Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Common Compliance Risks in OB/GYN Medical Billing and How to Address Them

Written by Noah Smith for BillingFreedom

The article will help healthcare professionals identify common compliance risks that can arise in OB-GYN medical billing and understand practical approaches for addressing those risks through accurate documentation, coding, claim review, internal audits, and consistent billing workflows.

OB/GYN billing can get complicated quickly. During the same week, a practice may bill for preventive visits, ultrasounds, office procedures, prenatal care, surgery, delivery services, postpartum visits, and treatment for unrelated gynecologic conditions. Those services do not always follow the same documentation, coding, or payer rules. That leaves plenty of room for small mistakes to slip into the billing process.

Sometimes the problem is obvious. A claim is rejected because the subscriber number is wrong or a required field is missing. Other problems are harder to notice. A payer may process a claim even though the documentation is weak, a modifier has been used inconsistently, or staff are following an outdated billing process.

One paid claim does not necessarily tell a practice that everything behind the claim was handled correctly. A better way to think about compliance is to look at the entire path a claim takes:

  • Patient information has to be accurate.
  • Coverage needs to be checked.
  • The provider's note has to support the service.
  • Coding needs to match the record, and payer requirements have to be addressed before the claim goes out.

When one part of that chain breaks down repeatedly, the problem can spread across dozens of claims before anyone recognizes the pattern.

Where OB/GYN Billing Problems Usually Start

Many compliance issues begin before a coder ever looks at the chart. Consider a returning patient whose insurance changed since her last appointment. If the old plan is still listed in the system, the claim may be sent to the wrong payer. By the time the rejection comes back, staff may need to update the account, verify benefits again, rebill the service, and make sure a filing deadline has not been missed.

Authorization problems can develop in much the same way. A service may have been appropriate and clearly documented, yet the claim can still run into trouble if the payer required prior authorization and nobody confirmed it.

Then there is the medical record itself. A provider may remember exactly what was discussed or performed during a visit, but the billing team can only rely on what appears in the documentation. If the note does not clearly support the service being reported, defending the claim later becomes much more difficult.

The Centers for Medicare & Medicaid Services (CMS) provides guidance on electronic healthcare claims and the information needed for claims processing. The larger point for a practice is simple: compliance starts long before a denial or payer review arrives.

Documentation and Coding Need to Tell the Same Story

Documentation and coding are often discussed as separate tasks. In actual billing, they are difficult to separate. The code on the claim is supposed to represent what happened during the encounter. The medical record is what supports that representation.

Problems begin when the two tell different stories.

A common OB/GYN situation is a preventive visit in which the patient also brings up a new medical concern. Additional evaluation may take place during the same encounter. Whether separate reporting is appropriate depends on the services performed, the documentation, coding rules, and the payer's requirements. Similar questions come up with procedures, diagnostic testing, postoperative care, maternity services, and modifier use.

A diagnosis code may be valid in general but still fail to match what the provider actually documented. A procedure code may describe a service correctly but lack enough support in the chart. A modifier can also create problems when staff use it routinely instead of deciding whether the circumstances of that particular encounter justify it. These are not always dramatic errors. That is part of the problem.

When the same documentation habit or coding shortcut is repeated week after week, an isolated weakness can turn into a larger compliance concern.

Periodic chart-to-claim reviews can help uncover those patterns. Instead of asking only whether the claim was paid, the reviewer looks at whether the claim accurately reflects the record and whether the documentation is strong enough to support what was billed.

Some Claim Errors Have Nothing to Do with Complex Coding

Not every denied or rejected claim involves a difficult coding question. Sometimes the problem is a wrong date, an outdated insurance record, missing provider information, an incorrect subscriber ID, or a claim field that was left incomplete. These errors may sound minor, but they still consume staff time and slow down payment.

Electronic claims generally pass through automated edits during processing. Certain missing or inconsistent details can cause the claim to stop before it gets very far.

A short review before submission can catch many of those problems. Staff may want to verify:

  1. Patient and subscriber information.
  2. Current insurance coverage and coordination of benefits.
  3. Provider and practice identifiers.
  4. Diagnosis codes, procedure codes, and modifiers.
  5. Documentation supporting the billed service.
  6. Required authorization or referral information.
  7. Payer-specific claim requirements and missing fields.

The review does not have to turn into a lengthy approval process for every claim. What matters is that the practice has a reliable way to catch repeatable errors before the payer does.

Eligibility Deserves More Attention in OB/GYN Billing

Insurance information can change during the course of care, and OB/GYN practices are especially likely to encounter that issue because many patients receive services over an extended period.

Pregnancy is an obvious example. A patient may have one insurance plan early in the pregnancy and another later. Employment can change. A spouse's coverage can change. Coordination of benefits may need to be updated. Authorization rules may also be different under the new plan. If staff rely on an eligibility check performed months earlier, the billing team may not find out about the change until a claim is denied.

Eligibility problems can affect more than reimbursement. They may also result in the wrong amount being assigned to the patient or create confusion about who is financially responsible for the service.

Checking coverage at appropriate points throughout treatment gives staff a chance to address those issues before the claim has already gone through the billing cycle. It also makes financial conversations with patients more accurate.

A Denial May Be Pointing to a Workflow Problem

Correcting a denied claim is necessary. Correcting the same type of denial twenty times should raise a different question - Why does it keep happening?

Suppose claims for a particular procedure regularly come back because information is missing. Billing staff can add the information and resubmit each claim, but that does not explain why the original claims were incomplete.

Maybe the registration team is not collecting something the payer requires. Perhaps the authorization information exists but is not being transferred correctly. It could also be that staff misunderstood a payer policy. The denial itself is only the visible part of the problem.

This is why useful denial management goes beyond counting how many claims were denied. Practices can look at which reasons occur most often, which payers are involved, whether one service keeps appearing, and where in the workflow the original error began.

That kind of review can reveal patterns that would otherwise remain hidden. The CMS Medical Review and Education resources also discuss claims analysis and medical record review in the context of identifying improper billing and documentation issues. For an OB/GYN practice, denial data can serve as a practical warning system. It shows where the revenue cycle is struggling, not just where payment was delayed.

Internal Audits Can Be Small and Still Be Useful

An internal audit does not have to involve hundreds of charts. A practice can learn a great deal from a carefully chosen sample.

Maybe one modifier has been causing questions. Perhaps a particular payer has denied an unusually high number of claims. There may be concerns about preventive visits, maternity billing, surgery, medical necessity documentation, or another service that carries more risk. Those claims can be reviewed against the medical record.

The reviewer may find that everything was handled appropriately. If not, the next step is to determine whether the problem was isolated or whether it reflects a larger habit. That distinction matters. One coding mistake made on a single claim may require a simple correction. Finding the same mistake across several providers or multiple dates of service suggests that the practice may need education, a workflow change, or closer monitoring. The audit should not end when the error is identified.

If a change is made, the practice needs some way to determine whether it worked. Reviewing another sample later can show whether the same problem is still appearing. Without follow-up, the practice has documented a problem but has not necessarily solved it.

Compliance Works Better When It Is Part of Routine Operations

A compliance process does not need to be complicated to be useful. In many practices, consistency matters more than creating a large set of policies that nobody uses. Staff should know how registration is handled, when eligibility is checked, how authorization information is recorded, how claims are reviewed, what happens when a denial arrives, and who is responsible for following up on recurring problems.

Those processes should not exist only in one employee's memory. Training matters for the same reason. Payer policies change. Coding guidance changes. Internal workflows change. New employees arrive, and experienced employees sometimes continue using a process that made sense under an older rule.

Regular education gives the practice a chance to catch those gaps.

Billing data can also help determine where training is needed. If eligibility denials suddenly increase, the first response should not necessarily be a general coding seminar. The practice may need to look at registration and verification instead. If several claims involving the same modifier are being questioned, a focused review of those encounters is probably more useful than retraining the entire staff on every coding topic. Compliance becomes easier to manage when the response matches the actual problem.

Documentation Reviews Should Include the Claim

A chart can look complete on its own while the corresponding claim still contains a problem.

The opposite is also possible. A claim may appear technically correct until someone compares it with the medical record.

Looking at both together usually provides a clearer picture. This is particularly important for services where the circumstances of the encounter affect billing. Preventive care, problem-oriented visits, procedures, maternity care, and postoperative services can all raise questions that cannot be answered by looking at a code alone.

The reviewer needs to understand what actually happened during the visit, what the provider documented, and how that information was translated into the claim.

Preparing for Billing Changes Before They Reach the Claims Department

One of the easiest ways for a billing problem to spread is for a rule to change while the practice keeps following the old process. Changes may affect coding, documentation, payer policies, reimbursement, or the way certain services are reported.

The first sign should not have to be a wave of denials.

When a significant change is announced, the practice can identify which services will be affected and who needs to know about it. Providers may need different documentation. Billing staff may need revised procedures. Software settings or claim edits may also need to be updated. Testing the new process early is usually easier than correcting a backlog later. This becomes especially important when changes affect maternity services because the care and billing may span several months.

The Bigger Compliance Question

A claim can be paid and still come from a weak process. That is why payment should not be the only measure of whether an OB/GYN billing operation is working well. A better question is whether the practice could explain and support the claim if someone reviewed it later.

  • Was the patient's coverage checked?
  • Does the chart support the service?
  • Does the code match what was documented?
  • Were payer requirements addressed?
  • If a similar problem appeared last month, was anything changed afterward?

