Professional Email Etiquette: Terms & Interactive Examples for Admin Assistants
Administrative emails can schedule care, resolve insurance problems, secure authorizations, and document decisions. A vague subject line, exposed recipient list, careless attachment, or rushed reply can also create delays, privacy incidents, and permanent evidence of poor judgment. Administrative assistants who understand effective patient communication, patient confidentiality, medical administrative workflows, and medical compliance terms can write messages that are clear, secure, actionable, and easy to defend later.
1. Why Professional Email Etiquette Is an Administrative Control
Professional email etiquette is the disciplined use of structure, tone, timing, recipient controls, and information safeguards to move work forward accurately. It supports front-desk operations, appointment scheduling, insurance verification, and medical records management because every effective message establishes the issue, responsible person, required action, supporting information, and expected response date.
The strongest emails reduce interpretation. “Please review” leaves the recipient guessing about urgency, scope, and outcome. “Please confirm by 2:00 p.m. whether authorization 58421 covers CPT 70553 for the September 12 appointment” creates a defined task. Administrative assistants who master prior authorization procedures, CPT terminology, scheduling conflict resolution, and time-management techniques can turn email from an inbox burden into a controlled workflow.
Healthcare email also requires deliberate privacy decisions. HHS permits covered healthcare providers to communicate with patients by email when reasonable safeguards are applied. Its guidance specifically identifies checking an email address for accuracy as a precaution against unintended disclosure. Treatment information may also be shared electronically between providers when appropriate safeguards are used.
That standard affects patient privacy communication, patient portal management, EMR integration tools, and virtual patient management. Before sending, the assistant should verify the recipient, communication purpose, attached record, permitted disclosure basis, appropriate channel, and amount of information required.
Professionalism also includes cybersecurity judgment. Phishing messages often imitate trusted organizations or colleagues to obtain credentials, trigger malicious downloads, or persuade employees to disclose sensitive information. NIST and CISA recommend teaching employees to recognize suspicious messages and report them through the organization’s security process.
A polished message can still be dangerous when it contains an unexpected login link, altered payment instructions, an urgent secrecy request, or a disguised attachment. Employees using healthcare CRM systems, medical office collaboration tools, patient communication applications, and staff scheduling platforms should verify unusual instructions through a trusted second channel.
Marketing and promotional emails create another compliance layer. The FTC’s CAN-SPAM guidance requires accurate header information and subject lines for covered commercial messages, along with identification, a valid postal address, and a functioning opt-out method. Administrative reminders, transactional messages, and promotional campaigns should therefore be classified before distribution.
The reference below translates common email terminology into administrative decisions. Use the search box and category menu to isolate terms related to structure, recipients, privacy, tone, workflow, or security.
| # | Email Term | Category | Operational Meaning | Common Mistake | Professional Example |
|---|---|---|---|---|---|
| 1 | Subject Line | Structure | A concise description of the message’s purpose, required action, reference, or deadline. | Using vague subjects such as “Question,” “Important,” or “Please Review.” | Authorization Confirmation Needed by 2:00 p.m. — MRI Appointment 58421 |
| 2 | Salutation | Structure | The opening greeting selected according to the recipient, workplace culture, and level of formality. | Misspelling the recipient’s name or using an overly casual greeting in a formal exchange. | Hello Ms. Rivera, |
| 3 | Opening Context | Structure | The first sentence that explains why the recipient is receiving the message. | Beginning with unnecessary background before identifying the issue. | I am following up on yesterday’s request for the signed operative report. |
| 4 | Call to Action | Structure | A direct statement explaining the response, decision, document, or action required. | Ending with “Please advise” when a specific approval or document is needed. | Please approve option B or return your revisions by Thursday at noon. |
| 5 | Closing Statement | Structure | The final sentence that confirms the next step or the sender’s future action. | Using a vague closing that leaves task ownership unclear. | After receiving your confirmation, I will update the schedule and contact the patient. |
| 6 | Email Signature | Structure | A standardized identification block containing the sender’s name, title, organization, and approved contact details. | Including outdated information, oversized images, decorative quotations, or personal social links. | Jordan Lee | Administrative Assistant | Direct Line: 555-0124 |
