GoHealthcare Practice Solutions | Healthcare MSO for Pain, Spine & Orthopedic Practices
  • Who we are
  • What We Do
  • Leadership
  • Case Studies
  • Knowledge Center
    • 8 Excellence Frameworks™
    • CMS Ambulatory Specialty Model (ASM)
    • Procedure Library
  • Specialty Guides
    • Spine Specialty Hub
    • Pain Management Specialty Hub
    • Neurosurgery Specialty Hub
    • Physical Medicine & Rehabilitation (PM&R) Specialty Hub
    • Orthopedic Surgery Specialty Guide
    • Ambulatory Surgery Center Specialty Hub
  • Prior Authorization Resource Center
    • Overview
    • Our Prior Authorization Process
  • Revenue Cycle Management Resource Center
    • Overview
    • RCM Process
    • Revenue Integrity
  • CLIENT PORTAL
  • READ OUR BLOG
  • GoHealthcare Pain and MSK Value-Based Reimbursement Center™
  • Frequently Asked Questions and Answers - GoHealthcare Practice Solutions
  • Remote Therapeutic Monitoring, Remote Physiologic Monitoring, and Chronic Care Management

GoHealthcare Regulatory, Risk & Compliance Excellence Framework™

GoHealthcare Regulatory, Risk & Compliance Excellence Framework™
GoHealthcare Regulatory, Risk & Compliance Excellence Framework™

Developed by GoHealthcare Practice Solutions

Part of the GoHealthcare Knowledge Center

Pillar 04 of the GoHealthcare Operational Excellence Framework™

GoHealthcare Regulatory, Risk & Compliance Excellence Framework™

Embedding Governance, Accountability, Risk Intelligence, and Audit Readiness Across Healthcare Operations

A comprehensive enterprise operating model for healthcare regulatory governance, risk management, compliance infrastructure, revenue integrity, privacy, security, patient safety, responsible artificial intelligence, and continuous improvement.

Regulatory, risk and compliance governance establishes the organizational structure through which a healthcare organization identifies its obligations, evaluates exposure, assigns accountability, makes compliance decisions, and monitors whether required controls are operating effectively.

The framework is designed as an enterprise management system connecting the governing body, executive leadership, physicians, compliance personnel, clinical operations, patient access, utilization management, coding, billing, finance, human resources, information technology, privacy, security, quality management, and external partners.

It applies across interventional pain management, physical medicine and rehabilitation, orthopedic surgery, orthopedic spine surgery, neurosurgery, neuromodulation, ambulatory surgery centers, and other related specialty-care operations.

Explore the 37-Section Framework

Governance and Enterprise Risk

  1. Regulatory, Risk and Compliance Governance
  2. Board and Executive Leadership Accountability
  3. Compliance Officer and Compliance Committee Structure
  4. Regulatory Intelligence and Legal Requirements Management
  5. Enterprise Risk Management

Compliance Infrastructure

  1. Organizational Compliance Risk Assessment
  2. Compliance Work Plan and Annual Priorities
  3. Code of Conduct and Ethical Standards
  4. Policy and Procedure Governance
  5. Compliance Education and Workforce Training

Reporting, Investigation, and Monitoring

  1. Confidential Reporting and Nonretaliation
  2. Compliance Investigations
  3. Corrective Action and Disciplinary Standards
  4. Compliance Monitoring and Internal Auditing
  5. Clinical Documentation Integrity

Revenue Integrity and Authorization Compliance

  1. Coding Compliance
  2. Billing and Claims Compliance
  3. Revenue Integrity and Financial Compliance
  4. Medical Necessity and Utilization Management Compliance
  5. Prior Authorization Compliance

Fraud, Privacy, and Payer Compliance

  1. Fraud, Waste and Abuse Prevention
  2. False Claims Act and Government Enforcement Exposure
  3. Anti Kickback, Stark Law and Financial Relationship Compliance
  4. Government Program and Payer Contract Compliance
  5. HIPAA Privacy and Confidentiality Compliance

Security, Vendors, Workforce, and Credentials

  1. Security Compliance and Breach Response
  2. Records Retention, Destruction and Legal Holds
  3. Third Party, Vendor and Business Associate Compliance
  4. Workforce, Employment and Labor Compliance
  5. Credentialing, Enrollment, Licensure and Exclusion Screening

Clinical, Specialty, ASC, and Patient Compliance

  1. Clinical Risk Management and Patient Safety
  2. Specialty Specific Compliance for Pain, Orthopedics, Spine, Neurosurgery and Neuromodulation
  3. Ambulatory Surgery Center and Facility Compliance
  4. Controlled Substances, Prescribing and Medication Compliance
  5. Patient Financial, Consumer Protection and No Surprises Act Compliance

AI Governance and Audit Readiness

  1. AI Healthcare Governance, Algorithmic Risk and Responsible Use
  2. Audit Readiness, Regulatory Performance and Continuous Improvement

Implementation and Resources

  1. Regulatory and Compliance Maturity Model
  2. Implementation Priorities
  3. Framework Insights
  4. Authoritative Regulatory References
  5. Related GoHealthcare Reading
01

Regulatory, Risk and Compliance Governance

Purpose

Regulatory, risk and compliance governance establishes the organizational authority, accountability structure, decision rights and oversight mechanisms required to manage healthcare compliance as an enterprise responsibility.

Compliance cannot operate as a collection of policies maintained by one individual or department. It must function as an integrated management system connecting the governing body, executive leadership, physicians, advanced practice providers, compliance personnel, clinical operations, patient access, prior authorization, utilization management, coding, billing, finance, human resources, information technology, privacy, security, quality and risk management.

The HHS Office of Inspector General General Compliance Program Guidance provides a voluntary and nonbinding reference for healthcare organizations. It organizes compliance program infrastructure around seven elements, including written standards, compliance leadership, education, communication, enforcement, risk assessment, auditing, monitoring, investigation and corrective action. The guidance must be adapted to the organization’s size, structure, services and risk profile rather than implemented as a universal template.

Governance Standard

The organization should establish a formally approved Regulatory, Risk and Compliance Governance Charter.

The charter should define the purpose of the compliance program, its scope, authority, reporting relationships, committee structure, decision rights, escalation pathways, documentation requirements and performance expectations.

The charter should apply across every legal entity, business unit, clinical location, service line and workforce category under the organization’s ownership, management or contractual control.

This includes physicians, advanced practice providers, employed personnel, temporary personnel, contractors, offshore teams, outsourced billing companies, management services organizations, technology vendors, consultants, business associates and other third parties performing services on behalf of the organization.

The governance structure should recognize that risk can originate anywhere within the healthcare operating system. A coding error may begin with incomplete physician documentation. A privacy incident may originate through vendor access. A prior authorization failure may arise from incorrect payer routing. An overpayment may remain undetected because of weak credit balance controls. An unsafe AI generated recommendation may occur because no human review requirement was established.

Governance must therefore connect regulatory requirements to the workflows where risk is created, controlled and monitored.

Enterprise Scope

The compliance governance structure should oversee the organization’s full clinical, administrative, financial and technological environment.

The scope should include clinical documentation, medical necessity, coding, billing, charge capture, claim submission, reimbursement, prior authorization, utilization management, patient access, payer contracts, patient privacy, information security, credentialing, enrollment, licensure, exclusion screening, controlled substances, patient safety, quality of care, financial arrangements, referral relationships, workforce conduct, vendor relationships, record retention, patient financial communications and artificial intelligence.

Oversight should extend beyond federal healthcare program requirements.

The organization must also identify applicable state laws, licensing requirements, accreditation standards, payer policies, contractual obligations, employment rules, consumer protection requirements and professional standards.

An obligation that has not been translated into an accountable owner, operational control, monitoring activity and escalation pathway remains an unmanaged risk.

Governance Architecture

The governance model should contain coordinated levels of accountability.

The governing body or ownership group provides ultimate oversight.

Executive leadership converts compliance expectations into organizational strategy, resources and operational accountability.

The compliance officer directs the compliance program and maintains independent access to the governing body.

The compliance committee coordinates implementation across clinical, operational, financial and administrative functions.

Department leaders own the controls operating within their areas.

Managers supervise day to day execution and address identified deficiencies.

Physicians and other clinicians remain accountable for clinical judgment, documentation accuracy, medical necessity and professional conduct.

Every workforce member remains responsible for following applicable requirements and reporting suspected concerns.

This structure should distinguish oversight from execution.

The compliance officer may establish coding audit requirements, but coding leadership remains responsible for maintaining accurate coding operations. Compliance may monitor authorization controls, but patient access leadership remains responsible for confirming authorization before services are performed. Compliance may review privacy controls, but technology and operations leaders remain accountable for implementing appropriate access restrictions.

The compliance function should not become the owner of every operational control. Doing so weakens departmental accountability and makes the compliance program responsible for policing processes that operational leaders should be managing directly.

Decision Rights

Compliance decision rights should be established before a serious concern occurs.

The organization should define who may approve policies, initiate investigations, retain outside counsel, suspend a workflow, hold claims, restrict system access, place a vendor on corrective action, stop use of an AI tool, disclose an incident, return an overpayment or escalate a matter to the governing body.

The level of authority required should reflect the seriousness of the issue.

Routine operational errors may be corrected by departmental management with appropriate documentation.

Potential patient harm, falsified documentation, systemic billing errors, significant overpayments, privacy breaches, excluded individuals, retaliation, intentional misconduct, government inquiries and unresolved repeat findings should be escalated immediately.

Revenue pressure, physician productivity, patient volume or organizational growth should never override an appropriate compliance escalation.

Regulatory Obligation Register

The organization should maintain a centralized Regulatory Obligation Register.

The register should identify the applicable requirement, authoritative source, affected entity, affected department, operational owner, compliance owner, required controls, evidence of implementation, monitoring frequency, review date and escalation threshold.

The register should distinguish among federal laws, state laws, regulations, agency guidance, payer requirements, accreditation standards, contractual obligations and internal organizational standards.

The purpose is not to reproduce the full text of every regulation. The purpose is to demonstrate how each material obligation has been translated into organizational accountability.

For example, a payer requirement governing lumbar radiofrequency ablation should be connected to physician documentation templates, authorization criteria, diagnostic block history, percentage of relief, anatomical level validation, scheduling controls, coding review and claim submission.

Governance Calendar

Compliance governance should operate through a defined annual calendar.

The calendar should address governing body reporting, compliance committee meetings, annual risk assessments, regulatory reviews, policy updates, workforce education, exclusion screening, coding audits, billing audits, medical necessity reviews, privacy assessments, security risk analysis, vendor reviews, credentialing validation, incident trend analysis and corrective action monitoring.

The calendar should also identify recurring payer updates, Medicare policy releases, accreditation activities, licensing renewals and major contract review dates.

Meeting frequency should reflect organizational complexity and risk.

A small physician group may operate effectively with quarterly formal meetings and monthly operational monitoring. A multisite MSK organization with ASCs, implantable procedures, multiple payer contracts, offshore operations and AI enabled workflows may require monthly committee meetings and more frequent reporting of significant matters.

Documentation and Evidence

Every material governance activity should produce evidence.

Evidence may include approved charters, meeting agendas, attendance records, minutes, risk registers, compliance reports, policy approvals, regulatory change logs, audit results, investigation summaries, training records, corrective action plans and documented leadership decisions.

Meeting minutes should identify the issue reviewed, the information considered, questions raised, decisions made, responsible owners, due dates and escalation requirements.

Minutes that merely state that a compliance matter was discussed do not demonstrate effective oversight.

The record should show that leadership understood the issue, evaluated the risk, assigned responsibility and monitored resolution.

Escalation and Resolution

The governance framework should define escalation thresholds and expected response times.

Immediate escalation should be considered when a matter involves patient harm, suspected fraud, falsification, significant financial exposure, intentional misconduct, excluded individuals, compromised protected health information, possible retaliation, interference with an investigation or repeated failure to complete corrective action.

The compliance officer should have direct access to the chief executive officer and governing body.

Operational leaders should not be permitted to suppress, delay or modify compliance findings because the findings could affect revenue, productivity, physician relationships, vendor relationships or reputation.

Every escalated issue should remain open until the organization has documented the investigation, determination, corrective action, financial resolution, policy response and monitoring plan.

Governance Performance Measures

The organization should evaluate whether governance works in practice.

Measures should include leadership attendance, risk escalation timeliness, policy completion, audit completion, training participation, corrective action closure, repeat finding rates, investigation cycle time, overpayment resolution and unresolved high risk issues.

The Department of Justice considers whether a compliance program is well designed, appropriately resourced, empowered to function and effective in practice. A program that exists primarily in policies but does not influence decisions, resource allocation or behavior may be viewed as a paper program rather than an effective operating system.

Application to MSK Specialty Care

In interventional pain management, orthopedic surgery, spine surgery, neurosurgery, neuromodulation and ambulatory surgery centers, compliance risk frequently originates within routine clinical and administrative workflows.

Examples include changing a procedure without verifying authorization, performing a different anatomical level than approved, repeating an intervention without documenting prior response, using an unsupported modifier, billing the wrong place of service, failing to reconcile implant documentation or proceeding before payer frequency requirements have been satisfied.

These are not simply billing problems.

They are governance failures because they reflect unclear authority, insufficient workflow controls, weak communication, inadequate monitoring or failure to assign accountability before the service was performed.

GoHealthcare Insights

Compliance must be embedded at the point where the organization makes clinical, financial and operational decisions.

A healthcare organization cannot become audit ready by reviewing claims only after submission. The organization must govern the complete pathway beginning with patient selection, clinical documentation, medical necessity, authorization, scheduling, coding, claim submission and payment validation.

The most effective compliance programs prevent unsupported services and claims from moving forward rather than depending exclusively on retrospective correction.

Leadership Perspective

A mature organization does not ask only whether it has a compliance manual.

It asks whether compliance expectations are visible in physician behavior, executive decisions, staffing models, compensation arrangements, technology design, vendor management and daily operations.

Compliance becomes credible when leaders are willing to delay a procedure, correct a claim, return an overpayment, investigate a respected employee or discontinue a profitable arrangement when the facts require it.

Key Takeaways

Regulatory, risk and compliance governance must be formal, enterprise wide, documented and supported by leadership authority.

Every material obligation should have an accountable owner, an operational control, evidence of implementation, a monitoring process and an escalation pathway.

The compliance program must influence real clinical, financial and operational decisions.

Back to framework navigation
02

Board and Executive Leadership Accountability

Purpose

The governing body and executive leadership are responsible for establishing the organization’s compliance culture, approving the compliance structure, allocating resources and maintaining reasonable oversight of regulatory and enterprise risk.

Compliance responsibilities may be delegated, but ultimate oversight cannot be transferred entirely to the compliance officer.

The governing body must understand the organization’s principal risks and determine whether management has implemented an effective system for preventing, detecting, escalating and correcting misconduct or control failures.

OIG guidance addresses board compliance oversight as a central component of compliance program infrastructure. OIG has also published resources describing the governing body’s responsibility to oversee senior management’s operation of the compliance program rather than functioning as a passive recipient of information.

Governing Body Responsibility

The governing body may consist of a board of directors, physician owners, managing members, corporate owners or another formally designated authority.

Regardless of legal structure, the governing body should understand what services the organization provides, how revenue is generated, which government programs and payers are involved and where material regulatory exposure exists.

The governing body should receive information concerning coding, billing, medical necessity, prior authorization, referral relationships, physician compensation, ownership arrangements, privacy, cybersecurity, patient safety, controlled substances, vendor performance and emerging technology.

The governing body is not expected to perform routine compliance work. It is expected to exercise informed oversight.

That means asking questions, challenging unsupported assumptions, assessing whether management’s response is proportionate to the risk and requiring resolution of identified deficiencies.

Executive Leadership Responsibility

The chief executive officer and senior leadership team are responsible for converting governing body expectations into operational execution.

Compliance should be incorporated into strategic planning, budgeting, staffing, service line development, acquisitions, contracting, physician arrangements, technology implementation and performance management.

Compliance review should occur before the organization launches a service, acquires a practice, employs a physician, enters a joint venture, adopts an AI tool, establishes a compensation methodology or changes its billing model.

Reviewing compliance only after the business decision has been made limits the organization’s ability to prevent risk.

Executive leaders should require business proposals to identify applicable regulatory considerations, control requirements, responsible owners, implementation costs and monitoring expectations.

Tone From the Top and Middle

Leadership behavior defines the practical meaning of the compliance program.

When senior leaders follow policies, attend education, respond to concerns and support corrective action, the workforce understands that compliance is an organizational expectation.

When leaders pressure staff to submit unsupported claims, ignore documentation deficiencies or tolerate misconduct by high producing physicians, the compliance program loses credibility.

Middle management is equally important.

Supervisors decide whether employees can raise concerns, whether policies are enforced consistently and whether operational problems are escalated or concealed.

A strong message from the governing body can be undermined by managers who reward speed, volume or collections without regard to documentation, authorization, privacy or billing integrity.

Leadership Education

Governing body members and executives should receive education appropriate to their roles.

Education should address the compliance program, major healthcare fraud and abuse risks, overpayment responsibilities, privacy and security obligations, reporting pathways, investigation responsibilities and board oversight duties.

Training should also address the organization’s specialty specific exposure.

Leadership of an MSK organization should understand the importance of medical necessity, procedure frequency, prior treatment response, diagnostic block requirements, implantable device criteria, anatomical specificity, place of service, physician ownership arrangements and ASC billing.

Board education should not be limited to general compliance terminology. It should prepare leaders to understand the information presented in compliance reports and ask meaningful questions.

Compliance Reporting

The compliance officer should provide regular written and oral reports to the governing body or its designated committee.

Reports should include significant risks, audit findings, investigations, reporting activity, corrective actions, overpayments, refund activity, privacy incidents, security events, exclusion screening results, education completion, regulatory changes and unresolved matters.

Information should be presented as trends rather than isolated incidents.

Repeated authorization failures, recurring modifier errors or continuing delays in corrective action should be identified as systemic patterns when the data supports that conclusion.

The governing body should receive enough context to understand the source, scope, severity and status of each material risk.

Executive Sessions

The governing body should periodically meet privately with the compliance officer.

These sessions provide an appropriate setting for discussing concerns involving senior management, insufficient resources, interference with compliance activities, retaliation, sensitive investigations and unresolved disagreements.

The compliance officer should not require permission from another executive to communicate directly with the governing body.

Direct access strengthens independence and reduces the risk that material information will be filtered through leaders whose decisions may be under review.

Resource Allocation

The governing body and executive leadership should ensure that compliance resources are proportionate to organizational size, complexity and risk.

Resources may include qualified personnel, legal support, coding expertise, auditing capacity, data analytics, investigation resources, education platforms and external specialists.

Resource adequacy should be evaluated against actual responsibilities.

Assigning one individual responsibility for compliance, privacy, security, human resources, quality and operations may create the appearance of coverage without providing adequate capacity or independence.

The Department of Justice considers whether compliance personnel have sufficient qualifications, authority, access to information, seniority and resources to perform effectively.

Leadership Performance and Incentives

Compliance responsibilities should be incorporated into executive, physician leader and management evaluations.

Leaders should be assessed on completion of corrective action, responsiveness to audit findings, training completion, policy enforcement, management of reported concerns and prevention of repeated deficiencies.

Financial performance should not be the sole measure of leadership success in a regulated healthcare organization.

An executive who meets revenue goals while allowing unsupported coding, inadequate documentation, unsafe practices or unresolved privacy risks has not met the organization’s full leadership standard.

Compensation and incentive structures should not encourage behavior that conflicts with medical necessity, documentation accuracy, patient safety or lawful billing.

Conflicts of Interest

Governing body members and executives should disclose actual and potential conflicts of interest.

A leader with a financial interest in a vendor, facility, referral source, laboratory, pharmacy, device company or related entity should not control the compliance review of that relationship.

Recusal decisions should be documented.

Independent review should be preserved when arrangements involve owners, senior executives, high producing physicians or close business relationships.

Application to Physician Led Organizations

In physician owned organizations, compliance accountability must apply consistently to owners and nonowners.

Ownership should not exempt a physician from documentation requirements, authorization controls, coding reviews, conflict assessments or corrective action.

The governing body must be prepared to address circumstances in which financial contribution and compliance responsibility appear to conflict.

Failure to hold influential physicians accountable can convert an individual problem into an organizational culture problem.

GoHealthcare Insights

Board reporting should not consist solely of favorable metrics.

Leadership needs visibility into exceptions, unresolved matters, repeated findings and emerging risks.

A strong governing body asks what management knows, how it knows it, what remains uncertain and whether the organization has sufficient evidence that corrective action is working.

Leadership Perspective

Leadership accountability is demonstrated most clearly when compliance is inconvenient.

The governing body’s most important role is not approving policies. It is requiring action when the organization discovers information that could affect patients, payers, government programs or the integrity of the organization.

Key Takeaways

The governing body retains responsibility for reasonable compliance oversight even when daily administration is delegated.

Executive leaders must integrate compliance into strategy, growth, contracting, compensation and operational design.

The compliance officer must have direct access to the governing body, appropriate independence and adequate resources.

Back to framework navigation
03

Compliance Officer and Compliance Committee Structure

Purpose

The compliance officer and compliance committee form the operational leadership structure of the compliance program.

The compliance officer directs the program, coordinates risk assessment, advises leadership, oversees monitoring, receives concerns, supports investigations and reports on compliance performance.

The compliance committee brings together clinical, operational, financial and administrative leaders to ensure that requirements are implemented throughout the organization.

Compliance Officer Authority

The compliance officer should have formal authority established through a board approved charter or equivalent governing document.

The officer should be authorized to access personnel, records, systems, contracts, claims, medical documentation, financial information, vendor information and other materials relevant to compliance activity.

The officer should be able to initiate reviews, recommend suspension of questionable practices, request corrective action, hold affected claims and escalate unresolved issues directly to executive leadership or the governing body.

The compliance officer should not depend on the permission of the department under review to obtain relevant information.

OIG’s General Compliance Program Guidance addresses the compliance officer, compliance committee and board oversight as core components of compliance leadership.

Independence

The compliance officer should be positioned independently from the functions that create or manage the risks being evaluated.

Whenever feasible, the compliance officer should not directly manage billing, coding, finance, claim submission or clinical operations.

Combining these functions can create a conflict in which the individual is expected to evaluate their own decisions or the performance of departments they supervise.

Smaller organizations may not be able to achieve complete separation.

In those circumstances, the organization should document the limitation and establish compensating controls. These may include external audits, direct board access, independent legal review or use of outside investigators for matters involving the compliance officer’s operational responsibilities.

Qualifications and Competency

The compliance officer should possess sufficient knowledge of healthcare operations, regulatory requirements, fraud and abuse risk, investigations, auditing, documentation, coding, billing and organizational governance.

The officer does not need to personally perform every specialized function.

The officer must, however, recognize when subject matter expertise is required and have authority to obtain it.

An MSK compliance program may require access to expertise in interventional pain management, orthopedic surgery, spine surgery, neuromodulation, ambulatory surgery center operations, payer policy, medical necessity, coding, privacy, cybersecurity and physician financial arrangements.

Competency should be maintained through ongoing education, regulatory monitoring, professional development and review of relevant enforcement activity.

Core Responsibilities

The compliance officer should coordinate the compliance risk assessment, develop the annual work plan, maintain the code of conduct, oversee policy governance, support training, administer reporting channels, oversee investigations, coordinate audits and monitor corrective action.

The officer should also track emerging regulatory requirements, advise on proposed business arrangements, participate in due diligence, review significant vendors and ensure that identified overpayments or violations are appropriately addressed.

The officer should maintain a clear distinction between providing compliance oversight and performing operational work.

Department leaders remain responsible for maintaining compliant operations within their areas.

Compliance Committee Charter

The compliance committee should operate under a written charter approved by executive leadership or the governing body.

The charter should define the committee’s purpose, authority, membership, responsibilities, meeting frequency, quorum, documentation standards, confidentiality expectations and escalation requirements.

The committee should support the compliance officer and coordinate implementation of the compliance program across the enterprise.

It should have sufficient authority to require departmental action and escalate matters that cannot be resolved at the committee level.

Committee Membership

Membership should reflect the organization’s structure and risk profile.

Representation may include executive leadership, physician leadership, patient access, prior authorization, utilization management, coding, billing, finance, human resources, information technology, privacy, security, quality, risk management, credentialing and ASC operations.

Legal counsel may participate when appropriate.

The committee should distinguish routine compliance management from communications intended to obtain legal advice. Not every compliance committee discussion is automatically protected by legal privilege.

Committee members should have sufficient authority to provide accurate information, commit departmental resources and implement assigned actions.

Committee Responsibilities

The compliance committee should review regulatory changes, risk assessment results, audit findings, reported concerns, investigation trends, education completion, policy revisions and corrective action status.

The committee should determine whether identified findings are isolated or systemic.

It should evaluate whether corrective action addresses the underlying cause rather than merely correcting individual cases.

Correcting one claim does not resolve a systemic compliance issue when the cause is an incorrect system configuration, weak physician documentation, flawed training or a defective workflow affecting multiple claims.

The committee should also consider whether similar exposure exists across other providers, locations, payers or services.

Meeting Management

Meetings should follow a structured agenda.

Materials should be distributed in advance when appropriate.

Minutes should identify attendees, matters reviewed, decisions reached, assigned owners, target dates and unresolved questions.

Open matters should remain on the agenda until formally closed.

Attendance should be monitored.

Repeated absence by a department leader may indicate that compliance responsibilities are not receiving appropriate attention and should be escalated.

Information Access and Data Transparency

The compliance officer and committee must receive timely and complete information.

Operational leaders should not delay disclosure of payer audits, billing errors, patient complaints, privacy incidents, adverse events, exclusion findings or employee concerns.

The compliance function should have access to data that allows it to identify patterns across providers, locations, procedures and payers.

Relevant information may include claim volume, denial reasons, modifier use, procedure frequency, authorization failures, refunds, credit balances, documentation deficiencies, incident reports and unusual utilization patterns.

The Department of Justice specifically evaluates whether compliance personnel have access to the data needed to identify misconduct or weaknesses at an early stage.

Subcommittees and Specialized Oversight

Larger organizations may establish specialized committees for revenue integrity, privacy, security, artificial intelligence, clinical quality, credentialing or ASC compliance.

These groups should operate within the broader governance structure.

Their findings, decisions and unresolved risks should be reported to the principal compliance committee and incorporated into the enterprise risk assessment.

Specialized groups should not become isolated structures that make material compliance decisions without visibility from the compliance officer or governing body.

Committee Effectiveness

The organization should evaluate the committee’s effectiveness at least annually.

Evaluation should consider attendance, timeliness of decisions, corrective action completion, escalation quality, repeat findings and whether committee activity has produced measurable changes in operations.

A committee that meets regularly but does not resolve issues is not functioning effectively.

Application to MSK Specialty Care

The compliance committee creates particular value in MSK specialty organizations because risks often cross departmental boundaries.

A prior authorization denial may involve payer policy interpretation, insufficient documentation, an incorrect diagnosis, a scheduling failure and a claim configuration problem.

A radiofrequency ablation audit may require review of diagnostic block history, percentage of relief, anatomical levels, frequency limits, procedure documentation, coding and place of service.

No single department can resolve these risks independently.

The committee provides a structure for coordinated analysis and accountability.

GoHealthcare Insights

The compliance committee should not become a passive meeting where departments present favorable updates.

Its value comes from identifying patterns, challenging assumptions and requiring accountable resolution.

Compliance leadership should be measured by the quality of risk detection and response, not by the absence of reported problems.

Leadership Perspective

A strong compliance officer is not an obstacle to growth.

The officer protects sustainable growth by identifying risk before it becomes a repayment, payer audit, regulatory investigation, patient safety event or reputational crisis.

Key Takeaways

The compliance officer must have authority, independence, access to information and direct reporting capability.

The compliance committee should include leaders who can implement decisions across the organization.

Committee activity must result in documented decisions, assigned responsibilities and verified resolution.

Back to framework navigation
04

Regulatory Intelligence and Legal Requirements Management

Purpose

Regulatory intelligence is the organized process through which a healthcare organization identifies, interprets, communicates and operationalizes new or revised legal, regulatory, payer and accreditation requirements.

Healthcare organizations operate within a continuously changing environment.

Requirements may originate from Congress, federal agencies, state authorities, licensing boards, Medicare contractors, Medicaid programs, commercial payers, accreditation organizations and contractual relationships.

Regulatory intelligence prevents important changes from remaining inside an email, newsletter or legal memorandum without being converted into operational action.

Source Hierarchy

The organization should establish a hierarchy of authoritative sources.

Primary sources may include statutes, regulations, official agency publications, the Federal Register, agency manuals, state government publications, Medicare Administrative Contractor policies, payer manuals and accreditation standards.

Industry publications, vendor notices, professional newsletters and third party summaries may support awareness, but material decisions should be validated against the controlling source.

The HHS Guidance Portal explains that agency guidance communicates how HHS interprets and applies existing laws and regulations. Guidance does not itself create new laws or legal requirements. This distinction is important when determining whether a publication is binding, interpretive, advisory or contractual.

Regulatory Inventory

The organization should maintain an inventory of authorities applicable to its operations.

The inventory should account for federal healthcare program requirements, state laws, professional licensure, privacy, security, controlled substances, payer policies, accreditation standards, employment requirements, corporate obligations, consumer protection rules and contractual commitments.

The inventory should be organized by entity, location, service line and responsible department.

A physician practice, ASC and management services organization may share certain obligations while remaining subject to different licensing, accreditation, billing and operational requirements.

Regulatory Surveillance

The organization should define who monitors each authoritative source and how frequently review occurs.

Surveillance responsibilities may be divided among compliance, legal, clinical leadership, revenue cycle, human resources, information technology and other specialists.

Monitoring sources may include the Federal Register, HHS, OIG, CMS, OCR, DOJ, DEA, state agencies, licensing boards, Medicare Administrative Contractors and commercial payer portals.

The Federal Register should be monitored for proposed rules, final rules, notices and effective dates that may affect healthcare operations.

The OIG Work Plan should also be reviewed because it is updated dynamically and identifies audits and evaluations that are underway or planned.

Regulatory Change Log

The compliance function should maintain a centralized Regulatory Change Log.

Each entry should identify the source, publication date, effective date, affected entity, affected service line, responsible owner, required policy changes, workflow implications, technology implications, training requirements and implementation status.

The log should distinguish among proposed rules, final rules, agency guidance, payer policy updates, contractual amendments and internal interpretations.

A proposed rule should not be treated as final.

An effective requirement should not remain classified as under review after the implementation deadline.

Impact Assessment

Every material change should undergo an operational impact assessment.

The assessment should identify affected patients, providers, locations, payers, procedures, systems and departments.

It should evaluate documentation requirements, coding changes, medical necessity criteria, patient notices, consent forms, authorization workflows, claim edits, privacy implications, technology configuration and education needs.

For example, a change affecting radiofrequency ablation coverage may require revision of physician templates, authorization checklists, diagnostic block documentation, scheduling controls, coding instructions and claim validation.

The change should not be assigned only to billing when the requirement affects clinical decision making and patient selection.

Ownership and Accountability

Each regulatory change should be assigned to an accountable operational owner.

The compliance officer should coordinate and monitor implementation, but the department responsible for the affected workflow should complete the operational work.

Clinical leaders may own documentation changes.

Revenue cycle leaders may own claim edits.

Patient access leaders may own authorization workflows.

Information technology may own system configuration.

Human resources may own employment policy revisions.

Compliance should verify that implementation is complete and supported by evidence.

Policy and Workflow Translation

Regulatory interpretation must be converted into practical instructions.

The organization should determine whether the change requires a policy, procedure, checklist, system edit, decision tree, training module, contract amendment or monitoring activity.

Policies explain organizational expectations.

Procedures explain what personnel must do.

A policy stating that the organization will comply with payer authorization requirements is insufficient without a workflow explaining how personnel identify the payer, determine the utilization management entity, locate the correct policy, submit documentation, track status and verify approval before scheduling.

Effective Date Management

Implementation plans should be built around effective dates.

Adequate time should be provided for interpretation, workflow design, system configuration, testing, communication and training.

When time is insufficient, the organization should establish an interim control.

An interim control may include manual claim review, temporary scheduling restrictions, secondary approval or focused monitoring until a permanent workflow is implemented.

Communication and Training

Affected personnel should receive targeted communication before the requirement becomes operational.

Communication should explain what changed, which workflows are affected, when the change becomes effective and where personnel can obtain assistance.

Training should be role specific.

Physicians may require education concerning medical necessity and documentation.

Schedulers may require new authorization rules.

Coders may require coding instructions.

Billing personnel may require claim submission changes.

Executives may require information concerning financial and operational impact.

Implementation Validation

Implementation should not be considered complete merely because a policy was distributed or training was delivered.

The organization should verify that people, workflows and systems are functioning as intended.

Validation may include test claims, chart reviews, workflow observation, staff interviews, system testing, denial analysis or focused audits.

The compliance committee should receive evidence of implementation and monitor early performance for unexpected consequences.

CMS maintains Medicare Provider Compliance Tips addressing medical necessity, ordering, documentation and billing expectations. These resources can be incorporated into regulatory intelligence and provider education processes.

State and Payer Variation

Organizations operating across multiple states or payer markets should account for variation.

A workflow that complies with one state’s rules or one payer’s policy may not satisfy another.

The regulatory intelligence system should identify which requirements apply universally and which depend on patient plan, provider location, site of service, procedure or state jurisdiction.

Technology should not apply one rule across all cases unless the rule has been validated for every relevant population.

Evidence of Implementation

The organization should preserve evidence demonstrating when the change was identified, how it was interpreted, who approved the response, what workflows were modified, who received education and how implementation was validated.

This evidence is essential during payer audits, regulatory inquiries and internal reviews.

Application to Emerging Technology

Regulatory intelligence should include artificial intelligence, automation, digital health, remote monitoring, cybersecurity and data sharing.

New technology should not be implemented solely through an information technology or vendor approval process.

Compliance, privacy, security, clinical safety and operational implications should be evaluated together.

GoHealthcare Insights

The most common regulatory intelligence failure is not an inability to locate a new requirement.

It is the failure to determine exactly how that requirement changes daily work.

Regulatory intelligence is incomplete until the requirement has been translated into policy, workflow, system configuration, training, evidence and monitoring.

Leadership Perspective

Executives should ask one direct question whenever a significant requirement changes:

What will our people do differently because of this change?

When no clear answer exists, the organization has received information but has not implemented it.

Key Takeaways

Regulatory intelligence must be centralized, assigned, documented and connected to operational execution.

Material requirements should be verified against authoritative sources.

Every significant change requires impact assessment, implementation planning, education and validation.

Back to framework navigation
05

Enterprise Risk Management

Purpose

Enterprise Risk Management provides a disciplined process for identifying, assessing and managing risks that could prevent the organization from achieving its clinical, operational, financial, compliance and strategic objectives.

Compliance risk is one part of enterprise risk.

Healthcare organizations must also evaluate patient safety, workforce capacity, cybersecurity, vendor dependence, financial performance, business continuity, technology failure, reputation and strategic execution.

Enterprise Risk Management connects these areas so leaders can understand how one risk may create consequences across multiple functions.

GAO describes Enterprise Risk Management as a forward looking management approach that helps organizations assess threats and opportunities affecting their objectives. Its framework emphasizes alignment with organizational goals, leadership engagement, risk identification, assessment, response and continuous monitoring.

Risk Philosophy

The organization should define its risk philosophy and tolerance.

Risk cannot be eliminated completely.

Leadership must determine which risks can be accepted, which require mitigation, which may be transferred through insurance or contracting and which are unacceptable.

Risk tolerance should be particularly restrictive when the potential consequence includes patient harm, fraud, exclusion, privacy breaches, loss of licensure or intentional misconduct.

Financial opportunity should not justify accepting risk that compromises patient safety, lawful billing or professional integrity.

Risk Categories

The Enterprise Risk Management structure should evaluate multiple categories.

Clinical risk includes patient selection, procedural complications, medication management, infection prevention, informed consent and emergency response.

Compliance risk includes documentation, coding, billing, medical necessity, financial relationships, privacy, authorization, licensure and payer requirements.

Operational risk includes staffing, scheduling, workflow failures, training deficiencies, supervision and capacity constraints.

Technology risk includes cybersecurity, outages, interface failures, unauthorized access, data loss and unreliable artificial intelligence.

Financial risk includes payer concentration, denials, credit balances, cash flow, underpayments, contractual exposure and inaccurate financial reporting.

Strategic risk includes expansion, acquisitions, new services, joint ventures and dependence on key physicians or vendors.

Reputational risk may arise from patient complaints, poor quality, data breaches, regulatory action or public misconduct.

These categories should not be managed independently when they affect one another.

A cyber incident may become a privacy risk, operational outage, patient safety issue, financial loss and reputational event at the same time.

Risk Identification

Risk identification should use internal and external information.

Internal sources include audits, denials, complaints, incident reports, investigations, employee concerns, quality data, financial trends, exit interviews, claim analytics, authorization failures and corrective action deficiencies.

External sources include regulatory developments, payer audits, enforcement actions, OIG Work Plan activity, professional guidance, malpractice trends, cybersecurity threats and developments affecting comparable organizations.

OIG’s General Compliance Program Guidance identifies formal risk assessment, auditing and monitoring as central components of an effective compliance program.

Risk Assessment Methodology

The organization should use a consistent methodology.

Each risk should be evaluated based on likelihood, impact, speed of onset, duration, detectability and existing control strength.

Impact should consider patient harm, financial loss, repayment exposure, operational disruption, legal consequences, regulatory action, reputational damage and strategic consequences.

The methodology should distinguish clearly among risks.

A minor documentation inconsistency should not receive the same rating as a systemic practice involving unsupported claims or patient harm.

The organization may use quantitative, qualitative or combined scoring, but the methodology should be defined and applied consistently.

Inherent and Residual Risk

Risk assessment should distinguish inherent risk from residual risk.

Inherent risk represents the level of exposure before controls are considered.

Residual risk represents the exposure that remains after existing controls are evaluated.

A high volume procedural service may have high inherent risk because of complex medical necessity, coding and authorization requirements.

Strong documentation templates, authorization controls, coding review and ongoing auditing may reduce residual risk.

Leadership decisions should be based primarily on the residual risk and the reliability of the controls supporting that conclusion.

Risk Register

Material risks should be documented in an enterprise risk register.

The register should identify the risk, category, cause, potential consequence, inherent rating, existing controls, control owner, residual rating, treatment plan, responsible executive, target date, monitoring indicator and escalation threshold.

The risk register should be a working management tool.

It should not become a static spreadsheet reviewed only once per year.

Material changes in operations, technology, staffing, payer policy, service mix or external enforcement should trigger reassessment.

Risk Response

The organization should select an appropriate response for each material risk.

Avoidance means discontinuing or declining an activity when exposure cannot be reduced to an acceptable level.

Mitigation means implementing controls to reduce likelihood or impact.

Transfer may involve insurance, contractual protections or allocation of defined responsibilities.

Acceptance means acknowledging the residual exposure and formally determining that it falls within approved tolerance.

Acceptance should be documented and approved at the appropriate level.

High risk matters should not be considered accepted merely because no action was taken.

Control Design

Every mitigation strategy should identify the preventive, detective and corrective controls involved.

Preventive controls stop an error before it occurs.

Examples include system edits, authorization verification, exclusion screening, access restrictions and required approvals.

Detective controls identify a problem after or as it occurs.

Examples include audits, exception reports, reconciliation and data analytics.

Corrective controls address the consequence and prevent recurrence.

Examples include refund processing, workflow redesign, education, discipline and monitoring.

A mature risk response uses an appropriate combination of all three.

Key Risk Indicators

Material risks should be monitored through Key Risk Indicators.

Indicators may include services performed without authorization, claim denial patterns, repeat documentation deficiencies, unusual modifier utilization, unresolved credit balances, privacy incidents, exclusion screening exceptions, staff turnover, system downtime and overdue corrective actions.

Thresholds should identify when performance requires management review or escalation.

Indicators should be linked to action rather than collected only for reporting purposes.

Scenario Analysis

The organization should conduct scenario analysis for significant risks.

Examples include ransomware, loss of a major payer contract, unavailability of the EHR, a significant privacy breach, exclusion of a provider, a government audit, sudden loss of key personnel or failure of a critical vendor.

Scenario analysis should address decision authority, communication, operational continuity, legal review, patient safety, documentation preservation and financial impact.

Integration With Strategy and Operations

Enterprise Risk Management should be integrated into strategic planning, budgeting, acquisitions, service line development and technology implementation.

Every major initiative should identify the risks created, the controls required, the resources needed and the person accountable for monitoring residual exposure.

Risk management should not begin after implementation.

Application to MSK Specialty Care

MSK specialty organizations face concentrated risk because clinical care, payer policy, procedural volume and reimbursement are closely connected.

A documentation deficiency can affect authorization, medical necessity, coding, reimbursement and audit defense.

A procedure frequency pattern can generate payer scrutiny even when care was clinically appropriate if the record does not demonstrate reassessment and treatment response.

GoHealthcare’s review of CMS audit readiness emphasizes that procedure frequency, medical necessity and outcome documentation must be evaluated as connected elements rather than isolated billing issues.

High risk services should receive focused assessment based on procedure volume, reimbursement, complexity, payer scrutiny, implant use, medical necessity and historical findings.

GoHealthcare Insights

Enterprise Risk Management should connect information that departments normally review separately.

Denials, authorization failures, patient complaints, coding audits and documentation findings may all point to the same underlying operational weakness.

The organization creates greater value when it identifies the common cause rather than managing each symptom independently.

Leadership Perspective

Risk management is not designed to eliminate informed decision making or prevent growth.

It allows leaders to understand exposure, strengthen controls and make deliberate decisions with greater visibility.

Organizations that identify risk early retain more strategic options than organizations that respond only after an audit, incident or financial loss.

Key Takeaways

Enterprise Risk Management must include clinical, compliance, operational, technological, financial, strategic and reputational exposure.

Risks should be documented, assessed consistently, assigned to accountable owners and monitored through meaningful indicators.

Risk management should be integrated into strategy, growth, budgeting and daily operations.

Back to framework navigation
06

Organizational Compliance Risk Assessment

Purpose

An Organizational Compliance Risk Assessment is the formal process used to identify, evaluate, prioritize and document the regulatory and compliance risks that could affect the organization.

The assessment provides the foundation for the compliance program. It determines where leadership attention, auditing, monitoring, education, policy development and corrective action should be concentrated.

A compliance risk assessment should not be a generic questionnaire completed only to satisfy an annual requirement. It should evaluate the organization’s actual services, billing patterns, payer mix, clinical procedures, workforce structure, technology environment, contractual relationships, locations and prior compliance performance.

The HHS Office of Inspector General identifies risk assessment, auditing and monitoring as central elements of an effective healthcare compliance program. The Department of Justice similarly evaluates whether an organization periodically reviews its risks, uses relevant data, incorporates lessons learned and allocates compliance resources according to identified exposure.

Compliance Risk Universe

The organization should first define its complete compliance risk universe.

The risk universe represents all areas in which the organization may face legal, regulatory, contractual, clinical, financial or ethical exposure.

The risk universe should include clinical documentation, medical necessity, coding, billing, prior authorization, utilization management, patient access, refunds, overpayments, physician compensation, referral relationships, privacy, security, credentialing, enrollment, licensure, exclusion screening, controlled substances, patient safety, employment practices, patient financial communications, vendor relationships, offshore operations, artificial intelligence and record retention.

The risk universe should also account for risks created by the organization’s structure.

A physician practice may face professional billing, documentation and medical necessity risks.

An ambulatory surgery center may face facility billing, accreditation, infection prevention, credentialing and implant reconciliation risks.

A management services organization may face corporate practice, fee allocation, vendor, data access and delegated services risks.

An organization operating several related entities should assess both individual entity risk and risk created by relationships among the entities.

Organizational Profile

The risk assessment should begin with an accurate organizational profile.

The profile should identify the organization’s legal entities, ownership structure, locations, providers, specialties, service lines, payer contracts, billing arrangements, outsourced services, technology platforms and major vendors.

It should also identify the organization’s volume of Medicare, Medicaid, commercial payer, workers compensation, Veterans Affairs and self pay activity.

The organization should document which services generate the highest volume, reimbursement and regulatory complexity.

A risk assessment that does not reflect the organization’s current operations may overlook material exposure created by new services, acquisitions, physician arrangements, locations or technology.

Risk Identification Sources

Risk identification should use multiple sources of information.

Internal sources should include claim denial data, audit findings, patient complaints, employee reports, compliance investigations, credit balance reports, coding patterns, authorization failures, incident reports, privacy events, security events, credentialing deficiencies, provider documentation reviews and corrective action history.

Other useful internal sources include exit interviews, employee surveys, policy exceptions, system access reports, unusual utilization, manual adjustments, claim edits, write offs, refund delays and repeated workflow failures.

External sources should include regulatory changes, OIG guidance, the OIG Work Plan, CMS publications, Medicare Administrative Contractor policies, payer audits, professional licensing actions, enforcement settlements, state regulatory developments and industry risk alerts.

The organization should not rely only on risks already reported internally. A weak reporting culture may produce few complaints even when significant problems exist.

Specialty and Service Line Assessment

Each specialty and service line should be evaluated according to its specific risk profile.

Interventional pain management may involve risks associated with procedure frequency, diagnostic block requirements, percentage of relief, opioid prescribing, drug testing, image guidance, sedation, implantable devices and medical necessity.

Orthopedic and spine practices may face risks involving global surgical periods, assistant surgeon services, modifiers, implants, durable medical equipment, therapy services, place of service and post operative billing.

Neuromodulation programs may involve psychological evaluation, trial criteria, permanent implantation, device documentation, explantation, programming and coordination among professional and facility claims.

Ambulatory surgery centers may face risks involving conditions for coverage, accreditation, infection prevention, credentialing, quality reporting, facility billing, anesthesia arrangements, medication management and transfer agreements.

The organization should avoid using one generic risk score for all specialties. A risk may be material in one service line and minimal in another.

Provider Level Risk Assessment

Compliance risk should also be evaluated at the provider level.

The assessment may review procedure volume, coding distribution, modifier use, documentation quality, authorization failures, denial patterns, frequency of repeat procedures and comparison with organizational or peer patterns.

Provider analysis should not assume that a higher volume physician is acting improperly.

The purpose is to identify patterns that require review, education or validation.

For example, one provider may use modifier 59 substantially more often than peers. Another may document treatment response inconsistently. A third may perform a high percentage of procedures at one anatomical level.

These patterns may have legitimate explanations, but they should be understood and documented.

Risk Scoring Methodology

The organization should use a consistent scoring methodology.

Each risk should be evaluated based on likelihood, financial impact, patient impact, regulatory consequences, reputational exposure, speed of occurrence, ability to detect the problem and strength of existing controls.

The organization may use numerical or descriptive ratings, but the criteria should be defined.

A high risk rating should not be assigned merely because an issue appears important. The rating should be supported by documented facts and an established methodology.

