Stark Law, Anti-Kickback Statute, MSO Structures, Telehealth, Physician Compensation, and Ancillary Services
July 2026 | Health Care Regulatory and Compliance Update
SEO summary: This health care compliance alert addresses key legal and regulatory issues for physician practices, medical groups, management services organizations, telehealth providers, digital health companies, private equity-backed health care platforms, ambulatory care providers, specialty practices, and ancillary service providers, including Stark Law compliance, Anti-Kickback Statute risk, physician compensation arrangements, fair market value analysis, commercial reasonableness, corporate practice of medicine restrictions, MSO compliance, fee-splitting rules, scope-of-practice rules, supervision requirements, telehealth reimbursement, telemedicine licensure, remote patient monitoring compliance, Medicare and Medicaid billing, ancillary service billing, medical necessity documentation, revenue cycle compliance, payer audit risk, and health care fraud and abuse enforcement.
Related compliance topics: physician self-referral law, value-based care arrangements, in-office ancillary services, laboratory compliance, imaging center compliance, physical therapy billing, durable medical equipment compliance, behavioral health telehealth, digital health compliance, professional corporation governance, medical director agreements, independent contractor provider agreements, referral source arrangements, overpayment refunds, claims audit response, health care transaction diligence, and multi-state provider compliance.
Federal and state health care regulators continue to scrutinize the financial, operational, and ownership arrangements that underpin physician practices, management services organizations, telehealth platforms, digital health businesses, and ancillary service lines. Recent developments in health care fraud and abuse enforcement underscore that technically compliant documentation is not always enough: regulators are increasingly focused on intent, operational control, fair market value, clinical independence, medical necessity, billing accuracy, and the practical realities of how arrangements function.
This health care regulatory Alert identifies key compliance themes affecting medical practices, physician groups, MSOs, telehealth companies, remote care platforms, and ancillary service providers, and outlines practical steps organizations should consider to reduce Stark Law, Anti-Kickback Statute, corporate practice of medicine, reimbursement, and billing compliance risk.
Executive Summary: Key Health Care Compliance Risks for Medical Practices and MSOs
- Stark Law compliance does not eliminate Anti-Kickback Statute risk. Recent OIG guidance reiterates that an arrangement may satisfy a Stark Law exception yet still present AKS risk depending on the parties’ intent and the totality of the circumstances.
- Fair market value remains important but is not a standalone AKS defense. Compensation that is commercially reasonable and consistent with fair market value should still be evaluated for referral-related intent, volume or value concerns, and safe harbor compliance.
- State corporate practice of medicine rules are becoming more consequential. Regulators are looking beyond written agreements to determine whether MSOs or other non-clinical entities exercise de facto control over clinical decision-making, physician ownership, staffing, or patient care protocols.
- Telehealth and ancillary service arrangements require integrated compliance review. Licensure, supervision, billing, privacy, documentation, and payer requirements should be addressed together rather than managed in separate silos.
- Health care organizations should refresh compliance controls now. Contract review, audit protocols, state-specific CPOM analyses, billing controls, and board-level oversight can help reduce risk before regulators, payers, or transaction counterparties identify deficiencies.
Background: Health Care Regulatory Compliance, Physician Practice Management, and Fraud and Abuse Risk
Medical practice structures have become more complex as physician groups, MSOs, telehealth companies, private equity-backed health care platforms, specialty practices, ambulatory care providers, and ancillary service providers pursue growth, integration, consolidation, and new care delivery models. At the same time, federal fraud and abuse enforcement, state corporate practice restrictions, payer audits, revenue cycle reviews, and health care transaction diligence are converging around a common question: whether business arrangements preserve compliant referral relationships, clinical independence, accurate billing, medical necessity, and patient-centered decision-making.
For organizations operating across multiple states or service lines, the compliance analysis is increasingly fact-specific. A form agreement may not be sufficient if day-to-day operations suggest that a non-clinical entity controls clinical judgment, compensation incentives reward referrals, ancillary services lack adequate documentation, or telehealth workflows do not align with licensure and payer requirements.
1. Stark Law, Anti-Kickback Statute, Physician Compensation, and Referral Source Arrangements
Separate Stark Law and AKS Analyses
Recent OIG updates reinforce a point that remains central to health care contracting: Stark Law compliance and AKS compliance are related but distinct analyses. The Stark Law generally operates as a strict liability statute focused on physician financial relationships involving designated health services, while the AKS is an intent-based statute that prohibits knowingly and willfully offering, paying, soliciting, or receiving remuneration to induce or reward referrals of federal health care program business.
