In late 2025, significant new ambulatory surgery center regulations were issued, marking a pivotal shift in the landscape of outpatient surgical care in the United States. These updates, implemented by federal and state health authorities, aim to enhance patient safety, improve quality of care, and ensure greater transparency and accountability within the ambulatory surgery sector.
Key Changes in the 2025 Ambulatory Surgery Center Regulations
The new ambulatory surgery center Regulations stricter requirements across several operational and clinical domains. Among the most notable changes are enhanced infection control protocols, updated emergency preparedness plans, and more rigorous credentialing standards for medical staff.
The rules also require ASCs to adopt advanced electronic health record (EHR) systems to improve data sharing and patient tracking, aligning with broader healthcare digitization efforts.
This update highlights the recent changes required by the new ambulatory surgery center regulations.
Stay tuned for more posts covering this very significant regulatory change.
Patient Safety and Quality Improvements
Patient safety is at the core of the 2025 regulatory updates. ASCs must now conduct more frequent and comprehensive safety drills, maintain higher standards for sterilization, and implement regular audits of procedural outcomes. Additionally, the regulations mandate transparent reporting of adverse events and surgical complications, facilitating better oversight and public awareness.
Transparency and Reporting Requirements
To foster greater transparency, the new rules require ASCs to publicly disclose performance metrics, including infection rates, patient satisfaction scores, and surgical outcomes. These reports must be updated quarterly and made accessible to patients and regulatory bodies. The aim is to empower patients to make informed decisions and encourage continuous quality improvement among providers.
Financial and Administrative Compliance
On the administrative side, ASCs face stricter financial reporting obligations, including detailed cost breakdowns for common procedures and disclosure of ownership structures. Compliance with these rules will be monitored through regular audits and unannounced inspections, with penalties for non-compliance ranging from fines to suspension of operating licenses.
Impact of New Regulations on ASC Operations
The introduction of these regulations is expected to raise operational costs for ASCs, particularly smaller centers that must invest in new technology and staff training. However, proponents argue that the long-term benefits—such as reduced complications, higher patient satisfaction, and improved public trust—will outweigh the initial challenges. Many ASCs have already begun updating their policies and investing in compliance initiatives to meet the new requirements ahead of enforcement deadlines in 2026.
Looking Ahead
To comply with the new regulations, ambulatory surgery centers should move quickly from awareness to action: assess current policies against the updated requirements, strengthen infection control and emergency preparedness procedures, verify staff credentialing and training records, upgrade EHR and reporting capabilities, and prepare for audits or inspections well ahead of enforcement deadlines. By treating compliance as an operational priority rather than a one-time administrative task, ASCs can reduce regulatory risk while supporting safer, more transparent, and higher-quality outpatient surgical care.
Keep your eye on our site for more details or contact Ambulatory Surgery Center Lawyer John Fisher through the contact page on this site.
How AI Can Mitigate or Create Fraud and Abuse Risks in the Healthcare Industry
The age of Artificial Intelligence is clearly upon us. Unless you are living in a cave it would be impossible not to understand that it will have an enormous impact on nearly every aspect of society, including the healthcare sector. It will have major economic and societal impacts. Some will be for the better and perhaps some “not so much.”
Artificial Intelligence is in use by the federal and state governments to detect patterns that may indicate potential fraud and abuse in the healthcare system. Health care providers are rushing to implement Artificial Intelligence as part of their operations and as part of their proactive corporate compliance program. Use of AI to detect fraud as part of a compliance program has become standard of care, particularly for larger organizations. Failure to use these tools to detect billing anomalies and other potential fraud and abuse could be used to impute knowledge of wrongdoing and trigger Federal False Claims Act liability.
What Is Artificial Intelligence (AI)?
Artificial Intelligence (AI), as defined in Executive Order 13960 and Section 238(g) of the National Defense Authorization Act (NDAA) of 2019, refers to artificial systems capable of performing tasks across diverse and unpredictable environments with limited human intervention, or systems that improve their performance by learning from new data and experiences. These systems may be implemented through software, hardware, or hybrid forms, and are developed to address challenges requiring capabilities such as human-like perception, cognition, planning, learning, communication, or physical action.
AI solutions are engineered to model or replicate human cognitive functions through architectures like neural networks and other advanced computational methods. Machine learning is a central technique that enables AI systems to approximate sophisticated cognitive processes. Additionally, the field encompasses systems designed for rational behavior, including intelligent agents and autonomous robots, which achieve specific objectives via perception, reasoning, planning, learning, communication, decision-making, and operational actions.
The concept of AI is frequently characterized as the emulation of human intelligence, encompassing faculties such as learning, complex problem-solving, rational behavior, autonomous execution, adaptability, and imitation of human activities. AI includes a broad range of sub-disciplines, each dedicated to replicating particular human abilities: natural language processing empowers systems to interpret and generate human languages; computer vision equips machines to analyze visual inputs; robotics integrates perception, analytical reasoning, and actuation; and reinforcement learning enables systems to enhance their behaviors based on environmental feedback.
AI systems are generally classified as either narrow—designed for specific, well-defined applications—or general, aimed at achieving flexible and adaptive performance comparable to human intelligence. At present, most leading AI technologies remain specialized; however, ongoing research is increasingly directed at developing broader, more contextually intelligent systems. As the field advances, ethical considerations, explainability, and transparency have become central concerns, with stakeholders demanding deeper understanding of system decision-making processes and operations.
