Template · Published Aug 18, 2026 · Updated Sep 2026
The Compliance Calendar: OSHA, HIPAA Training, CLIA in One Board
Compliance items lapse the exact same way credentials do: they run on long cycles, belong to no one, and disappear from attention until an audit finds them. The fix is the same too. Put every recurring compliance task, its cadence, and an owner on one board, so nothing expires.
Compliance items lapse the same way credentials do: nobody tracks the date. This free compliance calendar puts OSHA, HIPAA training, CLIA, and the rest on one board with cadences and an owner, so nothing expires.
Get the free compliance calendarA compliance calendar puts your recurring obligations, OSHA bloodborne pathogens training (annual), HIPAA training (at hire plus periodic), CLIA certificate renewal (every two years), and the rest, on one board with cadences and a clear owner. Compliance lapses for the same reason credentials do: long cycles, no owner, out of sight. The fix is renewal math applied to compliance: track the date, assign the owner, start ahead.
Key takeaways
- Compliance items lapse like credentials: long cycles, no clear owner, out of sight until an audit.
- OSHA bloodborne pathogens training is required at hire and at least annually (29 CFR 1910.1030); keep records three years.
- HIPAA training has no fixed interval; at hire plus periodic refresher (commonly annual) is best practice.
- CLIA certificates are effective for two years and must be renewed every two years.
- The fix is a tracked calendar with cadences and an owner, so nothing expires unnoticed.
Credentialing renewals lapse because they run on long cycles that no one tracks. Compliance obligations lapse for exactly the same reason, and they are just as damaging when they do. An annual training missed, a CLIA certificate expired, an Exposure Control Plan never reviewed, none of these announces itself, until an audit or an incident does it for you. The fix is the same renewal math that protects your credentials: one board, every cadence, a clear owner.
Why compliance lapses
Compliance does not usually fail because a practice decides to ignore a rule; it fails because the obligations are structured to be forgotten. Most compliance tasks run on long cycles, annual, biennial, or triggered by events, which means they vanish from daily attention for months or years at a time, and a task you last thought about eleven months ago is a task you are about to miss. They also tend to belong to no one specifically: OSHA training, HIPAA training, the CLIA renewal, and the rest sit in the gap between clinical and administrative, so unless someone owns them explicitly, they default to whoever happens to remember, which is how they get missed. This is the identical failure mode as credentialing revalidations and hospital privileges renewals, covered in the revalidation calendar and the privileges guide, and it has the identical fix. The stakes are real: lapsed compliance can mean fines, failed audits, and in the case of CLIA, an inability to perform and bill for testing, while lapsed OSHA training is one of the most commonly cited violations precisely because long-tenured staff quietly age out of their annual refresher. None of it is hard to prevent; it just has to be tracked.
The recurring compliance items
The specific obligations vary by practice, especially by whether you run a lab or handle controlled substances, but a core set recurs for most independent practices. Put each on the calendar.
| Obligation | What it covers |
|---|---|
| OSHA bloodborne pathogens training | Training for staff with exposure to blood or OPIM |
| OSHA Exposure Control Plan review | Reviewing and updating the written plan |
| HIPAA training | Privacy and security training for the workforce |
| CLIA certificate | Certification to perform laboratory testing, if applicable |
| Fire and emergency preparedness | Drills and emergency-plan review per applicable requirements |
| Controlled substances and DEA | DEA registration and related obligations, where applicable |
| State-specific requirements | Any additional obligations your state imposes |
Not every item applies to every practice, a practice with no lab has no CLIA obligation, so the first step in building your calendar is deciding which of these you actually carry. But for the ones you do, the discipline is identical: know the cadence, track the date, assign the owner. Note that this is provider-and-practice data, not patient data, so the chart-numbers-only rule that governs your project tools, described in the HIPAA-safe project management guide, is not the constraint here; the constraint is simply tracking dates that are easy to forget.
The cadences that matter
Getting the cadences right is the heart of the calendar, so here are the ones most often missed, stated precisely. OSHA bloodborne pathogens training is required at initial assignment before any exposure, and at least annually thereafter, meaning within twelve months of the previous session, not merely once per calendar year, under OSHA's Bloodborne Pathogens Standard, 29 CFR 1910.1030; additional training is required when tasks or procedures change, and training records must be kept for three years. The written Exposure Control Plan must be reviewed and updated at least annually and whenever exposure-affecting changes occur. HIPAA training has no fixed federal interval; it is required for new workforce members and when policies or rules materially change, with an annual refresher widely treated as best practice. The CLIA certificate is effective for two years and must be renewed every two years, with the renewal fee paid to keep it active, a biennial date that is especially easy to lose precisely because two years is long enough to forget. The common trap across all of these is the long interval: annual and biennial tasks are the ones that slip, because the gap between occurrences is longer than anyone's working memory. That is exactly what the calendar solves.
