The health center leader's trusted provider of HRSA Compliance expertise, mock site visits, and first-of-its-kind web-based site survey preparation tools.
HRSA Form 5A Service Descriptors Document Updates
HRSA quietly rewrote the Form 5A Service Descriptors — and the "last updated" date on the document still doesn't show it. Preventive Dental got gutted, Specialty Services vanished entirely, and several other descriptors lost language health centers that may have influenced their services. If nobody's checked your scope of project against these changes, you won't know you're out of compliance until an Operational Site Visit tells you.
Summarizing the new Scope of Project Policy Manual
HRSA just released an entirely new Scope of Project Policy Manual, retiring multiple long-standing PINs and consolidating years of scattered guidance into one document. The changes touch nearly every part of how health centers define and manage their scope — services, sites, contracts, telehealth, board approvals, and more. Some of it clarifies what you already knew. Some of it changes what's expected of you next. We broke down all of it, sorted by what's substantial, what's just clarification, and what's simply procedural — so you know where to focus first.
FTCA Coverage Eligibility of Individuals
Do you know which staff are eligible for coverage under HRSA’s Federal Tort Claims Act (FTCA) medical malpractice insurance?
Credentialing and Privileging for FQHCs and LALs
What's the difference between credentialing and privileging at an FQHC? See HRSA's exact requirements, timelines, and OSV documentation checklist.
2026 Federal Tort Claims Act (FTCA) Office Hours
HRSA opened FTCA Office Hours for the 2026 Redeeming cycle—free 15-minute sessions to help health centers complete their FTCA application. Here's how to schedule.
Frequently Asked Questions About the 2026 FTCA Application
Every year, certain questions about the FTCA redeeming application come up again and again. This year, the RegLantern team has noticed a handful of topics that keep popping up as health centers prepare their submissions. To help, I’ve pulled together the most common questions and clear guidance on each.
Do Clinical Supervisors, Peer Reviewers, and Administrators Need to Be Credentialed and Privileged?
HRSA Site Visit Protocol, Chapter 3 requires health centers to credential all clinical staff, including clinical supervisors, peer reviewers, and administrators. This blog discusses the HRSA and FTCA requirements.
HRSA NPDB Query Requirements for Health Centers
HRSA requires health centers to query the National Practitioner Data Bank (NPDB) for all clinical staff, including unlicensed or uncertified Other Clinical Staff (OCS). After flip-flopping the HRSA Site Visit Protocol language in 2020 and again in November 2025, HRSA's intent remains clear: query every LIP, OLCP, and OCS upon hire and on a recurring basis. Here's what the current guidance says, why querying OCS matters, and how to stay site-visit-ready.
Section 504 Final Rule: What FQHCs Need to Know About the New Disability Nondiscrimination Requirements
HHS updated Section 504 for the first time in 50 years. Here's what FQHCs, LALs, and community health centers need to know — and do — before the May 2026 compliance deadlines.
How Health Centers Can Be Ready for Medical Emergencies: A Practical Guide to HRSA Compliance
Discover what Federally Qualified Health Centers (FQHCs) and Look-Alikes (LALs) need to know about HRSA’s Basic Life Support (BLS) requirements. This brief guide explains who at your health center needs BLS training, what counts as valid documentation, and how to keep your records compliant and current. Learn how to identify clinical staff who require BLS, what evidence is acceptable for audits, and why even remote providers must meet these standards. Find out the best practices for maintaining up-to-date BLS credentials, including onboarding checks, renewal reminders, and the importance of clear policies. The article also covers what emergency supplies you should have on hand and how to decide between in-person, online, or licensure-embedded BLS training. Stay ready for emergencies and site visits by ensuring your health center’s policies are comprehensive, and your staff are always prepared to deliver life-saving care. Perfect for health center leaders looking for compliance tips and practical advice on BLS readiness.
Ready For Your FTCA Application Submission in 2026?
Are you ready to submit your FTCA redeeming application in 2026? This blog post will help!
