Quality
Auditing, Corporate Compliance, Quality

The Cost of an Unchecked Policy

WHEN POLICY MEETS PRACTICE | A TWO-PART SERIES

How quality assurance and quality improvement audits keep policies alive and patients safe

Written by Robert Colon-Torres   

Every health system has policies. Far fewer can prove those policies are followed, or that they work. That gap is where preventable harm, financial penalties, and legal exposure live.

In nearly 25 years of healthcare compliance work, I have rarely investigated an adverse event where no policy existed. Far more often, the policy was there. It had been approved, posted, and acknowledged in an annual training. It simply was not what happened on the floor, and no one had checked.

This is the first of a two-part series on that gap between the policies health systems write and the care they actually deliver. My argument across both parts is straightforward: quality assurance (QA) and quality improvement (QI) audits are what turn a policy from a document into a practice, and compliance and CQI must operate as one team to make that happen. Part 1 examines what is at stake when the gap goes unchecked: for patients, for the organization's finances, and in front of regulators and courts. Part 2 explains why the gap opens and how to close it.

Harm is common, and much of it is preventable

The Institute of Medicine's To Err Is Human (1999) estimated that up to 98,000 hospitalized Americans die each year from preventable error.[1] Later estimates ranged far higher, including the widely cited 2016 claim that medical error is the third leading cause of death in the U.S.[2] Those higher figures have been sharply criticized on methodological grounds, and a 2020 meta-analysis put preventable inpatient deaths closer to 22,000 a year.[3][4] Compliance professionals should resist the temptation to lead with the most dramatic number; our credibility depends on precision.

But the debate over mortality obscures a point on which the evidence is consistent: harm itself is common. The HHS Office of Inspector General found that one in four hospitalized Medicare patients experienced harm, and that 43 percent of those events were preventable.[5] A 2023 New England Journal of Medicine study of eleven Massachusetts hospitals found adverse events in nearly one in four admissions, about a quarter of them preventable.[6] More than two decades after To Err Is Human, the problem has not been solved. In most of these cases, the evidence-based practice that would have prevented harm was already known.

Where policy and practice drift apart

Bar code medication administration (BCMA) shows how the drift happens. BCMA was designed to stop wrong-patient and wrong-dose errors, yet researchers documented fifteen distinct workarounds, including spare wristbands taped to carts and door frames, multiple patients' medications carried on one tray, and medications given first and scanned later.[7] None of this was sabotage. Each workaround was a rational response to workload, equipment placement, or a process that did not fit the real work.

Left alone, workarounds become what sociologist Diane Vaughan called the normalization of deviance: each shortcut that does not immediately cause harm makes the next one feel acceptable, until the unofficial procedure has replaced the official one.[8] By the time an adverse event exposes the gap, the deviation may have been routine for years. An audit is the only reliable way to see it sooner. A workaround is not just a staff behavior to correct; it is data showing exactly where the policy and the work have come apart.

Regulators now ask whether your program works

The compliance standard has shifted from “Do you have a policy?” to “Can you show that it works?” The HHS-OIG General Compliance Program Guidance (2023) treats auditing and monitoring as a core element of an effective program and expressly identifies quality and patient safety as compliance risks that boards should oversee.[9] The Department of Justice's Evaluation of Corporate Compliance Programs (updated 2024) asks prosecutors to judge not only whether a program is well designed, but whether it “works in practice,” including whether the organization tests its controls and learns from what it finds.[10]

The financial incentives point the same way. Since 2008, Medicare has declined to pay the added cost of certain hospital-acquired conditions, and the HAC Reduction Program reduces payments by one percent for the worst-performing quarter of hospitals.[11] Measurable medical errors were estimated to cost the U.S. economy $17.1 billion in a single year.[12] An unaudited policy is not a neutral gap. It is unpriced financial risk.

Your policies will be read in court

Courts in many states allow a health system's own policies to be admitted as evidence of the standard of care.[13] In Jutzi v. County of Los Angeles (1987), a county policy authorizing emergency physicians to treat orthopedic injuries helped establish that the hospital had met its standard of care.[14] In Heastie v. Roberts (2007), where a restrained patient was burned after the hospital's own contraband-search policy was not followed, the Illinois Supreme Court held that internal policies may be considered by the jury as evidence bearing on the standard of care, while a violation alone does not automatically establish negligence.[15]

The lesson for compliance is that a followed policy can protect you, and an unfollowed one can hurt you, sometimes more than having no policy at all. The only way to know which kind you have is to audit it.

A system problem, not a staff problem

When harm occurs, the instinct is to find the person who made the mistake. A just culture approach asks a better question: what in the system made the error likely?[16] Individuals remain accountable for reckless choices, but most errors and workarounds are system signals. Blaming the individual closes the file and leaves the conditions in place for the next event. QA and QI audits are how an organization turns systems thinking from a slogan into a practice.

About the Author

Robert Colon-Torres is a healthcare compliance executive with roughly 25 years of experience, most recently as a chief compliance officer for federally qualified health centers in California. He holds a degree in health law from Loyola University Chicago.


References

  1. Kohn LT, Corrigan JM, Donaldson MS, eds. To Err Is Human: Building a Safer Health System. Institute of Medicine; 2000.
  2. Makary MA, Daniel M. Medical error: the third leading cause of death in the US. BMJ. 2016;353:i2139.
  3. Shojania KG, Dixon-Woods M. Estimating deaths due to medical error: the ongoing controversy and why it matters. BMJ Qual Saf. 2017;26(5):423–428.
  4. Rodwin BA, et al. Rate of preventable mortality in hospitalized patients: a systematic review and meta-analysis. J Gen Intern Med. 2020;35(7):2099–2106.
  5. HHS Office of Inspector General. Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (OEI-06-18-00400). 2022.
  6. Bates DW, et al. The safety of inpatient health care. N Engl J Med. 2023;388(2):142–153.
  7. Koppel R, et al. Workarounds to barcode medication administration systems. J Am Med Inform Assoc. 2008;15(4):408–423.
  8. Banja J. The normalization of deviance in healthcare delivery. Bus Horiz. 2010;53(2):139–148.
  9. HHS Office of Inspector General. General Compliance Program Guidance. November 2023.
  10. U.S. Department of Justice, Criminal Division. Evaluation of Corporate Compliance Programs. Updated September 2024.
  11. Centers for Medicare & Medicaid Services. Hospital-Acquired Condition Reduction Program.
  12. Van Den Bos J, et al. The $17.1 billion problem: the annual cost of measurable medical errors. Health Aff. 2011;30(4):596–603.
  13. Bal BS. An introduction to medical malpractice in the United States. Clin Orthop Relat Res. 2009;467(2):339–347.
  14. Jutzi v. County of Los Angeles, 196 Cal. App. 3d 637 (1987).
  15. Heastie v. Roberts, 226 Ill. 2d 515 (2007).
  16. Marx D. Patient Safety and the “Just Culture”: A Primer for Health Care Executives. Columbia University; 2001.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Compliance in Healthcare
Corporate Compliance

OIG’s Focus on Nursing Home Engagement of Medical Directors

Written by Kirsten Taylor-Billups, JD, RN, CHC 

The Nursing Facility Industry Specific Compliance Guidance was published by the Office of Inspector General (OIG) in November 2024 as the first industry-specific guidance since the November 2023 updated general compliance guidance was published. Improving the quality of care and safety of residents within nursing facilities is a top priority for OIG. This educational article is provided for educational purposes only and is not intended as legal or consulting advice.

In June 2025, the OIG workplan was updated to include the Monitoring and Engagement of Medical Directors in Nursing Homes and CMS will begin conducting their reviews in 2026. The scope of the OIG’s focus will be in three areas:

  1. the extent in which medical directors performed required duties in nursing homes,
  2. the extent in which pay-rolled based journal data on medical director’s hours are accurate and useful for oversight, and
  3. opportunities to improve oversight and transparency of nursing homes engagement and funding of medical directors through existing data or other monitoring mechanisms.

Given the up-and-coming medical director reviews by CMS this article will review the regulatory requirements for medical directors in nursing homes, the barriers nursing homes have faced when implementing the regulations and proactive takeaways to consider when analyzing your medical director’s arrangements and the documentation required to quantify the effectiveness of medical director services.

