Policy and procedure architecture is the design of how an organization's policies, procedures and forms are structured, numbered, owned, approved, reviewed and retired, so that one maintained set can be mapped to every standard the organization is held to. It is for organizations rebuilding or consolidating their policy and procedure set against several accreditors, regulators and contracts. Integral Healthcare Solutions (IHS) designs the architecture, maps every requirement to one document, and drafts the consolidated set; your leaders and clinicians approve each policy.
Last reviewed: October 2026.
What is policy and procedure architecture?
There is no single governing text. The architecture is built to the set of texts your organization is held to: accreditor manuals, federal and state rules, and contracts. Several federal rules require written policies and say how they are kept. Examples we read for this page:
- HIPAA Security Rule, 45 CFR 164.316. A covered entity or business associate must "Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart" (45 CFR 164.316(a)). Changes are allowed: "A covered entity or business associate may change its policies and procedures at any time, provided that the changes are documented and are implemented in accordance with this subpart" (same section).
- Medicare Advantage compliance program, 42 CFR 422.503(b)(4)(vi). The compliance program must include "Written policies, procedures, and standards of conduct that— (1) Articulate the organization's commitment to comply with all applicable Federal and State standards;" (42 CFR 422.503(b)(4)(vi)(A)).
- Medicaid managed care provider selection, 42 CFR 438.214(a). "The State must ensure, through its contracts, that each MCO, PIHP, or PAHP implements written policies and procedures for selection and retention of network providers" (42 CFR 438.214(a)).
- HHS-OIG General Compliance Program Guidance (2023). OIG describes it as follows: "The GCPG is voluntary guidance that discusses general compliance risks and compliance programs. The GCPG is not binding on any individual or entity" (HHS-OIG).
Accreditor manuals from URAC, ACHC, NABP, CARF, NCQA and others are purchased by your organization. They are part of the governing set for your build, and IHS maps to the editions you hold.
The HIPAA Security Rule also sets retention and review rules for its required documentation: "Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later," and "Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of the electronic protected health information" (45 CFR 164.316(b)(2)(i) and (iii)).
Who needs it and what triggers it
The buyers are organizations rebuilding or consolidating their policy and procedure set against several standards. Common triggers:
- The organization answers to more than one accreditor or regulator and keeps a separate policy for each, so the same topic is written several ways.
- A merger or acquisition leaves two policy libraries covering the same operations.
- A standard is revised and no one can say which policies it touches.
- The organization contracts as a Medicare Advantage organization or a Medicaid managed care plan and must keep the written policies those rules require (42 CFR 422.503; 42 CFR 438.214).
- Policy changes are made without the documentation the HIPAA Security Rule calls for (45 CFR 164.316(a)).
How IHS helps
IHS works through a fixed process against every governing text your organization names:
- Gap assessment and inventory. IHS inventories your current policies and gives each a disposition: keep, merge, rewrite or retire.
- Document and evidence mapping: a master crosswalk from each requirement in each governing text to the one document that carries it.
- Drafting. IHS drafts the policy architecture (hierarchy, numbering, templates, ownership, approval and review rules) in a policy on policies; rewritten and consolidated policies and procedures with approval lines for your clinical and executive owners; forms; a document-control procedure with version history and retention; a rollout work plan; and staff training material on finding and using the library. IHS drafts the program, policies and clinical content for your clinicians to review and approve.
- Mock review of the consolidated set against each governing text through the crosswalk.
- Readiness support: marked open items for every fact only your organization can supply, and a rollout plan for retiring the old set.
What your organization supplies: your current policies, the purchased manuals and contracts you are held to, an owner for each policy area, and access to your policy software if you use one.
The limit: IHS does not configure policy management software and gives no legal opinion. Where a provision turns on a legal question, IHS identifies the text your counsel should read. Your leaders and clinicians approve each policy, and your board approves those its bylaws reserve to it.
For a single register of requirements across several accreditors, see Multi-Accreditation Requirements Register. For compliance programs, see Compliance Program Development and Compliance Services. For a quality system built around the policy set, see Quality Management System Design. Related: Program Development and Accreditation Consulting.
What to have ready
Each item below ties to a text quoted on this page, as linked, or to the purchased manuals your organization holds.
- Your current policies and procedures, all versions in use, for the inventory and disposition.
- The accreditor manuals your organization has purchased, with edition numbers, and the contracts that impose policy requirements.
