Sentinel Compliance Command

Did You Know?

Most of what a practice misses has nothing to do with its physicians.

Sentinel maintains the record of what you’ve done — and the clock for what comes next.

Training and policies get attention. These rarely do.
Seven obligations your practice already carries — and the part of each that gets missed.

None of them announce themselves. There is no renewal notice, no letter, no email. Each clock simply restarts from the last time somebody acted, and runs quietly until it doesn’t.

Every claim below cites the rule it comes from, so you can check any of it.

Exclusion screening

TexasEnrollment condition

For a Texas Medicaid practice this is a condition of enrollment, revalidation and re-enrollment — not best practice. It is three lists, not one. And it covers everyone whose work is billed, not just clinicians: the front desk, the biller, the coder, your vendors. Federally, monthly screening is OIG’s own recommendation rather than a statute — OIG says plainly that providers “are not required by statute or regulation to check the LEIE.”

Business associate agreements

Regulation
Before PHI moves, then on expiry · 45 CFR 164.502(e)(1)

The shredding company. The IT contractor. The answering service. The billing company. Obtaining the agreement is the practice’s duty, not the vendor’s — the rule is written as an obligation on you to obtain satisfactory assurances. A missing agreement has been the sole finding in a settlement with a small pediatric group.

Licences, DEA registrations & CPR

Set by the issuer
Each on its own clock · one record per credential, per person · DEA registration

The physician’s licence gets watched. CPR cards, DEA registrations and CE hours run on their own, shorter clocks — and they belong to every person who holds one, not just the providers. A card in a drawer that lapsed in March is invisible until somebody looks. And a lookup on a board website is not the same as the document on file: one is a check, the other is evidence.

Small-breach log and annual report

Regulation
By 1 March · 45 CFR 164.408(c)

Breaches affecting fewer than 500 people are reported to HHS once a year, after year end. Two things get missed. The log is a standing obligation in its own right, required even in a year with nothing to report — you document the determination. And the annual filing does not slow the other clock: individual notice still runs at 60 days from discovery, whether one patient is affected or fifty thousand.

Safer medical device evaluation

Regulation

Alongside the annual exposure control plan review sits a quieter requirement: document, each year, that you considered commercially available safer medical devices. Considering them is not the obligation. Documenting that you did is — and the same standard asks you to solicit and record input from the staff who actually use the sharps.

Security risk analysis

Interval set by your policy
Kept current, reviewed on change · 45 CFR 164.308(a)(1)(ii)(A)

It is a Required implementation specification — not addressable, not optional. Only the interval is yours. The part that gets missed is that most practices believe they already have one: your MIPS or Promoting Interoperability security risk analysis is not this analysis. HHS says so directly — that assessment reaches only ePHI created or maintained inside certified EHR technology, and not the rest of the practice. Nor is a vulnerability scan a risk analysis.

HB 300 training statement

TexasRegulation
Within 90 days of hire · Tex. Health & Safety Code §181.101(d)

Texas requires training on state and federal law within 90 days of hire — broader than the federal rule, which asks only for training on your own policies. Then the part almost nobody keeps: each trained employee must sign a statement, retained until the sixth anniversary of signing. Without it the training is claimed, not proven.

Every citation above links to the rule text or the issuing authority. We would rather you checked than took our word for it. Regulations are quoted as in force at the time of writing.

Not one of these sends a reminder.

That is the whole difficulty. None of it is hard to do — it is hard to remember, across a dozen separate clocks, while running a practice. The work usually gets done. What goes missing is the date it was done on, and the document that proves it.

What the Command Center does with them
Dates every obligation from your last completed action — not from a calendar year, because that is not how the clocks actually run.
Warns before it matters, at 90, 60 and 30 days; 120 for the two-year cycles, and 60 and 30 for short ones like CPR.
Holds the evidence, so each obligation reads Proven rather than claimed — the signed statement, the dated inventory, the filed analysis.
Distinguishes what regulation fixed from what your policy fixed, and never shows one as though it were the other.
The Security Risk Analysis is also available on its own.

A dated written analysis for the period, with its remediation register — the document itself, not a scan or a checklist. Available as a standalone engagement, or included with membership. See what it covers →

Practice Snapshot

Tell us about your practice.

No obligation. No pitch. Just a starting point for the conversation.

What concerns you most?

No spam. No sales call without your permission. Just a conversation when you’re ready.

Thank you.

We received your Practice Snapshot and will be in touch within one business day.

Know where you stand. Every day.