The governing regulations on medical directors in nursing homes we will be reviewing is United States Code of Federal Regulations Title 42 Public Health Chapter IV CMS Part 483-Requirements for States and Long-Term Care (LTC) Facilities section 483.75 Administration. The Administration section requires LTC facilities to be administered in a manner that enables it to use its resources effectively and efficiently to attain or maintain the highest practicable, physical, mental, and psychosocial well-being of each resident. The requirements for medical directors are listed under section 42 CFR 483.75 (i) which indicates the facility must designate a physician to serve as a medical director who will be responsible for implementing resident care policies and coordination of medical care in the nursing facility. The intention of this regulation is to not only provide medical care in the facility but to also provide clinical guidance and clinical oversight on the implementation of resident policies and procedures to help with promoting quality of care and services to nursing homes residents.

The development, implementation and evaluation of resident care policies and procedures must be based on current evidence-based standards of practice and resolve medical and clinical concerns that affect residents’ quality of care and services. This is achieved when the medical director collaborates with the facility leadership (Administrator/ Director of Nursing/ Clinical Staff), attending physicians, physician extenders (nurse practitioners/ physician assistants), and consultants.

Documentation is key - The facility documentation which demonstrates the medical director’s level of involvement will need to be evident within the nursing homes facility assessments and quality assurance and performance improvement meetings. The medical director should be actively involved in the facility assessment process and not just be listed as a participant.

  • The facility documentation should show the medical director’s input in evaluating resident needs, staffing and resources.
  • Document the medical director’s attendance and contributions in meetings updating the facility assessment, during quality assurance and performance improvement (QAPI) meetings, policy reviews, and administrative decisions with the facility leadership team.
  • Record instances where the director intervenes in clinical care such as reviewing diagnoses, prescribing practices, or addressing issues with attending physicians.
  • Documentation should also show that the medical directors’ interventions are based upon current standards of practice.

Despite CMS regulations on Medical Directorships within nursing homes, the OIG has also provided ongoing guidance to medical directors’ roles within nursing homes. Initially in 2000 OIG Compliance Program Guidance for Nursing Facilities, which historically emphasized the risks of physician arrangements and medical director contracts being in violation of Anti-Kickback Statute (AKS), Physician Self-Referral and Stark Laws. In 2008 the Supplemental OIG Compliance Program Guidance for nursing homes and medical directorship expanded to the need for these arrangements to have documentation to show the arrangement was fair market value, document the services being provided, and they’re not sham for resident referrals.

Recently in 2024 OIG Nursing Facility Industry Segment-Specific Compliance Guidance (ICPG), medical directors are explicitly considered a compliance risk when it comes to their contracts, services, and likelihood for kickbacks for referrals. OIG also has enhanced their focus on the clinical and administrative responsibilities of medical directors when it comes to resident care policies and procedures, and quality of care and services and the billing for the services.

In addition to regulatory and operational responsibilities, it is essential for nursing homes to ensure that medical director arrangements comply with federal laws governing physician compensation and referrals. Specifically, the medical director’s role and compensation must be carefully structured and monitored to avoid violations of the physician self-referral law (commonly known as the Stark Law), the Anti-Kickback Statute, and related federal regulations.

  • Stark Law: The Stark Law prohibits physicians from making referrals for certain designated health services payable by Medicare or Medicaid to entities with which they (or an immediate family member) have a financial relationship unless an exception applies. Medical director’s agreements must be in writing reflect fair market value for bona fide services provided and not be based on the volume or value of referrals.
  • Anti-Kickback Statute: This statute makes it illegal to knowingly and willfully offer, pay, solicit, or receive any remuneration to induce or reward referrals of items or services reimbursable by federal health care programs. Medical director’s compensation arrangements must not serve as an incentive for directing referrals to the facility.
  • Physician Self-Referral Law: Overlapping with the Stark Law, this law restricts physician referrals when there is a financial relationship with the facility, unless specific safe harbors or exceptions are met.

OIG and Department of Justice (DOJ) have aggressively pursued nursing homes and related entities for sham medical director arrangements that violated the Anti-Kickback Statute and False Claim Act.

Sham arrangements typically involve payments for referrals rather than bona fide administrative or clinical services, with little or no documentation of actual work performed. There have been several settlements involving sham medical director arrangements for not only nursing homes but for other healthcare entities such as hospitals, home care, and assisted living entities. Here are a few healthcare entities who were in violation and entered into settlement agreements with the DOJ.

  • Prema Thekkek, Paksn Inc., and Six California Skilled Nursing Facilities (2023) entered into a $45.6 million consent judgement with a 5-year Corporate Integrity Agreement (CIA) with HHS-OIG where the settlement resolved allegations of False Claims Act and Antikickback Statute violations from 2009-2021. The basis for the settlement was medical director contracts were not used to pay for legitimate administrative services but pay for patient referrals, physicians were paid monthly stipends ($1,500-$10,000) regardless of actual services provided, physicians hired based on promises of patient refers minimums were met and if the minimum referrals weren’t provided the physician was terminated and the nursing homes documentation requirements for the services provided were not enforced.
  • Village Home Care LLC, CEO and Two Doctors (2023) the collective settlement amount was about half a million dollars for allegedly violating the false claims act and anti-kickback statute. The alleged violations involved sham medical director and sublease agreements used to pay physician for patient referrals with no actual services or use of the subleased space.
  • Phillip Esformes/Esformes Nursing Home Network (2019) settlement for violation of AKS and Fraud that resulted in criminal charges and imprisonment. Alleged large-scale kickback scheme where physicians, marketers, and others (Medical directors and consultants) were paid to refer patients to Esformes skilled and assisted living facilities.

Common themes in OIG/DOJ “sham medical director” cases

Across these and similar nursing home cases, the government tends to focus on a fairly consistent pattern:

  • Little or no documented services: Medical director agreements exist on paper, but there are few agendas, minutes, work product, QAPI deliverables, or time records to back up the payments.
  • Compensation not tied to FMV or effort: Physicians receive flat monthly fees that don’t match any reasonable estimate of hours or complexity, or that are unusually high given the size/acuity of the facility.
  • Referral‑driven motive: Evidence (emails, internal comments, timing of contracts) suggests the purpose of the arrangement was to secure or retain admissions, certifications, or orders, not to obtain genuine medical director services.
  • Duplicative or vague roles: Multiple physicians hold overlapping “medical director” or “quality consultant” titles for the same facility or service lines without clear differentiation of duties.
  • Weak compliance oversight: Compliance is either not reviewing these arrangements or is ignored; there’s no systematic FMV analysis, conflict review, or monitoring of actual performance.

The 2024 Nursing Facility ICPG essentially solidified these concerns for SNFs and are calling out medical director arrangements are being typically used by facilities to disguise kickbacks. Therefore, nursing homes compliance teams are encouraged to rigorously scrutinize the medical director’s contracts for their scope of work, fair market value, and services with quantifiable documentation to support the arrangement.

  • For instance, develop a medical director checklist that can be utilized to determine the essential elements of every medical director contract to determine whether there’s documentation to support fair market value, the amount of hours monthly the medical director spends performing medical director tasks and how to track their hours so their time in the facility as an attending isn’t added to their medical director task and duties.
  • Confirm the medical director is getting compensated for their medical director contracted hours only and not receiving additional compensation or financial incentives (a majority of the assigned residents, below market goods and services, bonuses for patient referrals or not providing the required number of hours and duties as a medical director before receiving their monthly stipend).

In 2025-2026 OIG workplan CMS implemented the requirement that nursing homes report medical director hours in the Payroll Based Journal (PBJ) system whether the medical director is an employee or an independent contractor. PBJ work hours only applies to hours work onsite for medical director roles which means only report the hours the medical directors spend performing medical director duties physically onsite. Therefore, any remote or offsite medical director tasks such as consulting, chart or policy reviews or monitoring performed cannot be reported by the nursing home in PBJ. The PBJ reporting system doesn’t have a separate code for medical directors.

Code 17 - The PBJ code that will have to be used is code 17 for Physician/MD/DO and reports the hours worked in the facility only. So, if a medical director is paid a flat monthly stipend, the facility must determine the actual on site hours worked.

When to Report 0 - If the medical director doesn’t do any onsite medical director duty within a quarter the facility must report a “0” zero on PBJ.

Based upon CMS review of the PBJ system, only 36% of nursing homes have reported PBJ hours for their medical directors. Therefore, the OIG is actively evaluating whether medical directors are performing their duties, whether PBJ date on medical directors is accurate and how to improve transparency and oversight of the medical directors in nursing homes. So, nursing homes can expect to see increased scrutiny of PBJ and reported medical director hours, potential audits comparing medical director contracts, invoices, and PBJ submissions as well as tightening of CMS guidance.

Therefore, nursing home administration, compliance and legal teams should incorporate into their medical director arrangements the following:

  • Maintain detailed logs of onsite medical director time.
  • Ensure the contract specifies onsite expectations.
  • Align invoices with documented onsite hours.
  • Avoid reporting offsite administrative time.
  • Audit PBJ submissions quarterly for accuracy.

