Healthcare Compliance Due Diligence Checklist: A Complete Guide for 2026

Buying, selling, or partnering with a healthcare organization is a high-stakes decision. A balance sheet tells only part of the story. The real risk often hides in expired licenses, sloppy billing, weak data protection, and quiet government investigations.

In January 2026, the U.S. Department of Justice reported more than $6.8 billion in False Claims Act recoveries for fiscal year 2025, the largest single-year total in the law’s history. More than $5.7 billion came from the health care sector. When a healthcare business has compliance problems, those problems follow the new owner.

That is why a careful review matters before you sign. This healthcare compliance due diligence checklist covers the legal, financial, clinical, and data protection areas, with the documents to request and the warning signs to watch for.

Ready to Simplify HIPAA Compliance?

Our intuitive HIPAA compliance software helps you stay secure, meet all regulations, and streamline your processes. Get started today and stay compliant with ease!

What Is a Healthcare Compliance Due Diligence Checklist?

A healthcare compliance due diligence checklist is a structured review of an organization’s legal, financial, and clinical health. You use it before a merger, an acquisition, a partnership, or a self-audit. Think of it as a guided inspection that tells you which documents to ask for, what to verify, and which problems should make you pause.

Why Compliance Due Diligence Matters in Healthcare Deals

In most industries, a bad surprise after a deal closes is a headache. In healthcare, it can be a fine, a payback demand, or a halt to operations, because Medicare and Medicaid carry strict rules and real penalties.

When you buy a healthcare business, you often inherit its history. Old billing mistakes, unpaid overpayments, and open investigations become your liability. A good review brings these into the open while you can still adjust the price or walk away.

Buy-Side vs. Sell-Side

The same checklist serves two goals depending on which side you sit on.

  • Buy-side: You hunt for hidden risk. Each problem is a reason to lower the price, ask for protections, or rethink the deal.
  • Sell-side: You review your own business first, fix the issues early, and protect your value before anyone signs a letter of intent.

When to Use This Checklist

You do not need a pending sale to put this checklist to work. It earns its place in a merger or acquisition, a new partnership, a change of ownership (often called a CHOW), and a routine internal audit. Using the same review regularly keeps you ready for any of these moments.

How to Scope and Build Your Document Request List

List every document you need, then collect it all in one secure shared folder so both sides work from the same source. A simple tracker keeps things moving by giving each item a category, an owner, a due date, and a status.

Here is a sample tracker format:

Document Category

Owner

Due Date

Status

Corporate records

Legal team

March 15

Complete

Medicare enrollment

Billing manager

March 18

In progress

HIPAA risk analysis

IT director

March 20

Not started

Staff credentialing files

HR director

March 22

In progress

Setting Up Your Data Room and Assigning Owners

A data room is just a secure online folder where the requested files sit. Set clear access so the right people see the right files, and group documents by topic. If patient information passes between the two sides, remove it or handle it through a HIPAA-safe process, since Protected Health Information, or PHI, should not float around in a shared folder during a deal. Give each item an owner and a due date, mark its status, and hold a weekly check-in so nothing slips through the cracks.

Adjusting the Checklist for Your Type of Organization

No two healthcare businesses need the exact same review. A lab cares deeply about its CLIA certificate, while a home health agency focuses on accreditation and patient charts. Match the depth of your review to the organization in front of you, whether it is a hospital, a physician group, a long-term care home, a behavioral health practice, a pharmacy, or a device maker.

1. Corporate Structure, Ownership, and Governance

Before you study the details, understand who owns this business and how it is built.

Ownership Structure, Entities, and Related-Party Transactions

Ask for an ownership chart, a list of any sister or parent companies, and details on every entity tied to the business. Pay close attention to deals made with owners or their family members, since a lease, loan, or service contract with an insider can hide a conflict of interest or an inflated cost.

Board Governance, Minutes, and Corporate Records

Board meeting notes from the past few years show whether leadership truly watches over compliance, so look for real discussion of risks and problems, not rubber-stamp approvals. Check that the company’s legal name, addresses, and provider ID numbers match across all records, because small mismatches can indicate sloppy recordkeeping or an entity that is not set up as it claims.

2. Licenses, Accreditation, and Regulatory Standing

A healthcare business runs on permission, and without current licenses it cannot legally operate or get paid.

