Most of what a practice misses has nothing to do with its physicians.
Sentinel maintains the record of what you’ve done — and the clock for what comes next.
None of them announce themselves. There is no renewal notice, no letter, no email. Each clock simply restarts from the last time somebody acted, and runs quietly until it doesn’t.
Every claim below cites the rule it comes from, so you can check any of it.
For a Texas Medicaid practice this is a condition of enrollment, revalidation and re-enrollment — not best practice. It is three lists, not one. And it covers everyone whose work is billed, not just clinicians: the front desk, the biller, the coder, your vendors. Federally, monthly screening is OIG’s own recommendation rather than a statute — OIG says plainly that providers “are not required by statute or regulation to check the LEIE.”
The shredding company. The IT contractor. The answering service. The billing company. Obtaining the agreement is the practice’s duty, not the vendor’s — the rule is written as an obligation on you to obtain satisfactory assurances. A missing agreement has been the sole finding in a settlement with a small pediatric group.
The physician’s licence gets watched. CPR cards, DEA registrations and CE hours run on their own, shorter clocks — and they belong to every person who holds one, not just the providers. A card in a drawer that lapsed in March is invisible until somebody looks. And a lookup on a board website is not the same as the document on file: one is a check, the other is evidence.
Breaches affecting fewer than 500 people are reported to HHS once a year, after year end. Two things get missed. The log is a standing obligation in its own right, required even in a year with nothing to report — you document the determination. And the annual filing does not slow the other clock: individual notice still runs at 60 days from discovery, whether one patient is affected or fifty thousand.
Alongside the annual exposure control plan review sits a quieter requirement: document, each year, that you considered commercially available safer medical devices. Considering them is not the obligation. Documenting that you did is — and the same standard asks you to solicit and record input from the staff who actually use the sharps.
It is a Required implementation specification — not addressable, not optional. Only the interval is yours. The part that gets missed is that most practices believe they already have one: your MIPS or Promoting Interoperability security risk analysis is not this analysis. HHS says so directly — that assessment reaches only ePHI created or maintained inside certified EHR technology, and not the rest of the practice. Nor is a vulnerability scan a risk analysis.
Texas requires training on state and federal law within 90 days of hire — broader than the federal rule, which asks only for training on your own policies. Then the part almost nobody keeps: each trained employee must sign a statement, retained until the sixth anniversary of signing. Without it the training is claimed, not proven.
Every citation above links to the rule text or the issuing authority. We would rather you checked than took our word for it. Regulations are quoted as in force at the time of writing.
That is the whole difficulty. None of it is hard to do — it is hard to remember, across a dozen separate clocks, while running a practice. The work usually gets done. What goes missing is the date it was done on, and the document that proves it.
A dated written analysis for the period, with its remediation register — the document itself, not a scan or a checklist. Available as a standalone engagement, or included with membership. See what it covers →
No obligation. No pitch. Just a starting point for the conversation.
We received your Practice Snapshot and will be in touch within one business day.