Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
General Compliance, HIPAA

Before PHI Enters a SaaS Workflow

Building a Vendor Evidence Register 

Written by Coco Yang 

Introduction

A clinic can approve a scheduling platform and still miss the place where patient information leaves the approved path. An intake form may pass data to the scheduler, which sends a notification through an email service, creates a record in a customer relationship management system, and copies details into an analytics tool. The vendor review may have covered the scheduling platform. The actual workflow contains four or five services.

That is why a product name and a "HIPAA compliant" statement are not enough to document a SaaS decision. The review needs to identify the exact service, plan, configuration, integrations, users, and data flow. It also needs a record of what each source supports, what it does not support, and what still requires an answer from the vendor.

A vendor evidence register provides that record. It is not a certification score and should not replace legal, privacy, security, procurement, or clinical review. It is a practical way to keep the evidence behind a decision visible before protected health information (PHI) enters a software workflow.

Start With the Workflow, Not the Vendor Name

The first question is not simply, "Does this vendor support HIPAA?" A more useful starting question is, "What will this organization do with this exact service?"

Write down the product edition and paid plan, the features that will be enabled, the people who will have access, and the systems that will send or receive data. Include support tools, exports, backups, browser extensions, mobile applications, application programming interfaces, automation services, and optional artificial intelligence features. Then identify where PHI is expected to be created, received, maintained, or transmitted.

This boundary matters. A vendor may make a business associate agreement (BAA) available only for certain products, plans, customers, or configurations. An integration may be provided by another company. A feature may use a separate sub-processor or different retention setting. HHS guidance on cloud computing advises covered entities and business associates to understand the cloud environment they are using so they can conduct their own risk analysis and enter into appropriate agreements.

A simple workflow sentence helps anchor the review. For example: "Patients submit contact and appointment information through Form A; the data is stored in Scheduler B; staff members access it through managed accounts; appointment reminders are sent through Service C; no PHI is sent to analytics." If the team cannot write that sentence with confidence, it is too early to approve the workflow.

Keep Different Kinds of Evidence Separate

Vendor material often arrives as a mixed folder of contracts, reports, help-center pages, questionnaires, and sales statements. These sources do not answer the same questions.

A BAA is contractual evidence. HHS explains that a business associate contract establishes permitted and required uses and disclosures, requires safeguards, addresses incident reporting, applies restrictions to relevant subcontractors, and covers return or destruction of PHI at termination when feasible. The review still needs to confirm that the agreement applies to the exact legal entity and service being purchased.

A SOC 2 report is security-assurance evidence. It can help a reviewer understand the systems, controls, time period, exceptions, and subservice organizations described in the report. It does not establish that the vendor will sign a BAA, that the intended product is included in the BAA, or that the customer's configuration is appropriate.

Product documentation explains how features work. It may describe access controls, audit logs, retention settings, encryption, data regions, or deletion behavior. Marketing language is a weaker source. It can point the team toward a question, but it should not be treated as proof that a contract, report, or technical control covers the planned workflow.

Keeping these evidence types separate prevents one familiar logo or badge from doing more work than it should.

What to Record

The register does not need to be elaborate. A spreadsheet, ticket, or procurement record can work if it preserves enough context for another reviewer to reconstruct the decision. For each item, record:

  1. The source title, owner, and location.
  2. The date it was retrieved and, when applicable, its effective period or report period.
  3. The legal entity, product, plan, feature, and region it covers.
  4. The conclusion the source supports.
  5. Conditions and limitations stated in the source.
  6. Questions that remain open and the person responsible for resolving them.
  7. The date or event that will trigger another review.

Short conclusions are more useful than broad labels. "Vendor says HIPAA compliant" is difficult to act on. "BAA offered for the Enterprise plan; analytics add-on not named; vendor confirmation pending" tells the next reviewer what is known and where the uncertainty sits.

The same discipline should be used for security evidence. Instead of recording "SOC 2 available," note the report type, review period, system description, relevant exceptions, complementary customer controls, and whether important subservice organizations are included or carved out.

Check the Operational Questions

Contracts and assurance reports are only part of the review. The intended use also depends on routine operational details.

Ask which sub-processors may create, receive, maintain, or transmit PHI. Confirm how administrators and support personnel obtain access, whether that access is logged, and how emergency support is handled. Review default retention, backup retention, deletion timing, export behavior, account termination, and the process for returning or destroying data.

Incident language deserves the same attention. Identify where the vendor describes security incidents and breach notification, who receives notice, and whether the timing and cooperation terms match the organization's requirements. Customer-side safeguards should also be explicit: identity management, multifactor authentication, role design, device controls, logging, staff training, approved integrations, and procedures for offboarding users.

A signed BAA does not configure the product. HHS risk-analysis guidance makes clear that regulated organizations must identify potential risks and vulnerabilities to all electronic PHI they create, receive, maintain, or transmit. The vendor's evidence informs that work; it does not perform the organization's risk analysis for it.

Use Evidence States Instead of a Single Verdict

A binary field labeled "compliant" hides too much. Evidence is often conditional, incomplete, inconsistent, or old. A small set of evidence states makes the record more honest:

  • Supported: the source directly supports the conclusion for the identified scope.
  • Conditional: the conclusion depends on a plan, configuration, contract, location, or customer action.
  • Missing: the needed source has not been obtained.
  • Conflicting: two sources disagree or describe different scopes.
  • Stale: the source no longer reflects the current product, contract, report period, or workflow.

These are evidence states, not compliance determinations. They help the organization route questions to the right owner and avoid treating silence as approval.

Review Again When Something Changes

An annual vendor review is useful, but a change in the workflow can make last month's evidence incomplete. Set event-based review triggers for a new contract or BAA, a plan change, a new integration, a material sub-processor update, revised retention terms, a new artificial intelligence feature, a security incident, or a change in the type of PHI being handled.

The register should also have an owner. Procurement may hold contracts, security may review assurance reports, privacy or compliance may assess uses and disclosures, and the operational team may know the actual configuration. Someone must be responsible for assembling those pieces and recording the final conditions of use.

Conclusion

A SaaS review is easier to defend when another person can see exactly what was reviewed, when it was reviewed, and which workflow the decision covered. Begin with the data path. Separate contractual, assurance, product, and marketing evidence. Record scope and dates. Preserve unresolved questions. Reopen the review when the service or workflow changes.

The purpose of a vendor evidence register is not to produce a universal badge. It is to make the reasoning behind a decision inspectable before PHI enters the workflow. Final decisions should remain with the organization's qualified legal, privacy, security, compliance, procurement, and operational professionals.

About the Author

Coco Yang is the Founder of ComplySaaS, an educational SaaS vendor compliance research project that organizes public HIPAA, BAA, PHI, and SOC 2 signals, source dates, workflow conditions, and verification questions. Her work is limited to documented vendor-research practice; she is not presenting herself as an attorney, auditor, healthcare provider, or compliance certifier. Company website: https://www.complysaas.com/

References

U.S. Department of Health and Human Services. "Guidance on HIPAA & Cloud Computing."

U.S. Department of Health and Human Services. "Business Associate Contracts."

U.S. Department of Health and Human Services. "Guidance on Risk Analysis."

National Institute of Standards and Technology. "SP 800-66 Rev. 2: Implementing the HIPAA Security Rule."

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Why Every Healthcare Facility Needs a Smart Hospital Security System

Written by Peter Lee, MSc, CIPP/US and Arif Khan researcher specializing in AI-driven security systems and healthcare compliance

The information provided is for educational purposes only and is not legal, consulting or IT advice.

Introduction

Healthcare facilities operate in one of the most complex and high-risk environments of any industry. Hospitals are open 24/7, manage large volumes of patients and visitors, and handle sensitive data, controlled substances, and critical care operations all at the same time. This combination creates a unique set of security and compliance challenges that cannot be addressed with traditional systems alone.

The scale of the issue is significant. According to healthcare safety data, incidents involving workplace violence, unauthorized access, and theft are rising across hospitals and care facilities. In addition, regulatory requirements such as the Health Insurance Portability and Security Act (HIPAA) place strict obligations on how patient data and physical access must be controlled. Even a single breach can lead to severe financial penalties, legal consequences, and reputational damage, which is enforced by the Office of Civil Rights (OCR).

At the same time, many healthcare facilities still rely on outdated surveillance and access systems that are limited to recording events rather than actively preventing them. These systems often fail to provide real-time visibility, making it difficult for administrators and compliance officers to respond quickly when incidents occur.

This is why modern hospital security systems are becoming essential rather than optional. A smart security system does more than monitor activity. It integrates surveillance, access control, and intelligent alerts into a unified platform that helps healthcare organizations protect patients, staff, and sensitive information while maintaining compliance.

The Complexity of Healthcare Environments Demands Smarter Security

Unlike typical commercial spaces, hospitals are highly dynamic environments. Emergency departments, patient wards, pharmacies, operating rooms, and administrative offices all operate simultaneously, each with different levels of access and risk.

Managing security in such an environment requires more than basic surveillance. It requires systems that can adapt to constant movement and provide clear visibility across all areas.