Those questions bring compliance into the normal revenue-cycle process instead of treating it as something that matters only during an audit.

Most billing problems do not begin as major compliance failures. They usually start much smaller: an insurance detail that was not updated, documentation that was a little too vague, a modifier applied out of habit, or a denial that was corrected without asking why it happened.

The risk grows when the same issue becomes routine.

Finding those patterns early is what gives a practice the best chance to correct them before they affect more claims, more patients, or more revenue.

About the Author Noah Smith

This article is written by Noah Smith on behalf of BillingFreedom. Noah is a medical biller, SEO and Content Outreach Specialist.

Additional Resources

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Auditing and Standard Deviation

The Importance of Statistical Significance 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

Information provided below is a basic overview of standard deviation when Auditing for Compliance and quality standards. It is not intended as being comprehensive, legal or consulting advice. You may be interested in other auditing articles – click here. 

Introduction

In an increasingly data-driven corporate healthcare environment, auditing has moved beyond traditional spot-checking to advanced analytics. Standard deviation, a statistical measure of dispersion, has become an essential tool for auditors to assess risk and operational performance. By quantifying how data points, such as transaction amounts, process times, or product quality metrics deviate from the mean, auditors can identify anomalies, measure volatility, and evaluate the consistency of operational processes.

This paper explores how standard deviation helps audit financial risk by identifying outliers and market volatility, and how it improves operational efficiency by highlighting process variations.

Why Standard Deviation (SD) is Vital

In simpler terms, standard deviation measures the variation in the data. A higher variance requires a larger sample size to achieve statistical significance. It represents the average amount of variation or dispersion of data points from the mean.

Standard deviation is another measure of dispersion that complements variance. Standard deviation indicates how spread out the data points are in relation to the mean. Just like variance, standard deviation helps us understand the consistency and reliability of the data.

  • SD helps to identify outliers and anomalies. Auditors use standard deviation to pinpoint unusual data points that fall far from the mean to flag potential fraud, waste, billing errors, patient waiting times and quality measures.
  • SD is used to assess consistency. In auditing, a small standard deviation indicates consistent performance, while a high one suggests unreliable processes or high variability.
  • Calculating SD is vital when used in evaluating treatment/clinical variation. It helps determine if outcomes are consistent across a population. High standard deviation in medical data indicates inconsistent patient responses, which may signal a need for audits on clinical quality.

Understanding Risk and Performance

Financial risk management requires understanding volatility and uncertainty. Standard deviation serves as a proxy for this risk, helping auditors and financial analysts determine the potential for loss or unpredictability.

Auditors are tasked with providing assurance on financial statements and improving business processes. While averages (means) provide a central reference point, they often disguise underlying inconsistencies or high-risk outliers.

Standard deviation (SD) is essential because it measures the spread of data; a small standard deviation indicates consistency, while a high standard deviation indicates high variability. For auditors, this variability is synonymous with risk and potential inefficiency.

It is essential for auditing financial risk and operational efficiency because it permits auditors to see if "average" performance is due to uniform, acceptable results, or a mix of excellent and failing results.

Standard deviation is particularly useful for auditors due to its specific mathematical properties:

  • Sensitivity to Outliers: Because standard deviation squares the variance, it heavily impacts outliers, making it an effective tool for surfacing extreme cases.
  • Comparability (Scale Invariance): Auditors can directly compare the volatility of different datasets, even if they are in different units, allowing for comprehensive risk assessment across diverse business units.
  • The Normal Curve (Bell Curve): In a normal distribution, roughly 68% of data falls within one SD, 95% within two, and 99.7% within three. Auditors can use these intervals to define "normal" transactions and immediately identify the 5% that are outliers.

While powerful, standard deviation has limitations that auditors must recognize:

  • Assumes Normal Distribution: It works best with normal, bell-shaped curves. If data is heavily skewed or has fat tails, standard deviation might underestimate tail risk (rare but extreme events).
  • Backward-Looking: It is based on historical data, which may not repeat in the future.
  • Treats Volatility Equally: It treats positive and negative deviations equally, whereas auditors are primarily concerned with downside risk.

Steps to Calculate Sample Standard Deviation (SD)

Calculating standard deviation for a health care audit measures how much individual data points (e.g., patient wait times, billing errors) differ from the average, showing consistency in care. To calculate, find the average (mean), calculate each data point’s distance from the mean, square them, average those squares, and find the square root.

1.  Calculate the Mean

  • This is calculating the average by adding all audit data points and then dividing by the total number of items.

2.  Calculate Deviations

  • Subtract the mean from each individual data point.

3.  Square the Deviations

  • Square each result from step 2 to remove negative values.

4.  Sum of Squares

  • Add all squared values together.

5.  Calculate Variance

  • Divide the sum of squares (sample size minus one).

6.  Calculate Standard Deviation

  • Take the square root of the variance.
Square Root Formula

 σ is the standard deviation, xi is each individual data point in the set, µ is the mean, and N is the total number of data points. In the equation, xi, represents each individual data point. The results are then summed (symbolized as Σ), which is the numerator of the fraction from the equation.

Example: Audit of Patient Wait Times (Minutes)

Data (patient wait times): 10, 15, 20, 25, 30

Mean is 20:         (10 + 15 + 20 + 25 + 30) ÷ 5 = 100 ÷ 5 = 20

1.  Deviations:

  • 10 - 20 = -10
  • 15 - 20 = -5
  • 20 - 20 = 0
  • 25 - 20 = 5
  • 30 - 20 = 10

2.  Squared Deviations:

  • (-10)2 = 100
  • (-5)2 = 25
  • (0)2 = 0
  • (5)2 = 25
  • (10)2 = 100

3.  Sum of Squares: 100 + 25 + 0 + 25 + 100 = 250

4.  Variance: 250 ÷ (5 - 1) = 250 ÷ 4 = 62.5

5.  Standard Deviation: 62.5 ~ 7.90569 (round to 7.91)

6.  Audit Conclusion: The average wait time is 20 minutes with a standard deviation of 7.91 minutes

Conclusion

Understanding the significance of standard deviation is essential for modern auditing. It allows auditors to shift from a focus on the average to a focus on the variation. By providing a clear, quantified metric for variability, standard deviation allows auditors to quickly pinpoint financial risks and compliance issues that require investigation. Used alongside other audit tools, it ensures that companies can better manage risk, maintain control over processes, and optimize performance.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

References

AIHC

National Library of Medicine

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
Corporate Compliance, HIPAA

The Hidden Risk in Multi Site Healthcare

When Visibility Fails, Compliance Follows 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

This article is for reference regarding risk management in healthcare, which is a complex topic and posted for educational purposes only. It is not intended as consulting or legal advice.

Introduction

Managing multiple healthcare facilities within a single organization has evolved from an operational responsibility to a complex enterprise risk function. As organizations expand across regions, states, and service lines, the ability to maintain consistent compliance, ensure patient safety, and protect financial performance becomes increasingly difficult without structured oversight.

For compliance and risk leaders, multi-site operations present a unique challenge. The risk is not limited to regulatory requirements or operational variability. The greatest risk is the loss of visibility. When leadership cannot clearly see what is occurring across sites in real time, issues are often identified only after they have already impacted patient care, compliance status, or revenue.

Recent federal guidance and national studies reinforce that multi-site risk is driven less by geographic dispersion and more by the absence of standardized oversight, integrated data, and structured accountability.¹ To manage multi-site healthcare environments effectively, organizations must move beyond decentralized oversight and adopt systems that promote accountability, visibility, and coordinated enterprise governance. Without these elements, growth introduces fragmentation rather than scalability.

The Risk Profile of Multi Site Healthcare Organizations

Multi-site healthcare organizations operate within a heightened risk environment driven by scale, variability, and complexity. While these risks are often described broadly, they consistently concentrate on specific operational and compliance areas that require targeted oversight. A primary risk is inconsistent application of regulatory requirements. Organizations governed by entities such as the Centers for Medicare & Medicaid Services and the Health Resources and Services Administration must ensure that standards related to documentation, billing, scope of services, and program integrity are applied uniformly across all locations. Variability in interpretation or execution increases the likelihood of audit findings, repayment exposure, and regulatory scrutiny.

Operational fragmentation is another critical concern. When sites operate with varying processes, undocumented workarounds, or informal practices, organizations lose the ability to ensure consistency and control. Over time, these inconsistencies evolve into systemic risk. Data fragmentation further compounds this issue. Without integrated systems, leadership lacks a reliable, centralized source of truth. This limits the organization’s ability to identify trends, monitor performance, and detect emerging risks before they escalate. Workforce variability also contributes to risk exposure. Differences in training, leadership capability, and staffing stability across sites directly affect compliance adherence, documentation quality, and patient safety outcomes.

Recent patient safety research demonstrates that breakdowns in communication, leadership engagement, and reporting culture are directly associated with lower safety performance and reduced incident reporting across healthcare organizations.²  In multi-site environments, these risks are amplified when leadership relies on inconsistent or anecdotal reporting rather than standardized enterprise data. Finally, delayed escalation of issues remains a persistent vulnerability. Without clear reporting structures and accountability, compliance concerns, incidents, and near misses may remain localized rather than addressed at the enterprise level.