In summary, artificial intelligence constitutes a dynamic and multidisciplinary field, drawing on knowledge from computer science, cognitive psychology, mathematics, engineering, and philosophy. Continued progress in AI consistently redefines the boundaries of machine capability, creating substantial opportunities while introducing new complexities across affected industries.
AI’s Potential to Transform Healthcare
Artificial intelligence (AI) has significant potential to transform various aspects of healthcare delivery. Its influence extends across administrative workflows, insurance verification, clinical decision support, reimbursable services, patient engagement, data analysis, revenue cycle management, billing, coding, compliance, care access, and scheduling. AI also contributes to reducing administrative burdens and after-hours documentation for physicians, which may help mitigate professional burnout and potentially enhance lifestyle.
As AI is increasingly integrated into healthcare systems, its impact is expected to be substantial. AI-driven solutions are already enhancing clinical workflows by increasing efficiency and facilitating the interpretation of large-scale patient data. Looking ahead, AI is poised to further advance healthcare through several key domains:
Diagnostic Accuracy: Machine learning algorithms can rapidly and accurately analyze medical images, laboratory results, and detailed patient histories, supporting clinicians in earlier and more precise diagnosis. Decision support systems powered by AI synthesize evidence-based recommendations from research and patient data to inform personalized treatment strategies.
Predictive Analytics: AI technologies can anticipate health events—such as hospital readmissions, adverse drug reactions, and disease outbreaks—by detecting patterns that might elude human analysis. This predictive capability enables proactive interventions and more effective resource allocation.
Administrative Efficiency: AI streamlines essential processes including scheduling, coding, billing, and compliance review, thereby decreasing clerical workloads. Automated virtual assistants can manage appointments, address patient inquiries, and facilitate follow-up care, resulting in improved provider productivity and enhanced patient engagement.
Expanding Access to Care: Telemedicine platforms powered by AI can triage patient symptoms, guide self-care practices, and connect individuals with specialists regardless of geographic limitations. Furthermore, natural language processing tools can translate medical information and simplify terminology to improve communication and comprehension for patients.
The integration of AI within healthcare is deepening, driving efficiency and accuracy while fostering a shift toward personalized, preventive, and accessible medicine. As these technologies continue to evolve, their capacity to learn from diverse datasets, adapt to new developments, and deliver real-time insights will empower clinicians to address emerging health challenges and deliver higher-quality care.
Despite its transformative promise, the adoption of AI in healthcare also raises important challenges. Issues related to data privacy, algorithmic bias, and the need for rigorous validation of AI tools must be addressed to ensure patient safety and equitable care. Additionally, integrating AI into clinical practice requires ongoing training for healthcare professionals and robust regulatory frameworks to oversee the deployment and monitoring of AI-driven solutions. Balancing innovation with ethical responsibility will be essential as AI continues to shape the future of healthcare delivery.
Furthermore, AI-enabled remote monitoring tools and wearable devices are increasingly being used to track patient health metrics in real time, allowing for early detection of complications and more responsive care. These advancements not only support continuous patient monitoring outside traditional clinical settings but also enable healthcare providers to deliver more timely and tailored interventions. As AI-driven innovations proliferate, collaborative efforts between technologists, clinicians, and policymakers will be critical to maximize benefits while addressing emerging ethical and operational concerns.
Summary
Artificial intelligence is revolutionizing healthcare by streamlining administrative tasks, enhancing diagnostic accuracy, enabling predictive analytics, and expanding access to care through telemedicine and remote monitoring. While AI promises improved efficiency, personalized treatment, and proactive interventions, its adoption presents challenges such as data privacy, algorithmic bias, and the need for strong regulatory oversight. Ongoing collaboration and ethical considerations are essential to harness AI’s full potential in delivering high-quality, equitable healthcare.
The Department of Justice (DOJ) uses resource allocation as a key measure when evaluating the effectiveness of compliance programs. Allocating sufficient resources to the compliance function is foundational to any systematic compliance initiative and remains central as regulatory expectations evolve. The DOJ assesses resource allocation alongside compliance officer autonomy, highlighting the strong connection between these two factors in achieving effective compliance oversight.
Compliance Officer Authority and Autonomy: Cornerstones of Effectiveness
For a compliance program to function effectively, the compliance officer must have both the authority and autonomy necessary to carry out oversight and enforcement duties. Insufficient funding represents a structural weakness that can undermine the credibility and operation of the program. Many organizations reinforce compliance officer autonomy by providing employment protections or financial safeguards in cases of compliance-related terminations or resignations. This autonomy allows compliance officers to address issues throughout the organization without fear of retaliation or loss of resources.
Best practices have long recommended that compliance officers hold senior management positions and report directly to the board of directors. This reporting structure ensures the independence needed to address compliance issues at every organizational level and is increasingly viewed as a hallmark of program effectiveness.
The Interrelationship Between Resource Allocation and Compliance Officer Autonomy
Resource allocation and compliance officer authority are deeply linked. Dedicated funding is necessary to maintain compliance independence; if compliance officers rely on other departments for resources, their ability to operate impartially can be compromised. To ensure true independence, organizations should allocate a segregated budget for compliance activities, allowing the compliance officer to justify expenses directly to the board of directors, rather than seeking supplemental funds from unrelated departments.