The assessment should distinguish inherent risk from residual risk.

Inherent risk is the exposure before controls are considered.

Residual risk is the exposure remaining after controls have been evaluated.

A service may carry high inherent risk but lower residual risk when the organization has strong documentation templates, authorization controls, coding validation and auditing.

Control Assessment

The organization should evaluate whether existing controls are properly designed and operating consistently.

A policy is not sufficient evidence that a control works.

The assessment should determine whether staff follow the policy, whether technology supports the required workflow, whether exceptions are identified and whether leaders respond when controls fail.

Controls should be classified as preventive, detective or corrective.

Preventive controls reduce the likelihood that an error will occur.

Detective controls identify an error or unusual pattern.

Corrective controls address the consequence and reduce the possibility of recurrence.

For example, an authorization checklist is preventive. A report identifying procedures performed without authorization is detective. A corrective action plan and claim review are corrective.

Risk Prioritization

The organization should prioritize risks based on residual exposure, regulatory significance and organizational capacity.

High risk matters should receive immediate or near term attention.

Moderate risks should be placed into the compliance work plan with defined timelines.

Lower risks may be monitored or accepted if they remain within approved tolerance.

The organization should avoid placing every risk at the same priority level. When all risks are labeled critical, leadership loses the ability to allocate resources strategically.

Priority should be based on evidence rather than departmental influence, revenue contribution or physician seniority.

Compliance Risk Assessment Report

The final assessment should produce a formal written report.

The report should describe the methodology, information sources, participants, identified risks, risk ratings, existing controls, control deficiencies, proposed responses and responsible leaders.

It should identify which risks require auditing, monitoring, policy revision, training, technology changes, legal review or corrective action.

The report should also identify limitations.

For example, incomplete data, unavailable records or recent system changes may affect the reliability of conclusions.

The compliance officer should present the assessment to the compliance committee, executive leadership and governing body.

The OIG and Health Care Compliance Association resource guide identifies annual documented risk assessments, risk based work plans, board approval and regular reporting as potential measures of compliance program effectiveness.

Reassessment Triggers

The organization should complete a comprehensive risk assessment at least annually and update it when significant changes occur.

Reassessment may be required after an acquisition, new service line, payer audit, government inquiry, data breach, major vendor change, system conversion, leadership transition, significant denial trend, new physician arrangement or implementation of artificial intelligence.

The annual assessment should not prevent the organization from responding to emerging risks throughout the year.

Application to MSK Specialty Care

MSK compliance risk assessments should connect clinical criteria, documentation, authorization, coding and billing.

For example, a lumbar radiofrequency ablation risk assessment should evaluate whether the organization documents qualifying diagnostic blocks, percentage and duration of relief, anatomical levels, laterality, frequency limitations, authorization validity, procedure performance and claim accuracy.

The assessment should determine whether these controls operate as a connected system.

Reviewing only the claim will not identify failures that originated during patient selection, documentation or scheduling.

GoHealthcare Insights

The strongest compliance risk assessments are operational.

They do not merely identify the law or policy involved. They identify where the requirement enters the workflow, who is responsible, how the control functions, what evidence is generated and how failure is detected.

Risk assessment should produce a clear answer to three questions.

Where can the organization fail?

How would leadership know that failure occurred?

What will the organization do to prevent or correct it?

Leadership Perspective

An honest risk assessment may identify weaknesses that leadership would prefer not to see.

That is the purpose of the process.

A risk assessment should not be evaluated by how few problems it identifies. It should be evaluated by whether it gives leadership an accurate and actionable understanding of exposure.

Key Takeaways

The Organizational Compliance Risk Assessment must reflect the organization’s actual services, providers, payers, systems and operating model.

Risk identification should use internal data, external developments and specialty specific analysis.

The assessment should result in documented priorities, assigned ownership and a risk based compliance work plan.

Back to framework navigation
07

Compliance Work Plan and Annual Priorities

Purpose

The Compliance Work Plan converts identified risks into specific compliance activities.

It defines what the organization will audit, monitor, educate, investigate, redesign and report during the year.

The work plan provides discipline and accountability. Without it, compliance activity may become reactive, with resources consumed by whichever concern is most recent or most visible.

A well designed work plan ensures that the organization’s most significant risks receive sustained attention.

Connection to the Risk Assessment

Every major work plan activity should be traceable to an identified risk, regulatory requirement, prior finding or strategic organizational change.

The work plan should not consist solely of standard annual activities repeated without evaluation.

Recurring activities may remain necessary, but the organization should determine whether they continue to address its highest risks.

For example, an annual coding audit may be appropriate. However, the audit scope should change when the organization identifies new service lines, unusual modifier patterns, payer scrutiny or documentation deficiencies.

The Department of Justice evaluates whether organizations devote appropriate attention and resources to identified risks and whether their compliance programs evolve based on lessons learned and changing operations.

Work Plan Components

The work plan should identify the risk or obligation being addressed, the planned activity, scope, methodology, responsible owner, required resources, start date, completion date, reporting pathway and expected outcome.

It should also identify whether the activity is an audit, monitoring review, policy project, education initiative, investigation, control redesign or effectiveness evaluation.

The work plan should distinguish compliance owned activity from operational activity.

Compliance may coordinate an audit, but the affected department should own operational remediation.

Each project should have a clearly defined completion standard.

“Review billing compliance” is not sufficiently specific.

A stronger work plan activity would identify the service line, providers, payer population, claim period, sample size, documentation criteria, coding standards and reporting deadline.

Annual Priorities

The organization should establish a limited number of material annual priorities.

Priorities should reflect the highest residual risks, major regulatory changes, unresolved findings, new business initiatives and areas of significant patient or financial impact.

Annual priorities may include medical necessity, provider documentation, modifier use, prior authorization, overpayments, privacy access, exclusion screening, controlled substances, physician arrangements, cybersecurity or artificial intelligence.

An MSK organization may prioritize epidural injection frequency, medial branch block documentation, radiofrequency ablation eligibility, spinal cord stimulation selection, implant reconciliation, place of service and procedure authorization.

Priorities should be realistic.

A work plan containing more projects than the organization can complete creates an appearance of ambition but weakens accountability.

Audit Plan

The work plan should include a risk based audit schedule.

The audit plan should identify which providers, procedures, departments, payers, locations and time periods will be reviewed.

Audit methodology should be appropriate to the objective.

A random sample may assess general compliance.

A targeted sample may evaluate a known risk.

A probe sample may determine whether a broader review is necessary.

Data analytics may be used to identify outliers or unusual patterns before records are selected.

Audit criteria should be documented before the audit begins.

The organization should identify the controlling documentation, coding, coverage, contractual or regulatory requirements.

Monitoring Plan

Monitoring differs from auditing.

Auditing generally evaluates a defined sample or process at a particular point in time.

Monitoring is an ongoing management activity used to confirm that controls continue to function.

Examples include monthly authorization exception reports, quarterly modifier analysis, weekly exclusion screening validation, credit balance aging, privacy access reports, training completion reports and corrective action status.

The work plan should identify which controls require continuous or periodic monitoring.

Monitoring responsibilities should be assigned primarily to operational leaders, with compliance oversight and independent validation.

Education Plan

The work plan should identify required compliance education.

Education should be based on identified risk rather than limited to a universal annual course.

If audits identify inadequate documentation of functional improvement, physicians and clinical staff should receive targeted education.

If services are being performed without valid authorization, schedulers and authorization teams should receive workflow training and competency assessment.

If vendors are accessing information outside their approved scope, privacy, security and vendor management education should be implemented.

Education should be connected to measurable operational expectations.

Policy Plan

The work plan should identify policies requiring creation, revision or retirement.

Policy priorities should be based on regulatory changes, risk assessment findings, workflow changes, investigation results and organizational growth.

A policy should not be updated merely to change its review date.

The review should determine whether the policy remains accurate, whether the related workflow functions as written and whether employees can understand and apply it.

Corrective Action Integration

Open corrective action plans should be incorporated into the compliance work plan.

Each corrective action should have an accountable owner, completion date, evidence requirement and validation process.

A finding should not be considered resolved when a department states that the issue has been corrected.

Compliance should verify completion and determine whether the corrective action reduced the underlying risk.

Repeat findings should trigger escalation and evaluation of whether the original corrective action was insufficient.

Resource Planning

The work plan should identify the resources necessary to complete each activity.

Resources may include internal staff, external coding experts, legal counsel, clinical reviewers, data analysts, technology support and education platforms.

Leadership should understand the difference between approving a work plan and funding its execution.

A work plan without sufficient personnel, data access or technical support cannot function effectively.

Governing Body Approval

The compliance committee should review the proposed work plan before it is presented to the governing body.

The governing body should understand how the work plan relates to the risk assessment and whether the organization has sufficient resources to complete it.

Approval should be documented.

The governing body should receive regular progress reports describing completed activities, findings, overdue projects, corrective actions and material changes in risk.

The OIG compliance effectiveness resource specifically identifies risk based work plans, governing body approval and regular reporting as measures organizations may consider when evaluating program effectiveness.

Work Plan Changes

The work plan should remain flexible.

New risks may require priorities to change during the year.

A government inquiry, payer audit, data breach, significant overpayment, new regulation or serious patient safety concern may require the organization to delay a lower priority project.

Changes should be documented and approved through the established governance process.

Removing a project without explanation can create the appearance that the organization ignored an identified risk.

Performance Tracking

The compliance officer should maintain a work plan dashboard.

The dashboard should identify project status, milestones, findings, corrective actions, responsible owners and overdue items.

Status categories should be clearly defined.

A project should not be reported as complete when the audit has been performed but findings remain unresolved.

Completion should include reporting, corrective action assignment and planned validation.

Application to MSK Specialty Care

A specialty specific compliance work plan may include provider documentation audits, procedure frequency reviews, prior authorization validation, modifier analysis, place of service review, implant reconciliation and payer policy implementation testing.

The plan should follow the entire service pathway.

For example, a spinal cord stimulation review should examine patient selection, psychological evaluation, conservative treatment, trial documentation, permanent implant criteria, authorization, operative documentation, coding and payment.

A narrow claim review may miss the point where noncompliance originated.

GoHealthcare Insights

A compliance work plan is not a calendar of meetings.

It is the organization’s documented commitment to investigate, measure and reduce identified risk.

The most important question is not whether the project occurred. It is whether the project changed the organization’s risk position.

Leadership Perspective

Leadership should resist the temptation to approve an excessively broad work plan.

A focused work plan that addresses the organization’s highest risks and is completed thoroughly provides greater protection than a long list of unfinished projects.

Key Takeaways

The Compliance Work Plan should be risk based, specific, measurable and approved by leadership.

Every project should have an accountable owner, defined scope, completion standard and reporting pathway.

The work plan should remain flexible enough to address significant emerging risks.

Back to framework navigation
08

Code of Conduct and Ethical Standards

Purpose

The Code of Conduct establishes the organization’s ethical foundation and communicates the standards expected of every person acting on its behalf.

It should explain how the organization expects employees, physicians, executives, owners, contractors, vendors and other representatives to behave when making clinical, financial, operational and professional decisions.

The code should not function as a ceremonial document signed during orientation and rarely consulted afterward.

It should guide behavior, support reporting, establish accountability and provide a foundation for discipline.

The Department of Justice identifies an accessible and broadly applicable code of conduct as an important component of a well designed compliance program. OIG physician compliance resources similarly emphasize written compliance standards, education, communication and well publicized disciplinary expectations.

Scope and Applicability

The Code of Conduct should apply to the governing body, owners, executives, physicians, advanced practice providers, employees, contractors, temporary personnel, students, volunteers and applicable third parties.

The code should apply across every entity and location unless a documented legal or operational reason requires a separate standard.

Contractors and vendors performing high risk functions should agree to follow relevant provisions.

This is particularly important for billing companies, prior authorization vendors, offshore teams, technology vendors and business associates with access to patient information.

Core Ethical Principles

The code should establish clear expectations concerning integrity, lawful conduct, patient welfare, documentation accuracy, billing honesty, privacy, confidentiality, conflicts of interest, professional behavior and reporting responsibility.

It should state that the organization will not knowingly submit false or unsupported claims, alter documentation improperly, conceal overpayments, misuse patient information, retaliate against reporters or tolerate conduct that compromises patient safety.

The code should also establish that financial pressure, productivity expectations and business relationships do not justify noncompliance.

Patient Centered Ethical Conduct

The organization should place patient welfare at the center of ethical decision making.

Clinical recommendations should be based on appropriate professional judgment and documented medical necessity.

Patients should receive accurate information about treatment, alternatives, risks, financial responsibility and authorization status.

The organization should not allow reimbursement opportunity, ownership interests or productivity incentives to improperly influence patient selection.

Ethical conduct includes respecting patient dignity, privacy, cultural differences, communication needs and rights.

Documentation Integrity

The code should state that medical, billing, financial and operational records must be complete, accurate and timely.

Personnel should not falsify dates, copy unsupported information, alter records to obtain approval, document services that were not performed or change a record to support billing after an audit begins.

Late entries, corrections and amendments should follow approved documentation standards and preserve the integrity of the original record.

Physicians and clinical personnel should understand that documentation supports both patient care and the organization’s representation to payers.

Billing and Financial Integrity

The code should prohibit knowingly inaccurate coding, duplicate billing, unbundling, inappropriate modifier use, unsupported charges and concealment of overpayments.

Employees should be instructed to raise concerns when the medical record does not support the service or when billing instructions conflict with applicable requirements.

Personnel should not be pressured to release claims simply because payment is needed.

Financial integrity also includes accurate cost estimates, patient balances, refunds, contractual adjustments and vendor payments.

Medical Necessity and Utilization

The code should establish that services must be clinically appropriate and supported by applicable documentation.

Prior authorization approval does not independently establish medical necessity.

The treating provider remains responsible for documenting the clinical rationale for the service.

Personnel should not omit unfavorable treatment history, exaggerate symptoms or manipulate documentation to satisfy payer criteria.

GoHealthcare’s specialty content emphasizes that medical necessity, documentation and utilization must be evaluated as connected elements of compliant MSK operations.

Conflicts of Interest

The code should require disclosure of relationships that could influence professional or business judgment.

Potential conflicts may involve referral sources, vendors, laboratories, pharmacies, device manufacturers, facilities, consulting relationships, ownership interests, family relationships and outside employment.

Disclosure does not automatically mean the relationship is prohibited.

It allows the organization to evaluate the arrangement, implement safeguards or require recusal.

Failure to disclose a material conflict should be treated as a compliance concern.

Gifts, Entertainment and Business Courtesies

The code should establish rules governing gifts, meals, travel, entertainment, discounts and other benefits.

The policy should address both benefits offered by the organization and benefits received by workforce members.

Personnel should not accept or offer anything intended to influence referrals, purchasing decisions, clinical judgment or business selection.

The code should provide practical examples because employees may not recognize that an apparently modest benefit can create risk when connected to referral or purchasing decisions.

Privacy and Confidentiality

The code should require protection of patient, employee, business and proprietary information.

Personnel should access patient information only for legitimate job responsibilities.

Curiosity, personal relationships or convenience do not justify access.

Information should not be discussed in public areas, shared through unapproved systems or disclosed to unauthorized individuals.

Confidentiality responsibilities should continue after employment or contractual relationships end.

Professional Conduct

The organization should establish expectations for respectful, safe and professional behavior.

Harassment, discrimination, intimidation, retaliation, violence, deliberate disruption and abusive conduct should be prohibited.

Professional conduct standards should apply to influential physicians and high performing employees in the same manner that they apply to other workforce members.

Failure to enforce standards consistently weakens the credibility of the entire compliance program.

Duty to Report

The code should clearly state that workforce members have a responsibility to report suspected misconduct, unsafe conditions, policy violations and regulatory concerns.

The code should identify available reporting channels and explain nonretaliation protections.

Personnel should not be expected to prove that misconduct occurred before raising a concern.

Good faith reporting should be protected even when an investigation does not confirm the allegation.

Leadership Responsibilities

Managers, executives and physicians in leadership positions should have additional responsibilities.

They should model appropriate conduct, respond to concerns, prevent retaliation, enforce policies and escalate matters when necessary.

A manager who receives a compliance concern should not conduct an informal private resolution when the matter requires compliance review.

Leadership accountability should be stated directly in the code.

Distribution and Acknowledgment

The Code of Conduct should be distributed during orientation and periodically thereafter.

Personnel should acknowledge that they received, understood and agreed to follow it.

The organization should provide translated or accessible versions when language, literacy or disability considerations affect understanding.

Acknowledgment should not replace education.

The organization should explain how the code applies to common decisions and workflows.

Enforcement

Violations should result in fair and consistent corrective or disciplinary action.

Discipline should be based on the nature, severity, intent and consequences of the conduct.

The organization should consider whether the individual reported the issue, cooperated with the investigation or attempted to conceal it.

Executives, owners and physicians should not receive preferential treatment.

Application to MSK Specialty Care

The Code of Conduct should address real specialty risks.

Examples include altering documentation to obtain procedure approval, performing a different level than authorized, failing to disclose an ownership interest, directing staff to use an unsupported modifier or submitting a claim despite known medical necessity deficiencies.

The code should make clear that production, collections and referral relationships do not override ethical and compliance responsibilities.

GoHealthcare Insights

The Code of Conduct should be written for real people making real decisions.

Employees should be able to recognize themselves, their responsibilities and their risks within the document.

A code that contains only broad legal statements may be technically complete but operationally ineffective.

Leadership Perspective

Organizational culture is revealed by the conduct leadership is willing to confront.

A code becomes credible only when the organization applies it consistently, including when the individual involved is influential, profitable or difficult to replace.

Key Takeaways

The Code of Conduct must be accessible, understandable and applicable to all workforce members and relevant third parties.

It should address clinical integrity, billing honesty, privacy, conflicts, professional conduct and reporting responsibilities.

Leadership must reinforce the code through behavior, education and consistent enforcement.

Back to framework navigation
09

Policy and Procedure Governance

Purpose

Policy and Procedure Governance establishes how organizational requirements are converted into approved, accessible and enforceable operating instructions.

Policies define what the organization requires.

Procedures define how personnel perform the work.

Together, they translate legal, regulatory, contractual and ethical obligations into daily operations.

The Department of Justice evaluates how organizations design, approve, update, communicate and operationally integrate policies and procedures. It also considers whether policies address the organization’s identified risks, remain accessible and incorporate lessons learned and emerging technology risks.

Policy Architecture

The organization should establish a defined policy hierarchy.

The hierarchy may include the Code of Conduct, enterprise policies, departmental policies, standard operating procedures, work instructions, checklists, decision trees, forms and job aids.

Each document type should have a defined purpose.

An enterprise policy should establish the organizational standard.

A departmental procedure should explain how the standard is implemented within a specific function.

A checklist may provide point of service verification.

A job aid may support a complex or infrequently performed task.

The organization should avoid placing every operational detail inside one lengthy policy.

Policy Inventory

The organization should maintain a centralized policy inventory.

The inventory should identify each policy’s title, owner, approval authority, effective date, review date, version, related procedures and status.

The inventory should identify duplicate, conflicting, expired or obsolete documents.

Policies stored informally in individual departments, email folders or personal files create significant risk.

Employees may follow different versions without knowing which one is controlling.

Policy Ownership

Each policy should have an accountable owner.

The owner should understand the subject matter, related workflow and applicable requirements.

Compliance may coordinate policy governance, but operational leaders should own policies governing their departments.

For example, patient access leadership should own authorization procedures. Revenue cycle leadership should own claim submission procedures. Information technology should own access management procedures. Compliance should review the documents for regulatory alignment and consistency.

Drafting Standards

Policies and procedures should be clear, practical and written for the intended audience.

The document should identify its purpose, scope, definitions, responsibilities, required actions, exceptions, documentation requirements, monitoring process and related authorities.

Ambiguous terms should be defined.

Words such as promptly, regularly or appropriately should be replaced with specific expectations whenever possible.

A procedure should identify who performs each action, when it occurs, what evidence is created and what happens when the standard cannot be met.

Legal and Regulatory Review

Policies addressing significant legal, regulatory, privacy, employment or financial matters should receive appropriate compliance or legal review.

Legal review should confirm that the document accurately reflects controlling requirements.

Operational review should confirm that the procedure can be performed in practice.

A legally accurate policy that cannot be operationalized will not create an effective control.

Approval Authority

The organization should define who may approve each policy category.

The governing body may approve the Code of Conduct and enterprise compliance policies.

Executive leadership may approve organization wide operational policies.

Department leaders may approve detailed procedures within established authority.

Approval should be documented and retained.

Employees should not create mandatory operating rules outside the approved governance process.

Version Control

Every policy and procedure should display a version number, approval date, effective date, review date and owner.

Previous versions should be retained according to the record retention schedule.

The organization should be able to determine which policy was effective at a specific point in time.

This is important during audits, investigations, litigation and employee disputes.

Uncontrolled copies should be minimized.

Printed copies should identify that the electronic version is the controlling document when appropriate.

Distribution and Accessibility

Policies should be available to personnel who need them.

Access should be simple, searchable and appropriate to the workforce’s language and technological capabilities.

Employees should not need to know the exact policy title to locate relevant guidance.

Policies should be organized by subject, department and workflow.

The Department of Justice specifically considers whether employees and relevant third parties can access policies, whether linguistic barriers are addressed and whether organizations confirm that personnel know how to locate them.

Communication and Acknowledgment

Material new or revised policies should be communicated to affected personnel.

Communication should explain what changed, why it changed, when it takes effect and what employees must do differently.

Acknowledgment may be required for high risk policies, but acknowledgment alone does not establish understanding.

Training or competency validation may be necessary when the policy changes a clinical, billing, authorization, privacy or safety workflow.

Workflow Integration

Policies should be integrated into the systems and workflows where decisions occur.

An authorization policy should be reflected in scheduling controls, work queues, documentation requirements and escalation rules.

A privacy policy should be reflected in system access, role assignments, audit logs and termination procedures.

A coding policy should be reflected in charge review, edits, education and auditing.

The organization should not rely on employees to remember a policy when the system could prevent the error.

Exception Management

The organization should establish a formal process for policy exceptions.

An exception should identify the policy involved, reason, duration, approving authority, safeguards and required documentation.

Exceptions should be limited and monitored.

A temporary exception that continues indefinitely becomes an undocumented policy change.

Emergency exceptions should be reviewed after the event to determine whether the policy or workflow requires revision.

Interim and Emergency Policies

Regulatory changes or urgent operational events may require interim guidance before a complete policy can be developed.

Interim instructions should identify their authority, effective date, expiration date and responsible owner.

They should be incorporated into the permanent policy system as soon as practical.

Temporary email instructions should not become the organization’s long term operating standard.

Policy Review Cycle

Policies should be reviewed according to risk, regulatory requirements and operational change.

A routine review cycle may be annual, biennial or another defined period.

High risk policies may require more frequent review.

A review should determine whether the policy remains legally accurate, operationally relevant and consistent with actual practice.

The reviewer should also consider audit findings, reported concerns, technology changes and lessons learned.

Policy Effectiveness Testing

The organization should test whether policies are working.

Testing may include staff interviews, workflow observation, record review, system testing, audit results and exception analysis.

The fact that employees signed an acknowledgment does not prove that the policy is effective.

A policy is effective when personnel understand it, follow it and produce the intended control outcome.

Application to MSK Specialty Care

MSK policy governance should address areas where clinical and administrative requirements intersect.

For example, a repeat procedure policy should define documentation of prior response, required intervals, frequency limitations, authorization verification, scheduling controls, coding review and escalation.

A policy that addresses only one of these functions may leave the remainder of the workflow uncontrolled.

GoHealthcare Insights

Policy governance fails when organizations confuse document completion with operational implementation.

A policy is not complete when it is approved.

It is complete when the affected people understand it, the workflow supports it, evidence is created and leaders can verify compliance.

Leadership Perspective

Leaders should be cautious when staff say, “We have a policy for that.”

The relevant question is whether people follow it consistently and whether the organization can prove that the control works.

Key Takeaways

Policies and procedures must be governed through a documented lifecycle.

Every document should have an owner, approval authority, effective date, review cycle and version history.

Policy effectiveness must be demonstrated through workflow integration, education, monitoring and testing.

Back to framework navigation
10

Compliance Education and Workforce Training

Purpose

Compliance Education and Workforce Training ensure that personnel understand the requirements applicable to their roles and possess the competence necessary to perform their responsibilities correctly.

Training should not be treated as an annual administrative exercise.

It should be a risk based workforce capability program connected to policies, workflows, job responsibilities and identified compliance deficiencies.

The Department of Justice describes appropriately tailored training and communication as a hallmark of a well designed compliance program. OIG physician guidance includes appropriate training and education among the foundational elements of a physician practice compliance program.

Training Governance

The organization should establish a formal compliance training plan.

The plan should identify required audiences, topics, delivery methods, frequency, completion standards, competency requirements and documentation expectations.

Training responsibilities should be divided among compliance, human resources, clinical leadership, privacy, security, revenue cycle, quality and departmental management.

Compliance should coordinate the enterprise program, but subject matter leaders should provide specialized instruction within their areas.

New Workforce Orientation

New employees, physicians, contractors and applicable third parties should receive compliance education as part of onboarding.

Orientation should address the Code of Conduct, reporting channels, nonretaliation, privacy, security, documentation integrity, billing honesty, conflicts of interest and individual responsibilities.

Personnel should complete required training before receiving unrestricted access to systems or independently performing high risk work.

Orientation should be adapted to the individual’s role.

A physician, prior authorization specialist, coder, scheduler and information technology administrator do not require identical instruction.

Annual Core Compliance Education

All workforce members should receive periodic core compliance education.

Core education should address the compliance program, Code of Conduct, reporting responsibilities, fraud and abuse awareness, privacy, security, conflicts, record integrity and disciplinary expectations.

Training should include current organizational risks and lessons learned.

Repeating the same generic presentation every year may satisfy a completion requirement but may not improve performance.

The organization should update annual training based on audit findings, investigations, regulatory changes, complaints and emerging risks.

Role Specific Education

Personnel should receive training directly related to their responsibilities.

Physicians and clinical staff should understand documentation, medical necessity, informed consent, professional standards and applicable coverage requirements.

Patient access personnel should understand eligibility, payer identification, authorization requirements, financial communication and scheduling controls.

Prior authorization teams should understand payer criteria, submission routing, documentation review, status tracking and escalation.

Coders should understand coding standards, modifiers, place of service, bundling and specialty specific requirements.

Billing personnel should understand claim submission, corrections, refunds, overpayments and payer requirements.

Managers should understand escalation, nonretaliation, investigation preservation and policy enforcement.

Physician Education

Physician education should be concise, relevant and tied to clinical workflow.

Training should explain how documentation supports patient care, medical necessity, authorization, coding and audit defense.

Physicians should receive specialty specific examples rather than broad compliance terminology.

For example, training for medial branch blocks and radiofrequency ablation should address pain history, conservative treatment, diagnostic block results, percentage and duration of relief, anatomical levels, laterality and frequency requirements.

Training for spinal cord stimulation should address patient selection, psychological assessment, trial response, functional outcomes and permanent implantation criteria.

OIG provides physician compliance resources and training materials concerning fraud and abuse laws, documentation, exclusions and effective compliance programs.

Manager and Supervisor Training

Managers should receive additional education concerning their leadership responsibilities.

They should understand how to receive concerns, preserve confidentiality, prevent retaliation, escalate potential violations and enforce policies consistently.

Managers should not conduct informal investigations without coordination when the matter involves fraud, privacy, patient safety, harassment or significant regulatory exposure.

Supervisors should also understand that productivity pressure does not justify bypassing required controls.

Third Party and Offshore Workforce Training

Contractors, vendors and offshore teams should receive training appropriate to the functions they perform and the information they access.

Training requirements should be included in contracts when material.

The organization should not assume that a vendor’s internal training satisfies its own obligations.

It should determine whether the vendor’s education addresses the organization’s policies, payer environment, specialty requirements, reporting channels and privacy expectations.

Language, time zone and cultural considerations should be addressed without reducing the standard of performance.

Delivery Methods

Training may be delivered through live sessions, web based modules, case studies, simulations, workflow demonstrations, written guidance and competency exercises.

The method should fit the subject and audience.

A short online module may be appropriate for general awareness.

A complex coding or authorization workflow may require interactive instruction and supervised practice.

Case based training is particularly effective for specialty healthcare operations because it shows how several requirements apply to one patient scenario.

CMS maintains Medicare Learning Network resources, web based education and provider compliance materials that may support organizational training programs.

Competency Validation

Training completion does not prove competence.

The organization should validate whether personnel can apply the instruction.

Validation may include testing, case review, observation, chart abstraction, mock authorization, coding exercises or supervised workflow completion.

High risk responsibilities should require a defined passing standard.

Employees who do not demonstrate competence should receive additional training and should not perform the task independently until competency is confirmed.

Corrective and Remedial Education

Audit findings, errors, complaints and investigations should trigger targeted education when knowledge or skill contributed to the problem.

Remedial education should address the specific deficiency.

A general annual compliance course is not an adequate response to repeated modifier errors or authorization failures.

Education should not replace corrective action when the problem involves intentional misconduct, inadequate supervision or defective system design.

The organization should determine whether the root cause is knowledge, behavior, workload, technology, policy or management.

Training Documentation

The organization should maintain evidence of training.

Records should identify the participant, topic, instructor, date, delivery method, materials, completion status, assessment result and required follow up.

Training records should be retained according to the organization’s record retention policy.

The organization should be able to demonstrate which version of the training was provided and which policies were in effect.

Training Effectiveness

Training effectiveness should be measured through more than completion rates.

Measures may include test performance, audit results, error rates, reported concerns, repeat findings, workflow adherence and competency validation.

A high completion rate with continuing operational failures indicates that the training may not be effective.

The organization should evaluate whether the content was relevant, whether employees understood it and whether behavior changed.

Training Updates

Education should be updated when requirements, policies, technology or operations change.

Personnel should receive instruction before implementing a new workflow whenever possible.

Urgent regulatory changes may require interim education followed by more comprehensive training.

Training materials should be reviewed for accuracy and retired when outdated.

Application to MSK Specialty Care

MSK compliance training should reflect the full patient and revenue pathway.

Clinical staff, authorization personnel, schedulers, coders and billers should understand how their work affects one another.

A physician documentation deficiency may prevent authorization.

An authorization error may require a procedure delay.

A procedure change may affect coding and payment.

Integrated education helps the workforce understand that compliance is not owned by one department.

GoHealthcare Insights

The most effective training is delivered close to the work.

Employees should be able to connect the requirement to the decision they make, the screen they use, the document they review and the evidence they must preserve.

Training that remains abstract will rarely change operational behavior.

Leadership Perspective

Executives should not measure education only by whether employees completed a course.

The real measure is whether the workforce can perform the work correctly and whether the organization experiences fewer preventable failures.

Key Takeaways

Compliance training should be risk based, role specific and connected to actual workflows.

High risk responsibilities require competency validation, not only attendance.

Training effectiveness should be evaluated through operational performance, audits and reduction of repeat findings.

Back to framework navigation
11

Confidential Reporting and Nonretaliation

Purpose

Confidential reporting and nonretaliation protections create a trusted mechanism through which workforce members, physicians, contractors, patients, vendors and other stakeholders can raise concerns without fear of punishment, intimidation or professional harm.

A healthcare organization cannot identify every compliance failure through audits, technology or management oversight. Individuals working closest to the process often recognize problems first. They may observe unsupported billing, altered documentation, privacy violations, unsafe clinical practices, improper financial relationships, authorization manipulation, exclusion screening failures or pressure to disregard policy.

The reporting system must make it practical and psychologically safe for those concerns to reach the compliance function.

The HHS Office of Inspector General recommends written confidentiality and nonretaliation policies, multiple methods of communication, anonymous reporting options and centralized logging of disclosures regardless of how the concern is received.

Reporting Culture

The organization should establish a culture in which reporting a concern is viewed as a professional responsibility rather than disloyalty.

Leaders should consistently communicate that early reporting allows the organization to protect patients, correct errors, resolve overpayments, improve workflows and prevent larger regulatory exposure.

Employees should not be expected to prove that wrongdoing occurred before reporting a concern. Their responsibility is to raise a good faith question based on information they observed or reasonably believe may require review.

The compliance function should distinguish between a report, an allegation and a substantiated finding. Receiving a report does not establish that misconduct occurred. It establishes that the organization has information requiring an appropriate assessment.

A healthy reporting culture does not measure success by the absence of complaints. Very low reporting volume may indicate fear, lack of awareness, inaccessible reporting channels or limited trust in leadership.

Available Reporting Channels

The organization should provide several methods for reporting concerns.

Channels may include direct communication with the compliance officer, a confidential telephone line, an independently administered hotline, secure electronic reporting, a dedicated email address, written correspondence, management escalation and direct access to designated board representatives.

Anonymous reporting should be available when permitted by applicable law.

Reporting information should be visible in employee handbooks, training materials, internal websites, clinical and administrative work areas, remote workforce portals and vendor onboarding materials.

OIG guidance recognizes that workforce members have different communication preferences and recommends providing familiar and accessible ways to reach compliance personnel.

Accessibility

Reporting systems should be accessible to the organization’s complete workforce.

The organization should consider language, disability, digital access, literacy, remote employment, offshore operations and different work schedules.

A telephone hotline available only during headquarters business hours may not adequately serve a distributed workforce.

Contractors, temporary personnel and vendors performing delegated services should know how to report concerns involving the organization.

Patients and family members should also have an appropriate route for raising privacy, financial, safety or ethical concerns that may require compliance review.

Confidentiality

The organization should protect the identity of a reporter to the greatest extent reasonably possible.

Information should be shared only with individuals who need it to evaluate, investigate or resolve the concern.

The organization should not promise absolute confidentiality when disclosure may be required to conduct a fair investigation, respond to legal process, protect patient safety or notify a government authority.

Reporters should be informed that their identity will be safeguarded but may become known when circumstances make disclosure necessary. OIG specifically recognizes this limitation and recommends communicating it clearly.

Investigation files should not be stored in general departmental folders or incorporated into ordinary personnel records unless a documented reason requires it.

Nonretaliation Standard

The organization should prohibit retaliation against any person who raises a concern in good faith, participates in an investigation, provides information, refuses to engage in suspected misconduct or exercises a legally protected right.

Retaliation may be direct or indirect.

It may include termination, demotion, reduced hours, unfavorable scheduling, exclusion from meetings, loss of referrals, denial of advancement, intimidation, threats, harassment, negative evaluations, undesirable assignments or interference with professional relationships.

Protection should apply even when an investigation does not substantiate the original concern, provided the report was made honestly and without intentional fabrication.

Knowingly making a false allegation may be addressed through the disciplinary process, but leadership should not characterize an unsubstantiated good faith report as a false report.

Leadership and Management Responsibilities

Managers and supervisors should receive specific training on how to respond when an employee raises a concern.

They should listen without making promises, avoid conducting an unauthorized investigation, preserve relevant information and notify the compliance function promptly.

Managers should not tell employees to resolve potentially serious concerns privately with the person involved.

They should not discourage reporting because an issue may affect productivity, a physician relationship, departmental performance or financial results.

A manager’s failure to escalate a known concern should be evaluated separately from the underlying conduct.

Centralized Intake and Disclosure Log

Every compliance concern should be entered into a centralized disclosure log.

The log should capture the date received, method of reporting, issue category, affected department, assigned reviewer, risk classification, investigation status, actions taken, closure date and whether retaliation concerns were identified.

Reports received by managers, human resources, privacy personnel, legal counsel, clinical leaders or other departments should be communicated to the compliance officer when they involve potential regulatory, billing, ethical, privacy or patient safety concerns.

OIG recommends logging disclosures regardless of whether they are made directly to compliance, through another leader or through an anonymous mechanism.

The organization should avoid fragmented reporting systems in which related concerns remain isolated across departments.

Triage and Risk Classification

Reports should be evaluated promptly according to potential severity.

Matters involving immediate patient danger, potential fraud, privacy breaches, controlled substance diversion, falsification, retaliation, exclusion, intentional claim manipulation or interference with an investigation should receive urgent escalation.

Routine policy questions or isolated operational errors may follow a standard review process.

The initial classification should determine who must be notified, whether records must be preserved, whether claims should be held and whether legal counsel or clinical leadership should be involved.

Risk classification may change as additional information becomes available.

Protection Against Interference

No person should be permitted to obstruct reporting, identify an anonymous reporter improperly, destroy evidence, coach witnesses or pressure employees to change their accounts.

Attempts to interfere with the reporting or investigation process should be treated as independent compliance violations.

Senior executives, physician owners and high revenue producers should be subject to the same reporting and investigation standards as other workforce members.

Reporter Communication

When possible, the organization should acknowledge receipt of the report and provide reasonable updates.

The reporter may not be entitled to confidential personnel, legal or disciplinary information. However, silence can undermine trust and discourage future reporting.

The organization can communicate that the matter was reviewed and appropriate action was taken without disclosing protected details.

Anonymous reporting systems should permit two way communication when technically feasible so investigators can request clarification while preserving anonymity.

Monitoring for Retaliation

The compliance function should assess retaliation risk during and after investigations.

Monitoring may include reviewing changes in employment status, assignments, schedules, evaluations, compensation, privileges or workplace treatment.

The reporter should know how to raise a retaliation concern.

A retaliation allegation should be investigated independently and promptly, even when the original concern was not substantiated.

Reporting Program Effectiveness

The organization should evaluate whether the reporting program functions in practice.

Relevant measures include reporting volume, reporting sources, anonymous report percentage, issue categories, response time, investigation cycle time, substantiation rate, repeat allegations, retaliation concerns and employee awareness.

Leadership should not create targets that reward low complaint volume.

The objective is not to minimize reports. It is to ensure that concerns are raised, assessed and resolved before they become larger failures.

Application to MSK Specialty Care

MSK specialty organizations should ensure that clinical and administrative personnel can report concerns involving medical necessity, procedure frequency, prior authorization, coding, implants, controlled substances, patient safety and physician conduct.

A prior authorization specialist may recognize that documentation is being changed solely to satisfy payer criteria.

A coder may be instructed to use a modifier that the record does not support.

A nurse may observe that the scheduled procedure differs from the authorized service.

A billing employee may identify recurring payments that appear inconsistent with the claim.

Each of these employees needs a trusted route to escalate the concern without fear of retaliation.

GoHealthcare Insights

Employees working inside prior authorization, coding, clinical documentation and revenue cycle processes frequently see risk before executive leadership does.

The organization loses one of its strongest compliance controls when employees believe that reporting will create personal consequences.

An effective disclosure program transforms frontline knowledge into organizational intelligence.

Leadership Perspective

Leaders should not ask why an employee reported a concern outside the chain of command.

They should ask whether the chain of command was trusted, accessible and capable of addressing the concern appropriately.

A workforce that speaks up early protects the organization. A workforce that remains silent forces leadership to discover problems through denials, audits, patient harm or government inquiry.

Key Takeaways

Reporting channels must be confidential, accessible, visible and available to employees, physicians, contractors and relevant third parties.

Nonretaliation protections must be enforced in practice, not merely stated in policy.

Every report should be logged, risk classified, reviewed and tracked through documented resolution.

Back to framework navigation
12

Compliance Investigations

Purpose

Compliance investigations provide a structured method for determining what occurred, whether a legal or policy violation may exist, who and what were affected, whether patients or payers were harmed and what corrective action is required.

An investigation should be objective, timely, appropriately scoped and supported by reliable evidence.

The purpose is not to prove a predetermined conclusion. It is to establish the facts sufficiently for the organization to make informed clinical, operational, financial and legal decisions.

OIG guidance recognizes that reports, audit results and monitoring findings may require investigation and that an investigation may determine that no wrongdoing occurred, identify an overpayment or uncover potential misconduct.

Investigation Governance

The organization should maintain a written investigation protocol.

The protocol should define intake, triage, authority, confidentiality, evidence preservation, investigator assignment, interview procedures, documentation standards, legal involvement, reporting and closure.

The protocol should distinguish compliance investigations from routine human resources reviews, clinical peer review, patient safety analysis, security incident response and legal proceedings.

Some matters may require several functions to work together. The organization should identify the lead function and preserve clear roles to avoid duplication, inconsistent conclusions or inappropriate information sharing.

Initial Assessment

Every reported matter should receive a documented initial assessment.

The assessment should consider the nature of the allegation, source reliability, potential patient impact, regulatory exposure, financial significance, affected individuals, scope of possible conduct and urgency.

The organization should determine whether immediate action is required.

Immediate action may include protecting a patient, restricting system access, securing controlled substances, preserving records, suspending a billing practice, holding claims, removing an individual from a workflow or notifying legal counsel.

Interim action should be designed to prevent continuing harm without presuming guilt.

Investigator Independence and Competency

The investigator should be sufficiently independent from the people and functions involved.

A department manager should not investigate allegations concerning their own instructions, performance or supervisory conduct.

Matters involving executives, owners, compliance personnel or influential physicians may require an outside investigator or independent counsel.

The investigator should understand the relevant clinical, regulatory and operational environment.

A case involving spinal cord stimulation criteria, physician compensation, privacy access or coding rules may require specialized clinical, legal, coding or technical expertise.

Investigation Plan

The investigator should establish a written plan proportionate to the matter.

The plan should identify the issues to be evaluated, applicable requirements, records to be reviewed, individuals to be interviewed, systems involved, relevant time period and anticipated reporting structure.

The scope should be broad enough to determine whether the conduct is isolated or systemic.

An allegation concerning one claim may reveal a template, system edit or management instruction affecting hundreds of claims.

The investigation should not expand without discipline. Material changes to scope should be documented with the reason for expansion.

Evidence Preservation

Relevant evidence should be preserved immediately when there is a reasonable possibility that information could be altered, deleted or lost.

Evidence may include medical records, claims, authorization submissions, emails, messages, contracts, system logs, call recordings, financial records, audit trails, personnel records, policies, meeting records and vendor communications.

The organization should suspend routine destruction when a legal hold or preservation obligation applies.

Metadata and system audit trails may be critical when the matter involves record alteration, unauthorized access or retrospective documentation.

Personnel should be instructed not to destroy, modify or discuss evidence outside the investigation process.

Medical Record Integrity

When an investigation involves patient records, the organization should preserve the original record and its audit history.

Personnel should not add documentation solely to improve the organization’s position after a concern, denial, audit request or investigation has begun.

Legitimate late entries, corrections or addenda should comply with applicable standards and clearly identify the author, date and reason.

The original entry should remain visible.

Interviews

Interviews should be planned and conducted consistently.

The investigator should explain the purpose of the interview, the organization’s expectation of truthful cooperation, confidentiality limitations and nonretaliation protections.

Questions should be open enough to obtain the individual’s account before presenting specific evidence.

The investigator should distinguish what the person directly observed from what they heard from others or inferred.

Interview notes should document material statements accurately.

The investigator should avoid promises concerning outcomes, discipline or confidentiality that the organization cannot guarantee.

Data and Transaction Analysis

Many compliance investigations require analysis beyond individual interviews.

Claims, procedure volumes, modifier use, authorization patterns, documentation dates, access logs and payment data may reveal the scope of the issue.

Data analysis should examine whether the pattern extends across providers, locations, payers, procedures or time periods.

The investigation should also identify control failures.

An individual error may be enabled by an inaccurate system rule, poorly designed template, inadequate supervision or incentive structure.

Legal Counsel and Privilege

The organization should involve legal counsel when the matter presents significant legal exposure, possible government disclosure, patient harm, privilege concerns, potential litigation or senior leadership involvement.

The presence of an attorney does not automatically make all investigation materials privileged.

The purpose, direction and handling of the investigation should be structured carefully when legal advice is being sought.

Routine operational compliance work should not be inaccurately labeled privileged merely to prevent disclosure.

Findings Standard

The organization should define the standard used to reach factual findings.

Internal compliance investigations commonly determine whether available evidence shows that conduct more likely than not occurred, unless another standard is required by law, policy, contract or professional process.

The report should distinguish established facts, disputed facts, reasonable inferences, unresolved questions and legal conclusions.

A finding that a policy was violated should identify the policy, evidence and reasoning.

The organization should avoid overstating conclusions when the evidence remains incomplete.

Investigation Report

Material investigations should produce a written report or documented closure memorandum.

The record should describe the allegation, scope, methodology, evidence reviewed, interviews conducted, factual findings, applicable requirements, financial implications, control weaknesses and recommended actions.

The report should identify any limitations, including unavailable records, uncooperative witnesses or incomplete data.

Reports should be written objectively and should not contain unnecessary personal information or speculation.

Financial and Claims Analysis

When the investigation identifies potential billing error or overpayment, the organization should determine the affected population, relevant period and appropriate financial response.

The analysis may require claim review, statistical expertise, payer contract interpretation and legal advice.

The organization should not limit its review to the initial claim when evidence suggests a broader pattern.

Claims that may be unsupported should be held when appropriate while the investigation proceeds.

Government and Payer Disclosure

Some findings may require repayment, breach notification, payer communication, self disclosure or government reporting.

The organization should evaluate these obligations promptly with qualified counsel and appropriate subject matter experts.

Failure to act after credible evidence has been identified may create exposure separate from the original conduct.

Investigation Closure

A matter should not be closed until the organization has documented the factual determination, financial resolution, corrective action, disciplinary decision, policy changes and follow up monitoring required.

The closure record should identify who approved the conclusion.

The reporter should receive an appropriate status communication when possible.

Closed matters should remain available for trend analysis and future risk assessments.

Trend Analysis

Individual investigations should be reviewed collectively.

Multiple reports involving the same department, provider, manager, workflow or control may reveal systemic risk even when each case appears limited.

The compliance committee should receive deidentified trend information sufficient to identify repeated issues and evaluate organizational response.

Application to MSK Specialty Care

A specialty investigation may involve whether procedures were performed at levels different from those authorized, whether diagnostic block results were overstated, whether repeat procedures complied with frequency limits or whether implant documentation supports the billed service.

A complete investigation should follow the entire workflow.

It should examine the office note, procedure history, payer policy, authorization request, approval, scheduling record, procedure note, code selection, claim and payment.

Reviewing one document in isolation may produce an incomplete conclusion.

GoHealthcare Insights

Compliance failures often travel across departmental boundaries.

A physician documentation issue may be reinforced by an authorization shortcut, accepted by scheduling, coded without clarification and submitted by billing.

The investigation should identify the complete failure pathway rather than assigning responsibility only to the last person who touched the claim.

Leadership Perspective

An investigation is successful when leadership receives an accurate account of what happened and acts on it.

The organization should not measure investigative success by whether allegations are substantiated or whether financial exposure is low.

A credible process protects both the organization and individuals who may have been accused incorrectly.

Key Takeaways

Investigations must be objective, timely, appropriately scoped and conducted by qualified, independent personnel.

Evidence should be preserved before records or system information can be changed.

Closure must include factual findings, financial resolution, corrective action and follow up validation.