High Risk Areas and Required Compliance Controls

Effective organizations do not manage multi-site risk at a high-level. They identify specific exposure areas and implement structured controls tied directly to those risks.

Documentation, Coding, and Billing Integrity - Variability in documentation and coding practices is one of the most significant sources of compliance exposure. Even with established policies, differences in provider behavior and oversight result in inconsistent application of requirements. Common risk patterns include insufficient documentation to support medical necessity, inconsistent use of modifiers, and failure to accurately capture services rendered. Across multiple sites, these inconsistencies increase audit vulnerability and repayment risk.

Administrative complexity and reliance on inconsistent workflows further increase risk and inefficiency across organizations. To mitigate this risk, organizations should implement centralized revenue integrity oversight, supported by routine pre and post billing audits. Documentation standards must be clearly defined and reinforced through targeted education tied directly to audit findings. Coding accuracy should be monitored through both random and focused audits, particularly in high-risk service lines. Transparent reporting of audit results reinforces accountability at both the provider and site level.

Sliding Fee Scale and Program Eligibility - For federally funded organizations, sliding fee scale compliance remains a critical risk area. Inconsistent eligibility determinations, failure to conduct required reevaluations, and inadequate documentation create exposure during audits and operational site visits. Organizations should implement standardized eligibility workflows supported by system controls that prevent incomplete processing. Routine audits should validate both documentation and application of discounts. Staff responsible for eligibility should receive structured training with defined competency expectations, and monitoring should include both process adherence and outcome accuracy.

Credentialing, Licensure, and Enrollment - Maintaining accurate credentialing and enrollment across multiple sites is operationally complex and highly regulated. Risks include expired licenses, services rendered prior to enrollment approval, and misalignment between credentialing records and payer systems. National credentialing standards emphasize ongoing monitoring, sanction checks, and oversight of delegated credentialing activities, particularly in multi-state environments.³

Centralized credentialing systems with automated alerts are essential. Organizations should maintain a single, validated source of provider data that is routinely reconciled with payer enrollment records. Pre-service verification processes should confirm that providers are eligible to render services. Routine audits should ensure alignment across credentialing, privileging, and enrollment data.

Patient Safety and Incident Reporting - Inconsistent reporting of incidents and near misses across sites creates significant patient safety and compliance risk. When reporting varies by location, organizations lose the ability to identify systemic issues. Recent studies highlight that organizations with stronger reporting cultures and leadership engagement demonstrate improved safety outcomes and increased event reporting.²

Centralized incident reporting systems should be implemented across all sites, with clearly defined expectations for reporting. Leadership must reinforce a culture that supports transparency and non-punitive reporting. Data should be trended at the enterprise level, and corrective actions should be tracked to completion. Regular leadership review ensures accountability and sustained improvement.

Data Integrity and Reporting - Reliable data is essential for effective oversight. In multi-site environments, inconsistent data definitions, delayed reporting, and lack of validation undermine decision making. Organizations should establish formal data governance structures that define standards, ownership, and validation processes. Standardized dashboards should be implemented across sites to ensure consistency in reporting. Data should be routinely reconciled across systems, and key risk indicators should be monitored consistently. Research indicates that dashboards are most effective when designed to drive action rather than simply display information.⁶

Workforce Competency and Training - Variability in workforce training directly impacts compliance and operational performance. Inconsistent onboarding, lack of role specific education, and high turnover create gaps in knowledge and execution. Standardized onboarding programs with defined competencies should be implemented across all sites. Ongoing training should be required and tracked, with reinforcement tied to identified risk areas. Competency should be validated through assessments and audit results to ensure effective application.

Vendor and Third-Party Oversight - Reliance on third party vendors introduces additional compliance and operational risk. Lack of visibility into vendor practices and misalignment with regulatory requirements can create exposure. Organizations should implement formal vendor risk management programs that include due diligence, clear contractual expectations, and ongoing performance monitoring. Vendors should be evaluated against defined compliance standards and subject to periodic audits. Contracts should clearly define accountability and regulatory obligations.

Enterprise Visibility and Remote Oversight

The most significant risk in multi-site operations is not complexity but lack of visibility. In organizations where leadership is remote or geographically dispersed, reliance on informal updates creates delayed awareness of risk. Federal compliance guidance emphasizes structured oversight, including risk assessments, auditing, monitoring, and board level reporting.¹ Organizations should establish a single enterprise view of risk that includes credentialing status, billing trends, patient safety events, training compliance, and corrective action tracking. Visibility must be standardized, real time, and actionable.

Accountability as an Enterprise Expectation - Accountability must be clearly defined and embedded at every level of the organization. Each site should have designated leadership responsible for compliance, quality, and operational performance, with measurable expectations aligned to enterprise standards. Research demonstrates that leadership structure and accountability directly influence safety culture, communication, and organizational performance. ⁵ Performance management should incorporate compliance metrics alongside operational goals. Enterprise leadership must maintain oversight through routine review of site performance, clear escalation pathways, and enforcement of corrective actions.

Systems, Monitoring, and Enterprise Oversight - Systems function as the infrastructure that supports compliance and risk management across multiple sites. Centralized platforms for audit tracking, incident reporting, credentialing, and performance monitoring provide the foundation for effective oversight. Monitoring should be continuous and risk based. Routine audits, data validation, and trend analysis allow organizations to identify patterns across sites and intervene proactively. Early warning indicators should be established to trigger action before risks escalate. Effective oversight requires translating data into action through structured governance and consistent follow through.

Addressing Blind Spots Through Validation and Culture

Blind spots represent one of the most significant risks in multi-site environments. These include underreported incidents, undocumented workarounds, and gaps in training that are not captured through standard reporting. Organizations must validate reported data through independent audits, direct observation, and cross site comparison. Identifying outliers often reveals underlying risk. Equally important is fostering a culture of transparency. Staff must feel supported in reporting concerns, and leadership must respond consistently to reinforce trust in reporting mechanisms.

Supporting Organizational Growth While Managing Risk

Growth must be supported by infrastructure and oversight. Research suggests that organizations that standardize core processes before expansion achieve more sustainable outcomes. ⁷ Organizations should ensure that systems, processes, and staffing models are scalable prior to expansion. Centralized governance should remain intact while allowing for controlled local execution. Data driven decision making should guide expansion, resource allocation, and performance improvement.

Conclusion

Managing multiple healthcare facilities requires a structured and deliberate approach to risk, compliance, and operational oversight. Multi-site environments introduce significant exposure across regulatory, clinical, operational, and financial domains. Across federal guidance and recent healthcare research, a consistent theme emerges. Multi-site success is driven by standardized visibility, structured accountability, integrated compliance controls, and proactive monitoring.¹ ² ³

Organizations that succeed invest in visibility, enforce accountability, and implement integrated systems that allow leadership to monitor performance in real time. By identifying specific risk areas and implementing targeted controls, organizations can reduce compliance exposure, strengthen patient safety, and support sustainable growth. In multi-site healthcare operations, risk is not created by scale alone. It is created by the absence of structure. Visibility, accountability, and systems remain the foundation of effective governance and long-term success.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Ms. Bertholette Pardieu, MPH, CCEP, OHCC is an accomplished compliance and risk leader with over a decade of experience developing and strengthening enterprise-wide compliance, governance, and risk programs across highly regulated healthcare sectors, including FQHCs, PBMs, and Medicare/Medicaid organizations. She currently serves as the Director of Risk Management & Corporate Compliance Officer for Broward Community & Family Health Centers, Inc. (the largest Federally Qualified Health Center in Broward County), overseeing risk, compliance and governance for a $16.4M multi-site FQHC system serving more than 13,000 patients. Previously, she led enterprise compliance risk initiatives at Convey Health Solutions, where she built the company’s first compliance risk program, directed effectiveness audits, and enhanced vendor oversight for national health plans.

A trusted advisor to executives and boards, Ms. Pardieu is known for her strategic mindset, collaborative leadership, and ability to embed compliance into organizational culture to protect against regulatory and operational risk. She holds a Master of Public Health from Florida International University and a Bachelor of Science from Barry University. Ms. Pardieu is a Certified Healthcare Compliance Officer (OHCC), with additional credentials including certifications in Corporate Compliance & Ethics and Healthcare Risk Management; and is a recent graduate of the Women’s Executive Leadership Accelerator Program through the Inclusion Learning Lab.

References

1. U.S. Department of Health and Human Services, Office of Inspector General
    General Compliance Program Guidance (2023)
    * Direct PDF (Full Guidance):
      
https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf
    * Official OIG Overview Page:
      
https://oig.hhs.gov/compliance/general-compliance-program-guidance/
2. Agency for Healthcare Research and Quality (AHRQ)
    Patient Safety Culture and Workforce Safety
    * 
https://psnet.ahrq.gov/perspective/ensuring-patient-and-workforce-safety-culture-healthcare
3. National Committee for Quality Assurance (NCQA)
    Credentialing Standards
    * 
https://www.ncqa.org/programs/health-plans/credentialing/benefits-support/standards/
4. Council for Affordable Quality Healthcare (CAQH)
    2023 CAQH Index Report
    * 
https://www.caqh.org/hubfs/43908627/drupal/2024-01/2023_CAQH_Index_Report.pdf
5. National Library of Medicine (PubMed)
    Leadership and Patient Safety Culture Systematic Review
    * 
https://pubmed.ncbi.nlm.nih.gov/41507881/
6. Journal of the American Medical Informatics Association (JAMIA Open)
    Healthcare Dashboard Effectiveness Study
    * 
https://academic.oup.com/jamiaopen/article/8/4/ooaf078/8214040
7. National Institutes of Health (PubMed Central)
    Healthcare Leadership Complexity and System Growth
    * 
https://pmc.ncbi.nlm.nih.gov/articles/PMC11223336/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

42 CFR Part 2 HIPAA Alignment Update

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

By February 16, 2026, all HIPAA-covered entities—including healthcare providers, health plans, and healthcare clearinghouses—that create, receive, or maintain Substance Use Disorder (SUD) records subject to 42 CFR Part 2 must update their Notice of Privacy Practices (NPP). The update requires clearly detailing enhanced protections for SUD records. The information in this AIHC update is not legal or consulting advice, but for educational purposes to prompt compliance.