Fair Market Value, Commercial Reasonableness, Safe Harbor Analysis, and Referral Intent
Accordingly, satisfying a Stark Law exception does not, standing alone, insulate an arrangement from AKS scrutiny. Similarly, compensation that is consistent with fair market value may be a critical compliance factor, but it is not a standalone AKS safe harbor. Regulators may still examine whether one purpose of the arrangement was to induce or reward referrals, whether the compensation methodology is commercially reasonable, and whether the parties documented the legitimate business rationale for the arrangement.
What this means for providers: Physician employment agreements, independent contractor provider agreements, medical director agreements, value-based care incentives, shared savings models, call coverage agreements, marketing arrangements, space and equipment leases, referral source arrangements, and ancillary service relationships should be reviewed for both Stark Law and AKS purposes. Organizations should document fair market value, commercial reasonableness, legitimate service need, safe harbor or exception analysis, and the absence of referral-based intent, and should implement periodic monitoring to confirm that arrangements operate as written.
2. Scope-of-Practice Compliance, Supervision Requirements, Credentialing, and Provider Billing Rules
State Scope-of-Practice Rules for Non-Physician Providers
States continue to expand, narrow, or clarify the scope of practice for nurse practitioners, physician assistants, pharmacists, behavioral health providers, and other non-physician practitioners. These changes can create opportunities to expand access to care, but they also introduce compliance risk if supervision, delegation, credentialing, billing, and documentation practices do not keep pace.
Organizations should maintain state-specific protocols addressing who may perform particular services, what level of physician collaboration or supervision is required, how services are documented, and how services are billed. Payer rules may impose additional requirements beyond state licensure laws, particularly for incident-to billing, split/shared services, telehealth, remote patient monitoring, and ancillary services.
Supervision, Delegation, Credentialing, and Billing Risk Areas
Risk areas to monitor: inconsistent collaborative agreements, outdated supervision policies, provider services performed outside permitted scope, billing under the wrong provider, insufficient chart review, unclear escalation pathways, and onboarding materials that do not reflect current state law.
Recommended action: Practices should conduct periodic state-by-state reviews of provider scope, delegation rules, collaborative practice agreements, payer enrollment requirements, and billing workflows. Training should be refreshed whenever state law, payer rules, or service lines change.
3. Telehealth Compliance, Telemedicine Licensure, Remote Patient Monitoring, and Reimbursement Policies
Telemedicine Coverage, Coding, and Payment Rules
Telehealth remains a major area of regulatory change as federal and state policymakers continue to evaluate which pandemic-era flexibilities should be extended, modified, or made permanent. Coverage and payment rules for telemedicine, remote patient monitoring, remote therapeutic monitoring, behavioral health telehealth, chronic care management, hybrid care models, Medicare telehealth services, Medicaid telehealth coverage, and commercial payer virtual care programs continue to evolve.
Licensure, Prescribing, Consent, Privacy, and Cybersecurity
Telehealth compliance is not limited to reimbursement. Organizations should evaluate licensure, prescribing, informed consent, modality requirements, patient location, provider location, privacy and security, documentation standards, record retention, and fraud and abuse considerations. Cross-state care models, in particular, should be reviewed before expansion.
Telehealth arrangements involving MSOs, professional corporations, leased clinicians, marketing platforms, or referral sources should also be reviewed under AKS, state fee-splitting rules, CPOM doctrines, and payer contract requirements. Administrative fee models, revenue-sharing arrangements, and platform relationships may require particular scrutiny.
Recommended action: Organizations should maintain a telehealth compliance matrix that addresses state licensure, prescribing rules, payer coverage, coding, consent, privacy safeguards, cybersecurity controls, and patient follow-up. Policies should be tested against actual workflows, not merely maintained as standalone documents.
4. Corporate Practice of Medicine, MSO Compliance, Fee-Splitting, and Professional Corporation Governance
Clinical Control and Corporate Practice of Medicine Restrictions
State corporate practice of medicine doctrines and related fee-splitting rules are receiving renewed attention, especially in arrangements involving private equity-backed platforms, MSOs, telehealth companies, professional corporations, friendly physician models, dental service organizations, management services agreements, and multi-state practice models. Regulators are increasingly focused on substance over form: who controls clinical decisions, who controls professional ownership, who sets staffing and compensation expectations, who owns or controls patient records, and whether business personnel influence patient care.
