HIPAA-Compliant AI for Skilled Nursing Facilities: The Complete Operator's Guide

F-tags are the codes CMS surveyors use to cite nursing home deficiencies, each mapping to a specific requirement in 42 CFR Part 483 Subpart B. A citation appears on Form CMS-2567 with an F-tag number, a scope and severity letter, and the surveyor findings. The facility must respond with a Plan of Correction, generally within ten days.

An F-tag is a pointer. It tells you exactly which regulatory requirement the surveyor believes was not met, which means the first move on receiving a citation is always the same: read the regulation the tag points to, then read the surveyor's findings, and see whether the findings actually establish the elements of that requirement.

Facilities that skip that step end up writing a Plan of Correction against what they assume the tag means rather than against what the regulation says.

Key takeaways

  • Each F-tag corresponds to a specific requirement of participation in 42 CFR Part 483 Subpart B.
  • The number is grouped by subject area, so nearby numbers cover related requirements.
  • A citation carries a scope and severity letter from A to L that determines enforcement consequences.
  • Levels J, K, and L are immediate jeopardy and require removal of the jeopardy within a very short window.
  • The most frequently cited tags nationally are concentrated in infection control, accident hazards, quality of care, and care planning.
  • Interpretive guidance in the State Operations Manual Appendix PP tells you how surveyors are instructed to apply each tag.

How the numbering works

F-tags are grouped by regulatory subject. Knowing the ranges lets you orient immediately when a citation arrives:

RangeSubject area
F540s–F580sResident rights, notification, and communication
F600sFreedom from abuse, neglect, and exploitation
F620s–F640sAdmission, transfer, and discharge; resident assessment
F650sComprehensive care planning
F670s–F700sQuality of care and quality of life
F710s–F720sPhysician services and nursing services
F740s–F760sBehavioral health and pharmacy services
F800sFood and nutrition services
F830s–F870sAdministration, QAPI, and infection control
F880sInfection prevention and control program
F940sTraining requirements

The authoritative source for what each tag requires and how surveyors are told to evaluate it is Appendix PP of the State Operations Manual. It contains the regulatory text, interpretive guidance, and investigative procedures. If you are responding to a citation and have not read the Appendix PP entry for that tag, you are working from a summary.

The tags cited most often

National citation frequency shifts year to year, but a consistent set dominates:

TagRequirementWhy it gets cited
F880Infection prevention and control programDirectly observed technique — hand hygiene, PPE, isolation practice. Surveyors watch rather than read.
F689Free of accident hazards and adequate supervisionFalls, elopement, unsafe transfers, environmental hazards. Broad and heavily used.
F684Quality of careA catch-all where care did not meet professional standards and no more specific tag fits.
F656Develop and implement a comprehensive care planPlans that are generic, not individualized, or not followed in practice.
F686Treatment and services for pressure ulcersRisk assessment, prevention documented as delivered, staging accuracy, physician notification.
F812Food procurement, storage, preparation, sanitationKitchen review runs on essentially every survey. Dating, temperatures, sanitation.
F609 / F600Reporting of and freedom from abuseTimeliness of reporting to the state agency is a frequent failure point.
F758Free from unnecessary psychotropic drugsMissing indication, no gradual dose reduction attempt or rationale, no behavior monitoring.
F677 / F676ADL care and maintaining abilitiesObserved care versus documented care.
F725Sufficient nursing staffTriangulated against the facility assessment, PBJ data, and call light response. Now the primary staffing exposure following the repeal of the federal staffing mandate.

The pattern across the top tags is worth noting: most are cited from observation rather than from record review. Surveyors see a hand hygiene lapse, an unattended resident at a meal, a medication pass error. Documentation-only preparation does not protect against tags that are earned or lost in practice on the unit.

What are the infection preventionist requirements?

Because F880 is consistently among the most-cited tags, the requirements behind it are worth setting out separately. They live at 42 CFR 483.80.

Every facility must maintain an Infection Prevention and Control Program and must designate at least one Infection Preventionist responsible for it. The IP must:

  • Have primary professional training in nursing, medical technology, microbiology, epidemiology, or a related field
  • Be qualified by education, training, experience, or certification
  • Have completed specialized training in infection prevention and control
  • Work at least part-time at the facility
  • Be a member of the facility's quality assessment and assurance committee, reporting to it on the program

The program itself must include a written infection prevention and control program based on a facility assessment, surveillance covering the resident population and the facility's own risks, written standards and procedures, an antibiotic stewardship program including protocols and a system for monitoring antibiotic use, and a documented annual review of the program.

