Skip to main content
Back to Our Blog
Phoebe Gutierrez

What a Corrective Action Plan Is—and Why Your Company Needs a Process for It

What a Corrective Action Plan Is—and Why Your Company Needs a Process for It

A corrective action is one of the most useful things that can happen to a healthcare company—and one of the most misunderstood. The phrase sounds like discipline. In practice, it is a heads-up: someone checked your work, found a gap, and told you before a regulator, a board, or a plaintiff’s attorney did.

I spent about 12 years as a California state regulator reviewing hospital systems and health plans. I issued many corrective action plans. Very few were about bad actors. Most involved good companies that did not have a process to catch their own gaps.

This post explains what a corrective action is, why you should want one, and why every telemedicine and digital health company needs its own internal corrective action process.

Educational notice: This article provides general compliance information only. It is not legal advice, does not create an attorney-client relationship, and is not a substitute for advice from qualified legal counsel regarding your company’s specific facts, contracts, or jurisdictions.

What a corrective action plan is

A corrective action plan, or CAP, is a documented plan to fix something that is not fully meeting a requirement. It is typically issued by whoever oversees compliance: a state regulator, health plan, payer, accrediting body, independent reviewer, or your own internal compliance team.

The basic idea is simple. At some point, someone reviewed, monitored, or checked your work to see whether you were following the rules. They found areas where you were not following them completely. So they told you, in writing, what needs to be fixed and by when.

That written piece matters. A CAP does two things at once. It tells you what to fix, and it documents that the reviewer told you. That second part protects the reviewer, but it also gives you a clear record that you were notified, you responded, and you fixed it. If anyone looks later, that record is your proof.

Why a corrective action is a good thing

The point of a corrective action is to catch a problem while it is still small. The alternative is that the gap keeps growing until an investigator, regulator, or licensing board finds it and tells you that you broke the rules. At that stage, you are not fixing a process. You are defending one.

A lot of people get defensive when they receive a CAP. I understand the reaction, but it works against you. If an internal reviewer—someone technically on your side—flags a discrepancy and you argue instead of fixing it, that pushback becomes part of the record. If you later face enforcement, a history of ignored findings looks much worse than a history of findings you closed.

This matters more now than it did a few years ago. There is more regulatory enforcement, more public attention on telemedicine and digital health, and more litigation. Compliance is also a moving target. Rules change, get updated, and get reinterpreted constantly. In telemedicine, there is rarely a short list of three or five rules that apply. Licensing, prescribing, privacy, marketing, corporate practice, and payer rules can all apply at once—and they vary by state.

In healthcare, especially telemedicine, many rules are gray. Regulators are not always watching every corner yet. That makes it more important, not less, to have someone reviewing your operations and identifying the gaps. The more you learn about the rules, the more you realize how difficult it is to comply with all of them perfectly.

Common corrective action examples in telemedicine and digital health

Most findings are not dramatic. They are ordinary operational gaps that nobody was assigned to check. A few I see often:

  • Missing BAAs. You use vendors that touch patient data, but you do not have business associate agreements saved in one place, so you cannot confirm you have them. The fix is a vendor inventory with a signed BAA on file for each one.
  • Medical director oversight not happening. Your policies or contracts say your medical director meets with the clinical team monthly, and those meetings have not been happening or are not documented. The CAP is a reminder that this is a requirement and needs to happen, with notes, going forward.
  • Provider licenses not monitored. You cannot say with confidence that every provider on your platform has an active license in every state where they see patients. You need a roster, a named person who checks it at least every 30 days, and a record of each check.
  • No provider disclosures. You are not collecting disclosures from providers about board actions, malpractice claims, or changes in license status. You need a regular attestation process.
  • Partner marketing not reviewed. If you are a white-label telemedicine company and your partners run their own marketing, you are still exposed if that marketing makes claims it should not. You need a process to review partner marketing and issue your own corrective actions when something is off.

That last example is the one most companies miss. If you have partners, delegates, franchisees, or vendors, overseeing them is part of your compliance program. That means you need an internal process to monitor them and issue CAPs to them—not just receive CAPs from others.

