False Claims Act Cases (FCA) remain one of the government’s most powerful health care enforcement tools. Recent matters illustrate its broad reach and continuing implications for providers, payors, and suppliers. This client alert highlights notable developments and practical steps organizations can take to mitigate risk.
Over the past year, courts and the Department of Justice (DOJ) have continued to pursue False Claims Act Cases involving improper billing, kickback arrangements, and misrepresentations about services provided. Recent settlements involving hospitals, outpatient providers, and pharmaceutical companies underscore the continuing risk for organizations that seek reimbursement from federal health care programs.
Recent Case False Claims Act Cases Highlights
Kickbacks and Referral Schemes: A major hospital system recently resolved allegations that it provided unlawful financial incentives to physicians in exchange for patient referrals. The alleged arrangements included disguised consulting agreements and excessive compensation for limited services, raising Anti-Kickback Statute concerns. The settlement included a substantial payment and enhanced compliance monitoring.
Billing for Non-Rendered Services: A large outpatient provider allegedly billed for physical therapy sessions that did not occur. Whistleblower reports and internal audits identified falsified patient records and claims for services that were not provided or were performed by unqualified staff. The matter resulted in significant penalties and a corporate integrity agreement.
Pharmaceutical Pricing and Marketing: Recent pharmaceutical FCA matters have targeted alleged inflation of drug prices reported to government programs and promotion of medications for unapproved uses. In one matter, a drug manufacturer allegedly misreported Medicaid rebate data and incentivized sales representatives to promote off-label uses, contributing to a significant settlement.
Legal Trends and Enforcement PrioritiesReflected in False Claims Act Cases
Whistleblower (qui tam) actions remain a key driver of FCA enforcement and a significant source of fraud allegations. Although courts continue to scrutinize whether alleged false claims are material under recent Supreme Court guidance, DOJ enforcement remains active and aggressive.
The FCA’s incentive structure helps explain the continued volume of qui tam activity. Private relators may bring claims on the government’s behalf and, in successful cases, receive a share of the government’s recovery. Relators may also benefit from statutory anti-retaliation protections, while treble damages and civil penalties create substantial settlement pressure for defendants.
Practical Guidance for Health Care Clients
Strengthen compliance policies governing billing, referral relationships, and service documentation.
Train personnel on FCA risks, reporting obligations, and whistleblower protections.
Use periodic audits to identify, investigate, and remediate potential FCA exposure.
Respond promptly to government inquiries and preserve relevant records.
Given the continued pace of FCA enforcement, health care organizations should take a proactive, well-documented approach to compliance. For assistance evaluating FCA risk or strengthening compliance strategies, please contact our health care law team.
Conclusion
Recent FCA activity confirms that health care providers remain a central focus of federal enforcement, particularly where billing practices, referral relationships, documentation, and pharmaceutical reporting are at issue. Organizations that invest in strong compliance controls, timely internal review, and clear reporting channels will be better positioned to identify risk early and respond effectively when concerns arise.
Introduction FDA Guidelines on AI Technologies in Medical Devices
The U.S. Food and Drug Administration (FDA) serves a central role in forming the regulatory landscape for artificial intelligence (AI) technologies used in medical devices. Given the distinct challenges that AI introduces, the FDA acknowledges the importance of establishing specific criteria and oversight for these innovations. To address these challenges, the FDA has introduced thorough guidelines that set out to ensure AI-driven medical technologies adhere to strict standards regarding both safety and effectiveness. These comprehensive guidelines are designed to support the responsible integration of AI in healthcare while prioritizing patient well-being and product reliability.
Recent Developments in FDA Guidance
In 2025, the U.S. Food and Drug Administration (FDA) introduced draft guidance specifically focused on device software functions that leverage artificial intelligence technologies. This guidance outlines comprehensive expectations for manufacturers regarding the safety and effectiveness of AI-enabled medical devices. Additionally, the document emphasizes the importance of ongoing monitoring to ensure these devices continue to meet regulatory standards throughout their lifecycle.
The primary objective of this draft guidance is to strike a balance between encouraging technological innovation and maintaining a steadfast commitment to patient safety. By clearly defining regulatory requirements, the FDA aims to support the development of reliable medical products that incorporate AI, ensuring that such advancements contribute positively to healthcare without compromising the well-being of patients.
Broader Regulatory Framework
The FDA’s 2024 guidance extends beyond AI, offering a broader regulatory framework that encompasses various medical products. This approach ensures that emerging technologies are consistently overseen through robust compliance measures. Previous initiatives—including the 2021 Artificial Intelligence/Machine Learning (AI/ML) Software as a Medical Device Action Plan and the 2019 proposed regulatory framework for AI/ML software as a medical device—have helped establish firm standards for patient safety and regulatory compliance.
Ongoing Commitment to Safety and Innovation
Together, these efforts underscore the FDA’s commitment to supporting responsible and effective development of AI-driven medical technologies. By providing clear guidance and establishing comprehensive oversight, the FDA continues to set a foundation for safe and innovative use of AI in healthcare.
Distinguishing Apparent and Actual Authority in AI Systems
When evaluating artificial intelligence applications within healthcare organizations, it is essential to distinguish between apparent authority and actual authority as they relate to AI systems acting on the organization’s behalf. Apparent authority exists when an AI system is presented in such a way that third parties are led to reasonably believe the system is authorized to make decisions or act for the organization. In contrast, actual authority consists of the specific powers granted to the AI system by the organization, whether those powers are explicitly stated or implied.
Understanding the difference between apparent and actual authority is critical for determining liability and accountability, particularly when decisions or recommendations made by AI impact clinical or administrative outcomes. This distinction takes on even greater importance in light of increased regulatory scrutiny and enforcement actions related to the adoption of AI in healthcare delivery and management.
Legal Implications of AI Authority
Healthcare organizations must be aware of the nuanced differences between apparent and actual authority as they implement AI technologies within their operations. If an organization either overstates an AI system’s capabilities or does not properly define the system’s scope of authority, it may face unexpected legal exposure. This risk escalates if patients or providers rely on AI-generated outputs without being informed about the limitations of the system. Consequently, it is vital for organizations to develop clear policies and to ensure that all stakeholders are aware of the boundaries of the AI systems’ decision-making authority.
Mitigating Legal Risks
For healthcare entities integrating AI into their workflows, it is crucial to both understand and clearly communicate the concepts of apparent and actual authority. Failing to define and share the scope of an AI system’s authority can leave organizations vulnerable to legal risks, especially if third parties act on AI-driven decisions that have adverse consequences. To reduce these risks and meet all relevant legal and regulatory requirements, organizations should put in place strong governance structures and maintain transparent communication practices.
Mitigating Legal Risks
For healthcare entities that are incorporating artificial intelligence into their workflows, it is essential not only to grasp but also to clearly communicate the meanings of apparent authority and actual authority as they pertain to AI systems. If an organization does not adequately define and disclose the scope of what an AI system is authorized to do, it may unintentionally expose itself to legal risks. This vulnerability becomes particularly serious if external parties, such as patients or providers, make decisions or take actions based on outputs generated by AI systems, and those actions lead to negative outcomes.
To effectively minimize these risks and ensure compliance with all applicable legal and regulatory obligations, organizations must establish robust governance frameworks. This includes creating clear policies and procedures that delineate the extent of each AI system’s authority. Additionally, maintaining transparent and ongoing communication with all stakeholders is vital. By doing so, healthcare entities can help ensure that everyone involved understands the limitations and responsibilities associated with AI-driven decisions, thereby supporting legal and ethical use of these technologies.
Overview. Covered entities and business associates should ensure that their HIPAA breach assessment procedures reflect the current regulatory standard. Since the 2013 amendments to the HIPAA Breach Notification Rule, an impermissible acquisition, access, use, or disclosure of protected health information is presumed to be a breach unless the entity can demonstrate, through a documented risk assessment, that there is a low probability the information has been compromised.
Why it matters now. Although the 2013 standard remains the foundation for HIPAA breach determinations, the practical risk environment has changed substantially. Ransomware and hacking incidents now dominate large-breach reporting, OCR has repeatedly emphasized risk analysis, risk management, timely breach notification, and workforce training in enforcement matters, and HHS has proposed the first major update to the HIPAA Security Rule since 2013. These developments make breach assessment less of a narrow notification exercise and more of an integrated privacy, security, incident-response, and governance function.
Major Developments Since 2013
Ransomware is now treated as a presumptive breach risk. OCR guidance issued after the 2013 amendments clarified that ransomware affecting electronic protected health information generally triggers breach-analysis obligations because unauthorized actors may have acquired or controlled the information. A covered entity or business associate seeking to avoid notification must be able to demonstrate, through the required low-probability-of-compromise analysis, that the PHI was not compromised.
Cybersecurity has become central to breach analysis. Since 2013, hacking, ransomware, phishing, credential compromise, and vendor incidents have become among the most significant drivers of reported HIPAA breaches. OCR has identified substantial growth in large-breach reports and individuals affected, particularly in connection with hacking and ransomware. As a result, breach assessment should be coordinated with forensic investigation, containment, business-continuity planning, and Security Rule compliance review.
OCR enforcement increasingly focuses on foundational Security Rule controls. Recent enforcement activity has emphasized accurate and thorough risk analysis, risk management, access controls, security awareness training, timely notification, and documentation. In practice, OCR may examine not only whether an organization reached the correct breach-notification decision, but also whether underlying security deficiencies contributed to the incident or delayed detection and response.
