Is Your Facility Truly Prepared? A Fall Compliance Checklist
As National Preparedness Month arrives every September, healthcare compliance and facility leaders face a dual priority: maintaining operational readiness for unexpected disruptions while preparing for annual survey requirements.

Under the Centers for Medicare & Medicaid Services (CMS) Emergency Preparedness Conditions of Participation (CoPs), surveyors continue to scrutinize Emergency Operations Plans (EOPs) for active, updated evidence of compliance rather than static shelf documentation.
Whether managing a acute care hospital, an ambulatory surgical center, or a long-term care facility, September serves as the ideal mid-year checkpoint to audit your four core pillars of CMS Emergency Preparedness before federal fiscal year transitions and winter weather risks hit.
The 4 Pillars of CMS Emergency Preparedness: Audit Checklist
CMS unifies its emergency preparedness standards across 17 provider types under Appendix Z of the State Operations Manual (SOM). Your September audit should evaluate readiness across each of the four core regulatory pillars:
1. Risk Assessment and Planning (All-Hazards Approach)
- [ ] Hazard Vulnerability Analysis (HVA): Has your facility updated its HVA within the last 12 months to reflect new regional threats, climate dynamics, or infrastructure changes?
- [ ] Cybersecurity Integration: Does your plan explicitly address extended IT outages, EHR downtime, and ransomware events as emergency operational triggers?
- [ ] Patient Population Tracking: Are procedures documented to account for vulnerable populations, medical equipment dependencies, and transportation logistics during a facility evacuation?
2. Policies and Procedures
- [ ] Subsistence Provisions: Are agreements up to date for emergency food, water, medical supplies, fuel, and backup generator services?
- [ ] Shelter-in-Place & Evacuation Protocols: Are primary and alternate evacuation routes verified, and are staff trained on transfer agreements with receiving facilities?
- [ ] Staffing Continuity: Do policies establish clear delegation of authority, succession plans, and protocols for managing volunteer healthcare practitioners during an emergency?
3. Communication Plan
- [ ] Contact Roster Verification: Are contact lists for current staff, attending physicians, local emergency management agencies, and state public health authorities updated and tested?
- [ ] Alternate Communications: Are primary and secondary communications systems (e.g., satellite phones, two-way radios, cloud-based notification systems) tested for operational readiness?
- [ ] Interoperability: Is there a process to share patient information and operational status with regional healthcare coalitions and emergency operations centers (EOCs)?
4. Training and Testing Program
- [ ] Annual Training Log: Have all current employees, contracted staff, and volunteers completed mandatory annual emergency preparedness training?
- [ ] Dual Exercise Requirement: Has your facility completed its two required annual testing exercises?
- Exercise 1: One full-scale community-based exercise (or an actual emergency event documented as an exercise).
- Exercise 2: One additional exercise of choice (tabletop exercise, mock disaster, or additional full-scale drill).
- [ ] After-Action Reports (AARs): Are signed After-Action Reports and Improvement Plans (IPs) on file for every exercise or real-world incident conducted this year?
3 Common Survey Pitfalls to Avoid This Fall
- Outdated Alternate Care & Vendor Agreements: Surveyors frequently cite facilities for Memorandum of Understanding (MOU) documents that have expired or fail to outline specific delivery timelines for emergency supplies.
- Missing After-Action Improvement Tracking: Conducting a drill is only half the requirement. Failing to document identified weaknesses and track corrective action plans to completion is a top source of Appendix Z citations.
- Siloed Cyber Emergency Plans: Cyberattacks are operational emergencies. If your IT department’s disaster recovery plan is not fully integrated into the facility-wide Emergency Operations Plan, your facility may fail survey scrutiny during an unannounced inspection.
September Action Steps for Compliance Leaders
- Schedule a Tabletop Exercise: If your facility still needs to fulfill its second annual exercise requirement, use September to host a tabletop exercise focused on cyber-downtime or supply disruption.
- Re-Verify Vendor MOUs: Review all third-party emergency supply contracts, fuel delivery agreements, and patient transfer MOUs (Transfer Agreements) for current dates and signatures.
- Conduct a Spot Audit of Training Records: Randomly audit 10% of employee files across clinical and administrative units to ensure mandatory annual training documentation is complete before Q4.
Regulatory References & Authorities
- CMS State Operations Manual (SOM): Appendix Z – Emergency Preparedness Guidance for All Provider Types (42 CFR §482.15 for Hospitals; §483.73 for LTC; §485.623 for CAHs).
- ASPR TRACIE: Technical Resources, Assistance Center, and Information Exchange for Healthcare Emergency Preparedness.
- The Joint Commission: Emergency Management Standards (EM.10.01.01 through EM.15.01.01).




