Summary. Healthcare is regulated by more overlapping regimes than any other industry, and the organizations that fail are rarely the ones that intended to — they are the ones whose arrangements expired without anyone noticing, whose risk analysis covered the electronic health record and nothing else, and whose response to a hotline report took four months. This toolkit maps the compliance surface in the order a provider encounters it: entity structure and licensure, the fraud and abuse framework governing every financial relationship with a referral source, privacy and security, billing and documentation, the compliance program itself, and the response sequence when something is found.


What this toolkit is for, and who should use it

A healthcare organization operates inside four distinct regulatory systems at once. Licensure determines whether it may practice at all and who may own it. Fraud and abuse law governs every financial relationship with anyone who refers. Privacy and security law governs the information it holds. Payment law governs what it may bill and what it must return. Each has its own agency, its own clock, and its own remedies, and a failure in one frequently produces exposure in the others — an arrangement that fails a Stark exception makes every claim referred under it a False Claims Act problem, and a hotline report about billing starts a 60-day overpayment clock.

This toolkit is for administrators, compliance officers, general counsel, and the physicians who own the practice. It assumes a provider organization — a practice, a facility, a service line, or a digital health company delivering care — rather than a payer or a pharmaceutical manufacturer.

Roadmap at a glance

  1. Structure and licensure — who may own, who may practice, and where.
  2. The arrangement inventory — every financial relationship with a referral source.
  3. Stark and Anti-Kickback analysis — exception by exception, safe harbor by safe harbor.
  4. Fair market value and documentation — where the cases are actually lost.
  5. Privacy and security — the risk analysis, the access process, and the vendor layer.
  6. Billing, coding, and medical necessity.
  7. The compliance program — the seven elements that matter and the three that do the work.
  8. Monitoring and auditing.
  9. Investigation and the 60-day clock.
  10. Disclosure, resolution, and remediation.

Stage 1 — Structure and licensure

Get this right before anything else, because a defect here reaches the claims themselves.

Corporate practice of medicine. In roughly half the states, a corporation not owned by licensed physicians may not employ physicians to practice or own a medical practice, with related prohibitions on fee splitting. The standard structure is a friendly professional corporation owned by a licensed physician, with a management services organization providing everything non-clinical under an administrative services agreement at a documented fair market value fee — flat or cost-plus rather than a percentage of professional revenue where the state treats percentage compensation as fee splitting.

Where these structures fail: a percentage-of-collections management fee in a fee-splitting state; a fee untethered to services actually delivered; MSO control over clinical decisions, treatment protocols, clinician credentialing, or utilization; nominal physician ownership with no real authority; and a single PC used across states with different rules.

Licensure follows the patient's location for telehealth, and scope of practice for nurse practitioners and physician assistants follows the same rule, including supervision and collaborative practice requirements.

Facility licensure, certificate of need, accreditation, and Medicare enrollment each carry their own conditions, and a change of ownership triggers reporting and sometimes re-enrollment.

Illustration. A digital health company forms one professional corporation in its home state and contracts with clinicians in twenty-eight. Two years later a payer recoups eighteen months of claims on the ground that the billing entity was not authorized to practice in the states where care was delivered. The fix — state-specific PCs with licensed owners — costs a few thousand dollars per state at formation and is unavailable retroactively.

Resources

Stage 2 — The arrangement inventory

This is the single highest-value control in healthcare compliance, and most organizations cannot produce it on demand.

Build a list of every financial relationship with every referral source — physicians, their immediate family members, physician-owned entities, and anyone in a position to generate federal program business. For each: the parties, the effective date, the term, the expiration, the compensation, the signature status, the location of the executed original, the documentation of services delivered, and the business owner responsible.

Then reconcile the inventory to accounts payable and payroll. Payments made outside any written agreement are the classic finding, and they surface only this way.

Flag everything that is expired, unsigned, undocumented, or paid but not in the inventory.

Resources

Stage 3 — Stark and Anti-Kickback analysis

The two statutes require opposite analytical postures, and conflating them is the most common error.