Does this new rule apply to my organization?

Yes, it can, but this requirement is specifically targeted at those handling Part 2 records. Entities must ensure their websites and privacy policies reflect these changes by February 16, 2026. Covered entities, including health plan sponsors and providers, must align their notices with the new, stricter privacy rules for sensitive SUD information by this date.

Tips to Update Your NPP

The NPP must contain the elements, information and statements specified in 45 CFR 164.520 and must include a specific header, a description of permitted uses/disclosures (treatment, payment, operations), individual rights, covered entity duties, and contact information for complaints.

It must be provided by the first service date and, as of February 16, 2026, align with updated substance use records regulations.

Key elements mandated by 45 CFR 164.520 include: 

  • Required Header: A specific statement regarding how medical information is used and the patient's rights.
    • i.e., “THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.”1
  • Permitted Uses and Disclosures: A detailed description of how the covered entity may use or disclose Protected Health Information (PHI) without the patient’s written authorization,2 including for treatment, payment, and healthcare operations.
  • Individual Rights: Information on the right to access, amend, request restrictions, receive confidential communications, and receive an accounting of disclosures.
    • A statement that other uses or disclosures will only be made with the individual’s authorization, and that the individual has the right to revoke her/his authorization subject to certain limitations.3
    • A summary of certain specified rights the individual has concerning his/her information.4
  • Covered Entity Duties: Statements confirming the entity's responsibility to protect privacy, provide notice of privacy practices, and abide by the terms of the notice.
  • Complaints Procedure: Instructions on how individuals can file complaints with the covered entity or the Secretary of Health and Human Services (HHS).
  • Contact Information: A designated person or office to contact for further information.
  • Effective Date: The NPP’s effective date.5
  • Special Considerations: Specific language regarding the restriction of uses/disclosures for underwriting purposes, the sale of PHI, and marketing, as well as updated, clearer descriptions regarding substance use disorder records.
  • Posting the Notice: The NPP must be prominently posted on the entity's website and physically at the service location by February 16, 2026 and, for plans without a website, distributed to participants by April 17, 2026 (within 60 days of the change).

Key Considerations:

Update Policies & Retrain Workforce - Organizations should act promptly to review their existing notices and implement the required changes before the deadline. Review and update internal privacy policies, procedures, and training materials to comply with the final rule.

Review your BAAs - Business Associate Agreements should be reviewed to ensure they account for the enhanced protections of SUD information.

For more information, check the updated Fact Sheet 42 CFR Part 2 Final Rule:

https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html.

References:

https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520

1 45 CFR 164.520(b)(1)(i)

2 45 CFR 164.520(b)(1)(ii)

3 45 CFR 164.520(b)(1)(ii)

4 45 CFR 164.520(b)(1)(iv)-(vii)

5 45 CFR 164.520(b)(1)(viii)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance, HIPAA

Privacy, Interoperability, and Trust in 2026

HIPAA Notice of Privacy Practices, 42 CFR Part 2, and USCDI v3 Compliance Risk 

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE 

Healthcare organizations entering 2026 face a convergence of heightened privacy enforcement and expanded interoperability obligations. Two major regulatory developments drive this shift:

  1. The February 16, 2026 deadline to update HIPAA Notices of Privacy Practices (NPPs) to reflect revised 42 CFR Part 2 requirements, and
  2. The January 1, 2026 mandate to comply with United States Core Data for Interoperability (USCDI) Version 3 standards. 

This article provides an executive and auditor-facing analysis of these intersecting requirements, examining enforcement risk, patient rights, data governance challenges, and operational compliance implications. Practical guidance is offered to support governing boards, executive leaders, and compliance professionals in aligning privacy, interoperability, and health IT strategies.

The information in this article is not intended as legal or consulting advice and should be used for educational purposes only.

Introduction

The healthcare compliance environment in 2026 reflects a deliberate regulatory emphasis on transparency, data access, and accountability balanced against strengthened privacy protections. Federal agencies have clearly signaled that interoperability and privacy are no longer siloed compliance domains but interdependent elements of patient trust and regulatory oversight.

As highlighted in the January 2026 Compliance Newsletter published by the American Institute of Healthcare Compliance, healthcare organizations must simultaneously address expanded HIPAA privacy obligations and mandatory interoperability standards. This convergence significantly elevates compliance risk for entities that fail to align governance, policy, and operational workflows.

HIPAA Notice of Privacy Practices: February 16, 2026 Enforcement Deadline

February 16, 2026 marks the enforcement deadline for updates to HIPAA Notices of Privacy Practices required under the February 2024 Final Rule modifying 42 CFR Part 2. These revisions align substance use disorder (SUD) privacy protections with HIPAA and subject violations to civil monetary penalties and corrective action plans.

Historically, Part 2 violations carried limited enforcement risk. Under the revised framework, failure to update NPPs or operationalize revised patient rights may be interpreted as systemic noncompliance.

Expanded Patient Rights Under Revised 42 CFR Part 2

The revised Part 2 framework introduces significant patient rights that must be clearly disclosed through updated NPPs. These include single-consent authorization for future disclosures, enhanced rights to request privacy protections, and explicit restrictions on the use of SUD records in legal proceedings. Compliance programs must ensure alignment across registration, consent management, EHR configuration, and workforce training to avoid inadvertent violations.

USCDI Version 3: Mandatory Interoperability in 2026

Already in effect, as of January 1, 2026, compliance with USCDI Version 3 became mandatory for certified EHR systems and health IT vendors.

This requirement expands the scope of standardized data exchange to include social determinants of health, health equity data, and expanded insurance information.  Failure to meet USCDI v3 standards may expose organizations to information blocking allegations, certification issues, and contractual noncompliance with payers and federal programs.

Intersection of Privacy and Interoperability

The intersection of privacy and interoperability represents one of the most complex compliance challenges facing healthcare organizations in 2026. Federal policy has deliberately accelerated health information exchange to improve care coordination, reduce administrative burden, and advance health equity. Simultaneously, regulators have strengthened patient privacy rights—particularly for sensitive data such as substance use disorder (SUD) information—recognizing that trust is foundational to patient engagement and data accuracy.

USCDI Version 3 expands the categories of data eligible for exchange, including social determinants of health, health equity stratifiers, and expanded clinical and insurance data elements. While these data sets are critical to population health and value-based care initiatives, they also increase the likelihood of inappropriate disclosure if consent and access controls are not precisely aligned. The revised 42 CFR Part 2 framework reinforces that interoperability does not negate privacy obligations; rather, it heightens the expectation that organizations implement granular, enforceable safeguards.

A Dual-Risk Environment - From an enforcement perspective, regulators have made clear that information blocking prohibitions do not override privacy protections. Organizations that indiscriminately share data without honoring consent restrictions—particularly for Part 2-protected information—may face simultaneous exposure under HIPAA, Part 2, and information blocking regulations. This creates a dual-risk environment in which both over-restriction and over-disclosure may trigger regulatory scrutiny.

To navigate this tension, healthcare organizations must adopt a privacy-by-design approach to interoperability, ensuring that consent management, data segmentation, and role-based access controls are embedded into health IT workflows. Interoperability initiatives that proceed without explicit privacy governance risk eroding patient trust and undermining regulatory compliance objectives.

Ensuring Trust Through Privacy-Centered Interoperability

Trust is not an abstract concept in healthcare compliance; it is an operational outcome shaped by transparency, consistency, and respect for patient autonomy. As data exchange expands, patients are increasingly aware of how their information is used, shared, and protected.

Failure to demonstrate meaningful privacy protections may result in patients withholding information, declining treatment, or disengaging from care altogether—particularly in behavioral health and substance use contexts.

Practical, trust-building strategies include:

Transparent and Understandable NPPs - Updated Notices of Privacy Practices should move beyond regulatory minimums to clearly explain how sensitive information is shared through interoperable systems, what choices patients have, and how consent is honored across care settings. Plain-language explanations reinforce trust and reduce confusion at registration and intake.

Consent Integrity Across Systems - Organizations should validate that consent decisions captured at intake are consistently enforced across EHRs, health information exchanges, and third-party platforms. Inconsistent application of consent restrictions is a frequent source of patient complaints and audit findings.

Data Minimization and Purpose Limitation - Even when data sharing is permitted, organizations should limit disclosures to the minimum necessary to achieve clinical or operational objectives. Demonstrating restraint reinforces patient confidence that interoperability serves care—not convenience.

Patient Access and Engagement - Providing patients timely access to their own records, including disclosures and consent history, supports transparency and aligns with broader federal access initiatives. Patients who understand how their data moves through the system are more likely to trust it.

