Healthcare Governance, Risk, and Compliance: An Operator’s Playbook for CMS, OCR, OIG, and Joint Commission Readiness
May 29, 2026
On this page
Ready to be survey-ready?
What healthcare GRC actually is (short answer)
Healthcare governance, risk, and compliance (GRC) is one integrated program that ties board oversight, enterprise risk, and regulator adherence to a single set of evidence. Compliance officers, COOs, and chief quality officers run it out of one command center so that CMS Conditions of Participation, HHS Office for Civil Rights (OCR) HIPAA obligations, the HHS Office of Inspector General (OIG) Seven Elements, DOJ False Claims Act exposure, and accreditor standards from The Joint Commission, CARF, AAAHC, and COA all point back to the same auditable record.
Five disconnected spreadsheets is not a GRC program. It is a slow-motion finding waiting for a surveyor to write it up. When a Joint Commission surveyor asks who owns the CAP tied to your last infection prevention finding, someone in the room needs to name the person, open the file, and show the closure evidence in under a minute.
The enforcement numbers operators should keep on the wall
The dollars tell you where regulators are spending their time. DOJ announced that False Claims Act settlements and judgments exceeded $2.9 billion in fiscal year 2024, and healthcare fraud made up over $1.67 billion of that total. Total FCA recoveries since the 1986 amendments now exceed $78 billion and have exceeded $2 billion annually for 16 consecutive years. Enforcement priorities for FY24 called out the opioid crisis, medically unnecessary services and substandard care, Medicare Advantage, unlawful kickbacks and Stark Law violations, pandemic-related fraud, and cybersecurity. Whistleblowers drove most of that: 979 qui tam lawsuits, the highest number ever filed in a single year.
Principal Deputy Assistant Attorney General Brian Boynton put it plainly: “The Department places a high priority on fighting fraud and abuse in federal programs… Such conduct will not be tolerated, and those who knowingly misuse taxpayer funds will be held accountable.”
On the privacy side, OCR stayed busy. In calendar year 2024, OCR received 30,256 new complaints about potential HIPAA violations and carried over 2,955 complaints from previous years. OCR issued 22 fines to resolve alleged HIPAA violations, collecting a total of $9,944,612 in penalties. Across 663 large breaches in 2024, the PHI of 242,908,056 individuals was exposed or impermissibly disclosed, with a single Change Healthcare incident driving most of that volume. In 2024, OCR announced a new enforcement initiative targeting noncompliance with the risk analysis provision of the HIPAA Security Rule, and risk analysis failure appeared in every single 2024 enforcement action. If you are a Texas hospital or a California FQHC, that is the first thing a lawyer will ask for after a breach.
And the cost of getting it wrong has not gotten easier on the budget. IBM’s 2024 Cost of a Data Breach Report put the average healthcare breach at $9.77 million, the costliest of any industry for the 14th year in a row.
What the OIG and Joint Commission expect, in plain language
The OIG published its General Compliance Program Guidance on November 6, 2023, its first major update to compliance program expectations in more than 15 years. It reframes the Seven Elements and adds two items operators should not skim: an annual risk assessment run by the compliance committee, and active board oversight of the program. The guidance also expects the compliance officer to report directly to the CEO with access to the board, and it folds quality of care into the compliance program rather than parking it in a separate silo.
The accreditors point at the same problem set from a different angle. Joint Commission publishes its top most frequently non-compliant requirements in the higher SAFER Matrix categories every year. Based on 2023 survey data, the list was led by IC.02.02.01, EP 2: performing intermediate and high-level disinfection and sterilization of medical equipment, devices, and supplies. Standard precautions and PPE (IC.02.01.01, EP 2), high-alert and hazardous medications (MM.01.01.03, EP 2), and look-alike/sound-alike medication safeguards (MM.01.02.01, EP 2) filled out the top of the list, with documentation of suicide risk under NPSG.15.01.01, EP 4 another repeat offender. None of those are mysteries. They are documentation, rounding, and follow-through problems that show up because the evidence lives in too many places and the CAP never closed.
Starting in January 2025, Joint Commission added short, plain-English names to the SAFER Matrix (for example, “Reusable Equip Policy/Procedure” for IC.04.01.01, EP 4, and “Completed Medical Records” for RC.02.01.01, EP 2). Operators should read that as a signal: surveyors want the finding to be legible to a board member, not just a compliance analyst.
How operators run GRC as one program, not five
An operator-grade GRC program treats the board’s risk register and the surveyor’s tracer methodology as two views of the same data. Here is how the surface area maps to what compliance officers, COOs, and chief quality officers own every day.
- Policy management. One library, version controlled, attested by the workforce, mapped to TJC, CARF, AAAHC, COA, and CMS Conditions of Participation.
- Incident and grievance tracking. Every patient grievance and every incident report routes to root cause analysis and, where needed, a CAP with an owner and a close date.