| 7 | To Field | Recipients | The field for recipients expected to act, decide, approve, or respond. | Placing every interested employee in the To field without assigning responsibility. | The department manager is placed in To because formal approval is required. |
| 8 | CC | Recipients | Carbon copy used for people who need visibility without carrying the primary action. | Using CC to embarrass a colleague, apply pressure, or create a surprise escalation. | The billing lead is copied because the scheduling decision affects claim submission. |
| 9 | BCC | Recipients | Blind carbon copy used to conceal recipient addresses from other recipients. | Exposing a large external mailing list through the To or CC field. | BCC is used for an approved newsletter sent to unrelated external recipients. |
| 10 | Reply All | Recipients | A response sent to the original sender and every visible recipient. | Replying to the entire group when the answer concerns only one person. | Reply All is used because the revised procedure affects every listed department. |
| 11 | Distribution List | Recipients | A managed group of recipients used for recurring announcements or team communication. | Sending confidential information without confirming who currently belongs to the group. | The department list is reviewed before the compliance update is distributed. |
| 12 | Email Thread | Workflow | A connected sequence of messages addressing the same subject or task. | Continuing an old thread after the subject, patient, project, or recipient group changes. | A new thread is created when the discussion changes from scheduling to billing. |
| 13 | Thread Summary | Workflow | A concise recap of previous decisions, completed actions, and unresolved items. | Forwarding a long conversation and expecting a new recipient to interpret every message. | Decision: reschedule the visit. Pending: payer confirmation by 3:00 p.m. |
| 14 | Response Deadline | Workflow | A specific date and time by which the recipient’s action is required. | Writing “ASAP” without identifying when the response becomes unusable. | Please respond by 11:00 a.m. so the patient can be contacted today. |
| 15 | Escalation | Workflow | Routing a high-risk, unresolved, or authority-dependent issue to the correct decision-maker. | Copying senior leadership before following the organization’s established escalation path. | The unresolved disclosure question is forwarded to the privacy officer. |
| 16 | Follow-Up Email | Workflow | A reminder that restates the original request, current status, required action, and consequence. | Sending “Following up again” without giving the recipient useful context. | The claim remains on hold pending the signed order requested Monday. |
| 17 | Acknowledgement | Workflow | A brief confirmation that the message was received and assigned for review. | Remaining silent until a complete answer is available. | Received. I am reviewing the discrepancy and will provide an update by 4:00 p.m. |
| 18 | Out-of-Office Reply | Workflow | An automated notice explaining the absence period and the correct alternate contact. | Sharing unnecessary travel details or omitting a route for urgent requests. | I will return August 18. For urgent scheduling issues, contact the central desk. |
| 19 | Professional Tone | Tone | Respectful, direct, factual, and proportionate language appropriate to the situation. | Using sarcasm, blame, emotional assumptions, excessive capitalization, or aggressive punctuation. | The form remains incomplete because the provider-signature field is blank. |
| 20 | Neutral Language | Tone | Objective wording that records observable events without assigning motive or intent. | Writing that a colleague ignored, refused, or deliberately delayed a task without evidence. | No response had been received as of 2:30 p.m. |
| 21 | Tone Marker | Tone | A phrase that clarifies appreciation, cooperation, urgency, or respect. | Depending on emojis or repeated exclamation marks to communicate warmth. | Thank you for reviewing this before today’s scheduling cutoff. |
| 22 | Minimum Necessary | Privacy | Limiting information to the amount reasonably required for the communication purpose when the standard applies. | Attaching an entire chart to answer one authorization or scheduling question. | The message contains the relevant order and supporting note only. |
| 23 | Recipient Verification | Privacy | Confirming the recipient’s name, email address, role, and authority before transmission. | Trusting autocomplete, an outdated contact list, or a previous email thread. | The address is checked against the organization’s approved directory before sending. |
| 24 | Secure Message | Privacy | A message transmitted through an organization-approved protected email or portal system. | Assuming any password-protected document automatically satisfies every privacy requirement. | Clinical documents are delivered through the approved secure patient portal. |
| 25 | Attachment Validation | Privacy | Opening and checking the file, patient, version, page count, and recipient before sending. | Selecting a file solely because its name appears familiar. | The attachment is opened and matched to the intended patient before transmission. |
| 26 | Confidentiality Notice | Privacy | Approved footer language explaining intended use and what to do after accidental receipt. | Believing the notice can correct an otherwise unauthorized or careless disclosure. | The footer supports the process while recipient and content verification remain mandatory. |
