# What 42 CFR 416.43 requires of an ASC's QAPI program

> An ASC must run QAPI, the quality program CMS requires. It tracks quality indicators, adverse patient events and infection control, finds causes and proves fixes last. The governing body owns it. Incident reports feed it, and corrective actions prove it.

Source: https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers · Updated Oct 5, 2026

## Key facts

- **Rule:** 42 CFR 416.43, condition for coverage
- **Survey guidance:** State Operations Manual Appendix L, tags Q-0080 to Q-0084
- **Who owns it:** The governing body (42 CFR 416.41 and 416.43(e))
- **Projects:** At least one improvement project a year, more for larger ASCs
- **Infection control:** Must be an integral part of QAPI (416.51(b)(2))
- **Survey type:** All ASC surveys are unannounced
- **State survey interval:** No more than 6 years for non-deemed ASCs (CMS FY2027 priorities)

- **Citation:** 42 CFR 416.43
- **Authority:** CMS
- **Applies to:** Medicare-certified ambulatory surgery centers surveyed by a state agency, Deemed ASCs accredited by a CMS-approved accrediting organization

## What does 42 CFR 416.43 require?

Measure what happens, find out why, fix it and prove the fix held. This is a condition for coverage, a rule an ASC must meet to be paid by Medicare. It has five standards.

*42 CFR 416.43 in plain language*

| Standard | What it asks for |
| --- | --- |
| (a) Program scope | Show gains in outcomes and patient safety. Measure, analyze and track quality indicators, adverse patient events, infection control and other performance. |
| (b) Program data | Use quality and patient care data to check that care works and is safe, and to find what to change. |
| (c) Program activities | Set priorities in high-risk, high-volume and problem-prone areas. Track adverse patient events, find causes, improve and keep the gains. Use preventive strategies facility-wide so all staff know them. |
| (d) Improvement projects | Run projects that fit the ASC's size and complexity. Record why each was done and what resulted. |
| (e) Governing body | Define and maintain the program. Set what data to collect and how often. Set safety goals, evaluate every improvement, and fund staff, time, information systems and training. |

Also see 42 CFR 416.41 and 42 CFR 416.51(b)(2). The first makes the governing body accountable for QAPI. The second makes infection control an integral part of it.

## Who does what in ASC QAPI?

The governing body owns the program. Others feed it or act on it.

- **Governing body:** defines the program and picks the data and how often to collect it. It sets safety goals and reviews results.
- **QAPI lead and analysts:** collect data and study causes. CMS expects them to be qualified. A contractor may help, but leaders stay responsible.
- **Clinical and support staff:** report events and near misses. They know the preventive strategies, such as wrong-site and wrong-patient safeguards and safe injection practices.
- **Infection control professional:** runs the infection program, which feeds QAPI.

## What do surveyors look for?

Surveyors ask one thing. Does the ASC have an effective, ongoing system to find problems, act and check the result? They do not judge whether problems occurred. CMS guidance: State Operations Manual Appendix L, tags Q-0080 to Q-0084. All ASC surveys are unannounced.

- Leaders describe the program, who runs it and what indicators it tracks.
- At a minimum, indicators include hospital transfers, surgical and infection control measures, and a way to track adverse patient events.
- Who studies the data, and whether they find root causes.
- A case where QAPI data led to a change, and proof it worked and lasted.
- How staff are trained to prevent adverse events.

> **Your own QAPI data** CMS says surveyors generally should not use an ASC's own QAPI data to prove violations of other conditions. It keeps that for egregious (the most serious) cases.

## What should an ASC show?

- The written program and the governing body minutes that created it
- Indicators, why each was chosen, and how often data is collected
- Dated data and analyses at regular intervals
- A log of adverse patient events and near misses, with analysis and action for each
- Hospital transfers and how each was reviewed
- Project records: why each ran and what resulted
- Training records for the preventive strategies
- Proof that planned staff, time and systems were provided

## Where do ASCs fall short?

CMS's own examples show these patterns.

- **Analysis stops at a person.** A drug error review that ends with who gave the drug is not a systems approach. Check storage, order clarity and training first.
- **Indicators that do not measure care.** Billing speed says nothing about patient outcomes.
- **A one-time effort.** Data collected once, with no regular intervals or re-measuring.
- **A fix in one room only.** After an event tied to emergency drug storage, check every room.
- **No proof it lasted.** For hand hygiene, show ongoing data, not one audit.
- **Projects with no reason or result.** Both are required.

## How do incident reports feed QAPI?

Incident reports feed 416.43(c)(2): track adverse patient events, examine causes, improve and keep the gains. CMS also expects near misses to be found.

