Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Common Compliance Risks in OB/GYN Medical Billing and How to Address Them

Written by Noah Smith for BillingFreedom

The article will help healthcare professionals identify common compliance risks that can arise in OB-GYN medical billing and understand practical approaches for addressing those risks through accurate documentation, coding, claim review, internal audits, and consistent billing workflows.

OB/GYN billing can get complicated quickly. During the same week, a practice may bill for preventive visits, ultrasounds, office procedures, prenatal care, surgery, delivery services, postpartum visits, and treatment for unrelated gynecologic conditions. Those services do not always follow the same documentation, coding, or payer rules. That leaves plenty of room for small mistakes to slip into the billing process.

Sometimes the problem is obvious. A claim is rejected because the subscriber number is wrong or a required field is missing. Other problems are harder to notice. A payer may process a claim even though the documentation is weak, a modifier has been used inconsistently, or staff are following an outdated billing process.

One paid claim does not necessarily tell a practice that everything behind the claim was handled correctly. A better way to think about compliance is to look at the entire path a claim takes:

  • Patient information has to be accurate.
  • Coverage needs to be checked.
  • The provider's note has to support the service.
  • Coding needs to match the record, and payer requirements have to be addressed before the claim goes out.

When one part of that chain breaks down repeatedly, the problem can spread across dozens of claims before anyone recognizes the pattern.

Where OB/GYN Billing Problems Usually Start

Many compliance issues begin before a coder ever looks at the chart. Consider a returning patient whose insurance changed since her last appointment. If the old plan is still listed in the system, the claim may be sent to the wrong payer. By the time the rejection comes back, staff may need to update the account, verify benefits again, rebill the service, and make sure a filing deadline has not been missed.

Authorization problems can develop in much the same way. A service may have been appropriate and clearly documented, yet the claim can still run into trouble if the payer required prior authorization and nobody confirmed it.

Then there is the medical record itself. A provider may remember exactly what was discussed or performed during a visit, but the billing team can only rely on what appears in the documentation. If the note does not clearly support the service being reported, defending the claim later becomes much more difficult.

The Centers for Medicare & Medicaid Services (CMS) provides guidance on electronic healthcare claims and the information needed for claims processing. The larger point for a practice is simple: compliance starts long before a denial or payer review arrives.

Documentation and Coding Need to Tell the Same Story

Documentation and coding are often discussed as separate tasks. In actual billing, they are difficult to separate. The code on the claim is supposed to represent what happened during the encounter. The medical record is what supports that representation.

Problems begin when the two tell different stories.

A common OB/GYN situation is a preventive visit in which the patient also brings up a new medical concern. Additional evaluation may take place during the same encounter. Whether separate reporting is appropriate depends on the services performed, the documentation, coding rules, and the payer's requirements. Similar questions come up with procedures, diagnostic testing, postoperative care, maternity services, and modifier use.

A diagnosis code may be valid in general but still fail to match what the provider actually documented. A procedure code may describe a service correctly but lack enough support in the chart. A modifier can also create problems when staff use it routinely instead of deciding whether the circumstances of that particular encounter justify it. These are not always dramatic errors. That is part of the problem.

When the same documentation habit or coding shortcut is repeated week after week, an isolated weakness can turn into a larger compliance concern.

Periodic chart-to-claim reviews can help uncover those patterns. Instead of asking only whether the claim was paid, the reviewer looks at whether the claim accurately reflects the record and whether the documentation is strong enough to support what was billed.

Some Claim Errors Have Nothing to Do with Complex Coding

Not every denied or rejected claim involves a difficult coding question. Sometimes the problem is a wrong date, an outdated insurance record, missing provider information, an incorrect subscriber ID, or a claim field that was left incomplete. These errors may sound minor, but they still consume staff time and slow down payment.

Electronic claims generally pass through automated edits during processing. Certain missing or inconsistent details can cause the claim to stop before it gets very far.

A short review before submission can catch many of those problems. Staff may want to verify:

  1. Patient and subscriber information.
  2. Current insurance coverage and coordination of benefits.
  3. Provider and practice identifiers.
  4. Diagnosis codes, procedure codes, and modifiers.
  5. Documentation supporting the billed service.
  6. Required authorization or referral information.
  7. Payer-specific claim requirements and missing fields.

The review does not have to turn into a lengthy approval process for every claim. What matters is that the practice has a reliable way to catch repeatable errors before the payer does.

Eligibility Deserves More Attention in OB/GYN Billing

Insurance information can change during the course of care, and OB/GYN practices are especially likely to encounter that issue because many patients receive services over an extended period.

Pregnancy is an obvious example. A patient may have one insurance plan early in the pregnancy and another later. Employment can change. A spouse's coverage can change. Coordination of benefits may need to be updated. Authorization rules may also be different under the new plan. If staff rely on an eligibility check performed months earlier, the billing team may not find out about the change until a claim is denied.

Eligibility problems can affect more than reimbursement. They may also result in the wrong amount being assigned to the patient or create confusion about who is financially responsible for the service.

Checking coverage at appropriate points throughout treatment gives staff a chance to address those issues before the claim has already gone through the billing cycle. It also makes financial conversations with patients more accurate.

A Denial May Be Pointing to a Workflow Problem

Correcting a denied claim is necessary. Correcting the same type of denial twenty times should raise a different question - Why does it keep happening?

Suppose claims for a particular procedure regularly come back because information is missing. Billing staff can add the information and resubmit each claim, but that does not explain why the original claims were incomplete.

Maybe the registration team is not collecting something the payer requires. Perhaps the authorization information exists but is not being transferred correctly. It could also be that staff misunderstood a payer policy. The denial itself is only the visible part of the problem.

This is why useful denial management goes beyond counting how many claims were denied. Practices can look at which reasons occur most often, which payers are involved, whether one service keeps appearing, and where in the workflow the original error began.

That kind of review can reveal patterns that would otherwise remain hidden. The CMS Medical Review and Education resources also discuss claims analysis and medical record review in the context of identifying improper billing and documentation issues. For an OB/GYN practice, denial data can serve as a practical warning system. It shows where the revenue cycle is struggling, not just where payment was delayed.

Internal Audits Can Be Small and Still Be Useful

An internal audit does not have to involve hundreds of charts. A practice can learn a great deal from a carefully chosen sample.

Maybe one modifier has been causing questions. Perhaps a particular payer has denied an unusually high number of claims. There may be concerns about preventive visits, maternity billing, surgery, medical necessity documentation, or another service that carries more risk. Those claims can be reviewed against the medical record.

The reviewer may find that everything was handled appropriately. If not, the next step is to determine whether the problem was isolated or whether it reflects a larger habit. That distinction matters. One coding mistake made on a single claim may require a simple correction. Finding the same mistake across several providers or multiple dates of service suggests that the practice may need education, a workflow change, or closer monitoring. The audit should not end when the error is identified.

If a change is made, the practice needs some way to determine whether it worked. Reviewing another sample later can show whether the same problem is still appearing. Without follow-up, the practice has documented a problem but has not necessarily solved it.

Compliance Works Better When It Is Part of Routine Operations

A compliance process does not need to be complicated to be useful. In many practices, consistency matters more than creating a large set of policies that nobody uses. Staff should know how registration is handled, when eligibility is checked, how authorization information is recorded, how claims are reviewed, what happens when a denial arrives, and who is responsible for following up on recurring problems.

Those processes should not exist only in one employee's memory. Training matters for the same reason. Payer policies change. Coding guidance changes. Internal workflows change. New employees arrive, and experienced employees sometimes continue using a process that made sense under an older rule.

Regular education gives the practice a chance to catch those gaps.

Billing data can also help determine where training is needed. If eligibility denials suddenly increase, the first response should not necessarily be a general coding seminar. The practice may need to look at registration and verification instead. If several claims involving the same modifier are being questioned, a focused review of those encounters is probably more useful than retraining the entire staff on every coding topic. Compliance becomes easier to manage when the response matches the actual problem.

Documentation Reviews Should Include the Claim

A chart can look complete on its own while the corresponding claim still contains a problem.

The opposite is also possible. A claim may appear technically correct until someone compares it with the medical record.

Looking at both together usually provides a clearer picture. This is particularly important for services where the circumstances of the encounter affect billing. Preventive care, problem-oriented visits, procedures, maternity care, and postoperative services can all raise questions that cannot be answered by looking at a code alone.

The reviewer needs to understand what actually happened during the visit, what the provider documented, and how that information was translated into the claim.

