A Law Firm Guide for Initial and Ongoing Compliance
Ambulatory surgery centers (ASCs) operate in a highly regulated environment in which certification survey performance directly affects licensure, Medicare participation, reimbursement, and operational continuity. Both initial and ongoing surveys are designed to assess whether an ASC satisfies applicable federal and state requirements, including the Medicare Conditions for Coverage (CfCs), as well as standards imposed by accrediting organizations. For owners, operators, governing bodies, and management teams, survey readiness should be treated not as an episodic project, but as an enterprise compliance function requiring documented oversight, disciplined implementation, and prompt remediation of identified risk areas.
Understanding Certification Surveys
Certification surveys evaluate whether an ASC can demonstrate compliance with applicable regulatory obligations in practice, not merely on paper. The initial certification survey generally occurs before the facility may accept patients or bill Medicare, while ongoing surveys may occur periodically, through validation activity, or in response to complaints or adverse events. Surveyors typically assess governance, policies and procedures, clinical operations, the physical environment, staff qualifications, patient records, and other indicia of regulatory compliance.
Recent Regulatory Changes Affecting ASCs
Recent CMS rulemaking reflects a continued policy shift toward expanding the role of ASCs in outpatient surgical care, while maintaining quality reporting and documentation expectations. For calendar year 2026, CMS finalized a 2.6 percent update to ASC payment rates for facilities that satisfy applicable quality reporting requirements, with the statutory payment reduction continuing to apply to ASCs that fail to meet those requirements. ASC operators should evaluate these changes not only as reimbursement updates, but also as compliance triggers that may require review of coding, billing, quality reporting, payer communications, and governing-body oversight.
CMS also finalized substantial changes to the ASC Covered Procedures List, including the addition of hundreds of procedures and a transition toward eliminating the Medicare inpatient-only list over a three-year period. These changes may create new opportunities for ASCs in specialties such as orthopedics, spine, cardiovascular, vascular, and other procedural areas, but they also heighten the need for defensible patient-selection criteria, medical-staff review, privileging, emergency-transfer planning, anesthesia protocols, informed-consent processes, and documentation supporting the appropriateness of the ASC site of service.
The ASC Quality Reporting Program also remains a material compliance consideration. Recent CMS updates remove certain measures while preserving the consequence of a reduced payment update for failure to satisfy reporting requirements. ASCs should confirm that their quality-reporting workflows, vendor arrangements, data validation processes, and internal calendars are current and adequately documented, particularly where reporting responsibilities are delegated to management companies, consultants, or third-party vendors.
From a survey-readiness perspective, these regulatory changes should be incorporated into policy review, staff education, credentialing, privileging, and governing-body minutes. Expansion of covered procedures does not eliminate the ASC’s obligation to demonstrate that each procedure can be performed safely in the facility’s setting and within its approved scope of services. Legal counsel should be involved when regulatory changes affect service-line expansion, physician ownership or compensation arrangements, payer contracting, informed-consent materials, state licensure requirements, or communications with regulators and accrediting organizations.
Preparing for the Initial Certification Survey
- Review Regulatory Requirements: Management should confirm that the ASC’s policies and procedures reflect current federal CfCs, state licensure obligations, and accrediting-body standards, including requirements imposed by organizations such as The Joint Commission or AAAHC. Counsel can assist in identifying regulatory gaps, reconciling conflicting requirements, and documenting the basis for compliance decisions.
- Staff Training and Credentialing: ASCs should maintain complete, survey-ready evidence that all personnel are properly credentialed, trained, and competent in relevant clinical procedures, infection-control obligations, emergency protocols, and patient-rights requirements. Deficiencies in credentialing or competency files may create both regulatory exposure and operational risk.
- Facility Readiness: The physical environment should be reviewed from a surveyor’s perspective, including safety, accessibility, cleanliness, equipment maintenance, emergency supplies, signage, and patient-facing materials. Where deficiencies are identified, the ASC should document corrective action and retain evidence of completion.
- Documentation and Recordkeeping: Medical records, incident reports, quality improvement materials, maintenance logs, medication records, and administrative files should be organized in a manner that permits prompt production during a survey. Because survey findings often turn on what can be documented, incomplete or inconsistent records may be treated as evidence of noncompliance.