For example, a visitor entering a general waiting area may be appropriate, but the same individual entering a restricted ICU or medication storage area presents a serious risk. Without intelligent monitoring, distinguishing between normal and suspicious activity becomes difficult.

Modern hospital security systems address this by combining video surveillance with access control and real-time monitoring. This allows healthcare administrators to not only control who can enter specific areas but also verify and track activity as it happens.

The result?  A more controlled and transparent environment, which is critical for both safety and compliance.

Protecting Patient Safety and Staff Well-Being

Patient safety is the top priority in any healthcare facility. However, safety risks are not limited to medical issues alone. Security incidents such as unauthorized access, aggressive behavior, or theft can directly impact patient care.

Healthcare workers are also at increased risk - Studies have shown that healthcare professionals face higher rates of workplace violence compared to many other industries. This makes it essential for hospitals to have systems in place that can detect and respond to potential threats quickly.

Smart hospital security systems help mitigate these risks by providing continuous monitoring and real-time alerts. For instance, if unusual activity is detected in a restricted area or if a situation begins to escalate in a waiting room, security teams can be notified immediately.

This ability to respond quickly can prevent incidents from escalating and ensures a safer environment for both patients and staff.

Supporting HIPAA Compliance and Data Protection

Compliance is a critical concern for healthcare organizations. Regulations such as the Health Insurance Portability and Accountability Act (HIPAA) require strict control over access to patient information and sensitive areas.

Physical security plays a major role in compliance. Unauthorized access to records rooms, server areas, or administrative offices can lead to data breaches, which carry significant legal and financial consequences.

A modern hospital security system supports compliance by providing controlled access, detailed activity logs, and audit trails. These features allow organizations to track who accessed specific areas and when, which is essential for audits and investigations. This integrated approach helps ensure that compliance requirements are met while improving overall operational efficiency.

Preventing Unauthorized Access to Critical Areas

Hospitals contain several high-risk zones that require strict access control. These include pharmacies, operating rooms, ICUs, data centers, and storage areas for medical equipment.

Unauthorized access to these areas can result in serious consequences, including theft of controlled substances, tampering with equipment, or exposure of sensitive information.

Traditional systems often rely on static access permissions, which can become outdated as roles change. This creates gaps where individuals may retain access they no longer need.

Smart hospital security systems address this issue by enabling dynamic access control. Permissions can be updated in real time, ensuring that access is always aligned with current roles and responsibilities.

In addition, integrating access control with video surveillance provides an added layer of verification. Administrators can not only see who accessed a door but also confirm the activity visually, reducing the risk of misuse.

Improving Incident Response and Emergency Management

In healthcare settings, response time is critical. Whether it is a security incident, a medical emergency, or an environmental issue, delays can have serious consequences.

Smart security systems improve response time by providing real-time alerts and centralized monitoring. Instead of relying on manual reporting, incidents can be detected automatically and communicated to the appropriate teams immediately.

For example, if an unauthorized entry occurs in a restricted area or if environmental sensors detect abnormal conditions, alerts can be triggered instantly. Security and medical teams can then coordinate their response more effectively.

This level of coordination is especially important in large facilities where multiple departments must work together during emergencies.

Enhancing Operational Efficiency

Beyond safety and compliance, hospital security systems also contribute to operational efficiency.

Manual processes such as maintaining access logs, issuing credentials, and monitoring multiple systems can be time-consuming and prone to errors. As healthcare facilities grow, these inefficiencies become more pronounced.

A centralized security system streamlines these processes by integrating surveillance, access control, and alerts into a single platform. This reduces administrative workload and allows staff to focus on patient care rather than managing systems.

Additionally, data collected from security systems can provide valuable insights into facility usage, helping administrators optimize workflows and resource allocation.

Adapting to Modern Healthcare Challenges

Healthcare is evolving rapidly, and security systems must evolve with it.

Facilities are expanding, patient volumes are increasing, and technology is becoming more integrated into daily operations. At the same time, threats are becoming more sophisticated, requiring a more proactive approach to security.

Smart hospital security systems are designed to adapt to these challenges. They provide scalability, allowing facilities to expand without overhauling their infrastructure. They also support integration with other systems, creating a unified approach to security and operations.

This adaptability is essential for healthcare organizations that want to remain secure and compliant in a constantly changing environment.

FAQs

What are hospital security systems?

  • Hospital security systems are integrated solutions that combine surveillance, access control, and monitoring tools to protect patients, staff, and sensitive areas within healthcare facilities.

Why are smart security systems important in hospitals?

  • They provide real-time monitoring, improve response times, and support compliance with healthcare regulations, making them more effective than traditional systems.

How do these systems support HIPAA compliance?

  • They control access to sensitive areas, maintain detailed logs, and provide audit trails that help meet regulatory requirements.

Can hospitals use existing infrastructure?

  • Yes. Many modern systems are designed to work with existing IP cameras and infrastructure, reducing the need for costly replacements.

Do these systems improve patient safety?

  • Yes. By detecting and responding to risks quickly, they help create a safer environment for patients and healthcare staff.

Conclusion

Healthcare facilities face unique challenges that require more than basic security measures. The combination of high patient volumes, sensitive data, and strict regulatory requirements makes security a critical component of daily operations.

Modern hospital security systems provide the intelligence, integration, and real-time visibility needed to address these challenges effectively. They help protect patients, support staff, ensure compliance, and improve overall efficiency.  Solutions like Coram demonstrate how this can be implemented effectively. Coram’s hospital security platform works with existing IP cameras and integrates with access control systems and environmental sensors. It provides high-definition video monitoring, intelligent alerts, and centralized management, allowing healthcare facilities to maintain visibility and control without replacing their current infrastructure.

As healthcare environments continue to evolve, investing in smarter security systems is not just a technological upgrade. It is a necessary step toward safer, more resilient, and compliant healthcare operations.

About the Authors

Arif Khan is a writer and researcher specializing in AI-driven security systems, healthcare compliance, and modern surveillance technologies. He holds a B.Tech degree in Computer Science and works as a freelance writer covering topics related to AI, physical security, access control, and intelligent monitoring systems. His work focuses on helping organizations understand emerging security technologies and their role in improving safety, compliance, and operational efficiency.

Peter Lee is a writer and researcher specializing in AI-driven security systems and healthcare compliance. His work focuses on topics such as hospital security, HIPAA requirements, and modern surveillance technologies, helping organizations understand and implement effective security solutions.

References

American Institute of Healthcare Compliance (AIHC)

National Library of Medicine (NLM)

Occupational Safety and Health Administration (OSHA)

U.S. Department of Health & Human Services (HHS)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Vendor Compliance – Old Problem, New Risks

Written by Susan Lee Walberg, JD MPA CHC 

Compliance Officers are always stretched thin with many responsibilities, and those duties seem to constantly grow with each year and every new law or regulation. One of the more challenging areas to monitor is the compliance of our vendors and Business Associates.

I believe this is now more important than ever. Why? Because cybercrime, hacking, phishing, and impersonation schemes are rampant, and the cyber-crooks are now using AI to circumvent our (and our vendor’s) security measures.

How many times have we heard about a major breach, and the root cause was a failure to conduct a Security Risk Assessment or apply patches or software updates timely? A failure of routine training is also often to blame. Over 60% of breaches are caused by Business Associates, so this is an area of risk that I believe needs more attention.

Over the years, I have found that prevention is the best cure. There are several steps we can take on the front end to reduce the risk of non-compliance during the term of the Agreement.

1.  Compliance needs to be at the table BEFORE arrangements are entered into. It’s not unheard of, in a large health system, for the compliance officer to not even know about every joint venture or acquisition, but, when there’s a compliance problem at that entity, they are on the hook. It’s critical to build trust with leadership, and educate them as to why Compliance needs to be at the table. We need to understand what the arrangement is about, why we are doing it, and who is paying what to who. If Compliance isn’t informed and engaged, some of these other steps likely won’t happen.

2.  Due diligence is critical for new business partners. While the finance team reviews the balance sheet, Compliance needs to be reviewing the organization’s compliance program, culture and reputation. There should be a document list the Compliance reviews for acquisitions and partnerships, but even for contracted services, we want to take a peek and do some basic reviews.

  • Review their Compliance Plan (and how often it’s been reviewed and updated)
  • Have a conversation with their compliance, privacy, and/or security officer to get a better sense of how they operate
  • Find out if they’ve been subject to any investigations
  • Run a List of Excluded Individuals and Entities (LEIE) OIG check
  • Ask to see their most recent Security Risk Assessment, if ePHI is going to be involved

Pay careful attention to any referrals that are considered as part of the contract. These are not only for physicians, but they can also be an IT vendor or other provider of goods or services-there have been plenty of cases where companies, such as Electronic Medical Record (EMR) companies have been found in violation of the Anti-Kickback statute. Have an attorney review it if this isn’t your area of expertise. The bottom line is to ask yourself if the arrangement itself is appropriate.

