Patient Rights and Informed Care
Patient-rights compliance reaches far beyond posting a notice in the lobby. Hospitals need reliable processes covering privacy, informed consent, communication assistance, visitation, access to records, grievance handling, freedom from abuse, and the safe use of restraints or seclusion.
A grievance log should show when the complaint was received, who investigated it, what evidence was reviewed, whether immediate protection was required, how the hospital responded, and what systemic correction followed. Repeated grievances involving the same department can be an early warning of a larger quality problem.
Hospitals should also verify that patients with disabilities or limited English proficiency can meaningfully understand important information. Staff should know how to obtain qualified communication assistance rather than relying automatically on relatives, children, or unapproved translation applications.
EMTALA and Emergency Department Compliance
The Emergency Medical Treatment and Labor Act requires Medicare-participating hospitals with emergency services to provide an appropriate medical screening examination when an individual seeks examination or treatment for a possible emergency medical condition. When an emergency medical condition is identified, the hospital must provide stabilizing treatment within its capabilities or arrange an appropriate transfer.
These protections apply regardless of a patient’s insurance status or ability to pay. Registration questions must not delay screening or stabilizing treatment. CMS provides current EMTALA requirements and interpretive resources.
The compliance review should examine the central emergency department log, waiting-room departures, transfers, refusals, on-call response, obstetric emergencies, ambulance interactions, and cases in which financial questions arose before screening.
Transfer documentation should demonstrate the patient’s condition, the reason for transfer, acceptance by the receiving facility, risks and benefits, available medical records, and the transportation arrangements used.
Quality Assessment and Performance Improvement
A compliant Quality Assessment and Performance Improvement program should identify meaningful patient-safety problems, prioritize high-risk issues, implement measurable interventions, and determine whether the changes worked.
Collecting data is not the same as improving quality. A dashboard may show an increase in patient falls, central-line infections, medication errors, or readmissions. The compliance question is whether the hospital investigated the pattern, identified contributing factors, assigned corrective actions, and measured outcomes.
QAPI should also connect with infection prevention, discharge planning, medication management, complaints, adverse events, and compliance investigations. Fragmented data can conceal patterns that become obvious when reviewed together.
Infection Prevention and Antibiotic Stewardship
An active infection-prevention program should cover healthcare-associated infection surveillance, standard and transmission-based precautions, hand hygiene, personal protective equipment, injection safety, environmental cleaning, reprocessing, exposure management, and outbreak response.
The CDC’s core practices provide a widely used foundation for infection prevention across healthcare settings. They address leadership support, education, patient and worker safety, surveillance, standard precautions, and monitoring of adherence. The CDC describes its core infection-control practices as fundamental standards applicable across healthcare settings.
Hospitals also need an antibiotic-stewardship program capable of monitoring and improving antimicrobial use. The program should have leadership support, accountable clinical ownership, pharmacy expertise, tracking, reporting, education, and practical interventions. CDC’s hospital stewardship framework explains the core structural and procedural elements.
Observation matters here. Training records cannot prove that employees perform hand hygiene at the correct moments, follow isolation procedures, or disinfect shared equipment between patients.
HIPAA Privacy, Security and Breach Response
HIPAA compliance should be divided into privacy, cybersecurity, individual rights, and incident response. Combining everything under a general “HIPAA training completed” entry makes meaningful oversight difficult.
The HIPAA Security Rule requires appropriate administrative, physical, and technical safeguards for electronic protected health information. Hospitals need an accurate and thorough risk analysis covering the ePHI they create, receive, maintain, or transmit. HHS states that the analysis should identify risks and vulnerabilities and feed directly into risk management. HHS provides detailed guidance on documenting and updating a HIPAA risk analysis.
The scope should include electronic health records, email, cloud platforms, connected medical devices, backup systems, remote access, mobile devices, imaging systems, legacy applications, vendors, and interfaces through which health information moves.
Hospitals should test whether access matches job responsibilities, terminated accounts are disabled promptly, privileged activity is reviewed, vulnerabilities are remediated, backups can be restored, and incident-response procedures work under realistic conditions.
A ransomware event is not merely an IT outage. It may affect the confidentiality, integrity, and availability of ePHI, disrupt clinical care, trigger breach analysis, and expose failures in contingency planning.
When unsecured protected health information is breached, notification duties may apply to affected individuals, HHS, and sometimes the media. For breaches affecting 500 or more individuals, HHS notification must be made without unreasonable delay and no later than 60 days after discovery. Different timing applies to smaller breaches. HHS explains the federal breach-notification process and deadlines.
For healthcare leaders responsible for privacy, security, risk management, or organizational oversight, a deeper understanding of HIPAA can make these checklist requirements easier to apply in practice. Our HIPAA Compliance Training – Executive Certification Program provides structured training across privacy, security, breach response, and executive compliance responsibilities.
Billing, Coding and Healthcare Fraud Prevention

Hospitals should audit whether billed services were ordered, medically necessary, performed, documented, coded correctly, and submitted to the appropriate payer. High-risk areas can include inpatient admission status, evaluation and management coding, observation services, modifiers, duplicate claims, medical necessity, cost reports, teaching-physician requirements, and services provided by excluded individuals.
Compliance reviews must also cover the False Claims Act, Anti-Kickback Statute, physician self-referral law commonly called the Stark Law, Civil Monetary Penalties Law, and federal exclusion authorities.
The Anti-Kickback Statute is intent-based and generally prohibits knowingly and willfully offering, paying, soliciting, or receiving remuneration to induce or reward referrals involving federal healthcare program business. Stark is a separate, technical prohibition governing certain physician referrals where a financial relationship exists, unless an exception applies.
