Confirm that the documentation justifies the care provided.
    • The principal diagnosis assigned.
    • Secondary diagnoses (comorbidities and complications).
    • Present on Admission (POA) indicators.
    • Query compliance, ensuring queries are evidence-based and not leading, with best practices focused on clarifying ambiguities in the medical record
  • Analysis and Validation 
    Auditors compare the documentation against evidence-based standards. Key questions include:
    • Did the documentation support the queried diagnosis through objective clinical indicators, e.g., vitals, labs, treatment?
    • Was the query necessary, or was the information already in the record?
    • Are there missed opportunities where documentation was insufficient?

3.  Reporting Audit Findings
     Audit findings should be reported through actionable metrics.

  • Query response rates and agreement percentages. Report if providers respond to queries and if those queries improve the record.
  • DRG shifts (change in Diagnosis Related Group).
  • Denial reduction rates.

4.  Provide Education to Implement Change
    The results are used to provide targeted feedback to clinicians and CDI staff.

  • Develop educational sessions based on recurring documentation gaps (e.g., chronic condition management).
  • Update templates and checklists for improved accuracy.
  • Re-audit to ensure improvements are sustained.

Key Metrics/Key Performance Indicators (KPIs) to Audit

To measure the success of a CDI program, organizations should track specific key performance indicators (KPIs):

CDI KPI

Conclusion 

Best practices for successful CDI audits involve the providers. After all – it is their documentation being audited! Ensure the CDI team creates processes that minimize administrative burden.

Leverage technology and streamline the audit process by using computer-assisted coding (CAC) and AI-powered analytics to scan for gaps and prioritize reviews. Ensure documentation is accurate across all patient encounters, not just for higher reimbursement.

Share feedback. Collaborate with the coding and billing departments to ensure documentation aligns with ICD-10/CPT guidelines. Create a closed feedback loop where findings are shared with clinicians and coders for ongoing training.

Remember, auditing for CDI is a continuous cycle of improvement, moving beyond simply chasing revenue to establishing a sustainable, compliant, and accurate record-keeping process. By focusing on regular reviews, actionable metrics, and ongoing education, organizations can improve the quality of clinical documentation, leading to better patient care and optimal financial outcomes.

About the Authors

Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC, is a member of the AIHC Volunteer Education Committee. Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS, is the Chief Executive Officer at the American Institute of Healthcare Compliance.

References 

American Institute of Healthcare Compliance

National Library of Medicine

Office of Inspector General, U.S. Department of Health and Human Services. (2023). General Compliance Program Guidance.

Social Security Act § 1815(a), 42 U.S.C. § 1395g(a)

Social Security Act § 1862(a)(1)(A), 42 U.S.C. § 1395y(a)(1)(A)

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Auditing and Standard Deviation

The Importance of Statistical Significance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of standard deviation when Auditing for Compliance and quality standards. It is not intended as being comprehensive, legal or consulting advice. You may be interested in other auditing articles – click here. 

Introduction

In an increasingly data-driven corporate healthcare environment, auditing has moved beyond traditional spot-checking to advanced analytics. Standard deviation, a statistical measure of dispersion, has become an essential tool for auditors to assess risk and operational performance. By quantifying how data points, such as transaction amounts, process times, or product quality metrics deviate from the mean, auditors can identify anomalies, measure volatility, and evaluate the consistency of operational processes.

This paper explores how standard deviation helps audit financial risk by identifying outliers and market volatility, and how it improves operational efficiency by highlighting process variations.

Why Standard Deviation (SD) is Vital

In simpler terms, standard deviation measures the variation in the data. A higher variance requires a larger sample size to achieve statistical significance. It represents the average amount of variation or dispersion of data points from the mean.

Standard deviation is another measure of dispersion that complements variance. Standard deviation indicates how spread out the data points are in relation to the mean. Just like variance, standard deviation helps us understand the consistency and reliability of the data.

  • SD helps to identify outliers and anomalies. Auditors use standard deviation to pinpoint unusual data points that fall far from the mean to flag potential fraud, waste, billing errors, patient waiting times and quality measures.
  • SD is used to assess consistency. In auditing, a small standard deviation indicates consistent performance, while a high one suggests unreliable processes or high variability.
  • Calculating SD is vital when used in evaluating treatment/clinical variation. It helps determine if outcomes are consistent across a population. High standard deviation in medical data indicates inconsistent patient responses, which may signal a need for audits on clinical quality.

Understanding Risk and Performance

Financial risk management requires understanding volatility and uncertainty. Standard deviation serves as a proxy for this risk, helping auditors and financial analysts determine the potential for loss or unpredictability.