Conclusion and Key Takeaways

The upcoming OIG and CMS scrutiny of nursing home medical director arrangements underscore the critical need for compliance, transparency, and robust documentation. Nursing homes must ensure their medical director contracts are clearly defined, reflect fair market value, and are supported by thorough records of onsite services. Avoiding sham arrangements and ensuring adherence to federal laws such as the Stark Law and Anti-Kickback Statute are essential to mitigate legal risks.

Key takeaways include:

  • Maintain detailed, contemporaneous documentation of medical director activities, especially onsite work.
  • Ensure contracts specify the scope of responsibilities and compensation aligns with actual services rendered.
  • Regularly audit Payroll Based Journal (PBJ) submissions for accuracy and compliance, reporting only onsite medical director hours as required.
  • Separate medical director’s duties from other physician roles to avoid duplicative or vague arrangements.
  • Engage compliance and legal teams in ongoing monitoring and evaluation of medical director arrangements to address regulatory risks and prevent enforcement actions.

By proactively addressing these areas, nursing homes can better withstand regulatory review, foster quality resident care, and mitigate any costly enforcement actions for noncompliance with the regulations.

About the Author Kirsten Taylor-Billups, JD, RN, CHC

Blog Kirsten

Kirsten Taylor-Billups is the owner and operator of Legal Healthcare Consulting, with 35 years of experience in acute and post-acute care. She holds the qualifications of Registered Nurse (RN), Juris Doctorate Degree (JD), and Certification in Healthcare Compliance (CHC). Over her 30-year tenure in healthcare, Kirsten has undertaken various roles, including Director of Nursing, Quality Assurance Consultant, Risk Manager, and Corporate Compliance Officer at multi-facility healthcare organizations such as University Hospitals, HCR ManorCare, Common Spirit Health, and Catholic Healthcare Initiatives.

Legal Healthcare Consulting, founded by Kirsten 30 years ago, offers expert services to government contractors and acute and post-acute care facilities in capacities including Chief Compliance Officer, Risk Manager, Quality Assurance Consultant and Mediation services. Kirsten’s extensive expertise and experience are invaluable assets.

If your nursing facility needs assistance with auditing, monitoring, or implementing effective medical director arrangements email a request to Ktaylor7284@legalhealthcareconsulting.com

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

RCA is a Patient Safety Initiative and a Compliance Imperative

The Ripple Effect: Applying Root Cause Analysis and Other Tools to Strengthen Patient Safey and Compliance 

Written by: Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

Improving patient safety and maintaining regulatory compliance requires more than addressing isolated incidents, it demands systemic methods that reveal and correct underlying issues. Root Cause Analysis (RCA) and related tools such as the Fishbone Diagram, Five Whys, Failure Modes and Effects Analysis (FMEA), and Human Factors engineering provide structured approaches to uncover systemic weaknesses. When applied effectively the methods recreate ripple effects that extend beyond resolving individual events to strengthening organizational culture, reducing liability, and promoting continuous learning. This article examines the processes and tools available for healthcare organizations, highlights evidence-based outcomes, and provides best practices for healthcare leaders seeking to transform patient safety and compliance through actionable, system-level improvements. 

Introduction

Healthcare organizations continually face pressure to provide safe, high-quality care while meeting regulatory and accreditation requirements. Despite advances in technology and clinical practice, medical errors and adverse events remain persistent challenges. The Joint Commission, the Centers for Medicare & Medicaid Services (CMS), and patient safety organizations consistently highlight the importance of systematic approaches to error prevention.  Root Cause Analysis (RCA) is one such approach.

RCA is defined as a structured method used to identify the underlying factors that contribute to errors or adverse events, with the goal of preventing recurrence. Unlike surface-level corrective actions that may only address symptoms, RCA examines deeper causes—whether they stem from human factors, organizational systems, or external pressures.

For healthcare compliance leaders, RCA provides not only a mechanism to resolve immediate issues but also a pathway to improve overall governance, reduce liability, and build a culture of safety.

Understanding Root Cause Analysis

RCA is widely recognized as a post-event analysis method designed to uncover systemic flaws. In healthcare, RCA is typically conducted after sentinel events, near misses, or other significant incidents. The Agency for Healthcare Research and Quality (AHRQ) emphasizes that RCA should shift focus from individual blame to systemic improvement, acknowledging that most errors are products of multiple contributing factors rather than a single failure.

While Failure Modes and Effects Analysis (FMEA) is proactive, RCA is reactive.

  • FMEA anticipates potential points of failure before they occur, while RCA investigates why an error has already happened. RCA is also distinct from corrective and preventive action (CAPA) systems because it emphasizes systemic causes rather than isolated fixes.

Healthcare organizations are required or strongly encouraged to use RCA following sentinel events. The Joint Commission mandates RCA for accredited facilities in these situations, underscoring its role as a compliance and accreditation tool.

Effective Root Cause Analysis relies not only on process but also on the right tools to guide deeper understanding. Several proven techniques help healthcare teams systematically uncover contributing and root causes:

  • Fishbone Diagram (Ishikawa) – A visual mapping tool that categorizes potential causes into 'bones' of a fish (such as people, processes, equipment, environment, and policies). This diagram helps teams recognize how multiple factors intersect, making it especially useful for complex events.
  • Five Whys Method – A simple but powerful questioning approach where the team repeatedly asks 'Why?'—typically at least five times—until underlying systemic causes emerge. This prevents premature conclusions and ensures that deeper issues are explored.
  • Flowcharts and Timelines – Reconstruct the sequence of events, allowing investigators to pinpoint where processes failed or communication broke down. These tools are particularly valuable in analyzing delays or patient handoff errors.
  • Failure Modes and Effects Analysis (FMEA) – Although technically proactive, FMEA complements RCA by anticipating points of failure before they occur. Together, RCA and FMEA create a cycle of learning that looks backward to prevent recurrence and forward to prevent potential risks.
  • Human Factors Engineering – Examines issues such as fatigue, workload, communication gaps, and environmental pressures. By incorporating human factors, RCA recommendations move beyond blaming individuals and instead focus on systemic redesign to support safer performance.

Integrating these tools ensures that RCA findings are not only comprehensive but also actionable, bridging the gap between analysis, compliance, and patient safety outcomes.

Tools and Techniques that Strengthen RCA

The RCA Process: Step by Step

A well-structured RCA typically follows these stages:

  1. Problem Identification – Define the event clearly and establish the scope of the investigation.
  2. Data Collection – Gather all available information, including medical records, staff interviews, policies, and timelines.
  3. Event Mapping – Use tools such as flowcharts or timelines to reconstruct the sequence of events.
  4. Identify Contributing Factors – Determine what conditions, decisions, or gaps led to the event.
  5. Determine Root Causes – Apply methods like the “Five Whys” or fishbone (Ishikawa) diagrams to move beyond symptoms.
  6. Develop Action Plans – Create corrective measures that are specific, measurable, achievable, relevant, and time-bound.
  7. Implementation – Assign accountability and resources to ensure recommended changes are put into practice.
  8. Follow-Up and Evaluation – Monitor whether interventions are effective and adjust as needed.

Benefits of RCA for Healthcare Organizations

  • Improved Patient Safety – RCA reduces the likelihood of repeat adverse events by targeting systemic issues.
  • Compliance and Accreditation – RCA aligns directly with regulatory and accreditation standards.
  • Financial Savings – RCA can reduce malpractice claims, settlements, and costs of rework.
  • Staff Engagement and Safety Culture – RCA fosters trust and encourages open reporting of near misses.
  • System Efficiency – RCA highlights inefficiencies and improves workflow.

Challenges and Limitations

  • Despite its benefits, RCA is not without obstacles:
  • Data Gaps: Missing or incomplete data can compromise findings.
  • Blame Culture: Without leadership support, staff may fear participating honestly.
  • Resource Constraints: RCA can be time- and labor-intensive.
  • Implementation Failures: Recommendations may not be acted upon or sustained.
  • Measuring Effectiveness: Many organizations fail to evaluate outcomes.

Best Practices for Effective RCA

Healthcare leaders can adopt best practices to strengthen RCA:

  • Leadership Commitment
  • Multidisciplinary Teams
  • Human Factors Perspective
  • Actionable Recommendations
  • Ongoing Monitoring
  • Learning from Success as well as Failures

Case Example

  • A community hospital reported repeated medication errors involving insulin administration.
  • An RCA team discovered that the electronic health record (EHR) system defaulted to 'units' without clarifying subcutaneous versus intravenous administration.
  • By redesigning the order entry screen and adding a double-check requirement, the hospital eliminated the error pathway.