Security Rule modernization is pending. HHS issued a proposed rule in December 2024 to strengthen HIPAA Security Rule requirements in response to escalating cyberattacks against the health care sector. Although proposed rules are not yet final obligations, regulated entities should monitor the rulemaking and consider whether current safeguards, asset inventories, access controls, encryption practices, incident-response procedures, and contingency plans would withstand heightened regulatory scrutiny.
Requests for sensitive PHI require closer legal review. Post-2013 developments, including the 2024 reproductive health privacy rulemaking and subsequent litigation, underscore that certain categories of PHI and certain law-enforcement, judicial, administrative, or oversight requests may require heightened legal analysis before disclosure. Organizations should maintain current procedures for evaluating requests involving sensitive health information and should update notices, policies, and training as applicable legal requirements evolve.
The Current Standard: Risk of Compromise to the Information
The principal change implemented in 2013 was a shift in the focus of the breach analysis. Prior to the amendments, many assessments emphasized the potential harm to the individual whose information was involved. The current standard focuses instead on whether the protected health information itself was compromised. A potential breach is not treated as a reportable breach only if a properly conducted risk assessment demonstrates a low probability that the information was compromised.
This distinction can materially affect breach determinations. Under a prior harm-based approach, an organization might have concluded that no breach occurred if the affected individual was unlikely to experience financial, reputational, or other harm. Under the current standard, however, the relevant inquiry is whether the information was subject to a meaningful risk of compromise.
For example, if a disc containing clinical records is mailed to the wrong address, the analysis should not end with whether the recipient can identify or harm the patient. The organization must assess whether the information was accessible, whether it was actually acquired or viewed, who received it, and what mitigation occurred. Depending on the facts, the information-focused standard may require a different conclusion than a harm-based analysis would have produced.
Key Takeaways for Covered Entities and Business Associates
Update breach response policies to reflect the presumption of breach, the information-focused risk assessment standard, and OCR’s ransomware guidance.
Coordinate breach analysis with cybersecurity response, forensic investigation, vendor management, and business-continuity planning.
Train workforce members to distinguish between a HIPAA violation, a regulatory exception to breach, and a reportable breach, including in ransomware and phishing scenarios.
Document all factual findings, mitigation efforts, forensic conclusions, and legal analysis supporting any determination that notification is not required.
Evaluate encryption, access controls, audit logs, backups, and evidence of acquisition or viewing early in the response process.
Monitor HIPAA Security Rule rulemaking, OCR enforcement trends, and evolving requirements for sensitive categories of PHI.
Resolve close factual or legal questions conservatively, especially where evidence of mitigation, non-access, or containment is incomplete.
Recommended Assessment Framework
1. Determine Whether a HIPAA Violation Occurred
The first step is to determine whether the underlying event involved an impermissible acquisition, access, use, or disclosure of protected health information. Not every HIPAA violation constitutes a breach; however, every breach necessarily includes a HIPAA infraction. If the use or disclosure was permitted under the HIPAA Privacy Rule, no breach exists for notification purposes, although other compliance obligations may still warrant review.
2. Assess Whether a Specific Breach Exception Applies
HIPAA recognizes three specific exceptions under which an impermissible use or disclosure is not treated as a breach: unintentional acquisition, access, or use by a workforce member or person acting under appropriate authority; certain inadvertent disclosures to another authorized person; and disclosures where the covered entity or business associate has a good-faith belief that the recipient could not reasonably retain the information. Because the entity bears the burden of establishing the exception, the analysis should be supported by contemporaneous documentation.
3. Confirm Whether the Information Was Properly Encrypted
Where the incident involves electronic protected health information, the organization should promptly determine whether the information was secured through encryption that satisfies applicable standards. If properly encrypted information is lost or disclosed, the incident generally will not trigger breach notification obligations under the HIPAA Breach Notification Rule. In cyber incidents, however, encryption should be evaluated alongside evidence of credential compromise, exfiltration, unauthorized access, malware activity, backup integrity, and whether the information was encrypted before or only after the attacker obtained access.
This inquiry should be addressed early in the response process because encryption may be dispositive in some matters, but it is not a substitute for a complete incident investigation. Organizations should maintain records sufficient to establish whether the relevant device, file, database, transmission, or backup environment was encrypted at the time of the incident and whether unauthorized actors had any ability to access usable PHI.
4. Evaluate the Probability of Compromise
If the matter is not resolved by the preceding steps, the organization must conduct and document a risk assessment to determine whether there is a low probability that the protected health information was compromised. Since 2013, this analysis has become increasingly intertwined with cybersecurity evidence, including forensic findings, system logs, endpoint data, network activity, containment timelines, and evidence concerning acquisition, viewing, exfiltration, or destruction of PHI.
At a minimum, the assessment should address the nature and extent of the protected health information involved, including identifiers and the likelihood of re-identification; the unauthorized person who used the information or to whom it was disclosed; whether the information was actually acquired or viewed; and the extent to which the risk to the information has been mitigated. In cyber incidents, the assessment should also consider whether data was encrypted, copied, staged, compressed, transferred, posted, sold, destroyed, or rendered unavailable.
The assessment should evaluate these factors collectively rather than in isolation. Clinical information, financial data, direct identifiers, or information that can be combined with other data may increase the likelihood of compromise. Conversely, credible evidence that the information was not accessed, was returned or destroyed, or was subject to effective mitigation may support a lower-risk conclusion.
The identity and reliability of the recipient may also be relevant. For example, disclosure to another regulated health care provider who promptly reports the incident may present a different risk profile than disclosure to an unknown recipient or a recipient whose conduct suggests possible misuse. The conclusion should be tied to verifiable facts rather than assumptions.
Because an impermissible acquisition, access, use, or disclosure is presumed to be a breach unless the entity demonstrates a low probability of compromise, the organization should treat documentation as a core compliance requirement. Any no-breach determination should be supported by reliable facts, mitigation records, forensic evidence where applicable, appropriate legal or subject-matter input, and a clear written rationale. Where material doubt remains, particularly in ransomware or hacking matters, the more prudent course is to proceed with breach notification.
Recommended Next Steps
Organizations subject to HIPAA should review their breach response policies, incident intake procedures, documentation templates, vendor incident protocols, cybersecurity controls, and workforce training materials to ensure alignment with current breach notification expectations and post-2013 enforcement priorities. Policies should reflect the presumption of breach, the required risk assessment factors, OCR ransomware guidance, the limited regulatory exceptions, encryption and forensic-evidence considerations, and the importance of prompt, well-supported documentation. Because breach determinations are highly fact-specific and increasingly technical, covered entities and business associates should involve privacy, security, compliance, legal, forensic, and vendor-management personnel early in the response process.
Host: Welcome back to our Ambulatory Surgery Center Compliance Series. I’m glad you’re here, because today we’re closing out the series with something incredibly practical — a clear, actionable ASC Compliance Checklist for 2026.
This episode is designed to be your quick‑reference guide. Whether you’re an administrator, a compliance officer, or a physician‑owner, this checklist will help you evaluate your ASC’s structure, operations, and financial relationships through the lens of what regulators are focusing on right now.
Let’s jump in.
Section 1: Ownership & Investment Structure
First, let’s talk about ownership — because this is where most ASC compliance issues begin.
Every year, you should confirm that each physician‑owner meets the one‑third tests that apply to your ASC type. That means they’re actually performing procedures at the ASC or in other ambulatory surgical settings, not just investing passively.
You also want to make sure every investor has real financial risk. That includes capital contributions, exposure to losses, and no preferential financing. If someone’s investment looks too easy, too protected, or too guaranteed, that’s a red flag.
And finally, distributions must never correlate with referral volume. If the numbers even appear to track referrals, regulators will take notice.
Section 2: Operational Participation
Next, let’s look at participation.
Every physician‑owner should be meaningfully engaged in performing procedures at the ASC. This isn’t just about meeting a threshold — it’s about demonstrating real involvement.
Track case volumes. Track income sources. And do it consistently. If someone is drifting toward the margins, address it early. Regulators care deeply about whether owners are actually using the facility.
Now let’s talk referrals — because this is where enforcement has been heating up.
Review your referral data for outliers. Look for reciprocal referral patterns. Make sure no payments, bonuses, or distributions are tied to referrals, directly or indirectly.
If you have relationships with hospitals, management companies, or other entities, evaluate them carefully. Regulators are increasingly focused on whether these arrangements create remuneration risk.
Section 4: Anesthesia, Management, and Service Agreements
This is an area where ASCs often stumble.
Anesthesia arrangements must avoid anything that looks like “pay‑to‑play.” Management fees must reflect fair market value and cannot be tied to volume or value of referrals.
And if you have co‑management, consulting, or marketing agreements, review them with a critical eye. These are frequent sources of Anti‑Kickback Statute concerns.
Section 5: Safe Harbor Alignment
Even if your ASC doesn’t fit neatly into a safe harbor — and many don’t — you should still document how your structure aligns with safe harbor principles.
That includes:
Bona fide investment risk
Meaningful participation
No referral‑based remuneration
Commercially reasonable terms
Think of this as building a compliance narrative. If regulators ever ask, you want to be able to show your work.
Section 6: Billing, Coding & Documentation
Let’s shift to operations.
Conduct periodic audits of your billing and coding. Make sure documentation supports medical necessity and procedure selection. And confirm compliance with CMS Conditions for Coverage.
Billing issues may not be as flashy as ownership structures, but they’re just as important — and just as risky.
