Start with the hospital’s controlling requirements

For a hospital participating in Medicare or Medicaid, the federal starting point is 42 CFR § 482.41. CMS incorporates the 2012 editions of NFPA 101 and NFPA 99 for covered hospitals, subject to regulatory exclusions and exceptions. A third party life safety audit should therefore begin with an authority matrix identifying the facility’s provider type, occupancy classifications, applicable regulations, adopted editions, accreditor requirements, and any state or local provisions.

The newest published code should not automatically become the audit criterion. NFPA 101’s 2024 edition may offer useful information, but it is not automatically the edition incorporated by CMS or adopted by another authority. Proposed improvements based on a newer edition should be labeled as recommendations unless the auditor verifies that the provisions are controlling for the hospital.

Accreditation requirements also require verification. Public Joint Commission resources can help identify documentation and fire-protection subjects, but the current program-year manual and the hospital’s actual accreditation pathway must be confirmed before findings are assigned to accreditation requirements.123458

Define the engagement before anyone enters the field

An independent audit is an advisory assessment, not an official CMS, accreditor, state, or fire-marshal survey. Its purpose and limits should be written into the scope. The agreement should identify the buildings and departments included, applicable authority pathways, field-review subjects, document-review period, sampling approach, deliverables, exclusions, and whether follow-up verification is included.

Hospitals should also define the business objective. An engagement intended to establish baseline conditions may require broad building coverage, while a review before a scheduled survey may emphasize unresolved deficiencies, current documentation, and high-risk operational gaps. A focused review of doors, barriers, drawings, or NFPA 99 systems is not equivalent to a comprehensive healthcare life safety assessment.

The scope should state that conclusions are based on the conditions, records, and access available during the engagement. Concealed construction, inaccessible rooms, unavailable records, and systems outside the agreed sample should be disclosed rather than treated as reviewed.12768

Build the audit scope around surveyable systems and conditions

Form CMS-2786R provides a practical framework for organizing hospital life safety subjects. Its K-tags address matters such as means of egress, locking arrangements, horizontal exits, suites, travel distance, hazardous areas, fire-alarm and sprinkler impairments, operating features, and applicable NFPA 99 systems. The audit should connect each reviewed condition to the correct regulatory and code path instead of relying on a generic checklist.

A hospital-wide scope commonly considers occupancy and construction information, current life safety drawings, compartmentation, rated assemblies, opening protectives, egress, fire-protection systems, impairment controls, operating features, and applicable healthcare building systems. NFPA 99 subjects should be evaluated separately from NFPA 101 subjects while accounting for the way CMS incorporates the 2012 Health Care Facilities Code.

Door scope requires particular care. CMS identifies annual inspection and testing under the 2010 NFPA 80 requirements for fire door assemblies in healthcare occupancies. Non-rated corridor and smoke-barrier doors should not automatically be classified as subject to the same annual NFPA 80 inspection requirement, although they remain part of routine maintenance and applicable operational review.63581011

Use a traceable field method rather than an undocumented walkthrough

CMS survey procedures include preparation, entrance activities, an orientation tour, information gathering, analysis, an exit conference, and post-survey work. A private audit does not become a CMS survey by following a similar workflow, but these stages provide a useful structure for collecting records, observing conditions, interviewing responsible personnel, validating findings, and communicating preliminary results.

Each observation should be traceable to a building, floor, room or area, asset or assembly when applicable, date, observed condition, photograph or other evidence, and governing criterion. If the engagement uses sampling, the report should identify the sample boundaries and avoid implying that unreviewed areas were compliant.

The field method should include a process for resolving incomplete information. For example, an apparent opening-protection issue may require confirmation from the life safety drawing, door label, barrier designation, approved construction documents, or adopted code path before it is reported as a deficiency.7638

Prepare drawings, inventories, and compliance records for review

The hospital should establish a controlled document request before fieldwork. Useful records may include current life safety drawings, previous survey findings, plans of correction, open corrective actions, fire-door inspection records, fire-protection testing and impairment records, applicable system inventories, construction documentation, and evidence that completed work was verified.

For hospitals using The Joint Commission, its public document-review tool identifies current and accurate drawings showing fire-safety features and annual fire-door inspection and testing records among the review subjects. The current program-year tool must be verified. Hospitals using another accreditation or certification pathway should map the document request to that authority’s current requirements rather than assuming the same document list applies.

Record review should test consistency, not merely the presence of files. Drawing designations should correspond to field conditions, asset identifiers should connect to inspection records, and work orders should connect the original finding to the completed action and verification evidence.81011121

Require findings that separate fact, authority, and recommendation

A useful healthcare life safety deficiency report distinguishes the observed condition from the cited requirement and the proposed response. Each finding should identify its location, supporting evidence, applicable authority and edition, rationale, and whether additional verification is needed. Recommendations based on good practice or a newer code edition should be labeled separately from adopted requirements.