Back to framework navigation
13

Corrective Action and Disciplinary Standards

Purpose

Corrective action is the structured response used to stop noncompliance, repair harm, address financial consequences, strengthen controls and prevent recurrence.

Discipline addresses individual accountability when conduct violates policy, law or professional expectations.

Corrective action and discipline are related but not interchangeable.

An organization may need to redesign a workflow even when no individual intentionally violated a requirement. It may also need to discipline an individual even when the immediate financial impact was limited.

OIG and DOJ evaluate whether organizations respond appropriately to identified misconduct, apply discipline consistently and test whether remedial measures prevent or detect similar conduct in the future.

Corrective Action Standard

Every substantiated compliance finding should be evaluated for corrective action.

The response should be proportionate to the nature, scope, cause, recurrence risk and impact of the issue.

Corrective action may include patient protection, claim correction, repayment, policy revision, education, system changes, workflow redesign, contract modification, access restriction, additional auditing and disciplinary action.

The organization should not rely solely on education when the root cause involves poor system design, inadequate staffing, conflicting incentives, management pressure or intentional behavior.

Immediate Containment

The first corrective action priority is stopping continued harm.

Containment may require suspending a billing practice, holding claims, correcting scheduling controls, limiting access, removing an employee from a task, securing data or pausing a vendor process.

Containment is temporary and does not replace permanent remediation.

Leadership should document the reason, authority, effective date and conditions required before the activity can resume.

Root Cause Analysis

The organization should identify why the problem occurred.

Potential root causes include unclear policies, insufficient training, poor workflow design, system configuration, excessive workload, inadequate supervision, data limitations, incentive structures, intentional misconduct or failure to enforce existing standards.

Root cause analysis should go beyond identifying the person who made the error.

For example, an employee may submit an authorization to the wrong utilization management entity because the payer routing process is incomplete, not because the employee failed to care.

The corrective action should address both individual performance and system design when both contributed.

Corrective Action Plan

Material findings should result in a documented Corrective Action Plan.

The plan should identify the finding, root cause, affected population, required actions, accountable owner, resources, due dates, evidence of completion, monitoring period and escalation threshold.

Actions should be specific and measurable.

“Reeducate staff” is not a complete corrective action.

The plan should identify who will be trained, on what content, by whom, by what date and how competence will be validated.

Claims and Financial Correction

Billing related findings should be evaluated for claim correction, refunds, credit balance resolution and overpayment obligations.

The organization should determine the scope of affected claims and not assume the issue is limited to the initial sample.

Qualified personnel should review the applicable law, payer policy, contract and repayment process.

Financial correction should be documented so the organization can demonstrate what was identified, how the amount was determined and when repayment or claim adjustment occurred.

Patient and Clinical Remediation

When the issue affects patient safety, treatment decisions, consent, medication management or continuity of care, corrective action should include clinical review.

Patients may require notification, follow up, reassessment or additional care.

Clinical leaders should determine whether similar patients could have been affected.

Financial correction alone does not resolve a compliance matter that created clinical risk.

Control Redesign

Systemic findings should result in redesign of the control environment.

The organization should determine whether preventive controls can replace reliance on memory or manual review.

Examples include scheduling restrictions, required authorization fields, electronic claim edits, documentation prompts, access controls, automated exclusion screening and reconciliation reports.

Detective controls should be added when prevention is not possible.

Corrective controls should define how exceptions are resolved and escalated.

Education and Competency

Education should be targeted to the actual cause of the problem.

Personnel should receive instruction on the applicable requirement, expected workflow, evidence requirements and escalation process.

High risk tasks should include competency validation.

Repeating the same general training that existed before the finding is unlikely to produce a different result.

The organization should determine whether employees have enough time, tools and supervision to follow the training.

Disciplinary Standards

The organization should maintain written disciplinary standards applicable to all workforce levels.

The standards should address intentional misconduct, reckless behavior, repeated negligence, failure to report, retaliation, obstruction, falsification, privacy violations, failure to cooperate and disregard of corrective action.

Potential consequences may include coaching, written warning, performance improvement, suspension, access restriction, termination, contract action, privilege review or referral to professional authorities.

The organization should preserve flexibility to consider the facts while maintaining consistency.

Factors in Disciplinary Decisions

Relevant factors may include intent, severity, patient impact, financial impact, prior conduct, level of responsibility, cooperation, self reporting, concealment, retaliation and whether the person was acting under management pressure.

A senior leader’s position may justify greater accountability because leaders are expected to model and enforce organizational standards.

Financial contribution, ownership, clinical reputation or difficulty of replacement should not shield an individual from appropriate action.

Consistency

Similar conduct should receive reasonably consistent treatment.

Consistency does not require identical outcomes when facts differ.

The organization should document why cases with similar allegations resulted in different decisions.

Compliance and human resources should review disciplinary patterns to identify whether certain departments, professions or levels of leadership receive preferential treatment.

DOJ’s compliance framework considers whether disciplinary measures are applied consistently and whether compensation and incentives reinforce ethical conduct.

Management Accountability

Managers should be evaluated for their role in the control failure.

Leadership responsibility may include issuing improper instructions, ignoring known problems, failing to supervise, discouraging reporting or allowing overdue corrective actions.

Disciplining only the frontline employee may be inappropriate when management created or tolerated the conditions that produced the violation.

Vendor Corrective Action

Third party failures should be addressed through documented vendor corrective action.

The organization should identify the contractual requirement, performance deficiency, remediation steps, reporting expectations and consequences of failure.

Material vendor problems may require enhanced monitoring, limitation of access, financial remedies, termination or notification of affected parties.

Outsourcing a function does not eliminate the organization’s responsibility to oversee it.

Corrective Action Validation

A corrective action should not be closed when the responsible department states that work is complete.

The organization should validate effectiveness through audit, data review, workflow observation, interviews, system testing or performance measures.

The Department of Justice specifically examines whether remedial controls have been tested to determine whether they would prevent or detect similar misconduct.

A finding that returns after closure indicates that the original action may not have addressed the root cause.

Escalation of Overdue Action

Corrective action plans should have defined escalation requirements.

Overdue high risk actions should be reported to executive leadership and the compliance committee.

Repeated failure to complete corrective action should be treated as a separate governance concern.

The governing body should receive visibility into unresolved matters that could create patient, financial or regulatory exposure.

Application to MSK Specialty Care

An audit may identify repeated radiofrequency ablation procedures without complete documentation of qualifying diagnostic blocks.

Correction should not consist only of asking physicians to improve notes.

The organization may need to revise clinical templates, authorization review, scheduling criteria, procedure history tracking, coding review and post implementation auditing.

Claims already submitted may require review.

Providers and staff may require competency validation.

The complete corrective action should address the pathway that allowed the unsupported service or claim to proceed.

GoHealthcare Insights

The difference between temporary correction and sustainable improvement is root cause resolution.

Correcting the claim addresses the past.

Redesigning the workflow, technology and accountability structure protects the future.

Leadership Perspective

Leadership should be willing to ask whether the organization itself contributed to the failure.

Employees cannot consistently comply with a process that is unclear, understaffed, technologically unsupported or contradicted by productivity expectations.

Accountability must apply to the system and the individual.

Key Takeaways

Corrective action should contain the problem, repair consequences, address root causes and reduce recurrence risk.

Disciplinary standards must apply consistently to employees, physicians, executives, owners and contractors.

Every material corrective action requires evidence of completion and validation of effectiveness.

Back to framework navigation
14

Compliance Monitoring and Internal Auditing

Purpose

Compliance monitoring and internal auditing provide structured assurance that clinical, administrative and financial controls are functioning as intended.

Monitoring observes performance continuously or periodically as part of routine management.

Auditing independently tests selected transactions, records, providers or processes against defined criteria.

Both activities are necessary.

Monitoring identifies developing problems early. Auditing provides deeper validation of whether the organization complies with applicable requirements.

OIG identifies risk assessment, auditing and monitoring as central elements of healthcare compliance infrastructure. DOJ also evaluates whether compliance functions have appropriate access to data and use lessons from monitoring, investigations and prior findings to improve controls.

Monitoring and Auditing Distinction

Monitoring should be embedded within daily and monthly operations.

Examples include authorization exception reports, unsigned note reports, credit balance aging, exclusion screening results, modifier utilization, procedure frequency alerts, privacy access reports and corrective action status.

Auditing typically evaluates a defined population or sample using documented criteria.

Examples include medical necessity audits, coding audits, provider documentation reviews, claim accuracy audits, vendor compliance reviews and privacy access audits.

An operational department may perform monitoring.

Auditing should include sufficient independence so the person evaluating the process is not solely reviewing their own work.

Risk Based Audit Plan

Auditing priorities should arise from the compliance risk assessment, regulatory developments, payer activity, internal reporting, data trends and previous findings.

The audit plan should identify the purpose, scope, responsible reviewer, population, time period, methodology, criteria and reporting date.

High volume and high value services may require greater attention, but financial value should not be the only factor.

Patient safety, privacy, fraud risk, complexity and prior deficiencies should also influence selection.

Audit Criteria

Audit criteria should be defined before records are reviewed.

Criteria may include statutes, regulations, CMS manuals, Local Coverage Determinations, National Coverage Determinations, payer policies, coding guidance, contracts, accreditation standards, clinical policies and organizational procedures.

The auditor should identify which version of the requirement was effective on the date of service.

Applying a later policy retrospectively may produce inaccurate findings.

When requirements are unclear or conflicting, the auditor should document the interpretation and obtain subject matter or legal review when appropriate.

Audit Population and Sampling

The organization should define the complete population before selecting a sample.

The population may include claims, encounters, providers, procedures, payers, locations, adjustments, refunds or system access events.

Sampling may be random, stratified, judgmental, targeted or statistically valid depending on the objective.

A small probe sample may identify whether a broader review is warranted.

A targeted sample may evaluate known outliers but should not be represented as a general organizational error rate.

Statistical extrapolation should not be performed without appropriate methodology and expertise.

Prospective and Retrospective Auditing

Prospective auditing occurs before claim submission or finalization.

It can prevent inaccurate claims from reaching the payer and is appropriate for new providers, new services, high risk procedures and corrective action monitoring.

Retrospective auditing evaluates completed services and claims.

It can identify patterns, overpayments, documentation deficiencies and weaknesses that were not visible before submission.

A mature compliance program uses both approaches strategically.

Prospective review should not become a permanent substitute for provider competence or effective workflow design.

Data Analytics

Data analytics can identify patterns that traditional random audits may miss.

Relevant analyses may include procedure volume by provider, modifier use, diagnosis distribution, place of service, frequency, claim adjustments, denial reasons, authorization failures and payment variation.

Analytics identify where review should occur. They do not independently establish noncompliance.

An outlier may reflect legitimate specialization, patient population or referral patterns.

The organization should investigate the clinical and operational context before reaching conclusions.

Provider Comparison

Provider comparison should use appropriate peer groups.

A neuromodulation specialist should not automatically be compared with a general orthopedic provider.

Differences in service mix, patient complexity, location, payer population and clinical role should be considered.

Providers should receive a fair opportunity to explain unusual patterns.

The goal is to identify and understand risk, not to penalize legitimate variation.

Medical Necessity Review

Medical necessity auditing should evaluate more than diagnosis codes.

The review should examine symptoms, examination, diagnostic findings, treatment history, conservative care, prior response, functional impairment, clinical rationale and applicable coverage criteria.

The longitudinal record may be necessary to support a service.

CMS explains that Medicare review may require records preceding the billed date when those records support coverage, coding and billing requirements.

Coding and Billing Review

Coding audits should determine whether the documentation supports the reported CPT, HCPCS and diagnosis codes, modifiers, units, laterality, levels and place of service.

The review should also evaluate bundling, global surgery, duplicate billing, incident to requirements, assistant surgeon rules and payer specific edits when applicable.

Payment does not establish that the claim was compliant.

Payers may identify an error after payment through post payment review.

Prior Authorization Audit

Prior authorization audits should assess whether authorization was required, obtained from the correct entity, valid for the provider and site, consistent with the procedure performed and effective on the date of service.

The review should compare the authorized service with the actual clinical documentation and claim.

Authorization approval does not replace medical necessity documentation.

The organization should identify services performed without authorization, procedures changed after approval and authorizations entered inaccurately into scheduling or billing systems.

Audit Documentation

The audit workpapers should allow another qualified reviewer to understand what was tested and how conclusions were reached.

Documentation should include the population, sample, criteria, records reviewed, findings, calculations, reviewer and quality assurance process.

Patient and employee information should be protected according to applicable privacy and security requirements.

Audit records should be retained under the organization’s record retention policy and any applicable legal hold.

Findings Classification

Findings should be classified according to severity, cause and required response.

Categories may include technical error, documentation deficiency, coding error, medical necessity concern, overpayment, policy violation, control failure or potential misconduct.

The organization should distinguish an isolated error from a systemic pattern.

A conclusion of no finding should also be documented when the evidence supports compliance.

Claims Hold and Escalation

Audits that identify credible concerns may require temporary claim holds or expanded review.

The organization should define when the auditor must notify compliance, revenue cycle leadership, legal counsel, clinical leadership or the governing body.

High risk findings should not wait until the scheduled audit report is complete before escalation.

Immediate notification may be necessary when patient harm, falsification, systemic overbilling or active privacy exposure is identified.

Corrective Action and Follow Up

Audit findings should produce assigned corrective action.

Follow up review should determine whether the corrective action was completed and whether the error rate or risk declined.

The validation sample should be selected after sufficient time has passed for the new process to operate.

Repeated findings should trigger expanded root cause analysis and leadership escalation.

Audit Independence and Quality Assurance

Internal auditors should have appropriate competence and independence.

The organization may use external reviewers when specialized knowledge, independence or credibility is required.

External auditors should receive a clear scope and should disclose conflicts.

The organization should review auditor qualifications, methodology and work quality rather than accepting conclusions without evaluation.

Audit Readiness

Audit readiness means that the organization can retrieve accurate records, identify applicable requirements, explain its workflows and produce evidence of compliance within required timeframes.

CMS describes an Additional Documentation Request as a request for medical records supporting payment and compliance with coverage, coding, billing and payment requirements.

Readiness should be tested through mock audits, document retrieval exercises and review of payer response procedures.

Application to MSK Specialty Care

MSK auditing should evaluate the complete patient journey.

A review of epidural steroid injections may examine imaging correlation, symptoms, conservative treatment, duration of pain, level and laterality, authorization, procedure documentation, frequency, outcome and claim coding.

A radiofrequency ablation audit may require review of diagnostic blocks, percentage of relief, duration of relief, functional improvement, anatomical consistency and repeat procedure criteria.

GoHealthcare’s MSK audit analysis emphasizes alignment among medical necessity, frequency, utilization and documented patient response across the longitudinal record.

GoHealthcare Insights

The strongest audit programs identify risk before the payer does.

This requires combining claim data, authorization information, clinical documentation and procedure history rather than auditing each function separately.

Audit readiness is created during the workflow. It cannot be manufactured after the request for records arrives.

Leadership Perspective

Leadership should welcome accurate audit results, including unfavorable findings.

An internal audit that identifies a correctable weakness is far less damaging than an external review that discovers the same weakness after it has affected a large population of claims.

Key Takeaways

Monitoring and auditing should be risk based, independent enough to be credible and supported by defined criteria.

Data analytics should direct attention but should not substitute for clinical and operational analysis.

Findings require documented corrective action, financial review and effectiveness validation.

Back to framework navigation
15

Clinical Documentation Integrity

Purpose

Clinical Documentation Integrity ensures that the medical record accurately, completely and clearly reflects the patient’s condition, clinical reasoning, treatment, response and plan of care.

The record must support safe patient care, communication among professionals, medical necessity, prior authorization, coding, billing, quality reporting and audit defense.

Clinical Documentation Integrity is not an initiative designed to maximize codes without regard to clinical truth.

Its purpose is to ensure that the coded and billed representation of the encounter is supported by an authentic, patient specific clinical record.

CMS states that payment depends on documentation supporting applicable coverage, coding and billing requirements and advises providers to submit enough information to support the claim.

Clinical Record Standard

The record should tell a coherent clinical story.

It should explain why the patient sought care, what the provider evaluated, what findings were identified, how previous treatment affected the condition, why the proposed service is appropriate and what outcome is expected.

Documentation should be patient specific.

The record should not consist primarily of imported history, copied language, templated statements or payer terminology that is not supported by the encounter.

A reviewer should be able to understand the provider’s reasoning without relying on assumptions or information that exists only in the provider’s memory.

Accuracy and Completeness

Documentation should accurately reflect the service performed and the information known at the time of care.

The record should identify relevant symptoms, diagnosis, anatomical region, laterality, level, duration, severity, functional impact, examination findings, diagnostic results, treatment history and clinical plan.

Not every encounter requires every possible detail.

The information included should be sufficient for the clinical situation and applicable coverage requirements.

Inaccurate detail can be as problematic as missing detail.

A template that automatically records examination findings not actually performed creates integrity risk.

Timeliness

Clinical documentation should be completed promptly after the encounter or procedure.

Delays increase the risk of incomplete recall, contradictory information, missed authorization deadlines and billing errors.

The organization should define expected completion timeframes and monitor unsigned or incomplete records.

Claims should not be submitted when required documentation remains incomplete.

Operational pressure should not result in billing based on assumed future completion.

Authentication and Signatures

The author of each clinical entry should be identifiable.

Signatures should meet applicable payer, legal and organizational requirements.

CMS permits certain attestations for missing signatures in medical documentation, but not for orders when a signature is required, and an attestation cannot be used to backdate a plan of care. CMS also encourages submission of complete records with appropriate signature documentation to reduce medical review delays.

Organizations should maintain signature logs when necessary and should educate providers regarding authentication requirements.

Medical Necessity

Documentation should demonstrate why the service was reasonable and necessary for the individual patient.

A diagnosis code alone is not sufficient.

The record should connect the patient’s symptoms, findings, treatment history and functional impairment to the proposed intervention.

Correct coding does not independently establish coverage or medical necessity.

GoHealthcare’s medical necessity guidance emphasizes that a service can be coded correctly yet remain nonpayable when the record does not satisfy applicable coverage criteria.

Longitudinal Documentation

Many MSK procedures must be evaluated across time rather than within one isolated office note.

The record may need to show prior conservative treatment, previous procedures, dates, anatomical regions, levels, laterality, percentage of relief, duration of relief and functional improvement.

The current plan should be consistent with the documented history.

Contradictions should be reconciled.

A procedure history that is scattered across notes, operative reports and outside records creates authorization and audit risk.

The organization should create a reliable method for presenting longitudinal clinical information.

Procedure Specific Documentation

Procedure documentation should identify the service performed, indication, consent, anatomical site, laterality, level, technique, guidance, medications, devices, findings, complications and patient disposition as applicable.

The procedure note should be consistent with the authorization, scheduling record and claim.

Differences should be resolved before billing.

When the procedure changes because of intraoperative or clinical circumstances, the record should explain why and the organization should evaluate authorization and coding implications.

Documentation of Patient Response

Repeat interventions require clear documentation of prior response when applicable.

The record should identify the percentage of pain relief, duration of relief, functional change, medication reduction, activity improvement and other clinically meaningful outcomes.

Statements such as “patient did better” may be insufficient when payer policy requires measurable response.

Outcome documentation should be clinically authentic and not limited to language copied from payer criteria.

Diagnosis and Procedure Alignment

The documented diagnosis should reflect the condition evaluated and treated.

Diagnosis selection should not be based solely on which code is likely to secure authorization or payment.

The anatomical region, laterality and clinical findings should align with the requested and performed procedure.

When several diagnoses are present, the record should clarify which condition supports the intervention.

Templates and Structured Documentation

Templates can improve consistency, but they must not replace clinical judgment.

Required fields can help capture laterality, levels, prior treatment and outcomes.

However, excessive templating may create cloned notes, internal contradictions and documentation that does not reflect the patient.

The organization should periodically audit templates and default settings.

Fields that generate inaccurate or unnecessary statements should be revised or removed.

Copying and Carrying Forward Information

Information carried forward from previous encounters should be reviewed and updated.

Outdated symptoms, examination findings, medication lists and treatment plans should not remain in the record simply because the system imports them.

Providers should distinguish unchanged history from findings obtained during the current encounter.

Repeated identical documentation across multiple dates can undermine the credibility of the record and make clinical progression difficult to understand.

Amendments, Corrections and Late Entries

Corrections should preserve the original information, identify the person making the change and record the date and reason.

Records should not be altered secretly or overwritten.

Late entries should be clearly identified and should reflect information that was known or performed at the relevant time.

Documentation should never be changed solely to respond to an audit, obtain authorization or support a claim when the original record did not contain the required facts.

Documentation Queries

Clinical documentation queries should be clear, neutral and supported by information in the record.

A query should request clarification, not direct the provider toward a predetermined diagnosis or reimbursement outcome.

Providers remain responsible for the final clinical determination.

The organization should monitor query volume, response time, leading language and repeated documentation gaps.

Frequent queries concerning the same issue may indicate that templates, education or workflows require redesign.

Artificial Intelligence Assisted Documentation

Artificial intelligence may assist with summarization, transcription, drafting and identification of missing information.

The treating professional must review, correct and authenticate the final record.

AI generated language should not be accepted without verification.

The organization should assess hallucination risk, copied inaccuracies, inappropriate inference, privacy, data retention, vendor access and whether the output reflects the encounter.

AI should never create clinical facts, examination findings, patient responses or medical necessity elements that the provider did not observe or determine.

Human accountability must remain explicit.

CDI and Coding Collaboration

Clinical documentation personnel and coding professionals should collaborate while maintaining appropriate role boundaries.

Coders may identify that documentation lacks specificity or does not support the reported service.

Clinical documentation personnel may facilitate clarification.

Neither function should direct the provider to document information that is not clinically true.

The objective is alignment between the clinical record, code assignment and billed service.

CDI Monitoring

The organization should monitor documentation completion, signature timeliness, query rates, coding related deficiencies, copied note patterns, medical necessity findings and repeat provider errors.

Performance should be analyzed by provider, service line, procedure and location.

Providers should receive individualized feedback supported by examples.

Education should focus on improving clinical clarity rather than merely satisfying an audit checklist.

Application to MSK Specialty Care

Clinical Documentation Integrity is central to pain management, orthopedic surgery, spine surgery, neurosurgery and neuromodulation.

The clinical record should connect diagnosis, examination, imaging, conservative treatment, prior procedures, patient response and proposed intervention.

GoHealthcare’s RCM Framework identifies Clinical Documentation Integrity as a core component of Revenue Integrity and emphasizes preventing reimbursement failures before claims are submitted.

When this information is incomplete or inconsistent, the consequences may include authorization denial, procedure delay, incorrect coding, nonpayment, recoupment and inability to defend medical necessity.

GoHealthcare Insights

Documentation is the operational bridge connecting clinical care, patient access, utilization management, coding, billing and compliance.

When documentation fails, every downstream function is forced to guess, clarify, delay or correct.

The most effective organizations improve documentation at the point of care rather than relying on retrospective repair.

Leadership Perspective

Physician documentation should be treated as a clinical and enterprise capability.

Leaders should provide usable templates, relevant education, efficient technology and timely feedback.

They should also maintain accountability when records remain incomplete, inaccurate or unsupported.

Key Takeaways

Clinical documentation must be accurate, timely, authenticated, patient specific and sufficient to demonstrate clinical reasoning and medical necessity.

Templates and artificial intelligence may support documentation but cannot replace provider judgment and verification.

Documentation integrity should be monitored across the complete longitudinal care pathway.

Back to framework navigation
16

Coding Compliance

Purpose

Coding Compliance establishes the governance, technical standards, workflow controls and professional accountability required to ensure that every diagnosis, procedure, service, supply, device, modifier, unit and place of service reported on a healthcare claim is supported by the medical record and submitted according to applicable coding and payer requirements.

Coding is not simply the conversion of clinical documentation into codes. It is the formal representation of what occurred during the patient encounter. The coded claim communicates the patient’s condition, the service performed, the professional or facility responsible for the service, the site where care was delivered and the circumstances affecting payment.

Coding errors can result in denials, underpayments, overpayments, payer recoupments, inaccurate quality data, distorted utilization reporting and potential regulatory exposure.

The HHS Office of Inspector General identifies accurate coding, billing, documentation and medical necessity as principal compliance responsibilities for physician practices. Physicians should ensure that claims submitted for payment are accurate and supported by the medical record.

Coding Governance

The organization should establish a formal Coding Compliance Program that defines authority, responsibilities, coding standards, escalation pathways, education requirements, audit expectations and documentation rules.

The program should apply to professional billing, facility billing, ambulatory surgery center claims, ancillary services, supplies, medications, implantable devices and any other coded service submitted by or on behalf of the organization.

The coding governance structure should identify who is responsible for code assignment, who may modify codes, who resolves documentation questions, who approves coding policies and who determines whether an identified coding problem requires claim correction or repayment.

Coding leadership should coordinate with compliance, clinical leadership, revenue cycle management, patient access, prior authorization and information technology.

Coding should not operate as an isolated back office function. The accuracy of the final code depends on information created throughout the patient care pathway.

Authoritative Coding Sources

The organization should maintain access to current and authoritative coding resources.

These may include the current CPT code set, HCPCS Level II code set, ICD 10 CM code set, ICD 10 PCS when applicable, official coding guidelines, CMS manuals, National Correct Coding Initiative resources, Medicare Administrative Contractor guidance and payer specific billing policies.

The organization should define which source controls when requirements differ.

CMS publishes the Medicare Claims Processing Manual and the National Correct Coding Initiative resources used to support Medicare coding and claims processing. CMS also publishes current Procedure to Procedure edits, Medically Unlikely Edits, add on code edits and the Medicare NCCI Policy Manual.

Commercial payer policies may contain requirements different from Medicare. A coding rule, modifier instruction or claim edit that applies to Medicare should not automatically be assumed to apply identically to every payer.

Code Set and Version Management

Coding systems, reference tools, charge capture applications and claim edits should be updated when code sets and payer requirements change.

The organization should document the effective date of each update, the affected codes, the responsible owner, testing performed and education delivered.

Historical claims should be evaluated according to the codes and requirements effective on the date of service.

The organization should prevent obsolete codes, deleted codes or future effective codes from being submitted inappropriately.

System updates should be tested before implementation. Testing should include code acceptance, modifier logic, unit limitations, fee schedule alignment, claim form mapping and interface performance.

Provider and Coder Accountability

Providers are responsible for accurately documenting the services they performed and the clinical basis for those services.

Coding professionals are responsible for assigning codes based on the documentation and applicable coding rules.

A coder should not infer a diagnosis, anatomical level, laterality, procedure component or clinical condition that the provider did not document.

A provider should not instruct a coder to select a code merely because it produces higher reimbursement or avoids a payer edit.

When documentation is incomplete, conflicting or unclear, the coder should initiate an appropriate query rather than making an unsupported assumption.

Final accountability should be clear when providers select their own codes. Provider selected coding should remain subject to professional review, claim edits, education and auditing.

Diagnosis Coding

Diagnosis codes should accurately represent the conditions evaluated, managed or treated during the encounter.

The code selected should reflect the highest supported level of specificity, including anatomical region, laterality, encounter type and other required characteristics.

Diagnosis selection should not be driven solely by payer approval history or reimbursement expectations.

The organization should monitor unspecified codes, inconsistent laterality, diagnosis and procedure mismatches, unsupported chronic conditions and codes carried forward without current clinical relevance.

The diagnosis should support the clinical rationale for the service, but diagnosis coding alone does not establish medical necessity.

Procedure and Service Coding

Procedure codes should accurately describe the service documented as performed.

Coding should reflect the complete procedure note, operative report, medication record, imaging guidance, supplies, devices, professional component and facility component as applicable.

The organization should verify that the code represents the exact technique, anatomical location, number of levels, number of units and clinical circumstances documented.

Codes should not be selected based only on the procedure name used by the physician, scheduler or vendor.

Clinical terminology may differ from formal coding definitions. Coding professionals should evaluate the actual service described in the record.

Modifier Compliance

Modifiers should be reported only when the documentation and payer requirements support them.

Modifiers communicate circumstances that may affect payment, bundling, professional or technical responsibility, laterality, anatomical distinction, repeated services and liability.

The organization should maintain written guidance for frequently used modifiers, including modifiers 25, 26, 50, 51, 52, 53, 57, 58, 59, 62, 76, 77, 78, 79, 80, 81, 82, RT, LT and the X modifiers when applicable.

A modifier should not be added merely because the unmodified claim was denied.

Modifier 59 and the X modifiers require particular attention because they may override procedure bundling edits when circumstances support separate reporting.

GoHealthcare’s specialty coding guidance emphasizes that modifiers should communicate documented circumstances and should not be applied routinely or without support in the medical record.

National Correct Coding Initiative Controls

The organization should incorporate current National Correct Coding Initiative requirements into coding workflows.

Procedure to Procedure edits identify code combinations that generally should not be reported together unless an appropriate modifier and documented circumstances support separate reporting.

Medically Unlikely Edits identify units of service that are unlikely to be correct for a beneficiary on the same date of service.

Add on code edits identify codes that are generally reportable only with an appropriate primary procedure.

CMS updates Medicare NCCI resources periodically, and organizations should ensure that their coding systems and reference tools use the applicable files.

An edit does not independently determine the clinical truth of a claim. The organization must evaluate the documentation, applicable modifier rules and payer policy before deciding whether codes should be reported separately.

Units, Levels and Laterality

Units of service should reflect the number of services, doses, levels, injections, supplies or other measurable components documented.

The organization should validate whether the code is reported once per session, once per level, once per side, once per lesion, once per drug quantity or according to another coding convention.

Anatomical levels and laterality should remain consistent across the order, authorization, scheduling record, procedure note, code assignment and claim.

Discrepancies should be resolved before claim submission.

This control is especially important for spinal procedures, peripheral nerve procedures, joint interventions, imaging guidance, implantable devices and drug units.

Place of Service Compliance

The place of service code should represent where the service was physically performed.

The organization should not select the place of service based solely on the billing entity, ownership structure or reimbursement advantage.

The place of service should align with the clinical record, facility documentation, professional claim and payer requirements.

Procedures performed in the physician office, ambulatory surgery center and hospital outpatient department may have different coding, payment, authorization and documentation implications.

The organization should establish a reconciliation process to identify inconsistencies among the scheduled location, documented location and billed place of service.

Global Surgery and Related Services

Coding workflows should identify services subject to global surgery rules.

The organization should determine whether preoperative, intraoperative and postoperative services are included in the global package or separately reportable.

Modifiers used during a global period should be supported by documentation explaining why the service is unrelated, staged, more extensive or returned to the operating room.

Orthopedic, spine and neurosurgical practices should monitor postoperative evaluation and management services, surgical complications, planned staged procedures and services performed by different providers.

Assistant Surgeon and Co Surgeon Coding

Claims involving assistant surgeons, co surgeons or team surgery should meet applicable documentation, medical necessity and payer requirements.

The operative report should clearly describe each physician’s role and contribution.

The organization should not assume that the presence of two physicians automatically supports modifier 62 or assistant surgeon reporting.

Payer policies may restrict assistant surgeon payment for specific procedures or specialties. Eligibility should be verified before claims are submitted.

Drug, Supply and Device Coding

Drugs, biologicals, supplies and implantable devices should be reported according to the applicable HCPCS code, unit definition, route, dosage and payer requirements.

The organization should reconcile medication administration records, invoices, inventory, procedure notes and claim units.

Discarded drug reporting should comply with applicable payer instructions.

Implantable device coding should be supported by the operative report, implant log, serial or lot information and facility charge documentation as applicable.

Unlisted and Category III Codes

Unlisted procedure codes should be used only when no existing code accurately describes the service.

The claim should include sufficient documentation to explain the procedure, clinical rationale, comparable service, time, complexity and resources.

Category III codes should be reported when the code accurately describes the service, even when a payer considers the procedure investigational or noncovered.

The organization should not substitute a different payable code for an unlisted or Category III service when the substituted code does not describe what was performed.

Coverage and coding are separate determinations.

Coding Queries

Coding queries should be neutral, nonleading and based on information already present in the record.

The query should explain what clarification is needed without directing the provider toward a code or diagnosis selected for reimbursement purposes.

The provider should make the final clinical determination.

The organization should retain query documentation and monitor patterns.

Repeated queries concerning the same provider, procedure or documentation element may indicate a need for template revision, physician education or workflow redesign.

Automated Coding and Artificial Intelligence

Computer assisted coding and artificial intelligence may support code suggestions, documentation review and edit detection.

These tools should not be permitted to assign final codes without appropriate human validation when the coding decision requires interpretation or clinical context.

The organization should test the tool’s performance across specialties, procedures, providers and patient populations.

AI generated code recommendations should be evaluated for hallucinated diagnoses, unsupported specificity, missed modifiers, incorrect units, outdated code sets and payer variation.

Responsibility for the final coded claim remains with the organization and the qualified individuals approving the submission.

Coding Auditing and Monitoring

The organization should conduct prospective and retrospective coding audits based on risk.

Audit selection may consider provider volume, modifier use, unusual code combinations, high reimbursement services, denial trends, new procedures, new providers, payer reviews and previous findings.

Audit reports should distinguish coding error, documentation deficiency, medical necessity concern and payer policy issue.

The organization should not classify every denial as a coding error.

The root cause may involve eligibility, authorization, coverage, documentation, enrollment, claim format or payer processing.

Application to MSK Specialty Care

Coding compliance in pain management, orthopedics, spine, neurosurgery and neuromodulation requires precise alignment among clinical documentation, anatomical detail, procedure history and payer policy.

Examples of concentrated risk include reporting incorrect spinal levels, unsupported bilateral services, inappropriate modifier 59 use, excessive units, inaccurate place of service, inconsistent implant coding and unbundling image guidance that is included in the primary service.

GoHealthcare’s MSK revenue cycle framework describes documentation, coding, claims, medical necessity and authorization as connected functions rather than separate administrative tasks.

GoHealthcare Insights

Coding accuracy begins before the coder receives the record.

Patient registration, provider orders, authorization, procedure documentation, medication records and facility information all influence the final coded claim.

The strongest coding compliance program therefore governs the complete information pathway rather than expecting coders to repair incomplete or conflicting information after the service.

Leadership Perspective

Leadership should not measure coding performance only by productivity, clean claim rates or reimbursement.

A coding team can submit claims quickly and still create significant exposure when documentation, medical necessity or payer requirements are not aligned.

Coding excellence requires accuracy, defensibility, consistency and appropriate escalation.

Key Takeaways

Coding must accurately represent the service documented and the circumstances under which it was performed.

Modifiers, units, laterality, levels, place of service and code combinations require procedure specific controls.

Technology and artificial intelligence may support coding, but qualified human accountability must remain.

Back to framework navigation
17

Billing and Claims Compliance

Purpose

Billing and Claims Compliance establishes the controls required to ensure that claims submitted to government programs, commercial payers, workers compensation carriers, liability insurers and patients are complete, accurate, timely and supported by the medical record.

A healthcare claim is a formal representation that the identified provider furnished the reported service to the identified patient, at the stated location, on the stated date, under circumstances supporting coverage and payment.

The claims process should therefore be governed as a compliance function, not solely as a financial transaction.

CMS publishes detailed billing and claim processing requirements through the Medicare Claims Processing Manual and electronic billing resources. OIG advises physicians to ensure that claims submitted for payment are accurate and supported by complete medical records.

Claims Governance

The organization should maintain written standards covering charge entry, claim creation, edits, submission, correction, appeal, payment posting, adjustments, refunds and retention of supporting records.

The claims governance structure should identify which department owns each stage, which exceptions require compliance review and who may approve claim changes.

Access to create, modify, release, void or adjust claims should be limited according to job responsibilities.

The organization should maintain audit trails capable of identifying who changed a claim, what was changed, when the change occurred and why.

Patient and Insurance Information

Claims should contain accurate patient demographic and insurance information.

The patient’s name, date of birth, member identification number, relationship to subscriber, payer, plan, coordination of benefits and claim address should be validated before submission.

Errors in registration may lead to denials, misdirected claims, privacy incidents and inaccurate patient balances.

The organization should not repeatedly correct registration errors downstream when stronger front end verification can prevent them.

Provider Information

Claims should identify the correct rendering, billing, ordering, referring, supervising and facility information as applicable.

Provider identifiers, taxonomy codes, enrollment status, network participation and practice location should be validated.

A provider should not be reported as rendering or supervising a service they did not perform or oversee according to applicable requirements.

Changes in employment, enrollment, credentialing, reassignment or location should be reflected promptly in billing systems.

Date, Location and Service Validation

The claim should align with the encounter date, procedure date and location documented in the medical record.

The billed service should match the order, authorization, procedure note, medication record and facility record as applicable.

Claims involving changes in procedure, laterality, level, units or location should receive secondary review before submission.

A service should not be billed merely because it appeared on the schedule or charge ticket.

The organization should verify that the service was completed and documented.

Charge Capture

All billable services should be captured accurately and only once.

The organization should reconcile scheduled encounters, completed visits, procedure logs, operative reports, medication administration, implant records and posted charges.

Missing charges create revenue leakage.

Duplicate or unsupported charges create compliance risk.

Charge capture controls should identify cancelled procedures, incomplete services, failed procedures, bilateral services, add on procedures, supplies and drugs.

Manual charges and late charges should receive enhanced review.

Claim Creation and Editing

Claims should pass through defined validation before release.

Edits may address eligibility, authorization, diagnosis and procedure consistency, modifier logic, units, place of service, provider enrollment, duplicate claims, NCCI relationships and required claim fields.

Edits should be reviewed periodically to determine whether they remain accurate.

An edit should not automatically change the code selected by a qualified coding professional without documented review.

Staff should not override edits merely to obtain claim acceptance.

Override authority should be limited, justified and monitored.

Documentation Completion

Claims should not be released when required medical documentation remains incomplete, unsigned or unauthenticated.

The organization should establish clear hold rules for incomplete encounters, operative reports, procedure notes, orders and required signatures.

Billing before documentation completion may create a claim that cannot be defended if reviewed.

CMS documentation guidance explains that records must contain sufficient information to support payment, coverage, coding and billing requirements.

Authorization Validation

When authorization is required, the claim should be compared with the approved procedure, provider, facility, date range, units, laterality and other limitations.

The presence of an authorization number does not establish that the billed service matches the approval.

Claims should be held when the procedure performed differs materially from the authorized service until the organization determines whether the authorization can be amended or whether another compliant resolution is available.

Electronic Claims and Transaction Integrity

Electronic claims should follow applicable transaction and data requirements.

The organization should test interfaces connecting the EHR, practice management system, clearinghouse, billing platform and payer.

Rejected claims should be reviewed promptly.

Repeated rejections may indicate mapping, enrollment, formatting or data quality problems.

The organization should distinguish clearinghouse rejection from payer denial. A rejected claim generally did not enter the payer’s adjudication process, while a denied claim was received and adjudicated.

CMS provides official information concerning electronic billing, EDI transactions and the Medicare Claims Processing Manual.

Timely Filing

Claims should be submitted within applicable payer and contractual filing limits.

The organization should establish earlier internal deadlines to allow time for rejection correction and resubmission.

Timely filing failures should be tracked by cause, department and payer.

Claims should not be backdated or altered to create the appearance of timely submission.

Proof of original filing, clearinghouse acceptance and payer receipt should be retained when relevant.

Corrected and Void Claims

Corrected and void claims should follow payer specific instructions.

The organization should document why the claim is being changed, who approved the correction and whether the change affects payment.

A corrected claim should not be used to conceal an original error or replace records requested in an audit.

When the correction creates an overpayment, the financial resolution should be coordinated with the organization’s overpayment process.

Denials

Denials should be classified by root cause rather than managed only as accounts receivable tasks.

Categories may include eligibility, authorization, medical necessity, coding, bundling, documentation, enrollment, timely filing, noncovered service, coordination of benefits and payer processing.

The organization should distinguish preventable denials from denials requiring contractual or clinical appeal.

Repeated denials should be escalated to the department where the failure originated.

GoHealthcare’s analysis of pain and orthopedic claims identifies incomplete medical necessity support, modifier errors and authorization failures among recurring drivers of reimbursement disruption.

Claims Appeals

Appeals should be truthful, complete and supported by the record and applicable policy.

Personnel should not alter documentation, create unsupported clinical statements or submit inaccurate explanations to overturn a denial.

The appeal should identify the reason for disagreement, supporting facts, relevant coverage provisions and requested resolution.

Appeal outcomes should be used to improve upstream workflows.

A successful appeal does not necessarily mean the original process was effective if the organization could have prevented the denial.

Payment Posting

Payments, denials, adjustments and patient responsibility should be posted accurately.

Automated posting rules should be tested.

Unusual adjustments, reversals and manual postings should receive review.

The organization should reconcile electronic remittance information with deposits, bank records and patient accounts.

Unapplied cash and unidentified payments should be investigated promptly.

Payment posting personnel should not move balances or apply adjustments merely to improve accounts receivable metrics.

Contractual Adjustments and Write Offs

Contractual adjustments should reflect the payer agreement and adjudicated claim.

Administrative write offs, small balance adjustments, charity care and bad debt should follow approved policy and authority.

Write offs should not be used to hide denials, registration errors, authorization failures, missed filing deadlines or uncollectible balances caused by operational mistakes.

Adjustment activity should be monitored by employee, payer, location, reason and amount.

Secondary Payer Compliance

The organization should identify when another payer may be responsible before Medicare or another secondary payer.

Workers compensation, liability, no fault, employer coverage and other insurance information should be collected and updated.

Claims should not be submitted to Medicare as primary when the organization has information indicating another payer may be responsible.

CMS maintains separate Medicare Secondary Payer guidance and recovery processes.

Credit Balances and Overpayments

Credit balances should be reviewed regularly to determine whether money is owed to a payer or patient.

The organization should establish procedures for identifying, quantifying, reporting and returning overpayments.

CMS states that Medicare Parts A and B providers and suppliers must report and return identified overpayments by the later of 60 days after identification or the due date of the corresponding cost report, when applicable. The organization should obtain legal advice when evaluating identification, scope and repayment obligations.

An overpayment should not be transferred indefinitely among accounts or held without documented review.

Vendor and Outsourced Billing Oversight

The organization remains responsible for claims submitted by billing companies, contractors and offshore teams acting on its behalf.

Contracts should define coding authority, claim controls, documentation access, audit rights, reporting expectations, security requirements and corrective action obligations.

Vendor compensation should not encourage aggressive or unsupported billing.

The organization should receive sufficient data to monitor vendor accuracy, denials, adjustments, overrides, refunds and unresolved claims.

Claims Monitoring

Leadership should monitor clean claim rate, rejection rate, denial rate, first pass acceptance, unbilled encounters, coding hold volume, timely filing losses, authorization denials, corrected claims, credit balances and overpayments.

Metrics should be interpreted together.

A very high clean claim rate may appear favorable but may not reveal whether the underlying claims were medically necessary or correctly coded.

Operational performance and compliance integrity must be evaluated together.

Application to MSK Specialty Care

Billing compliance in MSK specialty care requires alignment among the clinical record, authorization, procedure performed, code assignment, place of service and claim.

A spinal procedure scheduled for one level but performed at another may require authorization review before billing.

An implant claim should reconcile with the operative report and facility documentation.

A procedure performed in an ambulatory surgery center should not be billed with office place of service merely because the professional practice submitted the claim.

GoHealthcare Insights

The compliant claim is the final output of the entire clinical and administrative operating system.

When registration, documentation, authorization, coding or charge capture fails, billing receives the consequence.

Billing teams should identify and communicate upstream causes rather than repeatedly correcting the same errors downstream.

Leadership Perspective

Cash acceleration should never be achieved by weakening claim controls.

Submitting a questionable claim faster does not improve revenue cycle performance. It accelerates financial and compliance exposure.

Key Takeaways

Claims must be accurate, documented, authorized when required and consistent with the service performed.

Denials, adjustments, corrected claims and overpayments should be analyzed as compliance intelligence.

Outsourcing billing does not transfer the organization’s accountability for claim accuracy.

Back to framework navigation
18

Revenue Integrity and Financial Compliance

Purpose

Revenue Integrity and Financial Compliance ensure that the organization receives the payment it is entitled to for services that were actually performed, properly documented, medically necessary, correctly coded and submitted according to applicable requirements.

Revenue integrity protects against both underbilling and overbilling.

Underbilling, missed charges and payer underpayments weaken financial sustainability.

Overbilling, unsupported charges and retained overpayments create legal and compliance exposure.

The objective is accurate reimbursement, not maximum reimbursement without regard to clinical and regulatory standards.

GoHealthcare’s Revenue Integrity Framework describes prior authorization, documentation, coding, charge capture, claims and financial clearance as connected controls that should protect revenue before the claim is submitted.

Revenue Integrity Governance

The organization should establish multidisciplinary oversight involving clinical leadership, patient access, prior authorization, coding, billing, finance, compliance, contracting and information technology.

Revenue integrity responsibilities should not rest exclusively with the billing department.

The governing structure should define how discrepancies are identified, investigated, corrected and reported.

High risk issues should be escalated to compliance when they involve potential overpayments, unsupported claims, systematic coding errors, inaccurate adjustments or intentional conduct.

The Revenue Integrity Continuum

Revenue integrity begins before the patient encounter.

Insurance eligibility, network status, benefits, medical necessity, authorization, cost estimates and patient responsibility influence whether the service can be delivered and reimbursed appropriately.

During the encounter, documentation, orders, medication administration, devices, supplies, anatomical details and the actual service performed determine the accurate charge.

After the encounter, coding, claim edits, submission, payment posting, denial management, underpayment review, refunds and financial reporting complete the process.

A mature revenue integrity program evaluates this entire continuum.

Financial Clearance

Financial clearance should confirm that the patient, payer, provider, location and proposed service are aligned before the date of service.

The process should include eligibility, benefits, network status, authorization requirements, authorization status, site of service, patient responsibility and any identified coverage limitations.

Unresolved issues should be escalated before the service when clinically and operationally appropriate.

Financial clearance does not determine clinical care. It ensures that the organization and patient understand known coverage and financial conditions before proceeding.

Charge Integrity

Charges should accurately reflect services, drugs, supplies and devices that were documented as furnished.

The organization should reconcile charges with the clinical record and operational source documents.

Charge structures should not produce duplicate charges, missing charges or charges unsupported by documentation.

Manual charge entry should be limited and monitored.

The organization should evaluate recurring late charges, charge corrections and unusually high or low charge patterns.

Fee Schedule Governance

The organization should maintain complete and current fee schedules.

Each billable code should have an approved charge amount appropriate to the organization’s policy and contractual environment.

Fee schedule changes should follow documented approval and testing.

Missing fees can prevent charges from posting or cause claims to be released incorrectly.

Uncontrolled changes may produce inconsistent patient statements, contractual problems and inaccurate financial reporting.

The organization should maintain version history and effective dates.

Procedure, Drug and Implant Reconciliation

High cost procedures, medications and implantable devices require detailed reconciliation.

The operative report, medication administration record, inventory, implant log, vendor invoice, charge entry and claim should agree.

