Compliance in Healthcare
Corporate Compliance

Vendor Compliance – Old Problem, New Risks

Written by Susan Lee Walberg, JD MPA CHC 

Compliance Officers are always stretched thin with many responsibilities, and those duties seem to constantly grow with each year and every new law or regulation. One of the more challenging areas to monitor is the compliance of our vendors and Business Associates.

I believe this is now more important than ever. Why? Because cybercrime, hacking, phishing, and impersonation schemes are rampant, and the cyber-crooks are now using AI to circumvent our (and our vendor’s) security measures.

How many times have we heard about a major breach, and the root cause was a failure to conduct a Security Risk Assessment or apply patches or software updates timely? A failure of routine training is also often to blame. Over 60% of breaches are caused by Business Associates, so this is an area of risk that I believe needs more attention.

Over the years, I have found that prevention is the best cure. There are several steps we can take on the front end to reduce the risk of non-compliance during the term of the Agreement.

1.  Compliance needs to be at the table BEFORE arrangements are entered into. It’s not unheard of, in a large health system, for the compliance officer to not even know about every joint venture or acquisition, but, when there’s a compliance problem at that entity, they are on the hook. It’s critical to build trust with leadership, and educate them as to why Compliance needs to be at the table. We need to understand what the arrangement is about, why we are doing it, and who is paying what to who. If Compliance isn’t informed and engaged, some of these other steps likely won’t happen.

2.  Due diligence is critical for new business partners. While the finance team reviews the balance sheet, Compliance needs to be reviewing the organization’s compliance program, culture and reputation. There should be a document list the Compliance reviews for acquisitions and partnerships, but even for contracted services, we want to take a peek and do some basic reviews.

  • Review their Compliance Plan (and how often it’s been reviewed and updated)
  • Have a conversation with their compliance, privacy, and/or security officer to get a better sense of how they operate
  • Find out if they’ve been subject to any investigations
  • Run a List of Excluded Individuals and Entities (LEIE) OIG check
  • Ask to see their most recent Security Risk Assessment, if ePHI is going to be involved

Pay careful attention to any referrals that are considered as part of the contract. These are not only for physicians, but they can also be an IT vendor or other provider of goods or services-there have been plenty of cases where companies, such as Electronic Medical Record (EMR) companies have been found in violation of the Anti-Kickback statute. Have an attorney review it if this isn’t your area of expertise. The bottom line is to ask yourself if the arrangement itself is appropriate.

Those are just some suggestions, but at least these activities would give you a sense of how much they tend to compliance. Also, it never hurts to do a basic Google search. If they aren’t a new organization, and if they have any ethical or legal issues, you will likely find reviews on the Better Business Bureau site and/or sites where employees and customers can give a rating/review. That activity alone can speak volumes if the organization has a culture problem.

3. Contract provisions need to include compliance. Although bad actors sign contracts all the time, it still helps protect       your organization and does show that you take compliance and ethics seriously. Some suggested provisions:

  • The vendor agrees to comply with all applicable laws, rules, and regulations, including False Claims Act, Stark, HIPAA, and any other that are key for your business and the type of services.
  • The vendor agrees that you are allowed to audit their processes and records that pertain to the services under the contract
  • The vendor agrees that all their employees are checked for disbarment and that none of their employees or contractors are disqualified to participate in government health care programs; and to notify you immediately if that changes.
  • The vendor agrees and attests that they have a compliance, privacy, and security program that meets or exceeds industry and regulatory standards, and that they maintain stringent security standards to protect the integrity of ePHI.
  • Breach notification and remediation procedures need to be detailed. How long after a breach is identified must you be notified? Who notifies clients? Review the breach response requirements under HIPAA and make sure you address those.
  • Data use is an important provision. Review your contract or Business Associate Agreement, keeping in mind that data is now as valuable as gold. Can your business partners sell your data? What if it’s de-identified? Are you comfortable with them doing so, and does your agreed-upon rate take that into account? The advent of AI makes data much more valuable.
  • Adherence and compliance to all Medicare regulations, especially if this is a contract for any business office, documentation, coding, or record review service.