| 27 | Phishing | Security | A deceptive message designed to steal credentials, obtain information, or trigger a harmful action. | Trusting a message because it contains a familiar logo, signature, or executive name. | The employee reports the message without opening its login link. |
| 28 | Email Spoofing | Security | Manipulation that makes a message appear to come from a trusted person or organization. | Reviewing only the display name while ignoring the full sender address. | The sender address and unusual request are verified through a known contact route. |
| 29 | Suspicious Attachment | Security | An unexpected, unusual, or potentially malicious file included in an email. | Opening the attachment to determine whether it is legitimate. | The file is reported to the security team through the approved process. |
| 30 | Business Email Compromise | Security | Fraud involving an impersonated or compromised business account used to request payments, records, or sensitive actions. | Following urgent banking or payment instructions without independent confirmation. | The requested account change is verified by calling the vendor through a trusted number. |
2. How to Structure a Professional Administrative Email
A useful email begins with a specific subject line. Include the task, relevant identifier, and deadline when appropriate: “Provider Signature Needed — Order 30184 — Due Thursday.” Avoid putting sensitive clinical details in a subject line because subject text may appear in alerts, lock-screen previews, forwarding histories, and mailbox lists. This discipline complements patient confidentiality controls, HIPAA terminology, medical records procedures, and medical-office risk management.
The opening sentence should give the reader immediate context. Name the prior conversation, request, account, meeting, appointment, or document. “I am following up on the eligibility discrepancy identified during yesterday’s verification” gives the recipient a starting point. Administrative professionals managing insurance claims, coordination of benefits, appointment conflicts, and prior authorizations should avoid forcing recipients to search old threads before understanding the current issue.
The body should separate facts, impact, and requested action. Facts describe what has occurred. Impact explains what remains blocked or at risk. The requested action tells the recipient exactly what must happen next. A strong email might state that the payer rejected the member ID, the appointment cannot be financially cleared, and confirmation is needed by 3:00 p.m. This structure supports revenue cycle management, denials management, medical claims processing, and scheduling best practices.
Use bullets when the recipient must compare options, submit several items, or follow a sequence. A short paragraph works better for a single decision. Dense messages create hidden tasks because each request becomes buried inside background information. Assistants improving medical-office productivity, daily office procedures, EMR productivity, and administrative time management should keep each message centered on one operational outcome.
Every deadline should explain its consequence. “Please respond by Friday” is weaker than “Please confirm by Friday at noon so registration can contact the patient before the weekend.” The second version helps the recipient prioritize intelligently. It also reduces the repeated follow-ups that overwhelm front-desk teams, disrupt patient scheduling, delay insurance verification, and weaken patient satisfaction.
Close by confirming ownership. State what you will do after receiving the answer: update the chart, contact the patient, release the claim, revise the calendar, or notify the team. The recipient can then see how their response fits the workflow. This habit strengthens medical administrative policies, patient record updates, medical-office collaboration, and practice management systems.
Before sending, run a six-point check: recipient, subject, requested action, deadline, attachment, and privacy level. HHS guidance places responsibility on regulated entities to use reasonable safeguards, including accurate entry of email addresses. The HIPAA Security Rule also requires reasonable and appropriate administrative, physical, and technical safeguards for electronic protected health information.
3. Email Mistakes That Damage Trust, Security, and Productivity
Recipient errors carry the highest immediate exposure. Autocomplete can select a former employee, similarly named patient, unrelated provider, or outdated vendor contact. Reply All can expose internal discussions or recipient addresses. CC can distribute information beyond operational need. BCC can conceal addresses for approved mass communication, though it requires careful use because replies and forwards may still create confusion. These risks should be managed through patient privacy communication, healthcare portal controls, EMR compliance training, and legal responsibilities.
Attachment errors often result from similar filenames, open folders, downloaded copies, or outdated versions. “Scan.pdf” and “Document (4).pdf” provide little assurance that the correct file has been selected. Open every attachment from the composed message, verify its patient or project, confirm the version, and remove unnecessary pages. Connect this step with medical chart auditing, medical records release tools, clinical documentation improvement, and medical coding accuracy.
