Healthcare-provider compliance in China begins with the institution's legal form, licence or filing, approved address, departments, beds and service scope, then extends to each clinician's qualifications and the governance of actual clinical activity. The first task is to compare what the provider is authorized to do with what its staff, technology, online channels and contractors are doing in practice.
Preserve licences, personnel credentials, policies, quality and infection-control records, patient consents, original medical records, adverse-event and complaint files, advertising approvals, data-access logs and every inspection document. Do not alter a chart, backdate consent, continue an unauthorized service or suppress a report while investigating. This guide addresses provider compliance, not the merits of an individual medical-injury claim.
Subject to editorial and legal review. Obtain institution- and event-specific advice where patient safety is at risk, an authority has imposed a deadline, records may be sealed, or professional, civil or criminal exposure overlaps.
Map the institution and licence scope
Identify the operator, institution category, ownership and investment structure, medical-institution practice licence or clinic filing, approved name and address, departments, beds, diagnosis and treatment subjects, technical services and responsible persons. Some clinics use filing rather than traditional approval, but filing does not remove substantive standards. New sites, relocation, added departments, telemedicine or outsourced services require a fresh scope analysis.
Credential every person and activity
Maintain current records for physicians, nurses, pharmacists, technicians and other health personnel, including registration, practice location and scope, privileges, training and periodic assessment. Confirm the rules for multi-site practice, foreign or Hong Kong, Macao and Taiwan practitioners, trainees and remote consultation. Institutional permission cannot expand a professional's statutory scope, and a personal credential does not authorize an unlicensed facility.
Clinical governance and core quality systems
The institution's principal responsible person is the first person responsible for medical quality. Implement the core systems covering first diagnosis, ward rounds, consultation, graded nursing, duty and handover, difficult-case and death-case discussion, emergency rescue, preoperative discussion, identity and procedure checks, surgery safety, technology access, critical values, records, antimicrobial management, blood use and information security. Use audits, incident learning and corrective action to test actual performance rather than policy existence alone.
Technology, medicines and infection controls
Clinical technologies must match institutional capability and comply with access, restriction, ethics and safety requirements. New or high-risk technology requires appropriate assessment and preparation. Maintain pharmacy, controlled-drug, device, sterilization, blood, antimicrobial-stewardship and hospital-infection controls. Investigate clusters and report infections or other events through the required channel without confusing quality review with disciplinary blame.
Patient information and informed consent
Explain the condition and proposed medical measures as required. For surgery, special examination or special treatment, explain risks, alternatives and other required matters and obtain consent from the patient or an authorized person under the applicable rule. Emergency treatment follows its own authorization route. Consent is a process, not only a signature: record the information, questions, capacity, representative authority, interpreter needs and timing.
Medical records, access and preservation
Records must be objective, truthful, accurate, timely, complete and standardized. Emergency entries not made during rescue must be supplemented truthfully within the permitted period and marked accordingly. Patients have rights to inspect and copy the defined record set. Where a dispute arises, follow joint sealing and inventory procedures for records and relevant physical items; never conceal, destroy, seize or falsify materials. Maintain access controls, correction history, retention and backup for electronic systems.
Privacy, cybersecurity and data use
Health information is sensitive personal information. Map collection, clinical access, billing, insurance, research, teaching, cloud hosting, vendor support, telemedicine and cross-border access. Apply the Personal Information Protection Law, Cybersecurity Law, Data Security Law and healthcare rules to legal basis, necessity, notice or consent, access, retention, incidents and transfers. De-identification for secondary use must be technically and operationally effective.
Advertising and digital channels
A medical institution must obtain medical-advertising review before publishing a medical advertisement; non-medical institutions and internal departments cannot advertise medical services in their own right. Approved content is limited and must remain consistent with the institution's licence and review certificate. Audit websites, social media, livestreams, influencers, patient stories, rankings and consultation funnels for direct or indirect advertising and prohibited endorsements or outcome claims.
Complaints, incidents and inspections
Maintain a visible complaint route, investigate promptly, communicate truthfully and inform patients of lawful dispute-resolution routes. Serious incidents may require health-authority, drug/device, infectious-disease, cyber or public-security reporting. During inspection, record authority, scope, copies, interviews, sampling, findings and deadlines; preserve privilege questions and factual accuracy without obstructing officials. Coordinate patient safety, corrective action and legal response.
Working-file checklist
- Institution licence or filing and approved service scope.
- Personnel registrations, privileges and training.
- Quality core systems, audits and CAPA evidence.
- Technology, pharmacy, infection and blood controls.
- Consent forms, patient communications and interpreters.
- Original medical records, copies, seals and audit logs.
- Privacy, cybersecurity, vendor and transfer records.
- Advertising review, complaints, incidents and inspection notices.
Official sources
- Basic Healthcare and Health Promotion Law
- Medical Institution Administration Regulations
- Medical Quality Management Measures
- Medical Dispute Prevention and Handling Regulations
- Medical Advertising Measures
Law checked: September 11, 2026. Official Chinese texts control. Confirm provider type, licence scope, personnel credentials and the clinical or regulatory event before acting.