Those are just some suggestions, but at least these activities would give you a sense of how much they tend to compliance. Also, it never hurts to do a basic Google search. If they aren’t a new organization, and if they have any ethical or legal issues, you will likely find reviews on the Better Business Bureau site and/or sites where employees and customers can give a rating/review. That activity alone can speak volumes if the organization has a culture problem.

3. Contract provisions need to include compliance. Although bad actors sign contracts all the time, it still helps protect       your organization and does show that you take compliance and ethics seriously. Some suggested provisions:

  • The vendor agrees to comply with all applicable laws, rules, and regulations, including False Claims Act, Stark, HIPAA, and any other that are key for your business and the type of services.
  • The vendor agrees that you are allowed to audit their processes and records that pertain to the services under the contract
  • The vendor agrees that all their employees are checked for disbarment and that none of their employees or contractors are disqualified to participate in government health care programs; and to notify you immediately if that changes.
  • The vendor agrees and attests that they have a compliance, privacy, and security program that meets or exceeds industry and regulatory standards, and that they maintain stringent security standards to protect the integrity of ePHI.
  • Breach notification and remediation procedures need to be detailed. How long after a breach is identified must you be notified? Who notifies clients? Review the breach response requirements under HIPAA and make sure you address those.
  • Data use is an important provision. Review your contract or Business Associate Agreement, keeping in mind that data is now as valuable as gold. Can your business partners sell your data? What if it’s de-identified? Are you comfortable with them doing so, and does your agreed-upon rate take that into account? The advent of AI makes data much more valuable.
  • Adherence and compliance to all Medicare regulations, especially if this is a contract for any business office, documentation, coding, or record review service.

4. Training requirements are not optional. Privacy, Security, and Compliance training should be provided to the vendor’s   employees, or they can take training you provide, if you have that option. If they have their own program, it’s totally acceptable to ask to see it. Ongoing data security training, in particular, is important due to the constantly evolving phishing and other schemes.

5. Make sure you have tight controls on granting access to your information. Your business partner can’t just get one log-in that everyone uses. That should be a core requirement for data access-unique user IDs and passwords.

Those are some key front-end steps. Once the agreement is in place, if the previous activities are completed there shouldn’t really be a heavy load of monitoring, absent some incident or breach. Here are a few things to consider:

  • Stay in contact with the process/contract owner and ask how things are going. If there are problems, that person is likely the first to know. Make sure they know to call you if something starts to go sideways.
  • Conduct any audits or monitoring you included in the contract, if you’re able to (it’s a resource issue, for sure)
  • Send occasional surveys to your vendors inquiring about their compliance, privacy, or security measures. This at least lets them know you are paying attention.
  • Touch base with their compliance, privacy, or security officers
  • Monitor training logs, if they receive training from you (or ask them to provide that information)
  • Look them up online now and then to see if there are any new complaints out there.
  • Get an audit of what information their employees are viewing-make sure it’s appropriate.

Monitoring your vendors can seem like just one too many things to do, and most of the time you will find that there are no red flags. Most businesses try to do the right thing. But it’s important to keep in mind how much of a risk they could pose to your organization, especially if they are handling patient information and/or billing functions. You don’t want to be looking back and wishing you had done it and having to explain that to your leadership!

About the Author Susan Lee Walberg, JD MPA CHC

Ms. Walberg is an author, attorney and healthcare compliance consultant. She is available to help anyone work through these processes and provides a full range of compliance-related services and books, including serving as a fractional Compliance or Privacy Officer, or in an interim role. She can be contacted by email at swalberg@compliancealacarte.com, or find more about services and books on her website at susanwalberg.com or on LinkedIn!

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 3: The Pros and Cons of Interoperability Frameworks in Health Care

Written by: Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC and Dr. Tami M. Harris, DM, PMP, LSSBB 

Introduction 

Interoperability frameworks are the connective tissue of modern healthcare data exchange, defining how systems communicate, the structure of the data, and how information flows securely across organizations.

As healthcare organizations – including hospitals, payers, clinicians, and technology vendors – face significant challenges to deliver care in an environment dominated by fragmented data, siloed and competing systems, the push to standardize how information is exchanged has taken center stage. These frameworks offer a pathway toward a more connected healthcare ecosystem—one where patient medical records are transmitted securely, providers have timely access to essential information, and organizations can reduce the inefficiencies that drive patient care, increased costs, lost or duplication of data, and delays.

In the AIHC Part 1 Article on Interoperability: CMS Interoperability Framework Project: Should We Be Concerned?  A comprehensive overview dives into  the Problem with System Fragmentation in Healthcare and Security Concerns in the CMS Interoperability Framework Project (Part 1).

In the AIHC Part 2 Article: Interoperability and System Fragmentation in Healthcare, the contributing writers discuss Communication, Compliance, and Strategies for Successful Integration Interoperability and System Fragmentation in Healthcare (Part 2).

In this AIHC Part 3 Article, we will now walk the readers through the Pros and Cons of Interoperability Frameworks in Healthcare. As AI, Revenue Cycle Management (RCM) automation, payer auditing, and value-based care accelerate, these frameworks are rapidly becoming the backbone of national healthcare operations.

But like any key technology standard, these frameworks come with real advantages—and real trade-offs. Below is a practical, balanced breakdown that leaders should understand before deciding to adopt or move forward with how they will integrate these systems.

Pros & Cons - Let’s Start with the Pros

1. Exchange of Data Between Systems

Data Exchange interoperability frameworks, such as Health Level 7 (HL7), Fast Healthcare Interoperability Resources (FHIR), and Trusted Exchange Framework and Common Agreement (TEFCA), will help reduce fragmentation by providing a common language for AI-Powered Electronic Medical Record (EMR) systems, RCM platforms, and payer applications.

According to the Centers for Medicare & Medicaid Services (CMS), the Voluntary Interoperability Frameworks are designed to enhance manual back-and-forth, enable faster claims processing, reduce denials, and improve clinical decision-making.

Why it matters - Unconnected systems, duplicate documentation, and lost data cost hospitals millions of dollars every year. Current CMS estimates indicate that interoperability frameworks can shrink those losses by streamlining data exchange and minimizing manual errors. Integrating data into EHRs demonstrates the growing impact of interoperability frameworks on reducing fragmentation.

2. Stronger Clinical Quality and Patient Safety

With data flowing unimpeded, clinicians have a complete picture of labs, meds, allergies, imaging, and histories—regardless of where care was delivered. This improves the accuracy of care, reduces avoidable errors, and supports real-time decision-support tools.

A Forward-Thinking Angle - AI-enabled audits in Clinical Documentation Improvement (CDI) and RCM are most effective when built on interoperable data. Interoperability should be the prerequisite for advanced analytics and real-time clinical decision support.

3. Reduce Operational Waste and Administrative Burden

Implementing CMS Voluntary Frameworks, such as CMS 9115-f , automates and streamlines much of the documentation exchange, eliminating repetitive reconciliation, data entry, and faxing.

The CMS Interoperability and Patient Access Final Rule require payers to use FHIR-based APIs for data exchange, which has proven to reduce prior authorization response times and administrative costs for providers.

Impact - Minimize human touchpoints → fewer mistakes → shorter AR cycles → more cash collected faster.

4. Better Compliance with Federal Requirements

The goal is to minimize risk by leveraging the Assistant Secretary for Technology Policy and the Office of the National Coordinator for HealthIT’s (ASTP/ONC) Interoperability Frameworks, such as HL7, FHIR, CMS interoperability rules, and TEFCA, by aligning organizations with regulatory expectations for data access, patient API rights, and cross-network exchange.

TEFCA, launched in 2024, establishes a nationwide framework for secure health information exchange, connecting providers, payers, and public health agencies. Compliance with TEFCA and FHIR standards is now required for participation in federal programs and for avoiding penalties.

Bottom line - Staying compliant now avoids future penalties and positions organizations to participate in larger national data networks.

5. Fuel for AI, Predictive Analytics, and RCM Algorithms

AI models thrive on clean, structured, standardized data (Federal Register, Health Data).
Interoperability frameworks give organizations the quality inputs needed for:

  • Automated Claims Integrity Checks
  • Audit Ready Data Pipelines
  • Predictive RCM Drift Alerts
  • CDI optimization
  • Denials Prediction

The FDA and CMS are piloting FHIR-based submissions for real-world data, enabling advanced analytics and predictive modeling for population health and revenue cycle management.

Forward-Looking Reality - Organizations that implement interoperable data models today are better positioned to lead tomorrow’s AI-enhanced revenue cycle and clinical innovation.

The Cons

1. High Upfront Cost and Long Implementation Time

Implementing interoperability is not a simple upgrade. Many organizations underestimate the scale and cost, leading to project delays and budget overruns. Interoperability initiatives require:

  • API Integration
  • Data Mapping
  • Security Upgrades
  • Staff Training
  • Vendor coordination
  • Workflow Redesign

Truth - Interoperability is not a plug-and-play upgrade—it will be transformational.

2. Legacy System Limitations

Legacy systems often; lack support for modern APIs, contemporary data formats, or real-time exchange. These outdated platforms create bottlenecks, limit adoption, and increased maintenance costs.