Three things trip facilities up here, and none of them are clinical:

  1. The IP designation is nominal. Someone holds the title, and nobody can produce evidence of the specialized training or of the surveillance actually being performed. The role exists on an org chart rather than in practice.
  2. The annual review never happens, or happens without documentation, which is the same thing from a survey standpoint.
  3. Antibiotic stewardship is a policy, not a system. The regulation expects monitoring of antibiotic use, which means data someone looks at, not a binder describing what should occur.

The IP's QAA committee membership is the connective requirement worth attending to. It exists so that surveillance findings actually reach the body that can change practice — see the QAPI guide for how that linkage should function.

Scope and severity

Every citation carries a letter from a grid combining how many residents were affected with how serious the effect was.

SeverityIsolatedPatternWidespread
Immediate jeopardyJKL
Actual harmGHI
No actual harm, potential for more than minimal harmDEF
No actual harm, potential for minimal harmABC

The D through F band is by far the most common. A through C represent substantial compliance. G and above indicate actual harm occurred.

Immediate jeopardy at J, K, or L means noncompliance has caused or is likely to cause serious injury, harm, impairment, or death. It requires immediate removal of the jeopardy and carries the most serious enforcement consequences, including civil money penalties, denial of payment for new admissions, and in extreme cases termination.

Substandard quality of care is a separate designation triggered by findings at specified severity levels within the resident behavior and facility practices, quality of life, or quality of care requirement groups. It brings additional consequences including a mandatory extended survey and loss of nurse aide training program approval.

Reading a CMS-2567

Each deficiency on the form contains the tag number, the regulatory text, the scope and severity letter, and the surveyor's findings — typically observations, interviews, and record review, with dates and identifiers.

Read the findings as an argument with elements. For each cited tag, ask whether the findings actually establish every element of the requirement, whether the facts as stated are accurate, and whether there is documentation the surveyor did not see. That analysis determines whether you write a Plan of Correction, pursue informal dispute resolution, or both — and submitting a POC does not waive the right to dispute.

See the survey readiness checklist for what an acceptable Plan of Correction must contain, and the QAPI guide for the monitoring linkage a POC needs.

Where AI helps with F-tag work

  • Recurrence analysis. Read several years of CMS-2567 forms and identify which tags repeat, which root causes were never addressed, and which POC commitments have lapsed. This is the same analysis the survey team runs during offsite preparation, and most facilities have never done it on their own history.
  • Findings-to-elements review. Compare the surveyor's stated findings against the requirement and identify which elements are and are not established.
  • Plan of Correction drafting structured around the five required elements, with monitoring mechanisms rather than in-service language.
  • Policy gap check. Compare facility policy against the requirement behind a cited tag — including checking an infection prevention and control program against each element of 42 CFR 483.80.
  • Care plan and record consistency review for the documentation-based tags, finding the gap between planned and delivered before a surveyor does.

Statements of deficiency are scanned documents, often with handwritten annotations, and a multi-year set runs long. Hathr.AI reads handwriting, holds a full multi-year set in one pass, runs inside AWS GovCloud under a FedRAMP High authorization boundary, and signs a Business Associate Agreement within 24 hours on every plan.

Start with your own history

Upload your last three CMS-2567 forms and ask Hathr.AI which F-tags recur and which prior Plan of Correction commitments no longer appear to be in effect.

Start a free trial — $47 a month, no seat minimum, BAA in 24 hours →

Frequently asked questions

What is an F-tag in a nursing home?
A code CMS surveyors use to cite a deficiency, corresponding to a specific requirement of participation in 42 CFR Part 483 Subpart B.

What is the most cited F-tag?
Infection prevention and control (F880) and accident hazards and supervision (F689) are consistently among the most frequently cited nationally, along with quality of care (F684) and care planning (F656).

What does F689 cover?
The requirement that the resident environment remain as free of accident hazards as possible and that each resident receive adequate supervision and assistance devices to prevent accidents.