Preparing for Billing Changes Before They Reach the Claims Department

One of the easiest ways for a billing problem to spread is for a rule to change while the practice keeps following the old process. Changes may affect coding, documentation, payer policies, reimbursement, or the way certain services are reported.

The first sign should not have to be a wave of denials.

When a significant change is announced, the practice can identify which services will be affected and who needs to know about it. Providers may need different documentation. Billing staff may need revised procedures. Software settings or claim edits may also need to be updated. Testing the new process early is usually easier than correcting a backlog later. This becomes especially important when changes affect maternity services because the care and billing may span several months.

The Bigger Compliance Question

A claim can be paid and still come from a weak process. That is why payment should not be the only measure of whether an OB/GYN billing operation is working well. A better question is whether the practice could explain and support the claim if someone reviewed it later.

  • Was the patient's coverage checked?
  • Does the chart support the service?
  • Does the code match what was documented?
  • Were payer requirements addressed?
  • If a similar problem appeared last month, was anything changed afterward?

Those questions bring compliance into the normal revenue-cycle process instead of treating it as something that matters only during an audit.

Most billing problems do not begin as major compliance failures. They usually start much smaller: an insurance detail that was not updated, documentation that was a little too vague, a modifier applied out of habit, or a denial that was corrected without asking why it happened.

The risk grows when the same issue becomes routine.

Finding those patterns early is what gives a practice the best chance to correct them before they affect more claims, more patients, or more revenue.

About the Author Noah Smith

This article is written by Noah Smith on behalf of BillingFreedom. Noah is a medical biller, SEO and Content Outreach Specialist.

Additional Resources

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
General Compliance, HIPAA

Before PHI Enters a SaaS Workflow

Building a Vendor Evidence Register 

Written by Coco Yang 

Introduction

A clinic can approve a scheduling platform and still miss the place where patient information leaves the approved path. An intake form may pass data to the scheduler, which sends a notification through an email service, creates a record in a customer relationship management system, and copies details into an analytics tool. The vendor review may have covered the scheduling platform. The actual workflow contains four or five services.

That is why a product name and a "HIPAA compliant" statement are not enough to document a SaaS decision. The review needs to identify the exact service, plan, configuration, integrations, users, and data flow. It also needs a record of what each source supports, what it does not support, and what still requires an answer from the vendor.

A vendor evidence register provides that record. It is not a certification score and should not replace legal, privacy, security, procurement, or clinical review. It is a practical way to keep the evidence behind a decision visible before protected health information (PHI) enters a software workflow.

Start With the Workflow, Not the Vendor Name

The first question is not simply, "Does this vendor support HIPAA?" A more useful starting question is, "What will this organization do with this exact service?"

Write down the product edition and paid plan, the features that will be enabled, the people who will have access, and the systems that will send or receive data. Include support tools, exports, backups, browser extensions, mobile applications, application programming interfaces, automation services, and optional artificial intelligence features. Then identify where PHI is expected to be created, received, maintained, or transmitted.

This boundary matters. A vendor may make a business associate agreement (BAA) available only for certain products, plans, customers, or configurations. An integration may be provided by another company. A feature may use a separate sub-processor or different retention setting. HHS guidance on cloud computing advises covered entities and business associates to understand the cloud environment they are using so they can conduct their own risk analysis and enter into appropriate agreements.

A simple workflow sentence helps anchor the review. For example: "Patients submit contact and appointment information through Form A; the data is stored in Scheduler B; staff members access it through managed accounts; appointment reminders are sent through Service C; no PHI is sent to analytics." If the team cannot write that sentence with confidence, it is too early to approve the workflow.

Keep Different Kinds of Evidence Separate

Vendor material often arrives as a mixed folder of contracts, reports, help-center pages, questionnaires, and sales statements. These sources do not answer the same questions.

A BAA is contractual evidence. HHS explains that a business associate contract establishes permitted and required uses and disclosures, requires safeguards, addresses incident reporting, applies restrictions to relevant subcontractors, and covers return or destruction of PHI at termination when feasible. The review still needs to confirm that the agreement applies to the exact legal entity and service being purchased.

A SOC 2 report is security-assurance evidence. It can help a reviewer understand the systems, controls, time period, exceptions, and subservice organizations described in the report. It does not establish that the vendor will sign a BAA, that the intended product is included in the BAA, or that the customer's configuration is appropriate.

Product documentation explains how features work. It may describe access controls, audit logs, retention settings, encryption, data regions, or deletion behavior. Marketing language is a weaker source. It can point the team toward a question, but it should not be treated as proof that a contract, report, or technical control covers the planned workflow.

Keeping these evidence types separate prevents one familiar logo or badge from doing more work than it should.

What to Record

The register does not need to be elaborate. A spreadsheet, ticket, or procurement record can work if it preserves enough context for another reviewer to reconstruct the decision. For each item, record:

  1. The source title, owner, and location.
  2. The date it was retrieved and, when applicable, its effective period or report period.
  3. The legal entity, product, plan, feature, and region it covers.
  4. The conclusion the source supports.
  5. Conditions and limitations stated in the source.
  6. Questions that remain open and the person responsible for resolving them.
  7. The date or event that will trigger another review.

Short conclusions are more useful than broad labels. "Vendor says HIPAA compliant" is difficult to act on. "BAA offered for the Enterprise plan; analytics add-on not named; vendor confirmation pending" tells the next reviewer what is known and where the uncertainty sits.

The same discipline should be used for security evidence. Instead of recording "SOC 2 available," note the report type, review period, system description, relevant exceptions, complementary customer controls, and whether important subservice organizations are included or carved out.

Check the Operational Questions

Contracts and assurance reports are only part of the review. The intended use also depends on routine operational details.

Ask which sub-processors may create, receive, maintain, or transmit PHI. Confirm how administrators and support personnel obtain access, whether that access is logged, and how emergency support is handled. Review default retention, backup retention, deletion timing, export behavior, account termination, and the process for returning or destroying data.

Incident language deserves the same attention. Identify where the vendor describes security incidents and breach notification, who receives notice, and whether the timing and cooperation terms match the organization's requirements. Customer-side safeguards should also be explicit: identity management, multifactor authentication, role design, device controls, logging, staff training, approved integrations, and procedures for offboarding users.

A signed BAA does not configure the product. HHS risk-analysis guidance makes clear that regulated organizations must identify potential risks and vulnerabilities to all electronic PHI they create, receive, maintain, or transmit. The vendor's evidence informs that work; it does not perform the organization's risk analysis for it.

Use Evidence States Instead of a Single Verdict

A binary field labeled "compliant" hides too much. Evidence is often conditional, incomplete, inconsistent, or old. A small set of evidence states makes the record more honest:

  • Supported: the source directly supports the conclusion for the identified scope.
  • Conditional: the conclusion depends on a plan, configuration, contract, location, or customer action.
  • Missing: the needed source has not been obtained.
  • Conflicting: two sources disagree or describe different scopes.
  • Stale: the source no longer reflects the current product, contract, report period, or workflow.

These are evidence states, not compliance determinations. They help the organization route questions to the right owner and avoid treating silence as approval.

Review Again When Something Changes

An annual vendor review is useful, but a change in the workflow can make last month's evidence incomplete. Set event-based review triggers for a new contract or BAA, a plan change, a new integration, a material sub-processor update, revised retention terms, a new artificial intelligence feature, a security incident, or a change in the type of PHI being handled.

The register should also have an owner. Procurement may hold contracts, security may review assurance reports, privacy or compliance may assess uses and disclosures, and the operational team may know the actual configuration. Someone must be responsible for assembling those pieces and recording the final conditions of use.

Conclusion

A SaaS review is easier to defend when another person can see exactly what was reviewed, when it was reviewed, and which workflow the decision covered. Begin with the data path. Separate contractual, assurance, product, and marketing evidence. Record scope and dates. Preserve unresolved questions. Reopen the review when the service or workflow changes.

The purpose of a vendor evidence register is not to produce a universal badge. It is to make the reasoning behind a decision inspectable before PHI enters the workflow. Final decisions should remain with the organization's qualified legal, privacy, security, compliance, procurement, and operational professionals.

About the Author

Coco Yang is the Founder of ComplySaaS, an educational SaaS vendor compliance research project that organizes public HIPAA, BAA, PHI, and SOC 2 signals, source dates, workflow conditions, and verification questions. Her work is limited to documented vendor-research practice; she is not presenting herself as an attorney, auditor, healthcare provider, or compliance certifier. Company website: https://www.complysaas.com/

References

U.S. Department of Health and Human Services. "Guidance on HIPAA & Cloud Computing."

U.S. Department of Health and Human Services. "Business Associate Contracts."

