Compliance · 33 min read

Screening in regulated industries

A regulated employer's screening duty is not really an industry fact. It is one of a small number of mechanisms, and the mechanism decides what you owe.

The short version

  • Regulators do one of six things, and each produces a different duty: bar the employment, name the list and the window, state a standard and delegate the criteria, control access to a thing, bar the payment, or issue a credential somebody else checked.
  • The regimes with a hard requirement are the ones that named a list and a window. Where a regulator says only "screen them," the criteria are yours and the compliance work is documenting what you chose.
  • A bar is not a check. Where Congress forbade the employment, no policy, no individualized assessment and no vendor can soften it, and a conditional offer is the only structure that works.
  • Three claims an employer is most likely to have been sold are wrong. ITAR mandates no background check. The Bank Secrecy Act mandates no employee screening. CMMC Level 1 has no personnel security requirement.
  • An exclusion list bars the billing, not the employment. Treating the OIG list or SAM as a hiring bar means refusing candidates you were free to hire, and creating a disparate impact claim out of a compliance measure.

Six things a regulator can do, and only one of them is "run a background check"

Search for what a hospital, a broker-dealer or a defense contractor has to check, and the answers arrive as a list of industries. That shape is a listicle, and a listicle cannot answer the question the reader actually has, which is what a rule requires of them. Every regime in this area does one of six things, and the six produce different duties, different records and different failure modes.

The six mechanisms

A bar forbids the employment outright, and names no check.A named list and a named window specifies which offenses and how far back, which is the only form in which a regulator actually specifies a check. A delegated standard requires that you screen and leaves the criteria to you. An access controlgoverns who may see something, and says nothing about who you may employ.A billing bar permits the employment and forbids the payment. A credential is a check performed by a licensing body, which you verify rather than repeat.

The distinction is not academic. A bar and a delegated standard both end in a candidate being rejected, and they get there by different routes with different documentation. An employer that runs a careful individualized assessment against a statutory bar has done nothing, because the bar does not turn on judgment. An employer that applies a hard bar where the regulator delegated the standard has skipped the only step that was required of it.

The bar: where Congress removed the discretion

The cleanest example in federal law is banking. Section 19 of the Federal Deposit Insurance Act, at 12 U.S.C. § 1829(a)(1), provides that except with the prior written consent of the FDIC:

any person who has been convicted of any criminal offense involving dishonesty or a breach of trust or money laundering, or has agreed to enter into a pretrial diversion or similar program in connection with a prosecution for such offense, may not become, or continue as, an institution-affiliated party with respect to any insured depository institution.

Read what that does and does not say. It does not require the bank to run a background check. It forbids the employment, and then leaves the bank to work out how it will know. The FDIC's implementing rule puts the duty this way at 12 CFR § 303.220(b): insured depository institutions "must therefore make a reasonable, documented inquiry to verify an applicant's history to ensure that a person who has a Covered Offense under section 19 is not hired or permitted to participate in its affairs without the written consent of the FDIC."

Three things follow, and they are the reason this is the first mechanism rather than the third. The duty is an inquiry and it has to be documented, which means the record of what you did is part of the obligation rather than evidence about it. There is no adjudication, because there is nothing to adjudicate: the offense either is or is not on the list. And a conditional offer is expressly contemplated, because the rule says an institution may extend one "contingent on the completion of a background check satisfactory to the institution," provided the applicant does not work for or participate in the affairs of the institution until the determination is made.

The list is narrower than employers assume and the window is shorter than the folklore. A conviction with a pending appeal requires an application. A pardon requires one too, which surprises people who assume a pardon clears everything. Arrests, acquittals and reversed convictions do not count, and neither do expunged, sealed or dismissed convictions. The de minimis exemptions at 12 CFR § 303.227 turn on thresholds that were reset by the Fair Hiring in Banking Act, and the current figures are three years' confinement and $3,500, with $1,225 for simple theft and $2,000 in aggregate for insufficient funds checks. The one year and $2,500 still widely quoted is the pre-amendment version.