Auditors are tasked with providing assurance on financial statements and improving business processes. While averages (means) provide a central reference point, they often disguise underlying inconsistencies or high-risk outliers.

Standard deviation (SD) is essential because it measures the spread of data; a small standard deviation indicates consistency, while a high standard deviation indicates high variability. For auditors, this variability is synonymous with risk and potential inefficiency.

It is essential for auditing financial risk and operational efficiency because it permits auditors to see if "average" performance is due to uniform, acceptable results, or a mix of excellent and failing results.

Standard deviation is particularly useful for auditors due to its specific mathematical properties:

  • Sensitivity to Outliers: Because standard deviation squares the variance, it heavily impacts outliers, making it an effective tool for surfacing extreme cases.
  • Comparability (Scale Invariance): Auditors can directly compare the volatility of different datasets, even if they are in different units, allowing for comprehensive risk assessment across diverse business units.
  • The Normal Curve (Bell Curve): In a normal distribution, roughly 68% of data falls within one SD, 95% within two, and 99.7% within three. Auditors can use these intervals to define "normal" transactions and immediately identify the 5% that are outliers.

While powerful, standard deviation has limitations that auditors must recognize:

  • Assumes Normal Distribution: It works best with normal, bell-shaped curves. If data is heavily skewed or has fat tails, standard deviation might underestimate tail risk (rare but extreme events).
  • Backward-Looking: It is based on historical data, which may not repeat in the future.
  • Treats Volatility Equally: It treats positive and negative deviations equally, whereas auditors are primarily concerned with downside risk.

Steps to Calculate Sample Standard Deviation (SD)

Calculating standard deviation for a health care audit measures how much individual data points (e.g., patient wait times, billing errors) differ from the average, showing consistency in care. To calculate, find the average (mean), calculate each data point’s distance from the mean, square them, average those squares, and find the square root.

1.  Calculate the Mean

  • This is calculating the average by adding all audit data points and then dividing by the total number of items.

2.  Calculate Deviations

  • Subtract the mean from each individual data point.

3.  Square the Deviations

  • Square each result from step 2 to remove negative values.

4.  Sum of Squares

  • Add all squared values together.

5.  Calculate Variance

  • Divide the sum of squares (sample size minus one).

6.  Calculate Standard Deviation

  • Take the square root of the variance.
Square Root Formula

 σ is the standard deviation, xi is each individual data point in the set, µ is the mean, and N is the total number of data points. In the equation, xi, represents each individual data point. The results are then summed (symbolized as Σ), which is the numerator of the fraction from the equation.

Example: Audit of Patient Wait Times (Minutes)

Data (patient wait times): 10, 15, 20, 25, 30

Mean is 20:         (10 + 15 + 20 + 25 + 30) ÷ 5 = 100 ÷ 5 = 20

1.  Deviations:

  • 10 - 20 = -10
  • 15 - 20 = -5
  • 20 - 20 = 0
  • 25 - 20 = 5
  • 30 - 20 = 10

2.  Squared Deviations:

  • (-10)2 = 100
  • (-5)2 = 25
  • (0)2 = 0
  • (5)2 = 25
  • (10)2 = 100

3.  Sum of Squares: 100 + 25 + 0 + 25 + 100 = 250

4.  Variance: 250 ÷ (5 - 1) = 250 ÷ 4 = 62.5

5.  Standard Deviation: 62.5 ~ 7.90569 (round to 7.91)

6.  Audit Conclusion: The average wait time is 20 minutes with a standard deviation of 7.91 minutes

Conclusion

Understanding the significance of standard deviation is essential for modern auditing. It allows auditors to shift from a focus on the average to a focus on the variation. By providing a clear, quantified metric for variability, standard deviation allows auditors to quickly pinpoint financial risks and compliance issues that require investigation. Used alongside other audit tools, it ensures that companies can better manage risk, maintain control over processes, and optimize performance.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

National Library of Medicine

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
Corporate Compliance, HIPAA

The Hidden Risk in Multi Site Healthcare

When Visibility Fails, Compliance Follows 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

This article is for reference regarding risk management in healthcare, which is a complex topic and posted for educational purposes only. It is not intended as consulting or legal advice.

Introduction

Managing multiple healthcare facilities within a single organization has evolved from an operational responsibility to a complex enterprise risk function. As organizations expand across regions, states, and service lines, the ability to maintain consistent compliance, ensure patient safety, and protect financial performance becomes increasingly difficult without structured oversight.

For compliance and risk leaders, multi-site operations present a unique challenge. The risk is not limited to regulatory requirements or operational variability. The greatest risk is the loss of visibility. When leadership cannot clearly see what is occurring across sites in real time, issues are often identified only after they have already impacted patient care, compliance status, or revenue.

