Home Health OASIS Disclosure Policy Checklist for CMS Compliance
OASIS Data Collection Requirements
Your OASIS disclosure policy should anchor how clinicians collect the Outcome and Assessment Information Set and how leaders verify completeness before submission to CMS. Build procedures that define who completes which items, when assessments are due, and how supporting documentation backs each response.
Required assessment time points
- Start of Care: establish baseline status and service needs.
- Resumption of Care: update after an inpatient stay before services continue.
- Recertification: reassess at defined intervals to support ongoing eligibility and planning.
- Transfer to inpatient facility: capture status at transfer.
- Discharge: record outcomes and services provided.
Operational rules
- Use CMS item definitions verbatim to ensure consistent scoring across staff and locations.
- Designate qualified clinicians to complete and sign assessments; document dates and times of completion.
- Cross-check OASIS with the plan of care, therapy evaluations, and medication reconciliation for internal consistency.
- Track CMS Data Submission Timelines with internal alerts so records are completed and ready to transmit on time.
OASIS Privacy Notice Provision
Patients and representatives must understand what OASIS is, why it is collected, and how their information is protected. Your policy should describe how the privacy notice is delivered, documented, and retained alongside the clinical record.
Checklist
- Prepare an OASIS privacy notice that explains the purpose, authority for collection, routine uses, and patient rights.
- Provide the notice at or near Start of Care; use interpreters or translated materials as needed.
- Document acknowledgment with a signature, or record the reason when a signature is not obtainable.
- Give a copy to the patient and retain a copy per your Medical Record Retention policy.
- Train staff to answer questions about disclosures and to route privacy complaints promptly.
Electronic Data Submission Protocols
Submit OASIS electronically using the current CMS Electronic Record Layout and maintain a repeatable workflow from validation to acceptance. Security, role-based access, and audit evidence are core elements of a defensible submission process.
Submission workflow
- Export the assessment file in the required Electronic Record Layout; verify all mandatory fields and event sequencing.
- Run software edits, clear errors and critical warnings, and re-validate before transmission.
- Transmit through the CMS-designated system using authorized credentials and maintain least-privilege access.
- Review accept/reject reports the same day; correct and resubmit rejected records without delay.
- Archive submission receipts, error logs, and acceptance confirmations with the patient record or a secure repository.
- Monitor Data Submission Timelines with dashboards and escalation paths for nearing or missed deadlines.
Security controls
- Encrypt data in transit and at rest; when applicable, use solutions validated against a Federal Information Processing Standard.
- Implement unique user IDs, multi-factor authentication, and periodic access reviews.
- Document business continuity plans for outages and a resubmission protocol after service restoration.
Ensuring OASIS Data Accuracy
Accuracy starts with clear definitions, disciplined assessment practices, and routine auditing. High-quality OASIS data supports care planning, quality reporting, and the Patient-Driven Groupings Model by reliably reflecting functional status and clinical complexity.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Quality assurance checklist
- Deliver item-by-item training using CMS guidance; re-educate when updates are released.
- Use concurrent review to compare clinician narratives with OASIS responses before finalizing.
- Audit high-impact items that drive functional scoring and quality measures; give immediate feedback.
- Reconcile diagnoses, functional items, and therapy notes to prevent contradictions.
- Leverage automated edits and trend reports to track error types, late assessments, and corrections.
- Maintain a correction log with reasons, approver signatures, and resubmission dates.
Compliance with Data Format Standards
Standardized codes and formats reduce rejections and downstream rework. Ensure your software and staff apply current value sets, response options, and identifiers exactly as specified.
Format checklist
- Use the latest Electronic Record Layout and response value sets for all OASIS items.
- Enter dates, times, and IDs precisely; avoid placeholders, free text in coded fields, and invalid characters.
- Apply required code sets such as ICD-10-CM diagnoses, National Provider Identifier, and relevant Federal Information Processing Standard geographic codes when captured.
- Prevent duplicate or overlapping events with sequencing controls and version management.
- Keep mapping documentation for EMR upgrades, data conversions, and interface changes.
Medical Record Retention Policies
OASIS assessments and related artifacts are part of the legal clinical record. Define where records live, how they are indexed, and how long they are preserved to meet Medical Record Retention and payer requirements.
Retention checklist
- File each OASIS with signatures, completion dates, and correction history within the patient’s record.
- Retain adult records for at least five years after discharge or longer if required by state law; for minors, keep until the age of majority plus the required period.
- Store submission confirmations, reject/accept reports, and privacy acknowledgments with the record.
- Back up electronic records routinely and test restorations; document chain of custody for migrations.
- Use documented destruction procedures when retention periods end, including logs and approvals.
Penalties for Non-Compliance
Non-compliance can trigger survey citations, corrective action plans, and costly rework. Late, missing, or inaccurate data may delay claims, cause denials, or contribute to adverse Medicare Payment Adjustments under value-based programs.
What’s at stake
- Survey findings for failures in collection, disclosure, submission, or retention processes.
- Payment delays or recoupments when assessments are rejected or unmatched.
- Negative impacts on quality scores and potential Medicare Payment Adjustments.
- Increased audit exposure and reputational risk from unreliable data.
Summary and action steps
A strong OASIS disclosure policy aligns frontline practice, privacy communication, secure submission, and data integrity. Use structured workflows, proactive auditing, and clear accountability to meet CMS expectations every time.
- Publish and train on a unified OASIS policy and checklist.
- Automate timeline tracking, validation, and error resolution.
- Audit high-impact items and retention compliance on a set schedule.
- Continuously improve with metrics tied to rejections, corrections, and quality outcomes.
FAQs
What are the key components of the OASIS disclosure policy?
An effective policy explains the Outcome and Assessment Information Set, the authority and purpose of collection, routine uses and disclosures, patient rights, how to obtain help or file a complaint, and your Medical Record Retention approach. It also outlines staff roles, training, validation steps, and the internal escalation path for missed Data Submission Timelines.
How must OASIS data be submitted to CMS?
Submit assessments electronically using the current CMS Electronic Record Layout, after clearing software validation edits. Transmit through the designated portal with authorized credentials, review accept/reject reports, correct errors promptly, and archive confirmations. Build internal deadlines to meet CMS Data Submission Timelines and protect transmissions with strong encryption and access controls.
What are the consequences of OASIS data non-compliance?
Expect survey citations, corrective action plans, and operational rework. Financially, claim delays or denials can occur, and quality performance based on OASIS may influence Medicare Payment Adjustments under value-based programs. Repeated problems elevate audit risk and can harm your organization’s credibility.
How long must OASIS assessment records be retained?
Keep OASIS assessments as part of the clinical record for at least five years after discharge for adults, or longer if state law requires. For minors, retain records until the age of majority plus the applicable retention period. Store submission receipts and acknowledgment forms for the same duration to complete the audit trail.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.