- If you are a HIPAA covered entity or business associate, your Security Rule policies and procedures, which 45 CFR 164.316(a) requires (45 CFR 164.316).
- Records showing how past policy changes were documented and implemented (45 CFR 164.316(a)).
- Retired versions of required documentation, which the HIPAA Security Rule requires covered entities and business associates to keep for 6 years from creation or the date last in effect, whichever is later (45 CFR 164.316(b)(2)(i)).
- Evidence of periodic review and update of that documentation (45 CFR 164.316(b)(2)(iii)).
- If you are a Medicare Advantage organization, your written policies, procedures and standards of conduct (42 CFR 422.503(b)(4)(vi)).
- If you are a Medicaid managed care plan, your written policies and procedures for selection and retention of network providers (42 CFR 438.214(a)).
- Your bylaws provisions on which policies the board approves.
- A named owner for each policy area, and your policy software if any.
When the list is together, the introductory call is the place to start.
How it compares
Organizations rebuilding a policy set usually weigh these routes. They can be combined.
| Route | What it involves |
|---|---|
| Rebuild in-house | Your compliance, quality and clinical staff inventory, rewrite and consolidate the set themselves against the texts you hold. |
| Policy management software | Software stores, routes and tracks versions and approvals. The content of each policy and the crosswalk to each standard still have to be written. |
| Keep one policy set per standard | Each accreditor or regulator gets its own document for each topic. Each change has to be made in every copy. |
| IHS policy architecture build | Inventory and disposition, master crosswalk, policy on policies, consolidated policies and procedures with approval lines, document-control procedure and mock review. IHS gives no legal opinion and does not configure software. |
What it costs
Fees depend on scope. IHS scopes each engagement after a free introductory call.
What this is not
- This page is not legal advice. IHS identifies provisions for your counsel to read and does not give a legal opinion.
- IHS is not an accreditor or regulator, and a consolidated policy set does not guarantee any accreditor's or regulator's decision.
- IHS does not submit policies to any accreditor or regulator. Your organization's named contact submits; IHS drafts the text.
Frequently asked questions
We answer to several accreditors and regulators; can one policy set satisfy all of them?
IHS's reading (October 2026) is that one set can, when a master crosswalk maps each requirement in each governing text to the one document that carries it. Where two texts conflict, the crosswalk shows the conflict so your owners can decide how the policy meets both.
How do we map one policy to several standards without duplicating documents?
IHS builds a master crosswalk with one row per requirement and one document per row. A single policy can carry requirements from several texts, and the crosswalk records each citation so a reviewer for any one standard can find it.
How do we decide what is a policy, a procedure, a work instruction or a form?
None of the federal texts quoted on this page defines that hierarchy. IHS drafts it in a policy on policies, with templates, numbering, ownership and approval rules for each level, for your leaders to adopt.
How long must we keep retired versions of policies?
For documentation the HIPAA Security Rule requires, 45 CFR 164.316(b)(2)(i) requires retention for 6 years from the date of creation or the date it was last in effect, whichever is later. This page does not cover retention periods in other rules or accreditor manuals; IHS maps those from the texts you hold.
Who approves policies, and how do we record that approval?
Your leaders and clinicians approve each policy, and your board approves those its bylaws reserve to it. IHS drafts each policy with approval lines for its clinical and executive owners and a document-control procedure that records version history.
How do we consolidate policies after a merger or acquisition?
IHS inventories both libraries and gives each policy a disposition: keep, merge, rewrite or retire. The master crosswalk then confirms that every requirement either library carried is still carried by one document in the combined set.
How do we keep the library current when a standard is revised?
The crosswalk shows which documents carry the revised requirements. The HIPAA Security Rule, for example, calls for periodic review and update in response to environmental or operational changes, and allows changes at any time if they are documented and implemented.
Do we need policy management software, and what does it not solve?
The texts we read do not require software. Software can store and route policies, but it does not write their content or map them to standards. IHS does not configure policy management software.
Is the HHS-OIG General Compliance Program Guidance binding?
No. OIG states that the GCPG is voluntary guidance that discusses general compliance risks and compliance programs and is not binding on any individual or entity. A Medicare Advantage organization's compliance program, by contrast, must include written policies, procedures and standards of conduct under 42 CFR 422.503(b)(4)(vi).