4. Training requirements are not optional. Privacy, Security, and Compliance training should be provided to the vendor’s   employees, or they can take training you provide, if you have that option. If they have their own program, it’s totally acceptable to ask to see it. Ongoing data security training, in particular, is important due to the constantly evolving phishing and other schemes.

5. Make sure you have tight controls on granting access to your information. Your business partner can’t just get one log-in that everyone uses. That should be a core requirement for data access-unique user IDs and passwords.

Those are some key front-end steps. Once the agreement is in place, if the previous activities are completed there shouldn’t really be a heavy load of monitoring, absent some incident or breach. Here are a few things to consider:

  • Stay in contact with the process/contract owner and ask how things are going. If there are problems, that person is likely the first to know. Make sure they know to call you if something starts to go sideways.
  • Conduct any audits or monitoring you included in the contract, if you’re able to (it’s a resource issue, for sure)
  • Send occasional surveys to your vendors inquiring about their compliance, privacy, or security measures. This at least lets them know you are paying attention.
  • Touch base with their compliance, privacy, or security officers
  • Monitor training logs, if they receive training from you (or ask them to provide that information)
  • Look them up online now and then to see if there are any new complaints out there.
  • Get an audit of what information their employees are viewing-make sure it’s appropriate.

Monitoring your vendors can seem like just one too many things to do, and most of the time you will find that there are no red flags. Most businesses try to do the right thing. But it’s important to keep in mind how much of a risk they could pose to your organization, especially if they are handling patient information and/or billing functions. You don’t want to be looking back and wishing you had done it and having to explain that to your leadership!

About the Author Susan Lee Walberg, JD MPA CHC

Ms. Walberg is an author, attorney and healthcare compliance consultant. She is available to help anyone work through these processes and provides a full range of compliance-related services and books, including serving as a fractional Compliance or Privacy Officer, or in an interim role. She can be contacted by email at swalberg@compliancealacarte.com, or find more about services and books on her website at susanwalberg.com or on LinkedIn!

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Is it an Audit, Gap Analysis or Risk Assessment?

For Auditors and Compliance Officers 

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

New to Compliance & Auditing for Compliance?  This short article is #3 in a three-part series addressing various areas of auditing and monitoring healthcare providers for compliance.  You may want to read Article #1 – Importance of Compliance Audits and Article #2 Auditing for Anti-Kickback Statute Violations.

Introduction

A healthcare compliance audit checks adherence to laws (such as HIPAA, Stark, Anit-Kickback Statue, coding, billing rules) and includes reviewing written policies, assessing internal controls, verifying staff training, monitoring data security, examining processes, interviewing staff, and ensuring a robust reporting/corrective action process is in place.  This is all aimed at risk reduction and better patient care.

The focus of this article is to discuss the difference between a Gap Analysis and Risk Assessment when conducting an audit.

Conducting an Audit can be Complex

To audit, gap analyze, and risk assess healthcare compliance, an organization systematically identifies standards, gathers data, evaluates compliance gaps and threats, prioritizes issues, then create corrective plans.  This is followed by conducting monitoring audits and review to find and fix deficiencies before they become major problems. It is a continuous process.

Core Components of a Healthcare Compliance Audit often include:

Risk Assessment & Scope

  • Identifying high-risk areas (e.g., billing, privacy, patient safety) and defining what the audit will cover.

Performing a Documentation Review

  • Checking written policies, procedures, training records, consent forms, and compliance plans for completeness and accuracy.

Testing Internal Controls

  • Evaluating safeguards for data (EHR, access), billing, and operations to prevent fraud and errors.

Workforce Competency

  • Verifying that employees understand and follow policies through training logs and interviews.

Conducting Interviews & Observation

  • Talking to staff and watching workflows to see if policies are truly followed in practice.

HIPAA Compliance

  • Data Security & Privacy auditing to determine HIPAA/HITECH compliance, access controls, and breach protocols.

