DrCareMSO · Compliance
Compliance isn’ta document.It’s a state you hold.
Auditors don’t care about the binder you built last year. They care whether it’s still true today. Here’s what staying ready actually looks like — and what breaks the moment you stop paying attention.
Try it. This is the difference between staying ready and letting it slide.
The basics
The seven things regulators actually check for
In late 2023, the government’s healthcare watchdog (OIG) put out its first general rulebook for what a good compliance program should look like — before that, guidance was scattered and mostly written for hospitals. It didn’t reinvent anything. It just made these seven basics official. Tap through them.
Written Rules Everyone Follows
A plain-language rulebook that spells out how the organization and every employee are expected to behave — kept up to date, not written once and left in a drawer.
We keep our own rulebook current and tied to what our team actually does with your claims, not a template nobody re-reads.
The rhythm
Compliance isn’t an annual event. It’s a rhythm.
Most of what keeps a program audit-ready isn’t dramatic — it’s small, boring, and repeated on schedule. Here’s what that actually looks like, broken down by how often it happens.
Nothing glamorous — just eyes on the door.
- Access logs checked for anything that looks out of place.
- Anything flagged gets closed out same-day, not left overnight.
The real test
If they called tomorrow, could you open every drawer?
Most investigations don’t start with someone showing up at your door. They start with a letter asking for paperwork — and it’s almost always the same five things, in the same order. Here’s what’s actually supposed to be in each drawer.
What’s at stake
What it actually costs when things slip
The fine doesn’t scale with how the incident happened — it scales with how long it went unfixed. Real numbers, from actual 2025 enforcement.
An honest, first-time slip
A few hundred dollars per incident, capped around $36,000 a year
Caught fast, fixed fast, no pattern of neglect.
OCR closed 2025 with about 21 fines and settlements. The biggest one, just over $3 million, started at rung one and was never fixed.
What’s new
What’s actually changing right now
The seven basics above haven’t changed. What changed is how clearly regulators spelled them out. In late 2023, OIG put out the first general rulebook that applies to every type of healthcare provider, not just hospitals. It didn’t replace the old rules — it just raised expectations for what “good enough” looks like.
Separately, there’s a bigger update in the works for HIPAA’s security rules — the ones that haven’t really changed in over a decade. The government proposed the update in December 2024, and the old rules still apply while that gets sorted out. It was originally expected to be final by mid-2026. The government’s own tracker now says mid-2027 instead — though that’s just an estimate, and it could shift again.
None of this has slowed enforcement down. Regulators closed out 2025 with around 21 settlements and fines — one of the busiest years on record — and the penalties can be serious, as the ladder above shows. The biggest fine in 2025 came down to the same root cause as most of the others: an outdated risk report.
Compliance, in plain terms
Filter by what you're actually asking, or read all of it — every figure here is sourced, not a guess.
10 questions · filter by category
Not exactly — they're guidance, not a law you get fined for breaking directly. But regulators use them as the yardstick for what a "reasonable" compliance program looks like, and obvious gaps rarely help you once someone's already investigating.
Before 2023, official guidance was written mostly for hospitals and a few specific provider types. This was the first version meant for everyone. It didn't throw out the old seven-part framework — it just made it official and more specific about what regulators actually expect to see.
Yes. Any company that can see or handle patient data on your behalf needs a signed agreement in place first, no exceptions. DrCareMSO has one in place with every client we work with.
Almost always a complaint or a reported data breach, not a random inspection. A patient complaint, a breach affecting 500 or more people, or a tip from another agency are the usual starting points.
Almost always the same order: your current risk report, the plan for fixing what it found, and whatever policies relate to the complaint. Training records and vendor agreements come right after. If the risk report looks weak, everything else gets scrutinized harder.
That becomes the problem, even if it's not what triggered the investigation in the first place. An outdated risk report is the single most common issue behind recent fines — including cases where the original complaint was about something else entirely.
There's an update in the works for the security side of HIPAA, proposed in December 2024 and still not final. The current rules stay in place until it is. The government's own timeline has pushed the expected finish date from mid-2026 to mid-2027 — though that's not a hard deadline, so it could move again.
It depends on how bad the slip-up was — anywhere from a couple hundred dollars to well over two million dollars a year for something serious left unfixed. Regulators closed 2025 with about 21 fines and settlements, one of the busiest years on record. The biggest one, just over three million dollars, traced back to an outdated risk report.
There's no fixed number in the law, but "we did one years ago" won't hold up. A good rule of thumb: at least once a year, and any time something big changes — new software, a new location, a new vendor, or a security incident.
The same five things covered above, kept current all year round instead of scrambled together when someone asks: a living risk report, a tracked fix-it plan, up-to-date policies, training records for every role, and a current list of every vendor agreement — including ours with you.
Stay in the state
Readiness isn’t a project. It’s Tuesday.
We built the board at the top of this page because that’s honestly how we think about it — not a folder you open once a year, but something you’re either keeping up with or you’re not. If you want a billing partner who treats it the same way, let’s talk.
Talk to DrCareMSOHave Questions?
Let's Discuss
Fill out this form, tell us about your practice's unique needs, and get a tailored solution from our revenue cycle experts!
Email Us
contact@drcaremso.com
Response Time
Within 12 Hours
Schedule Your Free Demo
Our team will get in touch with you within 12 hours
Request Your Demo