Tone errors escalate routine problems. “You failed to send the order again” assigns blame and invites defensiveness. “The signed order was absent from the documents received at 10:15 a.m.” records the operational fact. Objective language protects relationships and creates a cleaner record when the email later supports patient complaint handling, difficult conversations, de-escalation procedures, or risk-management review.
Urgency abuse trains recipients to ignore the sender. Words such as “urgent,” “immediately,” and “ASAP” should be reserved for situations with a genuine operational deadline. State the exact time and impact so the recipient can evaluate priority. An authorization needed before tomorrow’s procedure carries a different consequence from a meeting agenda requested for next month. Effective urgency supports emergency appointment management, medical-office triage, scheduling conflict management, and daily office checklists.
Thread contamination occurs when a conversation about one patient, vendor, claim, or project changes subjects while retaining the old participants and subject line. A new topic deserves a new thread when the recipient group, privacy level, or required action changes. Long threads should be summarized before a new decision-maker is added. This practice helps employees using healthcare CRM tools, practice management systems, medical admin collaboration tools, and medical admin time trackers.
Phishing compliance failures happen when urgency defeats verification. Common pressure tactics involve invoices, password resets, account suspension, executive requests, payroll changes, document-sharing alerts, and unexpected attachments. CISA advises employees to report suspected phishing and follow organizational response procedures; NIST describes phishing as deceptive solicitation designed to obtain sensitive data or trigger harmful actions.
Verify unusual financial, credential, or disclosure requests through a known telephone number or approved system. Avoid replying to the suspicious message for confirmation because the attacker may control that channel. Employees working with medical office inventory, credentialing records, insurance claims, and patient communication platforms should receive scenario-based phishing training tied to their actual responsibilities.
4. Professional Email Examples for Administrative Assistants
Professional email judgment becomes easier when assistants can compare weak wording with a message that clearly assigns responsibility, protects information, and moves the task forward. The examples below cover common situations involving appointment scheduling, insurance verification, patient privacy communication, medical records management, and medical administrative workflows.
Example 1: Requesting a Missing Authorization
Weak version
Subject: Urgent
Hi,
We still do not have the authorization, and the appointment is tomorrow. Can someone please check this as soon as possible?
Thanks.
This message creates pressure without identifying the patient account, procedure, authorization number, response deadline, or consequence. The recipient must search other systems before understanding the request, which increases delays across prior authorization workflows, CPT code verification, secure scheduling processes, and insurance claims management.
Professional version
Subject: Authorization Confirmation Needed by 2:00 p.m. — MRI Appointment 58421
Hello Ms. Chen,
The MRI scheduled for tomorrow remains financially unconfirmed because authorization 88402 does not appear in the payer portal.
Please confirm whether the authorization has been approved or advise whether the appointment should be rescheduled by 2:00 p.m. today. This deadline will allow the scheduling team to contact the patient before the office closes.
Thank you,
Avery Smith
The revised email identifies the blocked task, provides the relevant numbers, requests a specific decision, and explains why the deadline exists. The recipient can act immediately without reviewing a long thread.
Example 2: Requesting a Missing Signature
Weak version
Subject: You forgot the form again
This is the second time you have sent the form without signing it. We cannot keep chasing these documents.
The message assigns blame, exaggerates frustration, and fails to state when the corrected document is required. Accusatory wording can damage collaboration and create an unhelpful written record during medical chart audits, clinical documentation improvement, patient complaint reviews, or risk-management investigations.
Professional version
Subject: Provider Signature Required — Surgical Clearance Form 47018
Hello Dr. Adams,
The surgical clearance form received at 10:15 a.m. contains the required clinical information. The provider-signature field remains blank.
Please return the signed form by 3:00 p.m. so it can be delivered to the surgical facility before today’s submission cutoff. I have attached the form again for convenient review.
Thank you,
Morgan Lee
This version documents observable facts, identifies the missing element, and gives the recipient an easy completion path. It also avoids language that assumes carelessness or intent.
Example 3: Communicating a Schedule Change
Weak version
Subject: Schedule
The doctor changed the schedule again. Please move everyone and let them know. Hopefully, this is the last time.
The wording contains emotional commentary while omitting the date, affected appointments, available alternatives, documentation requirements, and escalation route. Those omissions create inconsistent decisions across appointment conflict management, emergency appointment procedures, staff scheduling tools, and front-desk operations.