The HIPAA Privacy Rule and Parental Access to Minor Children’s Medical Records
HRSA’s updated Notice of Award terms put fresh emphasis on something health centers have always had to get right: parental consent and access rules for minors’ care, as defined by applicable state and federal law. In a December 3, 2025 memo, HHS and the Office of Civil Rights reiterated that, under HIPAA, parents are generally a minor child’s “personal representative,” which usually gives them the right to access the child’s medical records and PHI—and OCR has signaled it is seeing providers restrict parental access more than HIPAA requires. At the same time, long-standing HIPAA exceptions still apply when state law allows a minor to consent to certain services, when a court orders it, or when a parent agrees to a confidentiality arrangement. The practical takeaway for HRSA-supported health centers isn’t to abandon minor consent processes, but to ensure record-access and patient portal workflows mirror the legal consent rules: parents should typically have access to non-confidential portions of the record, while minor-consent services may require limiting parental access to those specific services.
Documenting Contracted Clinical Staff on HRSA Form 5A
HRSA clarified how to document locum tenens and other contracted clinical staff on Form 5A: check every service provided and mirror it in the contract.
HRSA Site Visit Protocol Updates: November 2025
On November 20, 2025, HRSA released an updated Health Center Program Site Visit Protocol (SVP), the tool reviewers use to assess compliance during Operational Site Visits (OSVs).
Behind the scenes, HRSA made more than a thousand edits; when you strip out formatting, you’re still left with hundreds of meaningful changes that affect how compliance is tested and documented.
A Checklist for FTCA Risk Assessment Compliance
Quarterly FTCA Risk Assessments are a critical safeguard for FTCA-deemed health centers, yet many submissions fall short of current HRSA expectations. A strong assessment goes beyond completing a tool and must clearly demonstrate how risks were identified, analyzed, prioritized, and acted upon to reduce malpractice exposure. This blog post breaks down the essential elements reviewers look for and highlights why compliant assessments are vital to patient safety and FTCA protection. A full checklist is included to help health centers evaluate the quality and completeness of their quarterly assessments.
Key Updates in HRSA’s October 2025 Health Center Compliance Manual Revision
In October 2025, the Health Resources and Services Administration (HRSA) released a revised Health Center Program Compliance Manual, marking the first major update since 2018. This comprehensive manual is the primary guide for Federally Qualified Health Centers (FQHCs) to understand and meet program requirements. For health center executives and compliance leaders, staying abreast of these changes is crucial. In this article, RegLantern summarizes the most significant updates across the manual’s chapters and appendices, discuss practical implications for health center leadership, and recommend action steps to ensure ongoing compliance under the updated guidance.
Q4: The Quarter That Can Transform Your Quality and Risk Management Year
Every year, I see it happen. By November, health center quality and risk management leaders suddenly realize they’re behind: the quarter’s risk assessments are incomplete, trainings lag far behind schedule, and end-of-year reports are looming. Panic sets in. They drop everything else to scramble through what’s overdue, all while the season fills up with holidays and vacations. Despite the celebrations, there’s hardly a moment to relax—they’re just trying to keep their heads above water. Then, almost overnight, it’s January. UDS reports are due, FTCA applications open, and the whole cycle starts again with new requirements for the first quarter.
If this sounds familiar, I understand—I've been there too. But here’s the truth: it doesn’t have to be this way, and the solution is well within reach.
FQHCs and HIPAA Security Risk Assessments
Federally Qualified Health Centers (FQHCs) are required under the HIPAA Security Rule to conduct regular Security Risk Assessments (SRAs) to safeguard electronic protected health information (e-PHI). This blog explains what an SRA is, why it’s essential for compliance, and how community health centers can complete one effectively. Learn how to identify where e-PHI is stored, assess risks and vulnerabilities, evaluate current safeguards, and document findings using best-practice frameworks such as NIST SP 800-30 and SP 800-66. The post also offers practical steps to turn assessment results into actionable security improvements. Conducting an annual SRA not only helps maintain compliance with the U.S. Office for Civil Rights (OCR) but also strengthens data protection and patient trust.
Creating an FTCA Risk Management Training Plan for the Coming Year
With each year’s fourth quarter, health center teams begin to prepare comprehensive risk management training plans to meet evolving HRSA/FTCA requirements. It’s important to use this time to plan out the coming year’s training to ensure all HRSA and FTCA requirements are met and that training is completed promptly.

