HIPAA-Compliant AI for Skilled Nursing Facilities: The Complete Operator's Guide

PBJ reporting is the mandatory quarterly electronic submission of direct care staffing data that every Medicare- and Medicaid-certified nursing home must file with CMS. Facilities report actual hours worked by nursing and therapy staff, verified against payroll, within 45 days of each federal fiscal quarter's end. CMS uses the data to calculate Care Compare staffing star ratings.

Most facilities that lose a staffing star do not lose it because they were understaffed. They lose it because of submission mechanics: a job code mapped wrong, agency hours entered under the wrong employment type, a pay period that straddled the quarter boundary, or an MDS backlog that quietly deflated the census denominator.

That is an unusually painful way to lose a star, because the staffing rating is publicly displayed on Care Compare, feeds the overall five-star rating, and is increasingly used by hospital discharge planners, managed care networks, and referral sources deciding where to send patients.

This guide covers what PBJ actually requires, how the data becomes a star rating, the errors that most often cause downgrades, and what to have ready if CMS audits your submission.

What PBJ is and why it exists

Payroll-Based Journal is the system CMS uses to collect verifiable, auditable staffing data from nursing homes.

Before PBJ, staffing information on Nursing Home Compare came from the CMS-671 form, a self-reported snapshot taken during the two-week window surrounding the annual survey. That design had an obvious flaw: facilities knew roughly when the survey window fell, and the reported numbers were not tied to payroll.

Section 6106 of the Affordable Care Act addressed this by adding a requirement to the Social Security Act that facilities electronically submit direct care staffing information based on payroll and other verifiable and auditable data. CMS implemented the requirement through the Payroll-Based Journal system, with mandatory electronic submission beginning July 1, 2016. The corresponding requirement appears in the long-term care facility requirements of participation at 42 CFR 483.70.

The statutory language matters more than it might appear. "Verifiable and auditable" is why PBJ is not a staffing estimate, a budgeted-hours report, or a scheduling export. It is a payroll-derived record, and CMS can and does ask facilities to produce the underlying payroll documentation.

Who must submit

Every long-term care facility certified to participate in Medicare or Medicaid must submit PBJ data. This includes facilities that are Medicare-only, Medicaid-only, or dually certified, and applies regardless of ownership type, bed size, or occupancy. Newly certified facilities begin submitting for the first full quarter after certification.

There is no small-facility exemption and no low-census exemption. A twenty-bed rural facility has the same submission obligation as a three-hundred-bed urban campus.

Quarterly deadlines

PBJ operates on the federal fiscal year, which begins October 1 — not the calendar year. This trips up facilities whose finance calendar runs January to December, and it is a recurring source of missed deadlines.

Data is due 45 days after the end of each fiscal quarter:

  • Fiscal Q1 — October 1 through December 31 — due February 14
  • Fiscal Q2 — January 1 through March 31 — due May 15
  • Fiscal Q3 — April 1 through June 30 — due August 14
  • Fiscal Q4 — July 1 through September 30 — due November 14

The deadline is absolute. CMS does not routinely grant extensions, and a submission that arrives on February 15 is a late submission with the same rating consequence as no submission at all.

A practical scheduling note: because the deadline sits 45 days out, most facilities can and should submit well before it. Submitting in the first two weeks after quarter close leaves room to review the CMS validation reports, correct errors, and resubmit — which is only possible before the deadline passes.

What data goes into a submission

A PBJ submission is, at its core, a set of records saying: this person, in this job category, under this employment arrangement, worked this many hours on this date.

Hours worked

PBJ captures hours actually worked providing services in the facility. This is narrower than payroll hours, and the difference is where most errors live.

Include: regular worked hours, overtime hours actually worked, hours worked by agency and contract staff, orientation hours if the person is providing care, hours worked by salaried exempt staff performing direct care functions.

Exclude: vacation, sick leave, holiday pay, bereavement, jury duty, and any other paid non-worked time. Also exclude on-call hours not actually worked, hours worked at a different facility, and hours spent in a capacity outside the reported job code.