Facility, Professional, CLIA, and DEA Registrations

Gather every license the business holds, including the building’s operating license and each provider’s professional license. Two extra items deserve a check: a CLIA certificate covers labs that test human samples, and a DEA registration is needed to handle controlled medications. In states that require a Certificate of Need before a facility is built or expanded, confirm those approvals are valid too.

Accreditation, Survey History, and Sanctions

Accreditation bodies like the Joint Commission, DNV, CHAP, and ACHC inspect healthcare organizations and report what they find. Ask for the most recent survey reports and the corrective action plans that followed, because a deficiency is normal, but the fix is what matters. Look back at past inspections, not just the latest one, and ask about any penalties or sanctions. A few findings should slow you down: expired licenses, a license name or address that does not match other records, repeat deficiencies cycle after cycle, and problems that were never corrected.

3. Medicare, Medicaid, and Fraud & Abuse Risk

Federal programs bring strict rules and strong penalties, and for many providers they make up half or more of income.

Enrollment in Medicare, Medicaid, and TRICARE

Confirm the organization is properly enrolled in the programs it bills. Medicare enrollment lives in a system called PECOS, and each provider should have an active National Provider Identifier, or NPI. Check that enrollment is current and revalidated on time, and apply the same care to TRICARE, the military health program, where it is used.

Stark Law and Anti-Kickback Statute Arrangements

The Stark Law bars a doctor from sending patients for certain services to a business the doctor or a close family member profits from, unless the deal fits a specific allowed exception, and it applies even when no one meant to break it. The Anti-Kickback Statute is a criminal law that forbids paying or accepting anything of value to encourage referrals paid by federal programs. Review physician deals, leases, and bonus structures with both rules in mind.

False Claims Act Risk, Whistleblower Actions, and Self-Disclosures

The False Claims Act creates penalties for billing the government for things that were not properly provided, and many cases start with a whistleblower who files what is called a qui tam lawsuit. Ask whether the organization has faced any such suits or made voluntary disclosures about billing errors, and find out how each was resolved. A past disclosure is not always a red flag, but you need to know it exists.

Exclusion Lists (LEIE, SAM) and Integrity Agreements

The government keeps lists of people and companies banned from federal health programs, mainly the OIG List of Excluded Individuals and Entities (the LEIE) and the System for Award Management (SAM). Screen owners, leaders, and billable staff against these lists, since employing an excluded person can trigger paybacks and fines. If the organization settled a past case, it may operate under a Corporate Integrity Agreement, which adds years of oversight the new owner inherits. Watch for undisclosed settlements, staff on an exclusion list, physician pay that looks too high for the work, and billing patterns far outside the norm.

4. Financial Health and Revenue Cycle Review

Financial strength matters, but so does how the organization earns its money. Billing errors and coding problems create legal risk.

Financial Statements, Adjusted EBITDA, and Quality of Earnings

Request audited financial statements for the past three years. If the organization does not have audited statements, request reviewed or compiled statements. Look at revenue trends, profit margins, and cash flow. A quality of earnings report adjusts EBITDA for one-time expenses, related-party payments, and other items that may not continue after the deal.

Compare revenue to industry benchmarks. If a skilled nursing facility reports 95% occupancy while the industry average is 80%, verify the numbers. High revenue can hide aggressive billing practices that will not survive an audit.

Billing, Collections, and the Numbers to Watch

How well a business bills and collects often decides whether it survives. A few figures give a fast read on its health:

  • Denial rate: how often payers reject claims.
  • AR aging: how long bills sit unpaid.
  • Clean claim rate: the share of claims paid the first time, without rework.
  • Net collections: the share of allowed revenue actually collected.


Also request payer mix data. If 80% of revenue comes from one insurer, losing that contract could destroy the business.

Coding Accuracy, Recoupments, and Audit Exposure

Request results from recent coding audits. Auditors review a sample of charts to see if the diagnosis and procedure codes match the documentation. Errors lead to overpayments, which payers can recoup. If an audit finds a 15% error rate, the payer may extrapolate that rate across all claims and demand repayment for years of billing.

Ask if any payers have demanded recoupment in the past three years. Large recoupments can wipe out a year’s profit. Also check for pending Recovery Audit Contractor (RAC) or Unified Program Integrity Contractor (UPIC) audits. These audits often result in repayment demands.