What are the infection preventionist requirements?
Under 42 CFR 483.80, a facility must designate an infection preventionist with primary professional training in nursing, medical technology, microbiology, epidemiology, or a related field, who is qualified by education, training, experience, or certification, has completed specialized infection prevention training, works at least part-time at the facility, and serves on the quality assessment and assurance committee.

Does a nursing home infection preventionist have to be full-time?
No. The regulation requires the infection preventionist to work at least part-time at the facility.

What do the scope and severity letters mean?
Letters A through L combine how widespread a deficiency was with how serious its effect. A through C is substantial compliance, D through F is potential for more than minimal harm, G through I is actual harm, and J through L is immediate jeopardy.

Where can I read what an F-tag requires?
Appendix PP of the State Operations Manual contains the regulatory text, interpretive guidance, and investigative procedures for each tag.

Can a facility dispute an F-tag citation?
Yes, through informal dispute resolution and, in certain circumstances, independent IDR. Submitting a Plan of Correction does not waive the right to dispute.


Part of the HIPAA-Compliant AI for Skilled Nursing Facilities hub. Related: Survey Readiness Checklist · QAPI in Nursing Homes · The Staffing Mandate Repeal

This article is general regulatory information, not legal or compliance advice. F-tag numbering, interpretive guidance, and citation frequencies are revised by CMS over time. Verify against the current State Operations Manual Appendix PP and 42 CFR Part 483 before relying on them.

Category
No items found.
Written by
Sam Hart headshot - Founder at Hathr.ai
Hathr.AI Clinical Compliance Team
Date Published:
2026-08-15

Our Youtube Videos

Hathr.AI is the fastest, safest way to handle sensitive medical records with HIPAA-compliant artificial intelligence. In this demo, watch how you can:✅ Summarize a patient’s medical record  ✅ Generate an AI-assisted treatment plan  ✅ Write a letter to the patient in plain English  ✅ Suggest CPT billing codes  ✅ Draft an insurance appeal for a denied claim  ✅ Evaluate the case for potential malpractice — all in under 5 minutes.The only AI tool hosted in AWS GovCloud and Powered by Claude 4.0 Sonnet, Hathr.AI is trusted by hundreds of practices that need speed, security, and compliance.Learn more: hathr.ai  For healthcare teams: hathr.ai/healthcare  Reach out to learn more: contact@hathr.ai

#HIPAACompliantAI#ArtificialIntelligenceInMedicine#HealthcareAI#MedicalBillingAI#AIForDoctors#HIPAAAI#MedicalRecords#AIInHealthcare

Description

As Hathr.AI, we are dedicated to providing a private, secure, and HIPAA-compliant AI solution that prioritizes your data privacy while delivering cutting-edge technology for enterprises and healthcare professionals alike.

In this video, we’ll dive deep into the growing concerns around data privacy with AI tools—especially in light of recent revelations about Microsoft’s Word and Excel AI features. These new features have raised alarm over data scraping practices, where user data could be used without clear consent, leaving individuals and organizations exposed to potential privacy breaches. What makes this especially concerning is the "opt-in by default" design, which could lead to unintended data sharing.

In contrast, Hathr.AI ensures that your data stays yours. With a firm commitment to HIPAA compliance, we take the protection of sensitive healthcare data to the highest level. Our platform is built with the understanding that privacy is not an afterthought but a fundamental pillar of our design. We don’t collect, store, or sell user data, and we employ state-of-the-art encryption, secure access protocols, and clear user consent processes to keep you in full control.

We’ll also touch on why Hathr.AI, powered by advanced LLM (Large Language Models) like Claude AI, offers a secure and private alternative for businesses looking to leverage AI technology without compromising sensitive information. While some AI tools may collect or expose data through ambiguous or hard-to-find opt-out settings, Hathr.AI puts transparency and security at the forefront, offering peace of mind in an era of increasing digital vulnerability.

If you’re concerned about your privacy or looking for a HIPAA-compliant AI solution that respects your data, Hathr.AI provides the robust security, transparency, and ethical design that you need.

Key Points:

  • HIPAA Compliant AI: Built for healthcare professionals, ensuring compliance with privacy regulations.
  • Privacy-first: No data scraping, no data selling, full user control over information.
  • Claude AI: Secure, powerful LLM tools for advanced capabilities without compromising security.
  • Data Transparency: Say goodbye to hidden opt-in/opt-out toggles—Hathr.AI gives you clear, easy-to-understand privacy settings.