The salaried-exempt case deserves attention. A Director of Nursing on salary still has reportable hours, but the facility must report hours actually worked rather than a default 40 per week. If the DON worked 52 hours, report 52. If she took Thursday off, do not report Thursday. Facilities that report a flat 8.0 hours per weekday for every salaried nurse regardless of actual attendance are creating audit exposure.

Job codes

CMS defines a set of 40 job title codes spanning nursing, therapy, and administrative and support functions. The nursing categories that drive the staffing rating are the ones to get right:

  • Registered Nurse categories — separating the RN Director of Nursing, RNs with administrative duties, and RNs providing direct care
  • Licensed Practical Nurse / Licensed Vocational Nurse categories — separating LPNs with administrative duties from LPNs providing direct care
  • Certified Nurse Aide, Nurse Aide in Training, and Medication Aide / Technician
  • Therapy categories — physical, occupational, and speech therapists, assistants, and aides, each reported separately
  • Other clinical and support categories — including administrator, dietary, housekeeping, social work, activities, and pharmacy roles

Mapping is where facilities go wrong. A nurse whose title in your HR system is "Unit Manager" or "Clinical Coordinator" or "Weekend Supervisor" has to land in a specific CMS category, and the choice affects the rating. An RN doing predominantly administrative work belongs in the administrative RN code, not the direct care code — reporting her as direct care inflates RN hours in a way an audit will find.

Build the crosswalk once, document the reasoning, and have the DON sign off on it. Then hold it stable, because a mapping that changes between quarters produces staffing swings that look like instability to anyone reading your trend line.

Employment type

Each hours record must identify whether the individual is an employee of the facility, a contractor, or agency staff. CMS reports contract and agency utilization publicly, and the distinction also matters for turnover measures. Misclassifying agency nurses as employees understates agency reliance and, in an audit, is a straightforward finding because the payroll records will not support it.

Census — and why you do not report it

Facilities do not submit resident census in PBJ. CMS derives the daily census from MDS assessment records.

This is one of the most consequential and least understood mechanics in the entire system, because census is the denominator in every hours-per-resident-day calculation. If your MDS submissions are late, incomplete, or contain discharge records that were never transmitted, CMS may be computing your staffing ratios against a census that does not match reality.

The direction of the error is not always intuitive. Failing to transmit discharge assessments leaves residents "in" the facility in the CMS census, inflating the denominator and lowering your calculated hours per resident day — hurting a rating that your actual staffing would have supported.

The practical implication: PBJ accuracy and MDS timeliness are the same problem. A facility with a chronically backlogged MDS process has a PBJ problem it may not know about. See the MDS Coordinator's guide for the assessment-side controls.

How PBJ becomes a star rating

CMS converts PBJ hours and MDS-derived census into hours per resident day, case-mix adjusts them, and assigns a staffing star rating that is displayed on Care Compare and folded into the overall rating.

Case-mix adjustment

Raw hours per resident day would penalize facilities caring for higher-acuity residents. CMS therefore adjusts expected staffing based on the resident population's assessed acuity as captured in the MDS. A facility with a heavy rehabilitation and complex-medical census has a higher expected staffing threshold than one with a predominantly custodial population.

This creates a second dependency on MDS accuracy. Under-coding acuity lowers your expected-staffing benchmark, which sounds helpful until you notice it also lowers your reimbursement under PDPM. Facilities should code acuity accurately and let both systems reflect reality.

The measures CMS reports

The staffing rating incorporates several distinct measures:

  • Total nurse staffing hours per resident day — RN, LPN/LVN, and nurse aide hours combined
  • RN staffing hours per resident day — weighted heavily, because RN coverage is the strongest staffing correlate of resident outcomes in the research literature
  • Weekend staffing — total nurse and RN hours on Saturdays and Sundays, added because weekend staffing frequently drops well below weekday levels
  • Nursing staff turnover — the percentage of nursing staff who left over a twelve-month period, plus administrator turnover

The weekend and turnover measures deserve specific attention because they were added later and many facilities have not adjusted operations to account for them. A facility with strong Tuesday staffing and thin Sunday staffing now has that pattern surfaced publicly. Turnover, likewise, is computed from the PBJ data itself — CMS can see individual staff identifiers appearing and disappearing across quarters.