5. Payer Contracts, Reimbursement, and Payer Mix

Payer contracts determine how much the organization gets paid. Losing a major contract after closing can sink the deal.

Assignability and Change-of-Control Clauses

Read each insurer contract with one question in mind: what happens when the business changes hands? Some contracts transfer easily, while others end or need fresh approval, so a contract that cannot transfer puts future revenue at risk. Find these clauses early so there are no surprises after closing.

Reimbursement Rates, Value-Based Contracts, and Payer Mix

The rate listed on paper is rarely the rate the business keeps, so work out the real number after denials, withholds, and adjustments. Pay attention to value-based contracts, where payment ties to quality or savings goals, since these carry both upside and risk. Map out how much revenue comes from each payer, because a business that leans on one insurer faces a real danger if that contract ends or the rate drops.

6. Material Contracts, Leases, and Vendor Agreements

Beyond payers, a healthcare business runs on many contracts and vendor agreements tied to patient data.

Major Contracts, Leases, and Change-of-Control Terms

Gather the contracts that keep the business running, such as supply agreements, service contracts, building leases, partnership deals, and loans. Read the terms that matter most, like length, renewal, and cost, since a long, locked-in contract on bad terms is a cost the new owner takes on. Check each one for a change-of-control clause, and list every contract that needs consent or notice before the deal can close, because missing one can stall a transaction.

Business Associate Agreements and Vendor Contracts

Under HIPAA, any vendor that handles protected health information must sign a Business Associate Agreement (BAA). Request a list of all vendors and confirm each one has a signed BAA on file. Missing BAAs create liability if the vendor has a data breach.

Review the terms of each BAA. The agreement should require the vendor to report breaches, encrypt data, and allow the organization to audit security controls. Weak BAAs shift too much risk to the organization.

Property and Equipment (Owned and Leased)

List the real estate and equipment the business owns or leases, including where each item sits, how it is used, and the terms of any lease. This helps the buyer understand what comes with the deal and what carries ongoing costs.

7. Medical Staff, Credentialing, and Privileges

Credentialing ensures that doctors and other practitioners meet professional standards. Errors in credentialing create liability if an unqualified provider harms a patient.

Credentialing Files and Source Verification

Request credentialing files for all employed and affiliated physicians, nurse practitioners, and physician assistants. Each file should include:


Credentialing must happen before the provider sees patients. If the organization lets a provider work while credentialing is pending, it risks billing denials and professional liability.

Privileges, Peer Review, and Individual Practitioner Claims

Privileges define what procedures a provider can perform. Request the medical staff bylaws and privilege lists. Confirm that each provider only performs procedures within their privileges. A family medicine doctor performing surgery without surgical privileges creates liability.

Peer review is the process of evaluating provider performance. Request summaries of peer review activity (with patient names redacted) for the past two years. Look for patterns. If the same provider keeps making the same mistakes, the organization may not be taking corrective action.

Also request malpractice claims against individual providers. High-risk providers create liability for the organization, especially if leadership knew about the risk and did nothing.

Physician Employment and Pay (Fair Market Value)

Request employment contracts for all employed physicians. Compensation must reflect fair market value for the work performed. Paying a doctor far above or below market rates can violate Stark Law.

Compare compensation to national benchmarks from sources like the Medical Group Management Association (MGMA). If a primary care doctor earns $400,000 per year while the benchmark is $250,000, find out why. High pay may reflect productivity bonuses, administrative duties, or other legitimate factors. It may also reflect an attempt to induce referrals.

8. Strength of the Existing Compliance Program

A strong compliance program reduces risk. A weak program, or no program, signals that the organization does not take compliance seriously.

The Seven Elements of an Effective Compliance Program

The OIG outlines seven elements of an effective compliance program:

Element

Present?

Evidence

Written policies and procedures

Yes/No

Policy manual, review dates

Compliance officer and committee

Yes/No

Job description, meeting minutes

Training and education

Yes/No

Training records, attendance logs

Effective communication

Yes/No

Hotline, reporting mechanism

Internal auditing and monitoring

Yes/No

Audit reports, corrective actions

Disciplinary standards

Yes/No

Disciplinary policy, examples

Prompt response to problems

Yes/No

Investigation records, fixes

Request evidence for each element. A policy manual that sits on a shelf does not count. Look for proof the program works in practice.