How the corrective action process works

If you have worked with health plans or payers, this process will feel familiar. It is standard across healthcare. Whether a regulator issues it or your own compliance team does, it usually follows the same steps:

  1. Review. A compliance review, monitoring check, or complaint review compares what you are doing against a requirement.
  2. Finding. The reviewer documents each gap, the requirement it ties to, and the evidence.
  3. Plan. You respond with what you will change, who is responsible, and a deadline.
  4. Implementation. You make the change: update the policy, build the roster, sign the BAAs, or hold the meetings.
  5. Evidence and closeout. You submit proof that the fix is in place, and the reviewer closes the finding.
  6. Follow-up. At the next review, someone checks that the fix stuck.

Not every finding has the same weight. Some are minor and easy to fix. Others are operationally difficult to build around. In those cases, a reasonable path may be a written policy that acknowledges the rule, explains why full compliance is difficult in your model, and lays out your best good-faith approach—after appropriate legal review. That is still a decision you are making knowingly and documenting, which is very different from not knowing the rule existed.

This is also how a compliance program evolves. Each CAP shows you where a process was weak. Fix enough of them and your operations get stronger in the places that actually matter for your business.

Where the requirements come from

Reviewers are not making requirements up. They generally review against three things: your contracts, state law, and federal law. That means you can build most of what you are supposed to do before anyone reviews you.

  • Your contracts. Payer agreements, partner agreements, management-services and professional-entity agreements, and vendor contracts all contain obligations. So do the contracts you sign downstream with your own vendors and partners. If a contract says you will do something, a reviewer may check that you did it.
  • State law. Licensing, prescribing, corporate practice of medicine, telehealth consent, and privacy rules vary state by state.
  • Federal law. HIPAA, controlled-substance prescribing requirements, FTC advertising rules, and Medicare and Medicaid requirements may apply, depending on your model.

A lot of this is also public. When I worked as a regulator in California, survey reports and corrective action plans for health plans were posted for anyone to read, and they still are. The California Department of Managed Health Care surveys licensed health plans and publishes public final reports. The California Department of Health Care Services posts audit reports and corrective action plans for Medi-Cal managed care plans. Reading a few is one of the best ways to see what reviewers look for and what a good CAP response looks like.

Compliance is not the same as legal or operations

The main reason most companies do not have a corrective action process is that they do not really have a compliance function. They lump compliance, operations, and legal together and assume one of them is covering it.

They are different jobs:

  • Legal tells you what the rules mean and drafts your agreements.
  • Operations runs the business day to day.
  • Compliance continuously monitors whether operations are actually following the rules and contracts, documents the gaps, and makes sure they get fixed.

Compliance is a specific role with a specific person or team responsible for it. Without that role, nobody is checking, so nobody finds the gaps until someone outside the company does. Good compliance is muscle memory: repeatable processes, solid operations, and a corrective action process that runs whether or not anyone is looking.

If you are a franchise, telemedicine company, or white-label platform without a solid process to oversee your partners, delegates, and vendors, it may make sense to bring in third-party compliance oversight to help build and run it.

A simple corrective action plan template

You do not need software to start. A basic CAP log covers each finding with the fields below. Here is one filled in with the license-monitoring example.

FieldExample
FindingNo documented process to verify provider licenses are active in each state where they see patients
RequirementState licensure laws; credentialing terms in payer and partner contracts
Source of findingInternal quarterly compliance review
Risk levelHigh
Root causeNo one assigned to monitor licenses after onboarding
Corrective actionBuild a provider license roster; assign the credentialing lead to verify all licenses every 30 days; document each check
OwnerCredentialing lead
Due date30 days from finding
Evidence of completionRoster, verification log, updated credentialing policy
Follow-up checkCompliance reviews the verification log at the next quarterly review
StatusOpen

Keep one row per finding in a shared log, review open items at a set cadence, and do not close a finding until the evidence is in.

The bottom line

If you have been placed on a corrective action, or your compliance team just handed you a list of findings, that is a good sign. It means someone is paying attention and you have a chance to fix things on your own terms. The companies I worry about are the ones that have never received a finding, because that usually means no one is looking.

An internal corrective action process lets you assess your own risk, make informed decisions about hard-to-meet rules, and show a clear record of good faith if a regulator ever comes calling. Every telemedicine and digital health company should have one.


Camino Strategy Group, LLC is a compliance consulting firm that helps healthcare companies build compliance programs, including internal compliance reviews, corrective action processes, and oversight of partners, delegates, and vendors. Camino Strategy Group, LLC is not a law firm, and its services do not constitute legal advice.