U.S. Department of Health and Human Services. "Guidance on Risk Analysis."

National Institute of Standards and Technology. "SP 800-66 Rev. 2: Implementing the HIPAA Security Rule."

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Healthcare Revenue Cycle Compliance

Common Risks and How Practices Can Address Them 

Written by: Zara Ahmad 

A revenue cycle rarely breaks because of one dramatic mistake. More often, the problem begins with something ordinary: an insurance card was updated but the old plan stayed in the system, a provider’s note lacked enough detail for coding, or a denied claim was resubmitted before anyone checked the first one.

Compliance is not limited to the billing office. It starts when patient information is collected and continues through documentation, coding, claim submission, payment posting, denials, and follow-up.

Where Compliance Risks Can Enter the Revenue Cycle

Consider a routine office visit. The front desk enters the patient’s demographic and insurance information. If the member number is wrong, or the payer on file is outdated, the claim may already be inaccurate.

The next risk may appear in the medical record. A provider knows what happened during the visit, but a coder can only rely on what is documented. If a note is vague, staff should not fill in missing details from habit or assumption.

Charge capture creates another point of exposure. A service can be missed, entered twice, or attached to the wrong date. Later, a biller may resend a denied claim without confirming whether the original is still processing. Payment posting and accounts receivable follow-up can create problems too, especially when adjustments or corrections receive little review.

Common Revenue Cycle Compliance Risks

One familiar risk is a mismatch between the medical record and the claim. The service billed should be supported by the documentation. CMS guidance for Medicare makes documentation part of determining whether applicable coverage, coding, billing, and payment requirements are supported.

Incomplete documentation is often less obvious. A note may show that care occurred but still omit information needed to support a code, modifier, or service level. If that happens regularly, the issue is no longer just one troublesome claim.

Administrative mistakes matter as well. Incorrect patient details, insurance information, provider identifiers, and dates of service can cause denials and repeated corrections. Duplicate claims are another example. When payment is delayed, resubmitting the same claim may feel harmless, but claims-processing rules include duplicate edits.

Corrections need a consistent approach – contingent upon the payer and circumstances, the right step may be a corrected claim, replacement claim, appeal, or another defined process.

Why Documentation and Coding Accuracy Matter

Documentation, coding, and billing are different jobs, but they should describe the same encounter.

Suppose a coder returns the same type of note to the same provider several times each month because one detail is routinely missing. Correcting each claim solves the immediate problem, not the workflow problem.

A short, focused discussion with the provider may be more useful than another round of individual corrections. The aim is simply to make sure the record clearly reflects the service provided and gives coding staff the information they need.

Using Internal Audits to Identify Compliance Risks

Internal audits are most useful when they answer a specific question.

A manager might sample claims involving a frequently used modifier, one provider, a service with rising denials, or a payer that has generated repeated corrections. The review can compare claims with medical records, check key fields, examine adjustments, and see whether staff followed internal procedures.

Patterns often tell the real story. Several eligibility denials traced to the same registration step suggest a front-end workflow problem. Repeated coding questions may point to training or documentation habits instead.

An audit should lead somewhere. Someone needs to own the follow-up, record what changed, and later check whether the change helped.

Building a Stronger Compliance Culture

Compliance works better when people see how their own work affects the claim. Front-office staff influence patient and insurance information. Providers influence documentation. Coders and billers influence what reaches the payer. Managers decide whether recurring problems are investigated or simply worked around.

OIG’s General Compliance Program Guidance discusses written policies, education, communication, auditing and monitoring, and corrective action as parts of a compliance program. In everyday practice, those ideas are more useful when connected to real problems rather than treated as an annual checklist.

Training should follow the same principle. If an audit finds repeated modifier errors, train on that issue. If registration mistakes are driving denials, review that workflow with the people who perform it.

Practical Steps Healthcare Practices Can Take

  1. Review a representative sample of claims regularly.
  2. Compare billed codes with the supporting medical record.
  3. Track denials and claim corrections by reason.
  4. Review write-offs, refunds, adjustments, and claim changes for consistency.
  5. Use recurring errors to guide staff and provider education.
  6. Keep billing and compliance procedures current and easy to find.
  7. Document corrective actions and check whether they worked.
  8. Follow relevant CMS, OIG, and other authoritative guidance as requirements change.

Keeping Compliance Part of Everyday Work

No revenue cycle will be completely free of errors. What matters is what happens after a mistake is found. Comply with overpayment rules. Submit appropriate claims adjustments, credit balance reports, or self-reported refunds directly to your assigned Medicare contractor.

Investigate. Correct the affected account, but do not stop there. Ask where the error entered the process, why it was not caught earlier, and whether the same thing is happening elsewhere. That turns compliance from a periodic exercise into part of ordinary revenue cycle work. Over time, it can reduce avoidable rework, support more accurate billing, and leave a practice better prepared when claims are reviewed.

About the Author

Zara Ahmad is a healthcare industry professional and Marketing Team Lead at MedsIT Nexus, with a focus on healthcare revenue cycle management, healthcare operations, and industry education. Her work involves developing educational resources on healthcare administration, revenue cycle processes, and operational challenges affecting healthcare organizations.

Resources – obtain training in conducting internal audits and investigations from the American Institute of Healthcare Compliance, a Licensing/Certification partner w/CMS.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

HCC Coding in 2026

Navigating Risk Adjustment in a Changing Healthcare Landscape 

Written by: Joy Rose, MSA, RHIA, CCS, CHA, CHPS 

In 2026, Hierarchical Condition Category (HCC) coding continues to evolve as a central pillar of risk adjustment in value-based care. Initially introduced by the Centers for Medicare & Medicaid Services (CMS) to project healthcare costs and determine payments for Medicare Advantage (MA) plans, HCC coding has become a strategic necessity across multiple payers and care settings.

Medicare Advantage Organizations (MAOs) are paid at a higher rate for patients who have conditions with greater levels of severity and multiple conditions, as their RAF scores and anticipated costs of care will be higher.

Key 2026 Medicare Advantage (MA) Cost Reporting Requirements

CMS requires Medicare-certified acute care hospitals reimbursed under the IPPS (inpatient prospective payment system) to report median negotiated payment rates from Medicare Advantage (MA) plans by MS-DRG on their annual cost reports for cost reporting periods ending on or after January 1, 2026.

This mandate aims to collect market-based data to set future inpatient prospective payment system (IPPS) relative weights.

  • Data will be used to set future MS-DRG weights likely by Fiscal Year 2029.
  • This requirement adds significant complexity to an already error-ridden annual Cost Report process.

Providers must ensure the accurate reporting of MA negotiated rates to avoid potential audit findings, as this data will influence future payment setting.

New in 2026 - Full transition to V28 Model has occurred

One of the biggest updates in 2026 is the full implementation of the CMS-HCC V28 model, which was first introduced in 2023. This model includes significant changes:

  • More clinically relevant or accurate groupings, especially for chronic conditions like diabetes and congestive heart failure.
  • Expanded but refined HCC categories: V28 increases the number of HCC categories from 86 to 115, creating more granular groupings while reducing additive combinations.
  • Renumbering and changing HCC categories.
  • Removal of some condition codes that were found to be less predictive of future healthcare costs.
  • Reduction in the number of ICD-10-CM codes from 9,797 to 7,770 (approximately 2294 codes deleted and 268 codes added)
  • More accurate clinical data and the use of data-drive results with the use of 2018 ICD-10-CM codes and 2019 payment information.

Healthcare providers must now re-map workflows for diagnosis coding processes and re-educate coding staff to ensure accurate code assignment based on the documentation provided by clinicians.

Greater Emphasis on Documentation Integrity - With more sophisticated audits by CMS and private payers, clinical documentation improvement (CDI) remains a top priority. Inaccurate or unsupported codes now carry steeper compliance risks, and real-time documentation tools are being widely adopted to assist clinicians. Clinicians must be educated and trained about the new model which will require even greater specificity in documentation and code assignment to ensure that the true level of the Medicare Advantage patients’ illness severity is captured and transmitted to CMS for appropriate costs analysis.

AI and NLP Integration - Natural Language Processing (NLP) and artificial intelligence (AI) tools are increasingly embedded in EHR systems to assist in identifying undocumented HCCs and improving capture rates. These tools help flag missed conditions, identify hierarchical overlaps, and ensure that chronic conditions are properly documented and reported annually. AI has its limitations according to a colleague managing denials.

Important Note - The AI tool that is being tested a major Boston medical facility is not intelligent enough to find HCCs, or even ICD-10 codes to ensure a robust denial can be created.  The medical team working with the denials team does not approve the AI findings in about 80% of the AI suggestions.