How the Program Works Day to Day

  • Ask how the compliance program operates. Does the compliance officer report to the board or to the CEO? Board reporting is better because it keeps the officer independent. How often does the compliance committee meet? Quarterly meetings are standard.
  • Review the code of conduct and key policies. Policies should cover billing, coding, fraud prevention, conflicts of interest, and reporting violations. They should be updated annually and distributed to all staff.
  • Check training records. New employees should receive compliance training during orientation. All staff should receive annual refresher training. If training completion is below 80%, the organization is not serious about compliance.
  • Request hotline reports for the past two years. A hotline lets employees report concerns anonymously. If the hotline receives zero reports, it may mean employees do not trust the process or do not know it exists. If it receives many reports, look at how the organization investigated and resolved them.

9. HIPAA, Data Privacy, and Cybersecurity

HIPAA requires healthcare organizations to protect patient information. Violations can lead to fines, lawsuits, and loss of trust.

The Privacy Rule, Security Rule, and Three Safeguards

HIPAA includes two main rules. The Privacy Rule controls how organizations use and disclose protected health information (PHI). The Security Rule controls how organizations protect electronic PHI (ePHI). The Security Rule requires three types of safeguards:

  • Administrative safeguards: Policies, risk analysis, workforce training
  • Physical safeguards: Locked doors, security cameras, device controls
  • Technical safeguards: Access controls, encryption, audit logs


Request the organization’s most recent HIPAA risk analysis. The analysis should identify every system that stores or transmits ePHI and assess the risk to that data. It should also document safeguards in place and any gaps.

Some states have their own privacy laws, such as the California Consumer Privacy Act. If the organization operates in multiple states, confirm it complies with state laws as well.

What the 2025 HIPAA Security Rule Update Means for Due Diligence

The rules here are moving. In January 2025, the Office for Civil Rights published a proposed update to the HIPAA Security Rule in the Federal Register, aimed at strengthening protection for electronic patient data. The proposal would turn many safeguards that were once optional into clear requirements, with stronger expectations around items like multi-factor login, encryption, and asset inventories.

Because this rule has been moving toward a final version, the exact requirements may change. Check HHS.gov for the current status before you rely on any single standard, and factor coming changes into how you judge an organization’s readiness.

Risk Analyses, Past Breaches, and Incident Response

A security risk analysis is a formal review of where patient data could be exposed, so ask for recent ones along with the plans made to fix the gaps they found. Review the breach history and the incident response plan, which is the playbook for handling a data event. A business with no recent risk analysis or no real plan is a clear concern.

Access Controls, Encryption, and Vendor Protection of ePHI

Request logs showing who accessed patient records in the past six months. Look for unusual activity, such as employees accessing records they do not need for their job. Many breaches involve insiders snooping on celebrity patients or family members.

Confirm that all devices storing ePHI use encryption. Laptops, tablets, smartphones, and portable drives should encrypt data so it cannot be read if the device is lost or stolen.

Review how vendors protect ePHI. Request a list of all vendors with access to patient data and confirm each one has a signed BAA. Ask what security controls the vendor uses. If the vendor stores data in the cloud, confirm the cloud provider also meets HIPAA standards.

10. Technology and EHR Systems

Technology supports clinical care and business operations. Outdated or unreliable systems create risk.

EHR/EMR Systems and Interoperability

The electronic health record, or EHR, holds patient information and drives daily care. Find out which system the organization uses and how well it connects with other software, since systems that do not talk to each other create extra cost and risk for a buyer.

Independent Security Testing, Backup, and Disaster Recovery

A SOC 2 report is an independent review of a company’s controls, and a penetration test is a simulated attack that hunts for weak spots, so ask for recent results of both. Confirm that data is backed up and that the business has a tested plan to recover after an outage, and ask how fast systems can come back online. A plan that has never been tested is only a hope, so look for proof of a real drill.

11. Clinical Quality, Patient Safety, and Outcomes

Quality metrics show how well the organization cares for patients. Poor quality creates liability and may signal deeper problems.

