The Compliance Checklist Every Hospital Should Use

Is your hospital truly compliance-ready? Use this hospital compliance checklist to review CMS, HIPAA, EMTALA, OSHA, safety, training, and more.

The Compliance Checklist Every Hospital Should Use

A hospital can deliver excellent clinical care and still face serious exposure because a policy is outdated, a risk assessment is incomplete, or staff cannot prove that required procedures were followed.

Hospital compliance is the coordinated system used to meet healthcare, patient-safety, privacy, billing, workplace, and operational obligations.

It is what connects written policies with everyday clinical decisions. It is why hospitals must monitor compliance continuously rather than relying on annual training. It is how leadership demonstrates that identified risks were investigated and corrected. It is also what protects patients, employees, public funds, and the hospital’s ability to operate.

In this blog, you will learn how to build a practical U.S. hospital compliance checklist, which areas require the closest attention, what evidence reviewers expect, and how to turn a static checklist into an effective compliance program.

Why Hospitals Need More Than an Annual Compliance Review

Hospital compliance is not governed by one law or regulator. A single facility may need to satisfy Medicare Conditions of Participation, HIPAA, EMTALA, OSHA standards, federal fraud and abuse laws, controlled-substance requirements, laboratory rules, state licensing conditions, accreditation standards, and local public-health obligations.

The exact requirements depend on the hospital’s location, services, ownership, payer relationships, patient population, and accreditation status. A psychiatric hospital, critical access hospital, teaching hospital, children’s hospital, and general acute-care hospital will not have identical compliance profiles.

For Medicare and Medicaid participation, hospitals must meet the federal health and safety requirements established through the Centers for Medicare & Medicaid Services Conditions of Participation. CMS surveyors assess compliance through observations, interviews, policy reviews, and patient-record examinations. A policy that exists only on paper will not demonstrate effective implementation. CMS explains that its Conditions of Participation form the health and safety foundation for participation in Medicare and Medicaid.

A useful checklist must therefore test three separate questions: whether the hospital has established the required process, whether employees follow it, and whether the hospital can produce reliable evidence.


The Essential Hospital Compliance Checklist

This checklist provides a federal baseline for U.S. hospitals. It should be supplemented with state law, professional licensing rules, payer requirements, accreditation standards, and service-specific obligations.

Free resource

Hospital Compliance Checklist

A 4-page checklist covering all 21 regulatory domains your compliance program is expected to control — what to verify, the evidence to retain, and how often to review it.

Download the PDF

Governance and Compliance Accountability

A hospital’s compliance program needs visible ownership. The governing body should receive enough information to understand material risks rather than receiving a simple statement that annual training was completed.

Effective oversight normally includes a compliance officer with sufficient independence, a multidisciplinary compliance committee, confidential reporting channels, consistent investigation procedures, disciplinary standards, and a process for monitoring corrective actions.

The hospital should maintain a current risk register that identifies the responsible owner, applicable requirement, control, evidence source, severity, remediation deadline, and status of each issue. High-risk findings should remain visible until evidence confirms that the problem has been corrected.

A closed investigation is not necessarily a corrected risk. If an audit finds that nurses are using shared credentials, for example, instructing employees to stop does not resolve the underlying issue. The hospital may also need to change access controls, investigate affected records, retrain staff, monitor compliance, and assess whether a reportable privacy incident occurred.

CMS Conditions of Participation and Survey Readiness

The Medicare Conditions of Participation at 42 CFR Part 482 cover core hospital functions including the governing body, patient rights, quality assessment and performance improvement, medical staff, nursing services, medical records, pharmaceutical services, infection control, discharge planning, emergency services, and physical environment.

Survey readiness should be part of routine operations, not an emergency project launched when a surveyor arrives. CMS’s hospital survey guidance makes clear that compliance can be examined through observations, interviews, and document or record reviews. The hospital must therefore be able to demonstrate that its policies are understood and followed. The CMS State Operations Manual provides the hospital survey protocol and interpretive guidance.

Leadership should regularly trace selected patients through admission, assessment, treatment, medication administration, transfer, and discharge. This reveals gaps that isolated department audits may miss.

CMS Conditions of Participation and Survey Readiness

Patient Rights and Informed Care

Patient-rights compliance reaches far beyond posting a notice in the lobby. Hospitals need reliable processes covering privacy, informed consent, communication assistance, visitation, access to records, grievance handling, freedom from abuse, and the safe use of restraints or seclusion.