The ten-year figure is the most misunderstood part. There is no permanent ban anywhere in Section 19. Ten years is the period during which the FDICmay not consent to an application for the enumerated Title 18 offenses, after which the ordinary consent route is available again. The reason it reads as permanent is that the older-offense exclusions, which waive Section 19 for an offense seven years old, or five years after release from incarceration, or thirty months after sentencing for an offense committed at twenty-one or younger, do not apply to those same enumerated offenses. Nothing is forever. Some things are simply ten years long with no shortcut.

Credit unions run the same structure under Section 205(d) of the Federal Credit Union Act, 12 U.S.C. § 1785(d), and the implementing rule at 12 CFR Part 752. The two are close enough that they are usually described as identical, and they are not quite. The credit union provision reaches a conviction involving dishonesty or breach of trust and stops there. The bank provision adds money laundering.

The mortgage industry has its own bar, and it is a narrower one. A state-licensed loan originator must never have been convicted of, or pled guilty or nolo contendere to, a felony, during the seven years before the application, or at any time at all if the felony involved fraud, dishonesty, a breach of trust or money laundering. Read the second half of that again, because it is the shape a great many licensing bars take: a recent window for ordinary felonies, and no window at all for the offenses that bear directly on the licensed activity.

Insurance has the sharpest version of the mechanism, because there the employer carries the exposure directly. Under 18 U.S.C. § 1033(e)(1)(A), an individual "who has been convicted of any criminal felony involving dishonesty or a breach of trust, or who has been convicted of an offense under this section, and who willfully engages in the business of insurance whose activities affect interstate commerce or participates in such business, shall be fined as provided in this title or imprisoned not more than 5 years, or both." Subparagraph (B) then reaches the employer, making it a crime for a person engaged in the business of insurance to "willfully permit the participation described in subparagraph (A)." There is no lookback and no list. The prohibition attaches to the fact of conviction and does not expire.

The only route back is at (e)(2), which allows the person to engage in the business if they "have the written consent of any insurance regulatory official authorized to regulate the insurer, which consent specifically refers to this subsection." That is the 1033 waiver the industry refers to, and it explains why insurance screening is organized around obtaining a document rather than making a decision. The employer is not adjudicating anything. It is establishing whether a waiver exists, because without one the hire is a federal offense committed by both parties.

The named list: the only form in which a regulator specifies a check

Where a regulator genuinely specifies a check, it does so by naming the offenses and naming the window. Those are the regimes with something to follow, and they are worth understanding as a family, because the numbers differ in ways that are easy to swap.

The FBI's Criminal Justice Information Services Security Policy, at control PS-3 in the current version, requires a state of residency and national fingerprint-based record check before a person is granted access to criminal justice information. Two corrections matter here and both are common. The policy is a versioned FBI document rather than a regulation, so it does not appear in the CFR, and the policy version most often cited in vendor material, 5.9.3, is a date-stamped version number rather than a section. In the 5.x line, personnel screening was Policy Area 12 at § 5.12.1. In the current 6.x line it is PS-3. The other correction is that the widely repeated deadline and repeat interval are neither. The requirement is pre-access rather than within thirty days, and the five-year reinvestigation was already only a recommendation, and remains one.

The Transportation Worker Identification Credential is a TSA security threat assessment rather than a simple record check, and its disqualifying provisions are two independent triggers rather than one window. An offense on the interim list disqualifies if the applicant was convicted within seven years of the application, or if the applicant was incarcerated for it and released within five years. Those run from different events with different numbers, and collapsing them into a single seven-year rule, which is what most summaries do, gets the second one wrong. A separate permanent list has no lookback at all, and a TWIC expires five years after it is issued.

Aviation runs the opposite way, which is why the two are so often confused. An airport operator must ensure that no individual is granted unescorted access authority unless a fingerprint-based criminal history records check discloses no disqualifying offense, and the window is ten years. There is no permanent disqualification category anywhere in the aviation parts. So the maritime credential has a seven and a five and a permanent list, and the aviation badge has a ten and no permanent list, and a vendor page that gives you one number for both has not read either.

The electric grid has the tightest version of the pattern because it names both numbers explicitly and they are easy to keep separate. The NERC reliability standard for personnel risk assessment, CIP-004-7, requires a documented program that includes a seven-year criminal history records check covering the subject's current residence and any other location where they resided for six consecutive months or more during the seven years before the check, and separately requires that individuals with authorized access have had an assessment completed within the last seven years. One seven is a lookback. The other is a validity period. Both are in the same standard and they mean different things.