Management Services Organization Agreements and Non-Clinical Functions
Traditional MSO structures remain viable in many jurisdictions when properly designed and operated. However, management agreements should clearly separate clinical and non-clinical functions. Licensed professionals should retain authority over diagnosis, treatment, clinical protocols, supervision, professional judgment, patient records, and quality of care. MSOs should avoid contractual or operational rights that give them de facto control over professional practice decisions.
Recommended action: Multi-state organizations should maintain state-specific CPOM analyses, governance documents, management agreements, fee schedules, clinical-control protocols, and escalation procedures. Particular attention should be paid to stock transfer restrictions, replacement rights, management termination rights, percentage-based fees, non-compete provisions, clinical staffing control, and communications that may suggest non-clinical control over patient care.
5. Ancillary Service Billing Compliance, Medical Necessity, Revenue Cycle, and Payer Audit Risk
Laboratory, Imaging, Therapy, DME, and Remote Monitoring Services
Ancillary service lines—including laboratory testing, imaging, physical therapy, durable medical equipment, remote patient monitoring, remote therapeutic monitoring, in-office ancillary services, diagnostic testing, and specialty ancillary services—remain attractive from an operational and patient-care perspective. They also remain vulnerable to scrutiny when ordering patterns, billing practices, medical necessity documentation, supervision requirements, payer contract obligations, or referral relationships are not well controlled.
Medical Necessity, Coding, Claims Submission, and Audit Controls
Billing compliance should be evaluated alongside fraud and abuse, payer contract, and medical necessity considerations. Common risk areas include insufficient documentation of medical necessity, standing orders that are not individualized, improper use of modifiers, billing for non-covered services, failure to meet supervision requirements, and compensation models that may create referral-related incentives.
Organizations should establish written protocols for ordering, performing, documenting, coding, billing, and auditing ancillary services. Internal audits should be risk-based and should include both claim-level review and operational review of referral flows, provider education, denial trends, refund processes, and corrective action.
Recommended action: Practices should confirm that ancillary services are clinically appropriate, adequately documented, properly ordered, and accurately billed. Where financial relationships exist among ordering providers, ancillary entities, MSOs, laboratories, imaging centers, or therapy providers, organizations should review Stark Law, AKS, state law, and payer contract implications before continuing or expanding the arrangement.
Practical Health Care Compliance Checklist for Physician Practices and Ancillary Services
- Inventory physician, provider, MSO, telehealth, marketing, and ancillary service arrangements.
- Confirm that each arrangement has a documented business need, fair market value support, and commercial reasonableness analysis where appropriate.
- Evaluate arrangements separately under Stark Law, AKS, state self-referral laws, fee-splitting rules, and CPOM doctrines.
- Refresh state-specific scope-of-practice, supervision, delegation, and licensure protocols.
- Review telehealth workflows for licensure, prescribing, consent, payer coverage, coding, documentation, privacy, and cybersecurity requirements.
- Audit ancillary service ordering, documentation, coding, claim submission, denials, refunds, and corrective action processes.
- Train clinical, administrative, billing, contracting, and leadership teams on updated policies and escalation procedures.
- Maintain board or leadership oversight of high-risk arrangements and document compliance decisions contemporaneously.
Client Compliance Checklist: Stark Law, AKS, Telehealth, MSO, CPOM, Revenue Cycle, and Billing Controls
The following checklist is intended to help health care organizations assess whether current arrangements, policies, and operational workflows are aligned with key fraud and abuse, reimbursement, corporate practice, telehealth, and ancillary service compliance expectations. Organizations should tailor the checklist to their state law requirements, payer contracts, service lines, and risk profile.
