Hospitals that participate in Medicare should be aware of two important accreditation policy changes finalized by CMS. The changes are intended to strengthen oversight of accrediting organizations, improve consistency between accreditation and state surveys, and reduce potential conflicts of interest.
CMS is eliminating the practice of accrediting organizations providing short advance notice before an accreditation survey begins. Some organizations had notified hospitals the same day, occasionally as little as an hour before surveyors arrived.
Going forward, hospitals should expect accreditation surveys to more closely resemble state surveys, where surveyors arrive without advance notice. The goal is to evaluate day-to-day operations rather than preparations made after receiving a call that surveyors are on the way.
For organizations that already maintain continuous survey readiness, this change should have little operational impact. It does, however, reinforce the importance of treating accreditation as an ongoing process rather than an event.
CMS is also limiting when an accrediting organization may provide mock surveys or similar consulting services to the hospitals it accredits.
If an accrediting organization accredits your hospital, it generally may not sell mock survey services during these periods:
CMS views these situations as potential conflicts of interest because the same organization responsible for evaluating compliance would also be providing consulting services designed to help the hospital prepare for that evaluation.
Importantly, this is not a ban on survey preparation.
Hospitals may still conduct internal mock surveys, use health system survey teams, or hire independent consultants—including former accreditation surveyors who now work in private consulting. The restriction applies to the accrediting organization itself, not to independent consulting firms.
Organizations using MediMizer CMMS can maintain continuous compliance in HTM and Facilities departments. If they routinely evaluate their processes, and perform regular internal assessments, they should be well positioned under the new rules.
The more significant change may be for hospitals that have relied on their accrediting organization to perform mock surveys immediately before an accreditation visit. Those organizations may need to shift that work to internal resources or independent consultants.
Ultimately, the CMS changes reinforce two longstanding principles: accreditation surveys should reflect everyday operations, and the organization performing the evaluation should remain independent of consulting activities that could influence the outcome.
These CMS oversight changes become effective June 16, 2027.
ECRI has released its Top 10 Health Technology Hazards for 2026, identifying the technology-related risks that healthcare organizations should prioritize to reduce preventable harm. Published annually, this list reflects ECRI’s independent analysis of device safety, human factors, cybersecurity, workflow design, and system resilience. The 2026 hazards emphasize risks associated with artificial intelligence misuse, digital infrastructure fragility, supply chain integrity, medical device interoperability, cybersecurity exposure, and sterilization processes. ECRI’s work is widely used by healthcare technology management (HTM), clinical engineering, patient safety, and risk management teams to guide planning, procurement, and operational controls.
According to ECRI, the Top 10 Health Technology Hazards for 2026 are: misuse of AI chatbots in healthcare; unpreparedness for a “digital darkness” event; the growing challenge of substandard and falsified medical products; recall communication failures for home diabetes management technologies; tubing misconnections amid slow ENFit and NRFit adoption; underutilization of medication safety technologies in perioperative settings; deficient device cleaning instructions; cybersecurity risks from legacy medical devices; technology designs or configurations that prompt unsafe clinical workflows; and water quality issues during instrument sterilization. ECRI stresses that these hazards are largely preventable through improved governance, technology selection, workflow alignment, cybersecurity controls, and disciplined maintenance and reprocessing practices. The full executive brief and supporting materials are published by ECRI and remain the authoritative source.
The Joint Commission (TJC) has introduced National Performance Goals™ (NPGs) effective January 1, 2026, replacing the former National Patient Safety Goals® (NPSGs). These goals organize key hospital and critical access hospital requirements into measurable areas that go beyond regulation, including safe imaging practices and staffing for quality care.
To help organizations prepare for these revised standards, the Joint Commission is offering a series of free, on-demand webinars. These sessions explain the new requirements by chapter, illustrate how they will be applied, and provide examples and resources to support compliance.
Hospitals and imaging departments can use these webinars to understand what’s new in the imaging services and patient safety requirements, ensuring readiness before the 2026 effective date.
Register to stay informed about new webinars or view past sessions here:
👉 https://www.jointcommission.org/standards/national-performance-goals/
Once on the page, select “Browse webinars” or “Register for updates” to receive email notifications when new educational sessions become available.
Building upon Claroty's acquisition of Medigate in 2021, the xDome platform integrates Medigate's cybersecurity expertise with Claroty's capabilities in securing cyber-physical systems (CPS). xDome is designed to protect all CPS in healthcare environments including medical devices and operational technologies such as HVAC. Benefits of xDome for Healthcare Include:
Enhanced Risk Reduction: The platform addresses unique healthcare cybersecurity challenges, such as network segmentation and medical device hardening, while also managing risks associated with CPS.