Workforce Accountability - Trust is undermined when staff lack clarity regarding privacy obligations. Targeted training that addresses real-world scenarios—such as responding to data requests involving SUD information—helps prevent inadvertent violations and reinforces organizational commitment to privacy.

These practices position privacy not as a barrier to interoperability, but as a prerequisite for sustainable data exchange.

Governance, Audit, and Enforcement Risk

Regulators increasingly evaluate privacy and interoperability compliance through a governance lens. Surveyors and auditors may assess leadership awareness of regulatory changes, oversight of data-sharing activities, and the effectiveness of training and monitoring programs.

Failure to demonstrate executive oversight may result in enforcement actions by OCR or CMS.

Operationalizing Compliance: Best Practices

To mitigate compliance risk, organizations should:

  • Update NPPs well in advance of enforcement deadlines;
  • Align consent workflows with interoperability requirements;
  • Validate EHR configurations; and
  • Conduct targeted workforce training.

Routine audits of data-sharing practices and consent management processes are critical to sustaining compliance.

Conclusion

The convergence of revised HIPAA privacy requirements strengthened 42 CFR Part 2 protections, and mandatory USCDI Version 3 interoperability standards reflects a broader regulatory recalibration of healthcare data governance. Federal agencies have signaled that access, transparency, and accountability must advance in parallel—not in competition. In this environment, privacy failures are no longer isolated compliance issues; they represent systemic governance risks with direct implications for patient trust, enforcement exposure, and organizational credibility.

Healthcare organizations entering 2026 must recognize that interoperability initiatives amplify privacy obligations rather than dilute them. Updated Notices of Privacy Practices, consent management workflows, and health IT configurations serve as visible indicators of organizational integrity. Regulators and auditors increasingly assess not only whether policies exist, but whether leadership understands how privacy and interoperability intersect operationally.

Organizations that proactively integrate privacy-by-design principles into interoperability strategies will be best positioned to navigate enforcement risk, avoid information blocking missteps, and sustain patient trust. This requires active governing body oversight, cross-functional collaboration between compliance, IT, legal, and clinical leaders, and continuous monitoring of evolving regulatory guidance.

Ultimately, trust is the currency of interoperable healthcare. Organizations that demonstrate respect for patient autonomy while advancing responsible data exchange will not only meet regulatory expectations but also strengthen care quality, engagement, and resilience in an increasingly data-driven healthcare system.

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • American Institute of Healthcare Compliance. (2026). January 2026 compliance newsletter. https://dev-main.aihc-assn.org
  • U.S. Department of Health and Human Services, Office for Civil Rights. (2024). Final rule modifying 42 CFR Part 2. https://www.hhs.gov/ocr
  • Centers for Medicare & Medicaid Services. (2025). United States Core Data for Interoperability (USCDI) Version 3. https://www.cms.gov

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
HIPAA Compliance
HIPAA

Part 3: The Pros and Cons of Interoperability Frameworks in Health Care

Written by: Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC and Dr. Tami M. Harris, DM, PMP, LSSBB 

Introduction 

Interoperability frameworks are the connective tissue of modern healthcare data exchange, defining how systems communicate, the structure of the data, and how information flows securely across organizations.

As healthcare organizations – including hospitals, payers, clinicians, and technology vendors – face significant challenges to deliver care in an environment dominated by fragmented data, siloed and competing systems, the push to standardize how information is exchanged has taken center stage. These frameworks offer a pathway toward a more connected healthcare ecosystem—one where patient medical records are transmitted securely, providers have timely access to essential information, and organizations can reduce the inefficiencies that drive patient care, increased costs, lost or duplication of data, and delays.

In the AIHC Part 1 Article on Interoperability: CMS Interoperability Framework Project: Should We Be Concerned?  A comprehensive overview dives into  the Problem with System Fragmentation in Healthcare and Security Concerns in the CMS Interoperability Framework Project (Part 1).

In the AIHC Part 2 Article: Interoperability and System Fragmentation in Healthcare, the contributing writers discuss Communication, Compliance, and Strategies for Successful Integration Interoperability and System Fragmentation in Healthcare (Part 2).

In this AIHC Part 3 Article, we will now walk the readers through the Pros and Cons of Interoperability Frameworks in Healthcare. As AI, Revenue Cycle Management (RCM) automation, payer auditing, and value-based care accelerate, these frameworks are rapidly becoming the backbone of national healthcare operations.

But like any key technology standard, these frameworks come with real advantages—and real trade-offs. Below is a practical, balanced breakdown that leaders should understand before deciding to adopt or move forward with how they will integrate these systems.

Pros & Cons - Let’s Start with the Pros

1. Exchange of Data Between Systems

Data Exchange interoperability frameworks, such as Health Level 7 (HL7), Fast Healthcare Interoperability Resources (FHIR), and Trusted Exchange Framework and Common Agreement (TEFCA), will help reduce fragmentation by providing a common language for AI-Powered Electronic Medical Record (EMR) systems, RCM platforms, and payer applications.

According to the Centers for Medicare & Medicaid Services (CMS), the Voluntary Interoperability Frameworks are designed to enhance manual back-and-forth, enable faster claims processing, reduce denials, and improve clinical decision-making.

Why it matters - Unconnected systems, duplicate documentation, and lost data cost hospitals millions of dollars every year. Current CMS estimates indicate that interoperability frameworks can shrink those losses by streamlining data exchange and minimizing manual errors. Integrating data into EHRs demonstrates the growing impact of interoperability frameworks on reducing fragmentation.

2. Stronger Clinical Quality and Patient Safety

With data flowing unimpeded, clinicians have a complete picture of labs, meds, allergies, imaging, and histories—regardless of where care was delivered. This improves the accuracy of care, reduces avoidable errors, and supports real-time decision-support tools.

A Forward-Thinking Angle - AI-enabled audits in Clinical Documentation Improvement (CDI) and RCM are most effective when built on interoperable data. Interoperability should be the prerequisite for advanced analytics and real-time clinical decision support.

3. Reduce Operational Waste and Administrative Burden

Implementing CMS Voluntary Frameworks, such as CMS 9115-f , automates and streamlines much of the documentation exchange, eliminating repetitive reconciliation, data entry, and faxing.

The CMS Interoperability and Patient Access Final Rule require payers to use FHIR-based APIs for data exchange, which has proven to reduce prior authorization response times and administrative costs for providers.

Impact - Minimize human touchpoints → fewer mistakes → shorter AR cycles → more cash collected faster.

4. Better Compliance with Federal Requirements

The goal is to minimize risk by leveraging the Assistant Secretary for Technology Policy and the Office of the National Coordinator for HealthIT’s (ASTP/ONC) Interoperability Frameworks, such as HL7, FHIR, CMS interoperability rules, and TEFCA, by aligning organizations with regulatory expectations for data access, patient API rights, and cross-network exchange.

TEFCA, launched in 2024, establishes a nationwide framework for secure health information exchange, connecting providers, payers, and public health agencies. Compliance with TEFCA and FHIR standards is now required for participation in federal programs and for avoiding penalties.

Bottom line - Staying compliant now avoids future penalties and positions organizations to participate in larger national data networks.

5. Fuel for AI, Predictive Analytics, and RCM Algorithms

AI models thrive on clean, structured, standardized data (Federal Register, Health Data).
Interoperability frameworks give organizations the quality inputs needed for:

  • Automated Claims Integrity Checks
  • Audit Ready Data Pipelines
  • Predictive RCM Drift Alerts
  • CDI optimization
  • Denials Prediction

The FDA and CMS are piloting FHIR-based submissions for real-world data, enabling advanced analytics and predictive modeling for population health and revenue cycle management.

Forward-Looking Reality - Organizations that implement interoperable data models today are better positioned to lead tomorrow’s AI-enhanced revenue cycle and clinical innovation.

The Cons

1. High Upfront Cost and Long Implementation Time

Implementing interoperability is not a simple upgrade. Many organizations underestimate the scale and cost, leading to project delays and budget overruns. Interoperability initiatives require:

  • API Integration
  • Data Mapping
  • Security Upgrades
  • Staff Training
  • Vendor coordination
  • Workflow Redesign

Truth - Interoperability is not a plug-and-play upgrade—it will be transformational.

2. Legacy System Limitations

Legacy systems often; lack support for modern APIs, contemporary data formats, or real-time exchange. These outdated platforms create bottlenecks, limit adoption, and increased maintenance costs.

Real-World Impact - Even if one part of the RCM process is modernized, the weakest legacy interface can undermine the entire process.

3. Cybersecurity Risks Rise with Connectivity

Expanding connectivity through APIs and cross-organizational networks increases the risk of cyber threats. The U.S. Department of Health & Human Services (HHS) emphasizes that interoperability must be paired with robust cybersecurity measures to protect sensitive health information.

Forward risk - AI-powered cyberattacks target health care's interconnected data ecosystems. Interoperability without hardened defenses is dangerous.

Organizations will need to ensure stronger access controls, encryption, and incident response plans are in place for threat prevention.

4. Vendor Resistance and Proprietary Barriers

Some vendors still rely on closed or proprietary systems to “lock in” clients, making interoperability expensive or technically challenging. This practice can significantly hinder the seamless exchange of health information across organizations.