This example demonstrates how RCA identifies systemic flaws and produces targeted solutions that protect patients while strengthening compliance.

Implications for Compliance and Risk Management

RCA is not just a patient safety initiative—it is also a compliance imperative. Documented RCA processes demonstrate adherence to regulatory expectations, mitigate liability risks, and strengthen audits. RCA outputs also inform staff training, policy revisions, and quality reporting, making it central to governance. In today’s environment, RCA bridges clinical safety and administrative accountability.

Several empirical studies confirm that Root Cause Analysis (RCA) can yield measurable improvements in patient safety and compliance when properly implemented:

These studies highlight that RCA effectiveness depends not only on identifying root causes, but also on implementing strong, system-level corrective actions and maintaining leadership accountability.

Conclusion

Root Cause Analysis is more than a checklist—it is a philosophy of continuous improvement. By uncovering underlying causes, implementing systemic solutions, and monitoring outcomes, healthcare providers can prevent recurrence, enhance compliance, and foster a culture of safety. The ripple effect of RCA begins with asking 'why' but extends across every level of the organization.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Quality Meets Sustainability

A Rising Imperative in Healthcare Compliance 

Written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 


This article explores the relationship between healthcare quality and sustainability, presents the rationale for adopting a “Triple Bottom Line” approach, and offers strategies for embedding ecological and social responsibility into compliance-driven quality improvement.

Introduction

Healthcare quality has long been measured through the lens of clinical outcomes, patient safety, and regulatory compliance. Yet, a new imperative has emerged—one that integrates environmental stewardship and social responsibility into the very definition of quality. This paradigm shift recognizes that sustainable healthcare is no longer a peripheral concern, but rather a fundamental component of ethical, compliant, and effective care delivery.

For healthcare organizations and compliance professionals, the integration of sustainability into quality frameworks represents both a timely opportunity and a professional responsibility. 

Defining Sustainable Healthcare

The healthcare sector is responsible for an estimated 8.5% of total greenhouse gas emissions in the United States (Health Care Without Harm, 2020). Hospitals are resource-intensive, operating 24/7 with significant consumption of energy, water, pharmaceuticals, and plastics. 

Sustainable healthcare is the practice of meeting present health needs without compromising the ability of future generations to meet theirs. It requires balancing three interdependent domains:

1. Economic sustainability – managing healthcare resources efficiently to ensure affordability and equity of access.

2. Social sustainability – promoting health equity, reducing disparities, and strengthening community partnerships.

3. Environmental sustainability – reducing the healthcare sector’s ecological footprint by minimizing waste, energy use, and emissions (Sustainable Healthcare, 2025).

Embedding sustainability within quality initiatives is both an ethical and a compliance imperative.

Quality and the Triple Bottom Line

Traditional quality improvement models—such as Donabedian’s framework of structure, process, and outcomes—have largely focused on clinical performance and patient safety. While essential, this lens is incomplete in today’s context of global health challenges. The Triple Bottom Line (TBL) expands quality assessment to include three metrics:

  • Clinical outcomes (health, safety, compliance)
  • Environmental outcomes (carbon footprint, waste reduction, resource efficiency)
  • Social outcomes (equity, workforce well-being, community health impact)

By incorporating the TBL into compliance frameworks, healthcare organizations can ensure that quality improvement is not only patient-centered, but also community-centered and planet-centered. This expanded view aligns with both ethical principles and federal regulatory trends that increasingly emphasize population health, social determinants of health (SDoH), and health equity.

Why Sustainability Matters for Healthcare Compliance

Regulatory and Policy Drivers

Recent policy developments underscore the growing expectation for healthcare organizations to consider sustainability:

  • Centers for Medicare & Medicaid Services (CMS) has prioritized health equity and community impact in value-based care models, indirectly encouraging sustainable practices.
  • The Joint Commission has begun incorporating sustainability questions into accreditation surveys, particularly in areas of waste management, climate preparedness, and resilience planning.
  • World Health Organization (WHO) emphasizes planetary health and urges member states to align healthcare delivery with environmental responsibility (WHO, 2021).

Compliance specialists can anticipate that sustainability metrics may eventually intersect with reimbursement, accreditation, and public reporting; similar to how quality measures evolved from voluntary to mandatory over the past two decades.

Risk Management and Cost Savings

Ignoring sustainability can increase compliance risk in areas such as waste disposal, pharmaceutical management, and energy inefficiency. Conversely, organizations that integrate sustainability often realize cost savings. Studies show that hospitals implementing energy efficiency programs save an average of $3 per square foot annually (Practice Greenhealth, 2022). These savings can be reinvested into quality improvement, creating a positive feedback loop between sustainability and compliance.

Integrating Sustainability into Quality Frameworks

1. Governance and Leadership Oversight

Boards and compliance officers should embed sustainability goals into governance structures. Policies must explicitly address environmental stewardship, community engagement, and equity. Leadership buy-in is essential for aligning sustainability with compliance and risk management functions.

2. Data, Metrics, and Reporting

Compliance professionals are uniquely positioned to integrate sustainability metrics into existing reporting systems. For example:

  • Environmental metrics: energy usage, emissions, recycling rates, pharmaceutical waste reduction.
  • Social metrics: staff wellness, equity initiatives, community partnerships.
  • Compliance metrics: adherence to environmental regulations and safety standards.

These metrics can be incorporated into existing dashboards, ensuring sustainability is monitored alongside clinical outcomes.

3. Workforce and Education

Staff education is critical. Training programs should link sustainability to ethical obligations and compliance standards. For instance, reducing unnecessary printing or improving medication disposal practices are not just “green initiatives”—they are compliance measures with real quality implications.

4. Partnerships and Community Engagement

Healthcare organizations cannot achieve sustainability in isolation. Collaborations with local agencies, waste management companies, and community health organizations create pathways for shared impact. Professional associations and educators can support this by curating best practices, facilitating dialogue, and providing compliance guidance.

The Role of Compliance Professionals in Leading the Movement

Compliance professionals and healthcare leaders are uniquely positioned to champion the integration of sustainability into quality frameworks. Potential initiatives include:

  • Developing training modules on sustainable compliance practices.
  • Publishing white papers that articulate the compliance case for sustainability.
  • Creating model policies that align environmental responsibility with regulatory requirements.
  • Advocating nationally for recognition of sustainability as a dimension of healthcare quality.

By doing so, compliance specialists reinforce their leadership in shaping healthcare education and practice, while also positioning themselves as stewards of ethical, socially responsible, and ecologically sustainable healthcare.

Challenges and Considerations

While the case for sustainability is strong, healthcare organizations will face several challenges:

  • Resource limitations: Upfront investments in energy efficiency or waste management may strain budgets.
  • Measurement complexity: Defining and standardizing sustainability metrics across diverse healthcare settings can be difficult.
  • Cultural change: Shifting mindsets from a narrow focus on clinical outcomes to a holistic view of quality requires strong leadership and sustained education.

Compliance professionals must be prepared to address these barriers while emphasizing the long-term value of sustainability for patients, organizations, and society.

Conclusion

Quality and sustainability are no longer parallel pursuits; they are intertwined imperatives.

Healthcare organizations that fail to integrate environmental and social responsibility into quality improvement risk falling behind in compliance, accreditation, and ethical standards. Conversely, those that embrace the Triple Bottom Line will be positioned as leaders in an era where patients, payers, and policymakers demand accountability beyond clinical outcomes.

For healthcare leaders, educators, and compliance professionals, this is an opportunity to advance the field by positioning sustainability as a core dimension of compliance and quality. By doing so, they can help reshape the healthcare quality movement into one that is not only clinically effective but also socially equitable and environmentally responsible; a legacy that benefits patients today and generations to come.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Health Care Without Harm. (2020). Healthcare’s climate footprint. Retrieved from https://noharm.org
  • Practice Greenhealth. (2022). The business case for environmental sustainability in healthcare. Retrieved from https://practicegreenhealth.org
  • Sustainable healthcare. (2025). In Wikipedia. Retrieved from https://en.wikipedia.org/wiki/Sustainable_healthcare
  • World Health Organization (WHO). (2021). WHO Manifesto for a healthy recovery from COVID-19: Prescriptions for a healthy and green recovery. Geneva: WHO.
  • Donabedian, A. (1988). The quality of care: How can it be assessed? JAMA, 260(12), 1743–1748.
  • The Joint Commission. (2023). Sustainability and accreditation: Environmental and emergency preparedness considerations. Oakbrook Terrace, IL.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Burnout, Boundaries, and Compliance
Leadership

Burnout, Boundaries, and Compliance

Why Staff Wellness Is a Risk Management Issue 

Written By Dr. Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

This article, grounded in findings from the recent AIHC webinar presentation 'Burnout, Boundaries, and Compliance: Why Staff Wellness Is a Risk Management Issue,' explores how staff wellness programs can be embedded into organizational quality plans and compliance frameworks to proactively address workforce fatigue and prevent downstream risks.