Key Challenges - Training and education remain critical as coding teams and clinicians adjust to new rules and technology.  In addition, there is coding fatigue from increased workload and regulatory pressure may affect coder accuracy and job satisfaction.

Providers must also balance HCC optimization with ethical standards and compliance, avoiding aggressive or unsupported upcoding practices. It is important for organizations to realize there is increased CMS scrutiny, by flagging providers as high-volume billing outliers or submitting claims with unusually high severity levels.

Opportunities:

  • Risk-adjustment data analytics now allow organizations to benchmark performance and track documentation trends in real time.
  • Proactive condition management enabled by accurate HCC coding allows payers and providers to better target care management and reduce preventable costs.
  • Interoperability and FHIR-based data exchange in 2026 enable smoother sharing of clinical data across systems, improving longitudinal risk tracking.
  • Increased focus on severity of patient diagnosis and claims by CMS

Real World Impact

As CMS moves further into outcome-based models and enhances its oversight of MA payments, the role of HCC coding will only grow in significance. Health systems that invest in robust CDI programs, AI-assisted coding tools, and clinician training will be better positioned to thrive in this value-based future.

Some analysts warn the shift could lower RAF scores 10-20% for providers still relying on V24-era documentation habits, since patients whose only qualifying condition was deleted in V28 effectively disappear from risk registries. Plans with large diabetic populations that previously captured a lot of complication-related detail are seeing the steepest declines, though expanding documentation breadth across different disease families can partly offset this.

Because of the revenue pressure, CMS/OIG have signaled they'll be watching closely for organizations overcompensating with inflated severity coding.

About the Author

Joy Rose, MSA, RHIA, CCS, CHA, CHPS is a member of the American Institute of Healthcare Compliance (AIHC) and serves as a subject matter expert on the AIHC Volunteer Education Committee.

References:

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

The Imperative of Documentation Integrity

Addressing the Healthcare Data Crisis 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

The information in this article primarily applies to providers when recording patient encounters in their office or other places of service. Content is for educational purposes only and is not intended as consulting or legal advice.

Introduction

Clinical documentation represents the foundational pillar of modern healthcare, ensuring patient safety, care continuity, accurate reimbursement, and the ethical use of medical data for research. However, the healthcare industry is currently grappling with a severe data crisis driven by the proliferation of historical documentation errors.

  • The transition from paper-based charts to Electronic Health Records (EHRs), while designed to streamline operations and reduce medical errors, has inadvertently introduced systemic vulnerabilities that compromise the integrity of clinical data.

The modern healthcare data crisis is not simply a matter of lost or misplaced files; it is a systemic degradation of data quality caused by the cumulative effect of historical documentation errors. At the center of this crisis is the phenomenon known as "chart lore" or "note bloat," where inaccuracies and redundancies are perpetuated across multiple patient encounters.

Several structural and behavioral factors drive this crisis:

  • Overuse of Copy/Paste and Cloning: The implementation of EHRs introduced time-saving functionalities such as the "copy-forward" or copy/paste features. Studies have revealed that over 50% of the text in inpatient and outpatient notes is duplicated. This practice often results in carrying over outdated, irrelevant, or entirely incorrect clinical information (e.g., documenting an allergy that was proven false years prior), creating information overload and increasing the risk of adverse events.
  • Template and Drop-Down Menu Errors: The reliance on pre-populated templates and drop-down menus can lead to "mouse-click errors," where a provider accidentally selects a normal finding for an abnormal condition. These errors obscure the true "patient story" and result in contradictory or missing clinical context.
  • Patient Matching and Interoperability Failures: Poor data entry and fragmented system integration contribute to patient misidentification. Industry surveys indicate that up to 20% of patients may not be correctly matched to their records, leading to scenarios where providers make treatment decisions based on another individual’s medical history.
  • Defensive and Billing-Driven Documentation: Because healthcare systems rely on Evaluation and Management (E/M) codes and reimbursement structures, clinicians are often pressured to document excessively to satisfy complex billing requirements, rather than focusing purely on clinical utility. This return-on-investment approach distorts the clinical record and leads to defensive medicine.
    • In light of Evaluation & Management guidelines allowing time or medical decision-making for many codes, providers must remember, when time is used, the complexity of the visit must be reflected to support longer visit times (higher reimbursed codes). Payers will question when high levels of service are billed but the note does not reflect the amount of work to support reimbursement.

Artificial Intelligence and the Physician/Provider Burden

Ironically, the tools intended to make documentation easier, EHR systems, have become a leading driver of clinician stress and burnout. The "cognitive load" of navigating drop-down menus and templating systems detracts from face-to-face patient time. And now with Artificial Intelligence (ambient scribes) being integrated into clinical documentation, the burden can become overwhelming due to time to ensure there are no errors in the record. AI is being built of historical information that is peppered with errors, inaccuracy, and omissions.

Despite promised efficiency gains, a large multi-center study found that AI ambient scribes saved a relatively modest 16 minutes of documentation time per eight hours of care. Because physicians are ultimately responsible for the accuracy of their medical records, they are forced to shift cognitive effort from typing to auditing—carefully reviewing AI-generated text to ensure no critical data has been omitted or misstated

Integrating artificial intelligence (AI) as ambient scribes in clinical settings reduces documentation time but yields distinct error profiles. Studies from the National Library of Medicine indicate that up to 70% of AI-generated notes contain at least one error, with an average of 2 to 3 errors per note. Omissions are the most common mistake, accounting for 71% to 83% of all errors.

Breakdown of AI Errors

Research shows that the types and frequencies of errors vary widely by system:

  • Omissions: Occurring in roughly 70-80% of recorded mistakes, this happens when AI leaves out critical details. Studies note that over 40% of these omissions carry moderate to significant clinical importance (e.g., omitting comorbidities or medication side effects).
  • Additions: Representing 4% to 11% of errors, this occurs when the AI fabricates or inserts information that was never discussed.
  • Hallucinations & Wrong Outputs: Fabricated or severely misidentified medical terminology.
  • Misplacements: Occurring in 6% to 25% of errors, where the AI correctly transcribes the info but places it in the wrong section of the chart.

Documentation Integrity & Accuracy Metrics

While traditional self-documentation by doctors can also be fragmented, ambient AI drafts often capture a much higher volume of the spoken interaction. However, this can sometimes lead to an inverse problem of information overload for the physician reviewing notes for accuracy.

Patient Safety and Clinical Continuity

The primary purpose of any clinical note is to support continuous, high-quality patient care. Outpatient practices frequently treat patients across extended timelines and involve diverse clinical staff. Therefore, documentation integrity is critical for several interconnected reasons:

  • Preventing Diagnostic and Medication Errors: When previous providers fail to update active problem lists, or when notes contain contradictory information, the risk of adverse events skyrockets.
    • Accurate documentation ensures that allergy lists, historical diagnoses, and ongoing treatment regimens are clear, preventing medication interactions and duplicative testing.
  • Facilitating Coordinated Care: In an era of team-based care and interoperability, patient notes are often referenced by external specialists, primary care physicians, and allied health professionals.
    • Complete, up-to-date clinical notes give care teams a holistic view of a patient’s health journey, allowing them to make informed, data-driven decisions.

Financial Sustainability and Revenue Cycle

Documentation dictates reimbursement and an organization’s ability to support compliant billing and reimbursement. In outpatient settings, practices rely on Evaluation and Management (E/M) coding guidelines established by the Centers for Medicare & Medicaid Services (CMS) and the American Medical Association (AMA).

  • Reducing Claim Denials: Payers use automated systems to verify that documented services match the billed codes. Incomplete or vague documentation leads to high rates of claim denials, requiring expensive and time-consuming rework for billing staff.
  • Combating the "Cloning" Risk: EHRs offer time-saving features like "copy-and-paste," "carry-forward," and auto-fill. While efficient, these features frequently lead to documentation cloning, where notes contain outdated or clinically irrelevant information.
    • Payers increasingly view cloned notes as a compliance risk, which can lead to delayed payments or allegations of upcoding, leading to allegations of violating the False Claims Act.