The ONC has repeatedly identified proprietary interfaces and lack of standardized APIs as major obstacles to nationwide interoperability. Proprietary health IT systems continue to present significant challenges to data sharing. These systems often require organizations to invest in costly custom integrations, which can result in persistent information silos.

Result - Organizations can get stuck negotiating costly interface fees or dealing with partial data exchange, which not only increases operational expenses but also limits the ability to provide coordinated, high-quality care.

5. Variation in Standards and Inconsistent Adoption

Even with frameworks like FHIR (HL7 FHIR) or TEFCA (TEFCA Governance), vendor implement differently.  There are variations in:

  • API Maturity
  • Profiles
  • Optional Fields Versioning
  • Create Ongoing Friction

Reality - Interoperability is only as strong as the weakest implementation in the network. The ONC Interoperability Standards Advisory underscores the need for consistent implementation and highlights gaps in adoption across the industry.

Summary: A High-Level Strategic View

Interoperability frameworks are rapidly becoming the backbone of a modern, connected healthcare ecosystem, offering benefits that extend well beyond simple data exchange —yet their impact is far from one-dimensional. Throughout this three-part AIHC series, we have explored the real and persistent challenges of system fragmentation, the security vulnerabilities exposed by national initiatives such as the CMS Interoperability Framework Project, and the practical strategies organizations can use to navigate and overcome communication and compliance barriers.

In this Part 3 article, we explored the significant advantages and real trade-offs that interoperability frameworks bring. These standards promise faster access to patient information, improved care coordination, and greater operational efficiency.  At the same time, it is important to realize that these benefits of interoperability in healthcare require rigorous governance, robust security, disciplined integration planning, and adaptability to evolving federal and state requirements, including market pressures Understand Interoperability in Healthcare.

As AI in RCM automation, payer oversight, and value-based care continue to accelerate, interoperability will become increasingly critical. Operational leadership that succeeds will be those who embrace connectivity with strategic foresight—leveraging the advantages while proactively managing the associated risks. 

Interoperability should be viewed not just as a technology requirement; it should be considered the de facto strategy and standard that will shape how healthcare delivers value, safeguards patients, and competes in a data-driven future.

About the Authors

Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC, is the Founder, Principal & Managing AI Consultant of P3 Quality, a Healthcare Tech Consulting Company. She is a Certified Artificial Intelligence Professional (CAIP) and a Certified Artificial Intelligence Medical Coder (CAIMC). In her current leadership role, she extracts and diagnoses core Drift in AI Medical Coding Models, thereby closing AI-Driven financial, quality, and compliance gaps. Corliss is also a published author of Artificial Intelligence, Rise, Survive, & Thrive In An AI-Powered World. She also serves on the AIHC Volunteer Education Committee.

Dr. Tami M. Harris, DM, PMP, LSSBB, is the Founder & Chief Operating Officer of H & H Consulting Group, Inc. With a doctorate in Management, she is recognized as a certified Lean Six Sigma Black Belt and Project Management Professional, reflecting a commitment to operational excellence and continuous improvement. In her current capacity as Portfolio Director for Middle and Back-office Revenue Cycle Management (RCM) AI Automation and Transformation, she leads strategic advisory initiatives, oversees practice leadership, and drives client engagement delivery to generate new value-streams through technology.

References:

  1. American Health Information Management Association. (2024). TEFCA Overview. AHIMA. https://www.ahima.org/
  2. Centers for Medicare & Medicaid Services (CMS). Interoperability and Patient Access Final Rule (CMS-9115-F). https://www.cms.gov/cms-9115-f
  3. Food and Drug Administration. (2025). Exploration of Health Level Seven Fast Healthcare Interoperability Resources for Use in Study Data Created From Real-World Data Sources for Submission to the Food and Drug Administration; Establishment of a Public Docket; Request for Comments. Federal Register, 90(77), 17067–17069. https://www.federalregister.gov/documents/2025/04/23/2025-06967/exploration-of-health-level-seven-fast-healthcare-interoperability-resources-for-use-in-study-data
  4. HL7 International. FHIR Overview. https://www.hl7.org/fhir/
  5. National Academy of Medicine. Proposing Interoperability Standards for Healthcare. https://www.federalregister.gov/algoritm-transparency
  6. Office of the National Coordinator for Health Information Technology (ONC). Interoperability Standards Advisory (ISA). https://www.healthit.gov/isa
  7. The Sequoia Project. TEFCA Framework and Common Agreement. https://sequoiaproject.org/tefca/
  8. Understand the four levels of Interoperability in Healthcare. www.wolterskluwer.com
  9. U.S. Department of Health & Human Services. (2024). Cybersecurity Program. https://www.hhs.gov/about/agencies/asa/ocio/cybersecurity/index.html

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Is it an Audit, Gap Analysis or Risk Assessment?

For Auditors and Compliance Officers 

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

New to Compliance & Auditing for Compliance?  This short article is #3 in a three-part series addressing various areas of auditing and monitoring healthcare providers for compliance.  You may want to read Article #1 – Importance of Compliance Audits and Article #2 Auditing for Anti-Kickback Statute Violations.

Introduction

A healthcare compliance audit checks adherence to laws (such as HIPAA, Stark, Anit-Kickback Statue, coding, billing rules) and includes reviewing written policies, assessing internal controls, verifying staff training, monitoring data security, examining processes, interviewing staff, and ensuring a robust reporting/corrective action process is in place.  This is all aimed at risk reduction and better patient care.

The focus of this article is to discuss the difference between a Gap Analysis and Risk Assessment when conducting an audit.

Conducting an Audit can be Complex

To audit, gap analyze, and risk assess healthcare compliance, an organization systematically identifies standards, gathers data, evaluates compliance gaps and threats, prioritizes issues, then create corrective plans.  This is followed by conducting monitoring audits and review to find and fix deficiencies before they become major problems. It is a continuous process.

Core Components of a Healthcare Compliance Audit often include:

Risk Assessment & Scope

  • Identifying high-risk areas (e.g., billing, privacy, patient safety) and defining what the audit will cover.

Performing a Documentation Review

  • Checking written policies, procedures, training records, consent forms, and compliance plans for completeness and accuracy.

Testing Internal Controls

  • Evaluating safeguards for data (EHR, access), billing, and operations to prevent fraud and errors.

Workforce Competency

  • Verifying that employees understand and follow policies through training logs and interviews.

Conducting Interviews & Observation

  • Talking to staff and watching workflows to see if policies are truly followed in practice.

HIPAA Compliance

  • Data Security & Privacy auditing to determine HIPAA/HITECH compliance, access controls, and breach protocols.

Billing & Coding Accuracy

  • Performing pre-billing and post-billing audits to ensure claims are correctly coded and comply with payer rules.

Reporting & Investigation

  • Assessing the effectiveness of hotlines, whistleblower protections, and how reported issues are handled.

Corrective Action Plan (CAP)

  • Developing and tracking steps to fix any identified compliance gaps.

Gap Analysis

The distance between where you are where you need to be

Conducting an audit often requires performing a gap analysis.  A gap analysis identifies the difference between your current state and desired compliance levels.   Simply put, it starts by defining the compliance goal, assesses current performance (what your organization is actually doing) and pinpointing exactly where the organization is falling short.

In healthcare compliance, a Gap Analysis finds what you're missing compared to a standard (e.g., Coding or HIPAA rules), showing the "what's missing" and "how far" from compliance, while a Risk Assessment identifies why you're vulnerable, evaluating the likelihood and impact of threats (like breaches) to determine what controls are truly needed to mitigate risk, forming two complementary steps to achieve full, effective compliance, not replacements for each other.

Key Steps for Risk Mitigation Gap Analysis:

1. First, start with defining the scope and objective.

  • Clearly state what you're analyzing (processes, compliance, performance) and the desired outcome or standard (e.g., regulatory compliance, industry best practice).

2. Next, define benchmarks, goals that need to be met.

  • Define the desired state. Establish benchmarks, goals, and ideal performance levels, often based on regulations, standards, or strategic objectives.
  • Create list of items being measured and evaluated.

3. Conduct an Evaluation to Assess Current State.

  • Document existing performance, processes, policies, and controls, gathering data through audits, interviews, and metrics.

4. Identify & Analyze Gaps.

  • Compare current vs. desired states to find discrepancies.
  • Use tools like SWOT or process mapping to visualize inefficiencies, as taught by AIHC in the Auditing for Compliance online course which addresses gap analysis.

5. Conduct Root Cause Analysis (RCA).

  • Dig deep to understand why gaps exist (e.g., outdated policies, lack of training, resource issues).

6. Prioritize or Rank by Severity.

  • Rank gaps by severity, impact, and risk level (e.g., using an impact/effort matrix) to focus on the most critical issues first.

7. Develop Action Plan (Remediation).

  • Create detailed plans with specific actions, assigned owners, resources, timelines, and success metrics to close each prioritized gap.

8. Implement & Execute.

  • The organization must act and ensure necessary resources and support are in place.

9. Monitor & Review.

  • Continuously track progress, measure results against KPIs, and make adjustments to ensure effective risk reduction.

10. Communicate & Report.

  • Share findings and progress with stakeholders to maintain transparency and buy-in.

Risk Assessment – The “Why” and “How Bad”

After identifying what's missing (the gaps), the risk assessment quantifies how bad those gaps are. The risk assessment evaluates potential threats to compliance and patient safety.  This process explains why gaps matter and dictates what to fix to manage risk effectively.  It includes an impact analysis, evaluating controls and calculate residual risk.