Hospitals should not treat contract approval as a procurement formality. Physician compensation, medical directorships, leases, recruitment arrangements, vendor benefits, joint ventures, free services, and referral relationships may require legal and fair-market-value review. HHS OIG notes that claims connected to kickbacks or Stark violations may also create False Claims Act exposure. The OIG’s fraud and abuse guidance explains how these federal laws interact.
Overpayments should be investigated promptly. The review should determine the cause, affected claims, repayment requirements, and whether the problem extends beyond the original sample.
Workforce Credentials, Safety and Training
The hospital should verify professional licenses, certifications, privileges, competencies, background requirements, and exclusion status throughout employment or affiliation. A credential that was valid at hiring may later expire, be restricted, or be revoked.
OSHA compliance should address the hazards employees actually face. Healthcare workers may be exposed to bloodborne pathogens, respiratory hazards, chemicals, hazardous drugs, radiation, lifting injuries, sharps injuries, workplace violence, and other serious risks. OSHA identifies the federal standards and occupational hazards relevant to healthcare facilities.
For employees with occupational exposure to blood or other potentially infectious materials, the Bloodborne Pathogens Standard requires an exposure-control approach that includes universal precautions and appropriate protective measures. Hospitals should review sharps injuries, exposure follow-up, engineering controls, hepatitis B vaccination procedures, and annual updates to the exposure-control plan.
Training should reflect role and risk. A billing specialist, emergency nurse, laboratory technician, facilities employee, physician, executive, and IT administrator should not receive identical compliance education.
Completion data alone is weak evidence of effectiveness. Hospitals should use assessments, observations, exercises, audits, and incident trends to determine whether employees can apply the required procedures.

Medication, Controlled Substances and Laboratory Compliance
Medication-management reviews should examine ordering, dispensing, preparation, storage, administration, reconciliation, monitoring, adverse-event reporting, and high-alert medication safeguards.
Controlled substances require additional oversight. Hospitals should monitor access, inventory movement, waste, discrepancies, unusual ordering patterns, theft, and significant loss. Records must support reconciliation from receipt through administration, transfer, wastage, or disposal.
Recent enforcement demonstrates why this area cannot be treated as a pharmacy-only concern. In July 2026, the DEA announced a settlement involving alleged hospital-system failures related to controlled-substance recordkeeping and reporting, including failure to notify the agency of thefts or significant losses. The DEA’s announcement describes the identified recordkeeping and reporting failures.
Hospital testing sites also require careful inventory. Under the Clinical Laboratory Improvement Amendments, a facility may be treated as a laboratory if it performs even one test on human material to provide information used in diagnosis, prevention, treatment, or health assessment. This can include waived testing performed outside the central laboratory. CMS explains which testing facilities require CLIA certification.
The hospital should identify every location performing testing and confirm that the correct certificate, personnel qualifications, quality-control procedures, and documentation are in place.
Emergency Preparedness and Operational Resilience
Emergency preparedness must account for more than natural disasters. Hospitals should consider cyberattacks, infectious-disease outbreaks, utility failure, mass-casualty events, supply disruption, severe weather, internal violence, evacuation, and loss of critical vendors.
The plan should be based on a facility-specific risk assessment. It should address patient continuity, communications, staffing, alternate care locations, medication and oxygen supplies, medical records, utilities, transportation, evacuation, sheltering, and coordination with community partners.
Exercises should test decisions under pressure rather than merely confirm that employees attended. After-action reports should identify failures, assign responsibility, establish deadlines, and document retesting.
Vendor and Business Associate Oversight
Hospitals frequently depend on vendors for cloud hosting, billing, transcription, medical devices, telehealth, staffing, waste management, laboratories, pharmacy services, and patient communication. Outsourcing the service does not eliminate the hospital’s risk.
Before engagement, the hospital should determine what information and systems the vendor can access, whether a HIPAA business associate agreement is required, what security controls are present, how incidents will be reported, whether subcontractors are used, and how data will be returned or destroyed.
Monitoring should be proportional to risk. A vendor hosting ePHI or supporting a critical clinical system requires closer oversight than a supplier with no access to patients, systems, or sensitive information.
How to Make the Checklist Audit-Ready
Every checklist entry should identify the accountable owner, applicable authority, required control, supporting evidence, last review date, finding, risk rating, remediation deadline, and validation result.
Avoid recording “compliant” without explanation. A stronger entry states exactly what was tested, which records were sampled, what period was covered, what exceptions were found, and how the reviewer reached the conclusion.
Sampling should also reflect risk. Reviewing five randomly selected records may reveal routine documentation errors, but it may not detect failures involving overnight transfers, high-risk medications, temporary workers, privileged system accounts, or unusual financial arrangements. Targeted samples are often necessary.
When a finding is corrected, an independent reviewer should confirm that the corrective action works. Closing an issue because a manager reports that it has been addressed creates weak evidence and allows repeat problems to survive.
Common Hospital Compliance Mistakes
The most common weakness is treating compliance as an annual event. Hospital risks change whenever software is introduced, a vendor is hired, a clinical service expands, employees change roles, regulations evolve, or a serious incident occurs.
Another mistake is relying on policies without testing practice. A technically accurate policy provides little protection when employees do not know it exists or when operational systems make compliance difficult.
Hospitals also weaken their programs by keeping compliance risks in separate departments. A medication discrepancy may involve patient safety, controlled-substance diversion, billing, employee conduct, cybersecurity, and reporting obligations at the same time.
Finally, organizations sometimes close findings without measuring whether the correction lasted. Sustainable remediation requires follow-up testing.