Real-World Impact - Even if one part of the RCM process is modernized, the weakest legacy interface can undermine the entire process.

3. Cybersecurity Risks Rise with Connectivity

Expanding connectivity through APIs and cross-organizational networks increases the risk of cyber threats. The U.S. Department of Health & Human Services (HHS) emphasizes that interoperability must be paired with robust cybersecurity measures to protect sensitive health information.

Forward risk - AI-powered cyberattacks target health care's interconnected data ecosystems. Interoperability without hardened defenses is dangerous.

Organizations will need to ensure stronger access controls, encryption, and incident response plans are in place for threat prevention.

4. Vendor Resistance and Proprietary Barriers

Some vendors still rely on closed or proprietary systems to “lock in” clients, making interoperability expensive or technically challenging. This practice can significantly hinder the seamless exchange of health information across organizations.

The ONC has repeatedly identified proprietary interfaces and lack of standardized APIs as major obstacles to nationwide interoperability. Proprietary health IT systems continue to present significant challenges to data sharing. These systems often require organizations to invest in costly custom integrations, which can result in persistent information silos.

Result - Organizations can get stuck negotiating costly interface fees or dealing with partial data exchange, which not only increases operational expenses but also limits the ability to provide coordinated, high-quality care.

5. Variation in Standards and Inconsistent Adoption

Even with frameworks like FHIR (HL7 FHIR) or TEFCA (TEFCA Governance), vendor implement differently.  There are variations in:

  • API Maturity
  • Profiles
  • Optional Fields Versioning
  • Create Ongoing Friction

Reality - Interoperability is only as strong as the weakest implementation in the network. The ONC Interoperability Standards Advisory underscores the need for consistent implementation and highlights gaps in adoption across the industry.

Summary: A High-Level Strategic View

Interoperability frameworks are rapidly becoming the backbone of a modern, connected healthcare ecosystem, offering benefits that extend well beyond simple data exchange —yet their impact is far from one-dimensional. Throughout this three-part AIHC series, we have explored the real and persistent challenges of system fragmentation, the security vulnerabilities exposed by national initiatives such as the CMS Interoperability Framework Project, and the practical strategies organizations can use to navigate and overcome communication and compliance barriers.

In this Part 3 article, we explored the significant advantages and real trade-offs that interoperability frameworks bring. These standards promise faster access to patient information, improved care coordination, and greater operational efficiency.  At the same time, it is important to realize that these benefits of interoperability in healthcare require rigorous governance, robust security, disciplined integration planning, and adaptability to evolving federal and state requirements, including market pressures Understand Interoperability in Healthcare.

As AI in RCM automation, payer oversight, and value-based care continue to accelerate, interoperability will become increasingly critical. Operational leadership that succeeds will be those who embrace connectivity with strategic foresight—leveraging the advantages while proactively managing the associated risks. 

Interoperability should be viewed not just as a technology requirement; it should be considered the de facto strategy and standard that will shape how healthcare delivers value, safeguards patients, and competes in a data-driven future.

About the Authors

Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC, is the Founder, Principal & Managing AI Consultant of P3 Quality, a Healthcare Tech Consulting Company. She is a Certified Artificial Intelligence Professional (CAIP) and a Certified Artificial Intelligence Medical Coder (CAIMC). In her current leadership role, she extracts and diagnoses core Drift in AI Medical Coding Models, thereby closing AI-Driven financial, quality, and compliance gaps. Corliss is also a published author of Artificial Intelligence, Rise, Survive, & Thrive In An AI-Powered World. She also serves on the AIHC Volunteer Education Committee.

Dr. Tami M. Harris, DM, PMP, LSSBB, is the Founder & Chief Operating Officer of H & H Consulting Group, Inc. With a doctorate in Management, she is recognized as a certified Lean Six Sigma Black Belt and Project Management Professional, reflecting a commitment to operational excellence and continuous improvement. In her current capacity as Portfolio Director for Middle and Back-office Revenue Cycle Management (RCM) AI Automation and Transformation, she leads strategic advisory initiatives, oversees practice leadership, and drives client engagement delivery to generate new value-streams through technology.

References:

  1. American Health Information Management Association. (2024). TEFCA Overview. AHIMA. https://www.ahima.org/
  2. Centers for Medicare & Medicaid Services (CMS). Interoperability and Patient Access Final Rule (CMS-9115-F). https://www.cms.gov/cms-9115-f
  3. Food and Drug Administration. (2025). Exploration of Health Level Seven Fast Healthcare Interoperability Resources for Use in Study Data Created From Real-World Data Sources for Submission to the Food and Drug Administration; Establishment of a Public Docket; Request for Comments. Federal Register, 90(77), 17067–17069. https://www.federalregister.gov/documents/2025/04/23/2025-06967/exploration-of-health-level-seven-fast-healthcare-interoperability-resources-for-use-in-study-data
  4. HL7 International. FHIR Overview. https://www.hl7.org/fhir/
  5. National Academy of Medicine. Proposing Interoperability Standards for Healthcare. https://www.federalregister.gov/algoritm-transparency
  6. Office of the National Coordinator for Health Information Technology (ONC). Interoperability Standards Advisory (ISA). https://www.healthit.gov/isa
  7. The Sequoia Project. TEFCA Framework and Common Agreement. https://sequoiaproject.org/tefca/
  8. Understand the four levels of Interoperability in Healthcare. www.wolterskluwer.com
  9. U.S. Department of Health & Human Services. (2024). Cybersecurity Program. https://www.hhs.gov/about/agencies/asa/ocio/cybersecurity/index.html

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Is it an Audit, Gap Analysis or Risk Assessment?

For Auditors and Compliance Officers 

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

New to Compliance & Auditing for Compliance?  This short article is #3 in a three-part series addressing various areas of auditing and monitoring healthcare providers for compliance.  You may want to read Article #1 – Importance of Compliance Audits and Article #2 Auditing for Anti-Kickback Statute Violations.

Introduction

A healthcare compliance audit checks adherence to laws (such as HIPAA, Stark, Anit-Kickback Statue, coding, billing rules) and includes reviewing written policies, assessing internal controls, verifying staff training, monitoring data security, examining processes, interviewing staff, and ensuring a robust reporting/corrective action process is in place.  This is all aimed at risk reduction and better patient care.

The focus of this article is to discuss the difference between a Gap Analysis and Risk Assessment when conducting an audit.

Conducting an Audit can be Complex

To audit, gap analyze, and risk assess healthcare compliance, an organization systematically identifies standards, gathers data, evaluates compliance gaps and threats, prioritizes issues, then create corrective plans.  This is followed by conducting monitoring audits and review to find and fix deficiencies before they become major problems. It is a continuous process.

Core Components of a Healthcare Compliance Audit often include:

Risk Assessment & Scope

  • Identifying high-risk areas (e.g., billing, privacy, patient safety) and defining what the audit will cover.

Performing a Documentation Review

  • Checking written policies, procedures, training records, consent forms, and compliance plans for completeness and accuracy.

Testing Internal Controls

  • Evaluating safeguards for data (EHR, access), billing, and operations to prevent fraud and errors.

Workforce Competency

  • Verifying that employees understand and follow policies through training logs and interviews.

Conducting Interviews & Observation

  • Talking to staff and watching workflows to see if policies are truly followed in practice.

HIPAA Compliance

  • Data Security & Privacy auditing to determine HIPAA/HITECH compliance, access controls, and breach protocols.

Billing & Coding Accuracy

  • Performing pre-billing and post-billing audits to ensure claims are correctly coded and comply with payer rules.

Reporting & Investigation

  • Assessing the effectiveness of hotlines, whistleblower protections, and how reported issues are handled.

Corrective Action Plan (CAP)

  • Developing and tracking steps to fix any identified compliance gaps.

Gap Analysis

The distance between where you are where you need to be

Conducting an audit often requires performing a gap analysis.  A gap analysis identifies the difference between your current state and desired compliance levels.   Simply put, it starts by defining the compliance goal, assesses current performance (what your organization is actually doing) and pinpointing exactly where the organization is falling short.

In healthcare compliance, a Gap Analysis finds what you're missing compared to a standard (e.g., Coding or HIPAA rules), showing the "what's missing" and "how far" from compliance, while a Risk Assessment identifies why you're vulnerable, evaluating the likelihood and impact of threats (like breaches) to determine what controls are truly needed to mitigate risk, forming two complementary steps to achieve full, effective compliance, not replacements for each other.

Key Steps for Risk Mitigation Gap Analysis:

1. First, start with defining the scope and objective.

  • Clearly state what you're analyzing (processes, compliance, performance) and the desired outcome or standard (e.g., regulatory compliance, industry best practice).

2. Next, define benchmarks, goals that need to be met.

  • Define the desired state. Establish benchmarks, goals, and ideal performance levels, often based on regulations, standards, or strategic objectives.
  • Create list of items being measured and evaluated.

3. Conduct an Evaluation to Assess Current State.

  • Document existing performance, processes, policies, and controls, gathering data through audits, interviews, and metrics.