Recent federal guidance and national studies reinforce that multi-site risk is driven less by geographic dispersion and more by the absence of standardized oversight, integrated data, and structured accountability.¹ To manage multi-site healthcare environments effectively, organizations must move beyond decentralized oversight and adopt systems that promote accountability, visibility, and coordinated enterprise governance. Without these elements, growth introduces fragmentation rather than scalability.

The Risk Profile of Multi Site Healthcare Organizations

Multi-site healthcare organizations operate within a heightened risk environment driven by scale, variability, and complexity. While these risks are often described broadly, they consistently concentrate on specific operational and compliance areas that require targeted oversight. A primary risk is inconsistent application of regulatory requirements. Organizations governed by entities such as the Centers for Medicare & Medicaid Services and the Health Resources and Services Administration must ensure that standards related to documentation, billing, scope of services, and program integrity are applied uniformly across all locations. Variability in interpretation or execution increases the likelihood of audit findings, repayment exposure, and regulatory scrutiny.

Operational fragmentation is another critical concern. When sites operate with varying processes, undocumented workarounds, or informal practices, organizations lose the ability to ensure consistency and control. Over time, these inconsistencies evolve into systemic risk. Data fragmentation further compounds this issue. Without integrated systems, leadership lacks a reliable, centralized source of truth. This limits the organization’s ability to identify trends, monitor performance, and detect emerging risks before they escalate. Workforce variability also contributes to risk exposure. Differences in training, leadership capability, and staffing stability across sites directly affect compliance adherence, documentation quality, and patient safety outcomes.

Recent patient safety research demonstrates that breakdowns in communication, leadership engagement, and reporting culture are directly associated with lower safety performance and reduced incident reporting across healthcare organizations.²  In multi-site environments, these risks are amplified when leadership relies on inconsistent or anecdotal reporting rather than standardized enterprise data. Finally, delayed escalation of issues remains a persistent vulnerability. Without clear reporting structures and accountability, compliance concerns, incidents, and near misses may remain localized rather than addressed at the enterprise level.

High Risk Areas and Required Compliance Controls

Effective organizations do not manage multi-site risk at a high-level. They identify specific exposure areas and implement structured controls tied directly to those risks.

Documentation, Coding, and Billing Integrity - Variability in documentation and coding practices is one of the most significant sources of compliance exposure. Even with established policies, differences in provider behavior and oversight result in inconsistent application of requirements. Common risk patterns include insufficient documentation to support medical necessity, inconsistent use of modifiers, and failure to accurately capture services rendered. Across multiple sites, these inconsistencies increase audit vulnerability and repayment risk.

Administrative complexity and reliance on inconsistent workflows further increase risk and inefficiency across organizations. To mitigate this risk, organizations should implement centralized revenue integrity oversight, supported by routine pre and post billing audits. Documentation standards must be clearly defined and reinforced through targeted education tied directly to audit findings. Coding accuracy should be monitored through both random and focused audits, particularly in high-risk service lines. Transparent reporting of audit results reinforces accountability at both the provider and site level.

Sliding Fee Scale and Program Eligibility - For federally funded organizations, sliding fee scale compliance remains a critical risk area. Inconsistent eligibility determinations, failure to conduct required reevaluations, and inadequate documentation create exposure during audits and operational site visits. Organizations should implement standardized eligibility workflows supported by system controls that prevent incomplete processing. Routine audits should validate both documentation and application of discounts. Staff responsible for eligibility should receive structured training with defined competency expectations, and monitoring should include both process adherence and outcome accuracy.

Credentialing, Licensure, and Enrollment - Maintaining accurate credentialing and enrollment across multiple sites is operationally complex and highly regulated. Risks include expired licenses, services rendered prior to enrollment approval, and misalignment between credentialing records and payer systems. National credentialing standards emphasize ongoing monitoring, sanction checks, and oversight of delegated credentialing activities, particularly in multi-state environments.³

Centralized credentialing systems with automated alerts are essential. Organizations should maintain a single, validated source of provider data that is routinely reconciled with payer enrollment records. Pre-service verification processes should confirm that providers are eligible to render services. Routine audits should ensure alignment across credentialing, privileging, and enrollment data.

