Infection prevention is an enterprise risk boards can’t delegate away

Advertisement

Over the years, Becker’s Hospital Review has run numerous articles describing the growing strain on health system leadership: margin pressure, workforce instability, rising patient acuity and heightened scrutiny of safety. Yet one of the most financially, operationally and reputationally consequential risks in healthcare still sits outside most board agendas: infection prevention.

For board chairs and health system CEOs, the implication is clear. Infection prevention is not a narrow quality metric. It is an enterprise risk indicator.

Yet governance structures often fail to treat it that way. Under the federal Conditions of Participation, hospital governing bodies are required to appoint a qualified infection preventionist under 42 CFR 482.42. What those requirements do not clearly specify is how, or whether, that leader engages directly with the board or how governing bodies are expected to exercise informed oversight of infection prevention and control.

The result is a common governance gap: Boards hold formal responsibility for infection prevention, but often lack routine, firsthand insight into prevention readiness, emerging risks and system constraints.

CMS should consider clarifying through interpretive guidance that governing body appointment of the infection preventionist includes responsibility for informed oversight. This could include explicit expectations that governing body members receive orientation and periodic education on infection prevention and control responsibilities, with direct involvement of the infection prevention leader. Without this clarity, infection prevention remains formally assigned but functionally distanced from board-level governance.

In practice, if infection information reports are provided to boards, they are often presented as lagging indicators, framed for compliance rather than foresight. Reports focus on rates and benchmarks, not on whether the organization has the workforce capacity, data infrastructure and leadership alignment required to prevent infections before they occur. 

Compounding this issue, even when reports are provided, they are often delivered by individuals without formal expertise in infection prevention — an approach akin to asking a head of human resources to present a detailed finance report. Boards may receive information but not the level of subject-matter insight required for meaningful risk governance.

Boards often see infection outcomes but are not engaged in infection prevention readiness. By the time boards become involved following a reported event, options are limited and the damage is already done clinically, financially and reputationally.

This disconnect is reinforced by limited direct exposure between infection prevention leaders and governing bodies. In a recent LinkedIn pulse poll of 104 self-identified infection prevention leaders, 60% reported that they have never presented to their facility’s board of directors, or have only done so during a crisis. That finding underscores how rarely boards receive proactive, structured insight into infection prevention risk, despite their accountability for it.

Infection prevention requires a systems approach. It depends on thoughtful system design, staffing continuity, surveillance infrastructure and operational discipline. This is not an argument for boards of directors to micromanage clinical practice. It is an argument for boards to govern risk consistently. Few boards would tolerate limited visibility into cybersecurity readiness or financial oversight. Infection prevention deserves the same rigor.

That rigor should include direct, routine engagement with the accountable and properly qualified infection prevention leader; particularly those holding a certification from the Certification in Infection Control, the field’s recognized standard for professional competency. Boards already approve these leaders. Expecting them to periodically brief the board on prevention readiness, emerging risks and resource constraints is not an overreach; it is sound governance.

Without a doubt, CEOs must balance a very dynamic set of priorities. However, often the temptation is to treat infection prevention as one more competing priority. In reality, it is a force multiplier. Strong infection prevention protects patients and staff, sustains organizational reputation and reduces downstream financial exposure.

In a healthcare environment that is becoming less forgiving, boards and CEOs should ask a simple question: Does our governance model allow us to see infection risk early or only explain it after harm occurs? The answer increasingly separates resilient systems from vulnerable ones.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Infection Control

Advertisement