Section 7: Annual Compliance Review
Every ASC should conduct a structured annual review. That includes:
Ownership structure
Distributions
Service agreements
Referral analytics
FMV assessments
This is your chance to catch issues before regulators do.
Section 8: When to Seek an Advisory Opinion
Finally, let’s talk about advisory opinions.
If your ASC structure is outside a safe harbor but still defensible, or if you have complex relationships with hospitals or management companies, an advisory opinion may be worth considering.
It’s not necessary for every ASC — but for borderline structures, it can provide clarity and protection.
Closing Thoughts
Host: And that’s your ASC Compliance Checklist for 2026.
This episode wraps up our ASC compliance series, but it also gives you a practical tool you can revisit throughout the year. Compliance isn’t a one‑time project — it’s an ongoing discipline. And with regulators sharpening their focus on ASCs, staying proactive is more important than ever.
Understanding Fee-Splitting Laws in Telehealth: Key Concepts Explained
Fee-splitting in telehealth is a critical legal and compliance consideration for healthcare providers, telehealth platforms, and management service organizations (MSOs) operating in the rapidly evolving digital health landscape. As telehealth continues to expand, understanding how fee-splitting laws apply to virtual care models is essential for avoiding regulatory pitfalls and ensuring sustainable business operations.
How State Fee-Splitting Laws Affect Telehealth and CPOM Compliance
Fee-splitting laws are closely related to telehealth corporate practice of medicine (CPOM) compliance. State fee-splitting laws generally restrict physicians from sharing professional fees with non-licensed persons or entities, especially when payments are connected to referrals, patient volume, or services that the non-licensed entity did not personally render. Some states may permit revenue-based arrangements when they reflect bona fide services at fair market value, while others prohibit or closely scrutinize percentage-based compensation. For telehealth companies, this means MSO fees, platform fees, marketing arrangements, lead-generation relationships, and provider compensation models should be reviewed carefully before being implemented.
Common Fee-Splitting Risks in Telehealth Business Models
Common fee-splitting risks in telehealth arise when business models or compensation structures involve sharing revenue with non-clinical partners. The risk is particularly significant when a non-clinical entity is compensated as a percentage of professional revenue, receives payments that increase with patient volume, or is rewarded for directing patients to a particular provider or service. Even where the payment is characterized as a technology fee, platform fee, or marketing fee, regulators may examine whether the amount reflects the fair value of legitimate services or instead operates as remuneration for referrals or patient access.
State-by-State Variations in Telehealth Fee-Splitting Laws
State laws on fee-splitting in telehealth can vary dramatically, making multi-state compliance especially challenging. Wisconsin illustrates how state-specific rules can affect CPOM in telehealth. Wisconsin law reflects restrictions on fee sharing and referral payments, and regulators may look beyond contract labels to determine whether payments compensate legitimate non-clinical services or reward business generation. Illinois is another example of a state where percentage-based management fees can raise concerns. Because state laws differ, a compensation model that appears acceptable in one jurisdiction may create risk in another.
Federal Anti-Kickback and Fraud Laws Impacting Telehealth Fee-Splitting
Federal law adds further complexity to fee-splitting in telehealth. The federal anti-kickback statute can be implicated when remuneration is exchanged to induce or reward referrals of items or services reimbursable by federal health care programs. The Stark Law may also be relevant when physician referrals for designated health services are involved. These federal rules do not replace state CPOM and fee-splitting analysis; they sit alongside it. A structure may need to satisfy state professional practice rules, state fee-splitting prohibitions, federal fraud-and-abuse laws, payor contract requirements, and professional board expectations.
Best Practices for Telehealth Fee-Splitting Compliance
Avoid percentage-based compensation tied to referrals, patient volume, or revenue when possible.
Conduct a state-by-state analysis of fee-splitting laws before entering new markets.
Ensure all compensation models reflect fair market value for actual services provided.
CPOM in telehealth is a significant legal and regulatory issue for virtual care companies, medical practices, investors, and management services organizations. Although telehealth may facilitate the delivery of health care across geographic boundaries, corporate practice of medicine laws remain largely state-specific and may affect ownership of the professional practice, control over clinical decision-making, the flow of professional revenue, and compensation for non-clinical support services. For organizations developing, acquiring, or expanding a virtual care model, early analysis of telehealth corporate practice of medicine requirements can mitigate restructuring risk, enforcement exposure, and transaction delays.
Principal Issue of CPOM in Telehealth
The principal compliance issue is straightforward in concept but complex in application: business entities may provide support to a medical practice, but they generally may not engage in the practice of medicine. In the telehealth context, that distinction may become less clear. A technology platform may schedule visits, collect intake information, route patients to clinicians, support billing functions, coordinate marketing administration, and provide virtual care infrastructure. Although those services may be non-clinical, the organization must avoid exercising control over diagnosis, treatment, prescribing, clinical protocols, or professional judgment.
This article addresses how CPOM in telehealth affects common business models, why management services organization and professional entity structures are frequently used, how fee-splitting restrictions may create additional risk, and what organizations should evaluate before launching, acquiring, or scaling a virtual care platform.
Listen to our Legal Pulse Podcast on CPOM in Telehealth
Telehealth corporate practice of medicine rules generally require licensed clinicians to retain control over diagnosis, treatment, prescribing, clinical protocols, and patient-care decisions.
Non-clinical companies, platforms, and MSOs should avoid owning, operating, or controlling the professional medical practice in ways that violate state CPOM laws.
Management fees should be commercially reasonable, supported by fair market value, and not structured as disguised payments for referrals or professional fee-splitting.
Because CPOM and fee-splitting laws vary by state, multi-state telehealth companies need jurisdiction-specific legal review before launch or expansion.
What Is the Corporate Practice of Medicine in Telehealth?
The corporate practice of medicine doctrine generally prohibits non-licensed business entities from practicing medicine, employing physicians to provide professional clinical services, or interfering with medical judgment. In a telehealth corporate practice of medicine analysis, the central inquiry is whether licensed providers—not investors, technology vendors, marketing companies, or MSOs—retain responsibility for clinical decision-making. These decisions include diagnosis, treatment plans, prescribing, supervision of clinical personnel, medical record policies, patient communications concerning care, and the provider-patient relationship.
The doctrine is grounded in the principle that medical judgment should be exercised by licensed professionals who owe ethical and professional obligations to patients. If a non-clinical entity pressures providers to follow business-driven treatment protocols, limits clinical discretion, controls the hiring or termination of clinicians, or influences prescribing decisions, regulators may view the arrangement as an impermissible exercise of corporate control over medicine. Depending on the jurisdiction, violations may result in licensure action, unenforceable contracts, repayment exposure, civil liability, or criminal penalties.
Telehealth makes these questions more complex because the patient, provider, platform, professional entity, and management company may all be located in different states. A company headquartered in one state may deliver services to patients in many others. For CPOM purposes, the relevant analysis often turns on the laws of the states where patients are located and where professional services are delivered, not merely where the business is organized.
How CPOM Affects Telehealth Business Models
CPOM in telehealth often shapes the relationship between a physician-owned professional entity and a management services organization. In many models, the professional entity provides clinical services and receives professional revenue, while the MSO provides non-clinical services such as billing support, scheduling, technology infrastructure, accounting, marketing administration, human resources support, compliance administration, payor enrollment support, and back-office operations. This structure can reduce risk when the MSO does not control clinical policies, provider supervision, prescribing decisions, or other professional judgment.
Management Service Organization and CPOM in Telehealth
The professional entity/MSO model is not, by itself, dispositive. Contractual documentation must be consistent with operational reality. If an MSO states that it provides only administrative services but, in practice, determines which clinical services are offered, selects clinical protocols, controls provider scheduling in a manner that affects care, or terminates clinicians for exercising independent judgment, the structure may still present CPOM concerns. Regulators and payors may evaluate how the arrangement operates in practice, not solely how it is described in the agreements.
Document Flow of Funds to Mitigate CPOM in Telehealth
Companies should also document the flow of funds. In a lower-risk structure, professional revenue is generally received by the professional practice, and the MSO is paid for defined non-clinical services under a written management agreement. Compensation should be commercially reasonable and supported by fair market value analysis. Recent federal guidance regarding telehealth MSO arrangements has also emphasized the importance of fees that are set in advance, supported by valuation, and not dependent on referrals, patient volume, or payor reimbursement.
Common Red Flags in Telehealth CPOM Structures
The MSO or platform controls clinical protocols, prescribing standards, or treatment pathways without meaningful provider discretion.
A non-clinical company can hire, fire, discipline, or supervise clinicians based on clinical judgment or patient-care decisions.
Management fees are calculated as a percentage of professional revenue without state-specific fee-splitting review.
Marketing or lead-generation payments vary based on patient conversions, referrals, or ordered services.
Contracts describe compliant separation, but day-to-day operations give the business entity practical control over medical decisions.
CPOM in Telehealth Compliance Checklist
Confirm that licensed clinicians retain control over diagnosis, treatment, prescribing, clinical protocols, and patient-care decisions.
Separate clinical services from non-clinical business functions in the operating model and contracts.
Define the MSO’s role as limited to administrative and operational support services.
Support management fees with fair market value analysis and commercial reasonableness documentation.
Avoid compensation formulas tied to referrals, patient volume, professional fees, or increased utilization.
Conduct state-specific CPOM and fee-splitting review before launching, acquiring, or expanding telehealth operations.