1. **Capture every event and near miss** Caught wrong-site errors, medication errors, falls, burns, unplanned transfers and infections all count. [IncidentKit intake](https://incidentkit.ai/product/incident-reporting) takes reports by text, QR code, email or web form.
2. **Investigate for system causes** Record contributing factors and the five whys, not a name. Lauren drafts each [investigation](https://incidentkit.ai/product/investigations). A person reviews, edits and signs.
3. **Fix it everywhere and train** Each [corrective action](https://incidentkit.ai/product/corrective-actions) has an owner, due date and evidence. Nothing closes until it is verified.
4. **Re-measure and report** [Analytics](https://incidentkit.ai/product/analytics) show whether the cluster went away. A [compliance packet](https://incidentkit.ai/product/compliance-packets) gives the governing body a QAPI summary.

Infection surveillance and patient experience data come from your other systems. IncidentKit runs alongside them.

## How often is an ASC surveyed?

CMS's fiscal year 2027 priorities ask states to allow no more than six years between surveys of any non-deemed ASC. That is an ASC the state surveys, not an accreditor. They also set targeted surveys of 25 percent of non-deemed ASCs in each state. They favor those not surveyed in over four years.

An ASC can use a CMS-approved accreditor instead and be deemed compliant: [AAAHC](https://incidentkit.ai/compliance/accreditation/aaahc), the [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission), [Quad A](https://incidentkit.ai/compliance/accreditation/quad-a), [ACHC](https://incidentkit.ai/compliance/accreditation/achc) or [DNV](https://incidentkit.ai/compliance/accreditation/dnv). They must cover 416.43. When CMS approved DNV's ASC program, it required DNV to revise its standards. The revision covers tracking adverse patient events and staff awareness of preventive strategies.

The [ASC Quality Reporting Program](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) is separate. Not reporting under it cuts the annual payment update by 2.0 percentage points.

## What the rule asks for, and how IncidentKit supports it

| Requirement | IncidentKit |
| --- | --- |
| 416.43(a)(2), (c)(2): measure, analyze and track adverse patient events | Intake by text, QR code, email or web form, plus routing. Analytics cluster events by cause. |
| 416.43(c)(2): examine causes | Investigations record contributing factors and five whys. Lauren drafts. A person reviews and signs. Human-authored RCA templates are rolling out. |
| 416.43(c)(2), (e)(2): implement improvements, sustain them and evaluate effectiveness | Corrective actions with owner, due date, evidence and an effectiveness check. Nothing closes until verified. |
| 416.43(c)(3): preventive strategies facility-wide, known to all staff | Each action has an owner, due date and evidence, such as a training sign-off. |
| 416.43(d): document each project's reason and results | Analytics trends and closed actions go into a compliance packet. Project charters stay in your QAPI documents. |
| 416.43(e): governing body oversight | A compliance packet gives the governing body a QAPI summary. The audit trail logs every change. Minutes stay yours. |

## Frequently asked questions

### Does an ASC need a written QAPI plan?

The rule does not say plan, but CMS guidance says the program should be defined in writing. Governing body minutes can serve. CMS sets no template, committee or indicator list.

### How many improvement projects must an ASC complete each year?

At least one. CMS guidance says every ASC must undertake one or more projects each year. Larger ASCs, with more rooms, procedure types or volume, should run more or harder ones.

### Are near misses part of ASC QAPI?

Yes. CMS guidance expects ASCs to track all adverse events and spot errors that cause near misses. Near misses can lead to future harm. Its example is a records mix-up between two patients, caught at the time-out.

### Does the ASC Quality Reporting Program replace QAPI?

No. They are separate. QAPI is a condition for coverage at 42 CFR 416.43. The ASC Quality Reporting Program pays for reporting: not reporting cuts the annual payment update by 2.0 percentage points.

## Sources

- [42 CFR 416.43, Quality assessment and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section/416.43)
- [42 CFR 416.41, Governing body and management (eCFR)](https://www.ecfr.gov/current/title-42/section/416.41)
- [42 CFR 416.51, Infection control (eCFR)](https://www.ecfr.gov/current/title-42/section/416.51)
- [CMS State Operations Manual, Appendix L: Guidance to Surveyors, Ambulatory Surgical Centers](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/Downloads/som107ap_l_ambulatory.pdf)
- [CMS Fiscal Year 2027 Mission and Priorities Document](https://www.cms.gov/files/document/fy-27-mpd.pdf)
- [Federal Register: approval of DNV's ASC accreditation program, December 8, 2025](https://www.federalregister.gov/documents/2025/12/08/2025-22203/medicare-and-medicaid-programs-approval-of-application-by-dnv-healthcare-inc-for-initial-cms)
- [42 CFR 416.300, ASC Quality Reporting Program basis and scope (eCFR)](https://www.ecfr.gov/current/title-42/section/416.300)
- [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs)

## Related

- [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness)
- [ASCQR Program: measures, deadlines, 2.0-point penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting)
- [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc)
- [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide)
- [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings)
- [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers)
- [QAPI: definition and meaning](https://incidentkit.ai/glossary/qapi)
- [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes)