Patient Safety and Incident Reporting - Inconsistent reporting of incidents and near misses across sites creates significant patient safety and compliance risk. When reporting varies by location, organizations lose the ability to identify systemic issues. Recent studies highlight that organizations with stronger reporting cultures and leadership engagement demonstrate improved safety outcomes and increased event reporting.²

Centralized incident reporting systems should be implemented across all sites, with clearly defined expectations for reporting. Leadership must reinforce a culture that supports transparency and non-punitive reporting. Data should be trended at the enterprise level, and corrective actions should be tracked to completion. Regular leadership review ensures accountability and sustained improvement.

Data Integrity and Reporting - Reliable data is essential for effective oversight. In multi-site environments, inconsistent data definitions, delayed reporting, and lack of validation undermine decision making. Organizations should establish formal data governance structures that define standards, ownership, and validation processes. Standardized dashboards should be implemented across sites to ensure consistency in reporting. Data should be routinely reconciled across systems, and key risk indicators should be monitored consistently. Research indicates that dashboards are most effective when designed to drive action rather than simply display information.⁶

Workforce Competency and Training - Variability in workforce training directly impacts compliance and operational performance. Inconsistent onboarding, lack of role specific education, and high turnover create gaps in knowledge and execution. Standardized onboarding programs with defined competencies should be implemented across all sites. Ongoing training should be required and tracked, with reinforcement tied to identified risk areas. Competency should be validated through assessments and audit results to ensure effective application.

Vendor and Third-Party Oversight - Reliance on third party vendors introduces additional compliance and operational risk. Lack of visibility into vendor practices and misalignment with regulatory requirements can create exposure. Organizations should implement formal vendor risk management programs that include due diligence, clear contractual expectations, and ongoing performance monitoring. Vendors should be evaluated against defined compliance standards and subject to periodic audits. Contracts should clearly define accountability and regulatory obligations.

Enterprise Visibility and Remote Oversight

The most significant risk in multi-site operations is not complexity but lack of visibility. In organizations where leadership is remote or geographically dispersed, reliance on informal updates creates delayed awareness of risk. Federal compliance guidance emphasizes structured oversight, including risk assessments, auditing, monitoring, and board level reporting.¹ Organizations should establish a single enterprise view of risk that includes credentialing status, billing trends, patient safety events, training compliance, and corrective action tracking. Visibility must be standardized, real time, and actionable.

Accountability as an Enterprise Expectation - Accountability must be clearly defined and embedded at every level of the organization. Each site should have designated leadership responsible for compliance, quality, and operational performance, with measurable expectations aligned to enterprise standards. Research demonstrates that leadership structure and accountability directly influence safety culture, communication, and organizational performance. ⁵ Performance management should incorporate compliance metrics alongside operational goals. Enterprise leadership must maintain oversight through routine review of site performance, clear escalation pathways, and enforcement of corrective actions.

Systems, Monitoring, and Enterprise Oversight - Systems function as the infrastructure that supports compliance and risk management across multiple sites. Centralized platforms for audit tracking, incident reporting, credentialing, and performance monitoring provide the foundation for effective oversight. Monitoring should be continuous and risk based. Routine audits, data validation, and trend analysis allow organizations to identify patterns across sites and intervene proactively. Early warning indicators should be established to trigger action before risks escalate. Effective oversight requires translating data into action through structured governance and consistent follow through.

Addressing Blind Spots Through Validation and Culture

Blind spots represent one of the most significant risks in multi-site environments. These include underreported incidents, undocumented workarounds, and gaps in training that are not captured through standard reporting. Organizations must validate reported data through independent audits, direct observation, and cross site comparison. Identifying outliers often reveals underlying risk. Equally important is fostering a culture of transparency. Staff must feel supported in reporting concerns, and leadership must respond consistently to reinforce trust in reporting mechanisms.

Supporting Organizational Growth While Managing Risk

Growth must be supported by infrastructure and oversight. Research suggests that organizations that standardize core processes before expansion achieve more sustainable outcomes. ⁷ Organizations should ensure that systems, processes, and staffing models are scalable prior to expansion. Centralized governance should remain intact while allowing for controlled local execution. Data driven decision making should guide expansion, resource allocation, and performance improvement.

