ClinicOps

Template · Published Aug 18, 2026 · Updated Sep 2026

The Compliance Calendar: OSHA, HIPAA Training, CLIA in One Board

Compliance items lapse the exact same way credentials do: they run on long cycles, belong to no one, and disappear from attention until an audit finds them. The fix is the same too. Put every recurring compliance task, its cadence, and an owner on one board, so nothing expires.

Jareer Ali· Research & field notes·11 min read
[ Preview: the medical office compliance calendar, every recurring compliance task and its cadence on one board with an owner. ]

Compliance items lapse the same way credentials do: nobody tracks the date. This free compliance calendar puts OSHA, HIPAA training, CLIA, and the rest on one board with cadences and an owner, so nothing expires.

Get the free compliance calendar

A compliance calendar puts your recurring obligations, OSHA bloodborne pathogens training (annual), HIPAA training (at hire plus periodic), CLIA certificate renewal (every two years), and the rest, on one board with cadences and a clear owner. Compliance lapses for the same reason credentials do: long cycles, no owner, out of sight. The fix is renewal math applied to compliance: track the date, assign the owner, start ahead.

Key takeaways

Credentialing renewals lapse because they run on long cycles that no one tracks. Compliance obligations lapse for exactly the same reason, and they are just as damaging when they do. An annual training missed, a CLIA certificate expired, an Exposure Control Plan never reviewed, none of these announces itself, until an audit or an incident does it for you. The fix is the same renewal math that protects your credentials: one board, every cadence, a clear owner.

Why compliance lapses

Compliance does not usually fail because a practice decides to ignore a rule; it fails because the obligations are structured to be forgotten. Most compliance tasks run on long cycles, annual, biennial, or triggered by events, which means they vanish from daily attention for months or years at a time, and a task you last thought about eleven months ago is a task you are about to miss. They also tend to belong to no one specifically: OSHA training, HIPAA training, the CLIA renewal, and the rest sit in the gap between clinical and administrative, so unless someone owns them explicitly, they default to whoever happens to remember, which is how they get missed. This is the identical failure mode as credentialing revalidations and hospital privileges renewals, covered in the revalidation calendar and the privileges guide, and it has the identical fix. The stakes are real: lapsed compliance can mean fines, failed audits, and in the case of CLIA, an inability to perform and bill for testing, while lapsed OSHA training is one of the most commonly cited violations precisely because long-tenured staff quietly age out of their annual refresher. None of it is hard to prevent; it just has to be tracked.

The recurring compliance items

The specific obligations vary by practice, especially by whether you run a lab or handle controlled substances, but a core set recurs for most independent practices. Put each on the calendar.

Common recurring compliance obligations
ObligationWhat it covers
OSHA bloodborne pathogens trainingTraining for staff with exposure to blood or OPIM
OSHA Exposure Control Plan reviewReviewing and updating the written plan
HIPAA trainingPrivacy and security training for the workforce
CLIA certificateCertification to perform laboratory testing, if applicable
Fire and emergency preparednessDrills and emergency-plan review per applicable requirements
Controlled substances and DEADEA registration and related obligations, where applicable
State-specific requirementsAny additional obligations your state imposes

Not every item applies to every practice, a practice with no lab has no CLIA obligation, so the first step in building your calendar is deciding which of these you actually carry. But for the ones you do, the discipline is identical: know the cadence, track the date, assign the owner. Note that this is provider-and-practice data, not patient data, so the chart-numbers-only rule that governs your project tools, described in the HIPAA-safe project management guide, is not the constraint here; the constraint is simply tracking dates that are easy to forget.

The cadences that matter

Getting the cadences right is the heart of the calendar, so here are the ones most often missed, stated precisely. OSHA bloodborne pathogens training is required at initial assignment before any exposure, and at least annually thereafter, meaning within twelve months of the previous session, not merely once per calendar year, under OSHA's Bloodborne Pathogens Standard, 29 CFR 1910.1030; additional training is required when tasks or procedures change, and training records must be kept for three years. The written Exposure Control Plan must be reviewed and updated at least annually and whenever exposure-affecting changes occur. HIPAA training has no fixed federal interval; it is required for new workforce members and when policies or rules materially change, with an annual refresher widely treated as best practice. The CLIA certificate is effective for two years and must be renewed every two years, with the renewal fee paid to keep it active, a biennial date that is especially easy to lose precisely because two years is long enough to forget. The common trap across all of these is the long interval: annual and biennial tasks are the ones that slip, because the gap between occurrences is longer than anyone's working memory. That is exactly what the calendar solves.

Get the free compliance calendar

Every recurring compliance task, its cadence, and space to assign an owner and next due date, ready to adapt.

Get the free Rescue Kit

Give it a calendar and an owner

The fix is the same two moves that protect your credentials: a tracked calendar and a single owner. Put every obligation you carry on one board with its cadence and its next due date, so all of it is visible in one place rather than scattered across memory and filing cabinets, alongside your other recurring dates in the recurring tasks tracker. Assign a single owner, usually the practice manager or a compliance-designated staff member, who is accountable for tracking every date and starting each task in time, because an obligation with no owner is an obligation waiting to lapse. Set reminders well ahead of each deadline, since some items, a CLIA renewal, an annual all-staff training, take lead time to complete, and a reminder that fires on the due date is already too late. That is the entire system: one board, one owner, early reminders. It is modest, and it converts compliance from a set of quietly ticking time bombs into a managed, visible routine, exactly as the same approach does for credentialing.