Evaluate federal Stark Law and anti-kickback statute implications where federal health care program reimbursement or referral relationships are involved.
Frequently Asked Questions About CPOM in Telehealth
Does CPOM apply to telehealth companies?
Yes. Telehealth companies are generally subject to the corporate practice of medicine rules in the states where patients receive care. A virtual delivery model does not eliminate the obligation to comply with state professional practice requirements.
Can an MSO manage a telehealth practice?
An MSO may provide non-clinical management services, but it should not control medical judgment, clinical protocols, prescribing, provider supervision, or other professional decisions. The services and compensation should be clearly documented.
Why are percentage-based fees risky in telehealth?
Percentage-based fees can raise fee-splitting and referral concerns if they appear tied to professional revenue, patient volume, or business generated for the practice. Some states scrutinize or restrict these arrangements more heavily than others.
What is the difference between CPOM and fee splitting?
CPOM focuses on who may own, operate, or control a medical practice and who may exercise clinical judgment. Fee-splitting rules focus on whether professional fees are being shared with non-licensed persons or entities in an impermissible way. In telehealth, both issues often arise together because the same MSO, platform, or investor relationship may affect both control and compensation.
When should a telehealth company review CPOM compliance?
CPOM in telehealth review should occur before launch, before entering a new state, before changing compensation terms, before signing major MSO or platform agreements, and before a financing or acquisition transaction. Waiting until diligence can create avoidable delays and may require restructuring under time pressure.
Can one telehealth corporate practice of medicine structure work nationwide?
In most cases, a single template is insufficient. An organization may use a consistent overall framework, but the details often must be adapted to address state ownership rules, professional entity requirements, supervision rules, fee-splitting restrictions, and payor contracting expectations.
Address CPOM Issues in Telehealth
CPOM in telehealth should be addressed at the outset of the transaction or business planning process—not after operations have commenced. A compliant telehealth corporate practice of medicine structure should preserve independent clinical judgment, separate professional and non-clinical functions, document fair market value compensation, and account for state-by-state variation. The structure should also be operationally consistent: contracts, governance documents, workflows, training materials, compensation terms, and day-to-day practices should support the same compliance position.
Conclusions About CPOM in Telehealth
As virtual care continues to expand, regulators, payors, and transaction counterparties are likely to continue scrutinizing who controls the medical practice and how funds move through the model. Organizations that treat CPOM and fee-splitting compliance as a core component of business design—not merely as a legal memorandum—will be better positioned to scale, attract investment, and maintain durable provider relationships.
The key takeaway is that CPOM in telehealth corporate practice of medicine compliance is not limited to selecting the appropriate entity form. It requires maintaining a defensible separation between clinical authority and business support, documenting fair value for services, avoiding referral-driven compensation, and updating the structure as the organization grows. Early guidance from experienced health care counsel and valuation professionals can help reduce enforcement risk and support a durable virtual care business model.
ASC safe harbors play a central role in evaluating ownership arrangements involving Physician Investors in ASCs. Ambulatory surgery centers frequently confront difficult questions about how to address physician-investors who perform fewer procedures at the center than their co-investors. These situations can create political and operational tension, particularly when higher-volume physicians believe lower-volume investors are benefiting from profits generated by more active users of the facility. If not handled carefully, that tension can lead to decisions that implicate the federal anti-kickback statute, which prohibits offering or maintaining investment opportunities based on the actual or expected volume or value of referrals.
This article explains how ASC safe harbors affect the treatment of Physician Investors in ASCs, particularly when some investors generate materially fewer procedures than others. The key issue is how an ASC can address ownership, redemption, and participation concerns without creating the appearance that investment rights depend on referral volume.
Why ASC Safe Harbors Are Counterintuitive Applied to Physician Investors in ASCs
The anti-kickback statute standards that apply to ambulatory surgery center ownership are somewhat counterintuitive. Unlike many other health care arrangements, ASC safe harbors for investment interests include conditions tied to the physician-investor’s use of the facility. In that context, referral-related thresholds are intended to help identify whether the ASC functions as a natural extension of the physician’s medical practice.
ASC safe harbors are not the only way to evaluate compliance risk. A physician who does not satisfy every safe harbor threshold may still legitimately use the ASC as an extension of his or her office practice. The safe harbor provides a pathway to more certain protection when all conditions are met, but failure to satisfy a threshold does not automatically mean the arrangement is unlawful.
Evaluating Lower-Volume Physician Investors in ASCs
When Physician Investors in ASCs do not meet the specific requirements of an ASC safe harbor, the center should still conduct a complete facts-and-circumstances analysis. A physician may practice in a specialty or subspecialty that naturally produces fewer ASC procedures than other specialties represented at the center. Lower procedural volume alone does not necessarily indicate greater anti-kickback risk than a physician who comes closer to satisfying the ASC safe harbors.
Depending on the practice type, a lower level of referrals may still be consistent with genuine use of the ASC as an extension of the physician’s practice. This may be frustrating to higher-volume surgeons, especially when they believe the center’s profitability is driven disproportionately by their procedures. However, using one-third tests or other volume-based metrics as a mechanism to exclude lower-volume Physician Investors in ASCs can create significant compliance concerns if the practical effect is to pressure investors to increase referrals.
ASC Safe Harbors, Forced Redemption, and Regulatory Risk
Excluding or redeeming Physician Investors in ASCs because they do not meet ASC safe harbor thresholds can create substantial legal risk. These actions may be challenged by excluded investors or reviewed by government enforcement agencies, particularly if the facts suggest that ownership was conditioned on generating additional procedures for the ASC.
Once physicians own interests in an ASC, it is difficult to force redemption without creating an inference that continued ownership depends on referral volume. Great care should be taken to ensure that frustration among higher-volume producers does not drive actions that increase regulatory exposure for the center, its owners, Physician Investors in ASCs, or its governing body.
Operating Agreement Considerations for Physician Investors in ASCs
Operating agreements that govern ASC ownership can themselves create compliance risk if exclusion or redemption provisions are tied too closely to referral-related criteria. Procedures for addressing investor eligibility should be established in advance, applied uniformly, and drafted to avoid any inference that Physician Investors in ASCs must generate additional referrals to maintain an investment interest.
Efforts framed as bringing investors closer to ASC safe harbors can easily be turned inside out and characterized as requiring additional referrals. For that reason, ASC governing documents and enforcement practices should be reviewed carefully before any action is taken against a lower-volume physician-investor.
Key Compliance Principle for ASC Safe Harbors
ASC safe harbors are intended to protect arrangements that present a lower risk of abuse when all specified conditions are satisfied. They were not designed to replace a complete risk analysis for Physician Investors in ASCs who fall outside one or more safe harbor elements. This distinction is especially important because the ASC safe harbor is unusual: it incorporates use-related thresholds in a legal framework that otherwise prohibits conditioning financial benefits on referrals.
In many other safe harbor contexts, structuring an arrangement to come close to safe harbor protection can be a valid risk-mitigation strategy. That approach does not translate neatly to ASC ownership. Requiring Physician Investors in ASCs to increase procedures in order to satisfy ASC safe harbors may itself invoke the referral prohibition. Forcing a physician out of the ASC solely because the physician does not meet a safe harbor threshold can therefore create significant anti-kickback risk.
Conclusion
ASC leaders should evaluate lower-volume Physician Investors in ASCs with caution, consistency, and a documented facts-and-circumstances analysis. While ASC safe harbors provide important compliance benchmarks, they should not be applied mechanically to force referrals or justify redemption. A careful, uniformly applied process helps address ownership concerns while reducing anti-kickback risk.
Learn More About Ambulatory Surgery Center Legal and Regulatory Issues
For more discussion of ASC safe harbors, Physician Investors in ASCs, and related compliance challenges, listen to our podcast series on ambulatory surgery center legal and regulatory issues. The series explores practical approaches to ownership, redemption, anti-kickback risk, and governance concerns affecting ASCs and their physician owners.
Episode 4: Legal Pulse Podcast Healthcare Edition the Health Law Podcast where law and medicine intersect
Artificial intelligence is revolutionizing healthcare, transforming the way medical professionals diagnose, treat, and care for patients. From streamlining administrative tasks to powering advanced diagnostic tools, AI technologies are making it possible for doctors and nurses to deliver more accurate and efficient care. The integration of machine learning and data analytics is not only improving patient outcomes but also reshaping the daily routines of those working in medicine.
In this podcast, we’ll explore the many ways AI is impacting the medical profession. We’ll hear from experts about how these innovations are changing the roles of healthcare workers, enhancing decision-making, and raising important questions about ethics and patient privacy. Whether you’re a medical professional, a patient, or simply curious about the future of healthcare, join us as we dive into the exciting—and sometimes challenging—world of artificial intelligence in medicine.
How Artificial Intelligence is Changing the Medical Profession
Lessons from a Real-World Case Study in Ambulatory Surgery Center Ownership
When it comes to Ambulatory Surgery Centers (ASCs), compliance with federal regulations is essential, especially regarding ASC Safe Harbors. Many surgery centers strive to boost their business by engaging physicians as owners. However, even seemingly harmless arrangements can cross legal boundaries, putting the entire facility at risk.
A Cautionary Tale: The Silent Partner Physician
Imagine a scenario in which a physician’s name appears on the ASC ownership roster, yet the facts tell a different story. A capital contribution that never materializes. Distributions that rise and fall, seemingly in lockstep with referral volume. And the clincher: an internal email stating, “We need him on the cap table to keep his cases here.” This is the story of the Silent Partner Physician — a case that highlights how overlooking ASC Safe Harbor rules can lead to textbook violations.