Differences in quantity, device type, laterality, dosage or wastage should be resolved before claim submission.

Device representatives should not control final coding or charging decisions.

Vendor information may support identification of a product, but the medical record and applicable coding standards control what is billed.

Revenue Leakage

Revenue leakage may arise from missing charges, incomplete documentation, unworked denials, underpayments, fee schedule errors, expired authorizations, registration failures and unbilled encounters.

The organization should quantify leakage by root cause.

Recovery activity should not result in retroactive charges that are unsupported or submitted beyond payer requirements.

The stronger response is to correct the workflow that allowed the revenue to be lost.

Overbilling Risk

Revenue integrity controls should also identify charges or payments exceeding what is supported.

Potential causes include duplicate billing, incorrect units, upcoding, unbundling, unsupported modifiers, inaccurate place of service, billing cancelled services and failure to apply contractual adjustments.

The organization should not define revenue integrity as the recovery of every possible dollar.

True revenue integrity requires that the amount billed and collected be accurate.

Contractual Payment Integrity

Expected reimbursement should be calculated according to payer contracts, fee schedules and applicable payment rules.

The organization should compare actual payment with expected payment and investigate material differences.

Underpayment review should distinguish payer processing error from incorrect organizational assumptions.

Contract terms, multiple procedure reductions, bundling, sequestration, patient responsibility and other payment factors should be incorporated accurately.

Disputes should be supported by the contract and claim facts.

Payment Variance Analysis

Payment variance reporting should identify underpayments, overpayments, unexpected adjustments and zero payments.

Variance thresholds should reflect financial significance and risk.

Patterns should be evaluated by payer, procedure, provider, location and reason.

The organization should not pursue underpayments while ignoring overpayments identified through the same analysis.

Credit Balance Governance

Credit balances should be reviewed according to a defined schedule.

The review should determine whether the credit resulted from duplicate payment, coordination of benefits, claim reversal, patient overpayment, incorrect posting or another cause.

Credits should not be cleared through unsupported adjustments.

Refunds should be issued to the correct party and documented.

Aging reports should identify unresolved credits and accountable owners.

Overpayment Identification and Repayment

The organization should establish a formal overpayment process addressing intake, investigation, quantification, legal review, repayment, disclosure and corrective action.

Potential overpayments may be identified through audits, denials, payer notices, employee reports, payment variance analysis, credit balances and government reviews.

CMS requires Medicare Parts A and B providers and suppliers to report and return identified overpayments within the applicable statutory and regulatory timeframe.

The organization should not delay reasonable diligence or narrowly define the affected population when evidence suggests a broader problem.

Refunds and Patient Financial Integrity

Patient payments should be posted correctly and refunded when appropriate.

The organization should monitor duplicate payments, deposits, prepayments, cancelled services and insurance payments received after the patient paid.

Patient refunds should not remain unresolved merely because the amount is small.

Financial statements and communications should accurately reflect patient responsibility.

Adjustments and Write Off Controls

Every adjustment should use an approved reason code and appropriate authority.

The reason should reflect why the balance changed.

Adjustment categories should distinguish contractual allowance, administrative error, charity care, bad debt, timely filing loss, authorization failure and other causes.

Broad adjustment codes such as “miscellaneous” should be minimized.

Large, unusual or repeated adjustments should receive secondary review.

Financial Reconciliation

Revenue cycle data should reconcile with the general ledger and bank activity.

Charges, payments, refunds, deposits, adjustments and write offs should be reconciled on a defined schedule.

Differences should be investigated and documented.

Unapplied cash should be aged and resolved.

Reconciliation controls should include separation of duties so that one person does not control receipt, posting, adjustment and refund without independent review.

Denial Prevention and Revenue Integrity

Denials should be analyzed according to whether they indicate missing revenue, compliance exposure or both.

A denial for missing authorization may represent preventable revenue loss.

A denial for medical necessity may also signal that the service or claim was not adequately supported.

A coding denial may reveal an edit issue, documentation gap or incorrect procedure reporting.

Revenue integrity leadership should resist treating every denial as a payer obstacle. Some denials provide valid information about weaknesses within the organization.

Financial Reporting Integrity

Operational reports should accurately represent charges, collections, adjustments, accounts receivable, denials, refunds, credit balances and net revenue.

Metrics should have consistent definitions.

Leaders should understand whether reports are based on date of service, date of posting, claim date, payment date or another period.

Manual manipulation of report classifications to improve performance appearance should be prohibited.

Technology and Automation

Technology may support charge reconciliation, payment variance analysis, claim edits, credit balance review and revenue dashboards.

Automated rules should be tested and monitored.

Technology can reproduce an error at scale when configuration is inaccurate.

The organization should retain human review for material exceptions and maintain evidence of rule changes, approvals and testing.

Revenue Integrity Auditing

Audits should evaluate the complete transaction from patient access through final payment.

The review may include eligibility, authorization, documentation, coding, charge capture, claim submission, adjudication, payment posting and adjustment.

Sampling only paid claims may miss unbilled services, rejected claims, write offs and lost revenue.

Sampling only denials may miss unsupported claims that were paid.

Application to MSK Specialty Care

MSK specialty care involves high value services, complex coding, strict authorization requirements, multiple sites of service and significant device and medication expense.

Revenue integrity controls should focus on alignment among patient selection, medical necessity, authorization, documentation, coding, procedure performance and payment.

GoHealthcare describes prior authorization as a revenue integrity function because the approval must align with the patient, payer, provider, facility, procedure, units, laterality, level and date range.

GoHealthcare Insights

Revenue is most defensible when integrity is created before the date of service.

Retrospective claim correction is expensive and incomplete.

The strongest organizations build controls into patient access, clinical documentation and scheduling so that unsupported or financially unresolved services are identified before they become claims.

Leadership Perspective

Revenue integrity is not synonymous with aggressive collections.

It is the discipline of ensuring that the organization bills and collects exactly what it earned, no more and no less.

This protects financial performance, payer relationships, patient trust and regulatory credibility.

Key Takeaways

Revenue integrity protects against both revenue leakage and improper reimbursement.

Clinical, operational, coding and financial data must be reconciled across the complete revenue cycle.

Overpayments, credit balances and unsupported charges require the same leadership attention as underpayments and missed revenue.

Back to framework navigation
19

Medical Necessity and Utilization Management Compliance

Purpose

Medical Necessity and Utilization Management Compliance ensure that services are clinically appropriate, supported by the patient’s documented condition and consistent with applicable coverage criteria, benefit requirements and professional judgment.

Medical necessity is not established solely by diagnosis coding, physician preference, prior authorization approval or historical payment.

The record should demonstrate why the service is reasonable and necessary for the individual patient.

CMS states that Medicare coverage is generally limited to items and services that are reasonable and necessary for the diagnosis or treatment of illness or injury and uses National Coverage Determinations and Local Coverage Determinations to establish coverage requirements.

Utilization Management Governance

The organization should establish governance for prospective, concurrent and retrospective utilization review.

Clinical leadership, compliance, patient access, prior authorization and revenue cycle management should have defined responsibilities.

Clinical determinations should remain under the authority of appropriately qualified professionals.

Administrative personnel may gather records, identify policy criteria and route cases, but they should not independently make clinical judgments beyond their training and authority.

Escalation should be available when clinical information is incomplete, criteria are ambiguous or patient circumstances do not fit standardized pathways.

Medical Necessity Versus Coding

Coding describes the service and diagnosis represented on the claim.

Medical necessity explains why the service was appropriate for the patient.

A correctly coded procedure may still be noncovered when the record does not satisfy applicable coverage requirements.

Conversely, a clinically appropriate service may require a noncovered notice, alternative payment arrangement or appeal when the payer policy does not provide coverage.

GoHealthcare’s medical necessity guidance emphasizes that coding accuracy and medical necessity are related but separate conditions affecting payment.

Medical Necessity Versus Prior Authorization

Prior authorization is a payer review conducted before the service under the applicable program or plan requirements.

An authorization may provide provisional approval for coverage, but it does not eliminate the provider’s responsibility to document medical necessity accurately.

CMS describes Medicare prior authorization as a process through which supporting documentation is reviewed before the service for provisional affirmation of coverage.

The medical record should remain defensible during postpayment review, even when authorization was obtained.

Coverage Hierarchy

The organization should identify the controlling coverage source for each payer and service.

For Original Medicare, relevant sources may include statutes, regulations, National Coverage Determinations, Local Coverage Determinations, billing and coding articles, manuals and Medicare Administrative Contractor instructions.

The Medicare Coverage Database provides searchable access to NCDs, LCDs and related coverage documents.

Commercial plans may rely on payer clinical policies, benefit documents, utilization management guidelines and contracted review organizations.

The organization should document which policy and version applied to the patient on the relevant date.

Policy Version Control

Coverage policies should be tracked by payer, plan, procedure, jurisdiction, effective date and retirement date.

Staff should not rely solely on personal notes, old printouts or prior approval experience.

Changes in frequency limits, conservative treatment, documentation requirements, anatomical restrictions or covered indications should be communicated before implementation.

The organization should preserve the policy version used for significant reviews and appeals when practical.

Patient Specific Clinical Assessment

Utilization review should evaluate the individual patient rather than depend solely on a checklist.

The record should describe symptoms, diagnosis, physical findings, diagnostic results, functional impairment, prior treatment, treatment response and the clinical rationale for the proposed service.

Criteria should support consistent review, but they should not replace professional judgment.

When a case falls outside standard criteria, the organization should determine whether additional clinical review, payer discussion or appeal is appropriate.

Longitudinal Review

Many MSK services require review of the patient’s procedural and treatment history.

The reviewer may need to identify previous injections, dates of service, anatomical regions, levels, laterality, percentage of relief, duration of relief, functional improvement, conservative treatment and procedure intervals.

Reviewing only the current office note may produce an incomplete determination.

The organization should establish a reliable process for locating and summarizing longitudinal information.

Conservative Treatment

When coverage criteria require conservative treatment, the record should identify the type, duration, adherence, outcome and reason for failure or intolerance.

Generic statements such as “failed conservative care” may not provide sufficient support.

The clinical record should explain what was attempted and how the patient responded.

Exceptions should be documented when conservative treatment is contraindicated, clinically inappropriate or not tolerated.

Frequency and Interval Controls

Utilization management should evaluate whether repeat procedures comply with applicable frequency and interval requirements.

The organization should maintain procedure history controls capable of identifying prior dates, regions, levels and outcomes.

A procedure should not be considered eligible solely because the scheduling system allows the appointment.

Frequency controls should be based on the patient’s complete history across the organization and available outside records.

Treatment Response and Functional Improvement

Repeat interventions may require evidence that the previous service produced clinically meaningful benefit.

The record should identify pain relief, duration, functional improvement, medication reduction, activity tolerance or other relevant outcomes.

The organization should avoid standardized outcome statements that are inserted without patient specific assessment.

Percentage of relief should be supported by the patient’s report and clinical documentation.

Diagnostic and Therapeutic Pathways

Utilization management should distinguish diagnostic procedures from therapeutic procedures.

Diagnostic blocks may be used to evaluate whether a targeted structure or nerve is contributing to pain.

Therapeutic interventions may require evidence from prior diagnostic procedures.

The record should demonstrate that the sequence of care is clinically coherent and consistent with applicable criteria.

Anatomical region, levels and laterality should remain consistent unless the provider documents a clinical reason for change.

Clinical Reviewer Qualifications

Utilization management personnel should have qualifications appropriate to the decisions they make.

Nurses, physicians and other clinical reviewers should work within their licensure and competence.

Nonclinical personnel may perform administrative verification and documentation assembly but should not independently override clinical determinations.

Complex or disputed cases should be escalated to a physician or appropriate specialist when required.

Payer Criteria and Independent Judgment

Payer criteria should be incorporated into pre-service review, but the treating provider retains responsibility for clinical judgment.

When the provider believes the service is appropriate but criteria are not met, the organization should not alter the medical record inaccurately.

It should determine whether additional documentation exists, whether an exception can be requested, whether peer review is appropriate or whether the service will not be covered.

The clinical record should reflect the provider’s honest assessment.

Avoiding Criteria Manipulation

Personnel should never add, exaggerate or conceal clinical information to satisfy coverage criteria.

Documentation should not be changed solely to obtain approval.

Prior treatment response, duration of symptoms, conservative care and functional impairment must be reported accurately.

Submitting information known to be false or materially misleading creates significant compliance exposure.

Denials and Clinical Appeals

Medical necessity denials should receive structured clinical review.

The reviewer should identify the specific unmet criterion, compare the determination with the record and evaluate whether relevant information was omitted or misunderstood.

Appeals should explain the patient’s condition, clinical rationale and applicable policy.

The organization should not appeal every denial automatically.

Cases without sufficient support should be corrected, redirected or not pursued.

Peer to Peer Review

Peer to peer review should be prepared using an accurate summary of the patient’s history, relevant findings, prior treatment and policy criteria.

The participating physician should understand the requested procedure and the reason for the payer’s concern.

The outcome should be documented, including conditions, limitations, approval details and any required follow up.

Information provided during the review should remain consistent with the medical record.

Utilization Data and Outlier Review

The organization should monitor procedure volume, repeat frequency, provider variation, payer denials, approval rates and clinical outcomes.

Outlier status does not establish inappropriate care.

It identifies patterns requiring explanation and review.

Analysis should account for specialty, patient complexity, referral patterns and provider role.

Persistent unexplained variation should be evaluated through documentation review and clinical leadership oversight.

Conflicts and Incentives

Compensation, productivity targets and ownership interests should not encourage unnecessary utilization.

Utilization management personnel should be protected from pressure to approve or submit services that are not supported.

Clinical and financial incentives should be reviewed for potential influence on patient selection, repeat procedures, device use and site of service.

Application to MSK Specialty Care

Pain management, orthopedic surgery, spine surgery, neurosurgery and neuromodulation require strong medical necessity controls because many services involve procedural progression, frequency limitations, implants, diagnostic testing and payer specific criteria.

The medical necessity review should connect clinical presentation, imaging, conservative care, prior procedures, treatment response and the proposed intervention.

A fragmented review can result in inappropriate scheduling, denials, delays or unsupported claims.

GoHealthcare Insights

Medical necessity is best evaluated before authorization submission and before the patient is scheduled for a high risk procedure.

The organization should not rely on the payer to identify that the record is incomplete.

Internal clinical review protects the patient, the provider and the organization.

Leadership Perspective

Utilization management should not be designed only to obtain approvals.

Its purpose is to ensure that the proposed care is supported, the documentation is complete and the organization can defend the service clinically and contractually.

Approval volume without integrity is not operational excellence.

Key Takeaways

Medical necessity requires patient specific clinical support beyond diagnosis and coding.

Utilization review should incorporate longitudinal history, policy criteria, clinical judgment and qualified human oversight.

Prior authorization approval does not replace complete documentation or eliminate postpayment review risk.

Back to framework navigation
20

Prior Authorization Compliance

Purpose

Prior Authorization Compliance ensures that authorization requirements are identified accurately, requests are submitted to the correct organization, clinical information is truthful and complete, approvals are validated before service and the procedure performed remains consistent with the authorization.

Prior authorization is both a patient access control and a revenue integrity control.

Weak authorization processes can delay care, create unnecessary cancellations, generate denials, increase patient liability and expose the organization to claims that cannot be defended.

CMS distinguishes prior authorization from preclaim review based on when the review occurs and when the service may begin. Under prior authorization, the provider or supplier receives the decision before the service is rendered.

Authorization Governance

The organization should establish written governance for determining requirements, submitting requests, tracking status, validating approvals, escalating unresolved cases and managing procedure changes.

The policy should apply to physician offices, ambulatory surgery centers, hospital outpatient departments and other sites of service.

Responsibilities should be defined for ordering providers, clinical staff, authorization specialists, schedulers, financial clearance personnel, coders and billers.

The authorization team should have access to clinical, payer and operational expertise.

Patient and Plan Identification

The authorization process should begin with accurate eligibility and benefit verification.

Personnel should confirm the patient’s active plan, member identification, product type, group information, network status and coordination of benefits.

A payer brand name alone may be insufficient because authorization requirements may vary by employer group, product, delegated medical group, utilization management entity or home plan.

The organization should determine which entity is responsible for the authorization decision.

Determining Whether Authorization Is Required

Staff should verify authorization requirements using current payer sources.

Sources may include payer portals, provider manuals, utilization management systems, plan representatives and contractual resources.

Prior experience should not replace current verification.

The organization should document the date, source and outcome of the requirement check when appropriate.

When the payer or portal does not provide a clear determination, staff should escalate or contact the payer rather than assume authorization is unnecessary.

Correct Submission Destination

The request must be routed to the entity responsible for review.

This may be the health plan, delegated medical group, third party utilization management company, workers compensation carrier, claim adjuster, Veterans Affairs program or another authorized reviewer.

Submitting to the wrong portal can create delays even when the clinical documentation is complete.

The organization should maintain payer routing resources and update them when delegation arrangements change.

Procedure Specific Verification

The requested service should be identified with sufficient specificity.

The request may require the CPT or HCPCS code, diagnosis, anatomical region, laterality, spinal level, number of units, provider, facility and expected date.

The authorization specialist should compare the provider’s order, clinical note and intended procedure.

Unclear or conflicting requests should be resolved before submission.

Staff should not select a code solely because it is more likely to be approved.

Clinical Documentation Review

Authorization personnel should evaluate whether the record contains the information required by the applicable clinical policy.

This may include symptoms, duration, examination findings, imaging, conservative treatment, previous procedures, percentage of relief, duration of relief, functional improvement and clinical rationale.

The team should not merely attach the most recent office note without determining whether it supports the request.

A longitudinal review may be necessary for repeat procedures.

Submission Integrity

All information submitted to the payer should be accurate and traceable to the medical record.

Staff should not modify dates, treatment history, pain relief, diagnoses or other clinical facts to satisfy criteria.

When the documentation is insufficient, the case should be returned for clarification or additional clinical review.

The organization should retain evidence of what was submitted, when it was submitted and by whom.

Supporting Records

Records should be organized so the reviewer can identify the relevant clinical evidence.

Submitting an excessive volume of unorganized records may obscure critical information.

The request should include required notes, imaging reports, treatment history, procedure reports, outcome documentation and other relevant materials.

Summaries may support navigation but should not replace the underlying record.

Authorization Tracking

Every request should be tracked from initiation through final determination.

The tracking record should include submission date, receiving entity, reference number, requested service, status, communication history, requested additional information, decision, approval number, effective dates and limitations.

Pending cases should have assigned follow up dates.

The organization should establish escalation thresholds based on procedure date, payer timeframe, clinical urgency and outstanding information.

Requests for Additional Information

Payer requests for additional information should be reviewed promptly.

The organization should identify whether the requested information already exists, requires provider clarification or cannot be supplied truthfully.

Responses should be submitted within the payer’s timeframe and retained.

Repeated requests for the same information may indicate that the initial submission workflow or documentation template requires improvement.

Approval Validation

An approval should be reviewed before the procedure is scheduled or finalized.

The organization should confirm the patient, payer, provider, facility, procedure, code, units, laterality, anatomical level, date range and any special conditions.

An approval number alone is not sufficient.

Errors in the approval should be corrected before the service whenever possible.

The approval details should be available to scheduling, clinical operations, coding and billing.

Scheduling Controls

The scheduling system should distinguish approved, pending, denied, not required and unable to verify cases.

High risk procedures should not proceed when authorization remains unresolved unless an authorized leader determines that clinical circumstances justify proceeding and the patient has received appropriate financial information.

Scheduling overrides should be limited, documented and monitored.

The organization should avoid informal verbal decisions that bypass the authorization workflow.

Procedure Changes

Changes in code, level, laterality, units, provider, facility or date may affect authorization validity.

The clinical and scheduling teams should notify the authorization function before the changed service is performed when possible.

The authorization team should determine whether an amendment, new request or payer notification is required.

The claim should not be submitted with authorization details that no longer match the service.

Authorization and Medical Necessity

Authorization approval should not be treated as a guarantee of payment or a substitute for medical necessity.

The claim may still be reviewed for eligibility, coding, documentation, coverage, provider enrollment and other payment requirements.

CMS describes Medicare prior authorization as provisional affirmation of coverage based on supporting documentation.

The organization should preserve the complete clinical record even when the payer approved the request.

Urgent and Expedited Requests

Urgent or expedited pathways should be used only when the patient’s clinical circumstances meet applicable requirements.

Routine scheduling pressure should not be represented as clinical urgency.

The request should document why delay could affect the patient’s health or ability to regain function when required.

The organization should track whether urgent requests are used appropriately and whether recurring urgent submissions reflect workflow delay.

Denials

Authorization denials should be classified by reason.

The reason may involve missing information, failure to meet criteria, noncovered service, coding mismatch, provider network, site of service, benefit exclusion or administrative error.

The organization should determine whether the denial is correct, whether additional information can resolve it or whether an appeal or peer review is appropriate.

Denial data should be used to improve clinical documentation and submission quality.

Appeals and Peer Review

Appeals should be based on the record and applicable policy.

The organization should identify the unmet criterion, relevant clinical evidence and rationale for reconsideration.

Peer review should be scheduled with a physician familiar with the patient and procedure.

The organization should document the discussion, decision and any limits placed on the approval.

GoHealthcare’s prior authorization guidance recommends understanding the specific denial reason and using complete clinical documentation to support reconsideration.

Retrospective Authorization

Retrospective authorization should not be treated as a routine substitute for pre-service verification.

When an authorization was missed, the organization should determine whether the payer permits retrospective review and whether the facts support the request.

The incident should be analyzed for root cause.

Repeated retrospective requests may indicate failures in eligibility, payer routing, scheduling or communication.

Authorization Expiration and Renewal

The organization should monitor authorization expiration dates, approved units and remaining visits.

Services should not continue after the approval expires or units are exhausted without appropriate renewal.

Recurring treatments should be reviewed before the final approved visit to prevent unnecessary interruption.

The authorization system should distinguish approved units from units actually used.

Portal and Data Security

Authorization portals contain protected health information and should be accessed through individual credentials.

Shared usernames and passwords should be prohibited when the payer supports individual access.

Access should be removed promptly when personnel change roles or leave the organization.

Submitted documentation should be stored and transmitted through approved secure methods.

Outsourced Authorization Oversight

The organization remains accountable when prior authorization is outsourced.

Vendor responsibilities should be defined through contracts, performance standards, privacy obligations, access controls, reporting requirements and audit rights.

The organization should monitor approval accuracy, turnaround time, submission quality, payer routing, denial causes, missed authorizations and unresolved cases.

A high approval percentage does not establish quality if requests were delayed, inaccurately submitted or poorly documented.

Electronic Prior Authorization

CMS is implementing electronic prior authorization policies for impacted payers, including standardized APIs and operational requirements established under the CMS Interoperability and Prior Authorization Final Rule.

Certain process requirements began in 2026, while API implementation requirements apply according to the timelines established by the rule. These requirements do not automatically apply to every payer or every service, so organizations should determine which plans and programs are covered.

Electronic exchange may reduce manual work, but it does not eliminate the need for clinical review, accurate payer routing, documentation integrity and human oversight.

Authorization Performance Measures

The organization should monitor authorization volume, approval rate, denial rate, turnaround time, pending case age, requests for additional information, peer review frequency, missed authorizations, retrospective requests, cancellations and authorization related claim denials.

Metrics should be segmented by payer, provider, procedure, location and reason.

Approval rate should not be evaluated in isolation.

The organization should also determine whether approved services were performed, billed accurately and paid.

Application to MSK Specialty Care

Prior authorization in pain management, orthopedics, spine, neurosurgery and neuromodulation requires clinical and procedural specificity.

The team may need to verify diagnostic block history, treatment response, functional improvement, spinal levels, laterality, imaging, conservative treatment, procedure frequency and device criteria.

GoHealthcare’s MSK prior authorization resources emphasize that the authorization must align with the exact procedure, clinical documentation and payer requirements.

GoHealthcare Insights

Prior authorization should not be measured only by whether an approval number was obtained.

Operational excellence requires that the approval is correct, the service remains clinically supported, the procedure performed matches the approval and the claim is paid appropriately.

The authorization process protects access, compliance and revenue only when these elements remain aligned.

Leadership Perspective

Prior authorization is a complex clinical and operational control.

Treating it as routine data entry creates avoidable delays, denials and compliance exposure.

Leadership should provide qualified personnel, reliable payer intelligence, structured clinical review, technology and clear escalation authority.

Key Takeaways

Authorization requirements must be verified for the specific patient, plan, provider, location and service.

Submitted clinical information must be complete, truthful and supported by the record.

Approval details must be validated against the service performed before the claim is released.

Back to framework navigation
21

Fraud, Waste and Abuse Prevention

Purpose

Fraud, Waste and Abuse Prevention establishes the organizational controls required to prevent improper claims, unnecessary utilization, misuse of healthcare resources, inappropriate financial arrangements and conduct that could compromise patients, payers or government healthcare programs.

Fraud, waste and abuse should not be managed solely as billing department concerns. Exposure can originate during patient selection, clinical documentation, ordering, prior authorization, scheduling, coding, claim submission, payment posting, vendor contracting, physician compensation, purchasing or use of clinical technology.

The HHS Office of Inspector General provides compliance materials, fraud alerts, advisory opinions and educational resources addressing conduct that may affect federal healthcare programs. CMS also maintains program integrity operations designed to identify and address fraud, waste, abuse and improper payments.

Distinguishing Fraud, Waste and Abuse

The organization should understand the operational distinction among fraud, waste and abuse.

Fraud generally involves knowing and intentional conduct intended to obtain an unauthorized benefit, payment or advantage.

Waste commonly involves unnecessary costs, inefficient practices, overutilization or poor management of healthcare resources. Waste may occur without a specific intent to deceive.

Abuse generally involves practices inconsistent with accepted clinical, business or financial standards that create unnecessary costs or improper payment.

The categories may overlap. An activity that initially appears to be waste may become a fraud concern when leadership learns that the conduct is unsupported and allows it to continue.

The organization should not delay review because it cannot immediately determine which category applies. The first responsibility is to protect patients, preserve evidence, stop continued exposure and establish the facts.

Prevention Governance

The organization should establish clear accountability for preventing fraud, waste and abuse.

The compliance officer should coordinate the prevention program and report material risks to the compliance committee and governing body.

Clinical leaders should oversee medical necessity, patient selection and utilization.

Coding and revenue cycle leaders should maintain accurate coding, billing and payment controls.

Finance should monitor payments, adjustments, refunds, credit balances and unusual financial activity.

Human resources should support screening, education and disciplinary processes.

Information technology should maintain access controls, audit logs and data monitoring capability.

Department leaders should remain accountable for the controls operating within their functions.

Risk Based Prevention Program

The prevention program should be based on the organization’s actual exposure.

Risk assessment should consider the services performed, procedure volume, payer mix, physician arrangements, vendors, locations, ownership interests, compensation models, medications, devices and previous findings.

High volume or high reimbursement services may warrant focused review, but financial value should not be the only consideration.

Services involving strict medical necessity standards, recurring procedures, controlled substances, diagnostic testing, laboratory services, implantable devices, physician ownership or aggressive vendor promotion may carry substantial risk even when claim volume is limited.

Medical Necessity Controls

Medical necessity is one of the most important fraud, waste and abuse prevention controls.

The organization should ensure that services are based on documented patient need rather than routine protocols, financial incentives, ownership interests or payer approval alone.

Clinical documentation should demonstrate the patient’s condition, examination, diagnostic findings, functional limitations, prior treatment, response to previous services and rationale for the proposed intervention.

The organization should monitor patterns in which the same service is ordered for nearly every patient, repeat procedures occur at uniform intervals or documentation contains identical medical necessity language across unrelated cases.

Clinical standardization can support quality. It should not eliminate individualized assessment.

Utilization Controls

Utilization should be evaluated by procedure, provider, location, payer and patient population.

The organization should monitor repeat frequency, units, diagnostic sequencing, therapeutic progression and outcomes.

Outlier status does not establish misconduct. It identifies activity requiring explanation and review.

A provider may have higher utilization because of specialization, referral patterns or patient complexity. The organization should determine whether the record supports that explanation.

Persistent patterns that cannot be explained clinically should receive focused audit and leadership review.

Coding and Billing Prevention Controls

Claims should be supported by the medical record and applicable coding requirements.

The organization should maintain controls addressing upcoding, unbundling, duplicate billing, unsupported modifiers, incorrect units, inaccurate place of service, billing for cancelled services and reporting services not documented as performed.

Coding systems should not be configured to select the highest paying code automatically.

Employees should not be instructed to change codes simply because a payer denied the original claim.

When documentation does not support the service, the claim should be held and reviewed.

Payment does not establish that the claim was compliant. Claims may be reviewed and recouped after payment.

Procedure Frequency and Repetitive Services

The organization should maintain reliable patient procedure histories.

The record should identify prior procedures, dates, anatomical regions, levels, laterality, outcomes and applicable frequency limitations.

This is particularly important when repeated services depend on documented response to previous treatment.

The organization should not rely solely on the scheduling system to determine whether a patient is eligible for another procedure.

Scheduling availability and clinical eligibility are different determinations.

Laboratory and Diagnostic Testing

Laboratory and diagnostic testing should be ordered according to individual clinical need.

Testing should not be driven primarily by ownership, standing financial arrangements, vendor recommendations or uniform protocols that ignore patient circumstances.

The organization should evaluate the relationship among ordering patterns, clinical documentation, test frequency, test complexity, provider compensation and financial interests.

Documentation should explain why the test was reasonable and necessary for the patient.

Drugs, Biologicals and Medical Supplies

The organization should monitor purchasing, storage, administration, documentation and billing for drugs, biologicals and supplies.

Drug units should reconcile with the amount administered, discarded and billed.

Inventory records, medication administration records and claims should be compared for material discrepancies.

Personnel should not substitute products, inflate units, report discarded amounts inaccurately or bill supplies that were not furnished.

Financial incentives from manufacturers, distributors or vendors should receive compliance review.

Implantable Devices

Implantable devices create clinical, financial and compliance exposure.

The operative report, implant log, inventory record, vendor documentation, invoice, charge and claim should reconcile.

Device selection should be based on clinical appropriateness and organizational purchasing standards rather than undisclosed benefits provided to the physician or facility.

Consulting arrangements, educational payments, travel, meals and other benefits involving device manufacturers should be reviewed under applicable fraud and abuse requirements.

OIG has specifically identified physician relationships with vendors and device companies as an area requiring careful scrutiny.

Physician Compensation and Productivity

Compensation structures should not encourage unnecessary services, unsupported documentation or inappropriate referrals.

Productivity incentives should be based on lawful and accurately reported services.

The organization should evaluate whether compensation formulas unintentionally reward high procedure frequency, excessive testing, unsupported coding or use of organization owned ancillary services.

Compensation should be reviewed before implementation and periodically thereafter.

Actual payment should be compared with the approved methodology.

Vendor and Contractor Risk

Billing companies, prior authorization vendors, laboratories, technology companies, marketing organizations and offshore teams can create risk on behalf of the organization.

Contracts should define compliance responsibilities, data access, documentation standards, audit rights, reporting obligations and corrective action requirements.

The organization should monitor vendor conduct rather than relying exclusively on contractual promises.

Outsourcing a function does not transfer accountability for claims, patient information or regulatory compliance.

Data Analytics

Data analytics should be used to identify patterns that may not be visible through individual record review.

Analytics may examine procedure volume, code distribution, modifier use, units, diagnosis patterns, claim adjustments, denial trends, repeat services, provider comparisons and unusual payment activity.

Data should be interpreted carefully.

An algorithmic alert identifies a potential risk. It does not determine that fraud occurred.

Qualified clinical, coding, operational and compliance personnel should evaluate the facts before conclusions are reached.

Reporting and Escalation

Employees should know how to report suspected fraud, waste or abuse.

Reports involving falsification, intentional claim manipulation, patient harm, kickbacks, diversion, excluded individuals or concealment of overpayments should be escalated immediately.

The organization should prohibit retaliation and preserve confidentiality to the greatest extent reasonably possible.

A person who raises a concern should not be expected to conduct the investigation or prove the allegation.

Investigation and Corrective Action

Potential fraud, waste or abuse should be investigated objectively and promptly.

The organization should determine the scope, affected claims, financial exposure, patient impact, responsible individuals and control weaknesses.

Corrective action may require claim holds, refunds, education, workflow redesign, system changes, discipline, vendor action or disclosure.

When credible evidence suggests that an issue extends beyond the initial claim or provider, the review should be expanded appropriately.

Prevention Program Measures

Leadership should monitor audit findings, reported concerns, repeat deficiencies, unusual utilization, refund activity, overpayments, modifier patterns, claim corrections and corrective action completion.

Low reporting volume should not automatically be viewed as evidence of a successful program.

The stronger measure is whether the organization identifies issues early, investigates them appropriately and prevents recurrence.

Application to MSK Specialty Care

Pain management, orthopedics, spine, neurosurgery and neuromodulation involve concentrated exposure because services may be high value, repeated, policy dependent and linked to devices, imaging, facilities or ancillary testing.

Potential warning patterns may include repeat procedures without documented response, identical testing protocols for every patient, unsupported bilateral or multilevel coding, routine use of unbundling modifiers, inconsistent place of service and financial relationships influencing referrals or device selection.

A specialty prevention program should understand the clinical pathway behind the claim rather than reviewing codes in isolation.

GoHealthcare Insights

Fraud, waste and abuse prevention begins before billing.

The organization should ask whether the patient was selected appropriately, whether the clinical record is truthful, whether the service was authorized, whether the procedure performed matches the documentation and whether the final claim accurately represents the complete encounter.

The strongest prevention program stops unsupported activity before it becomes a claim, payment or government concern.

Leadership Perspective

Leadership should never interpret strong collections or high procedure volume as proof that operations are compliant.

Revenue becomes sustainable only when it is clinically supported, accurately documented, properly coded and defensible under review.

Key Takeaways

Fraud, waste and abuse risk can originate throughout the clinical, administrative and financial pathway.

Prevention requires medical necessity controls, utilization monitoring, accurate coding, financial relationship oversight, data analysis and trusted reporting channels.

Outlier detection should initiate qualified review rather than automatic accusation.

Back to framework navigation
22

False Claims Act and Government Enforcement Exposure

Purpose

False Claims Act and Government Enforcement Exposure establishes the controls required to prevent the organization from knowingly submitting, causing the submission of or improperly retaining payments associated with false or unsupported claims involving government funds.

The federal False Claims Act is one of the government’s principal civil enforcement tools. The Department of Justice explains that liability may arise when a person knowingly submits or causes a false claim to be submitted, uses a false record material to a claim or improperly avoids an obligation to return government money. The law’s knowledge standard includes actual knowledge, deliberate ignorance and reckless disregard. Specific intent to defraud is not required.

Organizational Exposure

False Claims Act exposure may arise from direct claim submission or from conduct that causes another party to submit a false claim.

Physician groups, ambulatory surgery centers, laboratories, hospitals, billing vendors, management companies and other entities may create exposure through their own actions or through information supplied to another billing entity.

The organization should not assume that responsibility ends when a third party creates or transmits the claim.

If the organization provides inaccurate documentation, coding, ownership information, certification or cost information that becomes material to government payment, the conduct may require legal and compliance review.

Knowledge Standard

Leadership should understand that compliance exposure is not limited to intentional fraud.

Ignoring credible information, avoiding review of obvious warning signs or allowing known problems to continue may create significant risk.

The organization should not establish systems that discourage employees from identifying overpayments or reporting inaccurate claims.

Once credible information is received, the organization should conduct timely and reasonable review.

A finding should not be delayed indefinitely because the organization prefers not to quantify the exposure.

Common False Claim Risk Areas

Potential exposure may involve services not performed, medically unnecessary services, falsified documentation, upcoding, unbundling, duplicate claims, unsupported modifiers, incorrect units, inaccurate place of service, excluded providers, improper financial relationships and claims inconsistent with authorization or coverage requirements.

Exposure may also involve inaccurate certifications, provider enrollment information, ownership disclosures, cost reports, quality data or other representations material to government payment.

Not every billing error constitutes a False Claims Act violation.

The organization should distinguish inadvertent error from knowing, reckless or deliberately ignorant conduct. Qualified legal counsel should evaluate material issues.

Medical Necessity

Claims for medically unnecessary or unsupported services can create significant government enforcement risk.

The record should demonstrate why the service was reasonable and necessary for the patient.

The organization should not rely solely on the fact that a physician ordered the service, a payer approved it or the claim was paid.

Documentation should support the clinical pathway and the specific service billed.

Repeated medical necessity deficiencies should be treated as an organizational risk rather than a series of isolated documentation issues.

Documentation Falsification

The organization should prohibit creating or changing documentation to obtain payment when the information is not clinically true.

Examples include altering symptom duration, overstating prior treatment response, documenting examination findings not performed, changing anatomical information or adding unsupported medical necessity statements after an audit request.

Legitimate corrections and late entries should follow approved standards and preserve the original record.

Audit trails should be retained when electronic records are changed.

Causing the Submission of Claims

Organizations may create risk even when another entity submits the final claim.

A management services organization may provide coding instructions.

A physician group may supply documentation to an ASC.

A device company may influence coding or medical necessity information.

A billing vendor may submit claims using rules approved by the client.

The organization should evaluate the complete chain of information leading to the claim.

Contract language allocating responsibility does not eliminate the need to ensure that information supplied to another party is accurate.

Reverse False Claims and Overpayments

False Claims Act exposure may also arise when an organization knowingly and improperly avoids or decreases an obligation to return government funds.

Potential overpayments should be investigated, quantified and resolved according to applicable requirements.

The organization should maintain a formal process for identifying, reviewing, reporting and returning overpayments.

Credit balances, audit findings, payer notices, duplicate payments and coding reviews should feed into this process.

DOJ enforcement activity continues to address allegations involving the knowing retention of identified government overpayments.

Reasonable Diligence

The organization should respond promptly when credible information suggests that claims may be inaccurate.

Reasonable diligence may require data analysis, claim sampling, medical record review, coding expertise, clinical review and legal advice.

The scope should reflect the facts.

Reviewing only the claim that triggered the concern may be inadequate when the cause involves a template, policy, system setting, provider pattern or billing rule affecting a larger population.

The organization should document what information was received, when the review began, what methodology was used and how conclusions were reached.

Claim Holds

When credible information suggests that current claims may be unsupported, the organization should consider holding affected claims until the issue is resolved.

Claim holds should be targeted and managed so that compliant claims are not delayed unnecessarily.

The decision should identify the affected service, provider, period, payer and release authority.

Revenue pressure should not override a reasonable claim hold.

Qui Tam and Whistleblower Exposure

The False Claims Act permits private parties to bring actions on behalf of the United States under its qui tam provisions.

Employees, contractors, competitors and other individuals may possess information concerning suspected false claims.

The existence of external whistleblower risk reinforces the importance of trusted internal reporting, nonretaliation and credible investigations.

The organization should respond to concerns based on their substance rather than the status or motives of the person reporting them.

Government Requests and Investigations

Government contact should be escalated immediately to designated leadership and qualified counsel.

The organization should maintain protocols for subpoenas, civil investigative demands, search warrants, interviews, audit requests and document preservation.

Personnel should not destroy, alter or conceal information after learning of a government inquiry.

Employees should receive instructions concerning document preservation, communication and cooperation.

The organization should respond accurately and within applicable deadlines.

Voluntary Disclosure

Some matters may warrant voluntary disclosure to a payer or government authority.

The decision should be made with qualified counsel after evaluating the facts, applicable protocol, financial exposure, patient impact and timing.

Different issues may require different disclosure pathways.

The organization should not assume that repayment alone resolves every matter or that every billing error requires the same disclosure process.

Exclusion and Administrative Consequences

Government enforcement may involve more than financial repayment.

Potential consequences can include civil monetary penalties, exclusion from federal healthcare programs, corporate integrity obligations, licensing action and reputational harm.

The organization should evaluate both entity and individual exposure.

Leadership should understand that enforcement can affect credentialing, payer participation, financing, acquisitions and organizational value.

Board and Executive Reporting

Material False Claims Act concerns should be reported promptly to the governing body.

Reports should describe the issue, known scope, investigation status, claim holds, financial exposure, patient impact, legal involvement and corrective action.

The governing body should monitor the matter through resolution.

Sensitive legal advice may require privileged communication, but privilege should not be used to prevent appropriate governance oversight.

Application to MSK Specialty Care

MSK specialty organizations may face exposure involving unsupported procedures, inaccurate reporting of levels or laterality, repeat services that do not meet criteria, medical necessity deficiencies, device arrangements, facility relationships and improper modifier use.

A radiofrequency ablation claim, for example, may require evidence that the patient completed qualifying diagnostic blocks and achieved the required response under the applicable policy.

A claim may be coded correctly but still be unsupported when the underlying clinical pathway is incomplete.

GoHealthcare Insights

False Claims Act prevention requires leadership to connect documentation, medical necessity, coding, authorization and payment.

The highest risk is not always the original error.

The greater risk may arise when the organization learns that a problem exists and fails to investigate, correct claims, return money or redesign the control.

Leadership Perspective

Leadership must create an environment where bad news travels quickly.

Delaying review may protect short term cash, but it can significantly increase repayment, enforcement and reputational exposure.

Key Takeaways

False Claims Act exposure can arise from submitting, causing or improperly retaining government payments associated with false claims.

Knowledge includes more than intentional misconduct and can include deliberate ignorance or reckless disregard.

Credible concerns require timely investigation, appropriate claim controls, financial resolution and leadership oversight.

Back to framework navigation
23

Anti Kickback, Stark Law and Financial Relationship Compliance

Purpose

Anti Kickback, Stark Law and Financial Relationship Compliance establishes the controls required to evaluate physician compensation, ownership, referral relationships, vendor arrangements, consulting agreements, medical directorships, gifts, discounts and other transfers of value.

Healthcare relationships may be clinically legitimate and commercially reasonable while still requiring detailed regulatory analysis.

Financial arrangement compliance should begin before the relationship is executed or payment is made.

Distinct Legal Frameworks

The federal Anti Kickback Statute and the Physician Self Referral Law, commonly known as the Stark Law, are separate legal frameworks.

They have different elements, scopes, exceptions, safe harbors and consequences.

An arrangement that satisfies a Stark exception may still require Anti Kickback analysis.

An arrangement that does not implicate Stark may still create Anti Kickback, False Claims Act, state law, tax, corporate practice or contractual concerns.

The organization should not combine the analysis into one informal conclusion that an arrangement is generally compliant.

Federal Anti Kickback Statute

The federal Anti Kickback Statute is an intent based criminal law prohibiting the exchange of remuneration to induce or reward referrals or business payable by federal healthcare programs.

Remuneration can include cash, gifts, free or discounted services, excessive compensation, travel, entertainment, investment opportunities, favorable leases and other items of value.

The law can apply to both the party offering or paying the remuneration and the party soliciting or receiving it.

Intent Analysis

Anti Kickback review should evaluate the complete purpose and context of the arrangement.

The organization should consider who benefits, how compensation was determined, whether referrals were discussed, whether payment varies with business generated and whether the arrangement reflects actual services.

Documentation stating that payment is for consulting or administrative work does not resolve the risk when the services are unnecessary, undocumented, duplicative or excessively compensated.

Actual conduct should match the written agreement.

Safe Harbors

OIG safe harbor regulations describe certain payment and business practices that are protected from Anti Kickback enforcement when all applicable conditions are satisfied.

Failure to fit entirely within a safe harbor does not automatically mean an arrangement is unlawful.

It means the arrangement requires evaluation based on the statute, regulatory guidance, facts and circumstances.

The organization should not describe an arrangement as safe harbor compliant unless qualified review confirms that every required element is satisfied.

Physician Self Referral Law

The Physician Self Referral Law generally prohibits a physician from referring Medicare patients for designated health services to an entity with which the physician or an immediate family member has a financial relationship, unless an applicable exception is satisfied.

Financial relationships may involve ownership, investment interests or compensation arrangements.

CMS maintains the controlling law, regulations, exceptions, rulemaking history and voluntary self disclosure resources.

Strict Compliance With Exceptions

Stark analysis should identify the designated health service, referral, financial relationship and applicable exception.

Many exceptions contain detailed requirements involving writing, signatures, duration, compensation methodology, fair market value and commercial reasonableness.

Substantial business legitimacy does not replace satisfaction of an applicable exception.

The organization should monitor whether an arrangement remains compliant throughout its term, not only on the execution date.

Expired agreements, unsigned amendments, payment changes and services outside the contract can create exposure.

Financial Relationship Inventory

The organization should maintain a centralized inventory of material financial relationships.

The inventory should include physician employment, independent contractor arrangements, medical directorships, leases, professional service agreements, management agreements, recruitment, ownership interests, joint ventures, vendor consulting, speaking arrangements, research, laboratories, imaging, pharmacy, durable medical equipment and ambulatory surgery center interests.

Each entry should identify the parties, purpose, services, compensation, term, approval, valuation support, applicable legal analysis and monitoring requirements.

The organization should also track renewals and expiration dates.

Contract Approval Process

No material financial relationship should begin before appropriate operational, financial, compliance and legal review.

The review should determine whether the services are necessary, the arrangement is commercially reasonable, compensation is supported, duties are defined and referrals do not determine payment.

The contract should identify the services, schedule, deliverables, payment methodology, recordkeeping obligations and termination rights.

Retroactive documentation should be prohibited except when qualified counsel determines that a lawful corrective process is available.

Fair Market Value

Compensation should be supported by a reasonable fair market value methodology when required or appropriate.

The organization should document the data, assumptions, qualifications and scope used in the valuation.

External valuation may be appropriate for complex, high value or related party arrangements.

Fair market value alone does not establish full legal compliance.

The organization must also evaluate commercial reasonableness, referral linkage, actual services and satisfaction of any applicable exception or safe harbor.

Commercial Reasonableness

The organization should determine whether the arrangement serves a legitimate business or clinical purpose even without considering the value or volume of referrals.

A medical directorship should address a real organizational need.

A consulting agreement should require identifiable expertise and defined work.

A lease should involve space or equipment actually needed and used.

Arrangements created primarily to maintain or increase referrals require careful legal review.

Medical Directorships

Medical directorship agreements should define specific responsibilities, expected hours, deliverables, reporting and compensation.

Physicians should document the services performed.

The organization should monitor whether duties are completed and whether the time reported is reasonable.

Payments should not continue when services are not being provided.

Multiple directorships involving similar responsibilities should be reviewed for duplication.

Ambulatory Surgery Center Ownership

Physician ownership in an ambulatory surgery center requires careful analysis of federal and state requirements, safe harbor considerations, referral patterns and ownership conduct.

Investment terms should not reward the volume or value of referrals improperly.

Ownership opportunities should not be tied to commitments to perform a specific volume of cases.

The organization should review distributions, capital contributions, redemption terms, facility use and relationships with device or anesthesia vendors.

Vendor and Device Relationships

Relationships with device companies, pharmaceutical manufacturers and other vendors require formal oversight.