Difference between Gap Analysis & Risk Assessment:

Gap Analysis = Current vs. Standard

Risk Assessment = Threats/Vulnerabilities vs. Assets

Key steps for a risk assessment following a gap analysis:

1. Identify Risks from Gaps.
  • Take the identified gaps (e.g., lack of security training, outdated software) and pinpoint the specific threats or vulnerabilities they create (e.g., phishing, data breach, system failure).

2. Analyze Risk (Likelihood & Impact). For each identified risk, determine.

  • Likelihood: How probable is it that this risk will occur?
  • Impact/Severity: How bad would the consequences be (financial, operational, reputational) if it did happen?

3. Evaluate & Prioritize Risks.

  • Combine likelihood and impact to score each risk (e.g., High, Medium, Low) and prioritize them. Focus on high-impact, high-likelihood risks first.

4. Develop Mitigation (Control) Strategies.

  • For prioritized risks, design actions to eliminate, reduce, or transfer the risk. These are your control measures (e.g., implementing training, upgrading systems).

5. Record Findings & Controls.

  • Document the entire process, including identified risks, analysis, chosen controls, and responsibilities. This is often a legal requirement.

6. Implement Controls.

  • Put the planned actions into practice.  

7. Monitor & Review.

  • Don’t stop short, complete the cycle by regularly checking if controls are working and update the assessment as the environment, threats, or business needs change.

Auditing for Compliance

Even if you have some audit experience, taking an online course and certifying can fill-in knowledge gaps and provide essential skills to lead an audit team.

To become a lead auditor, many organizations will require you to complete a training course that covers auditing principles, management systems, and leadership skills, followed by passing an exam and gaining auditing experience, such as offered by the American Institute of Healthcare Compliance (AIHC), recognized as a Licensing/Certifying partner with the Centers for Medicare & Medicaid Services (CMS).

Resources to Stay Informed

Lead Auditors and Compliance Officers need to stay informed.  Subscribing to government notifications is one way.  You may also want to review current educational articles (free) published by the American Institute of Healthcare Compliance (AIHC)– click here for the Auditing category, and view all articles or by additional categories. 

Videos can be a helpful way to stay informed.  We recommend the following which may be of interest for you or members of your audit and compliance team!

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

  • Auditing for Compliance online training course by the American Institute of Healthcare Compliance.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

When Compliance Meets Forensics

Why Every Healthcare Organization Needs an Internal Investigator 

Written By: Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

Abstract 

In today’s complex healthcare environment, compliance alone is insufficient to detect and prevent misconduct, fraud, and abuse. Rising regulatory scrutiny, financial pressures, and technological complexity demand a proactive approach that blends compliance oversight with forensic auditing. This article introduces the concept of forensic auditing in healthcare, explains how internal investigators identify and mitigate internal risks before they escalate, and provides a real-world scenario that demonstrates the practical application of forensic principles. As the first in a three-part series aligned with the Certified Internal Forensic Healthcare Auditor (CIFHA) curriculum offered by the American Institute of healthcare Compliance (AIHC), this article establishes why healthcare organizations need internal forensic investigators to ensure accountability, compliance, and integrity across systems and staff.

Introduction

Healthcare organizations operate within one of the most highly regulated industries in the United States. Federal oversight through the Centers for Medicare and Medicaid Services (CMS), the Department of Justice (DOJ), and the Office of Inspector General (OIG) combined with state and accreditation requirements create a multifaceted compliance landscape. As regulatory expectations evolve, organizations must go beyond compliance checklists and adopt investigative capabilities that actively detect and mitigate risk. According to the Office of Inspector General’s 2023 guidance, healthcare compliance programs should include mechanisms for internal investigation and response to suspected violations to ensure early detection and self-disclosure opportunities.

Traditional compliance programs rely on audits and monitoring to identify irregularities and though these methods are proven; these processes are often periodic and limited in scope. Forensic auditing, on the other hand, integrates data analytics, investigative interviewing, and financial tracing to uncover intentional misconduct, hidden patterns, or emerging risks. When integrated within a compliance program, internal forensic investigators bridge the gap between prevention and enforcement.

Defining Forensic Auditing in Healthcare

Forensic auditing combines accounting, auditing, and investigative techniques to identify financial or operational irregularities that could indicate fraud, waste, or abuse. It differs from routine auditing because it assumes concealment, deception, and intent. Forensic auditing emphasizes verification, evidence preservation, and analytical reconstruction of transactions to determine whether misrepresentation occurred. According to the Association of Certified Fraud Examiners’ 2024 Report to the Nations, healthcare fraud remains one of the costliest forms of occupational abuse, with average losses exceeding $100,000 per incident in the provider sector.

Healthcare organizations are especially vulnerable because of the complexity of coding and billing systems, fragmented data environments, and third-party relationships. Forensic auditing in healthcare may involve reviewing claims data, vendor payments, procurement contracts, or physician compensation models. According to CMS program integrity data (2023), more than $60 billion in estimated improper payments were made across federal healthcare programs last year—highlighting the ongoing need for internal vigilance.

Roles, Skills, and Governance of an Internal Forensic Investigator

An internal forensic investigator provides a specialized function within the compliance ecosystem. This professional must possess a blend of analytical, legal, and ethical expertise. Recommended competencies include knowledge of healthcare reimbursement models, coding accuracy, and claims analysis; strong investigative skills such as interviewing, documentation review, and evidence preservation; and familiarity with relevant statutes including the False Claims Act, Anti-Kickback Statute, and HIPAA Privacy Rule.

The investigator’s independence is critical. According to the DOJ’s 2020 Evaluation of Corporate Compliance Programs, the credibility of internal investigations depends on independence, competence, and appropriate resources. Investigators should report directly to the Compliance Officer, Board Audit Committee, or General Counsel to avoid conflicts of interest. Collaboration with IT, Human Resources, and Finance is often necessary for effective data gathering and root-cause analysis.

Training and certification enhance credibility. Many investigators pursue credentials such as Certified Fraud Examiner (CFE), Certified in Financial Forensics (CFF), or Certified Professional Compliance Officer (CPCO). The CIFHA curriculum integrates these skill sets by combining investigative methods with forensic analytics and compliance oversight principles, preparing professionals to handle internal inquiries ethically and effectively.

A Realistic Scenario: The Case of EchoHealth Radiology Network

EchoHealth Radiology Network, a midsize radiology provider, noticed a rise in payer denials and outlier utilization trends within its Magnetic Resonance Imaging (MRI) service line. Routine audits did not reveal significant errors, but a compliance analyst flagged a spike in modifier use for certain spinal studies. The internal investigator initiated a forensic review and uncovered that one radiology group had systematically upcoded imaging services at the direction of a billing manager. Interviews revealed that coders were encouraged to “maximize revenue” by adding modifiers without sufficient documentation.

  • The investigator traced the pattern across six facilities, identified more than $1.2 million in questionable claims, and confirmed documentation gaps.
  • Because the issue was identified internally, EchoHealth voluntarily disclosed the overpayments, retrained coding staff, and implemented a pre-billing review process. The early forensic response protected the organization from potential False Claims Act liability, demonstrated good-faith remediation, and reinforced a culture of compliance and accountability.

Key Benefits and Return on Investment

According to the Government Accountability Office (GAO, 2023), proactive detection and response programs can reduce fraud-related losses by as much as 40 percent. The presence of an internal investigator also promotes a culture of transparency and reinforces the ethical tone of leadership. Internal forensic capacity delivers benefits such as early risk identification, reduced penalties through self-disclosure, improved internal controls, and measurable cost avoidance. Organizations that invest in forensic auditing capability often discover that the savings from avoided regulatory penalties and recovered funds exceed the cost of the program itself.

  • From a compliance culture standpoint, the visibility of an internal investigator acts as a deterrent. 

Employees are more likely to report concerns through proper channels when they see issues being addressed promptly and professionally. This aligns with the OIG’s emphasis on maintaining effective lines of communication and timely corrective action in healthcare compliance programs (OIG, 2023).

Challenges, Limitations, and Mitigations

Despite its value, integrating forensic auditing within compliance presents challenges. Resource limitations are common, particularly for smaller providers. Legal considerations such as maintaining privilege and confidentiality require coordination with counsel. Data analytics and automation can introduce false positives that distract investigators from genuine issues. To mitigate these challenges, organizations can start with pilot programs, outsource complex investigations as needed, and establish clear investigation protocols aligned with OIG and DOJ standards.

Another challenge involves maintaining staff trust. Employees may perceive investigations as punitive rather than corrective. Compliance leaders can address this by communicating the purpose of forensic reviews as a means of protecting both the organization and its workforce. Transparency, education, and post‑investigation feedback sessions can reduce anxiety and improve cooperation.

Alignment with CIFHA Goals

Certified Internal Forensic Auditor

This article—the first in a three-part series—introduces an essential component of the CIFHA curriculum: the intersection between compliance and forensics, embodied in the role of the internal investigator. The next two articles in this series will continue to build upon this foundation:

  • Article 2: “10 Common Mistakes in Internal Investigations—And How to Avoid Them” will draw directly from the CIFHA course section on Accepting the Investigation. It will offer practical insights into how investigators can recognize and avoid common sources of bias, procedural missteps, and compliance pitfalls that compromise investigative integrity.
  • Article 3: “From Findings to Action: Writing an Objective, Defensible Investigative Report” will focus on the analytical and reporting phase—how to synthesize data, present factual findings, and communicate results effectively and ethically. It will demonstrate how the course equips participants to transform raw information into defensible, actionable reports that withstand regulatory and legal scrutiny.