- Mock Surveys: Internal mock surveys should be conducted under a structured protocol to identify operational, documentation, and training gaps before they are cited by a regulator or accrediting body. ASCs should consider involving counsel when mock-survey findings may implicate sensitive compliance, quality, or risk-management issues.
Preparing for Ongoing Certification Surveys
Ongoing certification surveys are comprehensive regulatory evaluations intended to confirm that an ASC continues to satisfy patient-safety, quality-of-care, and compliance standards after initial certification. These reviews are often unannounced and may require immediate access to clinical areas, records, policies, equipment, and staff. Surveyors commonly review written policies, observe clinical practice, examine medical records, and interview personnel to determine whether the ASC’s actual operations are consistent with its regulatory obligations and internal procedures.
- Continuous Quality Improvement: The ASC should maintain a documented quality assessment and performance improvement process that evaluates patient outcomes, infection rates, incident reports, and staff performance. Governing-body oversight and follow-through on corrective actions are particularly important because surveyors may look for evidence that quality concerns are identified, escalated, and resolved.
- Regular Policy Reviews: Policies and procedures should be reviewed and updated as regulations, accrediting standards, and operational practices change, particularly in areas such as infection prevention, medication management, anesthesia safety, emergency preparedness, patient rights, and documentation. The ASC should also retain evidence that staff have been trained on material policy changes.
- Facility Inspections: Routine facility inspections should be treated as a compliance control rather than a housekeeping exercise. ASCs should verify that equipment is serviced on schedule, supplies are appropriately stocked, the environment remains safe and accessible, and identified deficiencies are tracked to closure.
- Record Audits: Periodic audits should include medical records, medication logs, sterilization records, incident reports, maintenance logs, and administrative documents. Audit results should be documented, trended where appropriate, and linked to corrective action so the ASC can demonstrate active oversight.
- Staff Engagement: Staff should understand their survey roles, know where key policies and records are maintained, and feel prepared to answer surveyor questions accurately. Training should emphasize truthful, concise responses and prompt escalation of legal, compliance, or patient-safety concerns to appropriate leadership.
Common Ongoing-Survey Deficiencies
Recurring survey deficiencies commonly involve incomplete or inconsistent documentation, outdated policies, inadequate evidence of staff training, infection-control gaps, medication-management errors, and lapses in equipment maintenance. From a risk-management perspective, these findings are significant because they may support deficiency citations, corrective-action obligations, heightened scrutiny, or other regulatory consequences. ASCs should conduct mock surveys, maintain survey-ready records, correct deficiencies promptly, and document remediation in a manner that demonstrates both accountability and sustained compliance.
Recent Enforcement Examples
Recent enforcement activity illustrates that ASC compliance risk extends beyond survey citations and may involve payment integrity, credentialing, coding, documentation, privacy, and self-disclosure issues. These examples are useful for governing bodies and management teams because they show how operational weaknesses can develop into repayment exposure, civil monetary penalties, False Claims Act liability, reputational harm, and heightened regulator scrutiny.
- Billing and coding enforcement: In 2025, the U.S. Department of Justice announced that Forefront Dermatology S.C. and Henghold Surgery Center LLC agreed to pay $847,394 to resolve allegations that they violated the False Claims Act by knowingly causing the submission of falsely coded Medicare claims for wound-repair procedures. The government alleged that linear repairs were coded as flap repairs and that smaller flap repairs were coded as larger repairs. Compliance tip: ASCs should maintain coding-validation protocols, periodically audit high-risk procedures, require documentation that supports the level and type of service billed, and escalate coding trends to compliance leadership before they become repayment or False Claims Act exposure.
- Credentialing and licensure enforcement: In 2026, HHS-OIG reported that PSA Ambulatory Surgery Center of Killeen, LLC entered into a $46,730.30 settlement after self-disclosing allegations that it submitted TRICARE claims for services furnished by an unlicensed nurse. Although the amount was relatively modest, the matter highlights that credentialing failures can create reimbursement and exclusion-related risk even when the underlying services were actually furnished. Compliance tip: ASCs should use real-time license monitoring, maintain complete credentialing files, assign responsibility for tracking expirations, suspend affected personnel promptly when licensure concerns arise, and document any billing review or self-disclosure analysis.