The Stark Law asks whether the arrangement fits an exception, exactly. It is strict liability — no intent element, no good-faith defense. If no exception fits, the referral is prohibited, the designated health service claim is not payable, and submitting it is a False Claims Act exposure. Identify the exception by citation and confirm every element: a signed writing describing the arrangement; the required term; compensation set in advance, at fair market value, and not determined in a manner taking into account the volume or value of referrals; commercial reasonableness; and any exception-specific requirement. Watch for per-click and percentage compensation in leases, which most exceptions prohibit.

The Anti-Kickback Statute asks why. Under the one-purpose test, a payment violates the statute if any purpose is to induce or reward referrals — even where the compensation is fair market value and the services are genuinely performed. Safe harbors are voluntary: fitting one is immunity, and failing one is not itself a violation but requires a documented facts-and-circumstances analysis.

EKRA, 18 U.S.C. § 220, applies separately to laboratories, recovery homes, and clinical treatment facilities, reaches all payors, and has a narrower employee exception than the AKS.

Resources

Stage 4 — Fair market value and documentation

Three arrangements out of four that fail do so on valuation or documentation, not on structure.

Obtain an independent valuation before signing for anything unusual. Treat survey benchmarks as evidence rather than as a safe harbor. Test for stacking — aggregate every payment stream to each physician, because four arrangements each at fair market value can be indefensible in total and can pay twice for the same hours. Document commercial reasonableness in plain language: why these services, why this person, why this quantity.

Then document the services. Time logs, meeting minutes, deliverables, reports — and make payment contingent on them, so non-performance suspends payment automatically. The undocumented medical directorship is the most common way a defensible arrangement becomes indefensible.

Calendar every term and renewal, with alerts, and stop payments when an agreement expires.

Stage 5 — Privacy and security

The risk analysis is the foundation, and inadequate scope is the most frequently cited failure in OCR enforcement. It must be enterprise-wide — every system, device, medium, location, and vendor where electronic protected health information lives, not the electronic health record alone.

Encrypt laptops, mobile devices, removable media, backups, and transmissions, because encryption is the breach notification safe harbor and converts the most common category of incident into a non-event.

Make the access process work — 30 days, cost-based fee, requested format. The Right of Access Initiative has produced more enforcement actions than every sophisticated security theory combined.

Inventory business associates and execute agreements before disclosure, negotiating a breach notification clock measured in hours, cost allocation for notification, and a liability carve-out.

Audit tracking technologies on every patient-facing page, because pixels and session-replay tools on intake flows have produced a substantial volume of wiretapping and privacy litigation independent of any regulatory question.

Layer state law — mental health, HIV, genetic, minors' records, Part 2 substance use records, and state consumer health data statutes.

Resources

Stage 6 — Billing, coding, and medical necessity

Documentation supports the code, or the code is wrong. The recurring theories are upcoding, services not rendered, services rendered by an unqualified or unsupervised person, unbundling, and services that were not medically necessary.

Confirm incident-to and supervision requirements are met where billed that way, and that teaching physician rules are followed where residents are involved.

Confirm credentialing and enrollment are current for every rendering provider, and that no one is billing under another's number.

Audit a sample of claims quarterly against the documentation, by an independent reviewer.

Screen every employee, contractor, and vendor against the OIG List of Excluded Individuals/Entities and SAM, on hire and monthly, and retain the results — because payments to an entity employing an excluded person are themselves penalized.

Stage 7 — The compliance program

The OIG's seven elements are the framework; three of them do most of the work.

  1. Written standards and procedures.
  2. A compliance officer and committee, with authority, resources, and a reporting line that does not run through the person whose conduct might be at issue.
  3. Training and education, on scenarios rather than statutes.
  4. Open lines of communication — a functioning hotline that someone actually answers.
  5. Auditing and monitoring.
  6. Enforcement through disciplinary standards, applied consistently.
  7. Prompt response to detected offenses and corrective action.

The three that matter most in practice: the arrangement inventory with centralized approval; exclusion screening; and a hotline that produces a prompt, non-retaliatory response, because most False Claims Act relators complained internally first.

Board oversight is a real obligation and an increasingly examined one. The board should receive periodic compliance reporting, understand the organization's risk areas, and document that it did.

Preserve privilege deliberately where an investigation is counsel-directed, while recognizing that a decision to disclose may waive it.