Billing & Coding Accuracy

  • Performing pre-billing and post-billing audits to ensure claims are correctly coded and comply with payer rules.

Reporting & Investigation

  • Assessing the effectiveness of hotlines, whistleblower protections, and how reported issues are handled.

Corrective Action Plan (CAP)

  • Developing and tracking steps to fix any identified compliance gaps.

Gap Analysis

The distance between where you are where you need to be

Conducting an audit often requires performing a gap analysis.  A gap analysis identifies the difference between your current state and desired compliance levels.   Simply put, it starts by defining the compliance goal, assesses current performance (what your organization is actually doing) and pinpointing exactly where the organization is falling short.

In healthcare compliance, a Gap Analysis finds what you're missing compared to a standard (e.g., Coding or HIPAA rules), showing the "what's missing" and "how far" from compliance, while a Risk Assessment identifies why you're vulnerable, evaluating the likelihood and impact of threats (like breaches) to determine what controls are truly needed to mitigate risk, forming two complementary steps to achieve full, effective compliance, not replacements for each other.

Key Steps for Risk Mitigation Gap Analysis:

1. First, start with defining the scope and objective.

  • Clearly state what you're analyzing (processes, compliance, performance) and the desired outcome or standard (e.g., regulatory compliance, industry best practice).

2. Next, define benchmarks, goals that need to be met.

  • Define the desired state. Establish benchmarks, goals, and ideal performance levels, often based on regulations, standards, or strategic objectives.
  • Create list of items being measured and evaluated.

3. Conduct an Evaluation to Assess Current State.

  • Document existing performance, processes, policies, and controls, gathering data through audits, interviews, and metrics.

4. Identify & Analyze Gaps.

  • Compare current vs. desired states to find discrepancies.
  • Use tools like SWOT or process mapping to visualize inefficiencies, as taught by AIHC in the Auditing for Compliance online course which addresses gap analysis.

5. Conduct Root Cause Analysis (RCA).

  • Dig deep to understand why gaps exist (e.g., outdated policies, lack of training, resource issues).

6. Prioritize or Rank by Severity.

  • Rank gaps by severity, impact, and risk level (e.g., using an impact/effort matrix) to focus on the most critical issues first.

7. Develop Action Plan (Remediation).

  • Create detailed plans with specific actions, assigned owners, resources, timelines, and success metrics to close each prioritized gap.

8. Implement & Execute.

  • The organization must act and ensure necessary resources and support are in place.

9. Monitor & Review.

  • Continuously track progress, measure results against KPIs, and make adjustments to ensure effective risk reduction.

10. Communicate & Report.

  • Share findings and progress with stakeholders to maintain transparency and buy-in.

Risk Assessment – The “Why” and “How Bad”

After identifying what's missing (the gaps), the risk assessment quantifies how bad those gaps are. The risk assessment evaluates potential threats to compliance and patient safety.  This process explains why gaps matter and dictates what to fix to manage risk effectively.  It includes an impact analysis, evaluating controls and calculate residual risk.

Difference between Gap Analysis & Risk Assessment:

Gap Analysis = Current vs. Standard

Risk Assessment = Threats/Vulnerabilities vs. Assets

Key steps for a risk assessment following a gap analysis:

1. Identify Risks from Gaps.
  • Take the identified gaps (e.g., lack of security training, outdated software) and pinpoint the specific threats or vulnerabilities they create (e.g., phishing, data breach, system failure).

2. Analyze Risk (Likelihood & Impact). For each identified risk, determine.

  • Likelihood: How probable is it that this risk will occur?
  • Impact/Severity: How bad would the consequences be (financial, operational, reputational) if it did happen?

3. Evaluate & Prioritize Risks.

  • Combine likelihood and impact to score each risk (e.g., High, Medium, Low) and prioritize them. Focus on high-impact, high-likelihood risks first.

4. Develop Mitigation (Control) Strategies.

  • For prioritized risks, design actions to eliminate, reduce, or transfer the risk. These are your control measures (e.g., implementing training, upgrading systems).