Conclusion

Managing multiple healthcare facilities requires a structured and deliberate approach to risk, compliance, and operational oversight. Multi-site environments introduce significant exposure across regulatory, clinical, operational, and financial domains. Across federal guidance and recent healthcare research, a consistent theme emerges. Multi-site success is driven by standardized visibility, structured accountability, integrated compliance controls, and proactive monitoring.¹ ² ³

Organizations that succeed invest in visibility, enforce accountability, and implement integrated systems that allow leadership to monitor performance in real time. By identifying specific risk areas and implementing targeted controls, organizations can reduce compliance exposure, strengthen patient safety, and support sustainable growth. In multi-site healthcare operations, risk is not created by scale alone. It is created by the absence of structure. Visibility, accountability, and systems remain the foundation of effective governance and long-term success.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Ms. Bertholette Pardieu, MPH, CCEP, OHCC is an accomplished compliance and risk leader with over a decade of experience developing and strengthening enterprise-wide compliance, governance, and risk programs across highly regulated healthcare sectors, including FQHCs, PBMs, and Medicare/Medicaid organizations. She currently serves as the Director of Risk Management & Corporate Compliance Officer for Broward Community & Family Health Centers, Inc. (the largest Federally Qualified Health Center in Broward County), overseeing risk, compliance and governance for a $16.4M multi-site FQHC system serving more than 13,000 patients. Previously, she led enterprise compliance risk initiatives at Convey Health Solutions, where she built the company’s first compliance risk program, directed effectiveness audits, and enhanced vendor oversight for national health plans.

A trusted advisor to executives and boards, Ms. Pardieu is known for her strategic mindset, collaborative leadership, and ability to embed compliance into organizational culture to protect against regulatory and operational risk. She holds a Master of Public Health from Florida International University and a Bachelor of Science from Barry University. Ms. Pardieu is a Certified Healthcare Compliance Officer (OHCC), with additional credentials including certifications in Corporate Compliance & Ethics and Healthcare Risk Management; and is a recent graduate of the Women’s Executive Leadership Accelerator Program through the Inclusion Learning Lab.

References

1. U.S. Department of Health and Human Services, Office of Inspector General
    General Compliance Program Guidance (2023)
    * Direct PDF (Full Guidance):
      
https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf
    * Official OIG Overview Page:
      
https://oig.hhs.gov/compliance/general-compliance-program-guidance/
2. Agency for Healthcare Research and Quality (AHRQ)
    Patient Safety Culture and Workforce Safety
    * 
https://psnet.ahrq.gov/perspective/ensuring-patient-and-workforce-safety-culture-healthcare
3. National Committee for Quality Assurance (NCQA)
    Credentialing Standards
    * 
https://www.ncqa.org/programs/health-plans/credentialing/benefits-support/standards/
4. Council for Affordable Quality Healthcare (CAQH)
    2023 CAQH Index Report
    * 
https://www.caqh.org/hubfs/43908627/drupal/2024-01/2023_CAQH_Index_Report.pdf
5. National Library of Medicine (PubMed)
    Leadership and Patient Safety Culture Systematic Review
    * 
https://pubmed.ncbi.nlm.nih.gov/41507881/
6. Journal of the American Medical Informatics Association (JAMIA Open)
    Healthcare Dashboard Effectiveness Study
    * 
https://academic.oup.com/jamiaopen/article/8/4/ooaf078/8214040
7. National Institutes of Health (PubMed Central)
    Healthcare Leadership Complexity and System Growth
    * 
https://pmc.ncbi.nlm.nih.gov/articles/PMC11223336/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Strong BAAs Build a Chain of Trust

Business Associate Agreements & Covered Entity Compliance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Building a chain of trust between healthcare providers (Covered Entities) and Business Associates (BAs) is a regulatory requirement under HIPAA designed to ensure that Protected Health Information (PHI) remains secure throughout its entire lifecycle, even when handled by third parties.

This chain of trust ensures that privacy and security obligations flow down to every subcontractor that creates, receives, maintains, or transmits PHI. This can produce increased confidence with your organization’s ability to earn and maintain patient trust.


Is Your Organization a Covered Entity, Business Associate or Both?

According to the Office of Civil Rights (OCR), the HIPAA enforcement agency, a Covered Entity (CE) is one of the following:

A Health Care Provider

A Health Plan

A Health care Clearinghouse

This includes providers such as:

  • Doctors
  • Clinics
  • Psychologists
  • Dentists
  • Chiropractors
  • Nursing Homes
  • Pharmacies

...but only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard.

This includes:

  • Health insurance companies
  • HMOs
  • Company health plans
  • Government programs that pay for health care, such as Medicare, Medicaid, and the military and veterans health care programs.

This includes entities that process nonstandard health information they receive from another entity into a standard (i.e., standard electronic format or data content), or vice versa.

It may not always be straightforward. If you are not sure if your organization is a covered entity – the Centers for Medicare & Medicaid Services (CMS) provides a an educational website and also a Covered Entity Decision Tool (58-pagePDF).

A HIPAA covered entity (CE) acts as a business associate (BA) when it performs functions or services involving protected health information (PHI) on behalf of another covered entity. This activity-specific role requires a Business Associate Agreement (BAA) for that specific work, even while the organization acts as a CE for its own operations.