The Clinical and Legal Repercussions

The accumulation of these errors across vast databases has severe, real-world consequences for patient safety and institutional liability. Regulatory bodies, including the Department of Health and Human Services (HHS) Office of Inspector General (OIG), heavily scrutinize outpatient billing. Ensuring documentation integrity limits the financial and reputational damage of audits:

  • Demonstrating Medical Necessity: Every medical service must be justified by documented medical necessity. Documentation must clearly demonstrate why a course of action was taken and what alternatives were considered. Without this, practices are vulnerable to recoupment during post-payment audits.
  • Combating Fraud, Waste, and Abuse: Accurate charting protects both the provider and the organization. Attempting to add missing information or diagnoses to a chart after an audit has been initiated is a serious legal violation that carries civil and criminal penalties. Maintaining real-time, tamper-evident documentation is the best legal defense for providers.
  • Patient Harm and Medication Errors: Data integrity issues directly impact diagnostic accuracy and treatment planning. Studies indicate that a significant percentage of EHR-related events—sometimes cited as over one-third of cases—have life-threatening potential. When providers are forced to skim through bloated records, critical changes in a patient's condition or medication history are frequently missed.
  • Artificial Intelligence and Big Data Limitations: The current push toward integrating artificial intelligence (AI) and machine learning (ML) into healthcare relies entirely on the premise of data accuracy. However, because a high percentage of EHR records contain documentation errors, predictive models are frequently built on flawed or "missing" data indicators, which compromises their clinical reliability and introduces unconscious biases into algorithmic decision-making.
  • Malpractice Liability: Legal teams increasingly scrutinize EHR meta-data and documentation errors during litigation. Many EHR-related malpractice liabilities stem directly from documentation errors and omission, making inaccurate record-keeping a major risk management concern.

Strategies for Restoring Documentation Integrity

Addressing the healthcare data crisis requires a fundamental shift in how documentation is viewed, created, and audited. Organizations must move beyond billing-centric metrics and prioritize true Clinical Documentation Integrity (CDI). We simply need more documentation professionals, specifically in the outpatient setting where most care is rendered.

Implement Continuous CDI Programs - Healthcare facilities must establish dedicated CDI teams that routinely review and audit charts for clarity, completeness, and clinical accuracy. However, it is important that auditors and those training providers in CDI have structured training themselves first. Not all coding and billing auditors are qualified to conduct a documentation integrity audit. By educating all those involved on best practices and modern documentation guidelines, organizations can ensure that the patient's medical history accurately reflects their current clinical state.

Engage with organizations for online CDI training to improve the basic understanding of a compliant medical record. Registering qualified staff and/or providers with an organization which is a Licensing/Certification partner with CMS is recommended, such as the American Institute of Healthcare Compliance which offers online training with option to Certify as a Medical Documentation Professional.

EHR Usability and Design Overhaul - Software vendors and IT departments must collaborate to redesign EHR interfaces. This includes implementing strict limits on copy-paste functionalities, utilizing anomaly detection tools to flag duplicated or contradictory text, and enhancing interoperability to reduce patient matching errors.

Structured Data Capture - Shifting from unstructured narrative notes to standardized, structured data formats allow for better data reuse, less error-prone information exchange, and more effective clinical decision support systems.

Patient Engagement as a Verification Tool - Opening up EHRs to patients—allowing them to access their own health records and actively report discrepancies—has proven to be an effective strategy for identifying and resolving embedded "EHRrors" before they cause harm.

Conclusion

The historical degradation of healthcare data integrity poses a significant public health threat, turning patient records from life-saving tools into repositories of perpetuated errors.

To mitigate this crisis, the healthcare ecosystem must prioritize actionable, systemic reforms. By investing in enhanced EHR design, responsible implementation of integrating AI, rigorous auditing and compliance, and a culture of clinical clarity, the industry can restore trust in medical data and safeguard patient lives.

Outpatient practices can no longer treat clinical documentation as a mere administrative byproduct. Documentation integrity is the structural backbone of patient safety, financial compliance, and legal protection. By actively investing in CDI processes, ongoing provider education, and optimized EHR workflows, outpatient practices can safeguard patient outcomes, reduce audit vulnerabilities, and restore clinician satisfaction.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing, Corporate Compliance

Auditing for Anti-Kickback Statute Violations

Written by the AIHC Education Department 

About the AKS 

The Anti-Kickback Statute [42 U.S.C. § 1320a-7b(b)] 

The AKS is a criminal law that prohibits the knowing and willful payment of "remuneration" to induce or reward patient referrals or the generation of business involving any item or service payable by the Federal health care programs (e.g., drugs, supplies, or health care services for Medicare or Medicaid patients). Remuneration includes anything of value and can take many forms besides cash, such as free rent, expensive hotel stays and meals, and excessive compensation for medical directorships or consultancies.

In some industries, it is acceptable to reward those who refer business to you or your organization. However, in the Federal health care programs, paying for referrals is a crime.  

The statute covers the payers of kickbacks, those who offer or pay remuneration, as well as the recipients of kickbacks. Yes, the law applies to those who solicit or receive remuneration. Each party's intent is a key element of their liability under the AKS.

The Department of Justice (DOJ), the Department of Health and Human Services Office of Inspector General (OIG), and the Centers for Medicaid and Medicare Services (CMS) are all charged with enforcing these laws. Filing claims to any Federal healthcare program related to an AKS violation may also violate the False Claims Act (FCA). From there, it just gets more complicated because kickbacks in health care can lead to:

  • Overutilization
  • Increased program costs
  • Corruption of medical decision making
  • Patient steering
  • Unfair competition

The kickback prohibition applies to all sources of referrals, even patients. For example, where the Medicare and Medicaid programs require patients to pay copays for services, you are generally required to collect that money from your patients. Routinely waiving these copays could implicate the AKS and you may not advertise that you will forgive copayments. It can be used to induce patients to choose a specific provider's services or to prescribe their products instead of cheaper alternatives. However, you are free to waive a copayment if you make an individual determination that the patient cannot afford to pay or if your reasonable collection efforts fail. It is also legal to provide free or discounted services to uninsured people.

The Government does not need to prove patient harm or financial loss to the programs to show that a physician violated the AKS. A physician can be guilty of violating the AKS even if the physician actually rendered the service and the service was medically necessary. Taking money or gifts from a drug or device company or a durable medical equipment (DME) supplier is not justified by the argument that you would have prescribed that drug or ordered that wheelchair even without a kickback.

Consequences for Violating the AKS

AKS Criminal penalties and administrative sanctions for violating the AKS include fines, jail terms, and exclusion from participation in the Federal health care programs as follows:

  • Civil penalties: The CMPL allows the Office of Inspector General (OIG) to impose civil penalties for violations of the Anti-Kickback Statute. These penalties include a fine of up to $50,000 per violation plus three times the value of the illegal kickback (treble damages).
  • Criminal penalties: Violating the Anti-Kickback Statute is a felony and can also lead to criminal penalties, including fines of up to $100,000 and imprisonment for up to 10 years.
  • Other consequences: In addition to financial and criminal penalties, individuals found guilty of kickback violations can be excluded from participation in federal health care programs. The Office of Inspector General (OIG) has the authority to exclude both individuals and entities. Claims that include items or services resulting from a violation are not payable and may constitute false or fraudulent claims under the False Claims Act.

Criminals Target Healthcare Providers

Physicians make an attractive target for kickback schemes because you can be a source of referrals for fellow physicians or other health care providers and suppliers. As a provider, you decide what drugs your patients use, which specialists they see, and what health care services and supplies they receive. And criminals count on providers not understanding the law. This point stresses the need to audit for potential AKS violations and to have a healthcare attorney familiar with the AKS to review any agreements in advance to avoid an unlawful situation.

There are still handshake deals made, where there is no written agreement, where remuneration is made in exchange for some form of kickback. Even these “unwritten” arrangements should be audited for potential issues.

Auditors are typically not attorneys, but an internal auditor can receive training to review for potential violations, then refer questionable situations to the Compliance Officer who will forward to outside legal counsel for further investigation and corrective action.  Why outside legal counsel? In-house legal counsel is likely to have reviewed or written the agreement in question, creating a conflict of interest in being involved in any aspect of the audit process.

Common targeting methods

  • Payments disguised as legitimate compensation:
    • Paying providers for patient referrals disguised as "bonuses" or "referral fees".
    • Offering or paying for patient information that is used to market to potential enrollees.
    • Paying providers for "consulting," "advising," or "research" when the primary purpose is to secure referrals.
    • Overpaying doctors for speaking engagements.
    • Payments for office space, phlebotomy, or other services that are inflated or not legitimate, intended to be a form of compensation for referrals.
  • In-kind or indirect benefits:
    • Providing free or below-market rent, equipment, supplies, or staff.
    • Offering gifts or tokens of appreciation that could be perceived as a reward for referrals.
    • Giving practice subsidies or covering expenses that are not otherwise required.
    • Free or discounted office space or supplies.
    • Gifts, meals, or tickets to events.
  • Compensation based on referral volume or status:
    • Offering payments or bonuses that are based on the number of patients a provider refers to a particular plan or service.
    • Providing remuneration that is contingent on the health status or demographics of the patients referred.
  • Exploiting "safe harbors":
    • Structuring arrangements that appear to be compliant (e.g., professional courtesy programs or recruitment benefits) but have the primary purpose of inducing referrals.