DOJ Guidelines: Emphasis on Autonomy and Resource Allocation
DOJ guidelines underscore the importance of compliance officer autonomy and adequate resource allocation. Prosecutors are directed to assess whether compliance personnel:
Hold appropriate seniority within the organization
Have sufficient staff and resources for thorough auditing, documentation, and analysis
Maintain independence from management, such as having direct access to the board or audit committee
Challenges in Compliance Budgeting
Budgeting for compliance is often complex, as these costs do not directly generate new business initiatives and compliance is frequently viewed as a cost center. This makes it difficult for executives to justify compliance expenditures, especially when compared to investments in program expansion or operational improvements. The value of a robust compliance budget often becomes clear only after major incidents, highlighting the need for proactive resource allocation.
Determining Adequate Compliance Resources
The appropriate budget for compliance depends on the organization’s size, structure, and risk profile. There is no universal standard for sufficient funding. The DOJ notes that larger organizations typically require more resources, while smaller entities may operate effectively with fewer formal processes and assets. Industry surveys provide benchmarks but may omit certain costs, such as incident investigations or legal counsel. Ultimately, organizations must use sound judgment to ensure all essential elements—appointing a compliance officer, establishing core processes, identifying risks, and implementing mitigation strategies—are adequately supported, regardless of size.
Scalability Considerations
Organizations, particularly those of mid-size, should be cautious about relying solely on scalability when determining compliance budgets. Failing to address critical risk areas can leave businesses exposed to regulatory scrutiny or whistleblower actions. It is advisable to proactively identify and mitigate risks, regardless of the organization’s size or perceived risk level.
Elements of an Effective Compliance Program
A successful compliance program assesses risk profiles, prioritizes audits and remediation, and works continuously to minimize organizational risks. Smaller entities may require proportionally fewer resources but must still address key risk areas thoroughly.
Segregation of Compliance Budget and Officer Access
The compliance budget should be distinct and not sourced from multiple departments. Direct access to allocated funds allows compliance officers to act independently and responsibly within set budgetary limits, free from undue restrictions on legitimate expenditures. Budgeting should align with the compliance work plan and reflect the organization’s stage of compliance development. Organizations new to compliance may need additional support to address emerging issues and build robust procedures.
Supporting Board Oversight with Expert Resources
A well-structured compliance budget should ensure the board of directors has access to specialized expertise in relevant regulatory areas. Prosecutors will review whether companies have invested in qualified personnel and consultative support tailored to industry-specific risks. For instance, healthcare organizations should prioritize legal professionals with experience in health law to support both compliance operations and board decision-making. Organizations facing budget constraints may consider non-specialized counsel, but this could compromise compliance oversight and increase regulatory risk for the board.
Key Questions for Prosecutors Assessing Compliance Budgeting and Autonomy
The DOJ provides guidance for prosecutors to evaluate whether compliance offices are adequately funded and sufficiently autonomous. Key questions include:
Structure: Where is the compliance function located within the company? To whom does it report? Is it led by a designated chief compliance officer, and does this individual hold other roles? Are compliance personnel solely dedicated to compliance or do they have additional responsibilities? What is the rationale for the chosen structure?
Seniority and Stature: How does the compliance function’s status compare to other strategic units in terms of rank, compensation, resources, and influence? What is the turnover among compliance staff? How is compliance integrated into strategic and operational decisions? How does the company respond to compliance concerns? Have transactions been modified as a result of compliance interventions?
Experience and Qualifications: Do compliance staff have appropriate qualifications and experience? How have these attributes evolved? How is performance evaluated and by whom?
Funding and Resources: Is staffing sufficient for necessary compliance activities? Has the company provided adequate funding? If requests were denied, what was the rationale?
Autonomy: Do compliance and control functions report directly to the board or audit committee? How frequently are meetings held, and is senior management present? What measures support the independence of compliance personnel?
Conclusion
Organizations should design and manage compliance programs with the expectation that they may need to demonstrate program effectiveness in regulatory proceedings, such as False Claims Act or Fraud and Abuse cases. High-stakes situations require clear evidence of robust compliance. Programs lacking segregated budgets and independent authority face significant challenges in proving effectiveness before regulators. Proactive, properly resourced compliance programs are essential for mitigating risk and protecting organizational integrity.
The Affordable Care Act (ACA) imposes specific requirements on individuals and entities that receive overpayments from designated government health programs. Under the ACA, any person who has received an overpayment from programs such as Medicare Part A, Medicare Part B, Medicare Advantage, Medicaid Fee-for-Service, and Medicaid Managed Care is required to report and return the overpayment within 60 days after the overpayment is identified. Failure to repay or self-disclose the overpayment within this 60-day window results in the amount becoming subject to penalties under the federal False Claims Act (FCA).
False Claims Act Penalties
The FCA is a federal law that enforces strict penalties for non-compliance with overpayment repayment obligations. Specifically, the FCA imposes damages amounting to three times the actual overpayment, in addition to a per-claim penalty that ranges from approximately $11,000 to $22,000. These substantial penalties serve as a strong incentive for providers to promptly self-disclose and repay any identified overpayments.
Importance of Effective Compliance Programs
Given the severity of FCA penalties, providers are strongly incentivized to operate effective compliance programs. The FCA applies a “should know” standard, which means that providers are expected to have systems in place to proactively identify and audit potential risk areas. An effective compliance program demonstrates that a provider is making reasonable efforts to detect and address overpayments before they become a liability.