Two traps in this family are worth naming because they recur across regimes. The first is the employment history element that does not exist. NERC's standard has no employment history requirement in any current version, and the aviation rule still contains a cross-reference instructing airport operators to subject individuals to an employment history verification that the referenced section no longer describes. TSA confirmed the language was obsolete in a technical amendment published in January 2025. The second trap is the version number that reads like a section number, which is the CJIS citation above and is worth checking every time a vendor page cites a standard with a decimal in it.

The delegated standard: where the criteria are yours

A regulator that does not want to write a list writes a requirement to have a process instead. The obligation is real and the content is left to the employer, which changes the compliance work from following instructions to documenting choices.

The clearest example is the defense industrial base. NIST SP 800-171, the publication that DFARS 252.204-7012 imports by reference, states the personnel security requirement at 3.9.1 in a single sentence: screen individuals prior to authorizing access to organizational systems containing controlled unclassified information. The accompanying discussion then explains that the screening activities reflect the applicable federal laws, executive orders, directives, policies, regulations and the specific criteria established for the level of access required for assigned positions. That is a standard that names no check, no database, no lookback and no adjudication threshold. It requires the contractor to have a position on all four.

CMMC sits on top of that, and the level structure is where most of the confusion lives. Level 1 is fifteen requirements drawn from the FAR, all of them access and technical controls, and it contains no personnel security requirement whatsoever. Level 2 is the 110 requirements of SP 800-171 Revision 2, which brings 3.9.1 with it. Level 3 adds selected requirements from SP 800-172, including one that requires systems to be protected when adverse information develops about an individual with access. So a small contractor at Level 1 has no screening obligation under CMMC at all, and a contractor at Level 2 has an obligation to have designed its own screening criteria. The one place CMMC does mandate a background investigation is its assessor ecosystem, where the requirement falls on the people who conduct assessments rather than on a contractor's workforce. That is worth stating plainly, because it is the sentence that gets lifted out of context.

The Drug Enforcement Administration is the honest limit case. The employee screening provisions at 21 CFR §§ 1301.90 to 1301.93 do not require a background check on anyone. They state the agency's position, propose two questions that the agency assumes will become part of a comprehensive program, and recommend where to make inquiries. The operative verbs are "it is the position of DEA," "it is assumed" and "DEA recommends." The provisions have not been amended since 1975. What they actually impose on a registrant is a policy and a statement of it, and what they suggest is a five-year felony window rather than the seven years frequently claimed. A registrant that reads these as a mandate will over-check, and one that reads them as nothing will miss the only enforceable part, which is having the policy and telling employees about it.

The access control: a rule about a thing, not a person

This is the mechanism that generates the most confident wrong claims, because the rule is real, it is serious, and it is genuinely about protecting something valuable. It simply does not require a background check.

The International Traffic in Arms Regulations control the export of defense articles and technical data. The operative concept is release. Technical data is released to a foreign person when that person can access it, whether by inspection, by oral or written exchange, or by using access information, and release to a foreign person requires an authorization. A U.S. person, as defined at 22 CFR § 120.62, needs no authorization to see it. So the employer's obligation is a control on access rather than a check on people, and the compliance question is who can reach the data rather than what a record says.

Searched end to end, Parts 120 through 130 of Title 22 contain no background check mandate. The phrases "background check," "criminal history," "personnel screening" and "employee screening" do not appear in any of the eleven parts. The only screening language in the entire regime is at 22 CFR § 126.18(c)(2), and it does three things that make it useless as an employer-screening authority: it is a condition of an exemption rather than a general requirement, it is imposed on a foreign end-user or consignee rather than on a U.S. employer, and it is one of two alternatives, the other being a host-nation security clearance. What it asks a foreign entity to do, if it takes that route, is screen its own employees for substantive contacts with restricted countries, and the regulation defines those contacts specifically: regular travel, continuing contact with agents or nationals, demonstrated allegiance, business relationships, a maintained residence, continuing compensation, or other acts indicating a risk of diversion.