4. Identify & Analyze Gaps.

  • Compare current vs. desired states to find discrepancies.
  • Use tools like SWOT or process mapping to visualize inefficiencies, as taught by AIHC in the Auditing for Compliance online course which addresses gap analysis.

5. Conduct Root Cause Analysis (RCA).

  • Dig deep to understand why gaps exist (e.g., outdated policies, lack of training, resource issues).

6. Prioritize or Rank by Severity.

  • Rank gaps by severity, impact, and risk level (e.g., using an impact/effort matrix) to focus on the most critical issues first.

7. Develop Action Plan (Remediation).

  • Create detailed plans with specific actions, assigned owners, resources, timelines, and success metrics to close each prioritized gap.

8. Implement & Execute.

  • The organization must act and ensure necessary resources and support are in place.

9. Monitor & Review.

  • Continuously track progress, measure results against KPIs, and make adjustments to ensure effective risk reduction.

10. Communicate & Report.

  • Share findings and progress with stakeholders to maintain transparency and buy-in.

Risk Assessment – The “Why” and “How Bad”

After identifying what's missing (the gaps), the risk assessment quantifies how bad those gaps are. The risk assessment evaluates potential threats to compliance and patient safety.  This process explains why gaps matter and dictates what to fix to manage risk effectively.  It includes an impact analysis, evaluating controls and calculate residual risk.

Difference between Gap Analysis & Risk Assessment:

Gap Analysis = Current vs. Standard

Risk Assessment = Threats/Vulnerabilities vs. Assets

Key steps for a risk assessment following a gap analysis:

1. Identify Risks from Gaps.
  • Take the identified gaps (e.g., lack of security training, outdated software) and pinpoint the specific threats or vulnerabilities they create (e.g., phishing, data breach, system failure).

2. Analyze Risk (Likelihood & Impact). For each identified risk, determine.

  • Likelihood: How probable is it that this risk will occur?
  • Impact/Severity: How bad would the consequences be (financial, operational, reputational) if it did happen?

3. Evaluate & Prioritize Risks.

  • Combine likelihood and impact to score each risk (e.g., High, Medium, Low) and prioritize them. Focus on high-impact, high-likelihood risks first.

4. Develop Mitigation (Control) Strategies.

  • For prioritized risks, design actions to eliminate, reduce, or transfer the risk. These are your control measures (e.g., implementing training, upgrading systems).

5. Record Findings & Controls.

  • Document the entire process, including identified risks, analysis, chosen controls, and responsibilities. This is often a legal requirement.

6. Implement Controls.

  • Put the planned actions into practice.  

7. Monitor & Review.

  • Don’t stop short, complete the cycle by regularly checking if controls are working and update the assessment as the environment, threats, or business needs change.

Auditing for Compliance

Even if you have some audit experience, taking an online course and certifying can fill-in knowledge gaps and provide essential skills to lead an audit team.

To become a lead auditor, many organizations will require you to complete a training course that covers auditing principles, management systems, and leadership skills, followed by passing an exam and gaining auditing experience, such as offered by the American Institute of Healthcare Compliance (AIHC), recognized as a Licensing/Certifying partner with the Centers for Medicare & Medicaid Services (CMS).

Resources to Stay Informed

Lead Auditors and Compliance Officers need to stay informed.  Subscribing to government notifications is one way.  You may also want to review current educational articles (free) published by the American Institute of Healthcare Compliance (AIHC)– click here for the Auditing category, and view all articles or by additional categories. 

Videos can be a helpful way to stay informed.  We recommend the following which may be of interest for you or members of your audit and compliance team!

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

  • Auditing for Compliance online training course by the American Institute of Healthcare Compliance.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing, Corporate Compliance

Auditing for Anti-Kickback Statute Violations

Written by the AIHC Education Department 

About the AKS 

The Anti-Kickback Statute [42 U.S.C. § 1320a-7b(b)] 

The AKS is a criminal law that prohibits the knowing and willful payment of "remuneration" to induce or reward patient referrals or the generation of business involving any item or service payable by the Federal health care programs (e.g., drugs, supplies, or health care services for Medicare or Medicaid patients). Remuneration includes anything of value and can take many forms besides cash, such as free rent, expensive hotel stays and meals, and excessive compensation for medical directorships or consultancies.

In some industries, it is acceptable to reward those who refer business to you or your organization. However, in the Federal health care programs, paying for referrals is a crime.  

The statute covers the payers of kickbacks, those who offer or pay remuneration, as well as the recipients of kickbacks. Yes, the law applies to those who solicit or receive remuneration. Each party's intent is a key element of their liability under the AKS.

The Department of Justice (DOJ), the Department of Health and Human Services Office of Inspector General (OIG), and the Centers for Medicaid and Medicare Services (CMS) are all charged with enforcing these laws. Filing claims to any Federal healthcare program related to an AKS violation may also violate the False Claims Act (FCA). From there, it just gets more complicated because kickbacks in health care can lead to:

  • Overutilization
  • Increased program costs
  • Corruption of medical decision making
  • Patient steering
  • Unfair competition

The kickback prohibition applies to all sources of referrals, even patients. For example, where the Medicare and Medicaid programs require patients to pay copays for services, you are generally required to collect that money from your patients. Routinely waiving these copays could implicate the AKS and you may not advertise that you will forgive copayments. It can be used to induce patients to choose a specific provider's services or to prescribe their products instead of cheaper alternatives. However, you are free to waive a copayment if you make an individual determination that the patient cannot afford to pay or if your reasonable collection efforts fail. It is also legal to provide free or discounted services to uninsured people.

The Government does not need to prove patient harm or financial loss to the programs to show that a physician violated the AKS. A physician can be guilty of violating the AKS even if the physician actually rendered the service and the service was medically necessary. Taking money or gifts from a drug or device company or a durable medical equipment (DME) supplier is not justified by the argument that you would have prescribed that drug or ordered that wheelchair even without a kickback.

Consequences for Violating the AKS

AKS Criminal penalties and administrative sanctions for violating the AKS include fines, jail terms, and exclusion from participation in the Federal health care programs as follows:

  • Civil penalties: The CMPL allows the Office of Inspector General (OIG) to impose civil penalties for violations of the Anti-Kickback Statute. These penalties include a fine of up to $50,000 per violation plus three times the value of the illegal kickback (treble damages).
  • Criminal penalties: Violating the Anti-Kickback Statute is a felony and can also lead to criminal penalties, including fines of up to $100,000 and imprisonment for up to 10 years.
  • Other consequences: In addition to financial and criminal penalties, individuals found guilty of kickback violations can be excluded from participation in federal health care programs. The Office of Inspector General (OIG) has the authority to exclude both individuals and entities. Claims that include items or services resulting from a violation are not payable and may constitute false or fraudulent claims under the False Claims Act.

Criminals Target Healthcare Providers

Physicians make an attractive target for kickback schemes because you can be a source of referrals for fellow physicians or other health care providers and suppliers. As a provider, you decide what drugs your patients use, which specialists they see, and what health care services and supplies they receive. And criminals count on providers not understanding the law. This point stresses the need to audit for potential AKS violations and to have a healthcare attorney familiar with the AKS to review any agreements in advance to avoid an unlawful situation.

There are still handshake deals made, where there is no written agreement, where remuneration is made in exchange for some form of kickback. Even these “unwritten” arrangements should be audited for potential issues.

Auditors are typically not attorneys, but an internal auditor can receive training to review for potential violations, then refer questionable situations to the Compliance Officer who will forward to outside legal counsel for further investigation and corrective action.  Why outside legal counsel? In-house legal counsel is likely to have reviewed or written the agreement in question, creating a conflict of interest in being involved in any aspect of the audit process.

Common targeting methods

  • Payments disguised as legitimate compensation:
    • Paying providers for patient referrals disguised as "bonuses" or "referral fees".
    • Offering or paying for patient information that is used to market to potential enrollees.
    • Paying providers for "consulting," "advising," or "research" when the primary purpose is to secure referrals.
    • Overpaying doctors for speaking engagements.
    • Payments for office space, phlebotomy, or other services that are inflated or not legitimate, intended to be a form of compensation for referrals.
  • In-kind or indirect benefits:
    • Providing free or below-market rent, equipment, supplies, or staff.
    • Offering gifts or tokens of appreciation that could be perceived as a reward for referrals.
    • Giving practice subsidies or covering expenses that are not otherwise required.
    • Free or discounted office space or supplies.
    • Gifts, meals, or tickets to events.
  • Compensation based on referral volume or status:
    • Offering payments or bonuses that are based on the number of patients a provider refers to a particular plan or service.
    • Providing remuneration that is contingent on the health status or demographics of the patients referred.
  • Exploiting "safe harbors":
    • Structuring arrangements that appear to be compliant (e.g., professional courtesy programs or recruitment benefits) but have the primary purpose of inducing referrals.

Safe Harbor Considerations

Safe harbors are specific, pre-approved exceptions to the AKS that provide immunity from prosecution if followed precisely. They are voluntary, and not all financial arrangements have a safe harbor. An arrangement must meet all conditions of a specific safe harbor to be protected; partial compliance is not enough.