Clarification of the 60-Day Repayment Rule
To avoid FCA penalties, repayment must be made within 60 days after the overpayment is identified or when a corresponding cost report is due. Recent regulations have provided some assistance in defining when a provider is considered to have “identified” an overpayment and when the 60-day period officially begins. However, these clarifications primarily apply to Medicare program overpayments, while regulations specific to Medicaid remain absent.
Scope and Application of Repayment Obligations
The statute’s repayment obligation is broadly applicable and extends clearly to the Medicaid program. Despite this, clarifying regulations have only been adopted for Medicare, leaving providers without guidance on compliance details for Medicaid overpayments. The statutory requirement for Medicaid mandates repayment within 60 days of discovery, but there is no regulatory detail explaining how to fulfill this obligation.
Medicare Parts A and B Final Rule
On February 12, 2016, the Centers for Medicare & Medicaid Services published the Medicare Parts A and B Final Rule. These rules provided important clarifications, such as defining when a provider is deemed to have discovered an overpayment and establishing the length of the “look-back” period. The look-back period determines how far back providers must go to identify overpayments once they suspect an infraction has occurred. While early Medicare regulations set a 10-year look-back, the 2016 rules reduced this to six years for Medicare overpayments. Notably, these regulations explicitly state that they do not apply to Medicaid overpayments, leaving the look-back period for Medicaid undefined.
Unresolved Issues for Medicaid Overpayments
Several critical areas of ambiguity persist regarding Medicaid overpayments. Key among these are the determination of the look-back period and the point at which an overpayment is deemed “identified.” While providers cannot ignore potential overpayments once a problem is identified, there is no guidance on whether the six-year Medicare look-back period, the earlier 10-year period, or another timeframe should apply to Medicaid. Likewise, it remains unclear whether providers can rely on the regulatory interpretations for the start of the 60-day clock for Medicaid overpayments.
Current Practices and Uncertainty
In practice, overpayments are often identified when a specific employee, department, or service area systematically makes a mistake in billing or documentation, and these errors typically span across both Medicare and Medicaid. As it stands, there is regulatory clarification for handling Medicare overpayments, but no similar guidance for Medicaid, resulting in uncertainty for providers.
Potential Approaches for Providers
Providers facing both Medicare and Medicaid overpayments are left to determine how best to fulfill their statutory obligations. Questions remain as to whether they should follow Medicare rules for Medicaid overpayments or await further regulatory guidance. The absence of Medicaid-specific regulations means providers must navigate this uncertainty, knowing that following Medicare regulations may not be fully appropriate or sufficient, and that future test cases could clarify these obligations.
Conclusion
Until Medicaid regulations are released, providers must contend with ongoing uncertainty regarding how to handle Medicaid overpayments. The ACA’s requirements are clear in their broad application, but the lack of regulatory detail for Medicaid repayments means providers must exercise caution and remain vigilant in their compliance efforts.
In the course of some reading on anesthesia billing issues, I came across a case from 2002 that clearly describes how not to handle an employee who alleges that your practice may have a billing problem.
Brandon v. Anesthesia & Pain Management Associates, Ltd., 277 F.3d 936 (2002) involved a physician who became suspicious that other members of his anesthesia group may have been pumping up the billings a bit. Specifically, the physician felt that other members of his group may have been falsifying the number of operations that they were supervising in order to qualify for “medically directed” reimbursement rates. He also alleged that members of the group may have altered billing sheets to indicate that they had performed work, even though they had left the hospital for the day.
It is not clear from the case whether the physician’s allegations were true or proved. However, the reaction of the anesthesia group where the physician raised these issues was far short of ideal from a legal standpoint.
The allegations were raised by the physician during a board meeting. A few weeks after the disclosure, the physician was told that he should start looking for other work. The physician asked for more information on his shortcomings and was not provided with any details. At that point, he began keeping a journal of suspected billing problems. A few months later, the physician was notified that he would be required to leave his job by the end of the year. The physician reiterated his complaints at that point. The complaints were met with strong, vulgar language (which you can read in the case). He was told that he did not have a contract and that the group would make life difficult for him if he did not resign.
The group was found to have violated Illinois’ retaliatory discharge laws for taking action against the physician who had alleged billing fraud. The court upheld the state law claim even though the Federal False Claims Act provided a civil remedy for the physician.
It should be pointed out that the physician had a possible claim as a “qui tam” litigant under the False Claim Act, assuming the facts described in the complaint were true.
This case provides a textbook example of how “not to” address employee allegations of billing deficiencies. All such allegations should be taken seriously and investigated. Your practice should adopt compliance policies to provide procedures to follow when employees or others make complaints. Handling complaints in the manner of the group in this case, exposes the group to a great deal of unnecessary risk. Once a complaint is made, make sure is it investigated. If there is a problem, take appropriate steps to remedy the situation. In some cases, this may require self-disclosure and repayment. When in doubt about what to do, consult your health care compliance attorney.
DOJ Limits Use of Agency Guidance in Civil Enforcement
Key Takeaway: Recent federal developments may provide health care providers with additional flexibility in meeting certain regulatory requirements. Most notably, the U.S. Department of Justice (DOJ) has limited how its attorneys may rely on agency guidance in civil enforcement actions, while the Bipartisan Budget Act of 2018 codifies flexibility for several technical Stark Law requirements.
Health care providers have long faced compliance risk where federal agencies issued guidance documents that were later used in enforcement matters as evidence of legal obligations. That approach is changing. In November 2017, U.S. Attorney General Jeff Sessions issued a memorandum stating that DOJ guidance documents may not create binding rights or obligations for parties outside the Executive Branch.
