2.2 Healthcare Accreditation Standards: Joint Commission, NCQA, and CARF Privacy Requirements

Key Takeaways

  • Accreditation organizations like The Joint Commission (TJC) maintain CMS 'deemed status,' meaning accredited healthcare facilities are recognized as satisfying Medicare Conditions of Participation (CoP, 42 CFR § 482.24) for medical record services.
  • The Joint Commission evaluates healthcare information governance through its Information Management (IM) standards (e.g., IM.01.01.01, IM.02.01.01, IM.02.02.01) and Patient Rights (RI) standards (e.g., RI.01.01.01), enforcing both digital security and bedside acoustic/physical privacy.
  • The National Committee for Quality Assurance (NCQA) establishes rigorous privacy requirements for managed care plans, Accountable Care Organizations (ACOs), and health insurers, emphasizing member confidentiality, credentialing file protection, and delegation oversight of downstream vendors.
  • The Commission on Accreditation of Rehabilitation Facilities (CARF) mandates specialized, person-centered privacy protections for behavioral health, addiction medicine, and physical rehabilitation, requiring explicit, time-limited written consent for session recordings.
  • Accreditation surveyors evaluate compliance through tracer methodology—tracking active patients through clinical and administrative pathways to audit real-time EHR chart access logs, interview frontline personnel, and observe environmental physical safeguards.
Last updated: September 2026

2.2 Healthcare Accreditation Standards: Joint Commission, NCQA, and CARF Privacy Requirements

CHPS Core Concept: While HIPAA sets the federal statutory floor for healthcare privacy and security, voluntary healthcare accreditation organizations establish operational standards that frequently exceed federal baselines. Accreditation directly impacts institutional prestige, commercial payer contracting, and Medicare reimbursement through deemed status. Candidates must understand how The Joint Commission (TJC), the National Committee for Quality Assurance (NCQA), and the Commission on Accreditation of Rehabilitation Facilities (CARF) evaluate privacy and security compliance during on-site surveys.


1. CMS Deemed Status and Conditions of Participation (CoP)

Under Section 1865 of the Social Security Act, healthcare facilities must satisfy the Conditions of Participation (CoP) established by the Centers for Medicare & Medicaid Services (CMS) to participate in and receive reimbursement from Medicare and Medicaid programs.

The Mechanics of Deemed Status

Rather than undergoing direct, routine inspections by state health department survey agencies on behalf of CMS, healthcare organizations may choose to be accredited by an independent, CMS-approved national accrediting body. When an accrediting body's standards meet or exceed CMS requirements, CMS grants that body deeming authority:

  • An organization accredited by a deemed program is 'deemed' to have demonstrated compliance with the corresponding Medicare CoP.
  • If an organization loses its accreditation due to serious, uncorrected survey deficiencies, its deemed status is revoked, placing Medicare and Medicaid provider agreements at immediate risk of termination.

CMS Medical Record CoP (42 CFR § 482.24)

The primary regulatory intersection between CMS CoP and healthcare privacy/security resides in 42 CFR § 482.24 (Condition of Participation: Medical Record Services):

  1. Standard: Form and Retention of Record (42 CFR § 482.24(b)): Medical records must be retained in their original or legally reproduced form for at least five (5) years.
  2. Standard: Confidentiality of Record (42 CFR § 482.24(a)): The hospital must have a procedure for ensuring the confidentiality of patient records. Information from or copies of records may be released only to authorized individuals.
  3. Standard: Security of Electronic Health Records (42 CFR § 482.24(b)(3)): Systems must ensure that only authorized personnel make entries in medical records, enforce user authentication, and prevent unauthorized record alteration.

2. The Joint Commission (TJC) Privacy & Security Standards

The Joint Commission accredits more than 22,000 healthcare organizations and programs across the United States. TJC evaluates privacy and security through two primary chapters of the Comprehensive Accreditation Manual: Information Management (IM) and Rights and Responsibilities of the Individual (RI).