In today’s healthcare environment, the intersection of staff wellness, regulatory compliance, and organizational quality has become impossible to ignore. As staff burnout reaches unprecedented levels, it is increasingly clear that wellness is not just a human resources concern, but a compliance and risk management imperative.

Understanding the Compliance Implications of Burnout

Burnout, defined by the World Health Organization as a syndrome resulting from chronic workplace stress that has not been successfully managed, presents real compliance risks. These risks include errors in clinical documentation, lapses in ethical judgment, and regulatory breaches. Healthcare organizations must recognize that failing to address burnout contributes to higher turnover, lower morale, increased patient safety incidents, and diminished organizational performance. These outcomes directly impact quality metrics and compliance reporting.

Embedding Staff Wellness into Quality Initiatives

A critical finding from Dr. Atkins presentation coupled with additional research identified the value of early detection—integrating wellness strategies at the onset of program design. Staff wellness plans must be embedded as part of quality improvement frameworks, not as optional extras. Organizations that build wellness into policy, practice, and compliance audits are more likely to see measurable improvements in documentation accuracy, patient satisfaction, and employee retention. Proactive wellness programs signal to staff that their well-being is prioritized and monitored, just like infection control or safety metrics.

Early Detection Is Essential

Early detection refers to the strategic implementation of burnout prevention strategies during the formative stages of a healthcare program or system process. Rather than responding to burnout reactively, early detection builds organizational resilience by identifying risk factors—such as understaffing, inadequate training, or high patient acuity—before they lead to harm. Embedding wellness at this early stage empowers staff and creates a feedback loop where staff input shapes policies, reducing the burden of moral distress and compassion fatigue.

Building a Compliance Culture That Prioritizes Wellness

Healthcare compliance leaders are in a unique position to advocate for systemic change. A culture of compliance that integrates wellness must address:

  1. clear policies on mental health support,
  2. confidential self-reporting pathways for burnout,
  3. regular staff wellness assessments, and
  4. accountability structures that enforce reasonable workloads and boundaries.

Wellness champions and wellness subcommittees can play a pivotal role in fostering peer support and resilience among teams.

Practical Steps for Implementation

To effectively embed wellness into compliance strategy, healthcare organizations should:

  • Incorporate staff wellness indicators into internal audits
  • Require burnout screening as part of risk assessments
  • Develop cross-functional wellness committees
  • Use anonymous staff feedback to refine wellness interventions
  • Align wellness initiatives with accreditation and CMS quality metrics

Conclusion

Burnout is a multifaceted risk that affects every level of a healthcare organization. By embedding wellness into compliance and quality frameworks from the start, organizations can create safer, more effective systems of care. Early detection, policy integration, and leadership advocacy are essential for ensuring that wellness is viewed not just as a benefit, but as a compliance requirement. The time for healthcare systems to act is now—staff wellness must be recognized as a foundational element of quality and risk management strategy.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Agency for Healthcare Research and Quality. (2022). Patient Safety Primer: Burnout and Resilience. Retrieved from https://psnet.ahrq.gov
  • National Academy of Medicine. (2019). Taking Action Against Clinician Burnout: A Systems Approach to Professional Well-Being. The National Academies Press.
  • Shanafelt, T. D., & Noseworthy, J. H. (2017). Executive leadership and physician well-being: Nine organizational strategies to promote engagement and reduce burnout. Mayo Clinic Proceedings, 92(1), 129-146.
  • World Health Organization. (2019). Burn-out an “occupational phenomenon”: International Classification of Diseases. Retrieved from https://www.who.int

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Monitoring Claims for Accuracy

Addressing Coding Discrepancies and CAC Limitations to Strengthen Quality and Compliance 

Written By Dr. Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

Computer-Assisted Coding (CAC) can expedite your process, but is it accurate?  This article discusses the limitations of CAC and how to strengthen documentation and compliance to improve quality of care and improve the accuracy of your claims.

Introduction

As healthcare delivery becomes increasingly data-driven, the integrity of clinical documentation and billing practices directly impacts provider reimbursement, compliance with federal and state regulations, and ultimately, patient outcomes. Monitoring claims for accuracy is a vital process within revenue cycle management, serving as both a quality assurance tool and a compliance safeguard. A critical area of concern is the rise of discrepancies in coding, particularly when documentation appears clinically accurate, but coding errors—often exacerbated by overreliance on Computer-Assisted Coding (CAC)—compromise claim validity. This article explores the importance of proactive claim review processes, discusses the limitations of CAC, and outlines evidence-based strategies to ensure documentation and coding alignment. Emphasis is placed on quality as the foundation of compliance, with practical suggestions for mitigating discrepancies, even amid the time pressures faced by providers.

The Link Between Coding Accuracy, Quality, and Compliance

Accurate clinical coding is essential for several reasons: it ensures appropriate reimbursement, supports population health analytics, and reflects the true acuity and complexity of patient care. According to the Office of Inspector General (OIG), improper payments in Medicare and Medicaid programs continue to cost billions annually, often stemming from coding errors rather than fraud (OIG, 2022). Compliance programs in healthcare are thus required not only to prevent intentional misconduct but also to detect and correct unintentional inaccuracies in claims data.

The Centers for Medicare & Medicaid Services (CMS) stress that quality documentation alone is insufficient; it must be accurately translated into billing codes to meet compliance standards (CMS, 2021). When documentation is thorough but coding does not reflect that detail—whether due to human error, insufficient training, or flawed automation—the result is inaccurate reimbursement, potential audits, and regulatory penalties.

Computer-Assisted Coding (CAC): Promise and Pitfalls

CAC systems, designed to improve coding efficiency, use natural language processing (NLP) to extract clinical concepts from documentation and assign appropriate codes. While they can reduce manual workload and improve turnaround times, CAC tools are not infallible. Studies show that CAC accuracy varies widely depending on clinical domain and documentation quality (Dai et al., 2020). A major concern is that CAC tools may suggest incorrect codes if the software misinterprets nuanced clinical information or lacks the specificity required for precise classification.

A 2021 Journal of AHIMA study found that while CAC tools reduced average coding time, they introduced a 12–15% increase in coding discrepancies when not accompanied by robust human review (AHIMA, 2021). This “automation bias” can lead coders to accept system-suggested codes without sufficient validation. Moreover, CAC limitations are particularly evident in complex cases involving chronic conditions, behavioral health diagnoses, or overlapping comorbidities, where documentation subtleties are critical to proper code selection.

Encounter Discrepancies: Causes and Consequences

Encounter discrepancies arise when the documentation recorded by providers does not align with the diagnosis, procedure, or service codes submitted on a claim. Common causes include:

  • Overgeneralization by CAC tools, which may default to unspecified codes.
  • Provider time constraints, limiting detailed note-taking or code validation.
  • Inadequate coder training, particularly in emerging or specialty service lines.
  • Misalignment between clinical terminology and coding nomenclature.

These discrepancies may be flagged as errors during internal audits or external reviews, resulting in claim denials, delayed payments, or post-payment recoupments. Additionally, persistent discrepancies can trigger focused audits by entities such as Recovery Audit Contractors (RACs) or Unified Program Integrity Contractors (UPICs).

Evidence-Based Models for Monitoring and Review

To mitigate discrepancies and ensure accurate claims, healthcare organizations must adopt evidence-based quality assurance models that include routine claim review, coder education, and collaborative documentation practices.

  1. Plan-Do-Check-Act (PDCA) Cycle: This quality improvement framework can be applied to the coding process. Regular monitoring (Check), followed by targeted interventions (Act), and process refinement (Plan/Do), can drive measurable improvements in claim accuracy (Deming, 1986).
  2. Clinical Documentation Improvement (CDI) Programs: These initiatives promote ongoing dialogue between providers and coders to clarify ambiguities and ensure specificity in documentation. Studies have shown that robust CDI programs can increase coding accuracy by 20–30% (Garza et al., 2019).
  3. Concurrent Coding Audits: Instead of retrospective reviews, concurrent audits allow for real-time identification and correction of errors before claims are submitted. When coders or compliance specialists are embedded in the clinical workflow, they can flag discrepancies early and reduce downstream issues (AHIMA, 2022).
  4. Root Cause Analysis (RCA): When high-error claims are identified, RCA can be used to trace the source of errors—be it documentation gaps, CAC misinterpretation, or coder oversight—and develop targeted solutions.