Consulting, speaking, training and product development arrangements should involve legitimate services, appropriate qualifications, documented work and compensation supported by the arrangement.

Gifts, travel, meals and entertainment should comply with organizational policy and applicable law.

OIG educational resources describe enforcement concerns involving device manufacturers and payments intended to influence physician product selection.

Marketing and Referral Arrangements

Marketing agreements should describe legitimate marketing services rather than payment for patient referrals.

Compensation based on the number of federally reimbursed patients, procedures or collections may create significant risk.

Lead generation, call center, patient recruitment and digital marketing relationships should receive compliance and legal review.

The organization should understand how marketers obtain patient information and whether communications comply with privacy, consumer protection and payer requirements.

Free and Discounted Services

Free personnel, office space, equipment, transportation, technology, billing support or other benefits may constitute remuneration.

Discounts, rebates and credits should be documented and handled according to applicable requirements.

The organization should evaluate who receives the benefit, whether it influences referrals and how it is reflected in claims or financial records.

Small or customary benefits should not be assumed to be risk free.

Conflicts of Interest

Physicians, executives and board members should disclose financial interests that could affect referrals, purchasing, contracting or clinical decisions.

The organization should maintain a conflict disclosure process and document recusal when appropriate.

Ownership and compensation relationships should be communicated to compliance personnel before relevant contracts or purchasing decisions are approved.

Failure to disclose a relationship should be treated as a compliance concern.

Monitoring Actual Performance

The organization should confirm that actual conduct matches the approved agreement.

Monitoring should review payments, invoices, time records, deliverables, referrals, contract changes and expiration dates.

Automated payments should not continue after an agreement expires.

Payments inconsistent with the contract should be investigated promptly.

A compliant agreement can become noncompliant when performance deviates from its terms.

Self Disclosure and Correction

Potential Stark violations may be addressed through the CMS Voluntary Self Referral Disclosure Protocol when appropriate.

Anti Kickback or other fraud and abuse matters may require different reporting or disclosure processes.

The organization should obtain qualified legal advice before deciding how to correct, refund or disclose an arrangement.

Application to MSK Specialty Care

MSK organizations frequently interact with ASCs, hospitals, imaging centers, laboratories, therapy services, device manufacturers, pharmacies and durable medical equipment suppliers.

Physicians may hold ownership, consulting, directorship or purchasing roles across several related entities.

These relationships are not inherently improper.

They require structured review because clinical recommendations, facility selection, implants, testing and referrals may create financial benefit.

GoHealthcare Insights

Financial relationship compliance cannot be managed through contract templates alone.

The organization must understand the business purpose, financial methodology, actual work, referral implications and operational behavior surrounding the arrangement.

Leadership Perspective

A profitable relationship should receive more scrutiny, not less, when referral influence, physician ownership or vendor incentives are involved.

The strongest organizations design compliant arrangements before money begins to move.

Key Takeaways

Anti Kickback and Stark requirements are distinct and should be analyzed separately.

Financial relationships require documented business purpose, appropriate compensation, formal approval and ongoing monitoring.

A written agreement does not protect conduct that differs from the agreement or is intended to influence referrals improperly.

Back to framework navigation
24

Government Program and Payer Contract Compliance

Purpose

Government Program and Payer Contract Compliance establishes how the organization identifies, implements and monitors the requirements governing participation in Medicare, Medicaid, commercial insurance, managed care, workers compensation, Veterans Affairs programs and other payment arrangements.

A payer relationship is not limited to a reimbursement fee schedule.

Participation may require compliance with enrollment, credentialing, medical necessity, authorization, coding, claims, quality, access, documentation, audit and repayment obligations.

The organization should maintain a complete understanding of the requirements connected to each payer and program.

CMS maintains the Medicare Program Integrity Manual, provider enrollment resources and program integrity operations governing medical review, data analysis, audits and corrective actions.

Program and Contract Inventory

The organization should maintain a centralized inventory of government programs and payer contracts.

The inventory should identify the legal entity, tax identification number, providers, locations, effective dates, products, networks, reimbursement terms, delegated entities and termination provisions.

The inventory should also identify the associated provider manuals, policy portals, amendments and notices incorporated into the relationship.

Different entities within the same corporate organization may have different contracts and enrollment records.

The organization should not assume that one agreement applies to every provider, facility or service location.

Contract Ownership

Each payer relationship should have an accountable executive or departmental owner.

Contracting personnel may negotiate the agreement, but operational leaders are responsible for implementing the requirements affecting their functions.

Patient access should understand eligibility, network and authorization requirements.

Clinical leaders should understand documentation and utilization standards.

Revenue cycle personnel should understand claim, filing and appeal rules.

Compliance should monitor material obligations and regulatory exposure.

Finance should understand reimbursement, adjustment and repayment provisions.

Contract Document Hierarchy

The organization should identify all documents governing the relationship.

These may include the signed agreement, amendments, fee schedules, provider manuals, electronic notices, clinical policies, billing guidance and delegated utilization management requirements.

The organization should determine which document controls when instructions conflict.

Material interpretations should be documented and escalated when necessary.

Staff should not rely on historical practice when current contract or policy language differs.

Government Program Enrollment

Providers and entities should maintain accurate enrollment information.

Changes involving ownership, practice location, reassignment, managing employees, banking, licensure and adverse legal action should be evaluated for reporting requirements.

The organization should track revalidation dates and pending applications.

Claims should not be submitted under providers or locations that are not properly enrolled for the service.

CMS maintains current Medicare enrollment and renewal requirements for providers and suppliers.

Credentialing and Network Participation

The organization should distinguish professional licensure, payer credentialing, government enrollment and network participation.

Completion of one process does not establish completion of the others.

Provider rosters should be reconciled with payer records.

New physicians, advanced practice providers and locations should not be represented as participating until participation is confirmed.

The organization should monitor terminated, closed or inactive providers so claims are not submitted under outdated credentials.

Payer Policy Management

Payer medical policies, authorization rules, coding instructions and payment requirements should be monitored systematically.

The organization should identify effective dates and affected services.

Policy changes should be translated into documentation templates, authorization workflows, scheduling controls, coding rules and staff education.

A payer update should not remain solely within the contracting or authorization department when it affects clinical care and billing.

Delegated Utilization Management

Many payers delegate authorization or medical necessity review to another organization.

The organization should identify the correct utilization management entity for the patient, plan and service.

Delegation may vary by product, employer group, location or procedure.

Submitting a request to the payer’s general portal does not establish that it reached the responsible reviewer.

Routing information should be maintained, tested and updated.

Network and Site of Service Compliance

Network status should be verified for the provider, facility and service involved.

A physician may participate while the selected facility does not.

A facility may participate for one product but not another.

The organization should evaluate site of service requirements, authorization conditions and patient financial implications before scheduling.

Claims should report the location where the service was actually performed.

Claims Submission Requirements

Claims should comply with program and contract requirements concerning provider identification, coding, modifiers, units, place of service, filing method and supporting documentation.

The organization should maintain payer specific billing instructions when requirements differ.

A rule used for Medicare should not automatically be applied to Medicaid, commercial payers, workers compensation or Veterans Affairs claims.

Claim edits and billing rules should identify the payer population to which they apply.

Timely Filing and Notification

The organization should track claim filing, corrected claim, reconsideration, appeal and notification deadlines.

Internal deadlines should be earlier than contractual limits.

Clearinghouse acceptance does not always establish payer receipt.

Proof of submission should be retained when relevant.

The organization should monitor losses caused by late filing and assign the root cause to the department where the delay originated.

Authorization and Notification Requirements

Contracts may require prior authorization, precertification, notification, referral or concurrent review.

These terms are not interchangeable.

The organization should identify the exact requirement, responsible entity, submission deadline and consequence of noncompliance.

Emergency and urgent services may follow separate notification rules.

Personnel should not assume that lack of prior authorization can always be corrected retrospectively.

Medical Necessity and Coverage

Contract compliance requires application of the payer’s coverage standards to the patient’s plan and service.

The organization should distinguish coverage criteria from clinical judgment.

When a service is clinically appropriate but not covered, the organization should follow applicable notice, appeal and patient financial processes.

Documentation should never be altered to create the appearance that criteria were met.

Payer Audits and Record Requests

The organization should establish a centralized process for payer audits, medical record requests, payment reviews and extrapolation notices.

Requests should be logged with the payer, deadline, affected claims, records submitted, response and final outcome.

The organization should verify that the requesting party is authorized to receive the information.

Records should be reviewed for completeness and consistency before submission.

Documentation should not be created retroactively for the purpose of the audit.

Recoupments and Offsets

Payer recoupments should be reviewed rather than accepted automatically.

The organization should determine the basis, affected claims, appeal rights, contractual authority and deadline.

Offsets against future payments should be reconciled.

Finance and revenue cycle teams should ensure that recoupments are posted correctly and do not create inaccurate patient balances.

Potential government overpayments should also be evaluated under applicable reporting and repayment requirements.

Appeals and Dispute Resolution

Appeals should be based on the record, payer policy and contract.

The organization should define who may approve clinical appeals, coding appeals, contract disputes and legal escalation.

Appeal outcomes should be analyzed for systemic improvement.

A favorable appeal should not prevent correction of an upstream workflow that caused the original denial.

Material disputes involving contract interpretation, payment methodology or network obligations may require legal or specialized contracting review.

Provider Manuals and Electronic Updates

Payer manuals and portal notices may change operational requirements.

The organization should assign responsibility for monitoring these sources and preserving material notices.

Important changes should be entered into the regulatory or payer change log.

The organization should not depend on individual employees to remember changes communicated through email.

Medicaid and State Variation

Medicaid requirements can vary by state, delivery system, managed care plan and provider type.

Organizations operating across several states should maintain jurisdiction specific guidance.

A process approved in one state should not be replicated automatically in another.

State licensure, coverage, enrollment, authorization and billing requirements should be evaluated separately.

Workers Compensation and Liability Programs

Workers compensation and liability claims may involve employer authorization, adjusters, state fee schedules, treatment guidelines, legal representatives and jurisdiction specific filing requirements.

The organization should verify the responsible carrier, accepted body part, claim status, authorized provider and approved treatment.

Commercial insurance processes should not be applied automatically to workers compensation cases.

Veterans Affairs and Community Care

Veterans Affairs and community care services may require specific referrals, authorization numbers, approved date ranges, providers and locations.

The organization should retain the referral or authorization and compare it with the service performed.

Claims should follow the required submission and documentation process.

Unresolved eligibility or authorization questions should be addressed before nonurgent services whenever possible.

Subcontractors and Delegated Functions

The organization remains accountable for vendors performing billing, coding, authorization, credentialing or other delegated activities.

Contracts should require compliance with applicable payer and government program obligations.

Performance should be monitored through reporting, audits, access controls and corrective action.

The organization should know which subcontractors have access to claims or patient information.

Contract Compliance Monitoring

Leadership should monitor denial trends, timely filing losses, authorization failures, underpayments, payer audits, credentialing exceptions, contract amendments and unresolved disputes.

Data should be segmented by payer, product, provider, location and service.

The organization should identify payers creating disproportionate administrative burden or financial risk.

Contract performance should be evaluated using both reimbursement and operational cost.

Application to MSK Specialty Care

MSK organizations frequently manage different coverage and authorization pathways for injections, diagnostic blocks, radiofrequency ablation, neuromodulation, spine surgery, joint procedures and implantable devices.

The same procedure may have different requirements depending on the payer, patient plan, state, provider, facility and utilization management vendor.

The organization should maintain payer intelligence at the procedure level rather than relying on broad payer summaries.

GoHealthcare Insights

Contract compliance is created when payer requirements are translated into actual workflows.

A signed agreement has limited value when staff cannot determine which plan applies, where authorization must be submitted, which documentation is required or how payment should be calculated.

Leadership Perspective

Payer relationships should be managed as enterprise operating relationships, not simply contracts stored by administration.

Leadership should understand the clinical, administrative and financial burden created by each major payer.

Key Takeaways

Every government program and payer relationship should be documented, owned and translated into operational controls.

Enrollment, credentialing, network status, authorization, coding, claims and payment requirements must remain aligned.

Payer manuals and delegated arrangements require active monitoring because they can change how daily work must be performed.

Back to framework navigation
25

HIPAA Privacy and Confidentiality Compliance

Purpose

HIPAA Privacy and Confidentiality Compliance establishes how the organization protects health information, limits inappropriate use and disclosure, supports patient rights and maintains accountability for workforce members and third parties with access to protected health information.

The HIPAA Privacy Rule establishes national standards protecting medical records and other individually identifiable health information. It applies to covered health plans, healthcare clearinghouses and healthcare providers that conduct specified electronic transactions. Business associates also have direct and contractual obligations under applicable HIPAA requirements.

Privacy Governance

The organization should designate a qualified Privacy Officer or responsible privacy leader.

The Privacy Officer should oversee policy development, patient rights, complaint management, privacy investigations, workforce education, business associate oversight and reporting to leadership.

Privacy governance should coordinate with compliance, information security, health information management, human resources, legal counsel, clinical operations and information technology.

Privacy and cybersecurity are related but distinct.

Privacy governs when health information may be used or disclosed.

Security governs safeguards protecting electronic health information.

Protected Health Information

Protected health information includes individually identifiable health information maintained or transmitted by a covered entity or business associate in applicable forms.

The organization should protect information regardless of whether it appears in the EHR, email, paper records, text messages, recorded calls, images, authorization portals, billing systems or reports.

Information does not lose protection merely because it has been copied into a spreadsheet or transferred to a vendor.

Data that has been properly deidentified according to applicable standards is treated differently, but informal removal of names may not be sufficient to deidentify information.

Permitted Uses and Disclosures

The organization should define when protected health information may be used or disclosed without patient authorization and when written authorization is required.

Permitted activities may include treatment, payment and healthcare operations, as well as other uses and disclosures specifically allowed or required by law.

Personnel should not assume that every healthcare related purpose is permitted.

The purpose, recipient, information requested and applicable authority should be evaluated.

When authorization is required, the organization should use a form containing the required elements and should verify that the authorization remains valid.

Minimum Necessary Standard

The organization should make reasonable efforts to limit many uses, disclosures and requests for protected health information to the minimum necessary to accomplish the intended purpose.

Minimum necessary does not apply in every circumstance, including certain treatment disclosures and other defined exceptions.

Personnel should be trained not to use the phrase minimum necessary as a reason to obstruct legitimate treatment or patient access.

Role based policies should identify what information workforce members need to perform their responsibilities.

Role Based Access

System access should be based on job responsibilities.

A scheduler, coder, nurse, authorization specialist, physician, billing employee and technology administrator may require different access.

The organization should approve access before it is granted and review access periodically.

Access should be modified promptly when responsibilities change.

Access should be terminated when employment or a contractual relationship ends.

Shared user accounts should be prohibited when systems support individual credentials.

Workforce Confidentiality

Workforce members should access protected health information only for authorized job responsibilities.

Curiosity, personal relationships, public interest or professional status do not justify access.

Employees should not review the records of family members, coworkers, public figures or acquaintances without a legitimate work related need.

Confidentiality obligations should continue after employment ends.

Unauthorized access should be investigated even when information was not shared outside the organization.

Notice of Privacy Practices

Covered healthcare providers should maintain and distribute an appropriate Notice of Privacy Practices.

The notice should explain permitted uses and disclosures, patient rights, organizational duties, complaint procedures and contact information.

The organization should make the notice available through required channels and update it when material privacy practices or legal requirements change.

Acknowledgment processes should be documented when applicable.

Patient Right of Access

Patients generally have a right to inspect or obtain copies of protected health information maintained in designated record sets, subject to defined limitations.

The organization should maintain a reliable process for receiving, verifying, tracking and completing access requests within applicable timeframes.

Access should be provided in the requested form and format when readily producible or in an agreed alternative format.

Reasonable cost based fees should be applied according to applicable requirements.

Access requests should not be delayed because the patient has an unpaid balance.

Amendment Requests

Patients may request amendment of protected health information in designated record sets.

The organization should evaluate the request and respond according to applicable requirements.

A request may be denied under defined circumstances, but the patient should receive the required explanation and opportunity to submit a statement of disagreement when applicable.

An amendment process should not delete or obscure the original clinical record improperly.

Restrictions and Confidential Communications

Patients may request restrictions on certain uses or disclosures and may request confidential communications through alternative means or locations.

The organization should evaluate and document these requests.

Accepted restrictions should be communicated to relevant personnel and systems.

Special attention is required when disclosure to a health plan may be restricted because the patient paid for the service in full and the applicable Privacy Rule conditions are satisfied.

Accounting of Disclosures

Patients may have the right to receive an accounting of certain disclosures made during the applicable period.

The organization should identify which disclosures must be tracked and which are excluded from the accounting requirement.

Business associate agreements and workflows should support the covered entity’s ability to respond.

HHS explains that the Privacy Rule provides a right to an accounting of certain disclosures and describes the applicable accounting period and exclusions.

Patient Representatives

The organization should verify the authority of personal representatives, guardians, parents, executors and other persons requesting information on behalf of a patient.

Authority may depend on state law, the patient’s status, the type of record and the scope of the representative’s authority.

Staff should not assume that a family relationship automatically authorizes unrestricted access.

Documentation supporting representation should be retained.

Business Associates

Business associates should receive protected health information only under an appropriate agreement when required.

The agreement should define permitted uses, safeguards, reporting, subcontractors, return or destruction of information and termination obligations.

The organization should know which vendors access protected health information and whether they use subcontractors.

Business associate status should not be determined solely by the vendor’s description of itself.

The actual services and data access should be evaluated.

Vendors and Offshore Operations

Remote and offshore personnel should follow the same privacy standards as onsite workforce members.

The organization should evaluate location, access method, device security, data storage, printing, screenshots, downloads and supervision.

Contracts should limit use and disclosure and require prompt incident reporting.

Access should be based on role and monitored.

The organization should not assume that a signed business associate agreement alone establishes effective privacy protection.

Electronic Communication

Email, text messaging, patient portals, fax and collaboration platforms should be used according to approved privacy and security standards.

Personnel should verify recipients before sending information.

Sensitive information should not be transmitted through unapproved personal accounts or consumer applications.

Misdirected communications should be reported promptly.

Automated patient communications should be configured carefully so appointment, procedure or financial information is not disclosed to an unintended recipient.

Verbal and Physical Privacy

Privacy controls should address conversations, paper records, screens, printers and physical work areas.

Clinical and financial discussions should not occur where unauthorized individuals can hear them unnecessarily.

Screens should be positioned appropriately.

Printed records should be retrieved promptly and disposed of securely.

Patient sign in, calling and waiting room processes should limit unnecessary disclosure.

Marketing and Patient Communications

Marketing communications involving protected health information require specific review.

The organization should distinguish treatment communication, healthcare operations, fundraising and marketing.

Vendor relationships involving patient outreach should be evaluated for authorization, remuneration and business associate requirements.

Patient contact information should not be shared with a manufacturer, marketer or unrelated business merely because the product may be relevant to the patient.

Legal and Law Enforcement Requests

Subpoenas, court orders, law enforcement requests and government inquiries should be routed through designated personnel.

HIPAA permits certain disclosures for law enforcement and legal purposes under defined conditions, but the existence of a request does not automatically authorize unlimited disclosure.

The organization should verify the requester, authority, scope and documentation required before releasing information.

Privacy Complaints

Patients and workforce members should be able to file privacy complaints without retaliation.

Complaints should be logged, investigated and resolved.

The organization should identify whether the complaint reflects an isolated incident, policy weakness, access problem, vendor issue or training deficiency.

Patients should be informed of their right to file a complaint with HHS when applicable.

OCR enforces the HIPAA Privacy and Security Rules through complaint investigations, compliance reviews, education and other enforcement activity.

Privacy Incidents

Suspected unauthorized use, access or disclosure should be reported immediately.

The organization should preserve evidence, contain the exposure and determine what information was involved, who received it and whether it was further used or disclosed.

The formal breach risk assessment and notification process will be addressed in Section 26.

Employees should not make independent conclusions that an incident is too small to report.

Substance Use Disorder Information

Records involving substance use disorder treatment may be subject to additional confidentiality requirements under 42 CFR Part 2, as well as state law and HIPAA.

The organization should identify whether it creates, receives or maintains Part 2 records and apply the appropriate consent, notice, redisclosure and patient rights requirements.

The 2024 Part 2 Final Rule aligned several provisions more closely with HIPAA, but Part 2 remains a distinct regulatory framework requiring specific analysis.

Artificial Intelligence and Privacy

Artificial intelligence tools should not receive protected health information until privacy, security, contractual and data use requirements have been evaluated.

The organization should determine whether the vendor retains prompts, uses data for model training, permits subcontractor access, stores information outside approved environments or transfers data across jurisdictions.

Users should not place patient information into public generative AI systems without organizational authorization and appropriate safeguards.

AI output should be handled as protected health information when it contains identifiable patient data.

Privacy Training

Privacy education should be role specific.

Clinical staff should understand treatment disclosures and patient communications.

Authorization and billing personnel should understand payment related uses and minimum necessary principles.

Health information personnel should understand patient rights.

Managers should understand incident escalation and nonretaliation.

Technology personnel should understand privileged access and audit logging.

Training should include realistic examples from the organization’s workflows.

Monitoring and Auditing

The organization should monitor access logs, patient complaints, misdirected communications, inappropriate downloads, shared credentials, terminated user access and vendor activity.

Random and targeted access audits should be conducted.

Unusual access should be investigated rather than accepted solely because the user had technical permission.

Repeat violations should result in corrective action and appropriate discipline.

Application to MSK Specialty Care

MSK organizations exchange protected health information across physician offices, imaging facilities, ASCs, hospitals, therapy providers, device vendors, payers and utilization management organizations.

The organization should ensure that each exchange has a legitimate purpose and appropriate authority.

Procedure photographs, imaging, operative reports, implant information and authorization records should not be shared beyond what is required for care, payment or another permitted purpose.

GoHealthcare Insights

Privacy compliance should follow the patient information across the complete operating pathway.

Data can move from referral intake to authorization, scheduling, clinical care, coding, billing, appeals, analytics and vendor systems.

Every transfer creates a responsibility to verify purpose, access, security and accountability.

Leadership Perspective

Privacy protection is not simply an information technology function.

It is a leadership obligation affecting patient trust, workforce behavior, vendor oversight, technology selection and organizational reputation.

Key Takeaways

Protected health information should be used, accessed and disclosed only for authorized purposes.

Patient rights require reliable operational processes, not merely written policies.

Business associates, remote personnel and artificial intelligence vendors must be governed according to their actual access and use of patient information.

Back to framework navigation
26

Security Compliance and Breach Response

Purpose

Security Compliance and Breach Response establish the administrative, physical, technical and organizational controls required to protect electronic protected health information, detect security incidents, contain unauthorized activity, determine whether a reportable breach occurred and complete required notifications and corrective actions.

Healthcare security should not be treated solely as an information technology responsibility. Security risk can originate through clinical workflows, remote access, mobile devices, email, patient portals, prior authorization systems, billing platforms, vendors, artificial intelligence tools, employees, contractors and physical work environments.

The HIPAA Security Rule requires covered entities and business associates to protect the confidentiality, integrity and availability of electronic protected health information through appropriate administrative, physical and technical safeguards. HHS identifies the current Security Rule separately from proposed modifications that may strengthen future cybersecurity requirements.

Security Governance

The organization should establish formal security governance with defined authority, accountability and reporting relationships.

The Security Officer should coordinate with the Privacy Officer, compliance leadership, executive leadership, clinical operations, information technology, human resources, legal counsel, risk management and vendor management.

The governance structure should identify who may approve security policies, accept residual risk, restrict user access, isolate systems, activate downtime procedures, retain forensic specialists, notify cyber insurers, engage law enforcement and communicate with patients or regulators.

Security decisions that could affect patient care, system availability, privacy or regulatory reporting should not depend on one technical employee acting without executive oversight.

Security Risk Analysis

The organization should conduct an accurate and thorough assessment of potential risks and vulnerabilities affecting electronic protected health information.

The risk analysis should include every system, device, location, application, interface, cloud platform, vendor connection and workforce arrangement that creates, receives, maintains or transmits electronic protected health information.

It should evaluate the EHR, practice management platform, billing system, prior authorization portals, patient portals, file storage, email, mobile devices, remote access tools, backup environments, medical devices, artificial intelligence applications and vendor hosted systems.

HHS continues to identify comprehensive risk analysis as a core Security Rule obligation and as a recurring area of enforcement activity.

Risk Management

Identifying a vulnerability is not the same as correcting it.

Every material finding should be entered into a security risk register and assigned to an accountable owner.

The organization should document the risk, affected information, likelihood, potential impact, existing safeguards, residual exposure, remediation plan, due date and executive acceptance decision.

High risk findings should not remain unresolved because remediation is expensive, operationally inconvenient or dependent on a vendor.

When immediate remediation is not possible, the organization should implement interim protections and document why the residual risk is temporarily accepted.

Administrative Safeguards

Administrative safeguards should define how the organization manages security responsibilities, workforce access, risk analysis, risk management, incident response, contingency planning and periodic evaluation.

Security policies should address acceptable use, password management, authentication, remote work, mobile devices, email, internet access, portable media, software installation, privileged access, data transmission, backup, system changes and vendor access.

Policies should be translated into operational procedures. A policy requiring secure access is incomplete without a process governing account approval, authentication, periodic review, access modification and termination.

Physical Safeguards

Physical safeguards should protect facilities, workstations, devices, servers, paper containing access credentials and other resources capable of exposing electronic protected health information.

The organization should control entry to restricted areas, secure network equipment, protect unattended workstations and establish procedures for device disposal and reuse.

Remote and home based personnel should follow defined workstation standards. Screens should not be visible to unauthorized individuals, devices should be secured when unattended and protected information should not be printed or stored locally without approval.

Technical Safeguards

Technical safeguards should include access control, unique user identification, authentication, audit controls, transmission protection and integrity mechanisms appropriate to the environment.

The organization should implement multifactor authentication where risk warrants it, particularly for remote access, cloud services, administrative accounts, email and systems containing significant quantities of patient information.

Encryption should be used according to organizational risk, system capability and applicable requirements.

Security logging should be configured so the organization can determine who accessed information, what actions were performed and when activity occurred.

Identity and Access Management

Access should be based on approved job responsibilities and the minimum level required to perform assigned work.

The organization should maintain documented processes for onboarding, role changes, temporary access, privileged access, contractor access and termination.

Former employees and contractors should not retain access after their relationship ends.

Shared accounts should be prohibited when individual credentials are available.

Privileged access should receive enhanced approval, monitoring and periodic review because administrative accounts can modify systems, disable controls and access large quantities of information.

Vulnerability and Patch Management

The organization should maintain an inventory of hardware, software, systems and versions.

Known vulnerabilities should be evaluated according to severity, exploitability, exposure, available remediation and operational impact.

Security updates should be tested and implemented within defined timeframes.

Unsupported operating systems, applications and devices should be replaced, isolated or managed through documented compensating controls.

HHS has specifically emphasized that risk analysis should include vulnerabilities arising from unpatched software.

Email, Phishing and Social Engineering

Email and social engineering remain major pathways for credential compromise, malware and unauthorized disclosure.

The organization should use technical filtering, multifactor authentication, employee education, suspicious message reporting and rapid credential containment.

Employees should be trained to verify requests involving payments, password resets, records, sensitive attachments and unusual system access.

A message appearing to come from an executive, payer, government contractor or known vendor should not be trusted solely because the sender name appears familiar.

Ransomware Preparedness

Ransomware preparedness should include prevention, detection, containment, backup protection, downtime procedures, legal review, forensic investigation and communication planning.

Backups should be separated appropriately from production systems and tested for restoration.

The organization should know which clinical and administrative functions must continue when systems are unavailable.

HHS explains that ransomware affecting unsecured protected health information may create a presumed breach unless the organization can demonstrate a low probability that the information was compromised through the required risk assessment.

Security Incident Response Plan

The organization should maintain a written Security Incident Response Plan.

The plan should define severity levels, reporting channels, response authority, technical containment, evidence preservation, clinical continuity, legal involvement, cyber insurance notification, vendor coordination, law enforcement contact and executive communication.

The plan should address ransomware, compromised credentials, unauthorized access, lost devices, misdirected information, malicious insiders, vendor incidents, system intrusion, denial of service, data corruption and accidental exposure.

Personnel should know how to report a suspected incident immediately without waiting to determine whether a breach occurred.

Initial Incident Containment

The first response priority is to protect patients, information and essential operations.

Containment may require disabling accounts, disconnecting devices, blocking network activity, suspending vendor access, retrieving a misdirected communication or temporarily shutting down a system.

Containment actions should be documented.

Personnel should avoid destroying evidence through unnecessary device wiping, file deletion or system modification before qualified technical review occurs.

Security Incident Versus Breach

A security incident is not automatically a reportable breach.

The organization must determine what information was involved, whether the use or disclosure was permitted, whether the information was secured and whether an exception applies.

When unsecured protected health information was used or disclosed impermissibly, a breach is generally presumed unless the organization documents that there is a low probability the information was compromised.

The HIPAA Breach Notification Rule governs notification following breaches of unsecured protected health information.

Breach Risk Assessment

The breach risk assessment should be performed by qualified privacy, security, compliance and legal personnel.

The assessment should evaluate the nature and extent of the information involved, the unauthorized person who used or received it, whether the information was actually acquired or viewed and the extent to which the risk was mitigated.

The analysis should be based on documented facts rather than assumptions.

The organization should not conclude automatically that an incident is harmless because the recipient is known, the number of patients is small or the information was returned.

Notification Requirements

When a reportable breach occurs, the organization should determine which individuals, regulators, media organizations, business partners and other parties must be notified.

Notification content, method and timing should follow applicable federal and state requirements.

Covered entities and business associates have different responsibilities depending on their relationship and the circumstances.

HHS states that covered entities and business associates must provide required notification following a breach of unsecured protected health information. HHS also continues to enforce timely business associate notification to affected covered entities.

Business Associate Incident Reporting

Business associate agreements should require vendors to report security incidents and breaches promptly.

The agreement should define the information the vendor must provide, the person to contact, cooperation obligations, investigation support, notification responsibilities and financial allocation.

A contractual deadline should provide the covered entity enough time to investigate and complete its own notification obligations.

The organization should not accept a vendor provision allowing delayed notification until the vendor has completed its entire internal investigation.

Communication Management

Incident communication should be coordinated.

Employees, patients, physicians, vendors and media representatives should receive accurate and consistent information appropriate to their roles.

Personnel should not speculate publicly or communicate with affected individuals independently.

The organization should preserve transparency while avoiding premature conclusions that could misstate the scope, cause or impact of the event.

Corrective Action

Incident closure should include more than technical restoration.

The organization should identify the root cause, affected controls, workforce behavior, vendor responsibilities, policy changes, technology remediation and monitoring requirements.

Corrective action may include password resets, system configuration, access reduction, encryption, employee education, vendor corrective action, disciplinary action and enhanced monitoring.

The organization should validate that the corrective action reduced the identified risk.

Incident Exercises

The Incident Response Plan should be tested through tabletop exercises and operational simulations.

Exercises should include executive leadership, compliance, privacy, security, clinical operations, communications, revenue cycle and vendor management.

Testing should determine whether contact information is current, leaders understand their authority, backup systems can be restored and patient care can continue during an outage.

Lessons learned should be incorporated into the plan.

Proposed Security Rule Changes

HHS published proposed modifications intended to strengthen the HIPAA Security Rule.

Because proposed requirements are not final merely because they have been published, the organization should monitor the rulemaking process and distinguish current obligations from future requirements.

The proposed rule can still be used as an indicator of regulatory direction and emerging expectations, but implementation decisions should identify clearly whether a control is legally required, recommended or voluntarily adopted.

Application to MSK Specialty Care

MSK organizations often exchange information among physician practices, ASCs, hospitals, imaging facilities, payers, device vendors, billing organizations and remote authorization teams.

A compromised account can expose clinical notes, imaging, operative records, authorization documents, financial information and implant data across several organizations.

Security controls should therefore follow the patient information through the complete clinical and revenue cycle pathway.

GoHealthcare Insights

Cybersecurity failures frequently become operational, financial, privacy and patient safety events at the same time.

Security leadership should not focus only on whether information was stolen. It should evaluate whether clinicians lost access to records, procedures were delayed, authorizations could not be completed, claims stopped moving and patients could not communicate with the organization.

Leadership Perspective

Security resilience is determined before the incident occurs.

Leadership must fund prevention, define authority, test downtime plans and require vendors to demonstrate their ability to protect and restore information.

Key Takeaways

Security compliance requires documented risk analysis, risk management and operational safeguards.

Security incidents must be contained, investigated and evaluated under applicable breach notification requirements.

Business associates, remote workers and artificial intelligence vendors must be included in the security governance structure.

Back to framework navigation
27

Records Retention, Destruction and Legal Holds

Purpose

Records Retention, Destruction and Legal Holds establish how the organization preserves clinical, billing, financial, corporate, workforce, compliance and technology records for required periods and destroys information securely when continued retention is no longer required.

A reliable retention program protects patient care, audit readiness, legal rights, regulatory response and institutional memory.

Uncontrolled retention creates privacy, security, discovery and storage risk. Premature destruction can compromise patient care, claims defense, litigation, government response and compliance investigations.

Records Governance

The organization should establish a formal Records Management Program overseen by designated leadership.

Health information management, compliance, privacy, security, legal counsel, finance, human resources, information technology and operational leadership should participate according to the record category involved.

The program should define ownership, retention periods, storage standards, access, preservation, destruction and evidence requirements.

Records management should apply to electronic, paper, audio, video and other information formats.

Records Inventory

The organization should maintain an inventory of material record categories.

The inventory should include medical records, operative reports, imaging, procedure histories, authorization files, claims, remittance information, coding audits, refund records, contracts, credentialing files, personnel records, compliance investigations, privacy incidents, security logs, meeting minutes, financial records, policies, training documentation and vendor records.

The inventory should identify where each record is stored, who owns it, who may access it, how long it must be retained and how destruction is approved.

Information stored outside the official system should also be considered, including email, shared drives, local devices, messaging platforms and vendor hosted environments.

Retention Schedule

The organization should maintain a written retention schedule based on applicable federal law, state law, payer requirements, contractual obligations, accreditation standards, statutes of limitation and business needs.

The schedule should identify the triggering event from which the retention period is calculated.

The trigger may be the date of service, final payment, contract termination, employee separation, policy retirement, investigation closure or another defined event.

Retention periods should not be copied from another organization without evaluating jurisdiction, provider type, patient population, service line and payer participation.

HIPAA Retention Distinction

HIPAA does not establish a universal medical record retention period.

HHS states that state laws generally govern how long medical records must be retained. HIPAA does, however, require certain privacy policies, notices, complaints, actions and designations to be documented and maintained for six years after the later of creation or last effective date.

The organization should not state broadly that HIPAA requires all medical records to be retained for six years.

Medical record retention and HIPAA compliance documentation retention are related but distinct requirements.

Medicare Documentation Requirements

Certain Medicare requirements may establish record maintenance and access obligations for specific services or provider relationships.

CMS guidance concerning records supporting ordered or referred services states that applicable records must be maintained for seven years from the date of service and must be provided when CMS or a Medicare contractor requests access.

The organization should identify which CMS retention requirement applies to each provider type, item, service and record category rather than applying one period universally.

State Law Variation

Medical record retention requirements vary by state and may differ for adults, minors, deceased patients, hospitals, ASCs and professional practices.

Organizations operating in several states should maintain jurisdiction specific requirements.

When several requirements apply to the same record, the organization should determine which period controls.

Legal counsel should review conflicts, unclear requirements and record categories involving significant exposure.

Payer and Contractual Requirements

Payer contracts may require records to be retained for defined periods and made available for audit.

Government managed care agreements and delegated arrangements may impose longer retention obligations than the organization’s routine policy.

Vendor contracts should require subcontractors to retain relevant records for the period necessary to support the organization’s obligations.

Contract termination should not eliminate access to records that may later be required for audit, appeal, repayment or litigation.

Medical Record Integrity

Medical records should remain complete, accurate, retrievable and protected throughout the retention period.

The organization should preserve audit trails, amendments, signatures, attachments and metadata necessary to understand the record.

A system conversion should not eliminate access to historical notes, images, author information or change history.

The organization should test whether archived records remain readable and can be produced within expected timeframes.

Financial and Revenue Cycle Records

Financial retention should include claims, remittance advice, payment posting, adjustment records, refunds, credit balances, authorizations, appeal submissions, payer correspondence and supporting documentation.

The organization should be able to reconstruct how a claim was created, submitted, adjudicated, adjusted and resolved.

Records supporting overpayment analysis and repayment should be preserved according to the applicable retention and legal requirements.

Compliance Records

Compliance records may include risk assessments, work plans, audits, investigations, hotline reports, corrective action plans, board reports, policy approvals and training records.

Access should be restricted according to sensitivity.

The retention schedule should distinguish routine compliance documentation from materials preserved under legal privilege, litigation hold or regulatory requirement.

The organization should not delete compliance records simply because the matter was closed.

Security Logs and Audit Trails

System logs should be retained long enough to support security investigation, privacy review, compliance monitoring and legal response.

The appropriate period will depend on system capability, risk, regulatory obligations and incident detection needs.

The organization should know whether vendors retain access logs, how quickly logs are overwritten and whether historical logs can be exported.

A security investigation may fail when relevant logs were deleted before the incident was discovered.

Email and Electronic Communications

Email, text messages and collaboration platforms may contain business, clinical, contracting, compliance or legal records.

Retention should be based on content rather than the communication platform alone.

Employees should not use personal email or unapproved messaging applications to avoid organizational recordkeeping.

The organization should establish rules for transferring material information from temporary communication channels into the official record when appropriate.

Artificial Intelligence Records

Records involving artificial intelligence may include prompts, outputs, validation results, model versions, user approvals, corrections, performance reports and vendor documentation.

The organization should determine which AI records are necessary to demonstrate clinical review, administrative decision making, security compliance and governance.

AI generated information incorporated into the medical or business record should follow the retention requirements applicable to that record.

The organization should not assume that a vendor will preserve prompts or outputs indefinitely.

Secure Storage

Records should be stored in environments appropriate to their sensitivity and required accessibility.

Controls should address encryption, physical protection, backup, redundancy, role based access, monitoring and disaster recovery.

Archived records should remain protected even when they are no longer used routinely.

Moving records to low cost storage does not eliminate privacy and security obligations.

Secure Destruction

Records should be destroyed in a manner that prevents reconstruction or unauthorized access.

Paper containing protected information should be shredded, pulverized or otherwise rendered unreadable.

Electronic information should be cleared, purged or destroyed according to appropriate technical standards and device capability.

HHS states that protected information must remain safeguarded for as long as the organization maintains it, including during disposal.

Destruction Authorization

Routine destruction should occur only through an approved process.

The organization should document the record category, date range, authority, method, vendor and date of destruction.

Employees should not delete records independently because storage is inconvenient or because the information appears outdated.

Destruction vendors should be evaluated, contracted and monitored as appropriate.

Certificates of destruction should be retained when used.

Legal Holds

A legal hold suspends routine destruction when records may be relevant to litigation, an audit, investigation, subpoena, government inquiry, payer dispute or reasonably anticipated claim.

The hold should identify the subject matter, affected custodians, systems, record categories and preservation requirements.

Legal holds should be issued promptly and acknowledged by affected individuals.

Routine deletion, recycling and automatic overwriting should be suspended for the relevant information.

Legal Hold Governance

Qualified legal or designated compliance leadership should approve issuance, modification and release of a legal hold.

The organization should track recipients, acknowledgments, preservation activity, system changes and periodic reminders.

A hold should remain active until formally released.

Employees should not determine independently that a matter is over or that records are no longer relevant.

Vendor Preservation

Vendors should be capable of preserving and producing records subject to legal hold.

Contracts should address data ownership, export, retention, preservation, return and destruction.

When a vendor relationship ends, the organization should retrieve necessary records and confirm how remaining copies will be handled.

The organization should not discover during an audit that a former vendor controls the only copy of a material record.

System Conversion and Data Migration

System conversion should include a documented record preservation plan.

The organization should determine which data will be migrated, archived, converted or maintained in read only form.

Validation should confirm that patient identity, dates, signatures, images, attachments and audit trails remain accurate.

Legacy systems should not be decommissioned until required information can be retrieved reliably from the replacement or archive.

Retention Monitoring

The organization should audit its retention process periodically.

Testing should determine whether records are stored for the required period, retrievable, protected from unauthorized access and destroyed only with approval.

The organization should assess whether departments maintain unauthorized local archives or dispose of records outside approved processes.

Application to MSK Specialty Care

MSK records frequently require longitudinal evidence.

A repeat procedure may depend on documentation from prior years showing dates, anatomical levels, laterality, percentage of relief, duration of relief and functional improvement.

Premature destruction or inaccessible legacy records can prevent the organization from establishing medical necessity, procedure eligibility and audit defense.

Implant records, device information, operative reports and facility documentation may also be required long after the immediate billing cycle ends.

GoHealthcare Insights

Record retention should be designed around the complete life of the patient, claim, contract and regulatory obligation.

A record has little compliance value when it technically exists but cannot be retrieved, interpreted or connected to the relevant service.

Leadership Perspective

Retention creates cost, but uncontrolled deletion creates significantly greater exposure.

Leadership should fund records governance as an operational capability rather than treating storage and retrieval as administrative housekeeping.

Key Takeaways

The organization needs a record specific retention schedule based on applicable requirements.

HIPAA does not establish a universal medical record retention period.

Legal holds must suspend routine destruction and apply to internal systems, communications and vendor controlled records.

Back to framework navigation
28

Third Party, Vendor and Business Associate Compliance

Purpose

Third Party, Vendor and Business Associate Compliance establishes how the organization evaluates, contracts with, supervises and, when necessary, terminates outside parties performing functions on its behalf.

Third parties can create clinical, privacy, security, billing, financial, workforce, operational and reputational exposure.

Outsourcing work does not outsource organizational accountability.

A vendor may perform prior authorization, coding, billing, cybersecurity, cloud storage, artificial intelligence, transcription, credentialing, collections, patient communication, analytics or clinical support. Each relationship requires oversight proportionate to its risk.

Third Party Governance

The organization should maintain a centralized vendor governance structure.

Procurement, operations, compliance, privacy, security, finance, legal counsel and information technology should participate according to the service involved.

The governance structure should define who may select a vendor, approve data access, negotiate terms, evaluate risk, monitor performance, issue corrective action and terminate the relationship.

Departments should not purchase or activate technology independently when the product will access patient, employee, financial or organizational information.

Vendor Inventory

The organization should maintain a complete inventory of vendors and contractors.

The inventory should identify the vendor, service, accountable owner, contract term, data accessed, systems connected, business associate status, subcontractors, geographic location, security review, insurance, performance standards and termination requirements.

The organization should identify shadow vendors acquired through individual departments, credit card purchases or trial subscriptions.

Uninventoried vendors create unmanaged data and compliance risk.

Risk Classification

Vendors should be classified according to the potential impact of failure.

A high risk vendor may access large quantities of protected information, submit claims, make authorization decisions, support patient care, operate critical infrastructure or control essential records.

Moderate and lower risk vendors may require less intensive oversight, but classification should be documented.

Risk should consider data sensitivity, operational dependence, financial authority, patient impact, subcontracting, offshore access and system connectivity.

Due Diligence

Due diligence should occur before the contract is signed or access is granted.

The organization should evaluate ownership, financial stability, qualifications, regulatory history, references, insurance, cybersecurity, privacy practices, staffing, business continuity, performance history and use of subcontractors.

Claims concerning HIPAA compliance, artificial intelligence accuracy or cybersecurity certification should be validated rather than accepted without evidence.

A vendor questionnaire alone is not sufficient for every high risk relationship.

Business Associate Determination

The organization should determine whether the vendor is a business associate based on the services performed and access to protected health information.

A vendor’s marketing description or refusal to sign a business associate agreement does not determine legal status.

The actual relationship and data use control the analysis.

HHS explains that business associates perform certain functions or services involving protected health information on behalf of covered entities and that appropriate business associate agreements are required when applicable.

Business Associate Agreement

The Business Associate Agreement should define permitted uses and disclosures, safeguards, incident reporting, subcontractor obligations, patient rights support, access to records, return or destruction of information and termination responsibilities.

The agreement should align with the underlying service contract.

Conflicting provisions between the Business Associate Agreement and master services agreement should be resolved before execution.

HHS provides sample Business Associate Agreement provisions but notes that those provisions alone may not satisfy all state law or contractual requirements.

Data Use Restrictions

The contract should identify what information the vendor may access, why access is necessary and whether information may be stored, copied, analyzed or used for product development.

The vendor should not use organizational or patient data for unrelated analytics, advertising or model training without appropriate authority.

The organization should understand whether the vendor aggregates data, creates deidentified data or derives commercial products from information provided by clients.

These rights should be addressed explicitly rather than assumed.

Subcontractors

Vendors should disclose subcontractors that access protected information or perform material services.

The organization should understand where subcontractors operate, what data they receive and how the primary vendor supervises them.

Business associates are responsible for ensuring that applicable restrictions and protections extend to subcontractors.

The organization should require notification before material subcontractor changes when risk warrants it.

Offshore Operations

Offshore access requires specific evaluation of privacy, security, supervision, business continuity and contractual enforceability.

The organization should know which countries are involved, whether data are downloaded locally, whether printing is permitted and how devices and workspaces are controlled.

Offshore status does not automatically make a relationship inappropriate.

It does require transparent governance and controls equivalent to the sensitivity of the work.

Cybersecurity Assessment

High risk vendors should undergo a security assessment before connection to organizational systems.

The review may include risk analysis, penetration testing, vulnerability management, encryption, multifactor authentication, logging, backup, incident response, business continuity and cyber insurance.

Security certifications may provide useful information but should not replace evaluation of the actual service and control environment.

The contract should require remediation of material weaknesses and notification of security events.

Artificial Intelligence Vendors

Artificial intelligence vendors require additional review.

The organization should evaluate training data, intended use, output reliability, human oversight, bias, privacy, security, model updates, data retention, subcontractors and performance monitoring.

The vendor should identify whether patient or organizational data are used to train or improve the model.

The organization should retain authority to suspend the system when performance, privacy or safety concerns arise.

Billing and Coding Vendors

Billing and coding contracts should define code assignment authority, claim release controls, documentation standards, payer requirements, refund support, data access, audit rights and error correction.

Compensation should not encourage aggressive or unsupported billing.

The organization should receive data necessary to monitor denials, overrides, adjustments, corrected claims and overpayments.

The vendor should report material errors promptly rather than waiting for the organization to identify them independently.

Prior Authorization Vendors

Prior authorization vendors should be evaluated for clinical competency, payer routing, documentation review, submission integrity, status follow up and escalation.

Performance should not be measured only by approval rate.

The organization should assess whether requests were sent to the correct entity, supported by the record, completed timely and matched the service performed.

Vendor personnel should not alter or exaggerate clinical information to obtain approval.

