9.4 Policies for High-Risk Clinical and Operational Domains

Key Takeaways

  • Policy topics are prioritized using the high-risk, high-volume, problem-prone triad plus regulatory mandate, the organization's own claim and loss history, and sentinel event or near-miss learning.
  • An organization's own policy is routinely admitted into evidence as the standard it set for itself, so a policy stricter than the law or than actual achievable practice manufactures liability.
  • The verbs shall and must create a mandatory duty while should and may preserve clinical discretion, and labeling an advisory recommendation as a protocol converts judgment into a binding obligation.
  • Telemedicine licensure is generally governed by the state where the patient is physically located during the encounter, and the Interstate Medical Licensure Compact expedites obtaining additional state licenses rather than creating a national license.
  • Credentialing by proxy under the Medicare Conditions of Participation requires a written agreement under which the distant-site entity's credentialing standards meet the applicable hospital standards, the practitioner is privileged at the distant site, a current privilege list is supplied, and the practitioner is licensed in the state where the patient's hospital is located.
Last updated: July 2026

Policies for High-Risk Clinical and Operational Domains

Domain 4 asks the risk manager to collaborate on the development of policies and procedures that provide direction to the organization on topics with a significant degree of risk, naming privacy, informed consent, infection prevention, documentation, and telemedicine as examples. Note the verb: collaborate. The risk manager does not author clinical policy alone and does not approve it. The risk manager identifies which topics need one, supplies the liability lens, and routes the draft to the committee that owns it. The approval lifecycle, version control, and archival rules are covered in the policy and credentialing section of this guide. This section is about which topics get a policy, the language trap, and the named high-risk domains.


Choosing Which Topics Get a Formal Policy

An organization cannot write a policy for everything, because every policy is a promise it must then keep and be able to prove it kept. Prioritization uses a repeatable screen:

Selection criterionWhat it looks like in practice
High-riskLow frequency, high severity: blood administration, restraint and seclusion, moderate sedation, surgical fire, infant abduction, retained surgical item
High-volumeSmall defect rates multiply into real harm: patient identification, medication reconciliation, handoff communication, specimen collection
Problem-proneHistorically failure-prone steps: specimen labeling, critical result reporting, verbal and telephone orders, alarm response
Regulatory mandateThe Conditions of Participation, accreditation standards, or state licensure require a written policy: restraint, EMTALA, grievances, infection control, emergency preparedness
Claim and loss historyThe organization's own loss runs and closed-claim reviews name a recurring allegation
Event learningA root cause analysis or a cluster of near misses recommends a standardized process
New service or technologyA new service line, device, or care modality operating with no existing internal standard

The first three form the classic high-risk, high-volume, problem-prone triad borrowed from performance improvement prioritization. The remaining four are the risk manager's distinctive contribution, because they draw on data that no single clinical department holds.


The Standard-of-Care Trap

This is the most important policy-related liability concept on the exam. An organization's own policy is routinely admitted into evidence as the standard the organization set for itself. A plaintiff's counsel does not have to establish what a reasonable hospital would have done if the hospital already wrote it down and then failed to do it.

The consequence is counterintuitive: a policy that sets a standard higher than the law requires or higher than actual practice manufactures liability. A sentence such as all patients on the fall-risk protocol will be visually observed every 15 minutes reads as a commitment to safety. In litigation, measured against night staffing as it actually exists, it becomes an admission of breach every time a flowsheet shows an 18-minute gap. Aspirational language is safe only where the standard is genuinely achievable, resourced, and audited.