Information Management (IM) Chapter

The IM standards focus on how an organization designs, captures, safeguards, and analyzes health information to deliver safe, high-quality patient care:

  • Standard IM.01.01.01 (Planning for Information Management): The hospital plans for managing information. This requires the facility to assess its internal and external information needs, define uniform data definitions, and integrate clinical and administrative systems.
  • Standard IM.02.01.01 (Privacy and Confidentiality): The hospital maintains the privacy and confidentiality of information. The hospital must:
    • Implement written policies preventing unauthorized access, disclosure, or modification of health records across all media.
    • Enforce role-based access rules limiting staff access strictly to the information necessary to perform clinical or operational duties.
    • Protect verbal communications from casual eavesdropping in public corridors, nurse stations, and waiting areas.
  • Standard IM.02.02.01 (Information Security, Integrity, and Continuity): The hospital maintains the security and integrity of information. Key requirements include:
    • Technical defenses protecting electronic systems from malicious software, intrusions, and unauthorized modifications.
    • Comprehensive disaster recovery and business continuity plans, including formal downtime procedures that ensure patient care continues uninterrupted during EHR outages.
    • Periodic testing of data backups, emergency electrical power for server rooms, and validation of off-site replication.

Rights and Responsibilities of the Individual (RI) Chapter

While the IM chapter addresses administrative and technical controls, the RI chapter addresses the human and ethical dimensions of patient care:

  • Standard RI.01.01.01 (Respecting Patient Rights): The hospital respects, protects, and promotes patient rights. Specifically, TJC evaluates:
    • Acoustic Privacy: Ensuring sensitive clinical inquiries, triage interviews, and financial screenings occur in environments designed to minimize sound transmission to unauthorized bystanders.
    • Visual and Physical Privacy: Providing privacy curtains, closed doors, and appropriate patient draping during clinical examinations, dressing changes, and inpatient transport through public hallways.
    • Confidential Communications: Honoring patient requests to receive communications by alternative means or at alternative locations, mirroring 45 CFR § 164.522(b).

3. National Committee for Quality Assurance (NCQA)

NCQA is the preeminent accrediting body for managed care organizations, health maintenance organizations (HMOs), preferred provider organizations (PPOs), and Accountable Care Organizations (ACOs). Because health plans maintain aggregated claims, clinical, and financial data for millions of insured members, NCQA standards enforce robust administrative data protections.

Core NCQA Privacy & Security Requirements

  1. Member Confidentiality and Rights (NCQA Health Plan Standards):
    • Health plans must implement documented policies restricting internal employee access to member PHI based strictly on business necessity.
    • Explicit procedures must govern verbal communications, member identity verification in call centers, and member portal security.
    • Protection of sensitive categories: Heightened protections must guard mental health records, substance use treatment details, and reproductive health claims from unauthorized employer or family view.
  2. Credentialing & Recredentialing (CR Standards):
    • Health plans collect exhaustive personal, financial, and legal records from participating physicians, including medical license verifications, malpractice claims history, National Practitioner Data Bank (NPDB) query results, and adverse disciplinary actions.
    • NCQA CR standards mandate that all practitioner credentialing records and peer review committee deliberations be kept strictly confidential in restricted-access physical files or encrypted digital repositories.
  3. Quality Measurement and HEDIS Data Collection:
    • The Healthcare Effectiveness Data and Information Set (HEDIS) requires health plans to collect clinical data from thousands of provider medical charts to measure quality performance across 90+ clinical measures.
    • NCQA requires health plans to collect only the minimum necessary medical record components needed to validate HEDIS measures, execute binding Business Associate Agreements (BAAs) with chart retrieval vendors, and enforce end-to-end encryption for electronic data transfers.
  4. Delegation Oversight Standards:
    • Health plans frequently outsource claims processing, utilization management, pharmacy benefits (PBMs), or credentialing verification (CVOs) to third parties.
    • NCQA delegation standards legally obligate the health plan to conduct formal pre-delegation security assessments, execute written contracts detailing privacy safeguards, and conduct documented annual compliance audits of delegates' data protection protocols.

4. Commission on Accreditation of Rehabilitation Facilities (CARF)

CARF International establishes accreditation standards for behavioral health centers, addiction treatment facilities (such as Opioid Treatment Programs), medical rehabilitation hospitals, and community living services. Because CARF-accredited programs serve populations with highly sensitive conditions, its standards place unique emphasis on dignity and specialized confidentiality.