Segment 1 — The Setup
The ASC at the center of this story was a small, high‑volume orthopedic facility. Like many ASCs, its financial health depended heavily on a few surgeons who generated most of its cases. One of those surgeons — let’s call him Dr. X — was invited to join as an investor. He signed all the necessary paperwork and was officially added to the ownership schedule.
But here’s the compliance pitfall: Dr. X never actually contributed capital. There was no check, no promissory note, nothing. Despite this, Dr. X began receiving quarterly distributions within months. This immediately raises red flags for ASC Safe Harbor compliance, which requires bona fide investment and risk.
Segment 2 — The Pattern Emerges
At first, the payments to Dr. X were small and almost symbolic. However, a troubling pattern soon surfaced:
When Dr. X’s case volume increased, his distributions increased.
This direct relationship between referrals and financial rewards is exactly what ASC Safe Harbors are designed to prevent. The lack of a real investment, combined with compensation linked to case volume, exposes the ASC to significant legal and regulatory repercussions.
Key Takeaways for ASC Owners and Administrators
Follow ASC Safe Harbor requirements: Ensure every physician-owner makes a legitimate capital contribution and bears real financial risk.
Avoid tying distributions to referral patterns: Distributions should be based on ownership percentages, not case volume or referral numbers.
Document compliance: Maintain thorough records of every investment and distribution. Transparency is crucial for defending your ASC in the event of an audit.
Educate your partners: Make sure all physician investors understand ASC Safe Harbor and anti-kickback rules to avoid accidental violations.
Conclusion
The story of the Silent Partner Physician serves as a warning: even well-intentioned ownership arrangements can cross into dangerous territory if ASC Safe Harbor rules aren’t strictly followed. To safeguard your ASC, prioritize compliance, transparency, and education—because when it comes to healthcare law, ignorance is never a defense.
Looking to learn more about ASC Safe Harbors or need a legal compliance check-up? Consult our qualified physicians’ healthcare attorney or compliance expert to keep your surgery center on the right side of the law.
Episode 3: The Ambulatory Surgery Center Safe Harbors – General Overview
Ambulatory Surgery Center (ASC) Safe Harbors are legal provisions designed to protect certain arrangements involving ASCs from liability under the federal Anti-Kickback Statute. These Safe Harbors outline specific criteria that must be met for ASC transactions—such as investment interests and referral relationships—to be considered exempt from prosecution. By adhering to these guidelines, ASCs can ensure compliance and minimize legal risks associated with improper financial incentives.
The Stark Law, formally known as the Physician Self-Referral Law, is a federal statute that prohibits physicians from referring patients for certain designated health services to entities with which they have a financial relationship, unless specific exceptions apply. The law is designed to prevent conflicts of interest and ensure that medical decisions are made in the best interest of patients, not influenced by financial gain. Violations of the Stark Law can result in significant penalties, including fines and exclusion from federal health programs.
Recently, there has been notable regulatory silence regarding updates or enforcement guidance for the Stark Law. This lack of clarity may leave physicians uncertain about compliance requirements, especially as healthcare practices evolve and new care models emerge.
What might this regulatory silence mean for physicians, and should they be concerned about potential changes or enforcement actions in the near future?
Ambulatory Surgery Center (ASC) Safe Harbors are legal provisions designed to protect certain arrangements involving ASCs from liability under the federal Anti-Kickback Statute. These Safe Harbors outline specific criteria that must be met for ASC transactions—such as investment interests and referral relationships—to be considered exempt from prosecution. By adhering to these guidelines, ASCs can ensure compliance and minimize legal risks associated with improper financial incentives.
The Safe Harbors cover a range of scenarios, including physician ownership, joint ventures, and payment structures. They require transparent operations, fair market value compensation, and documentation of legitimate business purposes. Understanding and applying these Safe Harbors is essential for ASCs to maintain ethical practices and avoid regulatory penalties.
Stark Law Period of Disallowance Guide for Healthcare Professionals
Stark Law Period of Disallowance Compliance. The Stark Law, formally known as the Physician Self-Referral Law, is a federal statute designed to prevent physicians from referring patients to entities with which they have a financial relationship, unless an exception applies. The primary purpose of the Stark Law is to safeguard the integrity of medical decision-making and prevent conflicts of interest that could compromise patient care. Compliance is critical, as violations can result in severe penalties, including repayment obligations, civil monetary penalties, and exclusion from federal healthcare programs.
What is Stark Law Period of Disallowance
The Stark Law period of disallowance is a significant concept in the enforcement of federal law governing physician referrals for designated health services, as defined by statute and regulation. Pursuant to 42 U.S.C. § 1395nn(h)(6) and 42 C.F.R. § 411.351, designated health services include the following:
Clinical laboratory services.
Physical therapy, occupational therapy, and outpatient speech-language pathology services.
Radiology and certain other imaging services.
Radiation therapy services and supplies.
Durable medical equipment and supplies.
Parenteral and enteral nutrients, equipment, and supplies.
Prosthetics, orthotics, and prosthetic devices and supplies.
Home health services.
Outpatient prescription drugs.
Inpatient and outpatient hospital services.
The period of disallowance denotes the period during which referrals and any related claims are prohibited upon the existence of a financial relationship that fails to comply with the Stark Law and its implementing regulations. The period of disallowance generally commences when the noncompliant financial arrangement is established and continues until the arrangement is either terminated or brought into compliance. During such period, any Medicare or Medicaid claims arising from prohibited referrals are not payable, and the provider must undertake corrective action to remedy the underlying noncompliance.
Legal Background on the What is Stark Law Period of Disallowance
The statutory and regulatory framework for the Period of Disallowance stems from Section 1877 of the Social Security Act and is further clarified by regulations issued by the Centers for Medicare & Medicaid Services (CMS). The law outlines prohibited financial relationships and sets forth exceptions that may apply. CMS regulations provide guidance on how to address violations, including the calculation and management of disallowance periods. The concept was introduced to ensure that improper financial relationships are corrected and that claims submitted during the violation are appropriately handled.
Stark Law Period of Disallowance Calculation Methods
Determining the Period of Disallowance requires careful analysis of the facts surrounding the violation. The period begins at the inception of the non-compliant financial arrangement, such as an improper lease or compensation agreement, and continues until the arrangement is terminated or corrected. Correction may involve repaying excess compensation, renegotiating terms to meet compliance standards, or ending the relationship altogether. The CMS has issued guidance clarifying that the period does not retroactively apply to arrangements corrected before any prohibited referrals occur, but it does encompass all claims submitted during the period of non-compliance.
Implications for Healthcare Providers
For healthcare providers, the Period of Disallowance has significant operational and financial repercussions. Providers must identify and disclose non-compliant arrangements promptly to minimize the period and associated liabilities. Claims submitted for services rendered during the disallowance period may be denied or subject to repayment, and providers may face penalties if violations are not addressed in a timely manner. Maintaining robust compliance programs and conducting periodic audits are essential strategies to prevent and manage disallowance periods effectively.
Practical Examples Stark Law Period of Disallowance
Consider a scenario where a physician enters into a lease agreement with a hospital for office space at below-market rates, violating the fair market value requirement under the Stark Law. The Period of Disallowance would begin when the arrangement was established and continue until the lease terms are adjusted to comply with fair market value standards. All referrals and related claims during this period would be disallowed. Another example involves a compensation arrangement that exceeds regulatory limits; once identified, the provider must repay excess amounts and bring the agreement into compliance to end the disallowance period.
Best Practices for Managing Disallowance Periods
• Conduct regular reviews of all financial relationships to ensure compliance with the Stark Law. • Establish clear policies and procedures for identifying and correcting non-compliant arrangements. • Maintain thorough documentation of corrective actions and communications with regulatory authorities. • Train staff and legal counsel on Stark Law requirements and the significance of the Period of Disallowance. • Seek guidance from CMS and legal experts when addressing complex arrangements or potential violations.
The Period of Disallowance under the Stark Law is a crucial mechanism for enforcing compliance and protecting the integrity of federal healthcare programs. Understanding its definition, calculation, and implications enables healthcare providers and legal professionals to navigate complex regulatory requirements and avoid costly penalties. By adopting best practices and maintaining vigilant oversight of financial relationships, organizations can minimize risk and ensure ongoing compliance with the Stark Law.
Best Practices In Compliance. Given the increased importance of compliance, it is helpful to for providers to get a feel for what constitutes “best practice” when operating a compliance program. “Best Practices” is a term that is thrown around all of the time in the business world. It is used in many contexts and takes on a variety of meanings depending on who is using it and for what purpose.
“…generally-accepted, informally-standardized techniques, methods or processes that have proven themselves over time to accomplish given tasks. Often based upon common sense, these practices are commonly used where no specific formal methodology is in place or the existing methodology does not sufficiently address the issue. The idea is that with proper processes, checks and testing, a desired outcome can be delivered more effectively with fewer problems and unforeseen complications. In addition, a “best” practice can evolve to become better as improvements are discovered. Best practice is considered by some as a business buzzword, used to describe the process of developing and following a standard way of doing things that multiple organizations can use. http://en.wikipedia.org/wiki/Best_practice
As I was thinking about the concept of “best practices” in health care compliance, the Wikipedia definition seems to fall al little bit short of what I would have in mind when discussing “best practices” in health care compliance programs.