- Data security and patient information exposure: A 2025 class action settlement involving Mount Kisco Surgery Center LLC, doing business as The Ambulatory Surgery Center of Westchester, arose from allegations relating to a data security incident in which private information may have been accessible by unauthorized parties. The defendant denied wrongdoing, but the matter demonstrates that privacy and cybersecurity weaknesses can become litigation and reputational risks for ASCs. Compliance tip: ASC compliance programs should include cybersecurity governance, vendor oversight, access controls, breach-response planning, workforce privacy training, and documented coordination among legal, privacy, information technology, and operational leadership.
These matters also should be viewed against the broader enforcement environment. DOJ reported more than $2.9 billion in False Claims Act settlements and judgments in fiscal year 2024, with health care fraud remaining a major area of federal enforcement activity. In addition, CMS compliance materials for ASCs identify insufficient documentation, no documentation, and incorrect coding as leading causes of improper payments. Accordingly, ASC leaders should connect enforcement lessons directly to operational controls: survey readiness should be aligned with billing compliance, credentialing, quality reporting, privacy safeguards, vendor oversight, corrective-action tracking, and governing-body reporting rather than managed in separate silos.
Risk Management Strategies
ASC risk management should integrate survey readiness, billing compliance, credentialing, quality reporting, privacy safeguards, and governance oversight into a coordinated compliance program. The following strategies can help management identify risk early, document remediation, and reduce the likelihood that operational issues develop into survey citations, repayment obligations, enforcement exposure, or litigation.
- Establish survey-readiness governance: Assign responsibility to the governing body, administrator, clinical leadership, compliance personnel, and counsel so survey readiness is tracked as an ongoing compliance function with clear reporting lines and accountability.
- Use a risk-based audit calendar: Schedule recurring audits for high-risk areas, including infection control, anesthesia documentation, medication management, credentialing, billing and coding, quality reporting, emergency preparedness, and vendor performance.
- Maintain corrective-action tracking: Each identified deficiency should have an owner, deadline, remediation plan, supporting documentation, and follow-up review to confirm that the correction is sustained over time.
- Connect survey findings to enforcement risk: Documentation gaps, coding errors, credentialing lapses, quality-reporting failures, and privacy incidents should be evaluated for potential repayment, self-disclosure, False Claims Act, licensure, and accreditation implications.
- Conduct privileged internal reviews where appropriate: When issues may involve serious compliance, billing, quality, or patient-safety exposure, ASCs should involve counsel early to structure the review and preserve privilege where available.
- Strengthen vendor and delegation oversight: Contracts and delegated-service arrangements should be reviewed for billing, quality reporting, sterile processing, anesthesia services, information technology, credentialing, management services, and other outsourced functions that may affect compliance.
- Prepare staff for surveyor interactions: Training should emphasize truthful, concise responses; familiarity with key policies and records; prompt escalation of uncertain questions; and avoidance of speculation during surveyor interviews.
- Document governing-body oversight: Governing-body minutes should reflect review of quality indicators, incidents, complaints, audit results, corrective actions, credentialing decisions, policy updates, regulatory changes, and material compliance risks.
- Build escalation protocols for serious findings: Management should identify when to notify counsel, ownership, the governing body, insurers, accrediting organizations, or regulators, particularly for adverse events, systemic deficiencies, billing concerns, privacy incidents, or patient-safety issues.
- Test readiness through exercises: Mock surveys and tabletop exercises should address adverse events, infection-control breaches, medication errors, cyber incidents, emergency transfers, and other scenarios that may require coordinated operational and legal response.
Survey Readiness Checklist with Examples
The following checklist can be used by ASC leadership, compliance personnel, and counsel to test whether the facility can demonstrate compliance during an unannounced survey. Each item should be supported by current documentation, assigned responsibility, and evidence of follow-up where deficiencies are identified.