Quality Scores, Patient Experience, and Outcomes

Review the main measures of care quality, including patient experience surveys, how often patients return soon after discharge, and infection rates. Compare these against similar organizations, since scores that lag behind point to problems that hurt both patients and the business.

Quality Improvement Plans and Handling of Serious Events

A good organization studies its mistakes and works to prevent them, so ask for its quality improvement plans and the records of how it handled serious events. Look for honest reviews and real changes, because a serious event with no follow-up is a sign of weak safety habits. Understand the patient mix too, since a practice with very complex cases needs different staffing than one with routine visits.

12. Day-to-Day Operations and Facility Safety

Operational details matter. Small problems like broken equipment or expired fire extinguishers can become big problems if left unaddressed.

Life Safety, Emergency Preparedness, and Equipment Upkeep

Confirm the basics of a safe building: fire safety systems, a clear emergency plan, and proof that equipment is maintained on schedule. Missing maintenance records or stale emergency drills are simple but real warning signs that often point to wider gaps.

Pharmacy and Controlled Substance Controls

Medications and controlled substances most of all need tight tracking, so review how the organization stores, counts, and reconciles its drug supply. Gaps in controlled-substance records draw serious regulatory attention, so confirm that the counts add up and the logs are complete.

Lab Quality, Specimen Handling, and Waste Disposal

If the business runs a lab, check its quality systems and how it handles specimens, since proper handling protects test accuracy and patient safety. Confirm the lab takes part in required quality checks. Review how the organization stores and disposes of hazardous and medical waste too, because improper disposal can break environmental rules and carry fines.

13. Staffing, Employment, and Benefits

Staff are the organization’s most important asset. Turnover, lawsuits, and misclassification create risk.

Staffing Levels, Turnover, and the Staff You Depend On

Check whether the organization has enough people to do the work safely, since high turnover can signal culture problems and adds risk for a new owner. Identify the few people the business truly depends on, because if they leave after the sale, the value can drop fast.

Employment Contracts, Non-Competes, and Worker Classification

Review employment contracts and any non-compete clauses, and confirm workers are correctly labeled as employees or contractors, since misclassifying them can lead to back taxes and penalties. One caution on non-competes: whether they can be enforced varies by state, and the rules are changing, so treat them as an open question and check current state law rather than assuming they hold.

Pay, Benefits, Hidden Liabilities, and Labor Relations

Look at how staff is paid and what benefits they receive, because some benefit plans carry future costs that do not show up on a simple income statement. Ask about pensions, retirement plans, and any unfunded promises. Review any history of labor disputes, union activity, or employee complaints too, since open claims are a cost and a distraction you want to know about before you take ownership.

14. Lawsuits, Insurance, and Risk Management

Legal exposure can outlast a deal, so this section finds the lawsuits, gaps, and risks not already covered.

Litigation History and Non-Fraud Government Inquiries

Request a list of all pending and threatened lawsuits from the past five years. Include professional liability claims, employment disputes, contract disputes, and regulatory actions. Exclude fraud cases, which are covered in Section 3.

Ask about government inquiries that are not related to fraud. Examples include OSHA investigations, environmental violations, and civil rights complaints. Even if the inquiry does not lead to a lawsuit, it may require corrective action or fines.

Insurance Coverage, Gaps, and Workers’ Compensation

Review every insurance policy the organization holds and confirm the coverage fits the size and type of business. Look for gaps where a claim could land with no protection, since thin coverage in a high-risk area is a real concern. Check the workers’ compensation history too, which covers staff injured on the job, because a high claim count adds cost and signals safety issues.

Going Beyond the Checklist: Ongoing Compliance Monitoring

Due diligence should not end the day a deal closes; the smartest organizations treat it as an ongoing habit.

Why a One-Time Review Isn’t Enough and How Software Helps

A single review captures one moment in time. The day after you finish, a license can lapse, a vendor can slip, or a new rule can take effect. Software makes ongoing review possible without drowning your team in paperwork. The right tool keeps every policy, contract, and record in one place, scores your risk, and tracks open tasks over time, so you stay ready year-round instead of scrambling before each audit.

Creating a Plan to Fix Issues and Integrate After the Deal Closes

When a review turns up problems, you need a plan to fix them, so list each issue, assign an owner, and set a deadline. After a deal, this plan also guides how you fold the new organization into your own and turn findings into action.