In January, Associate Attorney General Rachel Brand reinforced that position in what is now commonly referred to as the “Brand Memo.” The memo directs DOJ litigators not to use agency guidance documents to create “de facto regulations” and not to prove a violation of law based solely on a party’s failure to comply with guidance.
Why this matters: The change may reduce enforcement risk tied to informal agency interpretations that have not gone through formal rulemaking. DOJ attorneys may still rely on statutes, regulations, and other binding legal authorities, but agency guidance alone should no longer serve as the basis for proving noncompliance.
Stark Law Changes Provide Technical Compliance Flexibility
The Bipartisan Budget Act of 2018 also provides relief for certain technical requirements under the Stark Law. The changes largely codify prior Centers for Medicare & Medicaid Services (CMS) guidance and regulations addressing written agreements, signatures, and holdover arrangements.
The Stark Law generally requires certain physician compensation arrangements to satisfy an applicable exception, many of which include strict writing and signature requirements. Historically, otherwise compliant arrangements could create risk if documentation was incomplete, unsigned, or not contained in a single agreement.
Under the Budget Act, the writing requirement may be satisfied through a “collection of documents,” including contemporaneous records showing the parties’ course of conduct. The Act also allows required signatures to be obtained within 90 days after the arrangement should have been signed, provided the arrangement otherwise satisfies the applicable Stark Law exception.
The Budget Act further allows certain expired office space leases, equipment leases, and personal services arrangements to remain protected during a holdover period, so long as the arrangement continues on the same terms and conditions.
Practical impact: These revisions may help providers avoid disproportionate consequences for technical documentation defects, particularly where the underlying arrangement otherwise complies with Stark Law requirements. Providers should not treat the changes as eliminating documentation obligations, but they may offer useful flexibility when reviewing existing physician arrangements.
Recommended Next Steps for Providers
Review current physician compensation arrangements, leases, and personal services agreements for documentation gaps.
Confirm that any reliance on agency guidance is distinguished from binding statutory or regulatory requirements.
Update compliance policies and training materials to reflect the DOJ’s revised approach to guidance documents.
Consider whether any unsigned or expired arrangements may be addressed under the new Stark Law flexibility.
Prompt Authentication of Verbal Orders ; Verbal Order Risks
The failure of a physician to timely sign a verbal order can have reimbursement implications. In some cases, in some states, another responsible provider can sign a verbal order that is originally given by another practitioner. This option is not always available and depends a lot on whether state law permits the practice. Some states require the practitioner who gave the verbal order to authenticate the order. With the use of electronic medical records, practitioners cannot expect leniency on these types of requirements.
In states that permit one practitioner to authenticate for another, the authenticating proxy practitioner should understand that he or she is accepting responsibility for the authenticated verbal order. State scope of practice rules apply to cross authentication of orders. In otherwords, the practitioner authenticating the order must have practice authority to have provided the original verbal order. Facilities can develop policies that a more restrictive then what the law permits. Policy can eliminate or restrict cross authentication practices. There is inherent risk in permitting cross authentication because the authenticating provider did not give the original verbal order. Additionally, as covered in previous blog articles, verbal orders are over-used in many facilities and carry inherent risks. Facilities can enact policies to curtail the use of verbal orders. At minimum, facility policy should echo the CMS comments regarding the appropriate scope of use of verbal orders. Practices can be audited to determine whether a practitioner is overusing verbal orders.
How Telemedicine Licensing Issues Arise – Compliance for Telehealth Programs
The practice of medicine is licensed and regulated at the state level. The jurisdiction of individual states over medical licensure is broadly recognized by the courts and the federal government, including CMS. The fact that every state has its own set of laws and regulations regarding licensure of healthcare providers has been a substantial impediment to the development of cross-border telemedicine programs. There has been no meaningful movement in that direction, although there has been discussion of the creation of more uniform state licensure standards, thus far.
Licensing issues are important to both initiating sites (where the patient is located) and remote sites (where the provider is located). Licensing issues impact a physician who is providing care or consultation to a patient via potential professional discipline or charges of the unlicensed practice of medicine. Both ends of the telemedicine relationship need to assure that the physician is appropriately licensed because reimbursement for services of each provider requires that the physician be appropriately licensed to provide the service under the state law of the initiating site. Failure to assure proper licensing can raise compliance risks. If services are provided by a provider through telemedicine into a state where the provider is not licensed, claims for reimbursement could be false or fraudulent. For this reason, telemedicine should be specifically included within the compliance activities of both the initiating and remote sites.
Medicare permits a physician to bill for certain services furnished by a nurse practitioner or other auxiliary personnel under what is referred to as the “incident to” billing rules. The “incident to” rules permit services or supplies furnished as an integral, although incidental, part of the physician’s personal professional services in the course of diagnosis or treatment of an injury or illness to be reimbursed at 100% of the physician fee schedule, even if the service is not directly furnished by the billing physician.
A significant requirement to permit the services of physician extenders to be billed as “incident to” services requires direct personal supervision by the physician. The supervising physician does not necessarily need to be present in the room where the procedure is being performed. The “direct supervision” standard requires the supervising physician be “physically present in the office suite and immediately available to furnish assistance and direction” during the time the auxiliary personnel is providing the service.