Safe Harbor Considerations

Safe harbors are specific, pre-approved exceptions to the AKS that provide immunity from prosecution if followed precisely. They are voluntary, and not all financial arrangements have a safe harbor. An arrangement must meet all conditions of a specific safe harbor to be protected; partial compliance is not enough.

To be protected by a safe harbor, an arrangement must fit squarely in the safe harbor and satisfy all of its requirements. Some safe harbors address personal services and rental agreements, investments in ambulatory surgical centers, and payments to bona fide employees.

Congress set forth a number of factors to consider when developing safe harbors; while not binding with respect to any assessment of an arrangement that implicates the Federal anti-kickback statute (other than in the establishment or modification of safe harbors (see section 1128D(a)(2) of the Act, 42 U.S.C. 1320a–7d(a)(2)), they are instructive for assessing risk under the Federal anti-kickback statute.

For example, OIG’s advisory opinions frequently consider factors such as overutilization, increased costs to Federal health care programs, corruption of medical decision making, patient steering, and unfair competition.

One of OIG’s Compliance Program Guidance documents reiterates these factors by highlighting the following questions to help guide an assessment of any problematic arrangements or practices identified as a red flag:

  • Does the arrangement or practice have the potential to interfere with, or skew, clinical decision making?
  • Does the arrangement or practice have the potential to increase costs to Federal health care programs or beneficiaries?
  • Does the arrangement or practice have the potential to increase the risk of overutilization or inappropriate utilization?
  • Does the arrangement or practice raise patient safety or quality of care concerns?
  • Does the arrangement or practice raise concerns related to steering patients or providers to a particular item or service?

The health care community and its partners must be mindful of these types of factors and question arrangements that implicate the Federal anti-kickback statute. An affirmative answer to one or more of these questions is a red flag signaling an arrangement or practice may be particularly susceptible to the harm caused by fraud and abuse.

AKS Audit Checklist

To audit for Anti-Kickback Statute (AKS) violations, create a comprehensive inventory of financial relationships, assess existing contracts against AKS safe harbors, conduct internal reviews of transactions and billing, and implement a robust compliance program that includes regular monitoring and staff training. Key steps include analyzing payments to ensure they are for fair market value, are not tied to referrals, and that arrangements are documented properly with signed agreements and legal review.

  • Build an inventory of all financial relationships 
    • List all transactions -
      • Document all financial relationships and transactions with potential AKS implications, including those with physicians, vendors, and other healthcare entities.
    • Categorize relationships –
      • Group arrangements by type, such as physician recruitment, medical directorships, lease agreements, and professional service agreements.
    • Work with legal counsel –
      • Involve legal counsel to ensure no relevant relationships with government health care programs are missed.
  • Review and assess existing arrangements 
    • Check against safe harbors –
      • Compare each financial arrangement against the requirements of relevant AKS safe harbors. For example, safe harbor requirements often include a written agreement, specifies the services, is for at least one year, and compensation is at fair market value and not tied to the volume or value of referrals.
    • Verify compensation –
      • Ensure compensation is set in advance and is not changed retroactively, especially within the first year of a new contract. Compensation should not be based on referrals or revenue generated from referrals.
    • Examine billing practices –
      • Review billing and payment practices to confirm they align with contractual terms and are at fair market value.
  • Conduct data analysis and transaction-level audits 
    • Obtain relevant data –
      • Gather data from general ledgers, vendor files, payroll, and payment records.
    • Select a sample –
      • Randomly select a sample of payments for a detailed audit.
    • Validate transactions –
      • Cross-reference payments against supporting documentation, such as invoices, timesheets, and contracts.
    • Use data analytics –
      • Employ data analytics to identify patterns and trends that might indicate improper conduct. This is an area where implementing Artificial Intelligence programs can provide speed and accuracy.
  • Audit Results Can Strengthen the Compliance Program 
    • Implement policies –
      • Audit results can help the Compliance Department establish written policies and procedures for compliance with the AKS.
    • Provide training –
      • Regularly train staff and key stakeholders on the AKS and how to identify and report potential violations. This includes discussion with all providers during on-boarding and at least annually as part of compliance training.
    • Ensure due diligence –
      • Conduct due diligence on new and existing business partners and perform background checks, such as checking the OIG's exclusion list.
    • Monitor and report –
      • Create a system for ongoing monitoring and auditing and establish a confidential way for employees to report suspected violations.

Conclusion

Audits proactively uncover compliance gaps and vulnerabilities before they become a problem, allowing for corrective action to be taken.

Auditing for AKS (Anti-Kickback Statute) compliance is crucial for mitigating risk because it identifies and addresses vulnerabilities that could lead to severe legal penalties, financial fines, and reputational damage. Regular audits help ensure adherence to laws and regulations, protect company assets, and maintain the trust of stakeholders by demonstrating a commitment to ethical practices.

Monitoring for AKS violations helps to prove a commitment to ethical and legal conduct. These types of audits help maintain a positive brand image and public trust.

Remember, regular auditing fosters a company-wide culture of accountability and continuous improvement, where employees are more aware of and committed to compliance requirements.

About the AIHC Education Department

The American Institute of Healthcare Compliance (AIHC) Education Department provides classroom and web-based training and certification for healthcare administrators and professionals. It includes an enrollment department that processes registrations, and a research and development arm focused on creating new educational products. Learn more about short course and certification offerings in addition to free and low-priced Continuing Education Unit (CEU) certification renewal single short courses or CEU packages. Visit our website https://dev-main.aihc-assn.org/

References

  • Centers for Medicare and Medicaid Services - WPS Government Services on Waivers of Deductibles and Co-Insurance
  • Department of Justice Enforcement Activities
  • Office of Inspector General Fraud & Abuse Laws, Physician Roadmap
  • American Institute of Healthcare Compliance, Healthcare Compliance certification program

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

What Government Enforcement Can Teach Us About Coding and Reimbursement

Written By: CJ Wolf, MD 

This article presents educational information related to compliant documentation, coding and billing to avoid fraud, waste and abuse in our healthcare system. Dr. Wolf makes his point by presenting a qui tam case related to vascular diagnostic testing.

Medical coding is a critical aspect of accurate reimbursement for a variety of medical services. Many healthcare compliance enforcement actions, especially those brought under the Federal False Claims Act (FCA), stem from allegations of inaccurate coding.

Healthcare compliance professionals can learn a great deal from diving deep into the details of various enforcement actions. As it relates to medical coding, some enforcement actions teach compliance and coding professionals a great deal of how inaccurate coding can lead to significant investigations and multi-million-dollar settlements.

The details behind a recent $37 million settlement between the U.S. government and a medical device company, along with their former distributor, inform coders and compliance professionals about the risks of inaccurate coding related to a common medical condition known as peripheral arterial disease (PAD)1.

PAD in the lower extremities is the result of narrowing or blockage of the arteries carrying blood with oxygen to the legs. A common symptom for patients with PAD is leg pain when walking. This type of pain is frequently referred to as claudication. Physicians use their clinical knowledge, experience and certain tests to diagnosis PAD and its varying degrees of severity.

One of the most common diagnostic tests utilized by physicians to evaluate PAD is the ankle brachial index (ABI). The test can help estimate the severity of the blockage, which is important when planning treatment and management options. Medicare has coverage policies and requirements for tests that can measure blood circulation in situations such as PAD. The critical policy that played a major role in this multi-million-dollar settlement is Medicare’s National Coverage Determination (NCD) 20.14 on plethysmography.  Plethysmography involves the measurement and recording (by one of several methods) of changes in the size of a body part as modified by the circulation of blood in that part.

In addition, the definitions of certain Current Procedural Terminology (CPT®) codes, 93922, 92923, or 93924 must be accurately met to submit these codes on claims to Medicare for reimbursement of these diagnostic tests. The medical codes require that a provider conduct an ABI test plus certain additional testing. In addition, Medicare does not cover noninvasive vascular tests that use photoelectric plethysmography, also known as photoplethysmography (PPG), which uses a light sensor to detect changes in blood volume.