To be protected by a safe harbor, an arrangement must fit squarely in the safe harbor and satisfy all of its requirements. Some safe harbors address personal services and rental agreements, investments in ambulatory surgical centers, and payments to bona fide employees.

Congress set forth a number of factors to consider when developing safe harbors; while not binding with respect to any assessment of an arrangement that implicates the Federal anti-kickback statute (other than in the establishment or modification of safe harbors (see section 1128D(a)(2) of the Act, 42 U.S.C. 1320a–7d(a)(2)), they are instructive for assessing risk under the Federal anti-kickback statute.

For example, OIG’s advisory opinions frequently consider factors such as overutilization, increased costs to Federal health care programs, corruption of medical decision making, patient steering, and unfair competition.

One of OIG’s Compliance Program Guidance documents reiterates these factors by highlighting the following questions to help guide an assessment of any problematic arrangements or practices identified as a red flag:

  • Does the arrangement or practice have the potential to interfere with, or skew, clinical decision making?
  • Does the arrangement or practice have the potential to increase costs to Federal health care programs or beneficiaries?
  • Does the arrangement or practice have the potential to increase the risk of overutilization or inappropriate utilization?
  • Does the arrangement or practice raise patient safety or quality of care concerns?
  • Does the arrangement or practice raise concerns related to steering patients or providers to a particular item or service?

The health care community and its partners must be mindful of these types of factors and question arrangements that implicate the Federal anti-kickback statute. An affirmative answer to one or more of these questions is a red flag signaling an arrangement or practice may be particularly susceptible to the harm caused by fraud and abuse.

AKS Audit Checklist

To audit for Anti-Kickback Statute (AKS) violations, create a comprehensive inventory of financial relationships, assess existing contracts against AKS safe harbors, conduct internal reviews of transactions and billing, and implement a robust compliance program that includes regular monitoring and staff training. Key steps include analyzing payments to ensure they are for fair market value, are not tied to referrals, and that arrangements are documented properly with signed agreements and legal review.

  • Build an inventory of all financial relationships 
    • List all transactions -
      • Document all financial relationships and transactions with potential AKS implications, including those with physicians, vendors, and other healthcare entities.
    • Categorize relationships –
      • Group arrangements by type, such as physician recruitment, medical directorships, lease agreements, and professional service agreements.
    • Work with legal counsel –
      • Involve legal counsel to ensure no relevant relationships with government health care programs are missed.
  • Review and assess existing arrangements 
    • Check against safe harbors –
      • Compare each financial arrangement against the requirements of relevant AKS safe harbors. For example, safe harbor requirements often include a written agreement, specifies the services, is for at least one year, and compensation is at fair market value and not tied to the volume or value of referrals.
    • Verify compensation –
      • Ensure compensation is set in advance and is not changed retroactively, especially within the first year of a new contract. Compensation should not be based on referrals or revenue generated from referrals.
    • Examine billing practices –
      • Review billing and payment practices to confirm they align with contractual terms and are at fair market value.
  • Conduct data analysis and transaction-level audits 
    • Obtain relevant data –
      • Gather data from general ledgers, vendor files, payroll, and payment records.
    • Select a sample –
      • Randomly select a sample of payments for a detailed audit.
    • Validate transactions –
      • Cross-reference payments against supporting documentation, such as invoices, timesheets, and contracts.
    • Use data analytics –
      • Employ data analytics to identify patterns and trends that might indicate improper conduct. This is an area where implementing Artificial Intelligence programs can provide speed and accuracy.
  • Audit Results Can Strengthen the Compliance Program 
    • Implement policies –
      • Audit results can help the Compliance Department establish written policies and procedures for compliance with the AKS.
    • Provide training –
      • Regularly train staff and key stakeholders on the AKS and how to identify and report potential violations. This includes discussion with all providers during on-boarding and at least annually as part of compliance training.
    • Ensure due diligence –
      • Conduct due diligence on new and existing business partners and perform background checks, such as checking the OIG's exclusion list.
    • Monitor and report –
      • Create a system for ongoing monitoring and auditing and establish a confidential way for employees to report suspected violations.

Conclusion

Audits proactively uncover compliance gaps and vulnerabilities before they become a problem, allowing for corrective action to be taken.

Auditing for AKS (Anti-Kickback Statute) compliance is crucial for mitigating risk because it identifies and addresses vulnerabilities that could lead to severe legal penalties, financial fines, and reputational damage. Regular audits help ensure adherence to laws and regulations, protect company assets, and maintain the trust of stakeholders by demonstrating a commitment to ethical practices.

Monitoring for AKS violations helps to prove a commitment to ethical and legal conduct. These types of audits help maintain a positive brand image and public trust.

Remember, regular auditing fosters a company-wide culture of accountability and continuous improvement, where employees are more aware of and committed to compliance requirements.

About the AIHC Education Department

The American Institute of Healthcare Compliance (AIHC) Education Department provides classroom and web-based training and certification for healthcare administrators and professionals. It includes an enrollment department that processes registrations, and a research and development arm focused on creating new educational products. Learn more about short course and certification offerings in addition to free and low-priced Continuing Education Unit (CEU) certification renewal single short courses or CEU packages. Visit our website https://dev-main.aihc-assn.org/

References

  • Centers for Medicare and Medicaid Services - WPS Government Services on Waivers of Deductibles and Co-Insurance
  • Department of Justice Enforcement Activities
  • Office of Inspector General Fraud & Abuse Laws, Physician Roadmap
  • American Institute of Healthcare Compliance, Healthcare Compliance certification program

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 2: Interoperability and System Fragmentation in Healthcare

Communication, Compliance, and Strategies for Successful Integration Written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The healthcare industry continues to face significant fragmentation, as disparate systems and siloed data limit effective care coordination. Interoperability standards such as Fast Healthcare Interoperability Resources (FHIR) and regulatory requirements under the 21st Century Cures Act, HIPAA, and CMS interoperability mandates are reshaping the compliance landscape. Yet achieving interoperability is not only a technical challenge but also a communication and compliance imperative.

This article examines the compliance risks associated with fragmentation and explores communication strategies for healthcare leaders. Key areas include:

  1. educating internal teams on compliance-related adoption of FHIR standards;
  2. framing Health Information Exchanges (HIEs) and cloud-based platforms as compliance safeguards against information blocking and OCR investigations; and
  3. aligning staff expectations, training, and accountability during technology rollouts.

A compliance lens reinforces that interoperability is not optional—it is a regulatory obligation tied to patient rights, organizational risk management, and quality of care.

Introduction

Fragmentation in healthcare undermines not only care delivery but also compliance. When disparate systems fail to exchange data, organizations risk violating federal mandates related to patient access, privacy, and data sharing. The 21st Century Cures Act Final Rule requires organizations to provide patients with immediate electronic access to their records, while HIPAA’s Right of Access standard reinforces patients’ legal rights to their health information. Failure to comply may trigger Office for Civil Rights (OCR) investigations, penalties, or settlements (Office for Civil Rights [OCR], 2022).

Improved interoperability through standards like FHIR, Health Information Exchanges (HIEs), and cloud-based systems offers an opportunity to reduce compliance risk and strengthen organizational integrity. However, success depends on how effectively compliance leaders communicate changes, engage stakeholders, and align workflows with regulatory requirements.

The Compliance Risks of Fragmentation

System fragmentation is not merely an operational inconvenience—it directly impacts compliance.

Examples include:

  • HIPAA Violations: Incomplete or inaccessible patient records increase the likelihood of Privacy and Security Rule breaches.
  • Information Blocking: Under the ONC Cures Act Final Rule, organizations that delay or restrict information exchange risk penalties (ONC, 2020).
  • Claims and Billing Errors: Disconnected systems make it harder to validate documentation, increasing false claims liability.
  • Audit Vulnerability: Fragmented workflows create inconsistent documentation trails, raising red flags during audits.

From a compliance standpoint, breaking down silos is both a regulatory necessity and a risk management strategy.

Communicating FHIR Adoption Through a Compliance Lens

FHIR APIs are central to the ONC’s interoperability framework, enabling standardized, patient-directed data sharing. For compliance teams, communicating FHIR adoption requires balancing technical education with regulatory framing.

Compliance challenges:

  • Misunderstanding FHIR as a 'technology upgrade' instead of a compliance requirement.
  • Lack of clarity on how FHIR supports HIPAA Right of Access and ONC information blocking provisions.
  • Resistance from staff unfamiliar with regulatory consequences of noncompliance.

Communication strategies:

  • Regulatory Framing: Position FHIR adoption as a compliance mandate tied to federal law, not optional IT innovation.
  • Policy Alignment: Provide updated compliance policies showing how FHIR workflows safeguard patient rights.
  • Cross-Functional Briefings: Engage compliance, IT, and clinical teams together to prevent siloed communication.

By making compliance central to the conversation, staff understand that interoperability is not just about efficiency—it is about avoiding penalties and protecting patient trust.

