Hospital M&A: Keeping Infection Control, Credentialing, and Incident Reporting Intact Through Close

October 1, 2026

On this page

Ready to be survey-ready?

See how AccrediCulture turns compliance into an operating system across every facility.

The answer: three Joint Commission chapters break first in a hospital merger

Hospital M&A fragments three high-risk Joint Commission survey domains at the same time: Infection Prevention and Control (IC), Medical Staff (MS) credentialing and privileging, and Sentinel Event and incident reporting. Policies get rewritten, data systems get migrated, and reporting lines get redrawn mid-accreditation-cycle, which is exactly how Condition-level findings happen under CMS 42 CFR §482. Compliance leaders have to lock down a single source of truth for IC surveillance, OPPE/FPPE data, and sentinel event timelines across the legacy legal entities before Day 1, not after.

The volume question matters here. Kaufman Hall reported 46 announced hospital and health system transactions in 2025, with Q4 alone bringing 17 deals and four mega mergers where the smaller party’s revenue exceeded $1 billion. Every one of those transactions triggered a CMS §489.18 Change of Ownership (CHOW) analysis, a Joint Commission notification obligation, and a cascade of credentialing and IC re-work most compliance teams did not budget hours for.

What actually breaks: IC.02.01.01, NHSN facility IDs, and the surveillance baseline

Hospital M&A: Keeping Infection Control, Credentialing, and Incident Reporting Intact Through Close — What actually breaks: IC.02.01.01, NHSN facility IDs, and the surveillance baseline

Infection prevention is the first chapter to show cracks after close. The IC chapter was rebuilt in 2024, and The Joint Commission condensed the hospital IC standards to 12 Standards with 51 Elements of Performance effective July 1, 2024, with written policy and procedure requirements that must be in place on survey day. When two legacy entities merge, you now have two IC plans, two risk assessments, two sets of competencies, and two interpretations of standard precautions sitting under one new governing body.

IC.02.01.01 has been one of the most-cited standards for years. Historically, IC.02.01.01 posted a 43% non-compliance rate for hospitals and IC.02.02.01 (reusable medical equipment) hit 62%. Those were steady-state numbers. Add a merger on top of that and you compound the risk, because the IC Preventionist is now responsible for a facility whose hand hygiene audit history, high-level disinfection logs, and construction ICRAs live in two different systems. Here is what we see fracture most often in the first 90 days post-close:

  • CDC NHSN facility IDs that do not reconcile, so CLABSI, CAUTI, C. Difficile, and SSI denominators reset or double-count
  • Hand hygiene and PPE competency records that live in the legacy LMS and never make it to the surviving entity
  • High-level disinfection logs with two different formats and two different accountable owners
  • Infection Preventionist job descriptions that no longer match the new org chart
  • Antibiotic stewardship committees that technically exist on paper but have not met since announcement

Loss of NHSN surveillance continuity is the quiet one. If your HAI baselines reset at the facility-ID level, you lose the trend data a surveyor will ask about and the CMS Hospital-Acquired Condition Reduction Program uses to score you.

MS.06.01.05, OPPE/FPPE, and the NPDB re-reporting trap

Medical staff governance is the second chapter that breaks, and it breaks silently. Under CMS §482.22 Medical Staff, the governing body of the surviving entity owns privileging decisions on Day 1. The Joint Commission’s MS.06.01.05 requires focused and ongoing professional practice evaluation (FPPE and OPPE) data to follow each practitioner, which means the surviving CVO has to inherit, verify, and continue tracking performance data that was collected by someone else, in someone else’s system, under someone else’s bylaws.

Primary source verification does not transfer. The surviving entity needs documented PSV under its own name and date, not the legacy entity’s file. If the legacy hospital had an action in place (summary suspension, conditional reappointment, FPPE for cause), the NPDB Guidebook obligations do not pause for the transaction. The successor entity owns the reporting obligation forward and, in many structures, inherits the duty to query at reappointment. Miss that and you have an MS chapter finding, a potential Condition-level citation at §482.22, and NPDB exposure in the same quarter.