Service Level Agreements

Service Level Agreements should establish measurable expectations.

Measures may include turnaround time, accuracy, system availability, response time, backlog, security reporting, record retrieval and corrective action.

The agreement should identify how performance is calculated, what data support the measure and what happens when performance fails.

Service credits may address financial inconvenience but do not replace correction of compliance or patient safety failures.

Audit Rights

Contracts should provide meaningful audit rights.

The organization should be able to review performance, security controls, data handling, subcontractors, claims activity, access logs and compliance records appropriate to the service.

Audit provisions should address notice, frequency, confidentiality, remediation and access to evidence.

A right that can be exercised only under impractical conditions may provide little actual protection.

Incident Reporting

Vendors should report security, privacy, billing, patient safety and compliance incidents promptly.

The contract should define what constitutes a reportable event and who must be contacted.

The vendor should cooperate with investigation, evidence preservation, notification and corrective action.

HHS states that when a covered entity knows of a material business associate breach or violation, it must take reasonable steps to cure or end the violation and take further action when those steps are unsuccessful.

Performance Monitoring

Vendor monitoring should continue throughout the relationship.

The accountable business owner should review performance, complaints, incidents, audit results, staffing changes, subcontractors and financial stability.

High risk vendors should be reviewed more frequently.

Contract renewal should not occur automatically when material issues remain unresolved.

Corrective Action

Vendor deficiencies should result in documented corrective action.

The plan should identify the requirement, finding, root cause, remediation, owner, due date and evidence of completion.

The organization should validate that the correction worked.

Repeated failure should trigger escalation, restriction of access, contractual remedies or termination.

Termination and Transition

Termination planning should begin before the relationship ends.

The organization should identify how records, credentials, interfaces, patient communications, open claims, authorizations and system access will be transferred.

Access should be removed promptly.

Protected information should be returned or destroyed when required and feasible.

HHS explains that business associate agreements generally require return or destruction of protected information upon termination when feasible.

Concentration Risk

The organization should understand its dependence on critical vendors.

A single vendor may support the EHR, claims, authorization, cloud storage or communications across several entities.

Leadership should evaluate the operational effect if the vendor becomes unavailable, suffers a breach, changes ownership or terminates service.

Contingency planning should include alternative processes and access to organizational data.

Application to MSK Specialty Care

MSK organizations often rely on device companies, billing vendors, prior authorization organizations, ASCs, imaging facilities, technology platforms and remote teams.

These vendors may influence clinical scheduling, implant selection, claim submission, patient communication and access to longitudinal records.

Vendor oversight should therefore connect compliance, patient safety, revenue integrity and operational continuity.

GoHealthcare Insights

The strongest vendor contract cannot compensate for weak oversight.

Organizations must know what vendors are doing, what information they access, how performance is measured and what evidence exists that required controls are functioning.

Leadership Perspective

Vendor convenience should not override transparency.

A vendor that refuses appropriate security review, audit rights, data use restrictions or incident reporting requirements may create more risk than value.

Key Takeaways

Every material vendor should be inventoried, risk classified and assigned to an accountable owner.

Business Associate Agreements should reflect the actual service and data relationship.

Vendor performance, security, subcontractors, artificial intelligence use and incident response require continuing oversight.

Back to framework navigation
29

Workforce, Employment and Labor Compliance

Purpose

Workforce, Employment and Labor Compliance establishes the controls required to manage hiring, classification, compensation, workplace conduct, accommodation, leave, performance, discipline and separation in accordance with applicable federal, state and local requirements.

Healthcare workforce compliance is connected directly to patient safety, privacy, operational capacity and regulatory integrity.

Employees, physicians, contractors, remote teams and managers must be selected, trained, supervised and held accountable according to clearly defined standards.

Workforce Governance

The organization should assign responsibility for employment compliance among human resources, executive leadership, compliance, legal counsel, payroll, finance and operational management.

Human resources should not operate independently when a workforce issue also involves patient safety, billing, privacy, retaliation, licensure or professional conduct.

The organization should maintain consistent policies while accounting for jurisdiction specific requirements.

Multistate organizations should not assume that one employee handbook satisfies every state and local obligation.

Workforce Classification

The organization should evaluate whether workers are properly classified as employees or independent contractors under applicable federal and state standards.

A contract labeling a person as an independent contractor does not determine legal status by itself.

The actual economic and working relationship must be evaluated.

The Department of Labor states that employee misclassification occurs when a worker who is an employee under the Fair Labor Standards Act is treated as an independent contractor. The federal classification framework has also been subject to continuing rulemaking, so organizations should verify the current standard and applicable state requirements before making classification decisions.

Job Descriptions

Every role should have a current job description identifying responsibilities, qualifications, supervision, physical requirements, access authority and compliance obligations.

Job descriptions should reflect actual work.

A title should not be used to classify a worker as exempt from wage requirements when the employee’s duties do not support the classification.

Clinical roles should identify required licensure, certification and scope of practice.

Hiring and Background Review

The hiring process should verify identity, education, experience, references, required credentials and legal eligibility to work.

Background review should be appropriate to the role and consistent with applicable law.

Positions involving patient care, controlled substances, finances, information systems or protected health information may require additional screening.

Hiring decisions should be documented and applied consistently.

Equal Employment Opportunity

Employment decisions should not be based on prohibited discrimination.

The organization should maintain policies addressing recruitment, hiring, compensation, promotion, assignment, discipline, termination and workplace conditions.

Managers should receive practical training on lawful decision making and documentation.

Complaint procedures should be accessible and protect individuals from retaliation.

Harassment and Workplace Conduct

Harassment, intimidation, bullying, retaliation, violence and disruptive behavior should be prohibited.

Standards should apply equally to employees, physicians, executives, owners, vendors and patients interacting with the workforce.

High revenue contribution or professional status should not excuse abusive or discriminatory behavior.

Complaints should be investigated promptly and objectively.

Reasonable Accommodation

The organization should maintain a process for receiving and evaluating requests for reasonable accommodation.

The process should involve a timely, individualized and interactive assessment.

Medical information should be limited to what is necessary and stored confidentially.

The Equal Employment Opportunity Commission explains that covered employers must provide reasonable accommodation to qualified individuals with disabilities unless the accommodation would cause undue hardship.

Pregnancy Related Accommodation

The organization should address accommodation requests connected to pregnancy, childbirth and related medical conditions under applicable requirements.

Managers should know how to route requests and should not deny them informally.

The Equal Employment Opportunity Commission states that the Pregnant Workers Fairness Act requires covered employers to provide reasonable accommodation to qualified employees or applicants with known pregnancy related limitations unless the accommodation creates undue hardship.

Wage and Hour Compliance

The organization should comply with applicable minimum wage, overtime, recordkeeping, break and timekeeping requirements.

Employees should record all time worked.

Managers should not encourage off the clock work, unrecorded remote work or automatic deduction of breaks that were not taken.

Payroll corrections should be documented and completed promptly.

The Department of Labor maintains current Fair Labor Standards Act guidance concerning wages, hours and employer responsibilities.

Exempt and Nonexempt Status

Exempt classification should be based on current salary and duties requirements rather than job title.

Roles should be reviewed when responsibilities change.

Administrative healthcare positions are not automatically exempt merely because they involve specialized knowledge or office work.

The organization should obtain qualified advice for ambiguous roles and multistate workforce arrangements.

Timekeeping and Remote Work

Remote workers should follow the same timekeeping and authorization requirements as onsite personnel.

The organization should establish procedures for recording after hours work, responding to messages, system access and overtime approval.

Managers should not permit work they know is occurring and then refuse payment because it was not approved in advance.

Remote monitoring should be lawful, transparent and proportionate.

Leave Administration

Leave should be administered according to applicable federal, state and organizational requirements.

Managers should route requests to qualified personnel rather than making informal eligibility determinations.

The organization should coordinate leave, disability accommodation, workers compensation and other protections when more than one framework may apply.

Medical documentation should be stored separately and accessed only by authorized personnel.

Employee Medical Information

Employee medical information should be handled confidentially.

HIPAA generally excludes employment records maintained by a covered entity in its role as employer, but other laws may govern confidentiality and permitted use.

The Equal Employment Opportunity Commission states that employee medical information must be treated as confidential under the Americans with Disabilities Act.

Remote and Global Workforce

Remote and global workforce models require clear employer, contractor, tax, immigration, privacy, security and supervision analysis.

The organization should know which legal entity employs or contracts with each worker and which jurisdiction’s requirements apply.

Global personnel should receive role specific compliance education and secure system access.

The organization should not use offshore arrangements to avoid wage, privacy, licensure or workforce responsibilities.

Clinical Scope of Practice

Clinical personnel should perform only activities permitted by their licensure, certification, training and organizational authorization.

Delegation should follow applicable law and professional standards.

Administrative staff should not make clinical determinations merely because a workflow is standardized.

The organization should review scope when roles, technology or state operations change.

Productivity and Incentives

Productivity expectations should not encourage employees to bypass required documentation, privacy, authorization, coding or patient safety controls.

Incentive programs should be reviewed for unintended behavior.

An authorization team should not be rewarded solely for approval volume.

A billing team should not be rewarded solely for collections when aggressive claim submission or inappropriate adjustments could increase performance.

Performance Management

Performance standards should include quality, compliance, accuracy, professionalism and completion of required training.

Managers should document expectations, feedback, coaching and corrective action.

Performance processes should be applied consistently.

A legitimate performance process should not be used to conceal retaliation against an employee who reported a concern or requested protected accommodation.

Discipline

Discipline should be proportionate, documented and consistent.

Factors may include severity, intent, patient impact, prior conduct, cooperation, concealment and leadership responsibility.

Physicians, executives and high performers should be subject to the same fundamental standards.

Human resources, compliance and legal counsel should coordinate when conduct involves privacy, billing, patient safety, harassment, retaliation or professional licensure.

Workforce Investigations

Employment investigations should be objective and appropriately separated from compliance, clinical peer review and legal processes.

The organization should determine which function leads and how information is shared.

Witnesses should be protected from retaliation.

Investigation records should be stored securely and retained according to the applicable schedule.

Separation and Offboarding

Offboarding should address final pay, benefits, property return, confidentiality, system access, records, patient responsibilities and vendor credentials.

System and facility access should be terminated promptly.

Departing employees should not retain patient records, data exports, passwords or organizational documents.

Exit interviews may identify compliance, management and operational risks that were not previously reported.

Employment Law Monitoring

Employment requirements change over time and vary by jurisdiction.

The organization should monitor federal, state and local developments involving classification, wages, leave, accommodation, privacy and workplace protections.

Policies should be reviewed before expansion into a new state or engagement of a new workforce model.

Application to MSK Specialty Care

MSK practices depend on clinical and administrative personnel performing specialized functions.

Medical assistants, nurses, authorization specialists, coders, surgical coordinators and remote teams may influence patient selection, procedure readiness, protected information and claim integrity.

Workforce compliance should therefore be integrated with credentialing, training, supervision and workflow accountability.

GoHealthcare Insights

Many compliance failures that appear to be individual errors are workforce design failures.

Unclear roles, inadequate training, excessive workload, poor supervision and conflicting incentives can make correct performance difficult.

Leadership Perspective

A compliant workforce model should be scalable without weakening accountability.

Growth should not depend on ambiguous classification, uncontrolled remote access, insufficient supervision or individuals working beyond their authorized role.

Key Takeaways

Workforce compliance requires accurate classification, lawful compensation, consistent conduct standards and reliable accommodation processes.

Clinical personnel must remain within scope, and administrative personnel must not assume clinical authority.

Remote, outsourced and global workforces require the same governance discipline as onsite personnel.

Back to framework navigation
30

Credentialing, Enrollment, Licensure and Exclusion Screening

Purpose

Credentialing, Enrollment, Licensure and Exclusion Screening ensure that every professional and entity providing, ordering, supervising, billing or supporting healthcare services possesses the required qualifications and remains authorized to perform the assigned role.

These functions are related but distinct.

Licensure establishes legal authority to practice under state law.

Credentialing evaluates qualifications and professional history.

Privileging authorizes specific clinical activities within an organization or facility.

Payer enrollment establishes eligibility to bill or participate in a payment program.

Exclusion screening identifies individuals or entities prohibited from participation in federal or other healthcare programs.

Completion of one function does not establish completion of the others.

Governance

The organization should establish centralized oversight with defined responsibility among credentialing, medical staff services, compliance, human resources, payer enrollment, clinical leadership and revenue cycle management.

The process should identify who collects information, performs primary source verification, evaluates concerns, approves appointments, grants privileges, submits payer applications, monitors expirations and suspends activity.

Decisions should be documented and protected from improper financial or operational pressure.

A provider should not begin working merely because patient demand is high or payer enrollment is expected soon.

Provider Inventory

The organization should maintain a complete provider inventory.

The inventory should include physicians, advanced practice providers, therapists, nurses, technicians and other credentialed professionals as applicable.

For each individual, the organization should track legal name, identifiers, specialty, location, employment status, licensure, certification, privileges, payer participation, enrollment, reassignment, exclusion screening and renewal dates.

Changes should be communicated promptly to scheduling, billing, information technology and facility leadership.

Primary Source Verification

Credentials should be verified through authoritative sources rather than accepted solely from copies supplied by the applicant.

Verification may include professional licensure, education, training, board certification, controlled substance authority, malpractice history and other required qualifications.

The organization should document the source, date, result and reviewer.

Expired or restricted credentials should trigger immediate review.

Licensure

Providers should maintain active and appropriate licensure in every jurisdiction where professional practice requires it.

The organization should monitor expiration dates, restrictions, disciplinary actions and conditions.

Telehealth, remote supervision and multistate care may create licensure requirements based on the patient’s location and applicable law.

Administrative systems should prevent scheduling or billing under a provider whose authority has expired or been restricted.

Scope of Practice

Licensure does not authorize every possible activity.

The organization should evaluate scope of practice, training, competency, supervision and organizational policy.

Advanced practice providers and other clinicians should work within applicable state and organizational requirements.

Changes in delegation or service line should receive formal review before implementation.

Credentialing Application

The credentialing application should collect complete professional history, education, training, licenses, certifications, affiliations, malpractice claims, disciplinary actions, criminal matters, exclusions and other required disclosures.

Gaps and inconsistencies should be investigated.

Failure to disclose material information should be treated as a credentialing and compliance concern.

The applicant should attest to accuracy and authorize verification.

National Practitioner Data Bank

Eligible healthcare organizations may use the National Practitioner Data Bank as part of credentialing and professional review.

The NPDB is a confidential information clearinghouse that contains certain malpractice payments, licensure actions, adverse clinical privilege actions, exclusions and other reportable information.

Hospitals have specific federal querying obligations for medical staff appointment and clinical privileges, including recurring queries.

An NPDB report should be evaluated in context. The existence of a report does not automatically determine the credentialing outcome, and absence of a report does not replace other verification.

Privileging

Clinical privileges should identify the procedures and services the professional is authorized to perform within the organization or facility.

Privileges should reflect education, training, experience, competency and facility capability.

A general specialty appointment should not automatically authorize every advanced procedure.

Neuromodulation, complex spine procedures, implantable devices and advanced interventions may require procedure specific criteria and focused review.

Initial Appointment and Reappointment

Credentialing and privileging should occur before initial appointment and at defined reappointment intervals.

The organization should review quality, complaints, malpractice, utilization, peer review, licensure, exclusion status and professional conduct.

Reappointment should not be treated as an automatic administrative renewal.

Changes in health, competency, disciplinary history or practice scope should be evaluated.

Focused and Ongoing Professional Practice Evaluation

Facilities and organizations should maintain processes appropriate to their accreditation and governance requirements for evaluating professional performance.

New privileges, significant concerns, unusual outcomes or changes in practice may require focused evaluation.

Ongoing review should use relevant quality, utilization, complaint and peer information.

Professional review should be clinically credible and protected according to applicable law.

Medicare Enrollment

Medicare enrollment should be completed and maintained through the applicable CMS process.

PECOS is the CMS online system for Medicare provider and supplier enrollment and allows organizations to enroll, review existing information, upload documents and submit changes.

The organization should verify that individual providers, groups, locations, reassignment relationships and ownership information are accurate.

Enrollment approval for one entity or location does not establish authority to bill through another.

Revalidation

Medicare providers and suppliers must revalidate periodically to maintain enrollment.

CMS states that providers and suppliers generally revalidate every five years, while durable medical equipment, prosthetics, orthotics and supplies suppliers generally revalidate every three years. CMS may also request off cycle revalidation.

The organization should monitor the official Medicare Revalidation List and should not submit an unnecessary revalidation before CMS establishes the applicable due date.

Enrollment Changes

Changes in ownership, managing employees, practice locations, banking, reassignment, adverse actions and other enrollment information may require reporting.

The organization should evaluate reporting deadlines before the change occurs.

Credentialing, legal, finance and operations should coordinate acquisitions, relocations, entity changes and provider departures.

Claims should not continue under outdated enrollment information because internal systems were not updated.

Commercial Payer Credentialing and Enrollment

Commercial payer credentialing and network participation should be tracked separately from Medicare enrollment.

The organization should confirm the provider, group, location, product and effective date.

A provider may be credentialed but not yet effective in the network.

Claims should not be submitted as participating until participation has been confirmed.

Provider directories should be reviewed for accuracy.

Medicaid Enrollment

Medicaid enrollment requirements vary by state and managed care arrangement.

The organization should identify state specific screening, ownership, disclosure, revalidation and billing requirements.

Participation with a Medicaid managed care plan may also require enrollment with the state Medicaid program.

Organizations operating in several states should maintain jurisdiction specific controls.

Facility Enrollment and Accreditation

ASCs and other facilities may require separate licensing, certification, accreditation, enrollment and payer contracting.

Professional provider enrollment does not authorize facility billing.

The organization should track the legal entity, facility location, certification, accreditation, ownership information and effective dates associated with each facility claim.

OIG Exclusion Screening

OIG maintains the List of Excluded Individuals and Entities for persons and organizations excluded from participation in federal healthcare programs.

OIG states that healthcare entities should routinely check the list when hiring and during continued employment or contracting because payment may be prohibited for items or services furnished, ordered or prescribed by excluded persons.

The screening process should include employees, providers, contractors, vendors, owners and other persons whose work could affect federal healthcare program items or services.

Screening Frequency

The organization should establish a documented screening frequency based on applicable requirements and risk.

OIG guidance addresses the scope and frequency of exclusion screening and provides downloadable data updated regularly.

Monthly screening is commonly used by healthcare organizations to identify exclusions promptly, but the organization should evaluate federal, state, payer and contractual requirements applicable to its operations.

Identity Verification

Potential exclusion matches should be verified carefully.

Names alone may produce false matches.

The organization should compare available identifiers such as date of birth, address, professional license and Social Security number when permitted.

A potential match should be escalated without assuming either that the person is excluded or that the result can be ignored.

Verification steps and conclusions should be documented.

State and Federal Screening Sources

The organization should determine which federal and state databases must be screened.

Sources may include the OIG LEIE, SAM.gov, state Medicaid exclusion lists, licensing boards and other required databases.

SAM.gov is the official federal system containing entity registration and exclusion information.

One database should not be assumed to contain every relevant sanction, exclusion or licensing action.

Response to an Exclusion

A confirmed exclusion should trigger immediate compliance and legal review.

The organization should determine the effective date, services affected, claims, payments, employment or contract status and required notifications.

System access and work assignments may need to be restricted immediately.

The review should extend beyond services personally performed because exclusion can affect items or services furnished, ordered or prescribed by the excluded person.

Credentialing Vendors

Credentialing and enrollment functions may be outsourced, but accountability remains with the organization.

The contract should define verification sources, application accuracy, due dates, exclusion screening, data security, reporting, audit rights and termination support.

The organization should have access to application status, submitted documents, correspondence and approvals.

Vendor delay should not be discovered only when claims deny or a license expires.

Credentialing and Billing Integration

Credentialing information should be connected to scheduling, authorization, coding and billing systems.

The organization should know when each provider may begin seeing patients, performing procedures and billing each payer.

Effective dates should be entered accurately.

Claims should not be held indefinitely or submitted under another provider merely because enrollment remains incomplete.

Credentialing Dashboards

Leadership should monitor applications, reappointments, license expirations, payer effective dates, revalidations, exclusion screening, incomplete files and unresolved adverse information.

Dashboards should identify cases approaching expiration and assign accountable owners.

A credentialing file should not be considered complete until the final approval and effective date have been confirmed.

Application to MSK Specialty Care

MSK organizations frequently add physicians, advanced practice providers, ASCs and new procedure locations.

Providers may require specific privileges for injections, radiofrequency ablation, spinal cord stimulation, peripheral nerve stimulation, spine surgery and implantable devices.

Credentialing should verify that qualifications, privileges, enrollment and authorization all align before services begin.

GoHealthcare Insights

Credentialing and enrollment failures create patient access, compliance and revenue consequences simultaneously.

A qualified physician may be licensed and clinically competent but still unable to bill a payer or perform a procedure at a particular facility.

The organization must manage every authorization layer separately and connect them operationally.

Leadership Perspective

Provider growth should be governed by readiness, not projected revenue.

Scheduling patients before licensure, privileges, enrollment and payer status are complete shifts the financial and compliance risk to the organization and the patient.

Key Takeaways

Licensure, credentialing, privileging, payer enrollment and exclusion screening are separate controls.

Every provider and entity should be tracked through initial approval, renewal, revalidation and termination.

Exclusion screening must include relevant employees, contractors, vendors and entities, with documented verification and escalation.

Back to framework navigation
31

Clinical Risk Management and Patient Safety

Purpose

Clinical Risk Management and Patient Safety establish the governance, reporting systems, clinical controls and organizational learning processes required to prevent avoidable harm, identify unsafe conditions, respond appropriately to adverse events and strengthen the reliability of patient care.

Clinical risk management should not operate only after a serious event occurs. It should function prospectively by identifying hazards within patient selection, medication management, procedural preparation, clinical documentation, informed consent, infection prevention, equipment use, communication, discharge and follow up.

Patient safety is an enterprise responsibility involving the governing body, physicians, advanced practice providers, nurses, clinical support personnel, operations, quality, compliance, risk management, pharmacy, information technology and external clinical partners.

The Agency for Healthcare Research and Quality describes event reporting, investigation, communication, remediation, data tracking and system improvement as connected components of an effective patient safety response.

Clinical Risk Governance

The organization should establish a formal Clinical Risk and Patient Safety Program approved by the governing body.

The program should define leadership authority, reporting relationships, event classification, escalation criteria, investigation responsibilities, patient communication, corrective action, quality improvement and governing body reporting.

A qualified clinical leader should oversee the program in coordination with compliance, quality, operations and risk management.

The governance structure should identify who may suspend a procedure, remove equipment from service, restrict clinical privileges, initiate emergency transfer, retain external clinical expertise or report an event to a licensing, accreditation or government authority.

Financial performance, physician influence, scheduling pressure or concern about reputation should not delay patient protection or event escalation.

Culture of Safety

A culture of safety encourages clinicians and workforce members to identify risks, report near misses and raise concerns without fear of inappropriate punishment.

Leadership should distinguish human error, unsafe system design, reckless behavior and intentional misconduct.

Not every error warrants discipline. Some events reveal poorly designed workflows, ambiguous responsibilities, excessive workload, inadequate staffing, defective technology or missing safeguards.

A fair accountability model does not eliminate individual responsibility. It evaluates behavior within the context of the system in which the behavior occurred.

Employees should know that reporting a near miss is valuable even when the patient was not harmed. Near misses frequently identify weaknesses before a more serious event occurs.

AHRQ provides patient safety culture surveys for medical offices and ambulatory surgery centers that organizations may use to assess whether personnel feel supported in reporting and improving safety.

Clinical Risk Inventory

The organization should maintain an inventory of material clinical risks.

The inventory should include patient identification, diagnostic error, delayed treatment, medication error, controlled substance management, infection, falls, procedural complications, wrong site risk, anesthesia events, adverse reactions, device malfunction, incomplete consent, emergency response, discharge failure and communication breakdown.

Risks should be evaluated by specialty, procedure, setting and patient population.

An interventional pain practice may have different risk exposure from an orthopedic surgical practice, neuromodulation program or ambulatory surgery center.

Risk assessment should consider likelihood, potential severity, existing controls, detectability and ability to respond before patient harm occurs.

Patient Safety Event Definitions

The organization should establish consistent definitions for patient safety events.

An adverse event is an incident associated with patient harm.

A near miss is an event that could have caused harm but did not, whether because of timely intervention, chance or another protective factor.

An unsafe condition is a circumstance that increases the probability of an event even when no specific patient was affected.

A sentinel or serious event may require immediate executive, accreditation, regulatory or legal review depending on applicable definitions and requirements.

Consistent terminology supports accurate reporting, investigation and trend analysis.

Event Reporting System

The organization should maintain an accessible patient safety reporting system.

Reports should capture the patient, location, date, event type, immediate response, individuals involved, known clinical consequences and any continuing risk.

The system should permit confidential reporting and should be available to employees, physicians, contractors and other personnel involved in care.

Event reporting should be simple enough that staff can complete it without creating unnecessary delay during patient care.

A report should document what was observed without requiring the reporter to determine fault or legal liability.

Patient safety event reporting systems are most effective when reports are combined with investigation, clinical data, complaints, claims information and other sources rather than treated as the organization’s only method of detecting harm.

Immediate Clinical Response

The first priority following a clinical event is patient protection.

The organization should assess the patient, stabilize the condition, obtain appropriate clinical assistance, initiate emergency response and arrange transfer when required.

Necessary care should not be delayed while personnel complete an incident report or determine administrative responsibility.

The clinical record should document the patient’s condition, assessment, treatment and disposition.

The incident report should remain separate from the medical record unless organizational policy or applicable law requires otherwise.

Immediate response should also include protecting other patients when the event involves defective equipment, contaminated supplies, medication errors, unsafe staffing or a system failure that could affect additional cases.

Event Escalation

The organization should define events requiring immediate escalation.

These may include death, serious injury, wrong patient or wrong site events, retained foreign objects, medication overdose, uncontrolled bleeding, significant anesthesia complications, suspected abuse, controlled substance diversion, serious infection, equipment failure, unauthorized treatment and delayed emergency transfer.

Escalation should identify the clinical leader, administrator, compliance officer, risk leader and legal counsel who must be notified.

The organization should not wait for a complete investigation before notifying appropriate leadership of a potentially serious event.

Evidence Preservation

Clinical events may require preservation of records, equipment, medications, devices, video, system logs, photographs, staffing records and communications.

The organization should identify who has authority to secure materials and restrict access.

Equipment associated with an event should not be returned to service until appropriately evaluated.

Medical records should not be altered to improve the appearance of care after an event.

Legitimate corrections, addenda and late entries should follow approved documentation standards and preserve the original record.

Event Investigation

The investigation should determine what occurred, why it occurred, what controls failed and whether other patients may be affected.

The review should examine the complete care pathway rather than focus only on the individual closest to the event.

Relevant factors may include scheduling, patient identification, orders, clinical documentation, medication reconciliation, procedure preparation, staffing, competency, equipment, communication, supervision and technology.

The investigation should distinguish facts, clinical judgments, disputed information and unresolved questions.

Root Cause and Systems Analysis

Serious or recurring events should receive structured root cause or systems analysis.

The analysis should examine underlying conditions rather than stopping with a statement that an employee failed to follow policy.

Leadership should ask why the error was possible, why the control did not prevent it, why the issue was not detected earlier and whether similar exposure exists elsewhere.

A corrective action that depends only on staff remembering to be more careful is generally weaker than a control built into equipment, technology, workflow or required verification.

Near Miss Review

Near misses should receive proportionate review because they provide evidence of vulnerability without the consequence of actual harm.

Examples include identifying the wrong procedure before sedation, discovering an incorrect medication before administration, recognizing a missing authorization before the procedure or detecting an incomplete implant record before claim submission.

Near miss reporting should be encouraged and recognized as a contribution to patient safety.

Trend analysis should determine whether similar near misses occur repeatedly in the same workflow.

Informed Consent

Informed consent should be obtained according to applicable law, organizational policy and professional standards.

The patient should receive understandable information concerning the nature of the procedure, material risks, expected benefits, alternatives and the consequences of declining treatment.

The clinician responsible for the procedure should address clinical questions.

A signed form alone does not establish that meaningful informed consent occurred.

Consent should be obtained before sedation or other circumstances that impair the patient’s ability to make an informed decision.

Material changes to the planned procedure may require updated consent.

Patient Identification and Procedure Verification

The organization should use reliable methods to verify the correct patient, procedure, anatomical location, laterality, level, implant and site of service.

Verification should occur at defined points in the workflow.

The order, authorization, schedule, consent, clinical record, procedure documentation and claim should remain consistent.

Discrepancies should be resolved before the procedure begins whenever clinically possible.

The final procedural pause should involve the individuals responsible for performing and supporting the service.

Medication Safety

Medication safety should address prescribing, ordering, preparation, administration, storage, labeling, reconciliation, monitoring and disposal.

The organization should define controls for high risk medications, controlled substances, anticoagulants, sedatives, contrast agents, local anesthetics, antibiotics and emergency medications.

Medication allergies and relevant current medications should be confirmed before the procedure.

Verbal orders should be limited and documented according to policy.

Look alike and sound alike medications should be stored and labeled to reduce selection error.

Infection Prevention

Clinical risk management should include a comprehensive infection prevention program appropriate to the services and setting.

Controls should address hand hygiene, injection safety, medication preparation, environmental cleaning, sterilization, disinfection, personal protective equipment, single use items, multidose containers, device processing and surveillance.

Infection concerns should be escalated promptly.

The organization should identify whether an incident could affect additional patients and whether notification, testing, reporting or expanded review is required.

AHRQ provides a safety toolkit specifically designed to help ambulatory surgery centers strengthen safety culture and reduce surgical site infections and other complications.

Emergency Preparedness

The organization should maintain emergency response procedures appropriate to the patients, procedures, medications and anesthesia services provided.

Required equipment, medications and trained personnel should be available and checked according to policy.

Emergency processes should address cardiopulmonary events, allergic reactions, malignant hyperthermia when applicable, hemorrhage, falls, medication toxicity, respiratory compromise and other foreseeable events.

Personnel should understand how to activate emergency medical services and arrange transfer.

Emergency drills should be conducted, documented and evaluated for improvement.

Equipment and Device Safety

Medical equipment should be inspected, maintained, calibrated and used according to manufacturer instructions and organizational policy.

Personnel should be trained before operating equipment independently.

Preventive maintenance records should be retained.

Defective or recalled equipment should be removed from service promptly.

Implantable devices should be traced through patient, inventory, vendor and operative documentation.

The organization should maintain a process for responding to device recalls and safety notices.

Diagnostic and Clinical Communication

Clinical communication failures can create delays, duplicate treatment and incorrect procedures.

The organization should define processes for communicating critical test results, imaging findings, pathology, adverse events, medication changes and follow up requirements.

Responsibility for reviewing results should be assigned clearly.

The organization should monitor unreviewed, unsigned or uncommunicated results.

Patient notification should be documented.

Transitions and Discharge

Discharge criteria should be based on the patient’s clinical condition, procedure, anesthesia and support requirements.

The patient or responsible adult should receive understandable instructions concerning medications, activity, warning signs, wound or procedure care and follow up.

The organization should verify transportation and responsible adult requirements when applicable.

Discharge instructions should identify when the patient should contact the practice, seek emergency care or return for evaluation.

Patient Complaints and Grievances

Patient complaints can reveal safety, communication, privacy and quality concerns that may not appear in incident reports.

Complaints should be logged, evaluated and routed to the appropriate clinical, compliance or administrative function.

A complaint involving possible harm should not be handled only as a customer service matter.

The organization should analyze complaint patterns by provider, procedure, facility and issue category.

Peer Review and Professional Evaluation

Clinical performance concerns should be reviewed through an appropriate professional evaluation process.

Peer review should be clinically credible, fair and protected according to applicable state law and organizational requirements.

The organization should distinguish peer review from compliance investigation, human resources review and ordinary quality improvement.

Serious concerns may require focused professional practice evaluation, restriction of privileges, external review or reporting to an appropriate authority.

Corrective Action

Corrective action should address the immediate issue and the underlying system.

Actions may include clinical education, competency validation, equipment replacement, revised staffing, workflow redesign, policy revision, technology controls, additional supervision or privilege modification.

The organization should assign an owner, due date, evidence requirement and validation process.

Corrective action should not be closed until the organization has verified that the risk was reduced.

Patient Safety Measures

Leadership should monitor adverse events, near misses, complaints, infections, transfers, medication events, falls, procedure cancellations, emergency responses and unresolved corrective actions.

Measures should be interpreted carefully.

A rising number of reports may reflect improved reporting culture rather than worsening safety.

The organization should evaluate event severity, reporting reliability, recurring causes and corrective action effectiveness.

Application to MSK Specialty Care

Pain management, orthopedic surgery, spine surgery, neurosurgery and neuromodulation involve procedural, medication, implant and anesthesia risks that require coordinated controls.

The safety pathway should connect patient selection, imaging, authorization, consent, medication management, anatomical verification, procedure performance, recovery and follow up.

A procedure may be technically successful yet still reveal a safety failure when the wrong authorization, site, medication, implant or documentation was used.

GoHealthcare Insights

Clinical risk management should follow the patient through the full care pathway.

An event that appears to begin inside the procedure room may have originated during referral intake, medication reconciliation, authorization, scheduling or documentation.

The strongest patient safety programs identify and control these upstream conditions.

Leadership Perspective

Patient safety culture is created by how leadership responds when someone identifies a problem.

When staff are thanked for reporting, events are investigated fairly and corrective actions are completed, reporting becomes part of professional responsibility.

When concerns are minimized or punished, risk becomes hidden.

Key Takeaways

Clinical risk management must operate prospectively and retrospectively.

Adverse events, near misses, unsafe conditions and complaints should feed one coordinated safety system.

Patient protection, objective investigation, root cause analysis and validated corrective action are essential.

Back to framework navigation
32

Specialty Specific Compliance for Pain, Orthopedics, Spine, Neurosurgery and Neuromodulation

Purpose

Specialty Specific Compliance translates general healthcare compliance principles into the clinical and operational realities of interventional pain management, physical medicine and rehabilitation, orthopedic surgery, orthopedic spine surgery, neurosurgery, neuromodulation and related ambulatory services.

These specialties frequently involve high value procedures, strict payer criteria, multiple anatomical levels, implantable devices, recurring interventions, controlled substances, facility relationships and complex longitudinal documentation.

Generic compliance policies are not sufficient.

The organization must understand how medical necessity, patient selection, prior treatment, imaging, procedure history, authorization, coding, site of service and outcomes interact within each specialty pathway.

Specialty Compliance Governance

The organization should establish multidisciplinary specialty oversight involving physicians, clinical operations, utilization management, patient access, coding, revenue cycle management, compliance and facility leadership.

High risk procedures should have documented clinical, authorization, coding and billing controls.

The organization should identify which requirements apply to each procedure, payer, provider, facility and date of service.

Specialty oversight should not rely on one physician’s historical understanding of payer rules.

Policies and coverage criteria change, and requirements may vary by Medicare contractor, commercial payer, plan and delegated utilization management organization.

The Medicare Coverage Database provides current access to National Coverage Determinations, Local Coverage Determinations and associated coverage articles.

Patient Selection

Patient selection should be based on individualized clinical assessment.

The record should explain the diagnosis, symptoms, examination, functional limitations, diagnostic findings, previous treatment and rationale for the proposed intervention.

The organization should not treat payer criteria as a substitute for clinical judgment.

Criteria should be used to determine coverage and documentation expectations while the treating physician remains responsible for deciding whether the proposed care is clinically appropriate.

Financial opportunity, facility ownership, procedure capacity or vendor influence should not determine patient selection.

Longitudinal Clinical History

Many MSK procedures cannot be evaluated from the current office note alone.

The organization should maintain a reliable longitudinal summary containing prior procedures, dates of service, anatomical region, laterality, levels, percentage of relief, duration of relief, functional improvement, conservative treatment and complications.

This information should be reviewed before repeat procedures are requested or scheduled.

A fragmented history can result in unsupported authorization requests, frequency violations, duplicate treatment and inaccurate claims.

Anatomical Specificity

Anatomical information should remain consistent throughout the workflow.

The clinical assessment, imaging, order, authorization request, scheduling record, consent, procedure note and claim should identify the correct region, level, joint, nerve and laterality.

Differences should be resolved before the procedure whenever possible.

A procedure performed at a different level or side than authorized may create clinical, financial and compliance consequences even when the change was medically reasonable.

The reason for any clinically necessary change should be documented, and authorization implications should be evaluated promptly.

Conservative Treatment

When applicable coverage criteria require conservative treatment, the record should identify what was attempted, when it occurred, how long it continued and how the patient responded.

Statements such as “failed conservative care” may be insufficient without supporting detail.

The record may need to address medication, therapy, activity modification, home exercise, bracing or other relevant measures.

When conservative treatment is contraindicated or not tolerated, the clinical reason should be documented.

Imaging and Diagnostic Correlation

Imaging findings should be interpreted within the patient’s clinical presentation.

The existence of an abnormal imaging result does not independently establish medical necessity for a procedure.

The record should explain how symptoms, examination and imaging support the proposed treatment.

Outdated or unrelated imaging should not be cited without clinical explanation.

When image guidance is integral to or separately reportable with a procedure, documentation and coding should follow current code definitions and payer requirements.

Epidural Procedures

Compliance controls for epidural procedures should address diagnosis, symptoms, imaging correlation, conservative care, anatomical level, approach, laterality, medication, image guidance, frequency and previous response.

The organization should verify the current policy governing the patient’s payer and jurisdiction.

The record should distinguish radicular symptoms or other qualifying clinical findings from nonspecific pain when applicable to coverage.

Repeat procedures should be supported by documented response and continued clinical rationale.

Facet Interventions and Diagnostic Blocks

Facet related pathways should distinguish diagnostic blocks from therapeutic services.

The organization should document the suspected pain generator, anatomical levels, laterality, prior treatment, diagnostic block results and the rationale for progression.

When a payer requires sequential diagnostic blocks before radiofrequency ablation, the record should demonstrate that the applicable criteria were satisfied.

The percentage and duration of relief should be documented accurately and should not be changed or exaggerated to secure approval.

Radiofrequency Ablation

Radiofrequency ablation compliance requires alignment among diagnostic history, anatomical levels, laterality, prior response, frequency, authorization, procedure documentation and coding.

The organization should verify that the requested and performed levels match the qualifying diagnostic pathway.

Repeat ablation should include documentation of prior benefit and continued clinical need when required.

Scheduling systems should not determine eligibility solely from elapsed time.

Sacroiliac Joint Procedures

Sacroiliac joint procedures should be supported by relevant history, examination, diagnostic findings, prior treatment and applicable coverage criteria.

The organization should distinguish diagnostic injections, therapeutic injections, radiofrequency procedures and fusion related services.

Authorization and coding should reflect the exact service performed.

Broad use of a sacroiliac diagnosis without sufficient clinical support may create medical necessity risk.

Spinal Cord Stimulation

Spinal cord stimulation programs should govern patient selection, conservative treatment, psychological evaluation when required, trial documentation, outcome measurement, permanent implantation and ongoing management.

The trial record should document the patient’s response, functional improvement and clinical decision concerning permanent implantation.

The permanent implant should reconcile with authorization, operative documentation, device records and claims.

Vendor representatives may provide technical support, but clinical selection, documentation and coding decisions remain the responsibility of the healthcare organization.

Peripheral Nerve Stimulation

Peripheral nerve stimulation should be governed according to the specific device, clinical indication, treatment pathway, payer policy and code set.

The organization should distinguish temporary systems, permanent systems, implantation, removal and programming.

The medical record should identify the targeted nerve, clinical rationale, prior treatment and expected functional outcome.

Technology novelty should not be substituted for clinical evidence or payer coverage.

Vertebral Augmentation and Spine Procedures

Kyphoplasty, vertebroplasty and other vertebral procedures require accurate diagnosis, imaging, clinical correlation, anatomical level and procedure documentation.

Spine surgical procedures require detailed alignment among diagnosis, conservative treatment, imaging, surgical planning, implants, operative findings, assistant surgeon participation and postoperative care.

The organization should evaluate whether each planned component is separately reportable, included in another service or subject to payer restrictions.

Orthopedic Surgical Compliance

Orthopedic compliance should address preoperative evaluation, imaging, failed conservative treatment, surgical indication, implants, assistants, global surgery, postoperative care, therapy and durable medical equipment.

The operative report should identify the procedure actually performed, findings, anatomical site, laterality, implants and complications.

Changes from the planned procedure should be documented and evaluated before claim submission.

Global period services and postoperative procedures should be coded according to applicable rules and supported by the record.

Neurosurgery Compliance

Neurosurgical compliance requires coordination among clinical complexity, imaging, neurological findings, conservative care, surgical planning, facility capability and postoperative monitoring.

Complex cases may involve several surgeons, implants, navigation, monitoring and staged procedures.

The record should explain each professional’s role and the medical necessity for separately reported services.

The organization should not assume that advanced technology or additional personnel are separately payable merely because they were used.

Neuromodulation Device Governance

Neuromodulation programs should maintain a formal device governance process.

The process should address clinical evaluation, vendor selection, contracting, inventory, consignment, implant tracking, recalls, programming, explantation and patient follow up.

Device incentives, consulting arrangements and ownership relationships should receive compliance review.

Clinical decisions should remain independent from vendor sales expectations.

Sedation and Anesthesia

Sedation and anesthesia services should be based on patient condition, procedural requirements and applicable professional standards.

The organization should document the type of anesthesia, responsible professional, monitoring, medications, recovery and complications.

Separate reporting should be supported by the record and applicable coding rules.

Routine use of sedation should not be driven solely by convenience or reimbursement.

Site of Service

The organization should determine whether the selected site is clinically appropriate, authorized, covered and correctly reported.

Services performed in the office, ASC and hospital outpatient department may have different payment, staffing, equipment, authorization and safety requirements.

Place of service should reflect where the service was physically performed.

GoHealthcare’s analysis of CMS site of service policy emphasizes the need for consistency among clinical planning, authorization, scheduling and billing across physician offices, ASCs and hospital outpatient departments.

Durable Medical Equipment

Orthopedic braces, stimulators and other durable medical equipment should be ordered, supplied and billed according to applicable requirements.

The record should support medical necessity and delivery.

Supplier enrollment, proof of delivery, product description and patient instructions should be maintained.

Ownership or financial relationships involving equipment suppliers should receive formal review.

Procedure Frequency

The organization should maintain procedure frequency controls at the patient, provider and service level.

Frequency should be evaluated according to the current policy governing the service.

A repeat procedure should not be requested merely because a billing interval has passed.

The record should demonstrate continued clinical need, previous response and appropriate reassessment.

Outcomes and Functional Improvement

Outcomes should be measured using clinically meaningful information.

Pain reduction alone may not fully describe the patient’s response.

The record may also address mobility, sleep, medication use, work, activities of daily living and other functional objectives.

Outcome measures should be consistent enough to support longitudinal review while remaining individualized to the patient.

Implant and Supply Reconciliation

Implants, drugs and high cost supplies should be reconciled among the operative record, inventory, vendor documentation, invoice, charge and claim.

Serial numbers, lot numbers and patient identifiers should be preserved when required.

Cancelled, opened, wasted, replaced or explanted items should be documented accurately.

Vendor representatives should not direct charge capture or code selection without qualified organizational review.

Specialty Coding Controls

Coding controls should address levels, laterality, units, image guidance, add on codes, modifiers, professional and facility components, global periods, implants and code combinations.

The organization should use current code sets and payer guidance.

A code that accurately describes a service may still be noncovered.

Coverage, coding and medical necessity should be evaluated separately and then reconciled before submission.

Authorization Controls

The authorization request should match the intended procedure, provider, facility, date range, level, laterality and units.

The authorization team should review the longitudinal record rather than simply transmit the most recent note.

Approval should be verified before the service.

Changes in procedure, level, side, facility or provider should trigger authorization reassessment.

Specialty Audit Program

The organization should maintain a risk based specialty audit program.

Audits should examine the complete pathway from patient selection through payment.

A radiofrequency ablation audit should review qualifying diagnostic blocks, outcomes, levels, authorization, procedure documentation, coding and claim payment.

A spinal cord stimulation audit should review patient selection, psychological assessment when applicable, trial response, implant criteria, device records and billing.

Audits limited to code accuracy may fail to identify the clinical or authorization source of risk.

Application of Clinical Resources

Professional clinical guidelines and safety resources may inform internal policies, education and utilization review.

They should not automatically be represented as binding payer requirements.

The organization should distinguish clinical evidence, professional consensus, regulatory standards and payer coverage policy.

GoHealthcare’s safety resource for interventional pain procedures emphasizes the operational value of understanding the clinical procedure when reviewing utilization, documentation and payer requirements.

GoHealthcare Insights

MSK specialty compliance is a connected clinical and operational discipline.

Patient selection, documentation, authorization, procedure performance, coding and payment should tell the same story.

When these functions operate independently, the organization may obtain approval for one procedure, perform another service and submit a claim that cannot be defended.

Leadership Perspective

Specialty expertise must exist within compliance operations.

A generic auditor may identify a coding variance but miss the clinical sequence that determines whether the service was medically necessary.

Leadership should ensure that clinical, payer and coding expertise are available for high risk procedures.

Key Takeaways

MSK compliance must be procedure specific and longitudinal.

Anatomical detail, previous treatment, patient response, authorization and coding must remain aligned.

Implantable devices, advanced procedures and multiple sites of service require enhanced governance.

Back to framework navigation
33

Ambulatory Surgery Center and Facility Compliance

Purpose

Ambulatory Surgery Center and Facility Compliance establish the governance, clinical, operational and billing controls required to operate a safe, lawful and financially defensible outpatient facility.

An ASC is not simply a physician office with a procedure room.

It is a separately regulated facility subject to federal certification requirements, state licensure, payer enrollment, accreditation standards, infection control, patient rights, quality oversight, emergency preparedness, credentialing and facility billing rules.

CMS states that a Medicare participating ASC must be a distinct entity operating exclusively to furnish surgical services to patients not requiring hospitalization, with the expected duration of services not exceeding 24 hours following admission.

Facility Governance

The ASC governing body retains ultimate accountability for quality, safety, compliance, credentialing, infection control, emergency preparedness and facility operations.

The governing body should approve policies, appoint qualified leadership, oversee medical staff activities, monitor quality performance and ensure that contracted services meet facility standards.

Delegation does not eliminate responsibility.

The governing body should receive regular reports concerning adverse events, infections, transfers, complaints, medication incidents, credentialing, compliance audits, quality projects and unresolved corrective actions.

Conditions for Coverage

Medicare certified ASCs must comply with the applicable Conditions for Coverage.

CMS requirements address governing body and management, surgical services, quality assessment, environment, infection control, patient rights, medical records, pharmaceutical services, radiology, laboratory services, patient assessment and emergency preparedness.

