Healthcare Regulatory Gap Assessment and Readiness Consulting
Last updated: October 2026
A healthcare regulatory gap assessment compares your policies, procedures and daily operations with the federal, state and accreditation standards that apply to you, so you find the deficiencies before a surveyor or auditor does.
Integral Healthcare Solutions (IHS), founded in 2002 by Thomas G. Goddard, JD, PhD, former Chief Operating Officer and General Counsel of URAC, runs these assessments across CMS Conditions of Participation, HIPAA Security and Privacy, OIG compliance program elements, NCQA, ACHC, CARF, NABP, HRSA, NCCHC and state licensure in one engagement. Dr. Goddard personally leads IHS's regulatory gap assessment engagements. Maureen Plumstead leads IHS's NCQA accreditation and recognition work. For The Joint Commission, IHS offers readiness for Home Care pharmacy accreditation and Health Care Staffing Services certification. IHS drafts the findings, the corrective action plan and any policy text for your leaders to review and approve.
What is a healthcare regulatory gap assessment?
A gap assessment is a structured, forward-looking review of your current state against a defined set of requirements. It ends in a prioritized corrective action plan, so you close gaps on your own timeline.
The useful question is rarely whether you have gaps. It is which gaps carry the most risk and whether you know about them before an outside reviewer does.
What a gap assessment is not
- It is not a compliance audit. An audit tests whether you were compliant during a past period. A gap assessment looks at where you stand now against the requirements ahead of you.
- It is not a self-assessment. Staff know the organization but review processes they designed, and they have no outside benchmark.
- It is not a mock survey. A mock survey rehearses the survey event. A gap assessment is the diagnostic work that comes before one.
- It is not a policy review. A gap assessment reads each policy against the standard and then checks whether staff follow it.
Who needs a regulatory gap assessment?
Any organization that faces surveys, audits or a new rule can use one, and these are the common cases.
- Hospitals and critical access hospitals: CMS Conditions of Participation, HIPAA and state licensure.
- Health plans and managed care organizations: URAC and NCQA renewal cycles.
- Behavioral health facilities: CARF and ACHC survey readiness, and 42 CFR Part 2 consent and data-sharing practices.
- Home health and hospice agencies: CHAP and ACHC surveys, and the CMS hospice assessment change below.
- Federally qualified health centers: HRSA site visit readiness.
- Pharmacies: ACHC and NABP programs.
- Correctional health providers: NCCHC standards.
- Digital health and AI-enabled organizations: documented governance for AI in clinical and operational workflows.
- Organizations considering first-time accreditation: a gap assessment before you apply shows what to fix before you commit to accreditation fees. IHS planning range: start 9-12 months before the application.
When is a gap assessment the wrong tool?
If you only need a certified auditor's opinion for a legal proceeding or a financial statement, a gap assessment does not substitute for it. If a survey is already under way, you need survey support, not a diagnostic.
Which regulatory changes drive assessment requests?
Three federal changes can lead an organization to request an assessment. Each row below was read in its government source (page opened October 4, 2026).
| Change | What the source says | Source |
|---|---|---|
| 42 CFR Part 2 (substance use disorder patient records) | The February 2024 final rule set a compliance date of February 16, 2026 for persons subject to it. It also modified Part 2 to align more closely with the HIPAA Privacy Rule. | Federal Register, 89 FR 12472, February 16, 2024 |
| HIPAA Security Rule proposed update | HHS published a notice of proposed rulemaking on January 6, 2025. The proposal addresses multi-factor authentication, network segmentation and written verification from business associates. This page does not report whether the rule has been finalized, so check the Federal Register for its current status. | Federal Register, 90 FR 898, January 6, 2025 |
| CMS Hospice Outcomes and Patient Evaluation (HOPE) | CMS developed HOPE to replace the Hospice Item Set, and HOPE data collection began October 1, 2025. | CMS, HOPE |
The OIG publishes General Compliance Program Guidance as a reference guide for the compliance community, covering relevant federal laws and compliance program infrastructure (HHS-OIG, General Compliance Program Guidance, page opened October 4, 2026). IHS uses it as one reference when it assesses a compliance program.
Which regulatory domains does IHS assess?
IHS assesses ten regulatory domains in one engagement, and it flags where one finding touches several frameworks so you do not remediate the same issue twice.
| Domain | Frameworks | Key assessment areas |
|---|---|---|
| Clinical quality and patient safety | NCQA, CARF, ACHC, CHAP | Medical protocols, order sets, medication reconciliation, patient outcomes |
| CMS Conditions of Participation and Coverage | CMS | Condition compliance, QAPI programs, staffing, discharge planning |
| HIPAA Privacy and Security | OCR, HHS | PHI safeguards, business associate agreements, ePHI controls, breach notification |
| OIG compliance program elements | OIG GCPG | Compliance program structure, hotline, training, auditing and monitoring |
| State licensure | State agencies | Facility licensure, certificate of need, state surveys |
| Billing and coding compliance | CMS, OIG | Revenue cycle integrity, medical necessity documentation, No Surprises Act, False Claims Act risk |
| Credentialing and privileging | NCQA, ACHC | Primary source verification, credentialing policies, privileging criteria |
| Emergency preparedness | CMS, local ordinances | Emergency plans, local coordination, CMS emergency preparedness alignment |
| Financial controls and anti-kickback | OIG, CMS | Stark Law and anti-kickback program documentation, safe harbor documentation, physician compensation process documentation |
| IT, cybersecurity and AI governance | OCR, HIPAA | HIPAA Security Rule, third-party vendor risk, AI governance, access controls |
IHS is not a law firm. The financial controls and anti-kickback domain covers program documentation and process, and IHS gives no legal opinion on Stark Law or the Anti-Kickback Statute.
