POLICIES & GOVERNANCE
Policies, attestations, and the evidence that oversight happened.
Having the policy is the part everyone has covered. Showing that the board approved it, that it was reviewed when it was due, and that the staff it governs have read it — that is the part that takes three weeks to assemble.
A policy binder is not evidence of oversight.
Approved, but when and by whom
A policy without a traceable approval is a document, not a governance act. The minute that recorded the vote is the evidence, and it usually lives somewhere other than the policy.
Current, or just not yet noticed
Most policies carry a review cycle. A policy two years past its own review date is out of compliance with your own manual before anyone else's rule enters into it.
Read, or merely distributed
Sending a policy to staff and knowing which staff acknowledged it are different claims. Only the second one can be shown a year later.
From draft to attestation, on one record.
The lifecycle is not complicated — draft, review, approve, publish, attest, revisit. It breaks because each step lives in a different tool and the trail between them is email. Keeping the steps on the policy itself is most of the work.
- Policy lifecycle
- Attestations
- Board / governance actions
- Evidence & oversight
Who has attested, and — more usefully — who has not.
Attestation reporting is almost always built the wrong way round. A dashboard that says 87% attested is a statistic; what an administrator needs is the thirteen names, grouped by supervisor, so the follow-up is a short conversation rather than a project.
The same inversion applies to policies themselves. The useful view is not how many are current — it is which ones are not, who owns each, and how long they have been overdue.
Attestation also has to survive revision. A staff member who acknowledged version 3 has not acknowledged version 4, and a system that keeps a single “acknowledged” flag per person quietly loses that distinction at the exact moment it matters. RIEL attests to a version, not to a title.
Board and governance actions, on the record.
For a Health Center Program organization the governing board is not advisory, and its oversight is examined directly. The evidence is mostly documentary: minutes that record what was decided, approvals that are traceable to a meeting, and a composition you can demonstrate rather than assert.
Health Center Program Compliance Manual, Chapter 19: Board Authority — among the board's required authorities and responsibilities are approving the selection and, as appropriate, the termination of the Project Director/CEO; approving the annual project budget and applications; approving services and the location and hours of sites; and assuring the health center operates in compliance with applicable federal, state and local laws. The board must also have authority to establish or adopt policies for the conduct of the project, and to update them when needed — which is where the review cycle above stops being housekeeping.
The board must meet monthly, and the minutes must record attendance, key actions and decisions. That sentence is the reason minutes are the single most requested governance artifact: they are where the evidence of every other approval ends up.
Chapter 20: Board Composition — board size falls within a range of 9 to 25 members, with the health center determining the appropriate size, and non-patient members selected for expertise in relevant areas such as community affairs, local government, finance, legal affairs or social services.
The chapter numbers differ between HRSA's two documents. Board Authority is Chapter 19 of the Compliance Manual but Chapter 17 of the Site Visit Protocol; Board Composition is Chapter 20 in one and Chapter 18 in the other. If your evidence is filed by chapter, label which numbering it follows.
Read the HRSA documents for their exact terms; they are revised independently and nothing here is legal or regulatory advice.
What RIEL changes
- Approval, review date, current version and attestations live on the policy, not around it.
- Attestation is recorded against a specific version, so a revision does not silently inherit the old acknowledgements.
- Overdue reviews produce a name and a date rather than a percentage.
- Board and governance actions are recorded where the policies they approve can point back to them.
- Policy gaps roll into HRSA readiness instead of living in a parallel tracker.
- “Show me the current version and who has read it” is answered from the record, at the moment it is asked.
What it does not
- It does not write your policies. There is no library of model policies here, because a policy your organization did not write is a policy your organization cannot defend.
- It does not tell you which policies you are required to have. That comes from HRSA, your state, your payers and your own risk assessment.
- It does not replace the board, run its meetings, or draft its minutes. It holds the record of what the board did.
- It does not make an attestation meaningful. Whether staff actually read the policy is a management question; the system only records what they affirmed and when.
- It is not legal advice, and the summary of HRSA requirements on this page is not a substitute for the chapters themselves.
Evidence of oversight, ready before it is asked for.
The pattern across all of this is one thing: the artifact that proves a governance act is created at the moment of the act and then scattered. Minutes go to one place, the approved policy to another, the attestations to a third, and the connection between them exists only in the memory of whoever was there.
Keeping the connection is not a technology problem so much as a discipline problem — but it is a discipline that software can hold on your behalf, which is the only reason to buy any of this.
Policies and governance are one input to the wider picture; HRSA readiness is where it adds up, and the module tour covers the rest.
Could you show, today, that your board approved your current policies?
Not that they exist — that they were approved, when, and by a board whose composition you can demonstrate. If assembling that takes days, it is worth thirty minutes to see the alternative.