The defensive discipline follows directly:

  • Write what the organization can actually do and prove, then improve practice before raising the written standard.
  • Audit compliance with any policy containing a measurable interval, timeframe, or rate — and either fix the practice or amend the policy when the audit fails.
  • Avoid absolutes: always, never, all, immediately, 100 percent.
  • Match verbs to intent. Shall and must create a mandatory duty; should and may signal an expectation that preserves clinical discretion. Reserve mandatory verbs for steps that are genuinely non-negotiable.
  • Distinguish document types by how binding they are. A policy states a rule, a procedure states the steps, a protocol is a rigid clinical algorithm with defined inclusion criteria, and a guideline is advisory. Labeling an advisory recommendation as a protocol silently converts discretion into a duty.
  • Avoid rigid clinical mandates that remove appropriate professional judgment. Build an explicit deviate-and-document pathway rather than pretending exceptions never occur.
  • After a merger or acquisition, conflicting legacy policies on the same subject are a live exposure, because whichever version is stricter is the one produced in discovery. Harmonization is an integration priority, not an administrative housekeeping item.
Test Your Knowledge

A draft fall prevention policy states that all patients identified as high fall risk will be visually observed every 15 minutes. Current staffing achieves this reliably on days but not on nights, and compliance is not measured. What is the risk manager's primary concern?

A
B
C
D

The Named High-Risk Domains

DomainCore risk management angleCommon failure
Privacy and confidentialityMinimum necessary use, role-based access controls, workforce sanctions applied consistently, breach risk assessment and notification pathway, photography, recording, and social media rulesCuriosity access to a colleague's or celebrity's record; clinical texting of identifiable information
Informed consentWho obtains it (the practitioner performing the procedure), what must be disclosed, documentation of the discussion rather than only the signature, qualified interpreters and translated forms, telephone and electronic consent processes, capacity assessment, the emergency exceptionA signature witnessed by staff who cannot answer the patient's questions; no documentation that an interpreter was used
Infection preventionHand hygiene monitoring, transmission-based precautions and isolation, reportable healthcare-associated infections, outbreak response and communication, employee health and immunization, work restriction for infectious staffA policy that states a hand hygiene compliance target the organization does not actually measure
DocumentationTimeliness, authentication and countersignature, late entries labeled with the true date and time, prohibition on alteration, copy-forward controls, verbal order read-back, approved abbreviation limitsCopy-forward propagating a resolved problem for weeks and then anchoring a diagnosis
TelemedicineLicensure, standard of care parity, modality-specific consent, prescribing limits, technology failure, documentation, coverage confirmation, credentialingTreating a patient who is physically located in a state where the practitioner holds no license

Several of these carry traps worth memorizing. Informed consent disclosure is the performing practitioner's non-delegable duty; staff may witness a signature, but the conversation belongs to the person doing the procedure. Documentation policy must forbid alteration while providing a compliant late-entry method, because the remedy for an incomplete chart is a labeled addendum, never an edit. Infection prevention policy intersects with mandatory public reporting of healthcare-associated infections and with employment and occupational health law, so it should be drafted with infection prevention, occupational health, and compliance in the room together.


Telemedicine Policy in Depth

Telemedicine is the fastest-changing policy area in health care risk management. Technical safeguards and cybersecurity controls are covered in the health information technology section of this guide; what belongs here is the clinical, licensure, and liability layer.

