Blog/ Hospital management

Hospital compliance: how to ensure conformity

Hospital compliance goes beyond following rules: it is a strategy to protect revenue, prevent fraud and ensure the institution’s financial sustainability in an increasingly regulated industry

By
Rivio, Editorial team
Published
Reading time
6 minutes

Of the more than R$ 30 billion that private healthcare loses each year to fraud and waste, no less than 12% of this erosion is attributed to a lack of compliance. Exposure to fraud, improper denials, regulatory sanctions and fines for the misuse of clinical data undermines the sustainability of hospital operations and strains the relationship with payers, patients and regulators precisely when processes and controls are lacking.

Hospital compliance, more than a mere bureaucratic requirement, is a protective function for hospital management, with a direct impact on the revenue cycle.

What hospital compliance is

Hospital compliance is the set of policies, processes and controls that ensure a healthcare institution operates in accordance with laws, regulatory standards, contracts with payers and industry best practices. The term comes from the English to comply (“to fulfill,” “to be in agreement”) and became established in hospital management as the Brazilian regulatory environment grew more complex and demanding.

Hospital compliance covers three main fronts:

  • Care compliance: conformity with clinical protocols, rules from Anvisa (National Health Surveillance Agency), patient safety rules and accreditation requirements.

  • Financial and billing compliance:conformity with each payer’s billing rules, contracted tables, correct procedure coding and the prevention of denials and fraud.

  • Data compliance (LGPD):conformity with Law No. 13,709/2018, Brazil’s General Data Protection Law, which regulates the processing of sensitive personal data (in healthcare, mainly medical records, test results and medical histories).

The three fronts are interdependent. A failure in billing compliance may originate in an inadequate clinical record, and a data breach can compromise the contractual relationship with payers. That is why compliance programs must address these dimensions in an integrated way.

The regulatory framework for compliance in healthcare

The main regulatory framework for compliance in the industry is Normative Resolution No. 518/2022 of the ANS (Brazil’s National Supplementary Health Agency), which provides for the adoption of minimum corporate governance practices, with an emphasis on internal controls and risk management, for the purpose of health plan operators’ solvency.

Although RN 518 is formally addressed to payers, it directly affects provider hospitals: by requiring health plans to demonstrate internal controls and risk management, the rule pushes the provider chain to adopt equivalent practices.

The rule structures compliance around four pillars, according to Article 2 and the annexes of the resolution:

  • Governance: the system by which the payer is directed, monitored and incentivized, with a separation of roles between the board of directors and the executive board, and the adoption of the principles of transparency, fairness, accountability and corporate responsibility.

  • Internal controls: a set of measures to safeguard the payer’s activities, ensure the reliability of information and guarantee compliance with obligations at every level of the organization. They must be evaluated periodically, with at least one review a year.

  • Risk management: the process of identifying, analyzing, assessing and monitoring risks at the strategic, tactical and operational levels, with a focus on underwriting, credit, market, legal and operational risks.

  • Internal audit: an independent function, reporting directly to the board of directors, responsible for evaluating the quality of internal control systems and compliance with internal and regulatory rules.

In addition, the LGPD (Law No. 13,709/2018) classifies health data as sensitive personal data and imposes the highest level of protection. Hospitals that handle this data improperly are subject to fines of up to 2% of revenue. The law requires proper consent, access control, leak prevention and, for health plans, the formal appointment of a Data Protection Officer (DPO).

Which financial risks compliance prevents

The main risks a hospital compliance program fights are:

Denials and lost revenue

Billing processes without proper controls result in inconsistencies that payers dispute. Coding errors, missing prior authorizations, entries incompatible with the medical record: each of these points is a denial risk. Without a compliance program that standardizes and monitors these processes, the hospital reacts to denials instead of preventing them.

Fraud and internal misconduct

Studies by IESS (Institute for Supplementary Health Studies) estimate that between 12% and 18% of hospital claims contain improper items. Part of this problem originates in operational failures; another part, in misconduct that internal controls let through. Orthotics, prosthetics and special materials are one of the main vectors of irregularities in the industry.

Regulatory sanctions and interventions

According to the ANS, 119 health plan operators were liquidated between 2012 and 2018 because of management failures, which led to the publication of RN 518. Institutions that do not document their processes, do not carry out periodic risk assessments and do not send reports to the ANS are subject to warnings, suspensions and, in the most serious cases, extrajudicial liquidation.

Fines for data violations

The LGPD provides for fines of up to 2% of annual revenue for violations in the processing of sensitive data. For a mid-sized or large hospital, this amount represents a serious financial risk.

Reputational damage

Beyond the direct financial consequences, public exposure of irregularities undermines the institution’s credibility with payers, physicians and patients. Restoring a reputation tends to be more expensive and time-consuming than implementing a compliance program.

How to structure a hospital compliance program

Based on the pillars of RN 518 and industry best practices, the structure can follow four steps:

1. Diagnosis and risk mapping

The starting point is mapping the institution’s main processes (billing, auditing, contracts with payers, materials management, access to clinical data) and identifying vulnerabilities. This diagnosis should be formalized in a document and presented to leadership, prioritizing the risks with the greatest financial and regulatory impact.

2. Defining policies and internal controls

With the risks mapped, the institution sets clear policies for critical processes: billing rules, prior authorization protocols, coding standards, criteria for the use of special materials, data security procedures. These controls must be accessible to all professionals involved and reviewed at least once a year, as required by RN 518.

3. Whistleblower channel and a culture of compliance

For large payers, RN 518 requires a whistleblower channel that guarantees confidentiality and anonymity. For hospitals, this mechanism is equally strategic: it makes it possible to identify internal misconduct before it becomes a regulatory or financial problem. A compliance culture is built with regular training, clear communication from leadership and zero tolerance for documented irregularities.

4. Monitoring and internal audit

Compliance without monitoring is just bureaucratic paperwork. The institution needs to define indicators, periodically review the effectiveness of controls and carry out internal audits at least once a year. The results of these audits should be formalized in minutes and followed by action plans with defined owners and deadlines. For a complete overview of how internal auditing is structured at the hospital, see the article Hospital auditing: a complete guide for managers.

Compliance and the revenue cycle are inseparable

A hospital that operates in regulatory compliance bills with more predictability. Standardized billing processes reduce denials. Internal controls over materials and authorizations eliminate fraud vectors. Proper management of clinical data avoids fines and protects the relationship with payers. Intensive use of technology is essential for this.

Rivio was founded to transform hospital management through artificial intelligence. In a landscape under growing pressure from costs, regulatory complexity and operational inefficiencies, we believe technology is the way to bring financial predictability, scale and intelligence back to healthcare’s administrative processes.

Our vision is clear: to build the best operating system for healthcare in Latin America, starting with the hospital revenue cycle. By automating analysis, reducing rework and supporting decisions with reliable data, we help hospitals operate more efficiently, free up their teams’ time and create the conditions to focus on what really matters: quality of care and the patient experience.

Contact

We are selecting visionary hospitals that want to redefine their management and lead the industry over the next 10 years.

Talk to Rivio