8.4 Risk Assessments for New and Existing Services
Key Takeaways
- A new service or new technology review must be completed before the first case, covering clinical evidence, privileging criteria, staff competency, equipment, procedure-specific consent, insurance confirmation, regulatory approval, contracts, and post-launch monitoring with predefined stop criteria.
- Notifying the broker and carrier of a new service line is a required step, because a new exposure may fall outside the current professional and general liability program or trigger a policy provision requiring notice of a material change in operations.
- Inherent risk is scored before controls and residual risk after; boards and executives make accept-or-mitigate decisions on residual risk, and residual risk above the organization's stated tolerance threshold must be escalated rather than accepted locally.
- The four risk treatment options are accept, mitigate or reduce, transfer, and avoid; contractual transfer moves financial consequence but does not eliminate liability arising from apparent agency.
- In an acquisition, the acquiring organization's occurrence policy does not reach the target's pre-closing incidents, so prior-acts or tail coverage must be confirmed in writing before closing.
Why Proactive Assessment Sits at the Center of Domain 4
Domain 4, Health Care Operations, contributes 20 scored items to the CPHRM, and task B states it plainly: conduct risk assessments to identify exposures related to new and existing services and enterprise-wide services. Most of the rest of the exam is retrospective — an event happened, a claim arrived, a survey found a deficiency. Risk assessment is the one discipline that runs before harm, and the exam rewards candidates who recognize when a stem is asking for prospective work rather than investigation.
The scope boundary is tested just as hard as the content. The risk manager does not decide whether a service opens. The risk manager convenes the review, identifies exposures, documents them, offers mitigation options, and escalates residual risk that exceeds tolerance to the people who own the decision. Answer choices in which the risk manager "denies privileges," "vetoes the program," or "approves the new laser" exceed the role. Answer choices that say "convene a multidisciplinary review before the first case," "notify the broker of the new exposure," or "document the residual risk and take it to the risk committee" are inside it.
The New Service and New Technology Review
A new service review (also called a new technology or new program assessment) is a structured, multidisciplinary evaluation completed before a service goes live. It is triggered by more than a brand-new service line: a new procedure a surgeon learned at a weekend course, a new device, a new patient population (pediatrics in an adult facility, bariatrics, high-risk obstetrics), a new site of care, a telehealth expansion into another state, an investigational protocol, or a co-management deal with an outside group.
The review should cover, at minimum:
- Clinical need and evidence base. Is there demonstrated volume and a body of evidence, or is this a physician-driven request in search of a market? A service with no volume cannot sustain competence.
- Credentialing and privileging criteria. Criteria specific to the new procedure — training, case logs, proctoring, and Focused Professional Practice Evaluation (FPPE) — must be written and approved before the first case is scheduled, not retrofitted afterward. (The credentialing process itself is covered in the policy and credentialing section.)
- Staff competency and volume thresholds. Nursing, technologists, anesthesia, and perioperative staff need documented training and a competency check-off. Where the literature supports a volume-outcome relationship, set a minimum annual case threshold for both the practitioner and the program.
- Equipment, space, and support services. Biomedical acceptance testing, reprocessing and sterilization capability, imaging and blood bank availability, ICU and rapid-response backup, and a written rescue plan for the predictable complication.
- Informed consent content. A novel or investigational procedure requires consent language beyond the standard form: the procedure's newness at this facility, the practitioner's experience with it, alternatives including referral elsewhere, any investigational device or Institutional Review Board (IRB) status, and disclosure of financial relationships with the device manufacturer.
- Insurance coverage confirmation. This is the step candidates forget. A new service line may fall outside the current professional and general liability program, may require a specific endorsement, or may trigger a policy provision requiring notice of a material change in operations. Notify the broker and carrier in writing and get the confirmation before the first case.
- Regulatory and licensure approval. State facility licensure category, certificate of need (CON) where the state requires it, CMS provider-based and enrollment rules, FDA clearance or approval status of the device, IRB approval for research, and state-specific telehealth licensure.
- Contract review. Vendor, co-management, and joint venture agreements need indemnification language, insurance requirements with certificates of insurance and additional-insured status, a Business Associate Agreement (BAA) if protected health information moves, and a compliance and counsel review of the financial arrangement.
- Policies, protocols, and order sets. Written before go-live, including the escalation and transfer plan.
- Post-launch monitoring with predetermined stop criteria. Define the monitoring period, the metrics, the review interval, and — critically — the thresholds that trigger suspension. If leadership cannot state in advance what result would make them stop the program, the assessment is incomplete.