The State Operations Manual Appendix L provides CMS surveyor guidance for evaluating ASC compliance.

The ASC should monitor regulatory updates and ensure that internal policies reflect the current requirements.

State Licensure

The facility should maintain all licenses required by the state and local jurisdiction.

State requirements may address ownership, administrator qualifications, staffing, physical plant, pharmacy, anesthesia, reporting, infection control, emergency services and record retention.

An ASC operating in several states should maintain jurisdiction specific compliance resources.

Medicare certification or accreditation does not replace state licensure unless an applicable law expressly provides otherwise.

Accreditation

When accreditation is used for deemed status, payer participation or organizational quality, the facility should maintain compliance with the applicable accrediting organization’s standards.

Accreditation should not be treated as a periodic survey preparation project.

Policies, credentialing, quality improvement, infection control and documentation should operate continuously.

Survey findings should result in corrective action, leadership review and validation.

Quality Assessment and Performance Improvement

The ASC should maintain an active Quality Assessment and Performance Improvement program.

The program should use objective data to identify improvement opportunities, select projects, assign accountability, implement interventions and measure sustained results.

Quality projects should be relevant to the facility’s services, volume and risk.

Examples may include procedure cancellations, infections, transfers, medication safety, incomplete records, patient identification, discharge communication and implant reconciliation.

The program should not consist solely of collecting statistics without taking action.

Patient Safety Culture

Facility leadership should evaluate whether staff feel able to report concerns, question unsafe practices and stop a procedure when necessary.

The AHRQ ASC Survey on Patient Safety Culture provides a structured method for assessing teamwork, communication, staffing, learning and response to mistakes.

Results should be discussed with leadership and converted into improvement actions.

Credentialing and Privileging

The ASC should verify practitioner qualifications and grant procedure specific privileges before services are performed.

Credentialing should include licensure, education, training, experience, competence, professional history and other required information.

Privileges should reflect the procedures the practitioner is qualified to perform and the capabilities of the facility.

A physician’s professional practice privileges or board certification do not automatically authorize every procedure at the ASC.

New procedures should receive formal review before being added.

Medical Staff Governance

Medical staff responsibilities should be defined through bylaws, rules, policies or other governing documents.

The facility should establish processes for appointment, reappointment, peer review, focused evaluation, ongoing evaluation, discipline and privilege modification.

Medical staff governance should coordinate with the governing body while preserving appropriate clinical review.

Professional conduct and documentation standards should apply consistently to owners and nonowners.

Patient Selection

The facility should establish patient selection criteria appropriate to the procedures, anesthesia, staffing, equipment and emergency capability available.

Preoperative assessment should identify medical conditions, medications, allergies, anesthesia history, transportation, social support and other factors affecting suitability for outpatient care.

Financial or scheduling pressure should not override clinical selection criteria.

Patients requiring resources beyond the facility’s capability should be redirected to an appropriate setting.

Preoperative Assessment

The clinical record should contain an appropriate history and physical examination, procedure indication, required testing, medication review and anesthesia assessment.

The assessment should be current according to applicable requirements and updated when the patient’s condition changes.

The procedure, site, laterality and planned anesthesia should be confirmed before the patient enters the procedure room.

Incomplete assessment should result in escalation or postponement when patient safety cannot be established.

Surgical Services

Surgical services should be performed by qualified practitioners with appropriate privileges.

The facility should maintain policies for scheduling, preoperative verification, time out, procedure documentation, postoperative recovery and discharge.

The operative report should identify the procedure performed, findings, anatomical site, laterality, devices, medications, specimens, complications and disposition as applicable.

The record should support both professional and facility claims.

Anesthesia Services

Anesthesia services should comply with applicable professional, state, federal and facility requirements.

The ASC should define who may administer anesthesia, required preanesthesia evaluation, monitoring, documentation, recovery and discharge criteria.

Emergency medications and equipment should be immediately available.

Anesthesia arrangements, compensation and billing should receive compliance review.

The facility should monitor adverse events, unplanned transfers and recovery delays.

Pharmaceutical Services

The ASC should govern medication procurement, storage, security, preparation, administration, wastage, documentation and disposal.

Medication areas should be restricted to authorized personnel.

Controlled substances should be inventoried and reconciled.

Expired, recalled or compromised medications should be removed promptly.

Medication administration should be documented in the patient record and should reconcile with facility charges when billed.

Infection Control

The facility should maintain an active infection prevention and control program under qualified oversight.

The program should address hand hygiene, injection safety, environmental cleaning, sterilization, disinfection, medication preparation, personal protective equipment, surveillance and reporting.

Staff competency should be assessed.

Single use devices and multidose containers should be handled according to current requirements and manufacturer instructions.

Infection concerns should result in immediate containment, patient assessment and evaluation of whether additional patients may have been exposed.

Sterilization and Device Reprocessing

Reusable instruments and equipment should be cleaned, disinfected and sterilized according to manufacturer instructions and applicable standards.

The facility should maintain records of processing cycles, maintenance, testing and corrective action.

Personnel performing reprocessing should be trained and competent.

A failed indicator or process should trigger immediate review of affected items and potentially affected patients.

Physical Environment

The ASC should maintain a safe physical environment appropriate to the procedures performed.

Controls should address utilities, ventilation, electrical safety, emergency power, fire protection, hazardous materials, radiation, waste, equipment maintenance and environmental cleaning.

The facility should document inspections, preventive maintenance and corrective actions.

Changes to space or equipment should receive appropriate regulatory and safety review before use.

Emergency Preparedness

The ASC should maintain an emergency preparedness program addressing foreseeable emergencies and disruptions.

The program should include policies, communication, continuity planning and training.

Clinical emergencies should be supported by appropriate equipment, medications, trained personnel and transfer capability.

Operational emergencies should address power failure, fire, severe weather, cyber incidents, supply disruption and system outage.

Exercises should be documented and lessons incorporated into the plan.

Hospital Transfer Capability

The facility should maintain an effective process for transferring patients who require care beyond the ASC’s capability.

Responsibilities for stabilization, emergency medical services, communication, records and patient belongings should be defined.

Transfer relationships and physician hospital privileges should be evaluated according to applicable requirements.

Every transfer should be reviewed for quality improvement, including the clinical cause, response, timeliness and opportunity for prevention.

Patient Rights

The ASC should inform patients of their rights before care.

Rights may include privacy, respectful treatment, informed consent, access to information, participation in decisions, complaint processes and disclosure of applicable physician ownership.

Information should be provided in a manner the patient can understand.

Language, disability and communication needs should be addressed.

Patients should know how to file a grievance without retaliation.

Advance Directives

The facility should maintain policies addressing advance directives and provide required information before the procedure.

Patients should understand the facility’s policies and any limitations.

The facility should document that required information was provided.

Clinical personnel should know how to respond when an advance directive becomes relevant during an emergency.

Informed Consent

The facility should verify that required surgical, anesthesia and other consents are complete before the procedure.

Consent forms should identify the patient, procedure, site and responsible practitioner.

The patient should have an opportunity to ask questions before sedation.

Changes to the planned procedure should be evaluated for additional consent and authorization requirements.

Medical Records

Facility records should be complete, accurate, accessible and retained according to applicable requirements.

The record should include identification, assessments, orders, consent, medications, procedure documentation, anesthesia, implants, recovery and discharge.

Professional practice and ASC records should be reconciled when separate systems are used.

The facility should be able to produce a complete record during surveys, audits and payer reviews.

Discharge

Discharge should occur only when clinical criteria are satisfied.

The record should identify the patient’s condition, responsible adult when applicable, transportation and instructions.

Instructions should address medications, activity, warning signs, follow up and emergency contact.

The facility should have a process for postprocedure calls or follow up when required by policy or clinical risk.

ASC Quality Reporting

The facility should determine which CMS and payer quality reporting requirements apply.

Data should be accurate, submitted within required timeframes and supported by facility records.

Quality reporting responsibility should be assigned to qualified personnel.

The ASC should not rely exclusively on an outside vendor without verifying completeness and accuracy.

CMS maintains current ASC quality reporting and payment resources as part of the ASC payment system.

Covered Procedure Verification

Before scheduling, the ASC should verify whether the procedure is permitted, payable and authorized in the facility setting for the applicable payer.

Medicare maintains an ASC covered procedure list and related payment files that are updated through annual and quarterly processes.

A procedure may be clinically appropriate but not payable as an ASC facility service.

The professional service, facility service and implant may have different coverage and billing requirements.

Facility Billing Compliance

The facility claim should represent the service, location, procedure, supplies and devices documented.

The ASC should not bill a facility fee for a service performed elsewhere.

The facility and professional claims should be consistent without being duplicative.

Coding, units, implants and terminated procedures should receive qualified review.

Payment should be reconciled with the applicable payer contract and facility payment system.

Implant and Supply Controls

The ASC should maintain inventory, consignment, implant and supply controls.

The operative report, implant log, vendor record, invoice, charge and claim should agree.

Expired, recalled or damaged items should be identified and removed.

Vendor representatives should comply with facility access, credentialing, confidentiality and conduct requirements.

They should not control clinical selection or final billing decisions.

Controlled Substances

Controlled substances within the ASC should be secured, inventoried, administered, wasted and documented according to applicable requirements.

Access should be limited to authorized personnel.

Discrepancies should be investigated immediately.

Diversion concerns should trigger patient protection, evidence preservation, access restriction and compliance review.

Contracted Services

The governing body remains accountable for contracted anesthesia, laboratory, pharmacy, radiology, infection prevention, billing and other services.

Contracts should define qualifications, performance, compliance, reporting and corrective action.

The ASC should monitor actual performance.

A contractor’s failure may become a facility compliance deficiency.

Survey Readiness

Survey readiness should be maintained continuously.

The facility should be able to produce policies, credentials, quality data, infection control records, emergency exercises, equipment maintenance, medication records and corrective actions.

Mock surveys may identify gaps before an official review.

Documents should reflect actual practice.

A technically complete policy that personnel do not follow may increase rather than reduce survey risk.

Application to MSK Specialty Care

Pain, orthopedic, spine, neurosurgical and neuromodulation ASCs require enhanced controls for implants, image guidance, anesthesia, high cost supplies, procedure eligibility and facility billing.

GoHealthcare’s ASC guidance emphasizes that covered procedure lists, payment rules, accreditation duties and financial relationship requirements must be evaluated separately and updated regularly.

GoHealthcare Insights

The ASC sits at the intersection of clinical care, facility regulation, physician ownership, device utilization and reimbursement.

Operational efficiency should never be achieved by weakening patient selection, documentation, credentialing or emergency capability.

Leadership Perspective

An ASC governing body must behave like the governing body of a regulated healthcare facility, not merely a group of investors.

Ownership creates responsibility for quality, safety and compliance in addition to financial performance.

Key Takeaways

ASC compliance requires continuous governance under federal, state, accreditation and payer requirements.

Credentialing, patient selection, infection prevention, quality improvement and emergency preparedness must be operationally effective.

Facility and professional claims must align with the procedure, setting, documentation and current covered procedure requirements.

Back to framework navigation
34

Controlled Substances, Prescribing and Medication Compliance

Purpose

Controlled Substances, Prescribing and Medication Compliance establish the governance, clinical standards and operational safeguards required to prescribe, administer, store, monitor and account for medications safely and lawfully.

Controlled substance compliance is both a patient care and regulatory responsibility.

The organization must support individualized pain treatment while reducing risks involving overdose, diversion, inappropriate prescribing, unsafe drug combinations, impaired practice, inaccurate records and uncontrolled medication access.

The federal Controlled Substances Act places regulated substances into five schedules based on medical use, potential for misuse and safety or dependence risk.

Regulatory Governance

The organization should maintain a medication and controlled substance governance program appropriate to its services.

The program should address federal law, state prescribing law, professional licensing rules, prescription monitoring requirements, pharmacy requirements, facility standards and payer obligations.

A qualified clinical leader should oversee prescribing standards.

Compliance, pharmacy, nursing, risk management and operations should participate according to the organization’s structure.

Requirements should be reviewed by state because prescribing authority, monitoring, documentation and dispensing rules vary.

DEA Registration

Practitioners who prescribe, administer or dispense controlled substances should maintain the required DEA registration and state authority.

Registration should correspond to the practitioner, professional scope, location and activity involved.

The organization should track expiration dates and changes affecting registration.

A practitioner should not prescribe through another person’s registration or allow unauthorized use of credentials.

Loss, restriction or surrender of registration should be escalated immediately.

Legitimate Medical Purpose

Controlled substance prescriptions should be issued for a legitimate medical purpose by a practitioner acting within the usual course of professional practice.

The clinical record should demonstrate the condition evaluated, treatment rationale, medication selected, risks considered and follow up plan.

A prescription should not be issued solely at patient request, because another clinician prescribed it previously or to avoid a difficult conversation.

The organization should not create rigid prescribing practices that replace individualized clinical judgment.

Clinical Guidance Versus Legal Requirements

Clinical guidelines should support decision making but should not be misrepresented as law.

The CDC Clinical Practice Guideline for Prescribing Opioids for Pain provides voluntary recommendations for outpatient clinicians treating adults with acute, subacute and chronic pain, excluding certain clinical populations addressed separately.

The guideline emphasizes individualized, patient centered care and consideration of benefits, risks, nonopioid options and ongoing reassessment.

Organizations should avoid converting clinical recommendations into inflexible limits that result in unsafe or abrupt discontinuation.

Individualized Treatment Planning

The treatment plan should reflect the patient’s diagnosis, symptoms, functional goals, previous treatment, coexisting conditions and risk factors.

The clinician should discuss realistic objectives.

Complete elimination of pain may not be a realistic or appropriate treatment goal.

Functional improvement, activity tolerance, sleep, work capability and quality of life may provide more meaningful measures.

The plan should identify how benefit and harm will be evaluated.

Nonopioid and Nonpharmacologic Treatment

The clinician should consider appropriate nonopioid medications and nonpharmacologic treatment within the patient’s clinical context.

The existence of an interventional or medication option does not eliminate the need to evaluate alternatives.

The record should explain why the selected treatment is appropriate.

CDC notes that nonopioid therapies can be at least as effective as opioids for many common forms of acute musculoskeletal pain.

Risk Assessment

Before and during opioid treatment, clinicians should assess relevant risks.

Factors may include substance use history, overdose history, respiratory disease, mental health conditions, pregnancy, age, concurrent sedatives, renal or hepatic impairment and access to other controlled medications.

Risk assessment tools may support review but should not replace clinical judgment.

Patients should not be stigmatized or denied appropriate care solely because a screening tool identifies elevated risk.

Higher risk may require additional monitoring, consultation or treatment modification.

Prescription Drug Monitoring Programs

The organization should establish procedures for reviewing the applicable state Prescription Drug Monitoring Program.

Requirements vary by state and clinical circumstance.

The review should be documented according to applicable policy and law.

Potential concerns may include multiple prescribers, overlapping controlled substances, early fills or unexpected pharmacy patterns.

The clinician should evaluate the information with the patient rather than assume misconduct automatically.

Informed Discussion

Patients should receive clear information concerning expected benefits, material risks, safe use, storage, disposal, interactions and overdose.

The discussion should address alcohol, sedatives, illicit substances, driving and sharing medication.

Patients should know how to contact the practice if adverse effects or concerns occur.

The clinical record should document the substance of the discussion rather than rely solely on a signed form.

Controlled Substance Agreements

A written treatment agreement may establish expectations concerning medication use, refills, monitoring, pharmacy use, appointments, testing and safe behavior.

The agreement should support communication and safety.

It should not be used solely as a punitive contract.

Requirements should be applied consistently while allowing clinically appropriate exceptions.

Violations should trigger evaluation rather than automatic dismissal without assessment.

Toxicology Testing

Toxicology testing should be ordered according to clinical need and applicable requirements.

The organization should distinguish presumptive and definitive testing.

The record should support why the test was ordered and how the result influenced care.

Unexpected results should be interpreted carefully.

Potential explanations may include timing, metabolism, laboratory limitations, prescribed medications or specimen issues.

Testing should not be used primarily to generate revenue or performed uniformly without individualized rationale.

Naloxone and Overdose Risk Mitigation

Clinicians should consider overdose education and naloxone when patient risk warrants it.

The patient and relevant household members should understand how naloxone is used and how to obtain emergency assistance.

Naloxone availability should not be presented as evidence that the patient is misusing medication.

It is a safety intervention.

The organization should identify clinical circumstances in which discussion or prescribing is expected.

Follow Up and Reassessment

Patients receiving ongoing controlled substances should be reassessed at intervals appropriate to clinical risk, treatment duration and applicable requirements.

The clinician should evaluate pain, function, adherence, adverse effects, medication interactions, monitoring information and continued benefit.

Continuation should not occur automatically because the patient has taken the medication for a long time.

The record should explain the decision to continue, modify or discontinue treatment.

Dosage Changes

Dosage decisions should be individualized.

The organization should not pressure clinicians to increase medication to satisfy patient demand or decrease medication solely to meet an administrative metric.

Higher dosage may increase risk and warrants careful assessment, documentation and monitoring.

The clinical record should explain the rationale for significant changes.

Tapering and Discontinuation

Medication tapering should be planned collaboratively when clinically appropriate.

Abrupt discontinuation can create withdrawal, destabilization and patient harm except when immediate safety concerns require urgent action.

The organization should maintain a process for patients whose prescriber leaves, becomes unavailable or loses prescribing authority.

Patients should not be abandoned because of an administrative transition.

CDC guidance warns against rigid application of dosage thresholds and abrupt or rapid tapering that does not account for the patient’s circumstances.

Concurrent Medications

The clinician should evaluate concurrent opioids, benzodiazepines, sedatives, muscle relaxants and other medications that may increase risk.

Medication reconciliation should occur regularly.

The organization should not assume that a medication prescribed by another clinician is outside its responsibility.

Relevant communication and care coordination should occur when risks are identified.

Electronic Prescribing

Electronic prescribing systems should use individual credentials and appropriate authentication.

Prescribers should protect authentication tokens, passwords and signing devices.

Staff should not transmit a controlled substance prescription under a practitioner’s credentials without lawful authority and practitioner approval.

Access should be removed promptly when employment or clinical authority ends.

Telemedicine Prescribing

Telemedicine prescribing of controlled substances requires careful review of current federal and state requirements.

The regulatory environment has changed repeatedly and may distinguish practitioner registration, patient evaluation, medication schedule and clinical circumstance.

The organization should verify the rules in effect on the prescribing date rather than relying on emergency period practices or outdated guidance.

Proposed rules and temporary extensions should not be treated as permanent requirements unless finalized and effective.

Storage and Security

Controlled substances maintained onsite should be secured against unauthorized access.

Keys, codes and access rights should be limited.

Storage areas should be inspected.

Medication should not be left unattended in unlocked clinical areas.

The organization should maintain procedures for after hours access, emergency access and access termination.

Inventory and Reconciliation

The organization should maintain complete and accurate controlled substance records appropriate to its role.

Receiving, administration, dispensing, wastage, return and disposal should be documented.

Inventory should be reconciled at defined intervals.

Differences should be investigated promptly.

Repeated small discrepancies should not be dismissed merely because each individual amount is limited.

Wastage

Controlled substance wastage should be documented at the time it occurs.

Witnessing requirements should follow policy and applicable law.

The record should identify the medication, quantity used, quantity wasted, patient and personnel involved.

Delayed or reconstructed wastage documentation creates diversion and record integrity concerns.

Diversion Prevention

The organization should maintain a diversion prevention and response program.

Warning signs may include inventory discrepancies, altered records, unusual access, repeated wastage, medication disappearance, impaired behavior and inconsistent administration documentation.

Personnel should know how to report concerns confidentially.

A suspected diversion event should trigger patient protection, access restriction, evidence preservation, inventory review and qualified investigation.

Impaired Practitioners and Workforce Members

The organization should maintain a process for responding when a practitioner or employee may be impaired.

Immediate patient safety should guide the response.

The organization should evaluate removal from duty, testing, reporting, professional assistance and regulatory obligations.

Concerns should be handled confidentially but should not be concealed when reporting or patient protection is required.

Drug Samples and Noncontrolled Medications

Medication compliance should extend beyond controlled substances.

Samples, injectable medications, contrast agents, antibiotics and other products should be stored, tracked and administered appropriately.

Expired, recalled or compromised products should be removed.

The organization should not distribute samples in a manner that bypasses clinical documentation or medication reconciliation.

Emergency Medications

Emergency medications should be available, current and appropriate to the services performed.

Supplies should be checked and documented.

Personnel should know where medications are located and how to use them.

Emergency medication readiness should be included in clinical drills.

Medication Documentation

The clinical record should identify the medication, dose, route, timing and response as applicable.

Prescribing and administration documentation should be accurate and timely.

Copied medication lists should be reconciled.

The record should distinguish medications ordered, administered, discontinued and reported historically.

Prescribing Audit Program

The organization should monitor controlled substance prescribing according to risk.

Review may include documentation, PDMP use, toxicology testing, dosage, concurrent medications, early refills, lost prescriptions, patient outcomes and compliance with state requirements.

Outlier prescribing should receive qualified clinical review.

Data patterns should not be treated as proof of inappropriate prescribing without patient and clinical context.

Application to Interventional Pain Management

Pain practices should integrate prescribing compliance with interventional care.

Medication management, procedures, physical treatment, behavioral health and functional outcomes should form one coherent plan.

The record should explain how opioid or other controlled medication fits within the patient’s overall treatment strategy.

GoHealthcare’s risk management resources identify controlled substances as a major operational and legal exposure for pain practices and emphasize structured policies, documentation and ongoing review.

GoHealthcare Insights

Controlled substance compliance is not achieved by forcing every patient into the same protocol.

It requires individualized care within a governed system that supports documentation, monitoring, escalation and accountability.

Leadership Perspective

Leadership should protect both sides of medication safety.

The organization must prevent inappropriate prescribing and diversion while also preventing rigid administrative policies from disrupting legitimate patient care.

Key Takeaways

Controlled substances require coordinated clinical, legal, security and documentation controls.

CDC recommendations support individualized decision making and should not be converted into inflexible legal limits.

Registration, monitoring, storage, inventory, diversion response and patient follow up must operate as one system.

Back to framework navigation
35

Patient Financial, Consumer Protection and No Surprises Act Compliance

Purpose

Patient Financial, Consumer Protection and No Surprises Act Compliance establish how the organization communicates expected costs, determines patient responsibility, collects payment, manages out of network services, issues refunds and protects patients from unlawful or misleading financial practices.

Patient financial compliance begins before the service.

Patients should receive accurate and understandable information concerning coverage, known financial responsibility, payment expectations and available options.

Financial communication should support informed decisions without interfering with clinically necessary emergency care or creating inappropriate pressure.

The No Surprises Act created federal protections addressing certain unexpected out of network bills and established requirements for providers, facilities, plans and issuers.

Patient Financial Governance

The organization should establish formal governance for eligibility, benefit verification, cost estimates, financial consent, payment plans, collections, refunds, out of network communication and financial complaints.

Patient access, revenue cycle management, compliance, finance, contracting, clinical leadership and legal counsel should have defined responsibilities.

Financial policies should be approved, communicated and applied consistently.

Individual employees should not create unofficial discounts, payment arrangements or collection practices outside approved authority.

Financial Communication Standard

Financial information should be accurate, timely and understandable.

Personnel should distinguish an estimate from a guarantee.

Patients should be informed that benefit information is based on data available at the time and that final responsibility may depend on claim adjudication.

The organization should avoid vague statements such as “insurance will cover it” when coverage and payment have not been confirmed.

Known exclusions, deductibles, coinsurance, nonparticipation and authorization limitations should be communicated when applicable.

Eligibility and Benefits

The organization should verify active coverage, plan, network status, benefits and patient cost sharing before nonemergency services whenever possible.

Verification should identify the patient, payer, product, provider, facility and proposed service.

A payer representative’s general statement should not be interpreted as a guarantee of payment.

The organization should retain appropriate evidence of verification.

Eligibility verification should be repeated when the service date is significantly later or when coverage may have changed.

Network Status

The organization should determine network status separately for the professional provider, facility, anesthesia provider, laboratory, imaging service and other participants when applicable.

A participating physician does not establish that every facility or supporting provider is participating.

Patients should receive accurate information concerning known out of network participation.

The organization should not describe a service as in network solely because one component participates.

Patient Cost Estimates

Cost estimates should use available benefit, contract, fee schedule and service information.

The estimate should identify known professional, facility, implant, anesthesia and related charges when the organization is responsible for communicating them.

The methodology should be documented.

Estimates should be updated when the procedure, provider, facility or expected services change materially.

The organization should monitor the difference between estimated and actual responsibility to improve accuracy.

No Surprises Act Scope

The organization should determine whether federal surprise billing protections apply to the patient’s coverage, service and setting.

The federal protections generally address certain emergency services and certain nonemergency services furnished by out of network providers at participating healthcare facilities.

State laws may provide additional or broader protections.

The organization should not assume that the same rules apply to every payer, service or patient.

CMS maintains current provider requirements, model notices, rules and operational resources through its No Surprises website.

Emergency Services

Emergency care should not be delayed for financial screening or advance payment.

Applicable cost sharing and balance billing protections should be applied.

The organization should coordinate with emergency facilities, payers and patients to ensure that claims and patient balances reflect the applicable requirements.

Emergency services should not be reclassified administratively to avoid consumer protections.

Nonemergency Out of Network Services

Certain nonemergency services furnished by out of network providers at participating facilities may be subject to federal protections.

The organization should identify whether notice and consent are available and lawful for the particular service.

Notice and consent should not be used routinely or presented in a coercive manner.

Some services and circumstances may not permit waiver of protections.

Qualified compliance or legal review should guide the organization’s process.

Notice and Consent

When a notice and consent process is legally available, the notice should comply with applicable content, timing, format and language requirements.

Patients should receive meaningful opportunity to understand the information and decline out of network care when an in network option is available.

Consent should not be obtained after sedation, under inappropriate pressure or through a document that obscures the patient’s rights.

The organization should retain the completed notice and consent according to applicable requirements.

Balance Billing

The organization should prohibit balance billing when federal or state law protects the patient.

Patient responsibility should be calculated according to applicable plan, law and adjudication information.

Employees and collection vendors should not pursue amounts that have been placed on hold because of a dispute, appeal or regulatory review.

System rules should prevent protected balances from moving automatically into collection workflows.

Good Faith Estimates

Providers and facilities generally must provide uninsured or self pay individuals with a Good Faith Estimate when care is scheduled or when an estimate is requested, subject to applicable requirements and exceptions.

The estimate should identify expected charges for reasonably anticipated items or services based on information known when it is prepared.

CMS provides provider resources, decision tools and sample forms addressing Good Faith Estimate requirements.

The organization should not limit the process only to patients who state that they have no insurance. A patient who has coverage but chooses not to use it may qualify as self pay for the applicable service.

Good Faith Estimate Timing

The organization should establish scheduling controls that identify when a Good Faith Estimate is required and ensure delivery within the applicable timeframe.

The timing depends on when the service is scheduled or when the individual requests the estimate.

Staff should not wait until the date of service when the requirement applies earlier.

The estimate should be provided in a format the patient can retain.

CMS maintains a current consumer and provider explanation of Good Faith Estimate expectations.

Good Faith Estimate Content

The estimate should contain the required patient, provider, service, diagnosis and charge information, along with applicable disclaimers and dispute information.

It should reflect services reasonably expected at the time.

The organization should not exclude known major components merely because another department or related entity will bill separately.

Coordination with other providers and facilities should follow the requirements and current enforcement framework applicable to the organization.

Changes to the Planned Service

A new or revised estimate may be necessary when the planned procedure, facility, provider or expected service changes.

The scheduling and clinical teams should notify the financial clearance function promptly.

A material change should not be discovered only after the patient receives a significantly higher bill.

The organization should document why the original estimate changed.

Patient Provider Dispute Resolution

An uninsured or self pay individual may be eligible to initiate the federal Patient Provider Dispute Resolution process when billed charges are substantially higher than the Good Faith Estimate.

CMS consumer guidance identifies a difference of at least $400 as the threshold for potential eligibility under the federal process.

The organization should maintain a process for receiving dispute notices, preserving records, pausing collection activity when appropriate and responding within required timeframes.

Medicare Advance Beneficiary Notices

Medicare financial notice requirements should be managed separately from No Surprises Act processes.

When the organization expects that Medicare may deny an item or service under circumstances requiring an Advance Beneficiary Notice, the notice should be completed before the service according to applicable CMS requirements.

The patient should understand the service, reason payment may be denied and estimated cost.

An incomplete or improperly timed notice may not transfer financial liability to the patient.

Self Pay Pricing

Self pay pricing should be governed through approved policy.

The organization should define whether discounts apply, how they are calculated and who may authorize exceptions.

Prices should be communicated consistently.

A self pay amount should not be represented as a discount from an inflated charge created solely to make the offer appear more favorable.

Financial information should avoid deceptive or misleading comparisons.

Deposits and Prepayments

Deposits and prepayments should be posted accurately to the patient’s account.

The organization should explain whether the payment is an estimate and how final reconciliation will occur.

Overpayments should be refunded promptly after claim adjudication or cancellation.

Deposits should not be transferred to unrelated balances without appropriate authorization and policy support.

Payment Plans

Payment plans should be documented and administered consistently.

Terms should identify the amount, frequency, duration and consequences of nonpayment.

The organization should consider patient circumstances and applicable nondiscrimination requirements.

Employees should not create arrangements beyond their authority or promise terms the organization cannot honor.

Financial Assistance

When the organization maintains financial assistance or charity care programs, eligibility and application processes should be clear.

Patients should receive information about available assistance when appropriate.

Decisions should be documented and applied consistently.

Financial assistance should not be structured to induce federally reimbursable referrals or waive patient responsibility routinely without appropriate analysis.

Waiver of Patient Responsibility

Routine waiver of copayments, coinsurance or deductibles can create compliance risk.

The organization should distinguish individualized financial hardship decisions, lawful financial assistance and prohibited routine waivers.

Approvals should follow written policy and documentation requirements.

Marketing should not promise automatic waiver of patient responsibility.

Collections

Collection activity should be professional, accurate and consistent with applicable federal and state law.

The organization should verify that the balance is correct before collection begins.

Disputed, appealed, protected or unresolved insurance balances should be reviewed before being transferred to a collection agency.

Patients should receive understandable statements and a method to request explanation.

Aggressive collection should not replace correction of registration, authorization, posting or payer errors.

Collection Vendors

Collection agencies and patient financing vendors should be evaluated and monitored.

Contracts should address legal compliance, communication standards, privacy, complaints, data security, reporting and termination.

The organization remains responsible for reputational and compliance consequences associated with vendors acting in its name.

Vendor scripts, letters and automated messages should be reviewed.

Credit Balances and Refunds

Patient credit balances should be reviewed regularly.

Refunds should be issued to the correct party within applicable requirements.

Credits should not be cleared through unsupported adjustments.

The organization should monitor refund timeliness, aging, amounts and causes.

Recurring patient credits may indicate inaccurate estimates, duplicate collections or payment posting problems.

Financial Complaints

Patient financial complaints should be logged and evaluated.

Complaints may reveal incorrect estimates, misleading communication, inappropriate balance billing, duplicate collection, failure to apply payments or disrespectful conduct.

Material complaints should be reported to compliance and leadership.

Resolution should include account correction and analysis of the underlying workflow.

Language and Accessibility

Financial notices should be provided in a manner patients can understand.

The organization should account for language, disability, literacy and communication needs.

Employees should be trained to obtain qualified assistance rather than relying on untrained family members for complex financial discussions.

Accessibility should apply to electronic and paper communications.

Patient Financial Data

Financial information should be protected under applicable privacy, security and consumer requirements.

Payment card information should be handled through approved systems.

Employees should not record card information in unsecured notes, email or spreadsheets.

Access should be limited to legitimate responsibilities.

Monitoring and Auditing

The organization should monitor estimate accuracy, Good Faith Estimate completion, out of network notices, protected balances, refunds, complaints, payment plans, collection vendor performance and financial assistance decisions.

Audits should test whether required notices were provided before the service and whether patient responsibility was calculated correctly.

Repeat findings should result in workflow and technology changes.

Application to MSK Specialty Care

Pain, orthopedic, spine, neurosurgical and neuromodulation services may involve significant professional, facility, anesthesia, implant and imaging charges.

Patients need coordinated financial information before elective procedures whenever possible.

A professional estimate that excludes the ASC, implant or anesthesia charge may create a materially incomplete picture.

GoHealthcare’s revenue cycle guidance identifies Good Faith Estimates and patient financial clearance as essential components of high value MSK procedure planning.

GoHealthcare Insights

Patient financial compliance is part of patient access.

A patient cannot make an informed decision when the organization knows that major financial information is missing, inconsistent or likely to change.

The goal is not to guarantee an exact final bill. It is to provide the most accurate and complete information reasonably available.

Leadership Perspective

Patient collections should not be measured only by how much money is collected before service.

Leadership should also measure accuracy, transparency, refund performance, complaint volume and patient trust.

Key Takeaways

Patient financial communication must be accurate, timely and understandable.

No Surprises Act, Good Faith Estimate, Medicare notice and state balance billing requirements should be governed as distinct but coordinated processes.

Patient balances, refunds, collections and vendor activity require compliance oversight.

Back to framework navigation
36

AI Healthcare Governance, Algorithmic Risk and Responsible Use

Purpose

AI Healthcare Governance establishes the authority, policies, controls and accountability required to evaluate, approve, implement, monitor and retire artificial intelligence systems used within healthcare operations.

Artificial intelligence may support clinical documentation, coding, medical necessity review, prior authorization, scheduling, patient communication, claims analysis, audit preparation, denial prevention, workforce productivity and executive decision support.

These capabilities can improve efficiency and consistency. They can also introduce inaccurate recommendations, fabricated information, privacy exposure, cybersecurity vulnerabilities, algorithmic bias, automation errors, inappropriate clinical reliance and unclear accountability.

AI should therefore be governed as an enterprise risk capability rather than treated as an ordinary software purchase.

The National Institute of Standards and Technology Artificial Intelligence Risk Management Framework provides a voluntary structure for managing artificial intelligence risks through four principal functions: Govern, Map, Measure and Manage. The framework is designed to help organizations address risks to individuals, organizations and society throughout the artificial intelligence lifecycle.

AI Governance Standard

The organization should establish a formal AI Governance Program approved by the governing body or executive leadership.

The program should define the organization’s principles for responsible artificial intelligence, approval requirements, prohibited activities, risk classifications, human oversight expectations, validation standards, privacy controls, security requirements, vendor obligations, monitoring processes and escalation authority.

The governance program should apply to every artificial intelligence capability used by the organization, regardless of whether the system was purchased independently, included within an existing technology platform, provided by a vendor or accessed through a public application.

Artificial intelligence functionality embedded within an electronic health record, coding platform, patient portal, scheduling system or revenue cycle application should not be excluded from governance merely because the organization did not purchase it as a separate AI product.

AI Governance Committee

The organization should establish an AI Governance Committee or assign formal artificial intelligence oversight to an existing multidisciplinary committee.

Membership should include executive leadership, clinical leadership, compliance, privacy, cybersecurity, information technology, data governance, patient safety, revenue cycle management, legal counsel, quality, human resources and operational leaders responsible for affected workflows.

The committee should have authority to approve, restrict, suspend or discontinue artificial intelligence use.

Committee decisions should be documented and should identify the approved use, responsible owner, risk classification, authorized users, implementation conditions, performance measures, monitoring frequency and review date.

A technology department should not approve high risk artificial intelligence independently when the system affects patient care, clinical documentation, medical necessity, billing, coding, patient communication or protected health information.

AI Use Case Inventory

The organization should maintain a centralized inventory of all active, proposed, pilot and retired artificial intelligence use cases.

The inventory should identify the system, vendor, intended purpose, organizational owner, affected workflow, patient population, data used, users, output, risk classification, validation status, approval date, monitoring requirements and retirement status.

The inventory should include generative artificial intelligence, predictive models, automated classification, natural language processing, ambient documentation, computer assisted coding, patient communication tools, robotic process automation using artificial intelligence and artificial intelligence embedded within existing systems.

HHS maintains an artificial intelligence use case inventory to support transparency, accountability and secure AI use across its operations. Healthcare organizations can apply a similar inventory concept internally to ensure that leadership knows where artificial intelligence is being used and for what purpose.

Shadow AI

Shadow AI occurs when employees, physicians, contractors or departments use artificial intelligence tools without organizational approval.

Examples may include entering patient information into public generative AI platforms, using personal AI subscriptions to draft clinical notes, uploading payer documents to unapproved tools, generating appeal letters through public systems or using AI to interpret patient records without validation.

The organization should prohibit unauthorized AI use involving protected health information, confidential business information, employee information, proprietary policies or payer data.

Workforce members should receive a practical approved tool list and a clear process for requesting review of new AI capabilities.

The objective should not be to prohibit innovation automatically. It should be to ensure that innovation occurs within an accountable and secure governance process.

Intended Use Definition

Every approved AI system should have a clearly documented intended use.

The intended use should explain what the system is permitted to do, which users may operate it, which decisions it may support, what data it may access and what activities remain outside its authority.

An AI system approved to summarize a clinical record should not automatically be used to determine medical necessity.

A model approved to identify coding exceptions should not independently release claims.

A patient communication tool approved for appointment reminders should not provide individualized medical advice.

Use outside the approved purpose should require additional governance review.

AI Risk Classification

Artificial intelligence systems should be classified according to the potential consequence of error.

Lower risk systems may support administrative tasks such as meeting summaries, general scheduling assistance or nonclinical workflow reminders.

Moderate risk systems may support eligibility verification, work queue prioritization, denial prediction, coding recommendations or documentation gap identification.

Higher risk systems may influence diagnosis, treatment, patient selection, clinical decision support, medication management, procedure eligibility, medical necessity, coverage determination or patient specific recommendations.

Risk classification should consider patient harm, financial exposure, privacy, cybersecurity, regulatory impact, scale, autonomy, explainability and the ability of a human reviewer to detect an error before action occurs.

A system should not be classified as low risk solely because the vendor describes it as administrative. Its actual use and consequences should determine the classification.

Preimplementation Impact Assessment

Every material AI use case should undergo an impact assessment before implementation.

The assessment should evaluate the clinical or operational problem, intended benefit, affected population, data requirements, workflow impact, patient safety, privacy, cybersecurity, fairness, regulatory exposure, workforce implications and financial consequences.

The organization should identify what could happen if the system produces an incorrect output, fails completely, becomes unavailable or performs differently across patient populations.

The assessment should also determine whether a non AI solution could address the problem more reliably or at lower risk.

Artificial intelligence should not be adopted merely because it is innovative, widely marketed or included in a vendor demonstration.

Evidence and Vendor Claims

Vendor performance claims should be validated before approval.

The organization should request information concerning training data, testing methodology, performance measures, intended population, limitations, known failure modes, model updates and independent evidence.

A claim that a tool is highly accurate is incomplete without knowing what was measured, against which reference standard, in which population and under what operating conditions.

Clinical evidence obtained in another healthcare setting may not transfer directly to pain management, orthopedics, spine, neuromodulation or ambulatory surgery center operations.

The organization should distinguish vendor marketing, internal testing, peer reviewed evidence, regulatory authorization and actual local performance.

Regulatory Classification

The organization should determine whether an AI application may fall within medical device regulation or another specific regulatory framework.

FDA maintains information concerning artificial intelligence enabled medical devices authorized for marketing in the United States. FDA also publishes digital health guidance addressing lifecycle management, clinical decision support and changes to AI enabled device functions.

Not every healthcare AI tool is an FDA regulated medical device.

The organization should obtain qualified regulatory review when an AI system performs diagnostic, therapeutic or patient specific clinical functions that may raise device classification questions.

A vendor statement that a product is not a medical device should not be accepted without understanding the product’s intended use and actual implementation.

Certified Health Information Technology and Algorithm Transparency

Organizations using certified health information technology should understand whether predictive decision support functionality is subject to applicable ONC certification requirements.

The HTI 1 Final Rule established transparency requirements for predictive decision support interventions included within certified health information technology and updated certification expectations concerning algorithm information and risk management.

The organization should request available source attributes, intended use information, validation information, known limitations and risk management documentation from its health information technology vendor.

Certified functionality does not eliminate the healthcare organization’s responsibility to determine whether the tool is appropriate for its patients, clinicians and workflows.

Local Validation

Artificial intelligence should be validated within the organization’s intended environment before routine use.

Validation should use representative cases, workflows, providers, specialties, payer requirements and patient populations.

The organization should establish measurable acceptance criteria before testing begins.

Validation may examine accuracy, completeness, sensitivity, specificity, false positive rates, false negative rates, consistency, processing time, usability and agreement with qualified human review.

Results should be documented, reviewed and approved by personnel with appropriate clinical, operational, coding, technical or compliance expertise.

A successful vendor demonstration should not replace local validation.

Generative AI Validation

Generative AI requires additional validation because its output may vary and may contain fabricated, incomplete or misleading information.

Testing should evaluate whether the tool invents patient history, diagnoses, findings, citations, payer requirements, coding rules or clinical recommendations.

The organization should test adversarial and ambiguous scenarios, not only ideal examples supplied by the vendor.

Users should be trained to recognize that fluent language does not establish factual accuracy.

Every material generative AI output should be verified against the authoritative record or source before it influences patient care, documentation, billing, authorization or financial decisions.

Human Oversight

Human oversight should be defined according to the risk of the use case.

High risk outputs should require review and approval by a qualified person before action occurs.

A physician should verify AI generated clinical documentation and clinical recommendations.

A qualified coder should verify coding suggestions.

A utilization management professional should verify medical necessity and payer policy interpretations.

An authorization specialist should confirm the payer, procedure and submission requirements.

A revenue cycle professional should verify claim recommendations before submission.

The organization should identify which decisions may never be delegated entirely to artificial intelligence.

Human review should be meaningful rather than ceremonial. The reviewer should have enough time, information, authority and expertise to reject or correct the output.

Final Accountability

Artificial intelligence does not assume professional, legal or organizational accountability.

The treating professional remains responsible for clinical judgment and authenticated clinical documentation.

The organization remains responsible for claims submitted in its name.

The compliance function remains responsible for appropriate investigation and escalation.

The governing body and executive leadership remain responsible for oversight.

Contracts should not create the impression that the AI vendor has accepted responsibilities that legally or operationally remain with the healthcare organization.

Clinical Documentation

AI generated clinical documentation should reflect the actual encounter.

The clinician should verify symptoms, examination findings, diagnoses, clinical reasoning, treatment decisions and patient instructions before authentication.

AI should not create facts that were not observed, discussed or determined.

The organization should monitor copied language, inaccurate summaries, missing qualifications, contradictory statements and documentation created from conversations involving the wrong patient.

Clinical notes should not be authenticated automatically without provider review.

Coding and Billing

Artificial intelligence may identify coding opportunities, documentation gaps, modifier patterns and claim exceptions.

The final claim must remain supported by the medical record and applicable coding requirements.

AI should not select a higher reimbursing code because similar claims were paid historically.

It should not infer diagnoses, anatomical levels, laterality, units or procedures that were not documented.

Automated claim release should be restricted when the system’s output requires professional interpretation or when the service presents material compliance risk.

Medical Necessity and Prior Authorization

AI may assist with policy retrieval, record summarization, procedure history, documentation gap identification and authorization preparation.

The system should use the correct payer, plan, policy version, procedure, provider and site of service.

AI generated medical necessity summaries must be compared with the underlying record.

The tool should not invent conservative treatment, increase reported pain relief, change procedure dates or insert unsupported clinical findings to satisfy payer criteria.

An approval obtained through inaccurate AI generated information remains a compliance concern.

Patient Communication

Patient facing AI should clearly identify the limits of the service.

The system should not present itself as a physician or imply that it can address emergencies unless it has been specifically designed and approved for that function.

Clinical questions, urgent symptoms, complaints, medication issues and complex financial matters should be escalated to qualified personnel.

The organization should test whether the system communicates accurately across language, literacy and disability considerations.

Conversation records should be retained when required to support patient care, complaints, privacy review or quality monitoring.

Algorithmic Bias and Fairness

The organization should evaluate whether AI performance differs across relevant populations.

Assessment may consider age, sex, disability, language, insurance status, geography, race, ethnicity and other factors when legally and operationally appropriate.

Bias may arise from training data, incomplete representation, historical practice patterns, proxy variables, measurement error or workflow implementation.

A model may perform well overall while producing unacceptable errors for a smaller population.

Fairness review should be appropriate to the use case and should focus on whether the system creates unequal access, inaccurate recommendations, inappropriate prioritization or disproportionate denial risk.

Privacy

AI systems should receive protected health information only after the organization has evaluated the purpose, authority and minimum information required.

The organization should determine whether prompts, uploads and outputs are stored, retained, used for training, reviewed by vendor personnel or transmitted to subcontractors.

Public artificial intelligence systems should not receive protected health information without formal approval, appropriate contractual safeguards and applicable legal authority.

The organization should understand whether data are used to improve a vendor’s general model and whether the organization can prohibit that use.

Cybersecurity

Artificial intelligence systems should undergo security review before integration.

The review should evaluate authentication, encryption, privileged access, logging, vulnerabilities, interfaces, data exports, application programming interfaces, model access, incident response and subcontractors.

AI systems can create new attack surfaces and can amplify compromised access because they may connect several sources of sensitive data.

The organization should include artificial intelligence vendors in security risk analysis, business continuity planning and incident response exercises.

Data Quality

AI performance depends on the quality and relevance of its data.

The organization should evaluate completeness, accuracy, timeliness, consistency, lineage and representativeness.

Duplicate records, incorrect patient matching, outdated payer policies, incomplete procedure histories and inconsistent coding can produce unreliable outputs.

Data quality problems should not be corrected by allowing the model to infer missing information.

The organization should identify the authoritative source for each critical data element.

Explainability and Transparency

The level of explanation required should correspond to the significance of the decision.

Users should understand the purpose of the model, the information it considers, its limitations and the meaning of its output.

When an AI recommendation affects patient access, medical necessity, coding, clinical care or financial responsibility, the organization should be able to explain how the output was used and who made the final decision.

The system should not be implemented in a manner that makes meaningful human review impossible.

Model Change Management

Artificial intelligence systems may change through retraining, vendor updates, model replacement, configuration changes or changes in underlying data.

The organization should require notification of material changes.

A change that affects performance, intended use, data handling, user interface or decision logic should trigger review and possible revalidation.

The approved version should be documented.

The organization should not assume that a model validated during implementation will perform identically after repeated vendor updates.

FDA lifecycle guidance reflects the importance of managing AI enabled device performance and modifications throughout the product lifecycle.

Continuous Performance Monitoring

AI systems should be monitored after implementation.

Measures should reflect the intended use and may include error rate, override rate, agreement with human review, missed findings, false alerts, user complaints, processing time, downstream denials, documentation corrections and patient safety events.

Performance should be segmented when meaningful by specialty, provider, payer, location and patient population.

The organization should establish thresholds requiring investigation, retraining, restriction or suspension.