For example, the Medicare NCD classifies the types of technology used for the testing that is covered compared to those not covered. The covered and non-covered procedures from the NCD are listed below:

Covered

  • Segmental Plethysmography
  • Electrical Impedance Plethysmography
  • Ultrasonic Measurement of Blood Flow (Doppler)
  • Oculoplethysmography
  • Strain Gauge Plethysmography

Non-covered (Medicare considers these experimental)

  • Inductance Plethysmography
  • Capacitance Plethysmography
  • Mechanical Oscillometry
  • Photoelectric Plethysmography

Two experts in vascular diagnostic testing filed a qui tam, or whistleblower, lawsuit under the False Claims Act. They alleged the companies were marketing their devices to providers, such as physicians, telling them their testing device could be reimbursed by Medicare even though the procedure used is PPG, which is a non-covered classification as described in Medicare’s NCD. The government intervened in the case and joined in alleging that the medical codes submitted on claims to Medicare were inaccurate, thus the companies caused providers to submit false claims.

According to the legal complaint filed with the courts, the whistleblowers stated that the device manufacturer and their distributor promoted use of their PPG devices as easier, quicker, and less expensive than the use of Doppler technology for diagnosing PAD. They also claimed the companies said Medicare (and other government payers) pay out the same amount for any service that fits within a specific CPT code, irrespective of the actual cost to a medical provider to provide the service. Medical providers are consequently incentivized to perform the most inexpensive and least time-consuming services that qualify for a specific CPT code. Because the company claimed these PPG products are much less expensive and faster than the traditional diagnostic tests the devices can "diagnose" PAD within as little as five minutes, while traditional diagnostic tests take approximately 30-45 minutes.

The legal complaint also included materials about how the companies marketed the devices to providers.

The whistleblowers claimed:

  • The companies marketed one of their devices as a "new reimbursable office diagnostic test you can perform quickly and easily with no capital equipment purchase and no specialized personnel."
  • A physician gave a presentation at the New Cardiovascular Horizons (NCVH) conference and promoted the device as a method to help "increase your daily practice revenue." The presentation addresses the CPT codes that can purportedly be used to bill Medicare for services using the device and lists CPT codes 93922 and 93923.

Lessons Compliance Professionals Can Learn

Compliance professionals working for hospitals or physicians can learn a great deal from these details, such as:

  • First, compliance professionals should ensure the accuracy of any coding and reimbursement advice coming from device and/or pharmaceutical manufacturers.
  • Second, diligently review and follow Medicare and Medicaid coverage policies.
  • Third, go beyond just reading a medical code’s definition. Review enforcement settlements, audits, and authoritative references for the proper and intended use of medical codes.

This is just one of many enforcement actions that healthcare compliance professionals should be conversant about if they perform services for the common condition of PAD.

About the Author

CJ Wolf, MD, CPC, CPB, COC, AAPC Approved Instructor, is a highly regarded healthcare professional with more than 25 years of experience in revenue cycle management, practice management, compliance, coding, billing, auditing, and client services. He is a nationally recognized compliance thought leader who has published numerous articles and resources and has been featured at national conferences and events. He is a subject matter expert with Healthicity, a leading provider of compliance and auditing software solutions at https://www.healthicity.com

References:

  1. https://www.justice.gov/opa/pr/semler-scientific-inc-and-bard-peripheral-vascular-inc-pay-nearly-37m-resolve-false-claims
  2. https://www.cms.gov/medicare-coverage-database/view/ncd.aspx?NCDId=165&NCDver=1

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 2: Interoperability and System Fragmentation in Healthcare

Communication, Compliance, and Strategies for Successful Integration Written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The healthcare industry continues to face significant fragmentation, as disparate systems and siloed data limit effective care coordination. Interoperability standards such as Fast Healthcare Interoperability Resources (FHIR) and regulatory requirements under the 21st Century Cures Act, HIPAA, and CMS interoperability mandates are reshaping the compliance landscape. Yet achieving interoperability is not only a technical challenge but also a communication and compliance imperative.

This article examines the compliance risks associated with fragmentation and explores communication strategies for healthcare leaders. Key areas include:

  1. educating internal teams on compliance-related adoption of FHIR standards;
  2. framing Health Information Exchanges (HIEs) and cloud-based platforms as compliance safeguards against information blocking and OCR investigations; and
  3. aligning staff expectations, training, and accountability during technology rollouts.

A compliance lens reinforces that interoperability is not optional—it is a regulatory obligation tied to patient rights, organizational risk management, and quality of care.

Introduction

Fragmentation in healthcare undermines not only care delivery but also compliance. When disparate systems fail to exchange data, organizations risk violating federal mandates related to patient access, privacy, and data sharing. The 21st Century Cures Act Final Rule requires organizations to provide patients with immediate electronic access to their records, while HIPAA’s Right of Access standard reinforces patients’ legal rights to their health information. Failure to comply may trigger Office for Civil Rights (OCR) investigations, penalties, or settlements (Office for Civil Rights [OCR], 2022).

Improved interoperability through standards like FHIR, Health Information Exchanges (HIEs), and cloud-based systems offers an opportunity to reduce compliance risk and strengthen organizational integrity. However, success depends on how effectively compliance leaders communicate changes, engage stakeholders, and align workflows with regulatory requirements.

The Compliance Risks of Fragmentation

System fragmentation is not merely an operational inconvenience—it directly impacts compliance.

Examples include:

  • HIPAA Violations: Incomplete or inaccessible patient records increase the likelihood of Privacy and Security Rule breaches.
  • Information Blocking: Under the ONC Cures Act Final Rule, organizations that delay or restrict information exchange risk penalties (ONC, 2020).
  • Claims and Billing Errors: Disconnected systems make it harder to validate documentation, increasing false claims liability.
  • Audit Vulnerability: Fragmented workflows create inconsistent documentation trails, raising red flags during audits.

From a compliance standpoint, breaking down silos is both a regulatory necessity and a risk management strategy.

Communicating FHIR Adoption Through a Compliance Lens

FHIR APIs are central to the ONC’s interoperability framework, enabling standardized, patient-directed data sharing. For compliance teams, communicating FHIR adoption requires balancing technical education with regulatory framing.

Compliance challenges:

  • Misunderstanding FHIR as a 'technology upgrade' instead of a compliance requirement.
  • Lack of clarity on how FHIR supports HIPAA Right of Access and ONC information blocking provisions.
  • Resistance from staff unfamiliar with regulatory consequences of noncompliance.

Communication strategies:

  • Regulatory Framing: Position FHIR adoption as a compliance mandate tied to federal law, not optional IT innovation.
  • Policy Alignment: Provide updated compliance policies showing how FHIR workflows safeguard patient rights.
  • Cross-Functional Briefings: Engage compliance, IT, and clinical teams together to prevent siloed communication.

By making compliance central to the conversation, staff understand that interoperability is not just about efficiency—it is about avoiding penalties and protecting patient trust.

Cloud-Based Platforms and HIEs: Compliance Safeguards, Not Just Technology

Cloud platforms and HIEs expand data access across organizational boundaries. From a compliance perspective, these tools mitigate risks of information blocking and improve adherence to patient access laws.

Compliance benefits:

  • Audit Readiness: Centralized data improves traceability for regulatory reviews.
  • HIPAA Safeguards: Cloud vendors increasingly offer compliance-certified environments with robust encryption and BAAs (business associate agreements).
  • Patient-Centered Compliance: HIEs reduce delays in record sharing, directly supporting Right of Access standards.

Communication priorities:

  • Stress that cloud and HIE adoption is not only about efficiency, but also about reducing exposure to OCR penalties.
  • Clarify shared accountability between providers, payers, and vendors for maintaining compliance safeguards.
  • Use compliance case studies (e.g., OCR enforcement actions) to illustrate the risks of fragmented systems.

Framing cloud and HIE adoption as compliance risk mitigation ensures leadership buy-in and reduces resistance to sharing data.

Managing Staff Expectations and Training During Rollouts

System-wide rollouts require a compliance-centered training approach. Staff must not only learn technical workflows but also understand the compliance stakes tied to their responsibilities.

Compliance-driven communication strategies include:

  1. Mandatory Training: Incorporating interoperability requirements into annual compliance training to emphasize regulatory obligations.
  2. Expectation Management: Clearly communicating that delays or barriers in sharing data could constitute information blocking.
  3. Super-User Networks: Assigning compliance-trained 'champions' to monitor adherence to workflows and escalate issues.
  4. Policy Updates: Linking rollout communication to policy changes in HIPAA access, data governance, and security protocols.

When staff view interoperability as part of their compliance role—not just an IT task—they are more likely to integrate it into daily practice.