5. Record Findings & Controls.

  • Document the entire process, including identified risks, analysis, chosen controls, and responsibilities. This is often a legal requirement.

6. Implement Controls.

  • Put the planned actions into practice.  

7. Monitor & Review.

  • Don’t stop short, complete the cycle by regularly checking if controls are working and update the assessment as the environment, threats, or business needs change.

Auditing for Compliance

Even if you have some audit experience, taking an online course and certifying can fill-in knowledge gaps and provide essential skills to lead an audit team.

To become a lead auditor, many organizations will require you to complete a training course that covers auditing principles, management systems, and leadership skills, followed by passing an exam and gaining auditing experience, such as offered by the American Institute of Healthcare Compliance (AIHC), recognized as a Licensing/Certifying partner with the Centers for Medicare & Medicaid Services (CMS).

Resources to Stay Informed

Lead Auditors and Compliance Officers need to stay informed.  Subscribing to government notifications is one way.  You may also want to review current educational articles (free) published by the American Institute of Healthcare Compliance (AIHC)– click here for the Auditing category, and view all articles or by additional categories. 

Videos can be a helpful way to stay informed.  We recommend the following which may be of interest for you or members of your audit and compliance team!

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

  • Auditing for Compliance online training course by the American Institute of Healthcare Compliance.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

HITECH Compliance

Checklist for Individual & Small Group Practices

Written by: Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO, CORCM  

This article provides an overview of Health Information Technology for Economic and Clinical Health Act (HITECH) and basic checklist of policies and procedures for compliance of smaller health care organizations. This information is not all-inclusive and is not intended as consulting or legal advice.

HITECH is a critical aspect of the Health Insurance Portability & Accountability Act (HIPAA).  Since 2009, HITECH has given “teeth” to HIPAA law.  What’s the difference between HIPAA and HITECH? HIPAA guarantees patients access to their paper medical records. HITECH extended those rights to electronic medical records, extended privacy rights of patients to access their records, increased penalties for HIPAA violations, extended the HIPAA security and breach notification rules and expands the HIPAA encryption compliance requirement.

HIPAA and HITECH is for all health care organizations falling under the definition as a Covered Entity, from solo practices to larger clinics and hospital medical networks to health plans and clearinghouses. 

As a smaller organization your security measures can be in place whether you have an IT person you have access to as a 1099 employee or a person that is on your own payroll.  But, someone must be providing oversight to ensure compliance to both HITECH and HIPAA security rules, both Federal and any applicable State rules.

Let’s start with what HITECH, the acronym for the “Health Information Technology for Economic and Clinical Health Act.”  This act was signed into law by President Obama back in 2009.  For years we lived with HIPAA and understood we needed to protect patient information. HIPAA standards brought us the Administrative Safeguards, Physical Safeguards along with Technical Safeguards.  While we learned to protect information, everything was on paper.  Yes, we faxed and mailed and then the computer age brought us into sending information, claims, through the internet. Our PHI (Protected Healthcare Information) became EPHI (Electronic Protected Healthcare Information).   So here we are, understanding the rules on what we need to do on our own for our practices. But, is that really true?  As you will find out, we do have a lot of information, so much when you are writing your own HITECH plan you don’t know where to start.

Patient information is everywhere.  We can own a Durable Medical Equipment store, see our own doctor, or go and have a test done at a medical facility.  Each of these can cause exposure on behalf of patient information. 

The focus of this article is to be able to launch a list of questions which can be answered to put in place a basic plan in its simplicity of how to protect your own practice.  This can give you a start and with time being aware of “HITECH” you can add to what you have in place. Links have been provided for additional information which is recommended for review as you go through the process.

So, let’s start! Answer the questions and document.  Focus on the easier ones and go back into the others utilizing the links provided.

[Name of Your Practice]

HITECH Policy and Procedures

Electronic Health Records

When changing over from paper records to Electronic Health Records or E.H.R., electronic systems have the potential to actually reduce errors and often have additional security features, such as audit logs to track access to records and security controls assigned per user. 