Cloud-Based Platforms and HIEs: Compliance Safeguards, Not Just Technology

Cloud platforms and HIEs expand data access across organizational boundaries. From a compliance perspective, these tools mitigate risks of information blocking and improve adherence to patient access laws.

Compliance benefits:

  • Audit Readiness: Centralized data improves traceability for regulatory reviews.
  • HIPAA Safeguards: Cloud vendors increasingly offer compliance-certified environments with robust encryption and BAAs (business associate agreements).
  • Patient-Centered Compliance: HIEs reduce delays in record sharing, directly supporting Right of Access standards.

Communication priorities:

  • Stress that cloud and HIE adoption is not only about efficiency, but also about reducing exposure to OCR penalties.
  • Clarify shared accountability between providers, payers, and vendors for maintaining compliance safeguards.
  • Use compliance case studies (e.g., OCR enforcement actions) to illustrate the risks of fragmented systems.

Framing cloud and HIE adoption as compliance risk mitigation ensures leadership buy-in and reduces resistance to sharing data.

Managing Staff Expectations and Training During Rollouts

System-wide rollouts require a compliance-centered training approach. Staff must not only learn technical workflows but also understand the compliance stakes tied to their responsibilities.

Compliance-driven communication strategies include:

  1. Mandatory Training: Incorporating interoperability requirements into annual compliance training to emphasize regulatory obligations.
  2. Expectation Management: Clearly communicating that delays or barriers in sharing data could constitute information blocking.
  3. Super-User Networks: Assigning compliance-trained 'champions' to monitor adherence to workflows and escalate issues.
  4. Policy Updates: Linking rollout communication to policy changes in HIPAA access, data governance, and security protocols.

When staff view interoperability as part of their compliance role—not just an IT task—they are more likely to integrate it into daily practice.

Discussion - The intersection of interoperability and compliance is where organizational risk management, patient rights, and clinical efficiency converge. Communication breakdowns perpetuate system fragmentation, which can escalate into compliance violations. Conversely, transparent communication strategies—emphasizing regulation, patient safety, and organizational accountability—align stakeholders and promote sustainable interoperability.

Compliance leaders serve as translators between regulators, IT professionals, and clinicians. Their role is not only to enforce standards but also to ensure that staff understand why interoperability matters: to safeguard patients, maintain regulatory standing, and strengthen organizational trust.

Conclusion

Fragmentation is more than a technological problem; it is a compliance vulnerability. Interoperability initiatives such as FHIR adoption, HIE participation, and cloud migration reduce fragmentation but require strong communication strategies to succeed. From a compliance lens, effective communication ensures that staff recognize interoperability as a regulatory requirement, not an optional upgrade.

Ultimately, interoperability is a cornerstone of healthcare compliance and patient rights. By embedding compliance in communication, training, and strategy, organizations can break down data silos, mitigate risk, and deliver safer, more coordinated care.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • Adler-Milstein, J., Holmgren, A. J., & Kralovic, P. (2021). The impact of electronic health record interoperability on care quality and patient safety. Health Affairs, 40(9), 1427–1435. https://doi.org/10.1377/hlthaff.2021.00234
  • Cresswell, K., & Sheikh, A. (2017). Organizational issues in the implementation and adoption of health information technology innovations: An interpretive review. International Journal of Medical Informatics, 100, 63–76. https://doi.org/10.1016/j.ijmedinf.2017.01.001
  • Lin, S. C., Jha, A. K., & Adler-Milstein, J. (2020). Electronic health records and health care quality: Current evidence and future directions. Annual Review of Medicine, 71, 35–50. https://doi.org/10.1146/annurev-med-052218-020647
  • Mandel, J. C., Kreda, D. A., Mandl, K. D., Kohane, I. S., & Ramoni, R. B. (2016). SMART on FHIR: A standards-based, interoperable apps platform for electronic health records. Journal of the American Medical Informatics Association, 23(5), 899–908. https://doi.org/10.1093/jamia/ocv189
  • Office for Civil Rights (OCR). (2022). Enforcement highlights: Right of Access Initiative. U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html
  • Office of the National Coordinator for Health Information Technology (ONC). (2020). 21st Century Cures Act: Interoperability, information blocking, and the ONC Health IT Certification Program final rule. Federal Register, 85(85), 25642–25961.
  • Vest, J. R., Ancker, J. S., & Bates, D. W. (2019). Health information exchange: Persistent challenges and new strategies. Journal of the American Medical Informatics Association, 26(4), 325–331. https://doi.org/10.1093/jamia/ocy135

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 1: CMS Interoperability Framework Project: Should We Be Concerned?

Part 1: The Problem with System Fragmentation in Healthcare and Security Concerns 

Co-authored by Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 


The CMS Interoperability Framework is a call to action for health data networks that want to make what should already work actually work—by voluntarily meeting the CMS Interoperability Framework criteria to be designated as a CMS-Aligned Network.

This is a voluntary blueprint for modern health data exchange that puts patients and providers first. It is open, standards-based, and market-friendly so that the industry can stop theoretical debates and start delivering real results. CMS is offering shared infrastructure and clearly defined criteria for 2026.

The CMS Interoperability Framework doesn't mean centralizing all medical record data in a single location in the US. CMS is aligning networks to allow different types of health data sources, including health information networks, exchanges and other health technology platforms, to align with CMS goals for interoperability. The focus is on making it easier for different healthcare systems and applications to share and exchange medical information securely and efficiently. Here's what that means in simpler terms:

Think of it like different computer programs speaking the same language.

Currently, many healthcare systems use different formats and ways of organizing data. The CMS Interoperability Framework aims to establish common standards, especially using FHIR APIs, so that systems can understand and exchange information smoothly, regardless of where the data is stored.

  • A FHIR (Fast Healthcare Interoperability Resources) API is a standardized interface for exchanging health information between different healthcare systems using modern, web-based principles.
  • It acts as a shared "menu" that allows different software applications and platforms to "speak the same language," enabling them to request, retrieve, and share data like patient records, lab results, and other administrative or clinical information in a consistent format (JSON or XML).

It empowers patients and providers with access to medical information.

  • The framework promotes patient access to their health records through apps of their choice and makes it easier for providers to access the full patient history at the point of care.

It's a roadmap and a call to action, not a central database.

  • CMS is encouraging healthcare organizations, including networks, EHR systems, providers, and payers, to adopt common standards for data exchange, improving overall data sharing across the fragmented healthcare landscape.

It emphasizes data availability and standards, but it doesn't create a national repository.

  • The focus is on making it easier to share data between existing systems and promoting the use of standards like FHIR APIs and USCDI (United States Core Data for Interoperability).

So, instead of physically pulling all medical records into one place, the CMS Interoperability Framework is about creating a more connected system that allows patient data to flow securely between different locations and organizations, ultimately benefiting patient care and efficiency.

CMS Interoperability and the Risks of Sharing Patient Data with Big Tech Companies

The Centers for Medicare & Medicaid Services (CMS) has launched an ambitious Health Technology Ecosystem initiative aimed at creating a public-private partnership that facilitates seamless data exchange among patients, providers, and payers. As stated on the CMS website, Making Health Tech Great Again is a bold step toward modernizing our digital health ecosystem.

While details and operational aspects are still being finalized, partnerships have been publicly announced with major tech companies like Amazon, Apple, Google, Microsoft AI, OpenAI, and others, which signal a transformative shift in how healthcare data is accessed and shared. On July 30, 2025 CMS.gov posted a Press Release White House, Tech Leaders Commit to Create Patient-Centric Healthcare Ecosystem which states “More than 60 companies pledged to work collaboratively to deliver results for the American people in the first quarter of 2026. Twenty-one networks pledged to meet the CMS Interoperability Framework criteria to become CMS Aligned Networks. Eleven health systems or providers committed to participate and support patient use, and seven EHRs committed to facilitate data exchange and help “kill the clipboard.” At the same time, these collaborations also raise critical questions about data privacy, security, and governance.

Should we be concerned?

The CMS Health Tech Ecosystem initiative is overseen by the CMS Senior Advisor for Technology and supported by senior officials at the Department of Health and Human Services (HHS). Its mission is to promote a secure patient-centered digital healthcare system that would allow for ease of distribution, exchange, portability, and use of electronic health information. Fundamentally, this initiative seeks to improve patient access and enhance the efficiency of the healthcare industry. Its aim is to connect healthcare data sets that are currently siloed across disparate systems so that patients, providers, and healthcare payers will have reliable access to electronic medical records through a voluntary alignment. However, what lessons can be learned from the Change Healthcare breach?

Security Risks and Lessons Learned from the Change Healthcare Breach

A significant reminder of the vulnerabilities in extensive healthcare data systems is the February 2024 ransomware attack on Change Healthcare. Threat actors exploited the business associate’s lack of multifactor authentication, gaining unauthorized remote access via stolen credentials. Insufficient third-party vendor security postures create both upstream and downstream vulnerabilities across the healthcare ecosystem.