Distinctive CARF Privacy Protections

  1. Person-Centered Privacy and Dignity: CARF standards require that an individual's personal dignity and right to confidentiality be explicitly integrated into their Individualized Treatment Plan (ITP). Programs must train staff to eliminate stigmatizing language and ensure confidential treatment environments.
  2. Express Written Consent for Audio/Video Recordings: Unlike acute hospital care where treatment consent forms are broadly bundled, CARF enforces a strict, standalone standard for media capture:
    • Any audio, video, or photographic recording of a client—whether for clinical supervision, telehealth, counselor training, or research—requires an explicit, separate, time-limited, and revocable written consent.
    • The consent must detail the exact purpose of the recording, identify all individuals authorized to view it, specify the retention duration, and outline secure destruction protocols.
  3. Intersection with 42 CFR Part 2 and State Behavioral Health Laws: CARF-accredited substance use disorder programs must demonstrate full operational compliance with 42 CFR Part 2, including the mandatory federal prohibition against redisclosure notice and strict physical segregation of SUD records from general medical records.

5. Comparative Matrix: Accreditation Bodies vs. Privacy & Security Mandates

DimensionThe Joint Commission (TJC)NCQACARF International
Primary Healthcare SectorInpatient hospitals, ambulatory surgery, long-term careManaged care organizations, health plans, ACOs, PCMHsBehavioral health, addiction medicine, physical rehab
CMS Deemed StatusYes (Hospitals, Ambulatory Surgery, Home Health)No (Focus is on commercial, Medicare Advantage, Medicaid MCOs)Yes (Select Opioid Treatment Programs, DMEPOS)
Governing Chapters / DomainsInformation Management (IM), Patient Rights (RI)Member Rights & Responsibilities, Credentialing (CR), Quality (QI)Person-Centered Planning, Confidentiality, Rights of Persons Served
Distinctive Privacy FocusAcoustic privacy at triage/counters, visual curtains, chart securityCredentialing file confidentiality, HEDIS data safety, delegation auditsMandatory explicit written consent for audio/video recordings, SUD dignity
Survey Evaluation MethodOn-site Tracer Methodology, staff interviews, environmental roundsElectronic documentation review, annual delegation audits, file auditsDirect client interviews, clinical record reviews, facility tours

6. Accreditation Survey Methodologies & Evaluation Techniques

Accreditation surveyors do not merely inspect static written policy manuals in an administrative conference room. They utilize dynamic, real-time audit techniques to test whether policies are actively operationalized on the clinical frontlines.

┌─────────────────────────────────────────────────────────────────────────┐
│                     TJC SURVEY EVALUATION PROCESS                       │
└────────────────────────────────────┬────────────────────────────────────┘
                                     │
        ┌────────────────────────────┼────────────────────────────┐
        │                            │                            │
        ▼                            ▼                            ▼
┌──────────────────────┐   ┌──────────────────────┐   ┌──────────────────────┐
│ Individual Tracers   │   │   System Tracers     │   │ Environmental Rounds │
│ • Follows active pt  │   │ • IT / Info Mgmt     │   │ • Unattended PCs     │
│ • Audits EHR logs    │   │ • Infection control  │   │ • Hallway whiteboards│
│ • Inspects bedside   │   │ • Medication safety  │   │ • Server room locks  │
│   privacy / curtains │   │ • Downtime drills    │   │ • Shredding consoles │
└──────────┬───────────┘   └──────────┬───────────┘   └──────────┬───────────┘
           │                          │                          │
           └──────────────────────────┼──────────────────────────┘
                                      ▼
                     ┌──────────────────────────────────┐
                     │  Unannounced Staff Interviews    │
                     │  • Test 'Break-Glass' protocols  │
                     │  • Phishing reporting knowledge │
                     │  • Release of info escalation    │
                     └──────────────────────────────────┘

1. Tracer Methodology

Tracer methodology is TJC's core survey technique. Surveyors select active patients and 'trace' their care trajectory across every department (Emergency → Imaging → Surgery → Intensive Care → Inpatient Floor → Pharmacy → Billing):

  • Individual Patient Tracers: While evaluating clinical care, surveyors simultaneously evaluate information privacy. Surveyors examine where the patient's paper chart is stored, whether computer monitors are angled away from public view, whether verbal handoffs are conducted discreetly, and whether patient dignity is preserved during physical exams.
  • Real-Time EHR Audit Log Queries: During an individual tracer, surveyors may request the hospital's IT or Privacy Officer to generate a real-time audit log of the patient's electronic medical record. Surveyors cross-reference staff members who accessed the chart against the patient's assigned care team to detect unauthorized snooping.
  • System Tracers: Focus on enterprise-wide programs, such as Information Management. Surveyors convene meetings with the Privacy Officer, Security Officer, CIO, and HIM Director to evaluate data governance, risk analysis results, disaster recovery testing, and EHR downtime drills.