A clean operator playbook here looks like one list, maintained in one place, reconciled weekly:

  1. Every practitioner on either legacy medical staff, with current PSV status under the surviving entity
  2. Every OPPE cycle currently in flight, with the trigger date and reviewer named
  3. Every open FPPE for cause, with the end date and the governing body that will accept the result
  4. Every NPDB query and report filed in the trailing 24 months, with the surviving CVO’s confirmation
  5. Every delegated credentialing agreement with payers, re-papered under the new TIN

Sentinel events, RCAs, and who owns the pre-merger record

Hospital M&A: Keeping Infection Control, Credentialing, and Incident Reporting Intact Through Close — Sentinel events, RCAs, and who owns the pre-merger record

The third fracture is the one no one wants to find on survey day: an open sentinel event, or an RCA with corrective actions that were never closed, sitting in the legacy incident system that got decommissioned at close. The Joint Commission’s Sentinel Event Policy expects a thorough and credible RCA and action plan within 55 business days of becoming aware of a reviewable event. The clock does not reset because the parent company changed.

Quality after acquisition is already a documented concern. In the NEJM study by Beaulieu and colleagues (2020), being acquired was associated with a modest differential decline in patient experience, equivalent to a fall from the 50th to the 41st percentile, with no significant differential change in 30-day readmission or mortality rates. The NIHCM summary of the same work put it plainly: “there was no evidence that clinical processes or patient outcomes improved after an ownership change.” That is the baseline. Add fragmented incident reporting on top of flat-to-worse outcomes and you have the makings of a Preliminary Denial of Accreditation finding.

Record ownership needs to be answered in the purchase agreement, not after close. We tell operators to confirm the following before Day 1:

  • Who owns the pre-merger incident, grievance, and sentinel event records (usually the surviving entity, by assignment)
  • Retention periods under state law, CMS Conditions of Participation, and any AHRQ Patient Safety Organization work-product protections in play
  • Which open CAPAs transfer and who is accountable for closure under the new org chart
  • How the Patient Safety Evaluation System is reconstituted so PSO privilege is not lost
  • Where RCAs will live going forward (one system, one owner, one reviewer calendar)

At AccrediCulture, we help operators consolidate incident management, grievances, CAPAs, EOC rounds, EM drills, credentialing, and policy management into one command center so the Day 1 record is intact and the Day 180 survey file tells a single story. One source of truth, not two archives and a spreadsheet.

Frequently asked questions

Does a hospital merger trigger a new Joint Commission survey or a CMS CHOW re-survey?
It depends on the deal structure. The Joint Commission requires notification of a change in ownership and may conduct an extension survey of the acquired site, typically within a defined window of the effective date, to confirm the surviving entity’s standards compliance. On the CMS side, §489.18 treats a CHOW as an automatic assignment of the provider agreement to the new owner, which carries forward all existing deficiencies, plans of correction, and sanctions. There is no fresh start.

What happens to medical staff privileges and OPPE/FPPE records when two hospitals combine?
Privileges do not automatically port. The surviving entity’s governing body must grant privileges under its own medical staff bylaws, usually through a defined transition process. OPPE and FPPE data should be transferred to the surviving CVO and continued without a gap. The successor entity carries the NPDB query and report obligations forward from Day 1.

How should infection prevention programs be unified across legacy entities without losing NHSN surveillance continuity?
Decide the surviving NHSN facility ID before close, map every location to the correct CCN, and coordinate with CDC on any facility ID consolidation so your CLABSI, CAUTI, C. Difficile, and SSI denominators do not reset. Standardize the IC plan, risk assessment, and competencies under one Infection Preventionist, and keep both legacy audit histories accessible for the next survey.

Who owns sentinel event and RCA records from the pre-merger entity, and how long must they be retained?
In almost every deal structure, the surviving entity assumes the records and the open obligations. Retention is driven by state hospital licensure law, CMS Conditions of Participation, and any AHRQ PSO work-product arrangement. Confirm it in the asset purchase agreement, not after close, and keep the Patient Safety Evaluation System intact so privilege is not waived.

What are the most common accreditation findings cited after hospital M&A transactions?
In our experience, the repeat offenders are IC.02.01.01 (implementation of IC activities), IC.02.02.01 (reusable medical equipment), MS.06.01.05 (OPPE/FPPE), LD.04.04.05 (operational performance improvement), and gaps in sentinel event reporting timelines. The common thread is a documentation handoff that never happened. A single source of truth closes those gaps before a surveyor finds them.

Scroll to Top