Mitigation Strategies for Busy Clinical Environments

One of the persistent barriers to accuracy is the limited time that providers have with each patient. This pressure often leads to documentation shortcuts, copy-forward behaviors, or lack of specificity in notes, which in turn affects coding quality. The following strategies can help:

  • Leverage pre-visit planning tools that prompt providers on key documentation elements based on the patient’s problem list or chronic conditions.
  • Implement coder-provider feedback loops, where recurring discrepancies are discussed in monthly or quarterly forums.
  • Provide microlearning sessions or just-in-time training for coders, especially after major code set updates (e.g., ICD-10-CM changes each October).
  • Develop encounter-specific documentation templates that guide providers to document with the level of specificity required for accurate code assignment.
  • Use dashboards and KPIs to track claim denial reasons, coding error rates, and CAC override frequency. This enables continuous improvement monitoring.

The Role of Compliance Officers and Risk Management

Compliance professionals must view coding accuracy as a risk management issue. When errors go unchecked, they may result in False Claims Act (FCA) violations, whistleblower reports, and reputational damage. In fact, over 85% of healthcare compliance settlements involve allegations of inaccurate billing and coding (DOJ, 2023).

It is imperative that compliance teams collaborate closely with HIM (Health Information Management), billing, and clinical operations to:

  • Establish routine coding audits.
  • Analyze error trends and provider outliers.
  • Develop corrective action plans and re-education strategies.
  • Ensure CAC systems are updated and monitored for performance drift.

By embedding compliance into everyday workflows rather than viewing it as a retrospective function, organizations can create a culture of accountability that enhances both care and claim accuracy.

Conclusion

Coding accuracy is not merely a technical function—it is a linchpin of healthcare quality, financial integrity, and regulatory compliance. While documentation remains a critical starting point, coding must accurately reflect that documentation to meet standards of care and legal expectations.

As CAC tools become more prevalent, healthcare organizations must remain vigilant about their limitations and ensure human oversight remains central to coding decisions. With the implementation of quality improvement frameworks, clinical collaboration, and robust audit practices, encounter discrepancies can be mitigated—improving not only claims accuracy but also compliance resilience in an increasingly scrutinized healthcare landscape.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • AHIMA. (2021). Impact of Computer-Assisted Coding on Coding Accuracy and Productivity. Journal of AHIMA.
  • AHIMA. (2022). Concurrent Coding Audits in Clinical Workflows. American Health Information Management Association.
  • Centers for Medicare & Medicaid Services (CMS). (2021). Medicare Fee-for-Service 2020 Improper Payments Report.
  • Dai, H., et al. (2020). Evaluating the accuracy of computer-assisted coding systems in healthcare. Health Informatics Journal, 26(4), 2765-2778.
  • Deming, W. E. (1986). Out of the Crisis. MIT Press.
  • Department of Justice (DOJ). (2023). False Claims Act Settlements and Judgments: Annual Update.
  • Garza, H., Spivak, C., & Daniels, M. (2019). Documentation improvement and compliance outcomes. Journal of Healthcare Compliance, 41(3), 45-52.
  • Office of Inspector General (OIG). (2022). Top Management and Performance Challenges Facing HHS.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
Quality

Coding Integrity and CAC

Why Quality Must Precede Compliance in Healthcare Documentation   

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE   

Computer-Assisted Coding, better known as “CAC” has become the norm over the past decade, but are we producing compliant, accurate results?  Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less, which is the reason for this article.

Introduction

In today’s fast-paced healthcare environment, coding accuracy is often caught in the crossfire between compliance pressures, productivity demands, and evolving technology. While documentation may be clinically sound, coding associated with documentation can be misaligned or inaccurate, particularly when it is generated by CAC tools.  CAC can trigger regulatory scrutiny, revenue cycle inefficiencies, and reputational risk without verification by an experienced coding first. As a compliance specialist and educator, I contend that quality cannot be compromised for speed or convenience. In fact, quality is the cornerstone of compliance.

Healthcare consultants recently noted that “documentation is often accurate, but the coding is not,” underscoring a critical gap in the way organizations approach their revenue cycle and risk management. This article explores the current landscape of coding discrepancies, the limitations and risks of CAC, and the essential need for robust internal review processes.

The Disconnect Between Documentation and Coding

In many provider organizations, clinical documentation accurately reflects the patient’s story—diagnoses, treatments, and provider decision-making—but coding processes fall short. Coders may misinterpret documentation, overlook nuances, or rely too heavily on automation, leading to miscoded encounters that can have ripple effects across billing, audit, and quality reporting systems. When errors go undetected, the result can be upcoded services, denied claims, compliance violations, and patient safety concerns. According to the Office of Inspector General (OIG), improper payments stemming from inaccurate coding continue to plague the Medicare program, costing billions annually (OIG, 2023).

CAC: A Double-Edged Sword

Computer-assisted coding (CAC) software, designed to improve speed and efficiency, is now a common fixture in health information management. While these systems can process large volumes of data quickly, their reliance on algorithms rather than clinical reasoning poses significant challenges.

Research has shown that CAC tools may struggle to interpret context, such as distinguishing between active and historical conditions, or differentiating provider impressions from definitive diagnoses (AHIMA, 2022). Without skilled human oversight, these limitations result in critical coding inaccuracies. Unfortunately, some healthcare systems mistakenly treat CAC outputs as final codes without sufficient validation.

Quality needs to be the focus to meet compliance standards. CAC should be a tool to enhance human accuracy—not replace it.

Compliance Risks from Coding Discrepancies

Coding discrepancies—particularly those uncorrected in CAC workflows—are not simply operational issues; they are compliance risks. Auditors from CMS, OIG, and commercial payers increasingly target mismatches between documentation and billing codes. These discrepancies may be flagged as potential fraud, waste, or abuse.  Examples of common coding problems that trigger scrutiny include:

  • Upcoding or down coding visits that do not align with documentation
  • Inaccurate diagnosis coding affecting risk adjustment
  • Use of unspecified or non-supported codes
  • Failure to reflect clinical severity accurately

The DOJ's increased enforcement under the False Claims Act often centers on patterns of poor coding oversight. Healthcare entities must demonstrate that they are taking proactive steps to ensure coding integrity.

Quality as a Compliance Imperative

Ensuring the integrity of clinical coding isn’t just about reimbursement—it’s about compliance, patient care quality, and data accuracy. As healthcare moves toward value-based models, accurate coding supports correct risk adjustment, patient attribution, and performance measurement.

Implementing regular coding reviews, especially of CAC-assisted encounters, is a best practice that healthcare experts recommend. These reviews should be multidisciplinary, involving coding professionals, clinicians, and compliance officers. They help:

  • Identify patterns of misinterpretation or misclassification
  • Provide targeted coder education and clinical documentation improvement (CDI)
  • Verify whether CAC algorithms need adjustment or replacement

Quality assurance activities are not optional—they are essential to both ethical billing and regulatory compliance.

Balancing Productivity Pressures with Accuracy

It is well understood that providers are under immense pressure to manage high volumes of patients while fulfilling extensive documentation requirements. These constraints often lead to documentation fatigue and over-reliance on templated language or CAC tools.  However, automation cannot replace clinical judgment or attention to detail. Coders must be trained to spot subtle inconsistencies and to understand that their role is pivotal in compliance integrity. Likewise, providers need CDI support that makes documentation more efficient and accurate—not more burdensome.

Healthcare leaders should prioritize investments in coder training, CDI collaboration, and coding audits rather than shortcutting review processes for the sake of productivity.

Recommendations for Compliance-Driven Coding Integrity

To address the systemic risks tied to coding discrepancies and CAC errors, organizations should implement the following:

  1. Routine Internal Coding Audits: Conduct monthly or quarterly reviews of randomly selected encounters, with particular focus on high-risk services.
  2. Coder & Provider Education: Offer ongoing training on documentation standards, code selection, and regulatory updates.
  3. Review of CAC Outputs: Routinely validate CAC-generated codes against documentation. Never treat CAC outputs as final.
  4. Real-Time Feedback Loops: Encourage communication between CDI specialists, coders, and providers to resolve discrepancies quickly.
  5. Compliance-Focused KPI Tracking: Monitor error rates, denial trends, and audit findings to identify areas needing improvement.

Conclusion

Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less.

Automation cannot replace accountability.