K-tags can help organize CMS-related observations because Form CMS-2786R prints associated regulatory and code references. However, a private auditor’s use of a K-tag does not create an official CMS citation. Official deficiencies and plans of correction are communicated through the applicable survey and enforcement process, including Form CMS-2567 when used by CMS.

The report should also disclose limitations, duplicate findings, inaccessible areas, and unresolved authority questions. Priority categories may help management sequence work, but the report should explain how those categories were assigned and should not represent them as an authority’s determination unless the authority made that determination.612724

Convert the report into controlled corrective action

The audit should end with more than a list of observations. Each accepted finding should be assigned to a responsible party, target date, corrective action, and required closure evidence. Work orders should preserve the relationship among the original condition, exact location, performed work, completion date, responsible party, and verification result.

Hospitals should distinguish an internal corrective-action schedule from a regulatory Plan of Correction. CMS states that an institution receiving Form CMS-2567 is given 10 calendar days to respond with a Plan of Correction for each cited deficiency. That deadline is tied to the actual CMS enforcement process; receiving a private audit report does not itself create a CMS-2567 or start that response period.

Closure should include verification that the action corrected the cited condition without creating another problem. Depending on the finding, verification may require document review, photographs, functional testing, drawing updates, or a field revisit. The hospital should retain evidence in a form that can be retrieved during a later survey.121387

Procure the auditor and deliverables as one package

A request for proposals should ask how the auditor will determine the governing authority path, distinguish adopted editions from newer publications, address accreditation requirements, control field evidence, and resolve uncertain conditions. The hospital should request a representative report format and confirm whether the engagement includes document review, field assessment, interviews, an exit conference, corrective-action support, and reinspection.

Commercial comparisons should address more than price. Hospitals can evaluate proposed coverage, exclusions, sampling, report turnaround, data handling, access requirements, conflicts of interest, and responsibility for specialty testing. If the auditor recommends repairs or provides related services, the hospital should establish how potential conflicts and independent verification will be managed.

No universal qualification rule for every type of third-party hospital life safety audit is established by the cited sources. The hospital should verify any qualifications required by its jurisdiction, accreditor, procurement policy, or the specific inspection standard involved rather than relying on a general claim of life safety expertise.1235810

Schedule audits as part of continuous compliance

The cited authorities do not establish one universal interval for a comprehensive third-party audit. Hospitals may consider an independent review before an anticipated survey, after significant construction or system changes, when records and drawings have become unreliable, or when recurring findings indicate that existing controls are not preventing recurrence. These are planning considerations, not a substitute for mandated inspection and testing frequencies.

A comprehensive audit interval should not be confused with a system-specific requirement. For example, CMS identifies annual inspection and testing requirements for applicable fire door assemblies, while other systems and records follow their own governing criteria. The hospital’s compliance calendar should preserve those individual frequencies regardless of when a broader assessment is scheduled.

The strongest use of an audit is to support continuous compliance between surveys. Trends from field findings, work orders, testing records, and repeated deficiencies can inform maintenance priorities, document governance, and future assessment scope.791011

Frequently asked questions

Does CMS require every hospital to obtain a third-party life safety audit?

The cited federal and CMS sources establish hospital physical-environment and fire-safety requirements and describe official survey processes, but they do not establish a universal requirement for every hospital to purchase a comprehensive third-party audit. A state, local authority, accreditor, corporate policy, or specific corrective action may impose additional expectations, so the hospital’s jurisdiction and certification pathway must be verified.127

Can a third-party auditor issue CMS K-tags?

An auditor may organize observations using the K-tags and references printed on Form CMS-2786R. That does not make the observations official CMS citations. Official deficiencies are issued through the applicable survey process and may be documented on Form CMS-2567 with the provider’s Plan of Correction.6712

Which NFPA 101 edition should a hospital audit use?

For a covered hospital following the CMS pathway, CMS incorporates the 2012 NFPA 101 edition subject to regulatory exceptions. The audit must also verify state, local, and accreditation requirements. The 2024 NFPA 101 edition is a newer consensus publication but should not be treated as controlling unless the applicable authority has adopted it for the hospital.2134

What should the final audit report contain?

A useful report should identify the observed condition, exact location, evidence, applicable authority and edition, finding rationale, recommended action, limitations, and any item requiring further verification. It should also distinguish adopted requirements from recommendations and provide enough information to connect each finding with a corrective action and closure record.61287

How often should a hospital obtain an independent life safety audit?

The supplied authorities do not set one universal frequency for a comprehensive independent audit. Timing should reflect the hospital’s survey pathway, construction activity, system changes, recurring findings, and internal risk decisions. This does not replace prescribed frequencies for particular systems or assemblies, such as the annual inspection and testing CMS identifies for applicable fire door assemblies.791011

Related guidance for your next step

Continue your healthcare life safety review