Tune in to learn how Hathr.AI ensures your AI tools remain private, secure, and trustworthy, while still delivering the performance and accuracy you need to thrive in a fast-evolving digital landscape.

Don't forget to like, comment, and subscribe for more insights on secure AI solutions and how to protect your organization from emerging privacy risks!

Description

Discover how Hathr AI's advanced AI tools transform federal acquisition processes with unparalleled security and efficiency. Designed for government professionals, this video showcases Hathr AI’s capabilities, including secure AI data analysis, HIPAA-compliant tools, and AWS GovCloud integration, to help streamline decision-making and document management. Perfect for agencies seeking private, compliant, and powerful AI solutions, Hathr.AI delivers tools tailored for healthcare and government needs.

Key Topics Covered:

AI-driven data analysis for governmentHIPAA-compliant, secure AI tools for federal agencies

Private deployment options with AWS GovCloud

Learn more about Hathr AI’s secure, high-performance solutions at hathr.ai and transform your agency’s acquisition process with cutting-edge AI.

Description

Discover how Hathr.AI simplifies NSF grant evaluations with advanced AI-driven compliance and proposal review tools. This video showcases Hathr.AI’s capability to streamline grant compliance checks, enhance accuracy, and save time for evaluators and applicants alike. Ideal for research institutions, government agencies, and proposal writers, Hathr.AI offers secure, HIPAA-compliant AI solutions tailored to meet the complex requirements of NSF and other grant processes.Highlights:AI-powered compliance checks for NSF grant proposalsFast, accurate, and secure evaluations with Hathr.AITailored solutions for research, government, and healthcareOptimize your grant proposal process with Hathr.AI's private, secure AI tools. Learn more at hathr.ai and transform how you handle grant evaluations and compliance.

Description

Join Hathr.AI at the Defense Information Systems Agency (DISA) Technical Exchange Meeting to explore innovative AI solutions tailored for federal and defense applications. In this session, we highlight Hathr.AI's secure, private AI tools designed for efficient data handling, HIPAA compliance, and seamless integration within government systems, including AWS GovCloud. Perfect for agencies seeking reliable AI for data analysis, document summarization, and secure decision-making, Hathr.AI provides cutting-edge technology for defense and healthcare needs.Highlights:AI tools for federal and defense data managementSecure, HIPAA-compliant AI solutions with AWS GovCloudEnhancing operational efficiency with private AI deploymentsDiscover how Hathr.AI's solutions empower government and defense agencies to stay at the forefront of innovation. Visit https://hathr.ai to learn more about our services.

Blog and articles

Latest insights and trends

AI Healthcare solutions with Hathr.AI
HIPAA Compliant AI

AI Healthcare Solutions: How a HIPAA Compliant LLM can Revolutionize your practice

Learn how HIPAA compliant AI healthcare solutions can revolutionize your practice. Hathr AI offers secure, HIPAA & NIST-certified tools that automate billing, enhance diagnostics, and improve patient care while ensuring complete data privacy and compliance.
deepseek-ai-is-dangerous-for-healthcare
Security & Compliance

DeepSeek AI: Interesting Methods, Dangerous Product

Analysis of DeepSeek AI's computational efficiency innovations and why its security risks, censorship issues, and compliance concerns make it unsuitable for healthcare, government, and other regulated industries in the United States.
Challenges Finding Compliant AI
Security & Compliance

Challenges Finding Compliant AI: ChatGPT is Watching You

This blog post explores the recent discovery of AI-powered surveillance by Chinese intelligence using ChatGPT, highlighting the vulnerabilities of commercial AI tools in terms of security, privacy, and compliance. It discusses the implications for regulated industries and offers guidance on implementing secure, HIPAA-compliant AI solutions like Hathr.AI to safeguard operations without compromising functionality.
HIPAA Compliant AI

Low-Code HIPAA Compliant AI: Hathr.AI Integrates with Pipedream.com to Deliver HIPAA-Compliant AI Integration

Hathr.AI partners with Pipedream.com to offer HIPAA-compliant AI integrations, transforming healthcare automation with secure, low-code solutions. This collaboration empowers healthcare providers and developers to create compliant workflows, enhancing efficiency and patient outcomes while maintaining robust data security.