Every recurring compliance task, its cadence, and space to assign an owner and next due date, ready to adapt.
Get the free Rescue KitGive it a calendar and an owner
The fix is the same two moves that protect your credentials: a tracked calendar and a single owner. Put every obligation you carry on one board with its cadence and its next due date, so all of it is visible in one place rather than scattered across memory and filing cabinets, alongside your other recurring dates in the recurring tasks tracker. Assign a single owner, usually the practice manager or a compliance-designated staff member, who is accountable for tracking every date and starting each task in time, because an obligation with no owner is an obligation waiting to lapse. Set reminders well ahead of each deadline, since some items, a CLIA renewal, an annual all-staff training, take lead time to complete, and a reminder that fires on the due date is already too late. That is the entire system: one board, one owner, early reminders. It is modest, and it converts compliance from a set of quietly ticking time bombs into a managed, visible routine, exactly as the same approach does for credentialing.
Renewal math, applied to compliance
The same backward-planning that protects a credential works for a compliance deadline, and it is worth making explicit because compliance items often need real lead time. The math is simple: take the due date, subtract the time the task actually takes to complete, and that difference is when you must start, not the due date itself. A CLIA renewal is not a same-day task; the paperwork and fee take time, so a renewal due in, say, September should trigger action weeks earlier, not on the deadline. An annual all-staff training cannot happen the afternoon it comes due; it has to be scheduled around clinical hours, which means planning ahead so the whole team is trained within the twelve-month window rather than letting a few stragglers push you out of compliance. An Exposure Control Plan review is not a five-minute checkbox; it is a genuine review that deserves calendar time. So for each obligation, record not just the due date but the start date, backing up from the deadline by however long the task realistically needs, and set the reminder to the start date. This is the identical discipline that keeps credentialing from lapsing, and it turns compliance from a series of last-minute scrambles into scheduled work that comfortably beats every deadline.
Running it
A calendar only protects you if it stays live, so build a light rhythm around it. Review it in your operational reviews, so upcoming compliance deadlines are checked on a cadence rather than remembered by luck, a natural fit with the deadlines block in the quarterly review. Log completion when each item is done, training delivered, plan reviewed, certificate renewed, with the date, so you have both a record for audits and a clear next-due date. Keep the required documentation, like the three-year OSHA training records, attached to or referenced from the calendar, so proof of compliance is as tracked as the task itself. And update the calendar when obligations change, a new service that triggers a new requirement, a state rule that shifts, so it never drifts out of sync with what you actually owe. Done this way, the compliance calendar becomes the quiet backstop that keeps a well-run practice out of the two worst compliance outcomes: the preventable fine and the failed audit, both of which come not from bad intent but from a missed date. Track the dates, own the tasks, start ahead, and compliance stops being a source of risk and becomes just another system that runs. For a broader picture of where operational risk hides, the free Leak Audit looks at the whole practice, not just compliance.
Find your leak before you fix it
Two ways to start, both free. Take the tracker and denial log and run it yourself, or get a 20-minute Leak Audit where we put a real number on what your operations are costing, using your own practice.
Frequently asked questions
How often is OSHA bloodborne pathogens training required?
At initial assignment before any exposure, and at least annually thereafter (within twelve months of the previous session), plus additional training whenever tasks, procedures, or equipment change the exposure profile. This is set by OSHA's Bloodborne Pathogens Standard, 29 CFR 1910.1030. Training records must be kept for three years.
How often is HIPAA training required?
HIPAA does not set a fixed interval. Training is required for new workforce members and when policies or regulations materially change; annual refresher training is widely considered best practice. Because the rules and your own policies evolve, a regular cadence keeps the workforce current and documents your good-faith compliance effort.
How often does a CLIA certificate need to be renewed?
CLIA certificates are effective for two years and must be renewed every two years, with the renewal fee paid to keep the certificate active. If your practice performs any laboratory testing, even waived tests, tracking the CLIA renewal date is essential, because an expired certificate can halt your ability to bill for and perform testing.
What should be on a medical office compliance calendar?
The recurring compliance obligations with their cadences and owners: OSHA bloodborne pathogens training (annual) and Exposure Control Plan review (annual), HIPAA training (at hire plus periodic), CLIA certificate renewal (every two years), plus items like fire and emergency preparedness, controlled-substance and DEA matters where applicable, and any state-specific requirements.
Why do compliance deadlines get missed?
For the same reason credentialing renewals do: they run on long cycles, disappear from attention for months or years, and belong to no one specifically. An annual or biennial task is easy to forget precisely because it is not in front of you, so without a tracked calendar and a clear owner, it lapses quietly until an audit or an incident surfaces it.
Is the compliance calendar template free?
Yes. The medical office compliance calendar is a free download that lays out the common recurring compliance tasks, their cadences, and space to assign an owner and track the next due date. The only gate is your email, and it is built to adapt to your practice's specific obligations.