New Service Review Checklist
| Review area | Core questions | Risk management deliverable |
|---|---|---|
| Clinical need | Is there evidence and projected volume to sustain competence? | Written summary of evidence and volume projection |
| Privileging | What criteria, proctoring, and FPPE plan apply? | Draft criteria routed to medical staff office and credentials committee |
| Staff competency | Who is trained, and how is competency verified? | Competency validation plan with completion dates |
| Equipment and space | Is equipment accepted, reprocessing validated, rescue capability present? | Biomedical and infection prevention sign-off |
| Consent | Does the form address novelty, experience, alternatives, and research status? | Procedure-specific consent reviewed by counsel |
| Insurance | Is the exposure covered, and does the carrier need notice? | Written broker and carrier confirmation or endorsement |
| Regulatory | Licensure, CON, CMS enrollment, FDA status, IRB approval? | Regulatory clearance file |
| Contracts | Indemnification, insurance requirements, BAA, compliance review? | Executed agreement with risk-transfer terms |
| Monitoring | What is measured, how often, and what stops the program? | Monitoring plan with predefined stop criteria |
A general surgeon returns from a weekend course and asks to begin performing a new endoscopic bariatric procedure in six weeks. The hospital already owns a compatible scope. What is the risk manager's most appropriate action?
Choosing the Right Assessment Method
Different exposures call for different tools, and the exam tests whether you can match the method to the question.
- Failure Mode and Effects Analysis (FMEA) — a proactive, step-by-step analysis of a defined process to find failure modes before they cause harm. Use it when the question is "how could this process fail?" (Mechanics are taught in the RCA and FMEA section.)
- Gap analysis — a structured comparison of current practice against an external requirement: a regulation, an accreditation standard, a clinical practice guideline, or a contract obligation. Use it when the question is "where do we fall short of the standard?"
- Hazard Vulnerability Analysis (HVA) — prioritizes natural, technological, human, and hazardous-materials threats by probability and impact for emergency planning. (Covered in depth in the emergency preparedness section.)
- Security risk assessment — two distinct meanings. The HIPAA Security Rule requires an accurate and thorough assessment of risks and vulnerabilities to electronic protected health information, and it must be maintained and updated, not done once. Separately, a physical security and workplace violence assessment evaluates access control, high-risk departments such as the emergency department and behavioral health, and staffing patterns.
- Infection Control Risk Assessment (ICRA) — required before construction, renovation, and maintenance work by accreditation standards and the FGI design and construction guidelines. It pairs the type of activity with the risk level of the adjacent patient population to set containment requirements, and is completed with infection prevention and facilities as a pre-construction risk assessment (PCRA) covering air quality, infection control, utilities, noise, vibration, and emergency egress.
Scoring, Registers, and Risk Appetite
Assessment without scoring produces a list nobody can act on. Most programs score each identified exposure on a likelihood x consequence matrix, then record it in a risk register.
| Likelihood \ Consequence | 1 Insignificant | 2 Minor | 3 Moderate | 4 Major | 5 Catastrophic |
|---|---|---|---|---|---|
| 5 Almost certain | 5 Moderate | 10 High | 15 High | 20 Extreme | 25 Extreme |
| 4 Likely | 4 Low | 8 Moderate | 12 High | 16 Extreme | 20 Extreme |
| 3 Possible | 3 Low | 6 Moderate | 9 Moderate | 12 High | 15 High |
| 2 Unlikely | 2 Low | 4 Low | 6 Moderate | 8 Moderate | 10 High |
| 1 Rare | 1 Low | 2 Low | 3 Low | 4 Low | 5 Moderate |
Two scores matter for every entry. Inherent risk is the score before controls — the raw exposure. Residual risk is the score after existing and planned controls are credited. Boards and executives make decisions on residual risk; inherent risk shows how much the controls are actually buying you, which is the argument for keeping them funded.
A complete risk register entry names the exposure, the owner, the inherent score, the current controls, the residual score, the treatment decision, the action items with due dates, and the review date. Treatment decisions fall into four choices:
| Treatment | Meaning | Typical example |
|---|---|---|
| Accept | Retain the risk knowingly, within tolerance | Low-severity, low-frequency property exposure absorbed in a deductible |
| Mitigate / reduce | Lower likelihood or consequence with controls | Hard-stop alerts, competency validation, double-check protocols |
| Transfer | Shift financial consequence to another party | Insurance, indemnification and hold-harmless clauses, outsourcing with contractual terms |
| Avoid | Do not undertake or discontinue the activity | Declining to launch a service the organization cannot support safely |
Risk appetite is the amount and type of risk the organization is willing to pursue in order to meet its objectives; it is set by the board and is strategic. Risk tolerance is the acceptable variation around that appetite, expressed as concrete thresholds — for example, no residual score of 15 or higher may be accepted below the executive risk committee. Thresholds are what turn a scoring exercise into a decision rule, and they define the escalation path: residual risk above tolerance moves up, not sideways.