The automatic downgrades

Certain conditions produce a one-star staffing rating regardless of reported hours:

  • Failure to submit by the deadline
  • Submission of data that cannot be verified or that fails CMS validation
  • An excessive number of days in the quarter with no reported RN hours. Federal requirements at 42 CFR 483.35 require an RN for at least eight consecutive hours a day, seven days a week, and CMS treats a pattern of RN-less days as a serious finding

That third condition catches facilities that genuinely had RN coverage but failed to report it — for example, when the DON covered a shift and her hours went in under an administrative code, or when an agency RN's hours were never entered because the invoice arrived after the submission was built.

The ten errors that most often cost a star

  1. Paid time off included in worked hours. The single most common finding. Payroll exports include PTO by default; PBJ must not.
  2. Salaried staff reported at a flat rate. Reporting 8.0 hours every weekday for the DON regardless of actual attendance is not payroll-verifiable.
  3. Agency hours omitted entirely. Agency invoices often arrive after the pay cycle, and hours get missed. This both understates staffing and misstates employment-type mix.
  4. Job code drift. Different people mapping titles differently across quarters, producing artificial swings.
  5. Administrative RN hours reported as direct care. Inflates RN HPRD and is easily disproven in audit.
  6. Pay periods straddling the quarter boundary. Hours must be allocated to the actual date worked, not the pay period end date.
  7. MDS discharge records not transmitted. Inflates the census denominator and silently lowers every ratio.
  8. Double-counting universal workers. Staff performing multiple roles must have their hours split by actual function, not reported fully under each code.
  9. Orientation and training hours misclassified. Time spent providing care during orientation is reportable; classroom training generally is not.
  10. Ignoring the validation report. CMS returns validation feedback after submission. Facilities that submit on day 44 have no time to act on it.

Preparing for a PBJ audit

CMS conducts PBJ audits, and the request is usually straightforward: produce the payroll records supporting the hours you reported for a selected period.

What auditors typically want to see:

  • Payroll registers covering the audited period, showing hours by individual and pay type
  • Time and attendance records — punch detail, not summaries
  • Agency and contract invoices with hours detail
  • Your job code crosswalk, with documented rationale
  • Evidence of how PTO was excluded from reported hours
  • Documentation of how salaried staff hours were determined

The facilities that struggle in audit are rarely the ones that staffed poorly. They are the ones that cannot reconstruct how a number was produced eighteen months after the fact, because the person who built the submission has left and the methodology lived in their head.

Two controls fix most of this. First, write down the methodology — the crosswalk, the PTO exclusion rule, the salaried-hours rule — and treat it as a governed document. Second, archive the source payroll export alongside each submission, so the reconciliation can be rerun.

Where AI helps with PBJ

PBJ is fundamentally a reconciliation problem, and reconciliation across mismatched documents is what large language models are unusually good at.

Concretely, a HIPAA-compliant AI platform can:

  • Reconcile payroll exports against submitted PBJ files, flagging individuals whose hours differ and identifying which discrepancies are PTO-related
  • Audit the job code crosswalk against actual position descriptions and surface titles that appear mapped inconsistently
  • Read agency invoices — frequently PDFs, sometimes scanned, occasionally handwritten timesheets — and extract hours by individual and date for comparison against what was submitted
  • Draft the audit response narrative, explaining methodology in the structured form CMS expects
  • Analyze weekend and RN coverage patterns across a quarter to identify days at risk of triggering the RN-coverage downgrade before the quarter closes

The agency invoice case is where document handling capability separates platforms. A stack of scanned timesheets with handwritten hours is exactly the input most AI tools cannot process. Hathr.AI's OCR handles handwriting and its document capacity accommodates a full quarter of payroll and invoice records in a single working session.

What AI should not do is generate the submission. PBJ must be payroll-derived, and the value here is verification and reconciliation — catching the error before February 14, not manufacturing a number.

Try it against your own data

Upload last quarter's payroll export and your submitted PBJ file and ask Hathr.AI to reconcile them. Most facilities find at least one systematic discrepancy on the first pass.

Start a free trial — no seat minimum →

Frequently asked questions

What is PBJ reporting?
PBJ, or Payroll-Based Journal, is the mandatory quarterly electronic submission of direct care staffing data that Medicare- and Medicaid-certified nursing homes file with CMS. Facilities report actual hours worked by nursing, therapy, and other direct care staff, verifiable against payroll records.