2. Environmental Rounds & Physical Security Inspections

Surveyors conduct physical walk-throughs across all operational areas, actively looking for safeguards failures:

  • Unattended, unlocked workstations with active clinical sessions in public hallways.
  • Patient names and clinical details displayed on unshielded whiteboards in public view.
  • Unsecured paper shredding bins or unattended recycling consoles.
  • Uncollected printouts, faxes, or diagnostic reports sitting on output trays.
  • Unlocked server closets, network patch panels, or telecommunications rooms.

3. Unannounced Frontline Staff Interviews

Surveyors stop staff members (nurses, registration clerks, environmental services workers, medical assistants) to ask direct, situational questions:

  • 'If you suspect a coworker is looking at a celebrity patient's chart, how do you report it?'
  • 'Show me how you lock your computer screen when stepping away.'
  • 'What happens if the electronic health record goes down right now? Where are your paper downtime forms stored?'
  • 'If a patient asks for a complete electronic copy of their medical record, where do you direct them?'

7. CHPS Exam Tips & Candidate Traps

[!TIP] Exam Watch: Accreditation vs. OCR Enforcement Achieving Joint Commission accreditation or receiving a clean accreditation report does not grant immunity from HHS Office for Civil Rights (OCR) investigations or Civil Monetary Penalties (CMPs). TJC is a private accrediting organization with CMS deeming authority; HHS OCR is a federal law enforcement agency. While OCR may consider accreditation evidence during an audit, accreditation does not replace or supersede HIPAA statutory enforcement.

[!WARNING] Candidate Trap: The 'Incidental Disclosure' Defense During Accreditation Candidates often assume any verbal disclosure in a hospital is excused under HIPAA's incidental disclosure exception (45 CFR § 164.502(a)(1)(iii)). On accreditation exams, this is a major trap. TJC surveyors will cite a hospital under standard RI.01.01.01 if staff discuss sensitive clinical matters in public areas without taking reasonable precautions (such as speaking softly, pulling curtains, or moving to a private consultation alcove). An incidental disclosure is only legally defensible if reasonable safeguards were operationalized.

[!IMPORTANT] Candidate Trap: CARF Audio/Video Recording Consent Never assume a standard general treatment consent form satisfies CARF requirements for recording clinical sessions. CARF requires an explicit, separate, written authorization that specifies purpose, viewers, retention, and revocation rights. Questions regarding therapeutic recordings in rehabilitation or substance use settings test this specific standard.

Loading diagram...
Accreditation Tracer Methodology & Privacy Audit Flow
Test Your Knowledge

During an unannounced Joint Commission triennial survey at a 400-bed acute care hospital, a surveyor conducting an Individual Patient Tracer in the emergency department observes a triage nurse discussing a patient's psychiatric history and substance use diagnosis at an open counter while other waiting patients are seated three feet away. Additionally, the surveyor notices an unshielded whiteboard displaying patient full names, chief complaints, and attending physicians visible from the public waiting room. Under Joint Commission standards and HIPAA, what deficiency exists and what operational standard is implicated?

A
B
C
D
Test Your Knowledge

A commercial health maintenance organization (HMO) is preparing for an NCQA Health Plan Accreditation survey. During a pre-survey internal compliance audit, the privacy team reviews the organization's credentialing verification organization (CVO) processes and delegation agreements. Which of the following practices is essential to satisfy NCQA standards regarding the privacy and confidentiality of credentialing information?

A
B
C
D
Test Your Knowledge

A residential addiction treatment facility accredited by CARF International wishes to record group therapy sessions for clinical supervision, quality improvement, and counselor-in-training education. Under CARF confidentiality standards and specialized behavioral health privacy regulations, which operational protocol must the facility enforce before initiating any recording?

A
B
C
D