What NABH actually requires from your software, clause by clause
When NABH is three months away, most hospitals do the same thing: scramble for files, stitch together screenshots, and hope the assessor accepts a pile of registers as proof. The work is not the problem. Producing the evidence is. Every gap review says the same thing in different words — your software does not speak NABH.
Why this happens, even in well-run hospitals
Hospital systems were built to transact, not to prove. They can post a charge, register a patient, and print a discharge summary. They are weaker at what NABH actually tests: whether your processes run reliably, leave a trace, escalate when they should, and generate auditable evidence without a manual spreadsheet.
That divide shows up in four places during accreditation:
- Corrective and preventive action (CAPA) exists in meetings, not in a trackable workflow with owners, due dates and closure proof.
- Risk registers are on paper or shared drives, not live lists with status, mitigation and review history.
- HAI surveillance and antimicrobial stewardship are partly in LIS/Pharmacy, partly in WhatsApp, and rarely end-to-end traceable.
- Data-sharing and consent are handled as policy notes, not enforced in the software that actually moves patient data.
Clause by clause: what assessors actually look for in your systems
This is the software surface that supports what NABH asks hospitals to demonstrate. It is not more documents. It is evidence baked into daily work.
- CAPA: each nonconformance logged, assigned, investigated, acted on, and closed — with time stamps and an auditable trail.
- Risk management: a live register with identified risks, severity, mitigation, ownership, review cadence and status changes over time.
- HAI surveillance: definable indicators, case capture, investigation, trend analysis, and meeting notes tied to actions.
- Antimicrobial stewardship: restricted formulary, approval trails, indications, de-escalation reviews and periodic stewardship reports tied to orders and administrations.
- Data sharing and consent: a system-level check that data is shared or exposed only when a valid consent exists, and that access decisions are recorded.
- Traceability and audit: version history on important records, the ability to undo/roll back/compensate, and replay of automated actions for post-incident review.
What changes at audit time is not your hospital. What changes is whether your system can show the trail.
What you can do now, without buying anything
- Map every NABH indicator you report to a specific system field or event. If a value comes from a spreadsheet, mark it amber; if manual collation is needed, mark it red. Your red list is your action plan.
- Define CAPA, risk and AMS as workflows, not meetings. For each, name who logs, who approves, who closes, and where the evidence lives. If the answer is "in a folder", decide the system-of-record and push the capture there.
- Enforce consent at the gate. Make it impossible to export, share or integrate patient data without a consent record. If your current system cannot enforce it, create a pre-share checklist and a register of all outbound data until you fix the enforcement.
- Standardise HAI definitions. Publish one sheet of case definitions and indicators, and configure LIS/EMR forms to capture exactly those fields. If configuration is not possible, attach a mandatory data-collection checklist to the relevant orders.
- Run a monthly evidence drill. Pick one NABH clause (e.g., medication use or infection control), and ask for the evidence trail end-to-end without involving the person who created it. Where you hit a dead end, fix the capture point.
Where Ospia fits
Ospia HOS is an AI-native Hospital Operating System. It approaches accreditation evidence as a by-product of daily work, not a parallel exercise. We designed it so the following are part of the platform contract, not side projects.
- CAPA, a live risk register, HAI surveillance and antimicrobial stewardship: Ospia’s position is that these generate NABH evidence as a by-product when run inside the system, instead of being reconstructed for audit.
- NABH indicator packs, ABDM/ABHA and DPDP: these are in Ospia’s supported compliance surface, so data structures and flows align with Indian regulatory expectations from day one.
- Consent-aware interoperability: the Interop module exposes a FHIR R4 read surface for key resources and ships HL7 v2 ADT feeds, both gated behind a DPDP consent check.
- Reversibility and replay: Ospia’s position is that important records carry version history and recovery, every workflow supports undo/rollback/compensation, and every AI action is explainable and replayable months later for audit.
- Governed automation: above autonomy level L2, execution requires a named human; at L4, it requires a hospital-approved policy. That means automation operates within your governance and can be defended at assessment.
We are early. We are onboarding design partners and we do not publish customer counts. Our aim is clear: make compliance evidence the exhaust of normal operations, not a parallel cottage industry that spikes before audits and vanishes after.
How to read your next software demo through a NABH lens
- Ask to see a nonconformance go from incident to closed CAPA, with the full trail. Then ask to reverse a step and show the compensating action in the record.
- Open the risk register, change a risk’s severity, and show who is notified, how review dates shift, and where the version history is visible.
- Trigger an HAI alert. Follow it from case detection to action taken, and then to the indicator dashboard. Ask where the definitions live and how they are changed.
- Order a restricted antimicrobial. Watch the approval trail, the indication capture, and where stewardship review is recorded.
- Attempt to expose patient data via API or export without consent. Watch the system enforce the check and log the decision.
If your current system cannot demonstrate these flows quickly, you will carry the evidence burden on people and spreadsheets. That is expensive, brittle and risky.
Next step
If this is the gap you are trying to close, see an executive demonstration of Ospia HOS. We will walk through CAPA, risk, HAI and AMS the way an assessor would, and show how consent-aware interoperability and reversibility turn operations into audit-ready evidence.
Primary sources
This resource is grounded in the following official standards, laws and regulator guidance. Links were checked on 22 August 2026.