- Governance and oversight: Confirm that governing-body minutes reflect review of quality indicators, incidents, complaints, audits, corrective actions, credentialing, policy updates, and regulatory changes. Examples: minutes approving a revised infection-control policy, board review of quarterly quality data, documented follow-up on an adverse event, and evidence that corrective actions were tracked to closure.
- Policies and procedures: Verify that policies reflect current Medicare CfCs, state licensure requirements, and accrediting-body standards, and that they are approved, dated, accessible, and consistent with actual practice. Examples: current emergency-transfer policy, medication-management policy, anesthesia-assessment policy, patient-rights notice, and staff attestation showing training on revised policies.
- Staffing, credentialing, and training: Review license status, privileges, competency assessments, orientation records, continuing education, and role-specific training. Examples: current nursing licenses, surgeon privilege forms, anesthesia credentialing files, infection-prevention competency checklists, emergency-drill attendance sheets, and documentation resolving expired or pending credentials.
- Clinical operations: Audit pre-operative, intra-operative, anesthesia, discharge, emergency-transfer, and post-operative processes for consistency with policy and approved services. Examples: completed pre-operative assessments, anesthesia evaluations, informed-consent forms, discharge instructions, transfer-agreement documentation, patient-selection criteria, and post-operative follow-up records.
- Infection prevention and environment of care: Confirm that infection-control practices and the physical environment are monitored, documented, and corrected when issues are identified. Examples: sterilization logs, biological indicator results, hand-hygiene observations, cleaning schedules, infection-surveillance reports, equipment-maintenance records, emergency-supply checks, environmental-rounding reports, and deficiency-tracking logs.
- Medication management: Inspect storage, labeling, expiration tracking, controlled-substance controls, medication reconciliation, administration records, and incident follow-up. Examples: temperature logs, expired-medication checks, crash-cart logs, medication-error reports, controlled-substance reconciliation sheets, pharmacy-consultant reports, and corrective-action documentation.
- Records and documentation: Test whether surveyors could promptly access complete and consistent medical, quality, maintenance, medication, incident, vendor, and administrative records. Examples: sample closed-chart audits, incident-report files, quality-improvement committee materials, maintenance logs, vendor-service records, medication logs, complaint files, and proof that missing documentation was corrected.
- Billing, coding, and quality reporting: Review whether claims, coding, documentation, and ASC Quality Reporting Program processes are supported and monitored. Examples: high-risk procedure coding audits, documentation supporting billed services, quality-reporting calendars, vendor-submission confirmations, data-validation reports, claim-denial trend reports, and repayment or self-disclosure analyses where appropriate.
- Privacy, security, and vendor oversight: Confirm that privacy safeguards, cybersecurity controls, breach-response procedures, and delegated-service arrangements are documented and actively monitored. Examples: HIPAA training records, access-review logs, breach-response plan, cybersecurity tabletop exercise results, business associate agreements, billing-vendor monitoring reports, IT service records, and sterile-processing vendor performance reviews.
- Mock survey preparation: Conduct mock surveys and tabletop exercises using a surveyor-style approach, including staff interviews, document-retrieval testing, clinical-area walkthroughs, and corrective-action follow-up. Examples: mock-survey findings report, staff interview scripts, tracer-audit results, emergency-transfer tabletop notes, cyber-incident exercise documentation, assigned corrective-action owners, deadlines, and verification of completion.
Legal Considerations
ASCs should involve legal counsel early when interpreting regulatory requirements, evaluating survey findings, responding to statements of deficiencies, or preparing corrective-action plans. Counsel can assist with policy review, governance documentation, contract and delegation issues, privilege-sensitive internal reviews, and communications with regulators or accrediting bodies. When deficiencies are identified, timely remediation and a well-documented response are critical to protecting certification status, minimizing enforcement risk, and preserving the ASC’s ability to operate without interruption.
Conclusion
Certification survey readiness is a core compliance obligation for ASCs. Facilities that approach survey preparation through ongoing governance oversight, disciplined documentation, staff training, and timely legal review are better positioned to withstand scrutiny, respond effectively to deficiencies, and maintain certification while continuing to provide safe, high-quality outpatient surgical care.