The Miriam-Webster Dictionary defines “Best” as the superlative form of “good.” “Best” means “excelling all others” and “offering or producing the greatest advantage, utility, or satisfaction.” I believe that the definition from Wikipedia is an accurate depiction of what the term “best practices” has become in the business world. The term has been thrown around loosely to the point that is no longer carries the meaning of the plain words that make up the two word “buzzword.” Best Practices In Compliance means “Best,” not “just enough,” or “adequate.” Word still mean something. Best means best.
In the health care compliance context, I believe that it is not advisable to direct you efforts toward the standard “buzzword” meaning of “Best Practices In Compliance.” Instead, you should focus toward attempting to achieve the meaning of “best practices” that is tied to the superlative form of the word “good.” You should not focus on the “we are doing what everyone else is doing” or the “what we are doing will pass by in most cases” version of best practices when looking at your compliance plan. The consequences of that approach could easily come back to bite you in the superlative.
In reality, you may never be able to meet the truly “best” standard. However, the point of the compliance program requirement is that you are trying to make your compliance program and your organization “the best” when it comes to compliance at your organization and as applied to the makeup of your unique organization. Here are a few tips to help you attempt to meet the “best practices” standard:
Act as if you are under a Corporate Integrity Agreement. Always assume that the government is looking over your shoulder and that you will be called upon at some point to justify the effectiveness of your compliance program.
Follow the government guidelines to the tee (and that doesn’t mean the golf tee.” Familiarize yourself with the Federal Sentencing Guidelines and OIG Industry Guidance and integrate these requirements into your compliance plan.
Keep up with government releases, speeches, regulations, comments, advisory opinions, and all other communication that help to define your obligations.
Make your compliance plan a “living and breathing” documents that is continually up for revision based on specific things that you learn about your specific organizations.
Make sure your compliance officer focuses on compliance and does not wear other hats that compete for time, attention or perspective.
Make certain that sufficient resources are devoted to compliance.
Adopt the view that it is better to spend money on compliance that to pay for mistakes down the road. If there is any area where you are not able to achieve “best practices” for financial or other reasons, be prepared to justify your shortcomings. Key to all of this is to operate as if you will someday be required to defend the effectiveness of your compliance program. In all likelihood you will someday be in exactly that position given the current state of the health care industry and mentality of the governmental agencies that are charged with enforcement.
These are just a few tips to get you thinking about your compliance approach. Health care reform has made compliance programs mandatory for the first time. There are also multiple indications that the government wants organizations to devote more to compliance as a way to save health care costs. It is clearly time for organizations of all types and sizes to re-focus their efforts on compliance within their organizations.
Regulatory Developments Impacting Medical Practice Structures and Ancillary Services
The health care sector is undergoing continual transformation in response to evolving regulations and policy directives. Recent modifications at both federal and state levels are exerting considerable influence on the organization of medical practices and their ancillary services. This newsletter presents an overview of key regulatory developments and examines their potential implications for medical practices, physician groups, and affiliated health care services.
As regulatory updates reshape the landscape, medical organizations must remain vigilant, actively assessing how new laws and policies impact practice structure, provider roles, and the delivery of ancillary services. From adjustments to federal regulations such as the Stark Law and Anti-Kickback Statute, to state-driven scope of practice reforms and expanded telehealth opportunities, each change presents both operational challenges and opportunities for innovation. By closely monitoring these developments and adapting internal protocols accordingly, practices can maintain compliance, optimize patient care, and ensure sustainability in a rapidly evolving environment.
1. Stark Law and Anti-Kickback Statute Updates
The Centers for Medicare & Medicaid Services (CMS) and the Office of Inspector General (OIG) have implemented crucial revisions to the Stark Law and Anti-Kickback Statute regulations. The updates aim to facilitate value-based arrangements while maintaining strong safeguards against fraud and abuse. These changes allow for greater flexibility in structuring physician compensation and the use of ancillary services, as long as arrangements are designed to improve quality and efficiency. However, practices must continue to exercise caution and ensure compliance with specific exceptions and safe harbors.
In light of these regulatory enhancements, medical practices must thoroughly evaluate how their current arrangements align with the updated standards. This includes reviewing contracts with physicians and ancillary service providers to confirm that any value-based incentives or shared savings models meet the newly defined criteria for permissible practices. Enhanced documentation and regular compliance audits are recommended to ensure that all compensation structures remain within the boundaries of the law and that practices are prepared for potential regulatory scrutiny.
Additionally, the changes reinforce the importance of transparency and accountability in financial relationships. Practices should implement training programs for staff and leadership to ensure a clear understanding of the revised regulations, focusing on the practical implications for day-to-day operations. By fostering a culture of compliance and staying informed about ongoing regulatory updates, organizations can mitigate risks and leverage new opportunities presented by the evolving value-based care landscape.
2. State-Level Scope of Practice Reforms
Several states have enacted laws expanding the scope of practice for nurse practitioners, physician assistants, and other non-physician providers. These reforms are intended to address workforce shortages and improve patient access to care. Medical practices should review their organizational structures and supervision protocols to align with the new regulations, which may also affect how ancillary services are delivered and billed.
In addition, as states refine these scope of practice laws, medical practices must stay alert to evolving supervisory requirements and collaborative agreements, as well as any changes to credentialing standards for non-physician providers. It is essential for organizations to update internal policies and procedures to reflect these legal adjustments, ensuring that all clinical staff operate within their authorized scope and that documentation supports compliance with both state and payer expectations. These proactive steps will position practices to adapt efficiently to the regulatory landscape while continuing to provide high-quality, accessible care to their patient populations.
As the scope of practice for non-physician providers broadens, medical practices may also encounter changes in liability, risk management, and insurance requirements. It is advisable for organizations to consult with risk professionals and legal advisors to assess how these new laws may impact malpractice coverage and the delegation of clinical responsibilities. Establishing clear protocols for communication and decision-making can help mitigate potential risks associated with expanded provider roles.
Furthermore, ongoing education and training for both clinical and administrative staff remain critical as scope of practice regulations evolve. Regularly scheduled workshops or updates can ensure that all team members are aware of the latest requirements, fostering a collaborative environment that prioritizes compliance and patient safety. By investing in continuous professional development and updating onboarding materials to reflect new legal standards, practices can support their staff in delivering care that meets both regulatory and quality benchmarks.
Ultimately, adapting to state-level scope of practice reforms presents both a challenge and an opportunity for medical practices. Those that proactively address regulatory updates by revising policies, training staff, and streamlining workflows will be best positioned to enhance patient access, maximize operational efficiency, and maintain legal compliance in a changing health care landscape.
3. Telehealth Expansion and Reimbursement Policies
The regulatory environment for telehealth continues to shift, with many temporary waivers granted during the COVID-19 public health emergency now being codified or extended. Both Medicare and some commercial payers are expanding coverage for telemedicine visits and related ancillary services such as remote patient monitoring. Practices integrating telehealth must ensure compliance with licensure, privacy, and billing requirements, as these remain areas of regulatory focus.
As telehealth becomes a more integral part of care delivery, practices must also monitor state and federal legislative updates that may further influence how telemedicine services are provided and reimbursed. This includes staying current with evolving technology standards, addressing cross-state licensure challenges, and adapting to payer-specific requirements for claim submission and documentation. By proactively updating protocols and engaging in ongoing staff training, organizations can ensure that telehealth services remain compliant, efficient, and accessible for patients, while also supporting broader organizational goals for quality and innovation.
In addition to regulatory compliance, medical practices should evaluate the operational impact of telehealth expansion on ancillary services. For example, remote patient monitoring, virtual consultations, and digital diagnostics can enhance patient engagement and improve clinical outcomes, but they also require robust technology infrastructure and secure data management processes. Establishing clear workflows for scheduling, documenting, and billing telehealth encounters will help practices avoid errors and ensure appropriate reimbursement.
Furthermore, practices should consider the implications of telehealth on patient privacy and data security, especially in light of evolving HIPAA guidelines and state-specific privacy laws. Implementing end-to-end encryption, multi-factor authentication, and regular cybersecurity training for staff can help safeguard patient information during virtual visits.
Finally, as patient expectations for convenience and accessibility continue to rise, practices embracing telehealth are well-positioned to attract and retain patients. By prioritizing user-friendly technology platforms, offering technical support, and soliciting patient feedback, organizations can enhance the overall telemedicine experience. Ongoing evaluation of telehealth services and outcomes will allow practices to refine their offerings and remain competitive as the regulatory and reimbursement landscape continues to evolve.
4. Corporate Practice of Medicine and Management Services Organizations
States continue to clarify and, in some cases, tighten restrictions around the corporate practice of medicine (CPOM). Recent enforcement actions underscore the importance of structuring management services organizations (MSOs) and related entities in ways that do not violate CPOM prohibitions. Medical practices should consult legal counsel to confirm that their business relationships with ancillary service providers adhere to these evolving standards.
To mitigate risks associated with CPOM, organizations should regularly review their contractual arrangements and operational structures. This includes ensuring that all clinical decision-making remains under the control of licensed physicians, while MSOs and other non-clinical partners limit their activities to administrative and business support functions. Clear documentation of these boundaries, as well as periodic audits of management arrangements, can help practices demonstrate compliance in the event of regulatory scrutiny.
Additionally, as enforcement priorities shift, practices in multiple states must pay close attention to varying state-specific definitions and interpretations of CPOM. Maintaining open lines of communication with legal and compliance experts can help organizations respond quickly to regulatory changes and avoid unintentional violations. By fostering a culture of transparency and compliance, medical practices can safeguard their operations and continue to deliver high-quality patient care within the boundaries of the law.