  • Licensure follows the patient. The practice of medicine is generally deemed to occur where the patient is physically located at the time of the encounter, so the distant-site practitioner ordinarily needs a license in the patient's state. The Interstate Medical Licensure Compact offers an expedited pathway to obtain licenses in additional member states; it does not create a single national license. State-specific exceptions such as consultation exemptions, temporary telehealth registrations, and limited allowances for follow-up of an established patient vary widely and must be verified state by state. A patient who travels across a state line for a scheduled virtual visit changes the analysis mid-course, which is why location capture at the start of every encounter matters.
  • Standard of care parity. The standard of care for a telehealth encounter is the same as for in-person care. A defensible policy therefore names the presentations that are not appropriate for virtual evaluation and requires conversion to an in-person or emergency pathway. Failure to escalate a virtual encounter is an emerging claim theory.
  • Informed consent for the modality. Beyond consent to the treatment itself, the patient consents to the telehealth modality: its limitations, including the absence of a physical examination, privacy and recording practices, who else is present at either site, what happens if the connection fails, and how to obtain in-person or emergency care. Many states mandate this consent, and some specify how it must be documented.
  • Prescribing. Controlled substance prescribing by telemedicine is governed federally by the Ryan Haight Act, which generally requires at least one in-person medical evaluation before a controlled substance is prescribed by means of the internet. That requirement has been suspended by a series of DEA temporary rules extending pandemic-era telemedicine flexibilities, the most recent of which runs through the end of 2026 while a permanent rule and a special registration framework remain unfinished. Because the rule has changed repeatedly, the defensible policy references the current federal rule and the state's own telehealth prescribing limits rather than hard-coding a date, and several states impose limits stricter than federal law.
  • Technology failure contingency. The policy states what the clinician does when video drops mid-encounter: a documented attempt to reconnect, a fallback to telephone where clinically appropriate, and a defined threshold for rescheduling or directing the patient to in-person care.
  • Documentation of the virtual encounter. Record the modality used, the patient's physical location and the practitioner's location, who else was present, how patient identity was verified, the modality consent, any technical problems, and the disposition.
  • Coverage. Confirm in writing that the professional liability policy covers telehealth services and covers them in every state where patients may be located. Policies are frequently written on a state-specific basis or contain telehealth exclusions, sublimits, or endorsement requirements.
  • Credentialing by proxy. Under the Medicare Conditions of Participation, a hospital's governing body may rely on the credentialing and privileging decisions of a distant-site telemedicine entity instead of credentialing every remote practitioner itself, provided a written agreement satisfies the regulatory conditions: the distant-site entity's credentialing and privileging standards at least meet the applicable hospital medical staff standards, the individual practitioner is privileged at the distant site, the hospital receives a current list of that practitioner's privileges, the practitioner holds a license issued or recognized by the state in which the patient's hospital is located, and the originating hospital reviews the practitioner's telemedicine performance and provides that information back to the distant site for use in periodic appraisal. Proxy credentialing is optional; a hospital may still fully credential each practitioner. The written agreement is what makes the proxy route lawful.

Scenario

A health system launches direct-to-consumer virtual urgent care. Marketing wants the policy and the website to promise a licensed physician within five minutes, 24 hours a day. The clinical team wants a protocol requiring an automatic in-person referral for any complaint of chest pain. Legal notes that patients may connect from anywhere with a phone.

The risk manager's advice: strike the five-minute promise unless the staffing model can meet it and the organization will audit it, because it will be quoted back verbatim in the first delay claim. Convert the chest-pain rule from a rigid protocol into a mandatory escalation pathway that preserves and documents clinical judgment, since a protocol phrased as an absolute will be breached the first time a clinician reasonably deviates. Require capture of the patient's physical location at the start of every encounter with a hard stop when the practitioner is not licensed in that state, add the modality consent, and confirm in writing that the malpractice policy covers telehealth in every state where the service is offered.


Exam Traps

  • Trap: assuming a stricter policy is a safer policy. It becomes the standard a plaintiff uses. Write what is achievable, resourced, and audited.
  • Trap: mandatory verbs everywhere. Shall creates a duty; use should where clinical judgment must survive.
  • Trap: believing telehealth licensure follows the practitioner. It generally follows the patient's physical location, and the Compact expedites licenses rather than replacing them.
  • Trap: hard-coding federal controlled-substance telemedicine rules into a policy. They have changed repeatedly by temporary rule; reference the current rule and check state law, which may be stricter.
  • Trap: treating credentialing by proxy as automatic. It requires a written agreement meeting the Conditions of Participation, including licensure in the patient's state and a current privilege list.
  • Trap: leaving legacy policies in place after a merger. Conflicting versions on the same subject are produced together in discovery.
  • Trap: writing a policy for a topic simply because a peer hospital has one. Selection is driven by risk, volume, problem-proneness, mandate, and the organization's own loss data.
Test Your Knowledge

A physician licensed only in State A conducts a scheduled video visit with an established patient who is temporarily staying with family in State B. What is the correct licensure analysis?

A
B
C
D
Test Your Knowledge

A risk manager must recommend which of several proposed topics should receive a formal organization-wide policy this year. Which basis for prioritization is strongest?

A
B
C
D