None of which means a defense contractor has no personnel obligation. It means the obligation lives somewhere else, in the National Industrial Security Program, at 32 CFR Part 117, where access to classified information requires a need to know, a government eligibility determination adjudicated under the SEAD 4 national security adjudicative guidelines, and a signed non-disclosure agreement. That is a government investigation conducted by a government agency. A contractor's role is to submit fingerprints, verify citizenship from original documents, sponsor the application through the electronic questionnaire, and then operate a continuing reporting duty under 32 CFR § 117.8. The periodic reinvestigation cycle that employers still describe, five years for Top Secret and ten for Secret, has been replaced by continuous evaluation and continuous vetting under agency guidance. An article that tells a defense contractor that ITAR requires background checks has told them to spend money on the wrong control. The check they need is a clearance, and it is not theirs to run.

The billing bar: employment permitted, payment forbidden

An exclusion list is the mechanism most often mistaken for a hiring bar, and the mistake is expensive in both directions. The employer is not forbidden to employ the person. It is forbidden to be paid from a federal program for their work.

In healthcare the list is the Department of Health and Human Services Office of Inspector General's List of Excluded Individuals and Entities. What an exclusion actually does is set out at 42 CFR § 1001.1901(b)(1): unless and until the person is reinstated, "no payment will be made by Medicare, including Medicare Advantage and Prescription Drug Plans, Medicaid, or any other Federal health care program for any item or service furnished" by them. Paragraph (b)(4) then attaches the liability to the claim rather than to the employment, providing that a person who "submits, or causes to be submitted, claims for items or services furnished during the exclusion period is subject to civil money penalty liability under section 1128A(a)(1)(D) of the Act and criminal liability under section 1128B(a)(3)."

Nothing there prohibits the employment. The practical effect for a hospital or a nursing home is that an excluded person can hold a role that generates no federal billing and must be kept out of the roles that do, which is an operational question rather than a hiring one. Employers that read the list as an absolute bar refuse candidates they were entitled to hire, and a blanket rule applied at scale is a good way to generate a disparate impact question out of a compliance measure.

What drives the check, then, is a penalty hook rather than a mandate. The Civil Monetary Penalties Law at 42 U.S.C. § 1320a-7a(a)(6) reaches a provider that "arranges or contracts (by employment or otherwise)" with a person it "knows or should know is excluded," and the exposure runs to $10,000 for each item or service that person furnishes for which federal payment is sought, plus an assessment of up to three times the amount claimed. The standard is constructive knowledge, so the question is what the provider should have known rather than what it went looking for. The Office of Inspector General's own guidance is explicit that this is not a checking duty: "Providers are not required by statute or regulation to check the LEIE," and because there is no such requirement, "providers may decide how frequently to check the LEIE." It recommends a check at that cadence, on the reasoning that the list is refreshed monthly. A monthly screen is therefore the right answer to a cost of liability rather than to a rule, and a policy that describes it as a legal requirement is describing the wrong thing.

The federal procurement equivalent is SAM Exclusions, and its requirement structure is weaker than its reputation. The rule at 2 CFR § 180.300 requires a participant in a covered transaction to verify that the person they intend to do business with is not excluded or disqualified, and then offers three ways to do it: check SAM, collect a certification from the other party, or add a clause or condition to the transaction. Checking SAM is one of three, and for principals the same part says expressly that you are not required to. Where the check becomes effectively mandatory is narrower and it is a dollar threshold: a federal contractor is prohibited from awarding a subcontract in excess of $45,000, other than for a commercially available off-the-shelf item, to a party that has been debarred, suspended, proposed for debarment or voluntarily excluded. The clause mechanism is a disclosure duty rather than a checking duty, in that the contractor must require the prospective subcontractor to disclose its status in writing and must notify the contracting officer before awarding if the answer is that it is excluded.

Two details there are stale in most published versions. The current threshold is $45,000, and the clause carrying it was amended effective January 2025, so a page citing $30,000 or a 2021 clause date is working from an out-of-date text. And the renumbering of FAR Part 9 is a proposal published in September 2026 with comments still open, not an amendment in force, so Part 9 remains citable.

The credential: a check somebody else already ran

The last mechanism inverts the usual question. Instead of asking what to check, the employer asks what has already been checked, and the duty becomes verification of a credential rather than performance of a search.