A grievance log should show when the complaint was received, who investigated it, what evidence was reviewed, whether immediate protection was required, how the hospital responded, and what systemic correction followed. Repeated grievances involving the same department can be an early warning of a larger quality problem.

Hospitals should also verify that patients with disabilities or limited English proficiency can meaningfully understand important information. Staff should know how to obtain qualified communication assistance rather than relying automatically on relatives, children, or unapproved translation applications.


EMTALA and Emergency Department Compliance

The Emergency Medical Treatment and Labor Act requires Medicare-participating hospitals with emergency services to provide an appropriate medical screening examination when an individual seeks examination or treatment for a possible emergency medical condition. When an emergency medical condition is identified, the hospital must provide stabilizing treatment within its capabilities or arrange an appropriate transfer.

These protections apply regardless of a patient’s insurance status or ability to pay. Registration questions must not delay screening or stabilizing treatment. CMS provides current EMTALA requirements and interpretive resources.

The compliance review should examine the central emergency department log, waiting-room departures, transfers, refusals, on-call response, obstetric emergencies, ambulance interactions, and cases in which financial questions arose before screening.

Transfer documentation should demonstrate the patient’s condition, the reason for transfer, acceptance by the receiving facility, risks and benefits, available medical records, and the transportation arrangements used.


Quality Assessment and Performance Improvement

A compliant Quality Assessment and Performance Improvement program should identify meaningful patient-safety problems, prioritize high-risk issues, implement measurable interventions, and determine whether the changes worked.

Collecting data is not the same as improving quality. A dashboard may show an increase in patient falls, central-line infections, medication errors, or readmissions. The compliance question is whether the hospital investigated the pattern, identified contributing factors, assigned corrective actions, and measured outcomes.

QAPI should also connect with infection prevention, discharge planning, medication management, complaints, adverse events, and compliance investigations. Fragmented data can conceal patterns that become obvious when reviewed together.


Infection Prevention and Antibiotic Stewardship

An active infection-prevention program should cover healthcare-associated infection surveillance, standard and transmission-based precautions, hand hygiene, personal protective equipment, injection safety, environmental cleaning, reprocessing, exposure management, and outbreak response.

The CDC’s core practices provide a widely used foundation for infection prevention across healthcare settings. They address leadership support, education, patient and worker safety, surveillance, standard precautions, and monitoring of adherence. The CDC describes its core infection-control practices as fundamental standards applicable across healthcare settings.

Hospitals also need an antibiotic-stewardship program capable of monitoring and improving antimicrobial use. The program should have leadership support, accountable clinical ownership, pharmacy expertise, tracking, reporting, education, and practical interventions. CDC’s hospital stewardship framework explains the core structural and procedural elements.

Observation matters here. Training records cannot prove that employees perform hand hygiene at the correct moments, follow isolation procedures, or disinfect shared equipment between patients.

HIPAA Privacy, Security and Breach Response

HIPAA compliance should be divided into privacy, cybersecurity, individual rights, and incident response. Combining everything under a general “HIPAA training completed” entry makes meaningful oversight difficult.

The HIPAA Security Rule requires appropriate administrative, physical, and technical safeguards for electronic protected health information. Hospitals need an accurate and thorough risk analysis covering the ePHI they create, receive, maintain, or transmit. HHS states that the analysis should identify risks and vulnerabilities and feed directly into risk management. HHS provides detailed guidance on documenting and updating a HIPAA risk analysis.

The scope should include electronic health records, email, cloud platforms, connected medical devices, backup systems, remote access, mobile devices, imaging systems, legacy applications, vendors, and interfaces through which health information moves.

Hospitals should test whether access matches job responsibilities, terminated accounts are disabled promptly, privileged activity is reviewed, vulnerabilities are remediated, backups can be restored, and incident-response procedures work under realistic conditions.

A ransomware event is not merely an IT outage. It may affect the confidentiality, integrity, and availability of ePHI, disrupt clinical care, trigger breach analysis, and expose failures in contingency planning.

When unsecured protected health information is breached, notification duties may apply to affected individuals, HHS, and sometimes the media. For breaches affecting 500 or more individuals, HHS notification must be made without unreasonable delay and no later than 60 days after discovery. Different timing applies to smaller breaches. HHS explains the federal breach-notification process and deadlines.