How does an IHS gap assessment work?
An IHS gap assessment runs in four phases over 4-12 weeks. These durations are IHS planning ranges, not figures from an accrediting body or agency, and they depend on organization size and scope.
Phase 1: Scope definition and framework mapping (weeks 1-2)
IHS identifies every federal, state and voluntary standard that applies to you and maps your policies against all of them at once. A single well-written policy can serve more than one framework, and mapping the frameworks together shows which policies do the same work.
Phase 2: Current state assessment (weeks 2-6)
IHS reads your documents against the governing text, reviews outcomes and quality data you provide, and interviews the staff who run each process. This phase shows the difference between what a policy says and what staff do.
Phase 3: Root cause analysis (weeks 5-8)
For each gap, IHS looks at the workflow, system and staffing causes behind it. Many compliance gaps are operational problems that show up as documentation problems, so the fix has to address the operation.
Phase 4: Corrective action planning (weeks 8-12)
IHS drafts a prioritized corrective action plan that assigns each finding to an internal owner with a completion date. It separates items to resolve before an accreditation application from items your normal operations can absorb. Your leaders review and approve the plan.
What do you receive?
- A compliance maturity score across the frameworks assessed, set by IHS's own scoring method.
- A risk analysis and vulnerability matrix that flags the areas needing immediate attention.
- A prioritized remediation roadmap.
- A corrective action plan with owners, timelines and verification checkpoints.
- A policy and procedure gap list with a regulatory citation for each finding.
- Executive reporting suitable for a board.
- A framework routing guide that points you to the accreditation pathways that fit your organization type and services.
How much does a regulatory gap assessment cost?
The cost has three parts: IHS's consulting fee, your internal staff time, and the remediation work the findings lead to. A gap assessment itself does not carry an accreditation body fee. Each accreditor sets its own fees, so ask the body for its current fee information when you move from assessment to application.
Five factors drive the consulting scope: the number of frameworks in scope, organization size and number of sites, depth (document review only, or document review plus staff interviews and process walkthroughs), whether remediation support is included, and urgency before a survey.
IHS sets a fixed fee for each engagement after a free discovery session, because scope, number of sites and gap severity change the work.
How does IHS work on a gap assessment?
The IHS process covers standards acquisition, gap assessment, document and evidence mapping, mock review against the governing text and readiness support. IHS covers the frameworks listed above, so one engagement can assess several of them together.
The same IHS lead who writes the findings stays with you through remediation planning and survey readiness, so you do not brief a second team. Every item in the corrective action plan has an owner, a date and a verification checkpoint.
What this is not
- IHS is not an accrediting body or a regulator and does not grant, deny or influence an accreditation or licensure decision.
- IHS drafts the text, and your organization's named contact sends it to any regulator or accreditor. IHS does not communicate with them for you.
- A gap assessment is not legal advice and does not guarantee a survey result.
Which accreditation path fits your organization?
If you are not sure which accreditation applies, an assessment is a sound first step, and IHS then points you to the program that fits your organization type. IHS delivers this work under its Compliance Services and Accreditation Consulting practice lines.
- Health plans and PBMs: see URAC Health Plan Accreditation, URAC PBM Accreditation and NCQA Health Plan Accreditation
- Home health and hospice agencies: see ACHC/CHAP Survey Readiness
- Behavioral health facilities: see CARF Survey Readiness
- FQHCs: see HRSA OSV Readiness
- Pharmacies: see URAC Specialty Pharmacy Accreditation and Pharmacy Compounding Accreditation Consulting
- Correctional health providers: see NCCHC Survey Readiness
- OIG compliance programs: see Compliance Program Development
- Credentialing programs: see Credentialing Program Design
Frequently asked questions
See our complete Regulatory Gap Assessment FAQ for more questions, including framework selection and post-assessment remediation.
What is a regulatory gap assessment?
It is a structured review that compares your current policies, procedures and operations with the federal, state and accreditation standards that apply to you. The output is a prioritized corrective action plan, so you close gaps on your own timeline instead of a surveyor's.
When should we conduct a gap assessment?
Common triggers are a planned accreditation application or renewal, a major regulatory change, a merger, acquisition or new service line, and a prior survey citation where you need to confirm remediation. As an IHS planning range, start 9-12 months before an accreditation application.
How long does a healthcare gap assessment take?
IHS plans 4-12 weeks from kickoff to final report. Small single-site organizations sit toward the short end, and multi-site or multi-framework assessments toward the long end. These are IHS planning ranges.
How much does a gap assessment cost?
The cost is consulting fees, your internal time and later remediation work. IHS sets a fixed fee for each engagement after a free discovery session, because scope, number of sites and gap severity change the work.
What are the deliverables?
A compliance maturity score, a risk analysis and vulnerability matrix, a prioritized corrective action plan with owners and timelines, a policy and procedure gap list with citations, executive reporting for a board and a framework routing guide.
Should we do an assessment before applying for accreditation?
For most first-time applicants it is a sound step, because it shows what to fix before you commit to application fees. IHS plans the assessment 9-12 months ahead of the application, which leaves time to remediate.
Who is this not for?
It is not a substitute for a certified audit used in a legal proceeding, and it is not survey support once a survey has begun. IHS does not give legal opinions or guarantee a survey outcome.
Ready to find your gaps?
A free discovery session covers your current compliance posture, the frameworks that matter most for your organization and what a scoped assessment would involve.