The 2016 Medicare physician payment rule provided some clarification on how the direct supervision requirement under the “incident to” billing rules operates. The new rule clarifies that the physician who directly supervises the applicable auxiliary personnel is the only party that can bill the service of the auxiliary personnel as “incident to” his or her service. CMS considers this a clarification of its longstanding policy, but many providers will see this as a new restriction on the application of the “incident to” rules.
To understand the significance of this “clarification,” it is useful to note that more than one physician is often involved in the care of a patient. It is not uncommon for one physician to visit the patient and order a test or procedure that is then supervised by another physician. Prior to this “clarification,” the physician who originally ordered the service might have billed the service as “incident to” even though another physician actually supervised the performance of the service. The revised regulatory language clarified this is not permitted and that only the physician actually present in the office suite who supervises the service can bill for the service as “incident to” their service. When making a claim for services billed “incident to” a physician’s services, the billing number of the physician that actually supervises the performance of the service must be used rather than that of the ordering physician.
CMS clarifies the reasoning behind this rule as follows: “[B]illing practitioners should have a personal role in, and responsibility for, furnishing services for which they are billing and receiving payment as an incident to their own professional service.”
In view of this regulatory clarification, providers may wish to reexamine their billing process and procedures to clarify the correct billing for “incident to” services. Staff should also be trained on the proper supervision of services billed under the “incident to” rules.
A few months ago, the Atlanta Journal-Constitution reported on the guilty plea of an Atlanta dentist for Medicaid fraud. Just this week, the dentist was sentenced to serve a year and a half in federal prison.
The dentist was alleged to have netted around $1 million in fraudulently obtained reimbursement from the Medicaid program. As part of her plea agreement, the dentist agreed to forfeit her ill-gotten gains, including real estate that she acquired using the funds.
Some of the illegal activities alleged included:
Having employees back-date claims for patients whose Medicaid eligibility had expired at the time the service was provided.
Filing claims for services she provided on days she was not in the country; let alone in her office.
The alleged activities appear to have been intentional and deliberate. Even so, the situation is instructive on the type of risks to which a dental practice can be exposed. Even if the dentist had not instructed employees to back-date billings it would be possible for an employee to do this on their own initiative. The dentist under whose name the bill is submitted would still be responsible for the fraudulent billing. Criminal intent might not be present in such a case, but repayment and potential civil penalties would certainly be assessed. The government’s inquiry would likely focus on “what the dentist knew and when he or she knew it.” The stakes riding on the outcome of that analysis would be potential jail time or at least enhanced penalties.
So what is my point? I recently wrote an article in which I described just some of the reasons a dental practice needs to have an effective compliance program in place. Dental Practice Compliance Article. The program should operate to educate staff on appropriate (and inappropriate) billing practices. The program should include audits in areas of identified risk. If a problem is discovered through proactive audit, appropriate corrective action should be taken promptly. This may mean repayment and/or self-disclosure in some cases. In other cases it may mean adjustment to policies and processes, additional training, or employee discipline. It all depends on the circumstances.
One thing is absolutely clear. If there is a problem in your practice, you want to be the one who discovers it. It is still not fun to deal with, but at least you are not under active scrutiny by criminal or civil enforcement agents, or even worse, a potential whistleblower. The way to stay out in front of these issues is to have a compliance program that proactively looks for problems as a matter of routine.
For some reason, many dental practices do not prioritize compliance. Some practices believe compliance is mainly a “Medicare thing.” That belief is wrong. Medicaid and other governmental health programs apply, even when Medicare is not a significant source of revenue. Compliance also goes beyond reimbursement issues. A normal dental practice is subject to a host of federal and state statutes and regulations such as licensing requirements, insurance rules, OSHA regulations, DEA regulations, HIPAA, and state patient confidentiality laws, just to name a few. Each of these areas present potential areas of risk and require mitigation through the operation of a systematic compliance program.
One of the primary elements in a Compliance Program is the creation of a system that permits employees and others to provide information regarding potential compliance issues without fear of retaliation. In larger organizations, multiple pathways permitting employees to make anonymous complaints should be maintained. Oftentimes providers use 24 hour compliance “hotlines.” Online reporting systems or “drop boxes” are also commonly used. Whatever system is used, it is crucial that employee understand that they are encouraged to provide information and that there is a clear prohibition against others in the organization retaliating against them for providing information. It should also be made clear to employees that wherever possible the identity of the person providing the information will be kept confidential.
Establish Compliance Reporting Process
The establishment of the compliance reporting process and communication to employees that retaliation will not be tolerated is a central element to an effective compliance program. Such a system will help the practice obtain valuable information, hopefully early on, before the issue becomes a big problem. Additionally, the openness of the program will send a strong signal to the outside world, such as government regulators, that the organization takes compliance seriously.
If information is obtained through the hotline system it must be taken seriously. Certainly not every piece of information will be reflective of a serious compliance problem, and an employee could potentially have other motives for making a compliant. Regardless, it is crucial that the information be acted upon and that the action be documented. If the compliance officer concludes that there were alternative motivations for the complaint, that fact should be substantiated and documented. If an objective investigation indicates that there could be a compliance issue, the matter needs to be pursued through an appropriate outcome. Depending on the circumstances and the result of a thorough investigation, the outcome could range anywhere from additional training through a self disclosure to the government.
There’s a lot of activity in the area of provider based facilities and hospitals outpatient departments. Laws are changing to equalize reimbursement that is available between provider-based and physician office settings. Services provided in a provider-based setting are still eligible for higher rates of reimbursement; but that is changing. In the future this differential will be reduced or removed entirely. Differential reimbursement will be eliminated in 2017 except for certain grandfathered facilities. There is even talk now that grandfathering will eventually be targeted.