Discussion - The intersection of interoperability and compliance is where organizational risk management, patient rights, and clinical efficiency converge. Communication breakdowns perpetuate system fragmentation, which can escalate into compliance violations. Conversely, transparent communication strategies—emphasizing regulation, patient safety, and organizational accountability—align stakeholders and promote sustainable interoperability.

Compliance leaders serve as translators between regulators, IT professionals, and clinicians. Their role is not only to enforce standards but also to ensure that staff understand why interoperability matters: to safeguard patients, maintain regulatory standing, and strengthen organizational trust.

Conclusion

Fragmentation is more than a technological problem; it is a compliance vulnerability. Interoperability initiatives such as FHIR adoption, HIE participation, and cloud migration reduce fragmentation but require strong communication strategies to succeed. From a compliance lens, effective communication ensures that staff recognize interoperability as a regulatory requirement, not an optional upgrade.

Ultimately, interoperability is a cornerstone of healthcare compliance and patient rights. By embedding compliance in communication, training, and strategy, organizations can break down data silos, mitigate risk, and deliver safer, more coordinated care.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • Adler-Milstein, J., Holmgren, A. J., & Kralovic, P. (2021). The impact of electronic health record interoperability on care quality and patient safety. Health Affairs, 40(9), 1427–1435. https://doi.org/10.1377/hlthaff.2021.00234
  • Cresswell, K., & Sheikh, A. (2017). Organizational issues in the implementation and adoption of health information technology innovations: An interpretive review. International Journal of Medical Informatics, 100, 63–76. https://doi.org/10.1016/j.ijmedinf.2017.01.001
  • Lin, S. C., Jha, A. K., & Adler-Milstein, J. (2020). Electronic health records and health care quality: Current evidence and future directions. Annual Review of Medicine, 71, 35–50. https://doi.org/10.1146/annurev-med-052218-020647
  • Mandel, J. C., Kreda, D. A., Mandl, K. D., Kohane, I. S., & Ramoni, R. B. (2016). SMART on FHIR: A standards-based, interoperable apps platform for electronic health records. Journal of the American Medical Informatics Association, 23(5), 899–908. https://doi.org/10.1093/jamia/ocv189
  • Office for Civil Rights (OCR). (2022). Enforcement highlights: Right of Access Initiative. U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html
  • Office of the National Coordinator for Health Information Technology (ONC). (2020). 21st Century Cures Act: Interoperability, information blocking, and the ONC Health IT Certification Program final rule. Federal Register, 85(85), 25642–25961.
  • Vest, J. R., Ancker, J. S., & Bates, D. W. (2019). Health information exchange: Persistent challenges and new strategies. Journal of the American Medical Informatics Association, 26(4), 325–331. https://doi.org/10.1093/jamia/ocy135

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 1: CMS Interoperability Framework Project: Should We Be Concerned?

Part 1: The Problem with System Fragmentation in Healthcare and Security Concerns 

Co-authored by Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 


The CMS Interoperability Framework is a call to action for health data networks that want to make what should already work actually work—by voluntarily meeting the CMS Interoperability Framework criteria to be designated as a CMS-Aligned Network.

This is a voluntary blueprint for modern health data exchange that puts patients and providers first. It is open, standards-based, and market-friendly so that the industry can stop theoretical debates and start delivering real results. CMS is offering shared infrastructure and clearly defined criteria for 2026.

The CMS Interoperability Framework doesn't mean centralizing all medical record data in a single location in the US. CMS is aligning networks to allow different types of health data sources, including health information networks, exchanges and other health technology platforms, to align with CMS goals for interoperability. The focus is on making it easier for different healthcare systems and applications to share and exchange medical information securely and efficiently. Here's what that means in simpler terms:

Think of it like different computer programs speaking the same language.

Currently, many healthcare systems use different formats and ways of organizing data. The CMS Interoperability Framework aims to establish common standards, especially using FHIR APIs, so that systems can understand and exchange information smoothly, regardless of where the data is stored.

  • A FHIR (Fast Healthcare Interoperability Resources) API is a standardized interface for exchanging health information between different healthcare systems using modern, web-based principles.
  • It acts as a shared "menu" that allows different software applications and platforms to "speak the same language," enabling them to request, retrieve, and share data like patient records, lab results, and other administrative or clinical information in a consistent format (JSON or XML).

It empowers patients and providers with access to medical information.

  • The framework promotes patient access to their health records through apps of their choice and makes it easier for providers to access the full patient history at the point of care.

It's a roadmap and a call to action, not a central database.

  • CMS is encouraging healthcare organizations, including networks, EHR systems, providers, and payers, to adopt common standards for data exchange, improving overall data sharing across the fragmented healthcare landscape.

It emphasizes data availability and standards, but it doesn't create a national repository.

  • The focus is on making it easier to share data between existing systems and promoting the use of standards like FHIR APIs and USCDI (United States Core Data for Interoperability).

So, instead of physically pulling all medical records into one place, the CMS Interoperability Framework is about creating a more connected system that allows patient data to flow securely between different locations and organizations, ultimately benefiting patient care and efficiency.

CMS Interoperability and the Risks of Sharing Patient Data with Big Tech Companies

The Centers for Medicare & Medicaid Services (CMS) has launched an ambitious Health Technology Ecosystem initiative aimed at creating a public-private partnership that facilitates seamless data exchange among patients, providers, and payers. As stated on the CMS website, Making Health Tech Great Again is a bold step toward modernizing our digital health ecosystem.

While details and operational aspects are still being finalized, partnerships have been publicly announced with major tech companies like Amazon, Apple, Google, Microsoft AI, OpenAI, and others, which signal a transformative shift in how healthcare data is accessed and shared. On July 30, 2025 CMS.gov posted a Press Release White House, Tech Leaders Commit to Create Patient-Centric Healthcare Ecosystem which states “More than 60 companies pledged to work collaboratively to deliver results for the American people in the first quarter of 2026. Twenty-one networks pledged to meet the CMS Interoperability Framework criteria to become CMS Aligned Networks. Eleven health systems or providers committed to participate and support patient use, and seven EHRs committed to facilitate data exchange and help “kill the clipboard.” At the same time, these collaborations also raise critical questions about data privacy, security, and governance.

Should we be concerned?

The CMS Health Tech Ecosystem initiative is overseen by the CMS Senior Advisor for Technology and supported by senior officials at the Department of Health and Human Services (HHS). Its mission is to promote a secure patient-centered digital healthcare system that would allow for ease of distribution, exchange, portability, and use of electronic health information. Fundamentally, this initiative seeks to improve patient access and enhance the efficiency of the healthcare industry. Its aim is to connect healthcare data sets that are currently siloed across disparate systems so that patients, providers, and healthcare payers will have reliable access to electronic medical records through a voluntary alignment. However, what lessons can be learned from the Change Healthcare breach?

Security Risks and Lessons Learned from the Change Healthcare Breach

A significant reminder of the vulnerabilities in extensive healthcare data systems is the February 2024 ransomware attack on Change Healthcare. Threat actors exploited the business associate’s lack of multifactor authentication, gaining unauthorized remote access via stolen credentials. Insufficient third-party vendor security postures create both upstream and downstream vulnerabilities across the healthcare ecosystem.

In the Change Healthcare breach, inadequate security controls resulted in widespread disruptions, including delays in medical treatments and prescriptions, stalled claims processing and reimbursements, and fragmented financial and operational access and delivery. These events underscore the need for comprehensive data governance, continuous security monitoring, and resilient infrastructure to safeguard protected health information (PHI). Most importantly, the lessons learned highlight the criticality of data confidentiality, integrity, and availability to ensure trust and continuity in patient care.

Along those lines, it is meaningful to act as informed advocates and to engage in mission-aligned questions, such as:

  • What minimum security standards must CMS’s third-party vendors and data brokers meet to safeguard data protection?
  • How is patient transparency ensured, and how is informed consent managed across diverse platforms?
  • Who holds accountability for data misuse or breaches, and what oversight mechanisms are in place to ensure compliance?

Conclusion

CMS's initiative for a more connected and patient-centered healthcare system offers significant benefits. But the public/private voluntary alignment must be grounded in data governance, responsible management of sensitive information, and a foundation of trust, transparency, and robust security—particularly in an innovative landscape shaped by public/private partnerships.

Please watch for Part 2: Interoperability and System Fragmentation in Healthcare: Communication, Compliance, and Strategies for Successful Integration, written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE.

About the Authors

Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC, is a member of the AIHC Volunteer Education Committee. Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS, is the Chief Executive Officer at the American Institute of Healthcare Compliance.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More