Skip to main content


Risk management for healthcare entities: Strengthening patient documentation practices

Healthcare entities have a responsibility to provide safe and quality healthcare services to their patients and community.
Female doctor explaining diagnosis to her young patient

Healthcare entities have a responsibility to provide safe and quality healthcare services to their patients and community. Part of fulfilling this duty includes developing an effective process for how their practitioners communicate with patients and document their medical information.

When finetuning their approach to help ensure the clear and accurate documentation of medical records, healthcare entities will need to consider their range of risks across all settings and address them through a comprehensive management plan. In so doing, they must take steps to establish or enhance their code of conduct, strengthen their training programs, and standardize their documentation practices. By equipping themselves with a comprehensive and consistent approach to patient communication and documentation, healthcare entities can help make certain that their practitioners understand and are able to satisfy their organizational, professional, and ethical duties, requirements, and obligations.

The following guidance highlights key risk controls healthcare entities may implement to streamline the patient documentation process and minimize risks associated with gathering, documenting, and referencing patient information. It is not an exhaustive list and should be used in conjunction with internal policies and procedures, as well as in compliance with local laws and regulations.

Code of conduct

Establishing a code of conduct can help healthcare entities ensure practitioners across departments are aligned in their commitment to providing quality healthcare services to patients. The code of conduct should explain the ethical responsibilities and organizational standards for gathering patient data, such as personal details, medical history, symptoms, diagnoses, and test results, and documenting it appropriately. Be sure the code of conduct is in alignment with professional and ethical duties, requirements, and obligations.

  • Develop and review, at least annually, a comprehensive code of conduct that outlines healthcare practitioners’ duties and obligations for effectively documenting patient information, with guidance in the following areas:
    • Articulation of shared commitment to upholding a safe and inclusive healthcare environment
    • Reinforcement of the importance of patient well-being and confidentiality
    • Establishment of clear procedure for patient documentation, including any new amendments to the process
    • Roles and responsibilities of healthcare professionals under the code, including employees, independent practitioners, and students
    • Definitions and examples of unacceptable documentation practices
    • Internal and external resources available to all parties
    • Expectations for training related to the code of conduct
  • Ensure the code is easily accessible to all practitioners and departments


In order to uphold best practices for safe and compliant patient documentation, healthcare entities need to properly educate practitioners with role-based training programs. These trainings should outline individuals’ respective duties for gathering and recording patient information. They must also align with organizational, professional, and ethical standards.

  • Develop a mandatory training program for healthcare practitioners to learn the comprehensive process for patient communication and documentation. The training should address the following:
    • Expectations for patient documentation for all roles and settings
    • Consequences of non-compliance with policies and procedures
    • Internal and external resources available to all parties
    • Measures to promote effective documentation across the organization
    • Protections for patients
  • Establish a training schedule, which requires all healthcare practitioners to receive training upon hire and supplemental training on a regular basis

Standardized documentation practices

Healthcare entities have a responsibility to protect patient information across the healthcare ecosystem. By establishing clear and effective documentation practices, healthcare entities can help ensure their practitioners are able to share and record patient information in an organized, accurate, and confidential manner. In turn, this helps to ensure the safe and quality delivery of healthcare services. When standardizing the patient documentation process — with which the code of conduct and trainings should align — healthcare entities should keep the following best practices in mind:

  • Articulates standardized terminologies and abbreviations
  • Specifies expected documentation practices:
    • Named and signed
    • Dated and timestamped
    • Fact or information-based
    • Clear and concise
    • Accurate and complete
    • Legible and readable
  • Provides examples of unacceptable documentation practices, such as:
    • Using jargon or subjective information
    • Forgetting to date, timestamp, or sign the documentation
    • Failing to document a safety/harm incident involving the patient
    • Failing to document omitted medication or treatment
    • Failing to document any change in patient condition or treatment
  • Clearly defines and provides examples of appropriate medical record documentation as it relates to:
    • Physician orders and progress notes
    • Nursing and allied health progress notes
    • Health history and assessment notes
    • Medical history and administration notes
    • Transfer of care reports
    • Admission notes and discharge summaries
  •  Clearly defines and provides examples of documentation across applicable settings, such as:
    • Emergency departments
    • Inpatient areas
    • Outpatient areas


In order to deliver safe, high-quality care to patients, healthcare entities need to develop a comprehensive system around patient communication and documentation. This management plan should include a code of conduct, role-based training programs, and standardized practices to ensure practitioners are aligned and to help minimize the risks associated with gathering and recording confidential patient information.


If you have questions, please contact your Marsh representative.