For healthcare leaders responsible for privacy, security, risk management, or organizational oversight, a deeper understanding of HIPAA can make these checklist requirements easier to apply in practice. Our HIPAA Compliance Training – Executive Certification Program provides structured training across privacy, security, breach response, and executive compliance responsibilities.


Billing, Coding and Healthcare Fraud Prevention

Hospitals should audit whether billed services were ordered, medically necessary, performed, documented, coded correctly, and submitted to the appropriate payer. High-risk areas can include inpatient admission status, evaluation and management coding, observation services, modifiers, duplicate claims, medical necessity, cost reports, teaching-physician requirements, and services provided by excluded individuals.

Compliance reviews must also cover the False Claims Act, Anti-Kickback Statute, physician self-referral law commonly called the Stark Law, Civil Monetary Penalties Law, and federal exclusion authorities.

The Anti-Kickback Statute is intent-based and generally prohibits knowingly and willfully offering, paying, soliciting, or receiving remuneration to induce or reward referrals involving federal healthcare program business. Stark is a separate, technical prohibition governing certain physician referrals where a financial relationship exists, unless an exception applies.

Hospitals should not treat contract approval as a procurement formality. Physician compensation, medical directorships, leases, recruitment arrangements, vendor benefits, joint ventures, free services, and referral relationships may require legal and fair-market-value review. HHS OIG notes that claims connected to kickbacks or Stark violations may also create False Claims Act exposure. The OIG’s fraud and abuse guidance explains how these federal laws interact.

Overpayments should be investigated promptly. The review should determine the cause, affected claims, repayment requirements, and whether the problem extends beyond the original sample. 

Workforce Credentials, Safety and Training

The hospital should verify professional licenses, certifications, privileges, competencies, background requirements, and exclusion status throughout employment or affiliation. A credential that was valid at hiring may later expire, be restricted, or be revoked.

OSHA compliance should address the hazards employees actually face. Healthcare workers may be exposed to bloodborne pathogens, respiratory hazards, chemicals, hazardous drugs, radiation, lifting injuries, sharps injuries, workplace violence, and other serious risks. OSHA identifies the federal standards and occupational hazards relevant to healthcare facilities.

For employees with occupational exposure to blood or other potentially infectious materials, the Bloodborne Pathogens Standard requires an exposure-control approach that includes universal precautions and appropriate protective measures. Hospitals should review sharps injuries, exposure follow-up, engineering controls, hepatitis B vaccination procedures, and annual updates to the exposure-control plan.

Training should reflect role and risk. A billing specialist, emergency nurse, laboratory technician, facilities employee, physician, executive, and IT administrator should not receive identical compliance education.

Completion data alone is weak evidence of effectiveness. Hospitals should use assessments, observations, exercises, audits, and incident trends to determine whether employees can apply the required procedures.

 Medication, Controlled Substances and Laboratory Compliance

Medication-management reviews should examine ordering, dispensing, preparation, storage, administration, reconciliation, monitoring, adverse-event reporting, and high-alert medication safeguards.

Controlled substances require additional oversight. Hospitals should monitor access, inventory movement, waste, discrepancies, unusual ordering patterns, theft, and significant loss. Records must support reconciliation from receipt through administration, transfer, wastage, or disposal.

Recent enforcement demonstrates why this area cannot be treated as a pharmacy-only concern. In July 2026, the DEA announced a settlement involving alleged hospital-system failures related to controlled-substance recordkeeping and reporting, including failure to notify the agency of thefts or significant losses. The DEA’s announcement describes the identified recordkeeping and reporting failures.

Hospital testing sites also require careful inventory. Under the Clinical Laboratory Improvement Amendments, a facility may be treated as a laboratory if it performs even one test on human material to provide information used in diagnosis, prevention, treatment, or health assessment. This can include waived testing performed outside the central laboratory. CMS explains which testing facilities require CLIA certification.

The hospital should identify every location performing testing and confirm that the correct certificate, personnel qualifications, quality-control procedures, and documentation are in place.

 Emergency Preparedness and Operational Resilience

Emergency preparedness must account for more than natural disasters. Hospitals should consider cyberattacks, infectious-disease outbreaks, utility failure, mass-casualty events, supply disruption, severe weather, internal violence, evacuation, and loss of critical vendors.