In the Change Healthcare breach, inadequate security controls resulted in widespread disruptions, including delays in medical treatments and prescriptions, stalled claims processing and reimbursements, and fragmented financial and operational access and delivery. These events underscore the need for comprehensive data governance, continuous security monitoring, and resilient infrastructure to safeguard protected health information (PHI). Most importantly, the lessons learned highlight the criticality of data confidentiality, integrity, and availability to ensure trust and continuity in patient care.

Along those lines, it is meaningful to act as informed advocates and to engage in mission-aligned questions, such as:

  • What minimum security standards must CMS’s third-party vendors and data brokers meet to safeguard data protection?
  • How is patient transparency ensured, and how is informed consent managed across diverse platforms?
  • Who holds accountability for data misuse or breaches, and what oversight mechanisms are in place to ensure compliance?

Conclusion

CMS's initiative for a more connected and patient-centered healthcare system offers significant benefits. But the public/private voluntary alignment must be grounded in data governance, responsible management of sensitive information, and a foundation of trust, transparency, and robust security—particularly in an innovative landscape shaped by public/private partnerships.

Please watch for Part 2: Interoperability and System Fragmentation in Healthcare: Communication, Compliance, and Strategies for Successful Integration, written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE.

About the Authors

Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC, is a member of the AIHC Volunteer Education Committee. Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS, is the Chief Executive Officer at the American Institute of Healthcare Compliance.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Importance of Addressing Shadow AI for HIPAA Compliance

Criminal Use of Artificial Intelligence (AI) Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 

The process of identifying and containing a breach can be lengthy and expensive, particularly in healthcare, in addition to eroding patient trust.  Breaches can disrupt critical healthcare operations, leading to delays in patient care and financial losses due to closing emergency departments and cancellation of appointments. Healthcare providers are legally obligated to notify affected individuals and provide credit monitoring services, which incurs substantial costs. This article addresses AI use by cyber criminals and summarizes 2024-2025 breach findings as reported by IBM’s 2025 Report.

Introduction

In 2025, the average cost of a healthcare data breach is $7.42 million, according to a recent report by IBM. Even with a reduction of $2.35 million in breach cost to the healthcare sector, healthcare breaches remain the most expensive of all studied industries for 14 consecutive years! This figure represents a decrease compared to the previous year but still signifies the highest average cost across all industries. The 2025 IBM report, conducted by Ponemon Institute, sponsored and analyzed by IBM, is based on data breaches experienced by 600 organizations globally from March 2024 through February 2025.

Shadow AI security incidents cost more - Security incidents involving Shadow AI carried an added cost. They contributed USD 200,000 to the global average breach cost. This higher cost was likely driven by longer detection and containment times for these security incidents, approximately a week longer than the global average.

According to Suja Viswesan, Vice President, Security and Runtime Products, IBM "The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it."

She also states that "The report revealed a lack of basic access controls for AI systems, leaving highly sensitive data exposed, and models vulnerable to manipulation. As AI becomes more deeply embedded across business operations, AI security must be treated as foundational. The cost of inaction isn't just financial, it's the loss of trust, transparency and control."

Employees may turn to Artificial Intelligence (AI) tools to speed up tasks, solve problems, or improve productivity. However, there are risks associated with employees using AI tools, like ChatGPT, Midjourney, or AI-powered assistants, without IT's knowledge or permission, such as Shadow AI being used by criminals. Using AI tools that don't comply with regulations (like GDPR or HIPAA) can result in fines and legal issues. 

Shadow AI

Shadow AI refers to the unauthorized use of artificial intelligence (AI) tools and models within an organization, often bypassing IT oversight and security protocols.

AI tools are being used by cyber criminals to launch smarter attacks.  Shadow AI tools can introduce unsecured APIs, unmanaged integrations, or other vulnerabilities that attackers can exploit.  To reduce the risk of an AI generated attack, it is important to address Shadow AI. 

As AI becomes integral to operations, AI security incidents have the potential to disrupt a range of business activities, including compromising sensitive data and disrupting patient care (i.e. ransomware attacks locking access to important patient treatment records).  IBM’s report identifies the following:

  • Security for AI is lacking  
    • The Cost of a Data Breach Report 2025 – the AI Oversight Gap quantifies the extent to which attackers are taking advantage of this deficiency and successfully targeting AI models and applications. While the share of breaches involving AI security incidents are small, IBM researchers expect them to grow as AI vendors gain greater market share and penetration into enterprise systems. Shadow AI is of particular concern.
  • Impacts of security incidents involving Shadow AI  
    • Among organizations that experienced a security incident involving Shadow AI, 44% suffered data compromise. Another 41% reported increased security costs as a result of those incidents. Operational disruption was more widespread than incidents involving authorized AI. These results suggest Shadow AI incidents have an outsized impact on downstream breach issues that extend beyond data security.
  • Researchers found 16% of breaches involved attackers using AI
    • Most of these breaches focused on human manipulation through phishing (37%) or deepfake attacks (35%).
  • Supply chain compromise was the most common cause of AI security incidents
    • Security incidents involving AI models and applications were varied, but one type clearly claimed the top ranking: supply chain compromise (30%), which includes compromised apps, APIs and plug-ins. Following supply chain compromise were model inversions (24%) and model evasions (21%). Incidents involving prompt injections and data poisoning made up 17% and 15% of cases respectively.
  • Unsanctioned AI security incidents were more common than sanctioned AI
    • Shadow AI may go undetected by an organization, and attackers can exploit its vulnerabilities when employees use it. Security incidents involving Shadow AI accounted for 20% of breaches, which is 7 percentage points higher than those security incidents involving sanctioned AI. A further 11% of breached organizations were unsure if they experienced a Shadow AI incident.

Foster a Culture of Responsible AI to Reduce Risk

Healthcare organizations can cultivate a culture of responsible AI by prioritizing ethical considerations and extensive workforce training regarding Shadow AI tools and how to avoid an attack.  A few tips to reduce risk are listed below.

Build communication with your workforce - Instead of penalizing your workers for using AI tools without permission, find out what they’re using and why. Their feedback could be useful in highlighting the gaps in your technology stack and governance policies. This allows you to either optimize your workflows or find a way of integrating the tool into them, thereby moving them from unsanctioned “Shadow AI” to legitimate AI tools.

  • A modern data stack is a collection of tools and technologies that are used to manage and analyze data in a particular organization or business. It includes various software, programming languages, frameworks, and platforms that can be used to extract, store, process, and visualize data.

Develop Clear Policies - Establish guidelines for AI tool usage, including approved tools and security protocols. This requires inter-departmental teamwork.  When integrating AI tools into your business, make sure that IT, operations, and governance departments are aligned.

  • For example, operations might want to use the tool in a way that compromises HIPAA security. Another example is when IT evaluates the tool for security but doesn’t understand the need for privacy in this assessment, which is the main concern for governance.
  • By bringing all these departments together, you will create better policies for responsible AI use and oversight that work for everyone.

Effectively Communicate Policies - Provide workforce training and support. Educate employees about the risks of Shadow AI and offer resources for using AI responsibly. By investing in training and education, you inform your workforce of potential pitfalls and consequences. At the same time, you train those unfamiliar with such tools so they can utilize them effectively as well. Whether it’s GenAI or AI-powered automation, using it responsibly helps reduce your security vulnerabilities and helps your employees perform better.

Implement Authentical methods - Today, many attackers are logging in rather than hacking in, according to IBM’s report. To combat this issue, it’s critical to prevent attackers from obtaining those credentials in the first place. One of the most effective ways to do so is by ensuring all human users adopt modern, phishing-resistant authentication methods, such as passkeys. These technologies are designed to eliminate the vulnerabilities of traditional passwords and one-time codes, making it significantly harder for attackers to intercept or misuse login credentials.

Monitor and Manage AI Usage - AI models and applications can pose significant risks if left unchecked. Consider including tools powered by AI and automation which can augment already overburdened security teams. They can significantly reduce the volume of alerts; identify at-risk data; spot security gaps and threats earlier; detect in-progress breaches; and enable faster, more precise attack responses.

Conclusion

The rapid evolution of AI technology presents a challenge to existing regulatory frameworks. Relying solely on HIPAA, not originally designed specifically for AI, leaves gaps in addressing AI-specific risks.

When employees use Shadow AI, healthcare organizations lose visibility and control over how PHI is being accessed, processed, and stored. This makes it difficult to ensure that HIPAA's Privacy and Security Rules are being followed. Shadow AI tools may not have the same robust security measures in place as approved, HIPAA-compliant systems, making them vulnerable to cyberattacks and data breaches. If sensitive patient information (Protected Health Information or PHI) is exposed through these unauthorized channels, it constitutes a HIPAA violation, triggering potential fines legal repercussions and reputational damage. Another consideration is the lack of required Business Associate Agreements. Many AI tools are developed by third-party vendors. If these vendors handle PHI without a Business Associate Agreement (BAA) in place, another HIPAA enforcement action could be looming as Shadow AI usage bypasses the essential BAA requirement, exposing healthcare organizations to significant risk.

About the author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS. Joanne is the Chief Executive Officer of the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor and investigator in the healthcare field.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More