Healthcare Compliance & CPD Training in the US: The Complete Guide

Every Learnsignal guide to US healthcare compliance, organised by topic: Joint Commission accreditation and deemed status, and HIPAA training requirements.

Learnsignal Education Team
4 min read
Updated

US healthcare compliance runs on two tracks that get confused constantly, even though they answer completely different questions and come from completely different places. One track is federal privacy and security law, which applies to protected health information regardless of who's holding it or how good their care is. The other is accreditation — a voluntary process an organization chooses to pursue, evaluated against standards written by a private, non-profit body rather than a government agency, that unlocks a specific practical benefit with Medicare and Medicaid. A hospital can be fully HIPAA-compliant and still fail an accreditation survey, or vice versa, because the two systems aren't checking for the same thing. This guide pulls together everything Learnsignal has published on US healthcare compliance so far, organized around those two tracks.

Accreditation and survey readiness

The largest accrediting body for US healthcare organizations is The Joint Commission, a private, not-for-profit organization — not a government agency — that accredits hospitals, ambulatory care, behavioral health, home care, nursing care centers, and laboratories, each under its own standards manual. Accreditation matters in practice because of deemed status: when an organization earns accreditation from an approved body like The Joint Commission, the Centers for Medicare & Medicaid Services (CMS) can "deem" it to have met the Medicare Conditions of Participation without a separate federal survey for that purpose.

Our guide to Joint Commission accreditation and staff readiness covers how the unannounced survey process actually works, what tracer methodology is and why it matters so much for training records specifically, and the recent shift from National Patient Safety Goals to the new National Performance Goals introduced under Accreditation 360. Deemed status doesn't replace state licensure, and it isn't unconditional — CMS still oversees the accrediting bodies and can act directly if a serious issue arises — but it's the mechanism that keeps a lot of hospitals from facing two separate, duplicative federal inspection processes.

Federal privacy and security training requirements

Separately from any accreditation decision, HIPAA — the Health Insurance Portability and Accountability Act — sets federal requirements around protecting patient health information that apply to virtually every US healthcare employer, regardless of size, accreditation status, or whether they participate in Medicare at all. Our guide to HIPAA training requirements covers what the Privacy and Security Rules actually require of employee training, how often refresher training needs to happen, and what enforcement looks like in practice — including a real, independently verified OCR civil money penalty case rather than generic compliance-checklist content.

HIPAA training obligations exist whether or not an organization ever pursues Joint Commission accreditation, and accreditation surveyors don't audit HIPAA compliance directly — the two systems are enforced by entirely different bodies (OCR for HIPAA, The Joint Commission and CMS for accreditation and deemed status) and an organization needs to satisfy both independently.

There's a third federal layer worth knowing about even though we haven't built out dedicated content on it: OSHA's Bloodborne Pathogens Standard, which requires specific training for employees with occupational exposure to blood or other potentially infectious materials. It's a real, distinct requirement enforced by the Department of Labor rather than HHS, but the existing content on it is already thorough and well-established across the industry, so it isn't currently a priority for us to duplicate.

How these pieces fit together

The clearest way to separate the two tracks: HIPAA is a floor that applies to everyone handling protected health information, enforced by the Department of Health and Human Services' Office for Civil Rights, with no opt-out and no connection to accreditation status. Accreditation through The Joint Commission (or another CMS-approved accrediting body) is a choice, evaluated on a multi-year survey cycle, that primarily affects an organization's standing with CMS and its reputation with patients and referral partners — but it doesn't touch HIPAA obligations at all. An organization preparing for a Joint Commission survey and one running a HIPAA training refresh are, in compliance terms, doing two unrelated pieces of work that happen to both fall under "healthcare compliance," and neither one substitutes for the other.

State licensure adds a third dimension underneath both of these. Almost every healthcare facility still needs a state operating license, granted and enforced by that state's own health department, regardless of accreditation status or HIPAA compliance record — deemed status affects the federal Medicare relationship specifically, not the separate state licensing requirement. An organization juggling all three at once needs to track state license renewal dates, its Joint Commission (or other accreditor) survey window, and its HIPAA training refresh cycle independently, because none of the three deadlines move in sync with the others.

Looking for something specific?

The topics above are the ones we've researched and verified in depth so far, and we're continuing to expand this library — state-specific mandated reporter training requirements are next on our list. If your organization is working on the training side of any of this now, it's worth looking at Learnsignal's CPD hub rather than waiting for every topic to be published. Nothing on this page is legal advice or a substitute for checking directly with the relevant body (The Joint Commission, CMS, or HHS's Office for Civil Rights) before making a decision that affects your organization's accreditation, deemed status, or HIPAA compliance.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View Pricing