5. Ancillary Service Billing and Compliance
The OIG and Department of Justice have increased scrutiny of billing practices related to ancillary services, such as laboratory testing, imaging, and physical therapy. Recent settlements highlight the risks associated with improper billing, upcoding, or the provision of medically unnecessary services. Practices must review their compliance programs and ensure that all ancillary service arrangements are properly documented and justified.
To further support compliance, organizations should implement regular internal audits of their ancillary service billing and coding processes. These reviews help identify discrepancies and potential areas of risk before they escalate into legal or financial issues. Providing ongoing education and training for staff involved in billing, coding, and documentation is also crucial, as regulatory requirements and payer policies frequently change.
In addition, practices should develop clear protocols for verifying medical necessity and obtaining appropriate documentation for all ancillary services rendered. Leveraging technology, such as electronic health records and billing software with built-in compliance checks, can streamline these processes and reduce the likelihood of errors. Engaging compliance officers or external consultants to periodically review ancillary service arrangements can provide valuable insights and help maintain adherence to federal and state regulations.
Ultimately, a proactive approach to ancillary service billing and compliance not only minimizes regulatory risk but also supports the delivery of high-quality patient care. By fostering a culture of transparency and accountability, medical practices position themselves to respond effectively to evolving enforcement priorities and maintain trust with patients and payers.
Conclusion
Recent regulatory developments are reshaping the landscape for medical practices and their ancillary services. Staying informed and proactive in adapting to these changes is essential for maintaining compliance and optimizing practice operations. We recommend consulting with legal and compliance experts to ensure your practice is prepared for both current and future regulatory shifts.
Thank you for reading. For more information or to discuss how these changes may affect your practice, please contact our health care advisory team.
Since 2019, the United States federal government has taken significant steps to shape the future of artificial intelligence (AI) through a series of executive orders and policy memoranda. These Federal actions on AI have been designed to provide clear direction for the development, deployment, and oversight of AI technologies within federal agencies. The primary objectives of these initiatives are to promote American leadership in the field of AI, create robust ethical and technical standards, and protect civil liberties. By guiding the responsible integration of AI into public services, federal policies aim to ensure that innovation is balanced with accountability and the public good.
Executive Order: Maintaining American Leadership in Artificial Intelligence – February 2019
Executive Order 13,859, February 2019, established the American AI Initiative, initiating a coordinated federal strategy to enhance the United States’ position in artificial intelligence. The order directed federal agencies to focus on advancing AI research and development, encouraging agencies to increase investment and support for breakthroughs in the field. It also placed a strong emphasis on fostering collaboration between the public and private sectors to accelerate innovation and the practical application of AI technologies.
A critical component of this initiative was the creation of education and training programs aimed at building a skilled workforce prepared for the evolving demands of an AI-driven economy. The order recognized workforce development as essential for U.S. competitiveness, supporting Americans in adapting to jobs impacted by AI advancements.
To promote trustworthy AI, the executive order emphasized the development and adoption of technical standards and ethical guidelines. These measures were designed to ensure that AI systems are safe, secure, fair, and reliable in their operation and outcomes. Moreover, the order called for the removal of outdated regulations that might impede AI innovation, streamlining processes to facilitate technological progress.
International collaboration was another key element, as the order encouraged working with global partners to advance U.S. values in AI on the world stage. Throughout all efforts, the order underscored the importance of protecting civil liberties and privacy during the development and deployment of AI systems. By establishing these priorities, Executive Order 13,859 laid a strong foundation for future federal AI policy, focusing on investment, ethics, and collaboration to sustain American leadership in artificial intelligence.
Advance artificial intelligence research by increasing federal investment and supporting significant technological breakthroughs.
Facilitate workforce development initiatives to equip Americans for employment opportunities influenced by AI advancements.
Foster trustworthy artificial intelligence through the establishment of technical standards and the adoption of ethical guidelines that ensure system safety, security, fairness, and reliability.
Eliminate regulatory obstacles that hinder innovation in artificial intelligence.
Maintain international leadership by collaborating with global partners to promote U.S. values in the field of artificial intelligence.
Safeguard civil liberties and privacy throughout the development and deployment of AI technologies.
OMB Memorandum M-21-06 (November 2020): Guidance for Regulation of Artificial Intelligence Applications
The Office of Management and Budget (OMB) released Memorandum M-21-06 in November 2020 to offer federal agencies a clear framework for regulating artificial intelligence applications. This memorandum addressed both regulatory and non-regulatory strategies, aiming to support agencies in the responsible oversight of AI technologies. Central to the guidance were ten stewardship principles that agencies are encouraged to uphold throughout the development and deployment of AI systems.
The following principles guide the responsible development and governance of artificial intelligence:
Foster public trust in AI by implementing transparent and accountable practices.
Encourage meaningful public engagement to ensure AI applications address diverse needs and perspectives.
Uphold scientific integrity throughout AI research and deployment.
Perform comprehensive risk assessments to identify and mitigate potential harms related to AI use.
Assess both the benefits and costs of AI to support well-informed, balanced decision-making.
Maintain adaptable regulatory frameworks that keep pace with technological advancements.
Ensure fairness in both the deployment and impact of AI systems.
Increase transparency regarding AI processes, decisions, and outcomes.
Prioritize safety in all stages of AI technology development and operation.
Promote effective interagency coordination for cohesive federal AI governance.
Through these stewardship principles, Memorandum M-21-06 seeks to reduce unnecessary barriers to AI innovation while maintaining responsible stewardship and ensuring that public accountability remains at the forefront of federal AI initiatives.
Executive Order 13,960 (December 2020): Promoting the Use of Trustworthy Artificial Intelligence in the Federal Government
Executive Order 13,960 established a comprehensive framework for the federal government’s use of artificial intelligence (AI), prioritizing the interests and well-being of the American public. The order emphasized the need to protect privacy, uphold civil rights, and maintain core American values throughout the adoption and implementation of AI technologies.
To guide federal agencies, the order identified nine foundational principles for the design, development, acquisition, and use of AI. These principles served as a blueprint to ensure that AI systems deployed by the government were trustworthy, ethical, and aligned with the nation’s values. Agencies were required to rigorously apply these principles at every stage of their AI initiatives.
In addition, Executive Order 13,960 mandated federal agencies to publicly disclose their AI use cases. This commitment to openness aimed to foster greater transparency and build public trust in the government’s use of AI. By making information about AI applications accessible to the public, the order sought to ensure accountability and demonstrate the responsible stewardship of emerging technologies in service of the American people.
Executive Order 14,110 (October 2023): Safe, Secure, and Trustworthy Development and Use of AI
Guiding Principles for Federal AI Advancement
Executive Order 14,110 established eight guiding principles to direct federal agencies in the progress and governance of artificial intelligence. These principles emphasize the creation of clear guidelines and best practices for the safe, secure, and trustworthy utilization of AI technologies. The order requires agencies to build risk management frameworks, with special attention to generative AI, and to initiate programs that rigorously evaluate AI capabilities for safety and the prevention of harm. It further mandates close collaboration among key stakeholders—including the Secretary of Commerce, the National Institute of Standards and Technology, and the Secretary of Energy—to develop industry standards and ensure secure practices across AI applications.
Federal Implementation and Oversight Measures
In alignment with these directives, federal agencies have broadened their efforts to integrate AI responsibly within government operations. This includes the development of comprehensive implementation plans, the appointment of chief AI officers to oversee agency AI activities, and active engagement with both external experts and the public. These measures are designed to enhance transparency, strengthen accountability, improve the quality of data, and foster regulatory environments that support innovation. Additionally, the order calls for the establishment of mechanisms to continuously monitor and assess the performance and impact of AI systems. Collectively, these initiatives reinforce the federal government’s commitment to advancing AI in a manner that upholds democratic values, supports national competitiveness, builds public trust, and protects individual rights.
Executive Order 14,210 (April 2025): Advancing Responsible Artificial Intelligence in Federal Operations
Executive Order 14,210 was issued in response to the rapid evolution of AI technologies and their growing influence on public services. Building upon previous federal directives, this order required the establishment of unified federal standards to ensure AI safety, ethical use, and robust data protection across all agencies. To further these objectives, every federal agency must implement comprehensive risk management protocols for AI, prioritize the inclusive and equitable deployment of AI systems, and boost transparency by providing annual public reports on the performance and societal impact of AI applications within their operations.
Key Provisions
Emphasize human oversight in the operation and decision-making processes of AI systems to maintain accountability and ensure alignment with public values.
Promote equitable access to AI-enabled services, ensuring that all members of the public can benefit from advancements in AI regardless of background or status.
Increase investments in workforce training programs, with a particular focus on AI literacy and safety, to prepare federal employees to manage and oversee AI technologies responsibly.
Conduct regular audits of AI algorithms to detect and address potential biases, thereby supporting the development of fair and trustworthy AI systems.
Establish advisory committees comprised of diverse stakeholders, providing continued guidance for policy development and ensuring that a wide range of perspectives inform the federal AI agenda.
The order further created a federal AI oversight committee responsible for reviewing agency compliance with these mandates and promoting collaboration across sectors. This committee plays a crucial role in addressing emerging challenges related to algorithmic discrimination and broader systemic risks associated with AI. By reinforcing robust accountability mechanisms and supporting innovation, Executive Order 14,210 is designed to ensure that the integration of AI technologies within federal operations upholds democratic values, strengthens public trust, and advances the well-being of society as a whole.