  • Is your system a user-friendly tailored software for smaller practices? This will minimize challenges EHR has in setting up your software with your patient database. 
  • Does your system offer Artificial Intelligence (AI) options?
  • If so, is it “secure by design”?

Risk Assessment

  • When going through the list identify any vulnerabilities which can cause risks to Protected Health Information (PHI) or Electronic PHI (ePHI). Know your risks, so they can be mitigated accordingly. What are they? 
  • Who is responsible for conducting security risk assessments?
  • How often are these risk assessments performed?
  • What type of vulnerabilities were revealed and how were they address?

Patient privacy, confidentiality and the breach notification rule

  • The importance of maintaining privacy and confidentiality of patient information should be the top priority for your practice. 
  • How does patient information flow through your office?  Are all communications secure and private?  HIPAA requires Covered Entities to protect the privacy of all health information, including who can access it, and gives patients specific rights over it.
  • Is your organization compliant to a patient’s Right of Access?
  • How are security breaches prevented?
  • What is your procedure to notify patients in the event of a data breach?
  • Does your practice have a procedure for notifying the Health & Human Services (HHS) Secretary when there is a breach of 500 or records?

Preventing fraudsters

Having security measures in place safeguards patient data.  However, patients may not realize that someone has stolen their medical identity. 

  • Do your patients understand why they must show proof of identity when they arrive for care?
  • What are your protocols to verify patient identity?  Yes, there are patients that will use someone else’s medical card for services.
  • Does your organization have materials for patient education and risks of identity theft and medical fraud?
  • Do you encourage patients to review their medical statements for charges that are not known to them need to be reviewed?

Administrative safeguards

HIPAA administrative safeguards are actions, policies, and procedures designed to manage the selection, development, implementation, and maintenance of security measures to protect ePHI. These safeguards guide the conduct of a covered entity's staff concerning ePHI.

  • What security checks are employed to ensure that individuals in key employee positions are screened? This includes background checks and taking oaths of confidentiality, where necessary.
  • Administrative safeguards include four implementation specifications.  Is there documentation to support practice compliance to these requirements?
  1. Risk Analysis
  2. Risk Management
  3. Sanction Policy
  4. Information System Activity Review
  • What security measures are already in place to protect EPHI (i.e., safeguards)?
  • Is executive leadership and/or management involved in risk management and mitigation decisions?
  • Are security processes being communicated throughout the organization?
  • Does the covered entity need to engage other resources to assist in risk management?
  • Does your practice apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity?
  • Are employees required to sign a statement of adherence to security policy and procedures (e.g., as part of the employee handbook or confidentiality statement) as a prerequisite to employment?
  • Are there existing procedures for determining that the appropriate workforce members have access to the necessary information?
  • Are the procedures used consistently within the organization when determining access of related workforce job functions?
  • Does the sanction policy provide examples of potential violations of policy and procedures?
  • Does the sanction policy adjust the disciplinary action based on the severity of the violation?
  • Do the termination policies and procedures assign responsibility for removing information system and/or physical access?
  • Do the policies and procedures include timely communication of termination actions to ensure that the termination procedures are appropriately followed?
  • Are the information systems functions adequately used and monitored to promote continual awareness of information system activity?
  • What logs or reports are generated by the information systems?
  • Would it serve the organization’s needs to designate the same individual as both the Privacy and Security Official (for example, in a small provider office)?
  • Has the organization agreed upon, and clearly identified and documented, the responsibilities of the Security Official?
  • How are the roles and responsibilities of the Security Official crafted to reflect the size, complexity and technical capabilities of the organization?

Technical safeguards

Securing your electronic systems protects ePHI.  This is where it is recommended that you have an “IT person” who is a person who works in the field of information technology (IT) and specializes in computer systems and networks. 