When are PBJ submissions due?
45 days after the end of each federal fiscal quarter: February 14, May 15, August 14, and November 14.

What happens if a facility fails to submit PBJ data?
CMS assigns a one-star staffing rating on Care Compare, regardless of actual staffing levels.

Does paid time off count toward PBJ hours?
No. PBJ captures hours actually worked providing care in the facility. Vacation, sick leave, holiday pay, and other paid non-worked time must be excluded.

Where does the resident census in PBJ come from?
Facilities do not report census. CMS derives it from MDS assessment records, which is why MDS timeliness directly affects the staffing rating.

Do agency and contract staff hours count?
Yes. They must be reported with the correct employment type, and the underlying invoices must support the hours.


Part of the HIPAA-Compliant AI for Skilled Nursing Facilities hub. Related: Survey Readiness Checklist · QAPI in Nursing Homes

This article is general regulatory information, not legal or compliance advice. Verify current requirements against the CMS PBJ Policy Manual and applicable regulations before acting.

Category
No items found.
Written by
Sam Hart headshot - Founder at Hathr.ai
Hathr.AI Clinical Compliance Team
Date Published:
2026-08-07

Our Youtube Videos

Hathr.AI is the fastest, safest way to handle sensitive medical records with HIPAA-compliant artificial intelligence. In this demo, watch how you can:✅ Summarize a patient’s medical record  ✅ Generate an AI-assisted treatment plan  ✅ Write a letter to the patient in plain English  ✅ Suggest CPT billing codes  ✅ Draft an insurance appeal for a denied claim  ✅ Evaluate the case for potential malpractice — all in under 5 minutes.The only AI tool hosted in AWS GovCloud and Powered by Claude 4.0 Sonnet, Hathr.AI is trusted by hundreds of practices that need speed, security, and compliance.Learn more: hathr.ai  For healthcare teams: hathr.ai/healthcare  Reach out to learn more: contact@hathr.ai

#HIPAACompliantAI#ArtificialIntelligenceInMedicine#HealthcareAI#MedicalBillingAI#AIForDoctors#HIPAAAI#MedicalRecords#AIInHealthcare

Description

As Hathr.AI, we are dedicated to providing a private, secure, and HIPAA-compliant AI solution that prioritizes your data privacy while delivering cutting-edge technology for enterprises and healthcare professionals alike.

In this video, we’ll dive deep into the growing concerns around data privacy with AI tools—especially in light of recent revelations about Microsoft’s Word and Excel AI features. These new features have raised alarm over data scraping practices, where user data could be used without clear consent, leaving individuals and organizations exposed to potential privacy breaches. What makes this especially concerning is the "opt-in by default" design, which could lead to unintended data sharing.

In contrast, Hathr.AI ensures that your data stays yours. With a firm commitment to HIPAA compliance, we take the protection of sensitive healthcare data to the highest level. Our platform is built with the understanding that privacy is not an afterthought but a fundamental pillar of our design. We don’t collect, store, or sell user data, and we employ state-of-the-art encryption, secure access protocols, and clear user consent processes to keep you in full control.

We’ll also touch on why Hathr.AI, powered by advanced LLM (Large Language Models) like Claude AI, offers a secure and private alternative for businesses looking to leverage AI technology without compromising sensitive information. While some AI tools may collect or expose data through ambiguous or hard-to-find opt-out settings, Hathr.AI puts transparency and security at the forefront, offering peace of mind in an era of increasing digital vulnerability.

If you’re concerned about your privacy or looking for a HIPAA-compliant AI solution that respects your data, Hathr.AI provides the robust security, transparency, and ethical design that you need.

Key Points:

  • HIPAA Compliant AI: Built for healthcare professionals, ensuring compliance with privacy regulations.
  • Privacy-first: No data scraping, no data selling, full user control over information.
  • Claude AI: Secure, powerful LLM tools for advanced capabilities without compromising security.
  • Data Transparency: Say goodbye to hidden opt-in/opt-out toggles—Hathr.AI gives you clear, easy-to-understand privacy settings.