How ComplyAssistant Makes Healthcare Compliance Due Diligence Easier

Due diligence involves thousands of documents, dozens of people, and tight deadlines. ComplyAssistant simplifies the work by putting everything in one place and automating routine tasks. 

Here is how a manual approach compares to using the software:

Task

Spreadsheets and Manual Files

ComplyAssistant

Storing documents

Scattered across folders and inboxes

One secure, organized home

Tracking tasks

Easy to lose or forget

Owners, due dates, and status in one view

Running risk reviews

Built from scratch each time

Built-in assessments ready to use

Audit reports

Hours of pulling files together

Reports you can produce on demand

Vendor and BAA records

Hard to find when needed

Tracked in one spot with review dates

ComplyAssistant gives you a single home for policies, documents, and vendor records, with a signed Business Associate Agreement for every vendor and its terms and review dates easy to find. You can run built-in risk assessments without starting from scratch and produce audit-ready reports on demand. The software was built for healthcare, not adapted from a general tool, so it supports the frameworks healthcare teams work with, including HIPAA, HITECH, HITRUST, and NIST.

Wrapping Up! Making Your Due Diligence Checklist Work for You

A healthcare compliance due diligence checklist is more than busywork. It protects the price you pay, brings risk into the open early, and makes any transition smoother for both sides.

The strongest organizations do not treat this review as a one-time task. They build it into a habit, checking their own health the same way a buyer would, so they are ready when an opportunity or a deal arrives.

 If you want to make this process easier and keep your records ready year-round, ComplyAssistant can help. Reach out to ComplyAssistant’s professional team to see how a single platform can carry the weight of your compliance work.

Frequently Asked Questions

What is included in a healthcare compliance due diligence checklist?

A healthcare compliance due diligence checklist includes licenses, accreditation, Medicare enrollment, payer contracts, billing data, credentialing files, HIPAA risk analyses, vendor agreements, financial statements, quality metrics, lawsuits, and insurance policies. The exact items depend on the type of organization and transaction.

How long does healthcare compliance due diligence take?

Healthcare compliance due diligence typically takes four to twelve weeks. The timeline depends on the organization’s size, complexity, and readiness. Smaller organizations with organized records may complete due diligence in one month. Large hospitals or organizations with compliance problems may take three months or more.

What are the biggest warning signs in healthcare due diligence?

The biggest red flags include excluded individuals on staff, pending fraud investigations, high billing error rates, missing or expired licenses, weak HIPAA safeguards, repeat survey deficiencies, and unresolved malpractice claims. Any of these issues can stop a deal or require major price adjustments.

What’s the difference between buy-side and sell-side due diligence?

Buy-side due diligence is performed by the buyer to find risk and inform the purchase price. Sell-side due diligence is performed by the seller before listing the organization for sale. Sellers fix problems early to protect deal value and speed negotiations.

How is HIPAA compliance verified during due diligence?

HIPAA compliance is verified by reviewing the most recent risk analysis, incident response plan, breach history, Business Associate Agreements, access logs, encryption status, and training records. Buyers may also interview the privacy officer and test security controls.

Who should perform healthcare compliance due diligence?

Healthcare compliance due diligence requires a team. Attorneys review contracts and legal issues. Accountants review financial statements and billing data. Compliance consultants review policies, training, and regulatory standing. IT specialists review cybersecurity and EHR systems. The buyer’s internal compliance officer coordinates the process.

 

Ken Reiher

After more than 20 years of consulting and management experience in healthcare, I understand how quickly things can shift. My prior work in revenue cycle, finance, corporate compliance and auditing helped me appreciate the importance of building relationships to develop strategies and facilitate required change. In my current role as VP of Operations for ComplyAssistant, I wear quite a few hats, managing business operations, supporting consulting engagements, assisting with product development and supporting client engagement. I enjoy working directly with clients, listening to their needs, and working hand-in-hand with the software development team to create solutions that work for the modern needs of security and compliance in healthcare and other verticals. I received my BS and MBA degrees from Fairleigh Dickinson University Madison. And, I’m honored in my role to contribute to various industry publications, and to be affiliated with HIMSS (NJ, NY, Delaware Valley and National), NJPCA, NJAMHAA and HFMA (NJ and National).