| Workstream | Client Action Items | Key Documentation | Suggested Owner / Cadence |
| Governance and Compliance Program | Confirm that compliance oversight is assigned to leadership, a compliance officer, or a compliance committee; conduct periodic risk assessments; maintain escalation procedures for identified issues. | Code of conduct, compliance policies, risk assessments, committee minutes, corrective action logs. | Compliance / Legal; annual risk assessment with quarterly monitoring. |
| Physician and Provider Financial Relationships | Inventory employment, independent contractor, medical director, call coverage, marketing, lease, and referral-source arrangements; evaluate Stark Law and AKS separately. | Executed agreements, fair market value support, commercial reasonableness memoranda, board approvals, payment records. | Legal / Finance / Compliance; before execution, renewal, amendment, and annually for high-risk arrangements. |
| Fair Market Value and Commercial Reasonableness | Confirm that compensation is set in advance where required, supported by appropriate valuation materials, and not determined by the volume or value of referrals or other business generated. | FMV opinions, compensation surveys, productivity data, service need analysis, payment methodology records. | Finance / Legal; before execution and when compensation changes. |
| Scope of Practice and Supervision | Review state-specific rules for physicians, nurse practitioners, physician assistants, pharmacists, behavioral health providers, and other clinicians; confirm supervision, delegation, and billing workflows. | Collaborative agreements, supervision protocols, credentialing files, job descriptions, training materials. | Clinical Leadership / HR / Compliance; at onboarding and when state or payer rules change. |
| Telehealth and Remote Care | Verify licensure, patient and provider location rules, prescribing requirements, consent, modality requirements, coding, documentation, privacy, cybersecurity, and payer coverage. | Telehealth policies, consent forms, payer billing guidance, licensure matrix, cybersecurity procedures, workflow maps. | Operations / Compliance / IT Security; quarterly for active programs and before expansion into new states. |
| Corporate Practice of Medicine and MSO Arrangements | Confirm that licensed professionals retain clinical control and that MSO functions remain non-clinical; review fee structures, governance rights, replacement rights, and communications for de facto control concerns. | Management services agreements, professional entity governance documents, CPOM analyses, fee schedules, clinical-control protocols. | Legal / Executive Leadership; before launch, transaction, restructuring, or state expansion. |
| Ancillary Services and Billing Compliance | Review ordering, medical necessity, supervision, documentation, coding, claims submission, denial management, refund processes, and corrective action for lab, imaging, therapy, DME, and remote monitoring services. | Order forms, medical records, billing policies, audit reports, denial logs, refund documentation, corrective action plans. | Revenue Cycle / Compliance / Clinical Operations; routine risk-based audits and targeted reviews after payer inquiries. |
| Training and Monitoring | Train clinical, billing, contracting, administrative, and leadership teams on current policies; monitor whether arrangements and workflows operate as documented. | Training attendance records, policy attestations, monitoring reports, hotline or reporting logs. | Compliance / HR; at onboarding and annually, with refreshers after material changes. |
Clients should consider prioritizing arrangements that involve referral sources, percentage-based compensation, multi-state telehealth operations, non-clinical management control, high-volume ancillary services, or recent payer audit activity. Any identified gaps should be documented, assigned to a responsible owner, and tracked through remediation.
Key Takeaway for Health Care Organizations
Health care organizations should not assume that legacy structures, form agreements, or isolated compliance reviews will be sufficient in the current enforcement environment. Regulators, payers, and transaction counterparties are increasingly examining how arrangements operate in practice. A coordinated review of provider relationships, physician compensation arrangements, MSO structures, telehealth models, digital health platforms, scope-of-practice protocols, ancillary service billing, revenue cycle compliance, payer audit response, and overpayment refund processes can help identify and remediate risk before it becomes a regulatory, reimbursement, enforcement, or transaction issue.
If you have questions about these developments or would like assistance evaluating your organization’s provider arrangements, MSO structure, telehealth model, or ancillary service compliance program, please contact a member of our Health Care Regulatory and Compliance team.
This Alert is intended for general informational purposes only and does not constitute legal advice. Readers should consult legal counsel regarding how the issues discussed may apply to specific facts and circumstances.
Stark Law, Anti- Kickback Statute, M S O Structures, Telehealth, Physician Compensation, and Ancillary Services Recent False Claims Act Cases in the Health Care Industry: Key Takeaways for Providers Navigating False Claims Act Liability and Damages— The Importance of Compliance Programs for Healthcare Providers F D A Guidelines on A I Technologies in Medical Devices Agency Law Considerations for A I in Healthcare H I P A A Breach Risk Assessments Require Information- Focused Analysis What H I P A A Policies are Required for a Health Care Provider? - 🎙️
Companion Episode Transcript: A S C Compliance Checklist for 2026 Fee- Splitting Risks in Telehealth – Impacts on Telemedicine Structures C P O M in Telehealth: What the Corporate Practice of Medicine Means for Virtual Care Companies A S C Safe Harbors and Physician Investors in A S Cs: Managing Lower- Volume Owners How Artificial Intelligence is Changing the Medical Profession A S C Safe Harbors: The Silent Partner Physician and Compliance Pitfalls Podcast – The Ambulatory Surgery Center Safe Harbors – General Overview Podcast Episode 2: An Overview of the Stark Law & New Developments