Mortgage loan originators are the cleanest case. The S.A.F.E. Act requires an individual seeking a state license to submit fingerprints through the Nationwide Multistate Licensing System for a state and national criminal history background check, and to submit personal history and experience including authorization for the registry to obtain an independent credit report. Both sit at 12 CFR § 1008.105, in paragraphs (g) and (h). The employer does not repeat either one. It relies on the license, because the state evaluated the results and issued or withheld the credential on them.

Two corrections to the usual description. The credit report is a state-licensing requirement only: 12 CFR Part 1007 governs individuals registered through a federal agency rather than a state, and it contains no credit report element at all, so the common claim that the S.A.F.E. Act requires a credit check for mortgage loan originators is true of one population and false of the other. And the check is not annual, however annual the renewal is. The renewal rule requires the licensee to continue to meet the issuance standards, but fingerprints less than three years old may be reused, so an originator renewing in consecutive years is not re-fingerprinted each time. The employer that believes it must re-run the check annually is doing work the licensing body has already done.

The securities industry is a harder case to place, and it is worth being precise about why. A FINRA member firm has a duty under Rule 3110(e) to ascertain by investigation the good character, business reputation, qualifications and experience of an applicant before applying to register that person, and a separate duty to maintain written procedures reasonably designed to verify the accuracy and completeness of the registration form by a search of reasonably available public records, to be conducted no later than thirty calendar days after the form is filed. The rule permits that search to be done by the firm or by a third-party service provider, and it requires no consumer report. So the obligation is a regulatory one, the method is the firm's to choose, and the artifact is a filing rather than a report.

The published versions of this rule carry two errors that are worth naming. The five-year lookback usually attributed to Rule 3110(e) is not in the rule, which contains no lookback period; the five-year figure belongs to a different rule with a different trigger. And the sixty-day period usually attached to the investigation governs a different act, which is the review of the applicant's most recent termination form from a prior employer. The investigation itself happens before the firm applies to register. Where the industry claim does hold is at the hard end: a person subject to statutory disqualification under 15 U.S.C. § 78c(a)(39) cannot simply be hired, and the firm must obtain relief before the association begins if it wants to bring them on.

Healthcare: a statutory bar, a registry, and a check on the owners

Healthcare is where the mechanisms are most often mistaken for one another, because three separate rules sit on top of each other and only some of them are about hiring.

The hiring one is a bar, and it is federal. A nursing facility "must not employ or otherwise engage" anyone in three categories under 42 CFR § 483.12(a)(3): an individual who has "been found guilty of abuse, neglect, exploitation, misappropriation of property, or mistreatment by a court of law"; one who has "had a finding entered into the State nurse aide registry concerning abuse, neglect, exploitation, mistreatment of residents or misappropriation of their property"; or one who has "a disciplinary action in effect against his or her professional license by a state licensure body as a result of a finding of abuse, neglect, exploitation, mistreatment of residents or misappropriation of resident property."

Three things about that provision deserve attention. It bars a status rather than a conviction, so a registry finding or a license action disqualifies with no court involved. It carries no lookback period, because nothing in it expires; the bar lasts as long as the finding does. And it reaches past employment to anyone the facility "otherwise engage[s]," which takes in contractors and volunteers. The companion duty at § 483.12(a)(4) runs the other way, requiring the facility to report to the state nurse aide registry or licensing authorities any knowledge it has of a court action against an employee that would indicate unfitness. Screening here is two-way: the facility checks the registry and also feeds it.

The bar is not the only federal obligation in this setting, and the second one is affirmative. Before allowing anyone to serve as a nurse aide, a facility "must receive registry verification that the individual has met competency evaluation requirements" under 42 CFR § 483.35(d)(4), and must "seek information from every State registry" under (d)(5). Both are duties to inquire rather than duties to decide, and the second is deliberately plural. An aide who trained in another state has a record in that state's registry, and querying one state will not find it.

The registry that makes the second disqualifier work is a state system, and an aide entered in one state's registry does not automatically appear in another's. A facility operating across state lines cannot run a single national check and be done, which is a structural limit rather than a vendor shortcoming.