Together, these articles trace the natural progression of the investigative process—from recognizing the need for internal forensics, to conducting unbiased inquiries, to articulating findings that drive organizational accountability and improvement.

Conclusion

Healthcare organizations that embed forensic auditing within compliance are better positioned to detect misconduct, preserve integrity, and demonstrate proactive risk management. According to the DOJ and OIG, organizations that identify and correct issues internally are viewed more favorably in enforcement actions. Internal investigators serve as both a safeguard and a strategic asset—protecting financial integrity while promoting an ethical culture. As healthcare continues to evolve, forensic auditing will remain a cornerstone of mature compliance programs that prioritize transparency, accountability, and continuous improvement.

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Office of Inspector General (OIG). (2023). Compliance Program Guidance for Hospitals.
  • U.S. Department of Justice (DOJ). (2020). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Centers for Medicare & Medicaid Services (CMS). (2023). Improper Payments Data.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Health Care Compliance Association (HCCA). (2024). Best Practices in Internal Investigations.
  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • U.S. Department of Health and Human Services (HHS). (2024). Health Care Fraud and Abuse Control Program Annual Report.
  • Compliance Week. (2023). The Rising Role of Forensic Auditing in Healthcare.
  • Deloitte. (2024). Internal Investigation Trends in the Health Sector.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Understanding Whistleblower Protections in Healthcare

Legal Obligations and Compliance Implications  


Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

The government’s new whistleblower complaint portal launched in April 2025 emphasizes the importance of complying with regulations related to qui tam suits, OCR investigations and protecting the rights of employees submitting a tip or complaint internally or to authorities. This article illustrates how certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation.

Introduction

Healthcare compliance professionals are often the first line of defense when systems break down. Understanding the interplay between legal protections and organizational ethics is vital—not only to ensure legal compliance, but also to foster environments where staff feel empowered and safe to report misconduct.

Whistleblowers are critical to protecting the integrity of healthcare delivery. When individuals report unsafe care, fraudulent billing, privacy violations, or ethical concerns, they help ensure accountability, uphold regulatory compliance, and safeguard patient welfare. For compliance professionals—particularly those working in environments regulated by Medicare, Medicaid, HIPAA, and federal contracts—it is essential to understand the scope and implications of whistleblower protections under current U.S. law.

This article explores the legal framework that underpins whistleblower protections, including the False Claims Act (FCA), HIPAA Privacy Rule exceptions, and National Defense Authorization Act (NDAA) provisions. It also highlights recent federal developments and compliance best practices to foster a culture of transparency and non-retaliation.

The False Claims Act and Qui Tam Provisions

For compliance departments, the implications of Qui Tam lawsuits extend far beyond financial penalties. They can lead to reputational harm, loss of patient trust, and stricter regulatory scrutiny. Therefore, proactive compliance programs must include regular audits, anonymous reporting options, and a culture that encourages early identification of potential violations.

The False Claims Act (31 U.S.C. §§ 3729–3733) is the federal government’s primary tool for combating fraud against public programs. Healthcare fraud accounts for a significant portion of FCA activity. Under its Qui Tam provision, private citizens—known as “relators”—can file lawsuits on behalf of the government when they have direct knowledge of fraudulent activities, such as billing for services not rendered or providing substandard care reimbursed by federal programs.

When the Department of Justice (DOJ) intervenes in these cases, whistleblowers may receive 15%–30% of recovered funds as a reward. In 2023 alone, the DOJ recovered over $1.8 billion from healthcare-related FCA cases, with whistleblower suits representing the vast majority of those recoveries.

Importantly, the FCA also prohibits retaliation. Section 3730(h) protects whistleblowers from termination, demotion, suspension, or harassment due to lawful acts in furtherance of a Qui Tam action or efforts to stop violations of the FCA.

HIPAA and Whistleblower Disclosures

Healthcare entities must train their workforce on the specific conditions under which PHI disclosures are permissible. Internal policies should not only comply with HIPAA but clarify what constitutes a 'good faith belief' and ensure disclosures are directed to appropriate oversight entities.

While the Health Insurance Portability and Accountability Act (HIPAA) is typically associated with patient privacy, it also contains important exceptions that protect whistleblowers. Under 45 CFR § 164.502(j), a workforce member may disclose protected health information (PHI) if:

  1. They believe in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates clinical standards; and
  2. The disclosure is made to a healthcare oversight agency, public health authority, law enforcement agency, attorney, or accreditation organization.

This clause is critical for compliance officers to understand, especially when investigating disclosures involving PHI. Any internal policy must clearly explain the scope of permissible disclosures and educate staff on when HIPAA permits these exceptions.

NDAA Protections and the Role of Contractors

The National Defense Authorization Act (NDAA) of 2013 (41 U.S.C. § 4712) expanded whistleblower protections to employees of federal contractors, grantees, and subcontractors, which includes many healthcare providers receiving federal funds. Under this statute, employees are protected from reprisal for reporting gross mismanagement, fraud, abuse of authority, or dangers to public health and safety.

Notably, these protections apply even if the employee discloses information outside of the organization, including to Congress, an Inspector General, or a federal employee responsible for contract oversight.

Compliance officers working with contractors should incorporate NDAA requirements into onboarding and ethics training materials. Additionally, contract language should affirm non-retaliation protections and clarify processes for raising concerns externally.

Recent Developments: HHS Whistleblower Portal and Enforcement

On April 14, 2025, the U.S. Department of Health and Human Services (HHS) launched a new whistleblower complaint portal specifically designed to receive reports of potential harm to children, including medically controversial treatments involving minors.

This new government portal signals increased federal oversight in how healthcare institutions respond to ethical and religious concerns raised by employees and demonstrates the government’s increased commitment to ensuring that providers and institutions uphold safety, informed consent, and respect for medical ethics.

This tool may also be used to identify systemic gaps in institutional policies around consent, safety, and staff protections.

In a notable case publicized by HHS, a hospital faced sanctions for terminating a nurse who refused to participate in a pediatric procedure due to her religious beliefs. HHS concluded that the hospital violated federal conscience protections, highlighting the intersection of whistleblower law, employment rights, and provider conscience protections.

Such scenarios highlight the importance of thorough documentation and timely response by compliance departments. Independent reviews of whistleblower complaints, performed by third-party investigators or ombudspersons, can enhance transparency and fairness in case handling.

Consider a hypothetical but realistic scenario

  • A behavioral health technician reports unsafe restraint practices involving minors in a residential facility.
  • Shortly after filing the internal report, the technician is placed on administrative leave and subsequently terminated.
  • The technician files a complaint under both the FCA and state labor law.
  • The investigation reveals that internal reports were not documented properly, retaliation safeguards were not in place, and training on non-retaliation was outdated.

This case underscores the need for compliance programs to ensure proactive risk mitigation, thorough documentation, and a robust culture of safety and transparency.

The Compliance Officer’s Role: Promoting a Speak-Up Culture

Organizations should periodically evaluate the effectiveness of their whistleblower protection efforts through anonymous staff surveys, incident response audits, and tracking the outcomes of reported concerns. This proactive approach signals to staff that leadership values integrity and transparency.

Certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation. Organizations must go beyond policy documents and invest in cultural and procedural safeguards:

- Establish and communicate clear non-retaliation policies.
- Train all employees and leadership on reporting rights and retaliation indicators.
- Maintain multiple confidential channels for reporting concerns.
- Ensure prompt and fair investigation of all complaints.
- Audit for compliance with whistleblower protection policies.

Conclusion

Ultimately, the goal of any whistleblower protection program is not merely compliance, but the cultivation of an ethical culture that consistently does what is right—even when it is inconvenient or uncomfortable. This requires leadership buy-in, staff empowerment, and a long-term commitment to transparency.

Whistleblower protections are more than legal requirements—they are pillars of ethical healthcare. Laws like the FCA, HIPAA, and NDAA empower individuals to report wrongdoing without fear. Compliance professionals must champion these safeguards, not only to avoid legal liability but to protect patient welfare, support employee integrity, and sustain organizational trust.

As regulatory enforcement intensifies and new federal protections emerge, healthcare organizations must remain vigilant, proactive, and transparent. The call to protect whistleblowers is not just a mandate—it is a moral and professional imperative.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance.  Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • U.S. Department of Health and Human Services (HHS). (2025). New Whistleblower Guidance and Complaint Portal. Retrieved from https://www.hhs.gov/protect-kids
  • 31 U.S.C. §§ 3729–3733, False Claims Act (FCA).
  • 31 U.S.C. § 3730(h), Anti-Retaliation Protections under the FCA.
  • 45 CFR § 164.502(j), Whistleblower Disclosures under the HIPAA Privacy Rule.
  • National Defense Authorization Act (NDAA) of 2013, 41 U.S.C. § 4712.
  • Office for Civil Rights (OCR), HHS. (2025). Press release on hospital investigation, April 14, 2025.
  • American Institute of Healthcare Compliance (AIHC). (2025). Newsblast: New Whistleblower Complaint Portal.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More