- Credentialing and primary source verification. PSV completed before privileges are granted, re-credentialing on cycle, and the OIG List of Excluded Individuals/Entities checked at hire and monthly thereafter.
- Chart audits. Sample by service line, score against the standard, feed the findings back into education and the CAP queue.
- Environment of care and emergency management. EOC rounding logs, OSHA Bloodborne Pathogens compliance, and EM drills under the CMS Emergency Preparedness Rule at 42 CFR § 482.15.
- HIPAA Security Rule risk analysis. Annual, documented, with risk management actions tied to findings, per NIST SP 800-66 Rev. 2.
- Corrective action plans. A live CAP register with owners, due dates, and evidence of closure. Open CAPs are the single best leading indicator of survey risk.
This is what we mean by a command center. The CCO watches CAP closure rates. The COO watches EOC rounding completion. The chief quality officer watches chart audit pass rates by service line. The board watches one risk dashboard that ties HIPAA, fraud and abuse, accreditation, and patient safety together. One source of truth. Continuously ready.
The five metrics that make the board conversation short
Boards do not want a policy binder. They want trend lines they can act on. Five metrics work.
- Open vs. Closed CAPs, with average days to close. The single best leading indicator of survey risk.
- Percentage of policies attested by the workforce inside the current cycle. If it is under 95%, someone in HR or compliance has a problem.
- Credentialing and PSV turnaround time. Every day a provider sits uncredentialed is lost revenue and a re-credentialing risk on the back end.
- EOC rounding completion rate. Rounding you did not document did not happen, from a surveyor’s point of view.
- HIPAA Security Rule risk analysis status. Given that risk analysis failures appeared in every 2024 OCR enforcement action, this belongs on the same board slide as the financials.
Report these quarterly. Trend them. When a CEO in Florida asks the CCO on a Monday how survey-ready the organization is, the answer should be one dashboard, not one week of scrambling.
Frequently asked questions
What are the OIG’s seven elements of an effective compliance program?
The OIG’s Seven Elements are: written policies and procedures including a code of conduct; a designated compliance officer and compliance committee; effective training and education; effective lines of communication including a confidential reporting mechanism; enforcement of standards through well-publicized disciplinary guidelines; internal monitoring and auditing; and prompt response to detected offenses with corrective action. The November 2023 General Compliance Program Guidance adds annual risk assessments by the compliance committee and explicit expectations for board oversight of the program.
How is healthcare GRC different from traditional compliance?
Traditional compliance often lives inside the compliance office as a separate function. GRC pulls governance (the board), risk (an enterprise risk register covering clinical, financial, cyber, and accreditation exposure), and compliance (regulator and accreditor adherence) into one program with shared evidence. The OIG’s 2023 guidance explicitly integrated quality of care into the compliance program, which closes the historical gap between the CCO and the chief quality officer.
Who owns GRC in a healthcare organization: the board, the CCO, or the COO?
The board owns oversight. The CEO owns the program. The CCO runs it day to day and reports directly to the CEO with access to the board, per the OIG’s 2023 guidance. The COO owns operational execution: environment of care, emergency management, incident and grievance workflows, and credentialing turnaround. The chief quality officer owns chart audit results and patient safety outcomes. A single platform is what keeps all four roles looking at the same evidence on survey day.
What Joint Commission findings show up most often and how do we prevent them?
For 2023 surveys, Joint Commission’s top non-compliant requirements in the higher SAFER categories were led by IC.02.02.01, EP 2 (intermediate and high-level disinfection of medical equipment), followed by standard precautions and PPE (IC.02.01.01, EP 2), high-alert medications (MM.01.01.03, EP 2), look-alike/sound-alike safeguards (MM.01.02.01, EP 2), and suicide risk documentation (NPSG.15.01.01, EP 4). The pattern is consistent: the policy exists, the documented evidence of consistent execution does not. Fix that with EOC rounding logs, chart audits by service line, and a CAP register that closes findings before the next survey window.
How do we measure GRC program maturity for the board?
Five operator metrics carry a quarterly board conversation: open versus closed CAPs with average days to close; percentage of the workforce that has attested to policies in the current cycle; credentialing and primary source verification turnaround time; EOC rounding completion rate; and HIPAA Security Rule risk analysis status with documented remediation. Because OCR cited a risk analysis failure in every 2024 enforcement action it announced, that fifth metric belongs on the same board slide as the financials.
References
- U.S. Department of Justice, “False Claims Act Settlements and Judgments Exceed $2.9 Billion in Fiscal Year 2024” (Jan. 15, 2025)
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2024
- HHS Office of Inspector General, General Compliance Program Guidance (November 2023)
- The Joint Commission, “Top 5 Most Challenging Requirements for 2023” (April 3, 2024)
- IBM, “Cost of a Data Breach Report 2024” (July 30, 2024)
- 42 CFR § 482.15, CMS Emergency Preparedness Rule
- NIST SP 800-66 Revision 2, Implementing the HIPAA Security Rule
- HHS OIG, List of Excluded Individuals/Entities (LEIE)