There is one provider type where federal law does require an employer-side criminal background check outright, and it is not the one most people name. The hospice conditions of participation carry a provision titled, verbatim, "Standard: Criminal background checks." Under 42 CFR § 418.114(d), "The hospice must obtain a criminal background check on all hospice employees who have direct patient contact or access to patient records," and hospice contracts must require the same of contracted entities for their contracted employees. Paragraph (2) sets the window: checks follow state requirements, and absent state requirements they must be obtained "within three months of the date of employment for all states that the individual has lived or worked in the past 3 years."

That provision repays a second reading, because it is the clearest federal employer-side screening mandate in healthcare and it is almost never cited. It names a population, which is employees with patient contact or patient-record access rather than the whole workforce. It names a window, which is three months rather than the first day. It reaches past employees to contracted staff. And it defers to state law first, so in a state with its own requirement the federal timing is not the one that governs. A hospice that runs a criminal check on its whole workforce is doing more than the rule asks, and one that checks nobody because it read the conditions of participation as silent is the case the provision exists for.

The federal check that surprises employers is a different one, and it is aimed at owners rather than staff. Medicare enrollment screening runs at three levels, and at the high level under 42 CFR § 424.518(c)(2)(ii) the contractor requires "the submission of a set of fingerprints for a national background check from all individuals who maintain a 5 percent or greater direct or indirect ownership interest in the provider or supplier," and runs a fingerprint-based criminal history record check on those individuals through the FBI's system. It is an enrollment integrity measure directed at who owns the entity. It is not a workforce check, and a provider that assumes its CMS screening obligation covers its staff has read the rule backwards.

The remaining two healthcare overlays are the ones already described here: the Office of Inspector General exclusion list, which bars the billing rather than the employment, and HIPAA, which requires a workforce clearance procedure and names no criteria. A hospital's screening program in practice is a state licensure check, a registry check, a federal exclusion check and its own delegated policy, and only the first two of those are about the person.

A rule that specifies everything except a criminal check

Motor carrier hiring shows how far a regime can go in specifying a check without ever requiring the one employers assume. A carrier's federal screening duty sits at 49 CFR § 391.23, and the section is unusually specific. The carrier must obtain a motor vehicle record from every licensing authority that issued the driver a license or permit in the preceding three years, an investigation of the driver's safety performance history with Department of Transportation regulated employers over the preceding three years, and the driver's drug and alcohol violation history for the same period. It must verify the medical examiner's certificate and confirm the examiner was on the National Registry before the driver operates a commercial motor vehicle at all. It must keep the investigation records in a separately secured file with controlled access, at 49 CFR § 391.53.

What Part 391 does not require is a criminal records check. Not at § 391.23 and not anywhere else in the part. Criminal history enters motor carrier hiring through state law, through the hazardous materials endorsement in Part 1572, through insurer requirements and through the carrier's own policy, and the federal motor carrier rules expressly permit a carrier to impose requirements stricter than the federal ones. The prominence of the criminal check in trucking is a market fact rather than a regulatory one, and a carrier that describes it as a Department of Transportation requirement has both the obligation and its source wrong.

The ten-year figure that circulates here is a real number attached to the wrong thing. The employment application at 49 CFR § 391.21 requires three years of employer history generally, plus a further seven years of employers for which the applicant actually operated a commercial motor vehicle, which adds to ten years on the form. The investigation duty stays at three. A carrier that investigates ten years has exceeded the rule, and one that tells a driver the law requires it has misstated the law.

Two adjacent products are worth separating from a background check, because both are sold as one. The Drug and Alcohol Clearinghouse, which must be queried before employment under 49 CFR § 382.701(a), returns drug and alcohol program violations and nothing else, and the regulation caps what it discloses. It is not a criminal records check. And the Pre-employment Screening Program is voluntary as a matter of statute: 49 U.S.C. § 31150(c) provides that "use of the process shall not be mandatory and may only be used during the preemployment assessment of an operator-applicant," with the applicant's written consent required and the released information expressly subject to the Fair Credit Reporting Act. A carrier using it has opted into a convenience, and the consent and the FCRA duties that come with it are why the product is shaped the way it is.

What is not a requirement, and is sold as one

Three claims belong on their own, because each describes a real regime and then attributes to it a screening duty that the regime does not contain.