Faster Time-to-Value: xDome employs tailored discovery methods, including safe active scanning and integrations with medical device manufacturers, to provide rapid and comprehensive asset visibility.
Lower Total Cost: As a modular, SaaS-based solution, xDome consolidates CPS security management, reducing the need for multiple point products and streamlining resource allocation.
Although the product name will be changing from Medigate to xDome and additional features will be added, Claroty promises that existing users will experience a seamless transition.
MediMizer is excited to announce we will be attending the 2025 AAMI Exchange. The event takes place from June 20 - 23 in New Orleans, Louisiana. Visit us at our booth to learn more about how we're advancing healthcare technology solutions. We hope to see you there!
Celerium's no-cost PHI Data Breach Defense Program helps U.S. hospitals strengthen protection against patient data breaches. Given the frequency of hospital breaches, the program offers rapid deployment (within 30 minutes) to detect early signs of attacks. The solution provides proactive and reactive defenses without the need for additional hardware or software. The program aims to enhance security, contain breaches, and mitigate risks tied to legal or regulatory consequences. Participation starts in October 2024 and hospitals have an opportunity to sign up for a free one-year subscription. Celerium uses its proprietary detection technologies and does not access PHI or ePHI, complying with relevant data privacy regulations.
All aspects including work requests, web dashboard and web work orders are running in Windows 11. We will continue to test the new Windows 11 updates, now automatic, as they arrive. We have worked with and tested on Windows 10 for a few years. MediMizer supports operating in supported secure environments. Windows 8 support ended in January 2023. Windows 7 support ended in January 2015. Windows Vista support ended in 2012.Early warnings will result from connecting patient devices to EHR. Connecting to iOT products is MediMizer's first step into this arena. This permits the automatic gathering of data from iOT platforms (such as xxx). It is important to bring these product into inventory, and evaluate how patient data will be protected while allowing appropriate access to devices patient data. It is also important to evaluate how vulnerable a device is to tampering while connected to the internet.
https://www.24x7mag.com/standards/safety/cybersecurity/three-ways-boost-iot-security/?campaign_type=newsletter&_hsenc=p2ANqtz-9X0HO_2h2LSpow5cg-O-krQ8jHECZMcFSNZrMgHAehha6d83k5h0p7kuiUNlzbRoO6ZvmBJp6c7KFrlPxHSO-yrLL3KQ&_hsmi=78977003
https://www.nfmt.com/online/education/details.aspx?id=5224&&utm_source=NFMTInsiderMemberWeekly&utm_medium=email&utm_campaign=9/18/2019%2012:00:00%20AM&email=mark@medimizer.com#
https://medigate.pathfactory.com/c/cisos-and-the-transf?x=BEAKhD
https://medigate.pathfactory.com/c/medigate-honored-by-?x=BEAKhD
https://medigate.pathfactory.com/c/phi-access-avoidance?x=5meOeD
https://finance.yahoo.com/news/palo-alto-networks-completes-acquisition-201500324.html
https://medigate.pathfactory.com/medigate-newsletter-sep-2019/medigate-wins-iot-aw
https://medigate.pathfactory.com/medigate-newsletter-sep-2019/nchica-annual-confer-1
https://medigate.pathfactory.com/medigate-newsletter-sep-2019/medical-device-security-requires-clinical-expertise
Inventory of medical devices.
Predictive Maintenance?
Patient data in EHR
https://www.24x7mag.com/inside-htm/industry-events/ashe-ahe-collaborate-during-2020-conferences/?utm_source=newsletter&utm_medium=email&utm_term=24x7Z1JoltZ103.03.2020&utm_hsid=12057905&campaign_type=newsletter
Of Puerto Rico's 69 hospitals, 58 were without power and fuel as of Tuesday morning, and the government plans to establish 7 temporary hospitals, according to a FEMA report
Daily Operations Briefing
•Tuesday, September 26, 2017
8:30 a.m. EDT
Health and Medical: PR –11 of 69 hospitals have either power or fuel supply; government will create 7 temporary hospitals; USVI –1 hospital condemned by USACE
The mayor of San Juan said two people on life support died Monday because their hospital ran out of fuel, according to CBS’s David Begnaud
The island’s governor is pushing for the federal government to temporarily waive the Jones Act, a law requiring that all goods shipped between U.S. ports be carried by U.S. owned-and-operated ships. President Donald Trump’s administration has so far not granted his request. (Reuters, Sept 27th)