A model that performed acceptably during initial validation may deteriorate when workflows, populations or payer requirements change.

Automation Bias

Automation bias occurs when users accept system recommendations too readily because the output appears authoritative.

Training should instruct users to evaluate the evidence and identify situations in which the recommendation conflicts with the clinical record, policy or professional judgment.

Leadership should not create productivity expectations that make independent review unrealistic.

A reviewer who is expected to approve hundreds of AI outputs without adequate time is not providing meaningful human oversight.

AI Incident Reporting

The organization should maintain a process for reporting AI errors and concerns.

Reportable events may include inaccurate clinical recommendations, fabricated documentation, unauthorized disclosure, biased outcomes, incorrect coding, inappropriate patient communication, system malfunction, model drift and vendor security incidents.

AI incidents should be logged, classified, investigated and reported to leadership according to severity.

The organization should determine whether affected patients, claims, records or decisions require review.

Corrective Action

AI corrective action may include prompt modification, workflow redesign, user education, access restriction, model reconfiguration, data correction, expanded human review, vendor remediation or system suspension.

The organization should determine the affected period and population.

When AI generated errors affected claims or patient records, appropriate correction, notification, repayment or clinical follow up should be evaluated.

Corrective action should be validated before the system returns to unrestricted use.

Vendor Contract Requirements

AI vendor contracts should address intended use, data ownership, permitted data use, model training, subcontractors, security, performance, updates, audit rights, incident reporting, indemnification, record retention, termination and data return.

The organization should retain the right to obtain sufficient information to evaluate performance and investigate incidents.

Confidentiality or proprietary model protections should not prevent the organization from obtaining information necessary to protect patients, comply with law or respond to regulators.

The vendor should not change material functionality without notice.

Workforce Training

Users should receive training on approved use, limitations, verification responsibilities, privacy, security, reporting and prohibited activities.

Training should be role specific.

Physicians need different instruction from coders, authorization specialists, executives and information technology personnel.

Competency should be validated for high risk applications.

The organization should not assume that familiarity with consumer artificial intelligence establishes competency to use healthcare AI safely.

Decommissioning

The organization should maintain a formal process for retiring an AI system.

The process should address user access, interfaces, data return, data destruction, record retention, unresolved incidents, replacement workflows and vendor obligations.

The organization should preserve records necessary to explain decisions made while the system was active.

Decommissioning should be considered when performance is unacceptable, the vendor cannot meet requirements, the use case is no longer necessary or a safer alternative is available.

AI Governance Performance Measures

Leadership should monitor the number of approved and unapproved AI tools, risk classification, validation completion, incidents, override rates, unresolved vendor findings, model changes, training completion and corrective action status.

Metrics should measure safety and control effectiveness rather than AI adoption alone.

Rapid adoption without governance should not be presented as digital maturity.

Application to MSK Specialty Care

Pain management, orthopedics, spine, neurosurgery, neuromodulation and ambulatory surgery centers may use AI for documentation, medical necessity review, procedure history, prior authorization, coding and audit prevention.

These workflows require precise information concerning anatomical region, laterality, spinal levels, previous procedures, percentage of relief, duration of relief, conservative treatment and payer policy.

An AI system that omits or invents one of these elements can produce a denial, unsupported procedure, inaccurate claim or patient safety risk.

GoHealthcare emphasizes that AI governance must connect accuracy, transparency, human oversight, privacy, auditability and accountability across the full healthcare operating environment.

GoHealthcare Insights

Artificial intelligence should strengthen professional judgment, not obscure responsibility.

The organization creates value when AI identifies missing information, unusual patterns and workflow risk before the patient or claim is affected.

It creates exposure when users accept AI output without verification or when leadership deploys technology without understanding its limitations.

Leadership Perspective

AI governance is not a technology restriction program.

It is the operating discipline that allows healthcare organizations to adopt artificial intelligence with greater speed, confidence and accountability.

Organizations that govern AI early can scale successful use cases more effectively because expectations, evidence and decision rights are already established.

Key Takeaways

Every AI use case should have an approved purpose, accountable owner, risk classification and monitoring plan.

High risk outputs require qualified human review and final human accountability.

AI vendors, model changes, data use, bias, privacy, security and performance must be governed throughout the full lifecycle.

Back to framework navigation
37

Audit Readiness, Regulatory Performance and Continuous Improvement

Purpose

Audit Readiness, Regulatory Performance and Continuous Improvement establish the integrated operating system required to prepare for external review, respond accurately to record requests, measure compliance performance, resolve findings and continually strengthen the organization’s control environment.

Audit readiness is not created when an audit letter arrives.

It is created during patient intake, clinical documentation, medical necessity review, prior authorization, scheduling, coding, claim submission, payment posting, record retention, policy implementation and corrective action.

A healthcare organization is audit ready when it can retrieve complete records, identify the controlling requirement, explain the workflow, demonstrate oversight and respond within the required timeframe.

CMS explains that an Additional Documentation Request is issued when medical records are needed to support payment and demonstrate compliance with Medicare coverage, coding, billing and payment requirements. Medicare contractors may require information from periods before the reviewed service when those records support the claim.

Audit Readiness Governance

The organization should establish a formal Audit Readiness Program.

The program should define oversight, request intake, deadline management, record retrieval, clinical review, coding review, legal involvement, submission authority, payer communication, appeal responsibility and governing body reporting.

Compliance should coordinate the program, but operational departments remain responsible for maintaining complete and accurate records.

The organization should identify a central point of receipt for government, payer, licensing, accreditation and contractual review requests.

Requests sent to individual providers, locations or former employees should be routed immediately to the designated audit response function.

Audit Universe

The organization should maintain an inventory of external review mechanisms that may affect its operations.

The audit universe may include Medicare Administrative Contractor reviews, Additional Documentation Requests, Targeted Probe and Educate, Recovery Audit Contractors, Unified Program Integrity Contractors, Supplemental Medical Review Contractors, Comprehensive Error Rate Testing, commercial payer reviews, Medicaid audits, licensing reviews, accreditation surveys, privacy investigations and contractual audits.

Different review types have different purposes, authority, deadlines, appeal rights and documentation expectations.

Personnel should not respond to every review through the same generic process.

CMS states that Medicare Fee for Service medical reviews may be conducted by several types of contractors and programs, including Medicare Administrative Contractors, Supplemental Medical Review Contractors, Recovery Audit Contractors and Unified Program Integrity Contractors.

Central Audit Request Log

Every external request should be entered into a centralized log.

The log should identify the requesting entity, date received, response deadline, patient, claim, provider, procedure, date of service, review type, requested records, assigned owner, submission method, confirmation and outcome.

The log should capture correspondence, extensions, additional requests, determinations, appeals, recoupments and final resolution.

The organization should not rely on individual email inboxes or local office tracking for material audits.

Missed deadlines can convert a clinically supported service into a denial or recoupment.

Request Verification

The organization should verify the authenticity and authority of the requesting party.

Verification should include the payer or agency, patient, claim, dates, contact information, submission address and requested scope.

Suspicious requests should be evaluated before patient information is released.

The organization should confirm whether the request permits secure portal submission, electronic transfer, mail or another method.

Protected information should not be sent through unapproved channels.

Deadline Management

Audit deadlines should be entered into a tracked calendar with internal completion dates earlier than the official deadline.

The organization should allow enough time for retrieval, clinical review, coding review, legal evaluation, quality assurance and submission confirmation.

Requests for extensions should be made promptly when available and necessary.

An extension should not be assumed until the requesting entity confirms it.

Leadership should receive immediate notice when a material response may be late.

Medical Review Correspondence Address

The organization should ensure that Medicare correspondence addresses remain current.

CMS states that Additional Documentation Requests are sent to the practice address on file and advises providers to maintain the correct Medical Review Correspondence Address through the Provider Enrollment, Chain, and Ownership System.

Credentialing and enrollment teams should coordinate address changes with compliance and audit response personnel.

A valid audit request should not go unanswered because it was delivered to a former location or outdated contact.

Record Retrieval

The organization should be able to retrieve complete records from current systems, legacy platforms, scanned documents, vendor systems and external clinical sources.

The retrieval process should identify clinical notes, procedure reports, orders, diagnostic results, imaging, treatment history, authorization, coding, claims and supporting communications.

Records should be organized in a logical sequence.

The organization should not submit isolated pages when the reviewer requires longitudinal evidence.

Retrieval performance should be tested before an actual audit.

Documentation Completeness

Audit records should demonstrate the patient’s condition, clinical assessment, medical necessity, treatment history, procedure eligibility, service performed and outcome.

The organization should identify missing signatures, incomplete notes, absent orders, contradictory information and unavailable historical records before submission.

A record should not be altered to correct a deficiency after receipt of the audit request.

Legitimate late entries or corrections should follow applicable standards and should not create information that was not known or documented originally.

Longitudinal Record Review

MSK audits frequently require information from more than one encounter.

The organization may need to produce previous procedures, dates, anatomical region, laterality, levels, diagnostic block results, percentage of relief, duration of relief, functional improvement, conservative treatment and imaging.

The current procedure note may be technically complete but still fail to establish medical necessity without this history.

CMS indicates that documentation preceding the review period may be necessary when it supports the billed service.

Applicable Requirement Identification

The organization should identify the rule or policy effective on the date of service.

The review should consider National Coverage Determinations, Local Coverage Determinations, billing and coding articles, CMS manuals, payer policies, contracts, code sets and authorization requirements.

Later policy versions should not be applied retrospectively without legal or contractual authority.

The response file should preserve the policy version used in the organization’s review when practical.

Clinical Review

A qualified clinician should review whether the record supports the service.

Clinical review should consider diagnosis, symptoms, examination, imaging, conservative care, previous treatment, patient response, procedure sequence and ongoing need.

The reviewer should determine whether the procedure performed matches the documented plan and whether patient specific factors support the intervention.

Clinical review should not be limited to confirming that expected phrases appear in the note.

Coding Review

A qualified coding professional should confirm the procedure code, diagnosis, modifiers, units, levels, laterality, place of service and code combinations.

The coding review should evaluate the complete documentation rather than the original claim alone.

When the code is inaccurate, the organization should determine whether correction, refund, appeal or other action is appropriate.

The organization should distinguish coding error from medical necessity, authorization or documentation failure.

Authorization Review

The audit review should determine whether authorization was required, obtained from the correct entity and valid for the service performed.

The approval should match the patient, provider, facility, procedure, code, anatomical level, laterality, units and date.

Authorization does not independently establish medical necessity, but a missing or mismatched authorization may affect payment and contractual compliance.

Claim and Payment Reconciliation

The response team should compare what was ordered, authorized, scheduled, performed, documented, coded, billed and paid.

Differences should be explained or corrected.

The organization should review claim adjustments, prior appeals, secondary billing, patient responsibility, refunds and recoupments associated with the service.

Audit readiness requires the ability to reconstruct the complete financial transaction.

Submission Quality Assurance

A second qualified reviewer should confirm that the response is complete, accurate, organized and directed to the correct recipient.

The submission should include the request letter when appropriate and should identify the patient and claim clearly.

Records should be arranged so the reviewer can follow the clinical pathway.

The organization should avoid submitting unrelated information that increases privacy exposure or obscures the relevant evidence.

Submission confirmation should be retained.

Response Narrative

A response narrative may be appropriate when the record is complex or requires explanation.

The narrative should be factual and supported by the underlying documentation.

It may identify the service, clinical rationale, relevant history, authorization and applicable policy.

The narrative should not create new clinical facts or attempt to repair missing documentation.

Qualified personnel should approve material narratives before submission.

Legal Review

Legal counsel should be involved when the request presents significant financial exposure, extrapolation, suspected fraud, government investigation, privilege concerns, licensing risk or potential disclosure obligations.

Routine record requests do not necessarily require legal control of the entire response.

The organization should establish thresholds for legal involvement so that significant matters are escalated without delaying ordinary operational reviews.

Targeted Probe and Educate

CMS describes Targeted Probe and Educate as a program intended to help providers reduce claim denials and appeals through focused claim review and individualized education from Medicare Administrative Contractors.

The organization should treat Targeted Probe and Educate as a significant compliance signal.

Leadership should understand the reason for selection, claims reviewed, identified errors, education received and required corrective action.

Education should be translated into revised workflows, provider feedback, monitoring and follow up auditing.

The organization should not wait for later review rounds before addressing known deficiencies.

Recovery Audit Contractor Reviews

The Medicare Fee for Service Recovery Audit Program identifies and corrects improper payments, including overpayments and underpayments.

The organization should monitor approved Recovery Audit Contractor topics relevant to its services.

When a review occurs, the response should address the specific claim and evaluate whether similar claims may be affected.

Recoupment notices, discussion periods and appeal deadlines should be coordinated through one accountable process.

Commercial Payer Audits

Commercial payer audits may involve medical necessity, coding, authorization, contract compliance, provider participation, payment accuracy or suspected overutilization.

The organization should review the contract and payer manual before responding.

It should identify record production rights, lookback periods, extrapolation provisions, dispute processes and recoupment authority.

Commercial payer requests should receive the same record integrity and quality assurance applied to government audits.

Accreditation and Licensing Surveys

Facility and professional organizations should maintain continuous survey readiness.

Policies, credentialing, infection control, quality improvement, emergency preparedness, patient rights and corrective action records should reflect actual operations.

Personnel should understand their roles and be able to locate required evidence.

Survey readiness should not depend on creating temporary documents immediately before the reviewer arrives.

Mock Audits

The organization should conduct risk based mock audits.

A mock audit should simulate actual record selection, retrieval, deadline management, clinical review, coding analysis and submission preparation.

The exercise should identify retrieval delays, missing historical records, inconsistent policies, incomplete documentation and unclear decision authority.

Results should be reported to the compliance committee and converted into corrective action.

Audit Sampling

Internal sampling should include both paid and denied claims.

Reviewing only denied claims may miss unsupported claims that were paid.

Reviewing only paid claims may miss operational failures that prevented correct payment.

Sampling should consider high volume services, high value procedures, repeat services, new providers, new locations, modifier use, unusual units and prior findings.

The methodology should be documented.

Data Analytics

Data analytics should identify outliers before external reviewers do.

Relevant measures may include procedure frequency, provider variation, modifier use, diagnosis patterns, units, place of service, denial reasons, authorization failures, refunds, credit balances and coding changes.

Analytics identify risk and direct review.

They do not establish that a claim is incorrect without examination of the clinical and operational facts.

GoHealthcare emphasizes that audit prevention should use proactive pattern detection across documentation, medical necessity, coding and payer behavior rather than waiting for an external request.

Audit Findings Classification

Findings should be classified according to cause and severity.

Categories may include missing documentation, medical necessity, coding, authorization, signature, frequency, enrollment, claim processing, overpayment, patient safety or intentional conduct.

The organization should distinguish isolated errors from systemic weaknesses.

A finding involving one record may require expanded review when the cause is a template, system edit, training deficiency or management instruction.

Financial Exposure

The organization should quantify potential financial exposure using a defensible methodology.

The review should identify the affected claims, period, payer, provider, procedure and cause.

Statistical extrapolation should not be performed internally without appropriate expertise.

Leadership should understand the difference between the reviewed sample, known affected claims and estimated broader exposure.

Potential overpayments should enter the organization’s formal investigation and repayment process.

Appeals

Appeals should be filed when the record, policy and facts support disagreement with the determination.

The organization should identify the appeal level, deadline, evidence and responsible owner.

Appeals should not contain altered documentation or unsupported clinical explanations.

A successful appeal should not prevent the organization from correcting weaknesses that made the claim difficult to defend.

Appeal outcomes should be incorporated into provider education, policy management and payer intelligence.

Corrective Action

Every material audit finding should produce a documented corrective action assessment.

Actions may include claim correction, repayment, education, template changes, scheduling controls, authorization review, coding edits, vendor remediation or expanded auditing.

The plan should identify the root cause, owner, completion date, evidence and validation method.

The organization should not close a finding because a training session occurred.

It should verify that performance improved.

Regulatory Performance Scorecard

Leadership should maintain a Regulatory Performance Scorecard.

Measures may include audit response timeliness, record retrieval time, documentation completeness, error rate, appeal success, recoupment amount, overpayment resolution, repeat findings, corrective action completion, policy implementation, training competency and unresolved high risk issues.

Metrics should be defined consistently.

The scorecard should distinguish volume from effectiveness.

A large number of completed audits is not a favorable result when the same deficiency continues to recur.

Compliance Program Effectiveness

The organization should evaluate whether its compliance program is well designed, adequately resourced and effective in practice.

The Department of Justice uses these fundamental questions when evaluating corporate compliance programs and also examines whether organizations test remedial controls to determine whether similar misconduct would be prevented or detected.

The HHS Office of Inspector General General Compliance Program Guidance provides voluntary guidance concerning compliance leadership, risk assessment, auditing, monitoring, investigations and corrective action.

The organization should use these resources as governance references while adapting its program to its size, specialties, services and risk profile.

Governing Body Reporting

The governing body should receive regular reports concerning material audits, trends, financial exposure, investigations, appeals, corrective actions and unresolved risks.

Reports should explain what occurred, why it occurred, which controls failed and whether the response is working.

The governing body should challenge repeated findings and overdue corrective actions.

Board oversight should be documented through minutes, decisions and follow up.

Continuous Improvement Cycle

Continuous improvement should connect risk assessment, monitoring, audits, investigations, corrective action and strategic planning.

Every finding should be treated as information about the operating system.

Leadership should determine whether the issue affects policies, technology, staffing, training, incentives, vendor oversight or governance.

Improvement should be measured over time.

A corrective action that does not reduce the error, denial or recurrence rate should be reconsidered.

Lessons Learned

Audit outcomes should be translated into organizational learning.

Deidentified examples can be used in education, policy development and leadership reporting.

Lessons should be shared with departments that may face similar exposure.

An authorization finding in one payer population may reveal a workflow weakness affecting other payers.

A coding error associated with one procedure may indicate that the same modifier logic is incorrect throughout the system.

Compliance Maturity

The organization should assess its compliance maturity periodically.

An initial organization may rely on reactive problem resolution and individual expertise.

A developing organization may have formal policies, committees and scheduled audits.

A mature organization integrates compliance controls into technology, workflows, performance management and leadership decisions.

An advanced organization uses data analytics, predictive risk identification, automated controls and verified continuous improvement while preserving qualified human oversight.

Maturity should be demonstrated through evidence, not self designation.

Application to MSK Specialty Care

Pain management, orthopedics, spine, neurosurgery, neuromodulation and ambulatory surgery centers face concentrated audit risk because services frequently involve strict medical necessity, procedural sequencing, frequency requirements, anatomical specificity, implants, modifiers and multiple sites of service.

Audit readiness should follow the complete care and revenue pathway.

The organization should be able to show why the patient qualified, what was authorized, what was performed, how the record supported the service, how the claim was coded and how payment was resolved.

GoHealthcare’s MSK Compliance and Audit Readiness resource positions audit readiness as an operating system that connects clinical documentation, payer policy, authorization, coding, billing and leadership oversight.

GoHealthcare Insights

Audit readiness is not a binder, checklist or annual project.

It is the ability to demonstrate that the organization’s clinical, administrative and financial systems operate consistently and produce reliable evidence.

The strongest audit response is the record and control environment that existed before the reviewer asked for it.

Leadership Perspective

External audits should not be the first time leadership learns how the organization actually works.

Executives should use internal audit results, denial data, procedure trends and corrective action performance to understand risk continuously.

The organization that finds and corrects its own weaknesses retains more options than the organization that waits for a payer or regulator to find them.

Key Takeaways

Audit readiness must be built into the complete patient and revenue cycle pathway.

External requests require centralized intake, qualified review, deadline control, accurate production and documented resolution.

Continuous improvement requires leadership to convert findings into validated changes in policy, technology, workflow and accountability.

Back to framework navigation
MM

GoHealthcare Regulatory and Compliance Maturity Model

Purpose

The GoHealthcare Regulatory and Compliance Maturity Model provides a structured method for evaluating how effectively a healthcare organization governs regulatory obligations, manages risk, implements controls, identifies noncompliance and improves performance.

The maturity model is not intended to determine whether an organization is legally compliant through a single score. It evaluates whether the organization has developed the leadership, infrastructure, workforce capability, technology, evidence and accountability required to manage compliance consistently.

The model aligns conceptually with the HHS Office of Inspector General’s voluntary compliance program guidance, the Department of Justice’s evaluation of whether compliance programs are well designed and effective in practice, and the NIST approach to governing and managing artificial intelligence risk.

Level One: Reactive Compliance

At Level One, the organization responds to compliance concerns primarily after denials, audits, complaints, security incidents, payment recoupments or patient safety events occur.

Compliance responsibilities may be assigned informally to an administrator, billing manager, office manager or attorney without a defined enterprise structure.

Policies may exist, but they are incomplete, outdated, difficult to locate or disconnected from actual workflows.

Risk identification depends heavily on individual knowledge rather than a formal assessment process.

Departments resolve problems independently, which may prevent leadership from recognizing that several isolated events have the same underlying cause.

Auditing is limited or performed only when requested by a payer, regulator or business partner.

Training consists primarily of orientation documents or generic annual modules without role specific instruction or competency validation.

Corrective action focuses on the individual error rather than the workflow, technology, staffing, supervision or incentive structure that allowed the problem to occur.

The governing body receives limited compliance information and may become involved only when the organization faces material financial or legal exposure.

Artificial intelligence and new technology may be used without an inventory, approval process, validation standard or defined human oversight.

An organization at Level One remains vulnerable because compliance depends on informal knowledge, personal effort and crisis response.

Level Two: Foundational Compliance

At Level Two, the organization has established basic compliance infrastructure.

A compliance officer or responsible leader has been designated.

A Code of Conduct, reporting mechanism, nonretaliation policy and core compliance policies are in place.

The organization performs some exclusion screening, privacy training, coding review and claim monitoring.

The governing body receives periodic compliance reports, although the information may focus on completed activities rather than risk, trends and outcomes.

A compliance committee may exist, but meeting frequency, authority, documentation and departmental participation may be inconsistent.

The organization has begun identifying major obligations but may not yet maintain a comprehensive Regulatory Obligation Register, risk inventory or control library.

Audits are scheduled, but the scope may rely on routine annual topics rather than current organizational risk.

Corrective action plans are documented, although effectiveness validation may be limited.

Departments understand that compliance is an organizational responsibility, but accountability remains concentrated within the compliance or revenue cycle function.

Technology controls exist, but system configuration, user access, vendor management and artificial intelligence governance may not be integrated fully into the compliance program.

The organization can respond to routine audits but may experience difficulty retrieving longitudinal records, identifying historical policy versions or reconstructing complex claims.

Level Three: Standardized and Operationalized Compliance

At Level Three, the organization has converted compliance expectations into standardized operating processes.

The governing body has approved the compliance structure and receives regular reports concerning significant risks, audit findings, investigations, overpayments and corrective action.

The compliance officer has defined authority, access to information and direct escalation capability.

The compliance committee operates under a charter and includes clinical, operational, financial, privacy, security, technology and workforce leadership.

The organization performs a documented annual compliance risk assessment and uses the results to develop a risk based Compliance Work Plan.

Material regulatory obligations are assigned to accountable owners and connected to policies, procedures, evidence requirements, monitoring activities and escalation thresholds.

Policies follow a controlled lifecycle involving drafting, review, approval, communication, implementation and periodic testing.

Compliance training is role specific and reflects the organization’s specialties, payer environment and identified deficiencies.

Clinical documentation, medical necessity, authorization, coding, billing, payment and refund controls are designed as connected workflows.

Vendor due diligence, business associate review, contract management and exclusion screening are governed through defined processes.

Artificial intelligence use cases are inventoried, risk classified, approved and monitored.

Audits evaluate not only code accuracy but also documentation, patient selection, medical necessity, authorization, procedure performance and payment integrity.

Corrective action plans include accountable owners, completion dates, evidence requirements and follow up validation.

The organization can retrieve most audit records reliably and can explain how its controls operate.

Level Four: Integrated and Data Informed Compliance

At Level Four, compliance is integrated into strategy, budgeting, operations, technology and leadership decision making.

The governing body evaluates compliance performance together with clinical quality, patient safety, financial performance and enterprise risk.

Compliance review occurs before the organization adopts new service lines, contracts, compensation models, facilities, vendors or artificial intelligence systems.

The Regulatory Obligation Register, risk register, control library, policy inventory, audit plan and corrective action system are connected.

Operational data are used to identify patterns across providers, procedures, payers, locations and service lines.

Key Risk Indicators identify authorization failures, unusual modifier use, procedure frequency, documentation deficiencies, unresolved credit balances, privacy incidents, vendor issues and overdue corrective actions.

Departments perform continuous monitoring while compliance provides independent testing and enterprise oversight.

Leaders are evaluated on compliance performance, timely corrective action and prevention of repeated deficiencies.

The organization can determine where a failure originated, how it moved through the workflow and which controls failed to prevent or detect it.

Artificial intelligence and automation support risk detection, documentation review, policy matching and audit preparation, but qualified personnel remain responsible for final decisions.

Security, privacy, clinical safety, financial integrity and technology risk are coordinated through one governance environment.

Audit responses are centralized, timely, accurate and supported by complete longitudinal evidence.

Level Five: Predictive and Continuously Improving Compliance

At Level Five, the organization operates a predictive, evidence driven and continuously improving compliance system.

Compliance is embedded into the design of clinical, administrative, financial and technological workflows.

Leadership uses data, scenario analysis and emerging risk intelligence to identify exposure before it becomes a denial, audit, overpayment, breach or patient safety event.

Controls prevent unsupported services and claims from moving forward whenever practical.

The organization monitors whether each control remains effective and redesigns controls when operations, regulations, payer requirements or technology change.

Compliance analytics identify developing patterns across documentation, medical necessity, utilization, coding, authorization, site of service, provider behavior and payment.

Artificial intelligence is governed throughout its lifecycle and is used to enhance human judgment rather than replace accountability.

The organization tests adverse scenarios involving cyber incidents, government investigations, payer audits, vendor failure, system outages and serious patient safety events.

Corrective action produces measurable reductions in recurrence, financial exposure and operational failure.

Compliance findings inform strategic planning, staffing, technology investment, contracting and leadership performance.

The governing body can explain the organization’s principal risks, the reliability of major controls and the evidence demonstrating that the compliance program works in practice.

Maturity Assessment Standard

Organizations should evaluate maturity by evidence rather than intention.

A written policy does not demonstrate maturity unless the workforce understands it and the associated control operates consistently.

A compliance committee does not demonstrate maturity unless it identifies risks, makes decisions, assigns action and verifies resolution.

An audit program does not demonstrate maturity unless findings produce sustained improvement.

Artificial intelligence governance does not demonstrate maturity unless use cases are inventoried, validated, monitored and subject to meaningful human oversight.

The organization should reassess maturity annually and after major acquisitions, service expansion, technology implementation, payer enforcement activity, government inquiry or material compliance failure.

Back to framework navigation
IP

Implementation Priorities

Priority One: Activate Governance and Leadership Accountability

The organization should begin by confirming the authority and accountability structure.

The governing body should approve the Regulatory, Risk and Compliance Governance Charter.

A qualified compliance officer should be designated with direct access to executive leadership and the governing body.

The compliance committee should be established under a written charter identifying membership, responsibilities, meeting frequency, documentation standards and escalation authority.

Leadership should define which matters require immediate escalation, including patient harm, suspected fraud, significant overpayments, falsification, privacy breaches, excluded individuals, retaliation, controlled substance diversion and government inquiries.

The governing body should approve a reporting schedule that provides visibility into material risks, audits, investigations, corrective actions and unresolved deficiencies.

Priority Two: Build the Regulatory Obligation Register

The organization should identify the federal, state, payer, contractual, accreditation and professional requirements affecting its operations.

Each material obligation should be assigned to an accountable owner.

The register should identify the authoritative source, affected entity, affected workflow, operational control, evidence requirement, monitoring frequency and review date.

The obligation register should distinguish laws and regulations from agency guidance, payer policies, contract terms and internal organizational standards.

Requirements should be translated into practical workflows rather than stored only as legal summaries or policy documents.

Priority Three: Complete the Enterprise Compliance Risk Assessment

The organization should conduct a formal risk assessment reflecting its actual providers, specialties, procedures, payers, locations, facilities, vendors, technology and workforce structure.

The assessment should use internal and external information.

Internal information should include denials, audits, complaints, investigations, authorization failures, documentation deficiencies, privacy incidents, credit balances, refunds, employee reports and patient safety events.

External information should include OIG guidance, CMS review activity, enforcement developments, payer policy changes, licensing requirements, cybersecurity threats and professional standards.

The organization should assess inherent risk, existing controls, control reliability and residual exposure.

High risk areas should be assigned immediate mitigation, audit or monitoring activity.

Priority Four: Map Controls Across the Patient and Revenue Pathway

The organization should map the complete operational pathway from referral and registration through clinical care, authorization, coding, billing, payment, refund and record retention.

Every critical workflow should contain preventive, detective and corrective controls.

Preventive controls should stop unsupported activity before it occurs.

Detective controls should identify errors, exceptions and unusual patterns.

Corrective controls should address the consequence, resolve financial exposure and prevent recurrence.

Control mapping should identify who performs the control, when it occurs, which system supports it, what evidence it produces and how failure is escalated.

Priority Five: Standardize Policies and Procedures

The organization should establish a controlled policy inventory.

Duplicate, expired, contradictory and informal documents should be identified.

Each policy should have an owner, approval authority, effective date, review date, version history and related procedures.

Policies should define organizational expectations.

Procedures should explain who performs the work, what must be completed, when it occurs, what evidence is created and what happens when the standard cannot be met.

Material policy changes should be communicated before implementation and followed by training or competency validation.

Priority Six: Strengthen Workforce Capability

Every workforce member should understand the Code of Conduct, reporting channels, nonretaliation protections and responsibilities associated with their role.

Training should be tailored to physicians, clinical staff, authorization personnel, schedulers, coders, billers, managers, technology staff, remote workers and contractors.

High risk functions should require competency validation rather than attendance alone.

Education should address actual workflow risks and use realistic specialty examples.

Training effectiveness should be evaluated through performance, audit results, error rates and reduction of repeat findings.

Priority Seven: Establish Risk Based Auditing and Continuous Monitoring

The annual Compliance Work Plan should identify the organization’s highest residual risks.

Audits should evaluate complete clinical and revenue pathways rather than isolated claim elements.

Monitoring should occur continuously or periodically within operational departments.

Compliance should validate monitoring and perform independent risk based audits.

Audit criteria, population, sample methodology, findings and corrective action should be documented.

Follow up testing should determine whether corrective action reduced the underlying risk.

Priority Eight: Strengthen Reporting, Investigation and Corrective Action

The organization should maintain several confidential reporting channels and enforce nonretaliation protections.

Every report should enter a centralized disclosure log and receive documented risk classification.

Investigations should be objective, appropriately scoped and conducted by qualified personnel.

Evidence preservation, interviews, data analysis, legal involvement and findings standards should be defined.

Corrective action should address patient impact, financial exposure, individual accountability, workflow design, technology, supervision and organizational incentives.

Material findings should remain open until effectiveness has been validated.

Priority Nine: Govern Vendors, Security and Artificial Intelligence

All material vendors should be inventoried, risk classified and assigned to accountable owners.

Due diligence should evaluate qualifications, privacy, cybersecurity, subcontractors, data use, financial stability, incident response and operational continuity.

Business Associate Agreements should reflect the actual service and data relationship.

Artificial intelligence use cases should be inventoried, risk classified, validated and approved before implementation.

High risk AI output should require qualified human review.

Security risk analysis should include internal systems, cloud platforms, remote access, vendors, artificial intelligence applications and legacy technology.

Incident response and business continuity plans should be tested through realistic exercises.

Priority Ten: Build Continuous Audit Readiness

External audit requests should be received and managed through a centralized process.

The organization should maintain a request log, deadline controls, secure submission methods and quality assurance review.

Medical, authorization, coding, billing and payment records should be retrievable from current, legacy and vendor systems.

Mock audits should test whether the organization can produce complete longitudinal evidence within realistic deadlines.

Audit outcomes should inform risk assessment, policy revision, training, technology, staffing and strategic planning.

Back to framework navigation
IN

GoHealthcare Insights

Regulatory compliance is not a department added to the side of healthcare operations.

It is the operating discipline that keeps clinical care, payer requirements, organizational behavior, technology and financial representations aligned.

Most compliance failures are not created by one department acting alone.

A documentation deficiency may prevent authorization, create incorrect coding, cause a denial, produce an unsupported appeal and result in a payment that cannot be defended.

A privacy problem may originate through vendor access, remote workforce practices, weak authentication and inadequate contract oversight.

A patient safety event may begin with scheduling, incomplete medication reconciliation, incorrect anatomical information or a system design that allowed critical information to be overlooked.

The organization should therefore evaluate compliance through connected pathways rather than isolated functions.

In MSK specialty care, longitudinal information is particularly important.

Previous procedures, dates, anatomical levels, laterality, percentage of relief, duration of relief, functional improvement, imaging, conservative treatment and payer frequency requirements may determine whether the next service is clinically appropriate, authorized, billable and defensible.

Compliance excellence is created before the procedure and before the claim.

The organization should identify unsupported, incomplete or misaligned cases while there is still an opportunity to correct the workflow, clarify the record, obtain proper authorization or reconsider the service.

Artificial intelligence can strengthen this model by identifying missing information, unusual patterns and policy misalignment at scale.

It cannot replace physician judgment, qualified coding review, clinical utilization management, privacy accountability or governing body oversight.

The organization remains responsible for every decision, record, claim and patient communication made in its name.

Back to framework navigation
LP

Leadership Perspective

Regulatory, risk and compliance excellence begins with leadership behavior.

Employees evaluate the seriousness of compliance by observing what leaders do when compliance affects revenue, productivity, physician relationships or strategic growth.

A leader who approves policies but tolerates exceptions for influential individuals communicates that the policies are optional.

A governing body that receives reports but does not challenge repeated findings provides oversight in form rather than substance.

A compliance officer who lacks authority, information or resources cannot protect the organization effectively.

A mature leadership team welcomes accurate risk information.

It does not judge the compliance program by how few concerns are reported.

It judges the program by whether concerns surface early, investigations establish the facts, corrective actions address root causes and the organization becomes more reliable over time.

Compliance should not prevent responsible growth.

It should make growth sustainable by ensuring that new services, facilities, vendors, compensation arrangements and artificial intelligence systems are designed with appropriate controls from the beginning.

The strongest healthcare organizations do not choose between operational performance and compliance.

They recognize that clinical credibility, patient trust, reimbursement integrity, audit readiness and organizational value depend on both.

Back to framework navigation
KT

Key Takeaways

The GoHealthcare Regulatory, Risk & Compliance Excellence Framework™ establishes an enterprise operating model rather than a collection of independent policies.

Governance begins with the governing body and executive leadership.

The compliance officer requires authority, independence, resources, information access and direct escalation capability.

Every material regulatory obligation should be assigned to an operational owner and connected to controls, evidence, monitoring and escalation.

Compliance risk assessment should determine the annual work plan, audit priorities, training and resource allocation.

Clinical documentation, medical necessity, authorization, coding, billing and payment should operate as one connected integrity pathway.

Trusted reporting, nonretaliation, objective investigations and effective corrective action are essential to early risk detection.

Privacy, cybersecurity, record retention, vendor management and workforce governance must extend across remote, outsourced and technology enabled operations.

Artificial intelligence requires formal governance, local validation, human oversight, lifecycle monitoring and clear final accountability.

Audit readiness must be created during daily operations rather than assembled after an external request arrives.

Continuous improvement occurs only when the organization verifies that corrective action reduced the identified risk.

Back to framework navigation
AR

Consolidated Authoritative Regulatory References

The URLs below were accessible when verified on July 22, 2026. Official government and primary sources should be reviewed for updates before the framework is applied to a specific organization, transaction, payer, jurisdiction or date of service.

HHS Office of Inspector General

General Compliance Program Guidance

https://oig.hhs.gov/compliance/general-compliance-program-guidance/

Complete General Compliance Program Guidance PDF

https://oig.hhs.gov/documents/compliance-guidance/1135/HHS-OIG-GCPG-2023.pdf

OIG Compliance Guidance

https://oig.hhs.gov/compliance/compliance-guidance/

OIG Compliance Resources

https://oig.hhs.gov/compliance/

OIG Compliance Programs for Physicians

https://oig.hhs.gov/compliance/physician-education/compliance-programs-for-physicians/

OIG Work Plan

https://oig.hhs.gov/reports/work-plan/about-the-work-plan/

OIG Exclusions Program

https://oig.hhs.gov/exclusions/

Searchable OIG Exclusions Database

https://exclusions.oig.hhs.gov/

OIG Fraud and Abuse Laws

https://oig.hhs.gov/compliance/physician-education/fraud-abuse-laws/

OIG Safe Harbor Regulations

https://oig.hhs.gov/compliance/safe-harbor-regulations/

OIG Physician Relationships With Vendors

OIG’s current compliance resources describe the General Compliance Program Guidance as voluntary and nonbinding and maintain additional industry and physician compliance resources.

https://oig.hhs.gov/compliance/physician-education/iii-physician-relationships-with-vendors/

U.S. Department of Justice

Evaluation of Corporate Compliance Programs

https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl

DOJ Compliance Resources

https://www.justice.gov/criminal/criminal-fraud/compliance

Principles of Federal Prosecution of Business Organizations

https://www.justice.gov/jm/jm-9-28000-principles-federal-prosecution-business-organizations

False Claims Act

DOJ’s compliance evaluation guidance asks whether a program is well designed, applied earnestly and capable of working in practice. DOJ’s Justice Manual also identifies the adequacy and effectiveness of a corporate compliance program as relevant to prosecutorial decisions.

https://www.justice.gov/civil/false-claims-act

Centers for Medicare & Medicaid Services

Medicare Fee for Service Compliance Programs

https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs

Medical Review and Education

https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-and-education

Additional Documentation Requests

https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-education/additional-documentation-request

Targeted Probe and Educate

https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-and-education/targeted-probe-and-educate-tpe

Medicare Fee for Service Recovery Audit Program

https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medicare-fee-service-recovery-audit-program

Medicare Provider Compliance Tips

https://www.cms.gov/training-education/medicare-learning-networkr-mln/compliance/medicare-provider-compliance-tips

Medicare Coverage Database

https://www.cms.gov/medicare-coverage-database/search.aspx

Medicare Program Integrity Manual

https://www.cms.gov/regulations-and-guidance/guidance/manuals/internet-only-manuals-ioms-items/cms019033

Medicare Claims Processing Manual

https://www.cms.gov/regulations-and-guidance/guidance/manuals/internet-only-manuals-ioms-items/cms018912

National Correct Coding Initiative

https://www.cms.gov/medicare/coding-billing/national-correct-coding-initiative-ncci-edits

Prior Authorization and Preclaim Review Initiatives

https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/prior-authorization-and-pre-claim-review-initiatives

Electronic Prior Authorization

CMS describes Medicare Fee for Service compliance programs as mechanisms for preventing, reducing and measuring improper payments through medical review. Its Additional Documentation Request guidance identifies several contractor types that may review documentation for coverage, coding, billing and medical necessity.

https://www.cms.gov/priorities/electronic-prior-authorization/overview

HHS Privacy, Security and Breach Resources

HIPAA Privacy Rule

https://www.hhs.gov/hipaa/for-professionals/privacy/index.html

HIPAA Security Rule

https://www.hhs.gov/hipaa/for-professionals/security/index.html

Security Risk Analysis Guidance

https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html

HIPAA Breach Notification Rule

https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html

Business Associate Guidance

https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html

HIPAA Right of Access

https://www.hhs.gov/hipaa/for-individuals/right-to-access/index.html

Artificial Intelligence Governance

NIST Artificial Intelligence Risk Management Framework

https://www.nist.gov/itl/ai-risk-management-framework

NIST AI Risk Management Framework Resource Center

https://airc.nist.gov/airmf-resources/airmf/

NIST Generative Artificial Intelligence Profile

https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence

FDA Artificial Intelligence Enabled Medical Devices

https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-enabled-medical-devices

ONC HTI 1 Final Rule

NIST’s AI Risk Management Framework uses the functions Govern, Map, Measure and Manage to organize voluntary AI risk management activities.

https://healthit.gov/regulations/hti-rules/hti-1-final-rule/

Patient Safety, Controlled Substances and Consumer Protection

Agency for Healthcare Research and Quality Patient Safety

https://www.ahrq.gov/patient-safety/index.html

AHRQ Ambulatory Surgery Center Patient Safety Culture Survey

https://www.ahrq.gov/sops/surveys/asc/index.html

Drug Enforcement Administration Controlled Substances Act

https://www.dea.gov/drug-information/csa

CDC Clinical Practice Guideline for Prescribing Opioids for Pain

https://www.cdc.gov/mmwr/volumes/71/rr/rr7103a1.htm

CMS No Surprises Act

https://www.cms.gov/nosurprises

CMS Provider Requirements and Resources

https://www.cms.gov/nosurprises/policies-and-resources/provider-requirements-and-resources

CMS Good Faith Estimate Guidance

https://www.cms.gov/medical-bill-rights/help/guides/good-faith-estimate
Back to framework navigation
GH

Consolidated Related GoHealthcare Reading

The following GoHealthcare website and blog URLs were accessible when verified on July 22, 2026.

Compliance and Audit Readiness in MSK Specialty Care

This resource addresses the connection among documentation, medical necessity, authorization, coding, billing and audit readiness in MSK specialty care.

https://www.gohealthcarellc.com/compliance-audit-readiness-msk-specialty-care.html

Revenue Integrity for Pain, Spine and MSK Specialty Care

This resource explains how authorization, documentation, coding, claims, payments, refunds and compliance function as one revenue integrity continuum.

https://www.gohealthcarellc.com/revenue-integrity-msk-specialty-care.html

GoHealthcare RCM Framework™ for MSK Specialty Care

The framework provides the broader revenue cycle structure supporting documentation, coding, authorization, claims, payment and compliance operations.

https://www.gohealthcarellc.com/rcm-framework.html

Pain Management Prior Authorization

This resource addresses procedure specific medical necessity, conservative treatment, clinical findings, imaging and documentation requirements in interventional pain management.

https://www.gohealthcarellc.com/pain-management-prior-authorization.html

AI Governance in Healthcare

This article addresses formal AI oversight, transparency, validation, privacy, safety and organizational accountability.

https://www.gohealthcarellc.com/blog/ai-governance-in-healthcare-the-new-compliance-standard-every-medical-practice-must-adopt-in-2026

Audit Prevention in 2026

This article examines proactive documentation review, payer policy alignment, coding governance and risk pattern monitoring.

https://www.gohealthcarellc.com/blog/audit-prevention-in-2026-how-ai-identifies-risk-patterns-for-every-specialty-before-cms-or-payers-do

Why CMS Audits Are Increasing in 2026

This article addresses longitudinal medical necessity, utilization, documentation and outcome review in pain and orthopedic practices.

https://www.gohealthcarellc.com/blog/why-cms-audits-are-increasing-in-2026-and-what-pain-and-orthopedic-practices-should-understand

Why Medical Necessity Matters Under CMS Guidance

This article explains the distinction among coding accuracy, coverage, payment and documented medical necessity.

https://www.gohealthcarellc.com/blog/why-medical-necessity-matters-under-cms-guidance-in-2026-for-pain-and-orthopedic-procedures

Why Place of Service Matters Under CMS Guidance

This article addresses alignment among the actual care setting, authorization, professional billing and facility reimbursement.

https://www.gohealthcarellc.com/blog/why-place-of-service-matters-under-cms-guidance-in-2026-for-pain-and-orthopedic-practices

CMS and Payer Policy Changes for Coding and Compliance

This article discusses regulatory intelligence, documentation governance, coding compliance and payer policy monitoring.

https://www.gohealthcarellc.com/blog/cms-and-payer-policies-are-changing-fast-what-2026-means-for-coding-compliance-and-documentation-across-all-specialties

Frequently Asked Revenue Cycle Management Questions for MSK Specialty Care

This resource provides practical answers concerning MSK revenue cycle, compliance, payer and audit issues.

https://www.gohealthcarellc.com/msk-rcm-frequently-asked-questions.html

GoHealthcare Blog

The GoHealthcare blog contains additional resources concerning Medicare policy, prior authorization, medical necessity, coding, AI governance, audit readiness and MSK specialty operations.

https://www.gohealthcarellc.com/blog
Back to framework navigation
Framework Disclaimer: The GoHealthcare Regulatory, Risk & Compliance Excellence Framework™ is provided for general educational, operational and organizational planning purposes. It is not legal advice, medical advice, coding advice, tax advice, an audit opinion or a guarantee of compliance, payment, authorization or regulatory outcome. Laws, regulations, payer policies, coding requirements, coverage criteria and professional standards change and may vary by jurisdiction, payer, plan, provider, facility, procedure and date of service. Healthcare organizations should obtain advice from qualified legal counsel, licensed clinicians, certified coding professionals, privacy and security specialists, compliance professionals and other appropriate experts before applying the framework to specific circumstances. GoHealthcare Practice Solutions does not replace the independent clinical judgment, legal duties or regulatory responsibilities of healthcare organizations and professionals.

GoHealthcare Regulatory, Risk & Compliance Excellence Framework

DISCLAIMER        PRIVACY POLICY        TERMS OF USE       CONTACT US  

GoHealthcareAI Solutions Investor Relations   |  GoHealthcareAxis™ Investor Relations

GOHEALTHCARE KNOWLEDGE CENTER

Search GoHealthcare Practice Solutions

Search our procedure library, specialty guides, prior authorization resources, revenue cycle guidance, case studies, AI governance content, compliance resources, and healthcare operations insights.

Popular:
Procedure Library Specialty Guides Prior Authorization Revenue Cycle Case Studies Blog

Search results open in a new browser tab.


© COPYRIGHT 2026 GoHealthcare Practice Solutions LLC. ALL RIGHTS RESERVED.
  • Who we are
  • What We Do
  • Leadership
  • Case Studies
  • Knowledge Center
    • 8 Excellence Frameworks™
    • CMS Ambulatory Specialty Model (ASM)
    • Procedure Library
  • Specialty Guides
    • Spine Specialty Hub
    • Pain Management Specialty Hub
    • Neurosurgery Specialty Hub
    • Physical Medicine & Rehabilitation (PM&R) Specialty Hub
    • Orthopedic Surgery Specialty Guide
    • Ambulatory Surgery Center Specialty Hub
  • Prior Authorization Resource Center
    • Overview
    • Our Prior Authorization Process
  • Revenue Cycle Management Resource Center
    • Overview
    • RCM Process
    • Revenue Integrity
  • CLIENT PORTAL
  • READ OUR BLOG
  • GoHealthcare Pain and MSK Value-Based Reimbursement Center™
  • Frequently Asked Questions and Answers - GoHealthcare Practice Solutions
  • Remote Therapeutic Monitoring, Remote Physiologic Monitoring, and Chronic Care Management