Skip to main content
Compliance covers HIPAA security, quality assurance, and regulatory compliance.

Who can use it

Organization Admins, Location Admins, and Compliance Officers.

The compliance dashboard

Unlike most modules, Compliance leads with a summary rather than a table. It shows open findings by severity, findings by status, and how many have been open more than 30 days.
Aging findings are the number to watch. A finding open beyond 30 days is usually one nobody owns. Work the aging count down before adding new audits.

What lives here

HIPAA

Audit trail, security incidents, business associates, and compliance documents.

Quality

Audit findings, disallowances, audits, and the compliance calendar.

QAPI

Quality assurance and performance improvement initiatives.

Member safeguards

Complaints, incident reports, and member rights.

How findings arrive

Findings reach Compliance from two directions: Automated findings are the useful ones to act on daily, because they catch problems while they are still cheap to fix. See Quality.

Working the compliance cycle

1

Review open findings by severity

Start with the most severe. Severity levels are STANDARD, CONDITION, and IMMEDIATE_JEOPARDY.
2

Assign ownership

A finding without an owner does not get fixed.
3

Fix the underlying cause

Most findings point at another module — a lapsed credential, an unresolved EVV exception, an expired authorization.
4

Close the finding

Record the correction so the audit trail shows what was done.
5

Check the calendar

Upcoming regulatory deadlines are on the compliance calendar.
IMMEDIATE_JEOPARDY is the most serious classification available. Findings at this level carry regulatory deadlines and must be escalated immediately, not queued.

Troubleshooting

Survey preparation

Getting ready for a regulatory survey.

Licensing

Licences, surveys, and deficiencies.