The Bank Secrecy Act requires an anti-money-laundering program with internal controls, independent testing, a designated compliance officer and ongoing training. It does not require employee background checks, at banks, at broker-dealers or anywhere else. The employee-facing duties in the regime run to training and oversight. Where a financial institution does screen, at the institution's own choice, the source of the duty is Section 19 or Section 205(d) rather than the Bank Secrecy Act.

The Health Insurance Portability and Accountability Act protects health information and says nothing about the criminal history of the workforce handling it. What it requires sits at 45 CFR § 164.308(a)(3)(i), a workforce security standard directing a covered entity to implement policies and procedures ensuring that workforce members "have appropriate access to electronic protected health information" and preventing those who do not have access from obtaining it. The specification that implements it is (a)(3)(ii)(B): "Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate."

Read what that does not say. It names no database, no offense and no window. It requires a procedure and leaves the criteria to the covered entity. It is also marked Addressable, which is the most misread word in HIPAA. Addressable does not mean optional: under 45 CFR § 164.306(d)(3) the entity must assess whether the specification is reasonable and appropriate, implement it if it is, and if it is not, document why and implement an equivalent alternative measure. An employer that describes its screening program as a HIPAA requirement has described the right control and attributed it to the wrong kind of source. This is a delegated standard, and the compliance artifact is the documented decision.

A SOC 2 report is not a regulation and not a government requirement. It is an attestation against the AICPA trust services criteria, produced by an independent auditor, and personnel screening appears in it as one control among many rather than as its subject. Enterprise buyers frequently require one of a vendor, and that commercial pressure is real. It is a contract term rather than a legal duty, which matters because a contract term can be negotiated and a statute cannot.

The FCRA does not stop applying because a regulator is involved

Everything above is the regulatory layer. Underneath it the Fair Credit Reporting Act still governs any report a consumer reporting agency furnishes about a consumer for an employment purpose, and a regulated employer is not exempt from it because it also has a regulator.

One provision is worth naming here rather than leaving to the general articles, because it applies precisely to the records this kind of screening collects. Where a consumer reporting agency furnishing a report for employment purposes compiles and reports items of public record that are likely to have an adverse effect on the consumer's ability to obtain employment, 15 U.S.C. § 1681k requires one of two things: notify the consumer at the time the information is reported, together with the name and address of the person to whom it is being reported, or maintain strict procedures designed to ensure that the public record information reported is complete and up to date. The statute treats arrests, indictments, convictions, suits, tax liens and outstanding judgments as up to date if the current public record status of the item at the time of the report is reported.

That provision is why a regulated employer's screening file looks the way it does. A county court record pulled for a healthcare or financial role is exactly the kind of item the section describes, and the difference between the two compliance routes is whether the agency notified the consumer or built procedures that keep the record current. Asking which route a vendor uses is a reasonable question, and it has an answer.

What we do

We furnish reports into regulated workforces, and where a regulator has named a list and a window we scope the search to it. That last point is not a formality: a check broader than the standard requires produces records the employer cannot use, and in a bar regime a broader check is not more compliance, it is a different and larger problem.

Where the standard is delegated, which is the defense industrial base and much of healthcare, we will tell you that the criteria are yours to set and we will document what you set. That documentation is the compliance artifact in those regimes, since there is no list to follow and the regulator's question is whether you had a defensible process.

Where a credential already covers the check, we will say so. Re-running a fingerprint check that the state licensing body has already run and adjudicated adds cost and adds no information, and a screening program that can identify those cases is cheaper and easier to defend.

If your current program was built from an industry listicle, the three questions worth asking are which of the six mechanisms applies to each role, whether any of your checks are broader than a named list requires, and whether any of your rejections came from an exclusion list that bars billing rather than employment. The first two are usually quick. The third is the one that has a candidate on the other side of it.

Sources

Last reviewed 2026-09-27. Nothing here is legal advice; see the terms of use.

TrueFingerprints LLC is a Consumer Reporting Agency as defined by the Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681.

Consumers have rights under the FCRA and applicable state laws.
Learn more about your full rights on our Consumer Rights page.

To request or dispute a background report, click here to access the dispute form.