Tune in to learn how Hathr.AI ensures your AI tools remain private, secure, and trustworthy, while still delivering the performance and accuracy you need to thrive in a fast-evolving digital landscape.

Don't forget to like, comment, and subscribe for more insights on secure AI solutions and how to protect your organization from emerging privacy risks!

Description

Discover how Hathr AI's advanced AI tools transform federal acquisition processes with unparalleled security and efficiency. Designed for government professionals, this video showcases Hathr AI’s capabilities, including secure AI data analysis, HIPAA-compliant tools, and AWS GovCloud integration, to help streamline decision-making and document management. Perfect for agencies seeking private, compliant, and powerful AI solutions, Hathr.AI delivers tools tailored for healthcare and government needs.

Key Topics Covered:

AI-driven data analysis for governmentHIPAA-compliant, secure AI tools for federal agencies

Private deployment options with AWS GovCloud

Learn more about Hathr AI’s secure, high-performance solutions at hathr.ai and transform your agency’s acquisition process with cutting-edge AI.

Description

Discover how Hathr.AI simplifies NSF grant evaluations with advanced AI-driven compliance and proposal review tools. This video showcases Hathr.AI’s capability to streamline grant compliance checks, enhance accuracy, and save time for evaluators and applicants alike. Ideal for research institutions, government agencies, and proposal writers, Hathr.AI offers secure, HIPAA-compliant AI solutions tailored to meet the complex requirements of NSF and other grant processes.Highlights:AI-powered compliance checks for NSF grant proposalsFast, accurate, and secure evaluations with Hathr.AITailored solutions for research, government, and healthcareOptimize your grant proposal process with Hathr.AI's private, secure AI tools. Learn more at hathr.ai and transform how you handle grant evaluations and compliance.

Description

Join Hathr.AI at the Defense Information Systems Agency (DISA) Technical Exchange Meeting to explore innovative AI solutions tailored for federal and defense applications. In this session, we highlight Hathr.AI's secure, private AI tools designed for efficient data handling, HIPAA compliance, and seamless integration within government systems, including AWS GovCloud. Perfect for agencies seeking reliable AI for data analysis, document summarization, and secure decision-making, Hathr.AI provides cutting-edge technology for defense and healthcare needs.Highlights:AI tools for federal and defense data managementSecure, HIPAA-compliant AI solutions with AWS GovCloudEnhancing operational efficiency with private AI deploymentsDiscover how Hathr.AI's solutions empower government and defense agencies to stay at the forefront of innovation. Visit https://hathr.ai to learn more about our services.

Blog and articles

Latest insights and trends

AI Healthcare solutions with Hathr.AI
HIPAA Compliant AI

AI Healthcare Solutions: How a HIPAA Compliant LLM can Revolutionize your practice

Learn how HIPAA compliant AI healthcare solutions can revolutionize your practice. Hathr AI offers secure, HIPAA & NIST-certified tools that automate billing, enhance diagnostics, and improve patient care while ensuring complete data privacy and compliance.
deepseek-ai-is-dangerous-for-healthcare
Security & Compliance

DeepSeek AI: Interesting Methods, Dangerous Product

Analysis of DeepSeek AI's computational efficiency innovations and why its security risks, censorship issues, and compliance concerns make it unsuitable for healthcare, government, and other regulated industries in the United States.
Challenges Finding Compliant AI
Security & Compliance

Challenges Finding Compliant AI: ChatGPT is Watching You

This blog post explores the recent discovery of AI-powered surveillance by Chinese intelligence using ChatGPT, highlighting the vulnerabilities of commercial AI tools in terms of security, privacy, and compliance. It discusses the implications for regulated industries and offers guidance on implementing secure, HIPAA-compliant AI solutions like Hathr.AI to safeguard operations without compromising functionality.
HIPAA Compliant AI

Low-Code HIPAA Compliant AI: Hathr.AI Integrates with Pipedream.com to Deliver HIPAA-Compliant AI Integration

Hathr.AI partners with Pipedream.com to offer HIPAA-compliant AI integrations, transforming healthcare automation with secure, low-code solutions. This collaboration empowers healthcare providers and developers to create compliant workflows, enhancing efficiency and patient outcomes while maintaining robust data security.