Hospitals are rushing to establish provider based arrangements that will be grandfathered once the law changes in 2017. This in turn is leading to deeper scrutiny by CMS on the methods of billing in the provider-based environment and determination of whether a facility is actually provider based.
There is currently no survey process to assure that the conditions of provider-based status are being met. Rather, a hospital must simply certify that it meets the requirements described in 42 CFR section 413.65 and CMS transmittal 8–0 3–030.
The identification of the issue of provider based status by the OIG reflects the changes in this area of the law and signals that the OIG will be looking more closely at the conditions for meeting provider based rules and the conditions required for facilities to be be grandfathered into the current reimbursement differential. The stepped-up reimbursement that is currently available results in an area of potential abuse that the OIG will be scrutinizing with additional zeal. Arrangements that are being structured last minute to be grandfathered in under previous laws will likely be subject to even further scrutiny and should be carefully structured to assure compliance.
The relatively recent case serves as a reminder of the potential exposure to Stark Law liability arising from payments to medical directors. Let me immediately clarify that not all payments to directors who perform legitimate services that are appropriately documents raise compliance concerns. However, where medical director payments are not properly supported by documentation of effort involved, or where payments are well in excess of fair market value for legitimate services, compliance concerns exist and potential penalties can be quite substantial.
The case of United States v. Campbell, 2011 U.S. Dist. LEXIS 1207 (Jan. 2011) is is just one example of a case that found medical director payments to be abusive. The Campbell case involved an effort by a University of Medicine and Dentistry program to increase referrals of cardiothoracic patients by entering agreements with local cardiologists. The hospital entered into clinical assistant professor (“CAP”) agreements with a number of cardiologists which purported to require the physicians to perform a variety of teaching-related services. Physicians were paid between $50,000 and $180,000 per year under these contracts.
The Federal government viewed these CAP Agreements as being little more than a sham to encourage the referral of cardiology patients. Although there were services described in the agreement, there was little indication that many of these services were ever actually performed. The court hearing the case found that the Stark Law was violated because the physician was not compensated at fair market value, and the arrangement was not commercially reasonable. In order to comply with Stark Law requirements, compensation must meeting both fair market value and commercial reasonableness requirements. The Campbell Court found that the payments made to medical directors that were above fair market value amounted to impermissible payments in violation of the Stark Law.
The Campbell case is just one of a number of cases that have been brought challenging payments to medical directors. As a result, payment to medical directors has become a central compliance issue to many healthcare providers. The scrutiny of medical director arrangements require providers to set strict compliance standards for these arrangements.
Some elements of a medical director compliance standards might include:
An express requirement that these agreements be in writing and meet the elements of an applicable exception from the Stark Law and a Safe Harbor under the Anti-kickback Statute. A written agreement should always be in place and the term of the agreement should be monitored to assure that no payments are made on expired or unsigned agreements.
The agreement should include a detailed description of the services to be performed along with a system to track the performance of services in fulfillment of the Agreement. There are many details that can cause problems when creating these tracking systems. Make sure to get appropriate guidance and be detailed about the process and requirements for documenting time spent on individual contract tasks. General statements about time spent on medical director duties in general will not be sufficient to support payments under the Stark Law. This is an area where to be pays to be a stickler. Regular reports should be required to be submitted. Some providers are now requiring time reports to be submitted daily because this requires the director to contemporaneously document the time and specific tasks. Generally, more frequent time submissions will be more credible evidence of the tasks performed and will be more defensible from a regulatory standpoint.
Monitoring should take place to assure that the services are actually being performed as indicated by the medical director.
In all cases, the institution should document the commercial reasonableness and necessity of the medical director arrangement. Paying a medical director for services that are not required by the institution will likely be characterized as a regulatory violation.
There should always be backup in the file that clearly indicates that the fair market value of the services to be performed was assessed and that a reasonable judgement about the value of the service was made. It is normally recommended that there be an independent fair market value opinion that is credible and considers all factors relevant to value. Even if there is a fair market value opinion, there should be evidence that the organization’s reliance on the opinion was reasonable. Errors in fair market value determinations can be made on either side of the equation. Opinions can be too high or they can be too low. The assessment must be reasonably supported. Although we generally focus on whether payments to the medical director are excessive, the referral flow often flow both directions. Remuneration paid from the physician to the hospital could potentially be viewed as remuneration for referrals from the hospital (or its employees) to the physician. Therefore, it is important that the compensation be correct rather than conservatively low. Many providers miss this factor when determining fair market value of physician compensation arrangements. An extremely conservative approach from one perspective could possibly constitute a kickback from another perspective.
For more information on medical director agreements, Stark Law, fair market value of physician compensation arrangements, contact John Fisher at Ruder Ware through the contact information on this web site. Health Care Attorney Contact
Providers Get Another Push Into Proactive Compliance
The Patient and Program Protection Act (“PPACA”) added a number of additional tools to the government’s fraud fighting arsenal. One of those tools is found in PPACA Section 6402 and requires providers to repay any overpayments to government health programs within 60 days of identification. Like most “anti-fraud” provisions that the government has implemented, the 60-day repayment rule presents risk to even the most honest provider and represents yet another statement to the provider community that the federal government expects them to adopt effective compliance programs that are tailored toward self detecting.