The plan should be based on a facility-specific risk assessment. It should address patient continuity, communications, staffing, alternate care locations, medication and oxygen supplies, medical records, utilities, transportation, evacuation, sheltering, and coordination with community partners.

Exercises should test decisions under pressure rather than merely confirm that employees attended. After-action reports should identify failures, assign responsibility, establish deadlines, and document retesting.

 Vendor and Business Associate Oversight

Hospitals frequently depend on vendors for cloud hosting, billing, transcription, medical devices, telehealth, staffing, waste management, laboratories, pharmacy services, and patient communication. Outsourcing the service does not eliminate the hospital’s risk.

Before engagement, the hospital should determine what information and systems the vendor can access, whether a HIPAA business associate agreement is required, what security controls are present, how incidents will be reported, whether subcontractors are used, and how data will be returned or destroyed.

Monitoring should be proportional to risk. A vendor hosting ePHI or supporting a critical clinical system requires closer oversight than a supplier with no access to patients, systems, or sensitive information.

 How to Make the Checklist Audit-Ready

Every checklist entry should identify the accountable owner, applicable authority, required control, supporting evidence, last review date, finding, risk rating, remediation deadline, and validation result.

Avoid recording “compliant” without explanation. A stronger entry states exactly what was tested, which records were sampled, what period was covered, what exceptions were found, and how the reviewer reached the conclusion.

Sampling should also reflect risk. Reviewing five randomly selected records may reveal routine documentation errors, but it may not detect failures involving overnight transfers, high-risk medications, temporary workers, privileged system accounts, or unusual financial arrangements. Targeted samples are often necessary.

When a finding is corrected, an independent reviewer should confirm that the corrective action works. Closing an issue because a manager reports that it has been addressed creates weak evidence and allows repeat problems to survive.

 Common Hospital Compliance Mistakes

The most common weakness is treating compliance as an annual event. Hospital risks change whenever software is introduced, a vendor is hired, a clinical service expands, employees change roles, regulations evolve, or a serious incident occurs.

Another mistake is relying on policies without testing practice. A technically accurate policy provides little protection when employees do not know it exists or when operational systems make compliance difficult.

Hospitals also weaken their programs by keeping compliance risks in separate departments. A medication discrepancy may involve patient safety, controlled-substance diversion, billing, employee conduct, cybersecurity, and reporting obligations at the same time.

Finally, organizations sometimes close findings without measuring whether the correction lasted. Sustainable remediation requires follow-up testing.


Frequently Asked Questions

01 What is a hospital compliance checklist? +

A hospital compliance checklist is a structured control document used to evaluate whether a facility meets applicable healthcare, privacy, patient-safety, billing, workplace, licensing, and operational requirements. It should connect every requirement to an owner, review process, evidence source, finding, and corrective action.

02 How often should a hospital review compliance? +

Compliance monitoring should occur continuously, while the frequency of individual reviews should depend on risk and applicable requirements. High-risk areas such as infection control, billing, emergency care, access management, medication safety, and controlled substances may require monthly or continuous monitoring. A formal enterprise-wide risk assessment should also be performed periodically and when material operational changes occur.

03 Does accreditation replace CMS compliance? +

No. Accreditation may provide a recognized survey pathway for certain organizations, but the hospital remains responsible for meeting applicable federal participation requirements. State licensing, HIPAA, OSHA, fraud and abuse, DEA, CLIA, and other obligations may also remain independently enforceable.

04 Is annual compliance training enough? +

No. Annual education can support the compliance program, but it cannot replace role-specific onboarding, competency testing, policy updates, monitoring, incident-based retraining, or corrective action. Hospitals must be able to demonstrate that employees apply the requirements in practice.

05 Who should own the hospital compliance checklist? +

The compliance officer may coordinate it, but ownership should be distributed among accountable leaders in clinical care, privacy, cybersecurity, quality, infection prevention, pharmacy, billing, human resources, laboratory services, facilities, emergency management, and procurement. The governing body retains ultimate oversight responsibility.

06 Does this checklist cover state requirements? +

No. It provides a federal starting point. Hospitals must add state licensing, privacy, public-health reporting, professional practice, employment, controlled-substance, facility, and other jurisdiction-specific requirements.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.