Professional version
Subject: Schedule Revision Required — Dr. Patel — September 18
Hello Scheduling Team,
Dr. Patel will be unavailable from 1:00 p.m. to 4:00 p.m. on September 18.
Please move the six affected appointments into the approved openings listed in the attached worksheet. Document every patient contact attempt in the scheduling system by 5:00 p.m. tomorrow.
Escalate patients who cannot accept the offered times to Maria Lopez for further review.
Thank you,
Jordan Reed
The revised email defines the affected period, number of appointments, approved action, documentation requirement, deadline, and escalation contact. Each team member can follow the same process.
Example 4: Escalating a Patient Billing Complaint
Weak version
Subject: Angry patient
A patient is furious about billing and says nobody helps her. Please deal with this because she keeps calling.
Labels such as “angry” and “difficult” provide limited operational value. The billing team needs the disputed amount, payment history, contact attempts, patient request, and expected response time. Accurate escalation supports revenue cycle management, denials management, Explanation of Benefits interpretation, active listening, and de-escalation techniques.
Professional version
Subject: Billing Complaint Requiring Review — Account 73120
Hello Billing Supervisor,
The patient called at 9:10 a.m. and 11:35 a.m. regarding a $240 balance that she believes was previously paid.
The account shows a payment posted on July 8 and an adjustment entered on July 10. The patient requested a written explanation before submitting another payment.
Please review the payment allocation and advise the appropriate response by tomorrow at noon. I informed the patient that the billing team would contact her after completing the review.
Thank you,
Taylor Brooks
This message gives the supervisor a documented timeline, identifies the disputed amount, states what the patient wants, and confirms what the patient has already been told.
Example 5: Following Up With a Manager
Weak version
Subject: Following up again
I am just following up on my previous emails. Please let me know.
The message forces the manager to search the inbox for context and fails to define the decision. Effective follow-ups should reduce work for the recipient while protecting deadlines across medical-office policy development, daily office procedures, administrative time management, and medical-office organization.
Professional version
Subject: Decision Pending — Revised Intake Procedure — Response Needed Friday
Hello Ms. Green,
I am following up on the revised intake procedure sent Monday.
Approval remains pending for the following controls:
Two-identifier verification during telephone check-in
Documentation of patient portal proxy access
Escalation of incomplete consent forms
Please approve the draft or return revisions by Friday at noon so staff training can begin next week.
Thank you,
Casey Hall
This follow-up restates the original request, identifies every unresolved decision, and connects the response deadline to the next operational step.
Example 6: Responding to a Suspicious Vendor Email
Weak version
Subject: Vendor banking change
I received the new banking details and will update the payment system today.
Changing financial information directly from an email can expose the organization to business email compromise. Familiar logos, existing email threads, executive names, and urgent deadlines provide weak proof of legitimacy. Employees handling medical-office inventory, healthcare collaboration tools, medical credentialing, and emerging administrative technologies need an independent verification process.
Professional version
Subject: Verification Required — Vendor Banking Change Request
Hello Finance Team,
An email received today requests a change to the vendor’s payment account. The message includes a new banking document and asks for completion before 1:00 p.m.
I have not opened the attachment or changed the vendor record. Please verify the request by calling the vendor through the telephone number stored in the approved vendor file. Please also advise whether the message requires security review.
Thank you,
Riley Morgan
The assistant preserves existing controls, avoids interacting with a potentially malicious attachment, and directs the verification through trusted contact information.
Across all six examples, the strongest messages provide context, objective facts, a defined action, an accountable recipient, a realistic deadline, and a clear operational consequence. That structure improves professional medical-office communication, protects patient confidentiality, strengthens medical compliance, and reduces avoidable follow-up work throughout the medical administrative workflow.
5. How to Build a Reliable Email System for Administrative Teams
Begin with email classification rules. Staff should know which messages belong in ordinary business email, secure messaging, the patient portal, the EMR, the incident-reporting system, or a verbal escalation. A general inbox should never become the unofficial storage location for clinical decisions, consent records, payment changes, or privacy incidents. Classification should align with electronic health record terminology, patient portal workflows, medical records management, and practice management systems.
Create approved templates with decision fields. Useful templates include authorization follow-ups, missing-document requests, schedule changes, patient complaint escalations, claim-status requests, vendor verification, meeting summaries, and absence notices. Each template should prompt the sender to enter the action, deadline, impact, responsible person, and reference number. Templates should support medical claims processing, scheduling software mastery, front-desk operations, and medical-office policy creation.