Compliance leaders must treat quality assurance and coding integrity as non-negotiable pillars of risk management. Let us not allow convenience to compromise compliance. Instead, let quality lead the way.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  1. American Health Information Management Association (AHIMA). (2022). The Realities of Computer-Assisted Coding. Retrieved from https://www.ahima.org
  2. Office of Inspector General (OIG). (2023). Medicare Improper Payment Reports. Retrieved from https://oig.hhs.gov
  3. Centers for Medicare & Medicaid Services (CMS). (2024). Evaluation and Management Services Guide. Retrieved from https://www.cms.gov
  4. U.S. Department of Justice. (2023). False Claims Act Settlements and Judgments Exceed $2 Billion in Fiscal Year 2023. Retrieved from https://www.justice.gov/opa/pr

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Quality
HIPAA, Quality

Quality, Safety & Confidentiality

PSQIA, PSWP & HIPAA Compliance

Written by: AIHC Blogger   


This article addresses patient confidentiality and security related to patient safety evaluations systems, investigations, root cause analysis and compliance to rules and regulations.  It is a basic introduction to help understand the importance of appropriately managing this type of privileged information.

The goal of achieving quality and patient safety is to improve patient safety outcomes by creating an environment where providers can report and examine patient safety events without fear of increased liability risk.  Greater reporting and analysis of patient safety events will help gain a better understanding of patient safety events and result in improvements from lessons learned.

Health care is like “alphabet soup” – filled with acronyms, abbreviations and terms unique to our profession.  Let’s define the 3 acronyms used in the title of this article and how these three rules interact from a compliance perspective.

PSQIA - the Patient Safety and Quality Improvement Act

PSQIA established a voluntary reporting system with the government’s intent to enhance the data available to assess and resolve patient safety and health care quality issues.

On July 29, 2005, the President signed the Patient Safety and Quality Improvement Act of 2005 (Patient Safety Act, 42 U.S.C. sections 299b-21 to 299b-26) into law. The Patient Safety Act amended Title IX of the Public Health Service Act to provide for the improvement of patient safety and to reduce the incidence of events that adversely affect patient safety by authorizing the creation of patient safety organizations (PSOs).

The Agency for Healthcare Research and Quality (AHRQ) lists patient safety organizations which work with providers to improve quality and safety through the collection and analysis of aggregated, confidential data on patient safety events.

PSQIA authorizes our government’s Health & Human Services (HHS) to impose civil money penalties (CMPs) for violations of patient safety confidentiality.  The Office for Civil Rights (OCR) has been delegated the responsibility for interpretation and implementation of the confidentiality protections and enforcement provisions.  When OCR is unable to achieve an informal resolution of an indicated violation through such voluntary compliance, the Secretary may impose a CMP of up to $11,000 for each knowing and reckless disclosure of PSWP that is in violation of the confidentiality provisions.

To encourage the reporting and analysis of medical errors, PSQIA provides Federal privilege and confidentiality protections for patient safety information, called patient safety work product (PSWP).

PSWP - the Patient Safety Work Product

PSWP includes patient, provider and reporter identifying information that is collected, created or used for patient safety activities.

The PSWP is both privileged and confidential under the PSQIA.  PSWP is confidential and may only be disclosed in certain very limited situations where civil money penalties (CMPs) for impermissible disclosures of this information can be imposed.

What it Includes

PSWP is considered any data, reports, records, memoranda, analyses (such as root cause analyses), gap analysis, 8D approach, written or oral statements that are: assembled for reporting to a Patient Safety Organization (PSO); reported to a PSO; or developed by a PSO for the conduct of patient safety activities that could result in improved patient safety, health care quality, or health care outcomes.  It also applies to data used in a patient safety evaluation system (PSES).

PSWP may also include patient information that is protected health information as defined by the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (see 45 CFR 160.103).

What PSWP Is Not

PSWP differs from HIPAA as PSWP does not include a patient’s medical record, billing and discharge information, or any other original patient or provider record. It does not include information that is collected, maintained, or developed separately, or exists separately, from a patient safety evaluation system.

HIPAA- the Health Insurance Portability and Accountability Act

According to the final PSQIA rule, the HIPAA Privacy Rule does not require covered providers to obtain patient authorizations to disclose patient safety work product containing protected health information to PSOs. This is because patient safety activities are considered healthcare operations, typically addressed in the Covered Entity’s Notice of Privacy Practices (NOPP).  PSOs are business associates and should be operating under a Business Associate Agreement or BAA to be compliant under HIPAA rules.

As a Covered Entity (CE) or Business Associate (BA) under HIPAA, regulated entities are required to implement a security management process to prevent, detect, contain, and correct security violations.  This process includes conducting a risk analysis to assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI and implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

A regulated entity that has weak cybersecurity practices makes itself an attractive soft target.  Hackers can penetrate a regulated entity’s network and gain access to ePHI by exploiting known vulnerabilities.  Malicious cyber-attacks targeting the health care sector continue to increase. 

Conclusion

PSQIA, PSWP and HIPAA are government regulations working together to link health care quality, patient safety with privacy and security of privileged information.

All health care providers are expected to investigate any patient safety issues and stay HIPAA compliant while doing so. Sharing information to improve quality and safety in our health care environment is needed to mitigate risk and promote improved reimbursement. 


Online Training:

  • CEs and BAs are encouraged to have C-Suite and management teams trained in HIPAA privacy. Register for the online HIPAA Privacy course worth 12 AHIMA/AIHC CEUs.

Quality and Patient Safety Resources

  • For tips on preventing medical errors and promoting patient safety, measuring health care quality, consumer assessment of health plans, evaluation software, report tools, and case studies, visit the Agency for Healthcare Research and Quality (AHRQ) website and sign up for email updates.
  • The National Advisory Council (NAC) for Healthcare Research and Quality provides advice and recommendations to AHRQ's director and to the Secretary of the Department of Health and Human Services (HHS) on priorities for a national health services research agenda.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

You Play a Vital Role in Protecting the Integrity of the U.S. Healthcare System

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The U.S. health care system relies heavily on third-party payers to pay the majority of medical bills on behalf of patients. Health care insurance fraud is a pressing problem, causing substantial and increasing costs in medical insurance programs. To combat fraud and abuse, all levels within a medical practice, hospital or health care organization must know how to protect the organization from engaging in abusive practices and violations of civil or criminal laws.


If you are a health care provider, remember that payers trust you to provide medically necessary, cost-effective, quality care. You exert significant influence over what services your patients get. You control the documentation describing services they receive, and your documentation serves as the basis for claims you submit. Generally, the health care system pays claims based solely on your representations in the claims documents.


When the federal government covers items or services rendered to Medicare and Medicaid beneficiaries, the federal fraud and abuse laws apply. Many similar state fraud and abuse laws apply to your provision of care under state-financed programs and to private-pay patients. The most important federal fraud and abuse laws that apply to healthcare are the:

  1. False Claims Act (FCA);
  2. Anti-Kickback Statute (AKS);
  3. Physician Self-Referral Law (Stark Law);
  4. United States Criminal Code
  5. Exclusion Authorities; and
  6. Civil Monetary Penalties Law (CMPL).

Implementing a successful compliance program not only assists in protecting your organization but individuals within the organization. It is crucial for providers, coders and billers to understand these laws not only because following them is the right thing to do but also because violating them could result in criminal penalties, civil fines, exclusion from the federal health care programs or loss of your medical license from your state medical board.


Government programs, such as the Centers for Medicare & Medicaid Services (CMS), find the investment in their audit and monitoring programs are effective. CMS announced in the fall of 2021 that their aggressive corrective actions led to an estimated $20.72 billion reduction of Medicare Fee-for-Service (FFS) improper payments over seven years.


When you submit a claim for services provided to a Medicare beneficiary, you are filing a bill with the federal government and certifying you earned the payment requested and complied with the billing requirements. If you knew or should have known the submitted claim was false, then the attempt to collect payment is illegal.


When an organization fails to provide training and education to deter and detect fraud and/or abuse, it is likely to be detected by an outside investigative source via action such as:

  • Focused audit by the payer due to detection of suspect billing patterns when compared to your peers;
  • Routine audits conducted by the payer, such as Medicare’s Comprehensive Error Rate Testing (CERT); and
  • Internal whistleblower or qui tam action.

Internal auditing and monitoring programs are essential to keeping medical records and billing accurate. However, a routine internal billing and documentation review could turn into a more focused internal investigation. During that investigation, is it possible that an aberrant pattern of inappropriate billing is revealed? Do you know how to proceed if this happens?


First, remember that anyone can commit health care fraud. Fraud schemes range from solo ventures to widespread activities by an institution or group. Your organization should have a designated Compliance Officer. Audit professionals should have the authority to report potential fraud and abuse situations directly to the Compliance Officer for further investigation and resolution.


Problem areas brought to the attention of the Compliance Officer should also be included in corrective action training programs to avoid the continuation of the situation. One of the most important aspects of a compliance program is training and education at all levels of the organization.