Renewal math, applied to compliance

The same backward-planning that protects a credential works for a compliance deadline, and it is worth making explicit because compliance items often need real lead time. The math is simple: take the due date, subtract the time the task actually takes to complete, and that difference is when you must start, not the due date itself. A CLIA renewal is not a same-day task; the paperwork and fee take time, so a renewal due in, say, September should trigger action weeks earlier, not on the deadline. An annual all-staff training cannot happen the afternoon it comes due; it has to be scheduled around clinical hours, which means planning ahead so the whole team is trained within the twelve-month window rather than letting a few stragglers push you out of compliance. An Exposure Control Plan review is not a five-minute checkbox; it is a genuine review that deserves calendar time. So for each obligation, record not just the due date but the start date, backing up from the deadline by however long the task realistically needs, and set the reminder to the start date. This is the identical discipline that keeps credentialing from lapsing, and it turns compliance from a series of last-minute scrambles into scheduled work that comfortably beats every deadline.

Running it

A calendar only protects you if it stays live, so build a light rhythm around it. Review it in your operational reviews, so upcoming compliance deadlines are checked on a cadence rather than remembered by luck, a natural fit with the deadlines block in the quarterly review. Log completion when each item is done, training delivered, plan reviewed, certificate renewed, with the date, so you have both a record for audits and a clear next-due date. Keep the required documentation, like the three-year OSHA training records, attached to or referenced from the calendar, so proof of compliance is as tracked as the task itself. And update the calendar when obligations change, a new service that triggers a new requirement, a state rule that shifts, so it never drifts out of sync with what you actually owe. Done this way, the compliance calendar becomes the quiet backstop that keeps a well-run practice out of the two worst compliance outcomes: the preventable fine and the failed audit, both of which come not from bad intent but from a missed date. Track the dates, own the tasks, start ahead, and compliance stops being a source of risk and becomes just another system that runs. For a broader picture of where operational risk hides, the free Leak Audit looks at the whole practice, not just compliance.

Find your leak before you fix it

Two ways to start, both free. Take the tracker and denial log and run it yourself, or get a 20-minute Leak Audit where we put a real number on what your operations are costing, using your own practice.

Frequently asked questions

How often is OSHA bloodborne pathogens training required?

At initial assignment before any exposure, and at least annually thereafter (within twelve months of the previous session), plus additional training whenever tasks, procedures, or equipment change the exposure profile. This is set by OSHA's Bloodborne Pathogens Standard, 29 CFR 1910.1030. Training records must be kept for three years.

How often is HIPAA training required?

HIPAA does not set a fixed interval. Training is required for new workforce members and when policies or regulations materially change; annual refresher training is widely considered best practice. Because the rules and your own policies evolve, a regular cadence keeps the workforce current and documents your good-faith compliance effort.

How often does a CLIA certificate need to be renewed?

CLIA certificates are effective for two years and must be renewed every two years, with the renewal fee paid to keep the certificate active. If your practice performs any laboratory testing, even waived tests, tracking the CLIA renewal date is essential, because an expired certificate can halt your ability to bill for and perform testing.

What should be on a medical office compliance calendar?

The recurring compliance obligations with their cadences and owners: OSHA bloodborne pathogens training (annual) and Exposure Control Plan review (annual), HIPAA training (at hire plus periodic), CLIA certificate renewal (every two years), plus items like fire and emergency preparedness, controlled-substance and DEA matters where applicable, and any state-specific requirements.

Why do compliance deadlines get missed?

For the same reason credentialing renewals do: they run on long cycles, disappear from attention for months or years, and belong to no one specifically. An annual or biennial task is easy to forget precisely because it is not in front of you, so without a tracked calendar and a clear owner, it lapses quietly until an audit or an incident surfaces it.

Is the compliance calendar template free?

Yes. The medical office compliance calendar is a free download that lays out the common recurring compliance tasks, their cadences, and space to assign an owner and track the next due date. The only gate is your email, and it is built to adapt to your practice's specific obligations.

Who it's for
Practice managers and owner-physicians who want to stop compliance obligations from lapsing by tracking every cadence and owner on one board.
Why it matters
Compliance lapses like credentials do: long cycles, no owner, out of sight. A compliance calendar tracks OSHA (annual), HIPAA (at hire plus periodic), CLIA (every two years), and the rest with cadences and an owner, so nothing expires unnoticed.
Cite this page
ClinicOps, "The Compliance Calendar: OSHA, HIPAA Training, CLIA in One Board," September 2026. clinicops.us/guides/medical-office-compliance-calendar
Topics
compliance calendarOSHAHIPAA trainingCLIA
ClinicOps    We build the systems that keep independent practices independent.   Prices published. Face on camera. Your team owns it.