The key distinction is that the "business associate" status applies to the service being performed (e.g., providing administrative services) rather than the entity's status as a healthcare provider or payer.

Key Scenarios and Requirements:

  • Services for Another CE: If a hospital (CE) handles billing or provides administrative services involving PHI for an unaffiliated clinic (another CE), the hospital acts as a BA.
  • Subcontractor Relationships: If a BA hires a covered entity to perform work involving PHI, that hired CE is acting as a BA to that BA.
  • Data Sharing: While sharing for "treatment" between CEs doesn't need a BAA, sharing for services to one another (e.g., managing a personal health record or PHR) does. Common examples include patient portals, health apps, and online trackers, which can contain medical history, diagnoses, and medication logs. According to OCR, it is an electronic application used by individuals to maintain and manage their own health information, rather than records solely controlled by a doctor or insurer (EHR).

          PHRs are often, but not always, covered by HIPAA regulations. Key details include:

  • Control: Unlike Electronic Health Records (EHRs) managed by providers, PHRs are managed by the individual or their caregiver.
  • Types: They can be tethered (linked to a provider) or standalone (independent).
  • HIPAA Coverage: If a PHR is provided by a HIPAA-covered entity (like a health plan or doctor), it is covered under the HIPAA Privacy Rule.
  • Alternative Protection: If a PHR is offered by a company not covered by HIPAA, it is governed by the FTC’s Health Breach Notification Rule.
  • Compliance: When acting as a BA, the entity must adhere to HIPAA Security Rule and Privacy Rule requirements for the PHI it handles for that specific relationship.

A covered entity functions as a business associate in the following type of situations:

  • Centralized Administrative Services: A hospital (CE) provides billing, claims processing, or data analytics services for an independent physician group or affiliated clinic.
    • A hospital acting as a central billing clearinghouse for independent physician groups.
  • Specialized Clinical Services: An independent laboratory (CE) that typically treats patients directly acts as a BA if it analyzes data for a health plan's quality improvement program.
    • A large health system providing laboratory services.
  • Data Processing Support: A health insurance company (CE) assists another health plan with data processing or administrative tasks.
    • Managed Service Providers or IT support that requires access to another entity’s patient records.
  • Patient Safety Organizations (PSOs): PSOs are specifically treated as business associates when they receive and analyze patient safety event reports from other providers. Key Covered Entity Requirements regarding use of PSOs:
    • Risk Analysis & Mitigation: CEs must perform risk assessments to identify threats to ePHI, including data shared with PSOs, and implement appropriate security measures.
    • Staff Training & Governance: Implement comprehensive training on identifying PSWP and handling it according to both HIPAA and safety rules.
    • Breach Reporting: Any unauthorized disclosure of PSWP is treated as a breach, requiring prompt response and reporting to the Office for Civil Rights (OCR)

Compliance Obligations for the Dual Role

When acting as a business associate, the covered entity is required to:

  • Sign a BAA: It must execute a formal agreement with the other covered entity before PHI is shared.
  • Adhere to BA Duties: It must follow the specific privacy and security requirements outlined for business associates, including reporting breaches and following "minimum necessary" standards.
  • Segregate Data: Large organizations often use internal "self-BAAs" or separate departments to ensure PHI from their BA activities is not improperly mingled with their own patient data.

For more detailed regulatory definitions, you can refer to the HHS Summary of the HIPAA Privacy Rule.

When a BAA is NOT Required Between Covered Entities

Not all exchanges of PHI between covered entities trigger a business associate relationship. A Business Associate Agreement (BAA) is generally not required for:

  • Treatment Purposes: When two independent providers disclose or exchange PHI for treatment purposes, such as a doctor referring a patient to a specialist or treating a shared patient.
  • Standard Payment Activities: When a provider submits a claim to a health plan and the plan pays it; both are acting on their own behalf as covered entities.
  • Organized Health Care Arrangements (OHCA): When entities participate in a joint arrangement, such as a group health plan and its insurer, to perform joint health care activities.
  • Conduit Exception: Organizations that only transport PHI and do not access or store it, such as the U.S. Postal Service, internet service providers (ISPs), or private couriers.
  • Incidental Access: Personnel who might see or hear PHI by chance while providing services, such as janitors, maintenance workers, or electricians, where the access is not the purpose of the work.
  • De-identified Data: Sharing data that does not contain identifiers, as long as it cannot be re-identified.

Not sure if a BAA is required?

Do you need help determining if a specific service your organization provides requires a Business Associate Agreement? Consult with a HIPAA-experienced attorney or consultant instead of “guessing” or consulting with an unqualified professional.