Newly issued proposed regulations implementing the 60-day repayment rule make the government’s objectives absolutely clear. These regulations broadly define when a provider is deemed to have “identified” an overpayment. Identification is not limited to cases where there is actual knowledge that an overpayment exists. Rather, a provider will be deemed to have “identified” an overpayment if the provider acts in reckless disregard or deliberate ignorance of the overpayment. CMS makes it clear that their approach “gives providers and suppliers an incentive to exercise reasonable diligence to determine whether an overpayment exists.” CMS adds that “without such a definition, some providers and suppliers might avoid performing activities to determine whether an overpayment exists, such as self-audits, compliance checks and other additional research.” In short, CMS is affirmatively stating that providers need to adopt an ongoing program to detect potential overpayments and other compliance problems or risk being subject to the penalties for failing to repay amounts that would have been detected if an effective compliance and auditing plan was being operated.
A closer look at the penalties for failing to make repayment within 60 days of identification brings into focus the importance of operating a compliance program. Failure to meet the 60-day repayment deadline makes all “identified” payments a False Claim under the Federal False Claims Act. Penalties under the Federal False Claims Act include triple the amount of the repayment, plus up to $11,000 per claim. Calculations of liability very quickly add up, especially where they result from a systematic billing error that goes undiscovered for a long period of time. If CMS determines that the overpayment should have been discovered through a compliance and audit plan, the statute permits them to be rather draconian in their assessment of damages. To make matters worse, proposed regulations permit the government to “look back” for up to 10 years.
To reduce the risk of exposure to false claims act liability, providers should adopt compliance and audit programs that are tailored to the nature and size of their business. There is no “one size fits all” when it comes to compliance. Hospitals and health systems should have robust compliance programs covering their entire operations. Compliance should be under the auspices of a compliance officer who has a direct reporting relationship to the board of directors. It is normally recommended that the compliance officer not report to legal counsel or the CFO.
Smaller organizations such as small physician groups can adopt an appropriately scaled compliance plan. A “compliance responsible” individual can be appointed. Audits can cover billing issues and other risk areas that are unique to the practice. It is important that the compliance program be appropriately scaled and focused on the critical risk areas of the specific provider. Too narrow of coverage creates risk that typical problems are not detected and corrected. Too broad of coverage makes it impossible to fulfill the plan and creates a roadmap of what is not being done.
A recent “advanced session” was provided by the American Health Lawyer’s Association covering several of the central legal issues that arise with respect to ASC ownership and structure. The general issues covered in the webinar included:
1.ASC ownership structure and valuation issues;
2.ASC policies, procedures and compliance issues;
3.Regulatory issues involved with terminating physician ownership interests;
4.Compliance issues for ASCs that do not strictly meet safe harbor provisions;
5.ASC relationships with anesthesia providers;
6.Procedures performed “in office” versus in the ASC;
7.Conversion of physician ownership to hospital owned ASCs; and
8.Co-management and other creature arrangements with hospitals.
I have previously blogged on the ASC safe harbor provisions and will be supplementing previous work in this area with further articles.
I have represented physician groups, individual investors, institutions and management organizations in connection with surgery center legal and compliance issues and have a depth of knowledge in these issues.
ASCs involve extremely intricate and subtle legal and regulatory issues. The consequences of not carefully following regulatory requirements can be devastating to the ASC as well as organizers and investors. These issues must be squarely addressed and appropriately documented. ASCs are often structured with insufficient attention to appropriate regulatory parameters. Arrangements that are structured by parties who are not familiar with the subtleties of applicable regulations can present a great deal of risk to participants. Even when the ASC is appropriately documented, failure to exercise appropriate judgment when it comes to key issues such as valuation and termination of interests can lead to dire straits.
Stay tuned for more discussion on many of the subtle legal and regulatory issues involved in ASC structure and operation.
Conditions For Payment Of Medically Directed Anesthesia
In my previous article regarding anesthesia billing practices, I neglected to mention another risk associated with overbilling for medically directed anesthesia. Engaging in the described practices tends to raise issues beyond the “double billing” issue that is directly raised. This type of issue can also raise further scrutiny of the source bills. For example, an insurer may decide to perform an extended audit of billings as a result of the billing anomalies that I described in my previous article. The review might disclose a systematic problem documenting all of the prerequisites that permit the billing for medically directed services.
In order to bill medically directed anesthesia services, seven primary elements need to be clearly indicated in the medical record:
The physician must perform a pre-anesthetic examination and evaluation;
The physician must prescribe the anesthesia care;
The physician must personally participate in the most demanding aspects of the anesthesia plan, including, if applicable, induction and emergence;
The physician must assure that any procedures in the anesthesia plan, that he or she does not perform, are performed by a qualified individual as defined in the operating instructions;
The physician must monitor the course of anesthesia administration at frequent intervals;
The physician must remain physically present and available for immediate diagnosis and treatment of emergencies; and
The physician must provide indicated post-anesthesia care.
If one or more of these elements is not indicated in the medical record, the claim may be denied altogether, sometimes for both the physician and the CRNA services. The physician alone is responsible for documenting each of these activities in the chart. Like everything else, if it is not in the chart, it did not take place.
You can see how the originally risky billing practice could trigger a further audit and in turn uncover deficiencies in documenting the conditions for medically directed reimbursement. If a systematic error is made in documenting the seven elements, there can be significant additional financial exposure to the group.