  • Has an IT professional installed and set up your infrastructure in your organization can ensure reliability and security?
  • Encryption is not mandatory to be compliant to the security rule.  However, encryption renders data unusable.  In the event of a data breach, when the data was encrypted, the breach is not required to be reported.  The encryption implementation specification is addressable, which means is should be implemented if, after a risk assessment, your Security Officer has determined that the specification is a reasonable and appropriate safeguard in its risk management of the confidentiality, integrity and availability of e-PHI.  How does your organization protect ePHI that is used in emails and/or texts?

Cybersecurity

With all the cyber threats and vulnerabilities, a structured cybersecurity framework needs to be in place. 

  • What do you have in place to prevent malicious software?  What do you have to protect your network from cyber threats?
  • Are your monitoring systems done routinely?
  • How do you respond in the event to mitigate a cybersecurity incident?   
  • Do you have a contingency plan in the event of a cybersecurity incident?
  • How do you evaluate if the cybersecurity incident is a breach (or not)?
  • Ransomware attacks are also referred to as Cy-X or Cyber extortion. Don’t forget the anti-virus software and the educating of employees on signs of unusual activity.  NIST which stands for National Institute of Standards and Technology is part of the U.S. Department of Commerce.

Data backup and recovery

  • Data should be backed up on a regular basis.  Encrypted storage protects the integrity of the software and database in case of a disaster.  Has this been tested?

Audits and assessments

  • Are you conducting internal audits? Security assessments and compliance review should be in place.  Remember these are areas that can validate the protection of PHI and ePHI.

Education and Training

Training for employees on HITECH should include educating staff members about the basics. Their responsibilities include safeguarding protected health information (PHI), and the requirements of compliance regarding electronic health records (EHRs), and health information technology (HIT). Let’s look at what we can include under the training.

  • Include an overview of the HITECH Act, its purpose and objectives.  By providing comprehensive training on HITECH Act and related HIPAA regulations, employees will understand how to participate in safeguarding patient information. They will be able to actively prevent the risks of breaches, and help maintain compliance with regulatory requirements.
  • Understanding HIPAA is crucial.  Come up with a list of what ways you can prevent breaches.  Is it the computer screen in your office that is viewable from the lobby?  Can they hear you discussing with a patient privacy information? Are patient files sitting out?  Come up with your own list and implement training for prevention. Train your staff on HIPAA regulations and how their responsibility is in protecting patients.
  • Training and awareness educating staff members on the importance of protecting PHI and EPHI should be done on a continual basis.  How often are you training?
  • Are you keeping employees up to date on any changes in regulations? 
  • Are they reporting risks to management? 
  • Can your employees recognize a threat through an email such as Phishing?
  • Are there internal office policies regarding no downloading from unknown web pages? 
  • Are they allowed to attach their own devices to their computers which could cause breach of security controls.

Additional Resources

Review the HIPAA provisions and how the HITECH Act strengthens the HIPAA enforcement. You will see added information requiring privacy, security, and breach notifications.

HHS 405(d) Knowledge on Demand

Knowledge on Demand is the 405(d) Program’s free cybersecurity education platform. It includes multiple levels of delivery methodologies designed to reach the varied size health care facilities across the country. Our platform includes cybersecurity awareness trainings that align with the top 5 cybersecurity threats outlined in the landmark 405(d) Health Industry Cybersecurity Practices publication.

HIPAA Security 101 for Covered Entities

Health IT Privacy and Security Resources for Providers

HHS Smaller providers and businesses

NIST Small business for Cybersecurity Corner

Conclusion

This is just a start!  This is Part 1 in a mini-series on HIPAA and HITECH rules for smaller health care organizations. 

Utilize the steps and keep on adding as you gather your information.  There is a lot of information available.  Be sure to use web sites that give you information that is accurate such as Centers for Medicare and Medicaid Services, Health and Human Services, Office of Civil Rights and U S Government Agencies.

If you are a Practice Manager, Administrator or owner of a small medical organization and responsible for overseeing HITECH and HIPAA compliance, consider online training.  Click Here to learn more.

Learn more about HIPAA HITECH

  • For more information on our HIPAA Privacy and Security Course CLICK HERE!
  • For more information on our HIPAA Privacy Officer Course CLICK HERE!


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More