Act Now to be HIPAA Compliant

The HIPAA Final Rule is expected to be published in May 2026, with a 60-day effective date followed by a 180-day grace period for compliance. Covered entities should begin updating their policies now to meet these more stringent requirements.

Establishing a strong chain of trust under HIPAA requires vendor contracts to be updated, compliant and translate legal requirements into operational controls. A robust BAA ensures that all parties involved in creating, storing, and transmitting ePHI (overed entities, business associates, and subcontractors), are bound by the same rigorous privacy and security standards, mitigating risk in an era where nearly half of all HIPAA breaches involve third-party vendors.

A legally binding Business Associate Agreement (BAA) is the foundational document of the chain of trust.

A robust BAA ensures that all parties—covered entities, business associates, and subcontractors—are bound by the same rigorous privacy and security standards, mitigating risk in an era where nearly half of all HIPAA breaches involve third-party vendors.

  • Mandatory Clauses: The BAA must explicitly outline permitted uses/disclosures, require the implementation of safeguards (administrative, physical, and technical), and mandate prompt breach reporting.
  • Defined Scope and Data Flows: Explicitly mapping where Protected Health Information (PHI) is created, stored, or transmitted to ensure the "minimum necessary" standard is applied.
  • Subcontractor Flow-Down Obligations: A crucial component requiring the business associate to bind any subcontractors to the same level of security and privacy protections.
  • Stringent Breach Notification Procedures: Defining clear timelines (e.g., within 60 days, or faster, such as 24-hour notice for emergency plans) for reporting incidents to the covered entity.
  • Security Safeguards Requirement: Mandating administrative, physical, and technical safeguards, including encryption in transit/at rest, multi-factor authentication (MFA), and regular risk assessments.
  • Termination and Destruction Protocol: Ensuring that upon contract termination, PHI is either returned or securely destroyed, with no further retention.
  • Audit and Compliance Rights: Granting the covered entity the right to audit the vendor's security controls and requiring access to records for HHS investigations
  • Pre-engagement Requirement: The BAA must be signed before any PHI is shared.

Do Your Due Diligence - Trust is built on verification, not just contracts. Conduct comprehensive risk assessments to evaluate a vendor's security posture, policies, and procedures before partnering.

  • Verify the vendor’s compliance.
  • Review the vendor's documented risk analyses, audit trails, and, if applicable, third-party certifications.

Best Practices for Maintaining the Chain of Trust –

  • Regular Updates: Reviewing and updating BAAs whenever services, technologies (e.g., cloud, AI), or regulations change, such as preparing for upcoming 2025 HIPAA revisions.
  • Vendor Due Diligence: Assessing a business associate's security posture before signing a BAA, rather than relying solely on the contract for security.
  • Employee Training: Ensuring the business associate trains its staff on the specific requirements of the BAA.
  • Assigning Liability: Clearly defining which party covers financial penalties, legal fees, or remediation costs in the event of a breach.

Consult with a HIPAA legal expert to assist your organization as you update your BAAs to be compliant to the New Final Rule. By tightening your BAAs and relationships with vendors, you will move from a compliance posture to an active, operationalized partnership that protects patient data, reputation and builds patient trust.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with  Officer of the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Vendor Compliance – Old Problem, New Risks

Written by Susan Lee Walberg, JD MPA CHC 

Compliance Officers are always stretched thin with many responsibilities, and those duties seem to constantly grow with each year and every new law or regulation. One of the more challenging areas to monitor is the compliance of our vendors and Business Associates.

I believe this is now more important than ever. Why? Because cybercrime, hacking, phishing, and impersonation schemes are rampant, and the cyber-crooks are now using AI to circumvent our (and our vendor’s) security measures.

How many times have we heard about a major breach, and the root cause was a failure to conduct a Security Risk Assessment or apply patches or software updates timely? A failure of routine training is also often to blame. Over 60% of breaches are caused by Business Associates, so this is an area of risk that I believe needs more attention.

Over the years, I have found that prevention is the best cure. There are several steps we can take on the front end to reduce the risk of non-compliance during the term of the Agreement.

1.  Compliance needs to be at the table BEFORE arrangements are entered into. It’s not unheard of, in a large health system, for the compliance officer to not even know about every joint venture or acquisition, but, when there’s a compliance problem at that entity, they are on the hook. It’s critical to build trust with leadership, and educate them as to why Compliance needs to be at the table. We need to understand what the arrangement is about, why we are doing it, and who is paying what to who. If Compliance isn’t informed and engaged, some of these other steps likely won’t happen.

