HRSA Operational Site Visit: what reviewers actually ask for
The Site Visit Protocol is not the Compliance Manual, their chapter numbers do not match, and reviewers sample files rather than read policies. What that means for how you prepare.
RESOURCES
Ten pieces on the parts of health center compliance that are genuinely confusing. Every regulatory statement in them is linked to the HRSA, CMS or OIG document it comes from, so you can check it rather than take our word for it.
What a review actually examines, and why the preparation most centers do is aimed at the wrong artifact.
The Site Visit Protocol is not the Compliance Manual, their chapter numbers do not match, and reviewers sample files rather than read policies. What that means for how you prepare.
Most findings are evidence failures, not practice failures. The four properties that make a record hold up, and how to test your own the way it will be tested.
Verification, privileging decisions, and the distinction between them that produces most of the findings in this area.
Which sources can genuinely be queried in real time, which cannot, and why “unable to verify” must never be recorded as verified.
Credentialing asks who someone is; privileging asks what they may do here. A request-to-renewal cycle, and why pre-review is the step that decides everything.
The distance between ready to practice and ready to bill, and the federal rules that decide what it costs.
Internal days, payer days and silent days — how to measure them separately with four columns and ten rows, and why the variance matters more than the average.
Why the approval date is not the effective date, why your internal time before filing is the part that is permanently lost, and what does not carry over to other payers.
What the OIG recommends, which lists apply, and the part of the obligation that is really about records.
Where the monthly cadence comes from, why scope is where programs fail, and the uncomfortable test: could you produce last December's run today?
Board authority, composition, and the attestation records that quietly stop meaning anything after a revision.
Attest to a version, not to a title. Why a revision silently inherits every prior acknowledgement, and what the record has to contain.
The board's required authorities, the monthly meeting and minutes requirement, the 9-to-25 composition range, and the decisions index almost nobody keeps.
The constraints that most credentialing software was not designed around.
ORCPS license verification on a three-year cycle, PEP as a hard prerequisite, and the 30-day inactivity expiry that forces an application to be started over.
Each piece has to be useful even if you never buy RIEL. That is not modesty — a page written to rank rather than to help is obvious, and in compliance it costs more credibility than the traffic is worth.
So: no invented requirements. Every regulatory statement links to the HRSA, CMS or OIG document it comes from, and where a citation could not be linked (eCFR blocks automated requests) it is named precisely enough to look up. Where something is our opinion about good practice rather than a requirement, it says so.
If you find something here that is wrong or out of date, we would rather hear it than not — tell us.
RIEL Compliance Suite is built for health centers operating under exactly these constraints. Thirty minutes on your own scenario, not a slide deck.