Conclusion
Collectively, these federal actions establish a comprehensive approach to AI governance, ensuring that technological advancements align with democratic values and societal needs. Regular assessments and transparent reporting encourage agencies to address challenges such as algorithmic bias and data security vulnerabilities. This ongoing commitment to responsible stewardship is critical to maintaining public confidence as AI becomes increasingly integrated into government operations and services.
What Organisations Should Know as AI is Changing False Claims Act Fraud Risk, Compliance Operations and Enforcement
Artificial intelligence is AI is Changing False Claims Act enforcement and the way organizations identify compliance risk. The government was already on the path to implementing AI solutions for fraud detection before AI emerged as an available tool to detect potential fraud. For healthcare providers, government contractors, and other recipients of federal funds, that shift matters because the False Claims Act remains one of the government’s most powerful enforcement tools.
AI can help organizations strengthen internal controls, detect billing or contracting issues earlier, and respond more efficiently to potential problems. It can also make government investigations faster and more data-driven.
The federal False Claims Act is the government’s primary civil anti-fraud law for addressing false or misleading claims for payment submitted to federal programs or contracts. In simple terms, it allows the government—and in some cases private whistleblowers acting on the government’s behalf through qui tam lawsuits—to pursue companies or individuals that knowingly seek federal funds they are not entitled to receive.
Just as importantly, a company’s failure to maintain an effective compliance program can be powerful evidence of the knowledge required to support liability. Violations can lead to repayment, significant civil penalties, and treble damages, which helps explain why the statute remains such a powerful enforcement tool.
For example, if a contractor knowingly bills Medicare for medical services that were never provided, the government can use the False Claims Act to recover the money and impose additional penalties.
The False Claims Act is a primary federal anti-fraud law.
It applies to knowingly false or misleading claims for federal payment.
Whistleblowers may bring qui tam actions on the government’s behalf.
Weak compliance controls can increase enforcement risk.
Exposure may include repayment, penalties, and treble damages.
What AI Means for Compliance Programs
For many organizations, the most immediate value of AI is in day-to-day compliance monitoring. AI-enabled tools can assist with real-time review of transactions, contracts, and claims, helping compliance teams identify unusual patterns before they become larger problems.
In practice, these tools may include transaction-monitoring platforms that flag anomalous payment activity, claims-integrity systems that identify suspect billing patterns, contract-analytics tools that scan terms for regulatory risk, and NLP-based review tools that analyze emails, policies, and other documentation for warning signs. Organizations may use platforms such as AuditBoard or Hyperproof for continuous control monitoring, while healthcare payers increasingly rely on AI-enabled claims-integrity and fraud, waste, and abuse detection platforms to surface improper billing before or after payment.
Used well, these tools can help compliance teams prioritize risk, reduce manual review burdens, and improve the consistency of internal oversight. Machine learning can identify anomalies across large datasets, natural language processing can assist in reviewing internal documentation and communications, and predictive analytics can help direct attention to issues that warrant further investigation. At the same time, AI should support—not replace—sound compliance judgment, escalation procedures, and human review.
How AI Can Increase Enforcement Risk
AI does not only benefit companies; it also gives enforcement agencies more efficient ways to identify and investigate potential False Claims Act violations. Automated data analysis can help uncover patterns associated with false claims, kickbacks, inaccurate certifications, or other misrepresentations, allowing investigators to focus resources more quickly and strategically. AI may also streamline document review and evidence organization, which can shorten investigative timelines and increase pressure on organizations that lack strong compliance controls, documentation, and remediation processes.
Why False Claims Act Enforcement Continues to Expand
Organizations should expect continued investment in False Claims Act enforcement because both enforcement agencies and oversight bodies continue to emphasize its economic value. In fiscal year 2025, the Department of Justice announced more than $6.8 billion in False Claims Act settlements and judgments, the highest annual total on record, with more than $85 billion recovered since 1986.
More broadly, the federal Inspector General community has reported that its monetary accomplishments represented approximately $18 for every $1 invested in fiscal year 2024, and other government and non-government sources have described similarly strong returns in healthcare fraud and oversight work. Together, those figures help explain why healthcare, government contracting, cybersecurity, and other federally funded activities remain under close scrutiny, and why organizations should treat compliance investments as a core risk-management function rather than a back-office exercise.
Key Considerations When Using AI in Compliance
AI can be a valuable compliance tool, but it also raises practical legal and operational issues. Before relying on AI in sensitive compliance functions, organizations should focus on the basics below.
Data quality and reliability of the inputs used by the tool
Privacy and confidentiality risks when sensitive data is processed
Documentation showing how outputs are reviewed and used
Validation and testing to confirm the tool performs as intended
Oversight, escalation, and human review for high-risk decisions
Key Takeaways
AI can strengthen compliance monitoring and help surface problems earlier.
The same technology can also make government investigations more efficient.
Organizations should pair AI tools with clear documentation, oversight, and human judgment.
As AI becomes more embedded in compliance and enforcement, organizations should assume that both internal monitoring expectations and external investigative capabilities will continue to increase. The practical question is no longer whether AI will affect False Claims Act risk, but whether an organization is using the technology carefully enough—and documenting its compliance efforts clearly enough—to reduce exposure when issues arise.
A common error in telehealth corporate practice of medicine planning is assuming that a structure accepted in one state will be appropriate in all jurisdictions. CPOM rules vary substantially. Some states strictly limit non-physician ownership or control of medical practices. Others apply the doctrine more narrowly or focus more heavily on fee-splitting, licensure, or professional entity requirements. Enforcement priorities may also evolve as virtual care models, direct-to-consumer platforms, and investor-backed health care businesses continue to expand.
Practical state-by-state review should address ownership, clinical control, employment of professionals, permissible entity types, management fee restrictions, referral rules, advertising requirements, professional board guidance, and payor contracting implications. The analysis should also be refreshed when the company adds a new service line, begins treating patients in a new jurisdiction, changes compensation, or enters into a new marketing or platform relationship.
For a multi-state telehealth company, this means expansion should include a legal map of where services will be provided, which clinicians will deliver care, what professional entities are required, whether local ownership or supervision rules apply, and how administrative fees may be structured. A launch plan that does not account for state variation may create operational delays when the company seeks payor contracts, investor financing, acquisition diligence, or regulatory approval.
A Comprehensive Examination of Regulatory Implications and Practical Considerations for Ambulatory Surgery Centers
Are you a physician investor or operator of an ambulatory surgery center (ASC) seeking guidance on the 1/3 income test and compliance with federal anti-kickback statutes?
The 2023 Frequently Asked Questions (FAQ) regarding ASC safe harbors delivers essential insights for healthcare professionals navigating these regulatory requirements.
In this blog post, we explore the background, key regulatory framework, the consequences of failing the 1/3 income test, and practical compliance tips to help you avoid legal risks and maintain ASC investment integrity.
Background: ASC Safe Harbors and the 1/3 Income Test
Ambulatory Surgery Centers (ASCs) have become a cornerstone of the U.S. healthcare system, offering efficient, cost-effective outpatient surgical care. To foster legitimate investment and operational arrangements, the federal government has established safe harbors under the Anti-Kickback Statute (AKS), shielding certain financial relationships from prosecution if specific requirements are met. Among these requirements is the “one-third income test,” which mandates that each physician investor in the ASC must derive at least one-third of their annual medical practice income from performing procedures at the ASC in which they invest.
The 2023 FAQ: Key Insights
The 2023 FAQ clarifies that failure to meet the 1/3 income test does not, in itself, constitute a violation of the AKS. Rather, it means the physician’s investment arrangement loses the protection of the safe harbor, subjecting it to potential scrutiny under the AKS. The FAQ emphasizes that arrangements falling outside the safe harbor are not inherently illegal; instead, they are evaluated based on the totality of the circumstances, including intent, remuneration, and referral patterns.
Regulatory Implications of Failing the Test
Failing the 1/3 income test exposes physician investors and ASC operators to increased regulatory risk. Without safe harbor protection, the Office of Inspector General (OIG) and the Department of Justice (DOJ) may review the arrangement for evidence of improper inducement for referrals or other prohibited conduct. The FAQ underscores the importance of maintaining appropriate documentation and ensuring that all arrangements are commercially reasonable, with fair market value compensation and no linkage between investment returns and referral volume.
Practical Considerations for Compliance
ASC operators and physician investors should proactively monitor compliance with the 1/3 income test throughout the fiscal year. If a physician is at risk of failing the test, it is advisable to seek legal counsel, review the structure of the investment, and implement corrective actions. These may include divestiture, reallocation of ownership interests, or reclassification of the physician’s status. The 2023 FAQ also suggests that transparent communication and robust compliance programs can help mitigate enforcement risks.
Tips for ASC Compliance
Stay up to date with ASC regulatory changes and anti-kickback statute guidelines.
Regularly review physician income distribution to ensure compliance with the 1/3 income test.
Implement strong documentation practices and seek legal counsel when investment arrangements change.
Promote transparency and maintain clear communication among ASC investors and operators.
Develop and maintain robust compliance programs to minimize regulatory risk.
By following these best practices, ASC stakeholders can confidently navigate the complexities of federal regulations and optimize their operations for compliance and sustainable growth. For more expert updates and guidance on ASC safe harbors, subscribe to our blog and stay informed on the latest healthcare compliance news.