Now, let’s talk more about qui tam action. There are five potential areas in which qui tam cases arise related to Medicare or Medicaid claims and the False Claims Act (“FCA”). Qui tam claims involving Medicaid/Medicare healthcare vary, depending on the level of care needed and provided. Categories often involve allegations of total neglect or no services, worthless services, inadequate and inferior services and products, and aggressive patient treatment. Other areas of fraud involve misrepresentation of credentials, upcoding of services, unbundling of services, and misrepresentation of patient data or populations.


Words of Advice


Maintain accurate and complete medical records and documentation of the services you provide.

  • Ensure your documentation supports the claims you submit for payment. Good documentation practices help to ensure your patients get appropriate care and allow other providers to rely on your records for patients’ medical histories.

Anytime a health care business offers you something for free or below fair market value, ask yourself, “Why?”

  • Remember, when a vendor or consultant provides coding and billing advice, the provider filing the claim is responsible for the accuracy of that claim. Be suspicious when you are told that a huge enhancement of revenue will be realized if you bill like this . . .

Get expert advice from a qualified source before investing or getting into a joint venture.

  • Some physicians who invest in health care business ventures with outside parties, such as imaging centers, laboratories, equipment vendors, or physical therapy clinics, may refer more patients for the services provided by those parties than physicians who do not invest. These business relationships may improperly influence or distort physician decision-making and result in the improper steering of patients to a therapy or service where a physician has a financial interest. Arrangements could be viewed as illegal.

Avoid illegal incentives to join a hospital’s community.

  • A hospital may pay you a fair market-value salary as an employee or pay you fair market value for specific services you render to the hospital as an independent contractor. However, the hospital may not offer you money, provide you free or below-market rent for your medical office, or engage in similar activities designed to influence your referral decisions.
  • Admit your patients to the hospital best suited to care for their medical conditions or to the hospital your patients select based on their preference or insurance coverage.

Don’t sell free product samples.

  • Many drug/biologic companies provide free product samples to physicians. It is legal to give these samples to your patients free of charge, but it is illegal to sell the samples.
  • The federal government has prosecuted physicians for billing Medicare for free samples.
  • If you choose to accept free samples, you need reliable systems in place to safely store the samples and ensure samples remain separate from your commercial stock.

Relationships with the pharmaceutical and medical device companies

  • As a practicing physician, you may have opportunities to work as a consultant or promotional speaker for the drug or device industry. For every financial relationship offered to you, evaluate the link between the services you can provide and the compensation you will get. Test the appropriateness of any proposed relationship by asking yourself the following questions and when in doubt, get legal advice: o Does the company really need your specific expertise or input? o Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services? o Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?

o  Does the company really need your specific expertise or input?

o  Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services?

o  Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?


Educate C-Suite and Compliance Officials in Your Company


An executive, top-down approach is required for a successful compliance program. The following seven components provide a solid basis for a compliance program:


1. Conduct internal monitoring and auditing

2. Implement compliance and practice standards

3. Designate a compliance officer or contact

4. Conduct appropriate training and education

5. Respond appropriately to detected offenses and develop corrective action

6. Develop open lines of communication with employees

7. Enforce disciplinary standards through well-publicized guidelines


Establishing and following a compliance program helps health care providers avoid fraudulent activities and submit accurate claims. However, implementing mechanisms to develop a culture of compliance requires educating high-level influencers within your organization. 


Suggest C-Suite executives take online training in healthcare Corporate Compliance.

Require your Compliance Officer, Chief Executive Officer and Chief Financial Officer to become certified not only in Compliance, but in Auditing for Compliance and Conducting Internal Investigations.


Joanne Byron is the Board Chair and Chief Executive Officer of the American Institute of Healthcare Compliance (AIHC) with more than 35 years of health care coding, documentation, billing and compliance experience as a consultant, health care executive and corporate trainer. Learn more about AIHC, a 501(c)(3) non-profit training organization, today.  

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Addressing Revenue Cycle Labor Shortage With Technology and Outsourcing

Written by: Melvin Miller, COO




The labor shortage is currently one of the biggest issues across industries. Be it restaurants, hospitals, retail, hospitality, and manufacturing – take any sector and you will find that this is perhaps the #1 problem operations managers are facing.


In healthcare, the labor shortage is not limited to clinical roles but extends across administrative functions. Front-office staff, billers, coders, accounts receivable, denial management, and physician credentialing experts are in short supply.


If you look at the revenue cycle, lack of timely filing and follow-ups can increase denials and result in delayed cashflows. When your revenue cycle faces a staffing shortage for core functions, you tend to ignore the optimization functions such as quality assurance and underpayment reviews, which can unlock additional revenue opportunities.


The staffing shortage is aggravating problems for the hospitals, which were impacted already by the pandemic. Over the years, we have seen declining reimbursements necessitating revenue cycle operations to deliver the best financial outcomes, which requires deep healthcare and reimbursement process expertise.


With expert revenue cycle team members already in short supply and the mandate to get all employees vaccinated for COVID-19, hospitals and healthcare systems are losing employees due to resignations and terminations. Due to the shortage of clinical and non-clinical staff, many hospitals are on the verge of closing; in fact, many rural facilities have closed already. Further, the shortage has resulted in a fight for talent, which led to increased salaries and the cost of operations.


In this blog, we look at some of the strategies revenue cycle CFOs are deploying.

  • Cloud-based IT infrastructure

With the need to operate remotely, IT leaders are tasked with making mission-critical EHR and RCM platforms available anytime, anywhere. In most physician practices, the adoption of SaaS-based EMR/RCM solutions is increasing.

  • Process automation

Within both clinical and non-clinical revenue cycle solutions, the application of machine learning, AI, and RPA technologies are enabling revenue cycle leaders to combat the staffing shortage to some degree. Technology and automation can move routine, repeatable, labor-intensive tasks to the machines and reduce manual effort. For instance, claims status automation and the adoption of portals reduce call center workloads. When you free up people from mundane activities, they can focus on higher-value activities and have better job satisfaction.

  • Operational rigor

While all revenue cycle leaders talk about managing tighter operations, few have gone on to invest time and money in implementing workflow systems that help them measure, monitor, and manage the productivity of each employee. Transactional productivity improvements will, in the short term, lead to gains in financial outcomes.

  • Analytics for sustainable transformation

Usually, revenue cycle success boils down to strategic A/R management, i.e., understanding the patterns in denied claims, addressing root causes, strategic touches to claims in higher revenue brackets, and not allowing claims to fall into longer aging buckets. Revenue cycle analytics and adoption of industry-standard reporting can help RCM managers create the focus.

  • Outsourcing

Perhaps the #1 strategy that organizations are looking at is outsourcing, which gives them access to trained, certified labor across the nation. And with offshoring, you also get the benefits of cheaper cost structures. With the outsourcing and offshoring market now nearly two decades old, you can find service providers who have invested in process expertise and technology to help you get access to best-of-the-breed practices.

  • Optimizing costs to collect requires simultaneous implementation of pervasive change strategies

Across the revenue cycle operations, the questions that leaders need to ask are:


o What can you automate?


o What technologies do you need to invest in - workflow automation, analytics,
front-end tech?


o Where will you find the money to invest in new-age technology?


o Does this function need to be done onshore, or can you offshore it? 

  • Cash is king. Leaving revenue on the table is a crime.

Faster cash flow cycles are critical to the survival of healthcare organizations. Address the problems such as revenue leakage and front-end processes sustainably to streamline operations.

  • Change the job content for your employees

Accelerating the adoption of technology and outsourcing can shift the focus of your employees to strategic tasks. The change in job content makes them feel empowered to impact the organization’s revenue cycle outcome, which is more satisfying.

  • Don’t just outsource. Choose your vendor partner well.

Plan along with your vendors, transition and stabilize operations, and then move the goal post for the vendor every quarter.

While you can take the short-term to address your revenue cycle issues, it is time for revenue cycle leaders to implement sustainable solutions. The labor shortage is not going away quickly, and reimbursements will continue to decline. Technology, operational rigor, and outsourcing are the only options you have. Choose well, plan well, and execute in style.

Additional Resources:

  • Medical Billing Wholesalers - https://www.medicalbillingwholesalers.com

    _________________________________________________________

    Melvin Miller is an experienced Chief Operating Officer with a demonstrated history of working in the healthcare industry for over 15 years, Satish, a.k.a. Melvin, has experience in team building, business development, Healthcare Information Technology (HIT), revenue cycle process training, US. Health Insurance Portability and Accountability Act (HIPAA), and Healthcare Management.
Read More