A risk register entry for an outpatient sedation program carries an inherent score of 20. After a new capnography monitoring requirement and mandatory rescue training, the residual score is 12. Organizational policy states that residual scores of 10 or higher may not be accepted at the department level. What should the risk manager do?
Reassessing Existing Services
Existing services are reassessed on a cycle and on trigger. The annual enterprise-wide assessment refreshes the register, but the exam is more interested in the event-driven triggers:
- A claim or loss trend in one service line, one shift, or one practitioner group
- A sentinel event or serious safety event that reveals a system vulnerability broader than the single case
- Staffing changes — high turnover, heavy locum or agency use, loss of a subspecialist, a new residency rotation
- New technology or an EHR change, including an upgrade that alters order sets, alerts, or documentation flow
- Volume shifts in either direction; volume that falls below the competence threshold is as dangerous as volume that overwhelms capacity
- Service-line acquisition, outsourcing, or a vendor contract termination
- Regulatory change, accreditation survey findings, or repeat deficiencies
- Patient complaint and grievance themes clustering around one unit or process
Mergers, Acquisitions, Outsourcing, and Joint Ventures
These transactions carry exposures that ordinary operations do not, and the risk manager belongs on the due-diligence team.
In an acquisition, examine open claims and their reserves, known events not yet reported, litigation and regulatory history, any corporate integrity agreement or open survey, credentialing and licensure files for practitioners who will come across, malpractice history, and the state of the target's policies and event reporting system. The dominant risk-financing question is prior acts: an acquiring organization's occurrence policy does not cover incidents that happened before the entity became an insured, and a claims-made program requires either tail (extended reporting) coverage or prior-acts (nose) coverage for those exposures. Confirm coverage in writing before closing, not after the first demand letter arrives.
Outsourced and joint-ventured services — hospitalists, emergency physicians, anesthesia, radiology reads, dialysis, laboratory, environmental services — raise a distinct question: whose liability is it? The contract should set indemnification, insurance minimums with certificates and notice of cancellation, who credentials and who monitors quality, whose policies apply, and how events are reported to the hospital. But the contract does not settle patient perception. Under apparent (ostensible) agency, a hospital can be held liable for a contractor's negligence when the patient reasonably believed the practitioner was a hospital employee — an exposure that badging, signage, and consent-form language can reduce but not eliminate.
Scenario
An orthopedic group wants to begin same-day outpatient total joint replacement in the hospital's attached ambulatory surgery center, with the first case in six weeks. The right move is not to approve or refuse. The risk manager convenes a new-service review, and within two meetings the team surfaces four exposures: the ASC has no overnight capability and no written transfer agreement for the patient who cannot be discharged; the anesthesia group's contract predates the ASC and does not name it as a covered site; patient selection criteria excluding higher-risk comorbidities have not been written; and the professional liability program was underwritten without outpatient arthroplasty in the exposure schedule. The risk manager documents each exposure with an inherent and residual score, obtains a carrier endorsement, drafts transfer and selection protocols with the medical director, and takes one residual item — the anesthesia contract gap — to the executive risk committee because it exceeds tolerance. The launch is delayed four weeks. That delay is the deliverable.
Exam Traps
- Confusing reactive with proactive. RCA follows harm. Risk assessment precedes it. A stem describing a service that has not yet launched is not asking for an RCA.
- Skipping the insurance step. New services and acquisitions can fall outside the current program. Notifying the broker and carrier is a tested step, and it is the one candidates omit.
- Exceeding scope. The risk manager identifies, documents, advises, and escalates. Approving, denying, and disciplining belong to medical staff leadership, executives, and the governing body.
- Treating a signed contract as risk elimination. Contractual transfer moves financial consequence; apparent agency and reputational exposure remain.
- Launching without stop criteria. A monitoring plan with no predefined threshold for suspension is not a monitoring plan.
- Assuming a certificate of insurance is continuing proof. It documents coverage on the day it is issued; require notice of cancellation and re-verify at renewal.
A health system is acquiring a freestanding infusion center that will begin administering chemotherapy under the system's name. During due diligence, which risk-financing action is most important for the risk manager to complete before closing?