Templates need human review before sending. An outdated recipient, irrelevant sentence, wrong deadline, or retained patient information can turn a productivity tool into a disclosure risk. Employees should read the entire final message, including quoted history, signature, attachments, and auto-populated fields. This review reinforces EMR compliance training, medical chart auditing, patient privacy communication, and daily office checklists.
Establish response-time categories. For example, urgent operational messages may require acknowledgement within one hour, patient-facing administrative questions within one business day, and routine internal requests within two business days. Acknowledgement can state that the message has been received, identify the owner, and promise a realistic update time. This system helps time-management planning, emergency appointment management, virtual patient management, and patient satisfaction improvement.
Define CC and escalation rules. Employees should know when a manager needs awareness, when approval is required, and when a compliance, privacy, security, billing, or clinical specialist must take ownership. Copying senior staff should follow purpose and policy. A quiet problem-solving attempt may be appropriate for a routine omission, while a suspected privacy incident or fraudulent payment request requires immediate escalation. Connect these rules with medical compliance guidance, risk-management strategies, denials management, and patient complaint procedures.
Build phishing resistance into daily work. Staff should report suspicious messages, avoid opening unexpected files, inspect complete sender addresses, and verify sensitive requests through trusted contact information. CISA recommends a workplace culture in which employees can report phishing quickly, while NIST supports training programs that measure how difficult simulated phishing messages are to detect.
Security training should reflect actual administrative threats: fake portal alerts, altered invoices, fraudulent payroll forms, false credentialing requests, malicious document-sharing links, and executive impersonation. Tie simulations to medical credentialing, medical inventory management, healthcare collaboration tools, and emerging medical technologies so employees recognize attacks within familiar tasks.
Measure performance through operational evidence. Review wrong-recipient incidents, attachment corrections, unanswered requests, excessive Reply All use, recurring tone complaints, unresolved threads, phishing reports, and email-caused scheduling or billing delays. Use findings to improve medical-office organization, medical admin time tracking, staff scheduling tools, and professional administrative training.
6. Frequently Asked Questions About Professional Email Etiquette
-
Response expectations should follow the organization’s policy, message urgency, and operational consequence. A brief acknowledgement is useful when the complete answer requires research or approval. State who owns the issue and when the sender can expect an update. This practice supports time-management mastery, front-desk workflows, appointment management, and medical-office productivity.
-
Include the task, relevant identifier, and deadline when useful. “Signature Needed — Clearance Form 44820 — Due Wednesday” is more actionable than “Important.” Avoid unnecessary patient diagnoses or sensitive details in the subject line. Strong subject practices reinforce patient confidentiality, medical records management, medical compliance terms, and patient privacy communication.
-
Use CC when a person needs visibility because the decision affects their work, oversight, or responsibilities. Place a recipient in the To field when their action or decision is required. Avoid using CC as a threat, surprise escalation, or substitute for direct communication. Apply this distinction within medical-office collaboration, medical administrative workflows, staff scheduling, and risk-management processes.
-
BCC can protect recipient addresses during an approved external distribution, announcement, or newsletter. Internal conflict communication and hidden managerial escalation require a more transparent route. Distribution lists should be reviewed for purpose, current membership, privacy exposure, and marketing requirements. Commercial messages covered by CAN-SPAM must follow applicable header, subject-line, identification, address, and opt-out requirements.
Administrative teams should coordinate BCC use with healthcare CRM systems, patient communication apps, medical-office policies, and legal responsibility guidance.
-
HIPAA permits providers to communicate electronically with patients and other providers when applicable requirements and reasonable safeguards are followed. Staff should verify the address, purpose, recipient, attachment, privacy level, and approved method before sending. The organization’s policy may require secure email or portal delivery for particular information.
Relevant procedures include patient privacy communication, patient portal management, medical records release, and HIPAA compliance for scribes.
-
Report the event immediately through the approved privacy or security process. Preserve the message, recipient, attachment, time, and other relevant facts. Follow authorized mitigation instructions and avoid deciding independently that the content was harmless. The organization must assess the circumstances under applicable policy and law. This process should connect patient confidentiality, medical compliance procedures, risk management, and medical-office policies.