Resources

Stage 8 — Monitoring and auditing

Build an annual plan covering: the arrangement inventory reconciled to payments; claims sampled for coding accuracy and medical necessity; exclusion screening results; HIPAA access logs actually reviewed; business associate agreements confirmed; documentation of services under every professional services arrangement; and the hotline log analyzed for patterns.

Use data analytics where volume permits — coding distribution against peers, utilization outliers, and referral concentration — because payers and the government use the same techniques.

Report findings to the compliance committee and the board, with remediation tracked to completion.

Stage 9 — Investigation and the 60-day clock

When credible information arrives, the clock is running. Under 42 U.S.C. § 1320a-7k(d), an identified overpayment must be reported and returned within 60 days of identification, and CMS regulations treat an overpayment as identified when the person has, or should have through reasonable diligence, determined it was received and quantified it — with reasonable diligence generally described as timely, good-faith investigation within about six months.

Investigate promptly. Stop the conduct, because continuing a known violation converts a repayment problem into a knowing one. Scope it — how many claims, over what period, at what value, using sampling and extrapolation where necessary. Run the investigation under counsel with Upjohn warnings to interviewees.

Resources

Stage 10 — Disclosure, resolution, and remediation

Choose the path deliberately, because the choice materially affects the outcome:

  • The OIG Self-Disclosure Protocol, for conduct implicating the Anti-Kickback Statute or false billing. It offers a presumption against a corporate integrity agreement, a settlement multiplier well below litigation exposure, and suspension of the 60-day clock.
  • The CMS Voluntary Self-Referral Disclosure Protocol, for Stark-only violations, where the settlement history is far more favorable.
  • A simple refund through the payer or contractor, for coding and billing errors with no fraud dimension.

Disclosing to the wrong body forfeits the benefit. A Stark technical violation with no kickback dimension belongs with CMS.

Weigh disclosure honestly. It is an admission and it costs money — and an undisclosed known overpayment retained past the deadline is a reverse false claim with treble damages, and arrangements surface through relators, payer audits, and data analytics with considerable regularity.

Fix the control, and document the fix. Whether the government is deciding on a corporate integrity agreement or a relator's counsel is evaluating a case, the difference between an organization that found and fixed a problem and one that did not is substantial.


Stage 11 — The questions providers actually ask

"We pay our medical directors fair market value. Isn't that enough?" No. Under the one-purpose test a fair payment is still unlawful if any purpose was to induce referrals, and under Stark a fair payment still fails if the exception's writing, term, or documentation elements are not met. The recurring finding is not an inflated rate; it is an expired agreement, a missing signature, or services nobody documented.

"Our compliance officer reports to the CFO. Is that a problem?" It is a structural weakness the government will note. The compliance function needs a reporting line — at minimum a dotted line to the board or an audit committee — that does not run through the people whose conduct might be at issue, and it needs the authority and budget to investigate.

"We found a billing error. Do we have to report it?" If it is an overpayment, yes, within 60 days of identifying and quantifying it, with the diligence obligation starting from credible information. The choice is not whether to return it but which path — a refund through the payer for a simple coding error, the CMS protocol for a Stark-only violation, or the OIG protocol where the Anti-Kickback Statute is implicated.

"An employee complained about a physician's billing. Can we just look into it informally?" Look into it promptly and formally, under counsel, and never retaliate. Most qui tam relators raised the issue internally first, and the response to that report frequently determines whether there is a case at all.

"How much does a compliance program cost?" Far less than the alternative. For a mid-sized practice, the recurring cost is a part-time compliance officer, an annual coding audit, monthly exclusion screening, an enterprise risk analysis every year or two, and the arrangement inventory maintained by someone whose job it is. The single largest expense in this field is a corporate integrity agreement, and the program is what avoids one.

"Does a corporate integrity agreement mean we did something criminal?" No. A CIA is negotiated with OIG as an alternative to exclusion in a civil resolution, and it typically runs five years with a compliance officer and committee, board certifications, training, an independent review organization auditing claims and arrangements, and reportable event procedures. Avoiding one is a legitimate settlement objective and is one of the principal benefits of self-disclosure.

Master resource index

Articles

Checklists

Related toolkits

External and primary sources

This toolkit is educational and not legal advice. Healthcare regulation is fact-specific, state licensure and corporate practice rules vary substantially, and safe harbors and exceptions contain requirements not fully described here. Consult qualified healthcare regulatory counsel.