2.  Due diligence is critical for new business partners. While the finance team reviews the balance sheet, Compliance needs to be reviewing the organization’s compliance program, culture and reputation. There should be a document list the Compliance reviews for acquisitions and partnerships, but even for contracted services, we want to take a peek and do some basic reviews.

  • Review their Compliance Plan (and how often it’s been reviewed and updated)
  • Have a conversation with their compliance, privacy, and/or security officer to get a better sense of how they operate
  • Find out if they’ve been subject to any investigations
  • Run a List of Excluded Individuals and Entities (LEIE) OIG check
  • Ask to see their most recent Security Risk Assessment, if ePHI is going to be involved

Pay careful attention to any referrals that are considered as part of the contract. These are not only for physicians, but they can also be an IT vendor or other provider of goods or services-there have been plenty of cases where companies, such as Electronic Medical Record (EMR) companies have been found in violation of the Anti-Kickback statute. Have an attorney review it if this isn’t your area of expertise. The bottom line is to ask yourself if the arrangement itself is appropriate.

Those are just some suggestions, but at least these activities would give you a sense of how much they tend to compliance. Also, it never hurts to do a basic Google search. If they aren’t a new organization, and if they have any ethical or legal issues, you will likely find reviews on the Better Business Bureau site and/or sites where employees and customers can give a rating/review. That activity alone can speak volumes if the organization has a culture problem.

3. Contract provisions need to include compliance. Although bad actors sign contracts all the time, it still helps protect       your organization and does show that you take compliance and ethics seriously. Some suggested provisions:

  • The vendor agrees to comply with all applicable laws, rules, and regulations, including False Claims Act, Stark, HIPAA, and any other that are key for your business and the type of services.
  • The vendor agrees that you are allowed to audit their processes and records that pertain to the services under the contract
  • The vendor agrees that all their employees are checked for disbarment and that none of their employees or contractors are disqualified to participate in government health care programs; and to notify you immediately if that changes.
  • The vendor agrees and attests that they have a compliance, privacy, and security program that meets or exceeds industry and regulatory standards, and that they maintain stringent security standards to protect the integrity of ePHI.
  • Breach notification and remediation procedures need to be detailed. How long after a breach is identified must you be notified? Who notifies clients? Review the breach response requirements under HIPAA and make sure you address those.
  • Data use is an important provision. Review your contract or Business Associate Agreement, keeping in mind that data is now as valuable as gold. Can your business partners sell your data? What if it’s de-identified? Are you comfortable with them doing so, and does your agreed-upon rate take that into account? The advent of AI makes data much more valuable.
  • Adherence and compliance to all Medicare regulations, especially if this is a contract for any business office, documentation, coding, or record review service.

4. Training requirements are not optional. Privacy, Security, and Compliance training should be provided to the vendor’s   employees, or they can take training you provide, if you have that option. If they have their own program, it’s totally acceptable to ask to see it. Ongoing data security training, in particular, is important due to the constantly evolving phishing and other schemes.

5. Make sure you have tight controls on granting access to your information. Your business partner can’t just get one log-in that everyone uses. That should be a core requirement for data access-unique user IDs and passwords.

Those are some key front-end steps. Once the agreement is in place, if the previous activities are completed there shouldn’t really be a heavy load of monitoring, absent some incident or breach. Here are a few things to consider:

  • Stay in contact with the process/contract owner and ask how things are going. If there are problems, that person is likely the first to know. Make sure they know to call you if something starts to go sideways.
  • Conduct any audits or monitoring you included in the contract, if you’re able to (it’s a resource issue, for sure)
  • Send occasional surveys to your vendors inquiring about their compliance, privacy, or security measures. This at least lets them know you are paying attention.
  • Touch base with their compliance, privacy, or security officers
  • Monitor training logs, if they receive training from you (or ask them to provide that information)
  • Look them up online now and then to see if there are any new complaints out there.
  • Get an audit of what information their employees are viewing-make sure it’s appropriate.

Monitoring your vendors can seem like just one too many things to do, and most of the time you will find that there are no red flags. Most businesses try to do the right thing. But it’s important to keep in mind how much of a risk they could pose to your organization, especially if they are handling patient information and/or billing functions. You don’t want to be looking back and wishing you had done it and having to explain that to your leadership!

About the Author Susan Lee Walberg, JD MPA CHC

Ms. Walberg is an author, attorney and healthcare compliance consultant. She is available to help anyone work through these processes and provides a full range of compliance-related services and books, including serving as a fractional Compliance or Privacy Officer, or in an interim role. She can be contacted by email at swalberg@compliancealacarte.com, or find more about services and books on her website at susanwalberg.com or on LinkedIn!

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More