Healthcare Compliance lawyers
1 law firm.
Ordered by membership tier. The Verified badge is earned from approved evidence, not payment; docket-practice checking is available only on Premium.
List your Healthcare Compliance practice?
Submit your firmRelated practice areas
- Health Care Law (broader)
- All practice areas →
Strongest states
- Arizona (1)
- All states →
Practice guide
Healthcare compliance under the fraud-and-abuse triad: HIPAA programs, audits, self-disclosure, and choosing counsel
VerifiedLawFirms editorial · Updated 2026-07-17 · Editor-reviewed 2026-07-17
Five linked sections, one continuous guide. The sources cited below apply throughout.
The governing doctrine: elements, defenses, and the frameworks practitioners actually litigate
Three statutes carry most of the weight in healthcare compliance enforcement, and each one runs on separate logic. The physician self-referral law, 42 U.S.C. 1395nn, called Stark, imposes strict liability. A physician who holds a financial relationship with an entity may not refer Medicare patients to that entity for designated health services unless a defined exception fits the arrangement. Intent does not enter the analysis. The claim either meets an exception or it does not. That binary quality makes Stark the sharpest instrument a healthcare compliance lawyer confronts, because a technical foot fault, a lease that lapsed, a signature never obtained, can taint every downstream claim.
Contrast the Anti-Kickback Statute, 42 U.S.C. 1320a-7b(b). It is a criminal law reaching anyone who knowingly and willfully offers, pays, solicits, or receives remuneration to induce referrals of items or services payable by a federal program. Scienter is the whole ballgame. The Third Circuit read the statute broadly in United States v. Greber, holding that a payment violates the law if even one purpose is to induce referrals, regardless of other legitimate reasons. Its safe harbors are voluntary. An arrangement that misses a safe harbor is not automatically illegal, unlike Stark, where missing an exception ends the inquiry. Healthcare compliance counsel spend much of their time mapping deals against both regimes at once, since a single medical director agreement can implicate each.
The False Claims Act, 31 U.S.C. 3729, is the multiplier that gives the other two their teeth. It imposes treble damages plus a per-claim penalty on anyone who knowingly submits a false claim to the government. Standing alone, Stark and the Anti-Kickback Statute reach conduct. The False Claims Act converts that conduct into money, and it deputizes private relators to sue on the government's behalf. Since the 2010 amendment codified at 42 U.S.C. 1320a-7b(g), a claim tainted by a kickback is per se false under the Act, which welded the criminal statute to the civil recovery engine. Most healthcare compliance exposure now travels this path. A billing error becomes a fraud theory once a relator recasts it as a knowing falsehood.
Materiality and scienter are where these cases are actually fought. In Universal Health Services v. United States ex rel. Escobar, the Supreme Court held that implied certification can support liability but that materiality is demanding, meaning the government's payment despite knowledge of noncompliance cuts against the relator. In United States ex rel. Schutte v. SuperValu, the Court held in 2023 that what matters is the defendant's subjective belief at the time, not a later reasonable interpretation, which narrowed the defense borrowed from Safeco Insurance Co. v. Burr. A healthcare compliance defense often lives or dies on contemporaneous documents showing the client held a good faith reading of an ambiguous rule.
The stakes are not abstract. In United States ex rel. Drakeford v. Tuomey, the Fourth Circuit affirmed a judgment exceeding 237 million dollars against a South Carolina hospital whose part time physician contracts violated Stark and fed False Claims Act liability. The case showed how a compensation formula that rewards referral volume can survive internal review and still destroy a system, because one lawyer's favorable opinion did not immunize the deal once other advisers flagged it. Healthcare compliance teams cite Tuomey as the reason a single supportive legal memo is thin cover when the structure itself pays for referrals.
Value based coordination rules reshaped the terrain in 2020. Effective January 2021, CMS finalized new Stark exceptions and OIG finalized parallel Anti-Kickback safe harbors for value-based arrangements, keyed to the level of financial risk a participant assumes. Full financial risk and meaningful downside risk arrangements receive broad protection, while care coordination arrangements with no assumed risk get narrower treatment tied to a required infrastructure of governance and outcome measures. These provisions let providers share data analytics, care management tools, and even remuneration that would once have looked like a kickback. A healthcare compliance program that wants to use them has to document the value-based enterprise, the target population, and the outcome measures, because the protection collapses if the paperwork does not match the practice.
Structuring is the front end of the same discipline. Before a hospital signs a physician employment agreement, healthcare compliance counsel run the compensation against the bona fide employment exception, obtain an independent fair market value valuation, and confirm the personal services do not turn on referral volume. The remuneration definition is broad, reaching anything of value, so free rent, discounted services, above market call coverage, and waived management fees all draw scrutiny. When a deal cannot fit a Stark exception, the analysis shifts to whether an Anti-Kickback safe harbor can hold it, and if neither works, whether the arrangement should be restructured or disclosed.
Defenses cluster in a few places. On Stark, counsel argue that an exception applies, that the referral was not for a designated health service, or that compensation was set in advance at fair market value and did not vary with volume. On the Anti-Kickback side, the fight is willfulness and the one purpose reading from Greber. On the False Claims Act, defendants press materiality under Escobar and attack the relator's knowledge theory. The government answers with statistical extrapolation and pattern evidence. A healthcare compliance record built before any subpoena, meaning board minutes, fair market value opinions, audit logs, and signed contracts, is the raw material for every one of these arguments. How that record plays depends heavily on the forum, because state law adds a second layer that federal practitioners sometimes forget.
How forums differ: the biggest state splits, statutes, and cases
Healthcare compliance looks like a federal subject, and the marquee statutes are federal, but a parallel body of state law reaches conduct the government cannot. The federal False Claims Act covers only claims to federal programs. It does not touch a kickback paid to steer commercially insured patients. Several states filled that gap with their own statutes, and the differences among them decide where a relator files and how much a defendant faces. A healthcare compliance program that operates in multiple states cannot assume the federal analysis travels intact across a border. The stakes rise when a state attorney general and a federal prosecutor both claim the same conduct, because a release from one does not bind the other unless the settlement says so. Healthcare compliance planning accounts for that gap from the first day of an internal review.
California went furthest on private insurance. The Insurance Frauds Prevention Act, Cal. Ins. Code 1871.7, lets a private relator and the state pursue anyone who pays or receives kickbacks connected to claims submitted to commercial insurers, with civil penalties per claim plus assessments. That reach matters because a physician arrangement lawful under a Medicare only reading can still draw an IFPA suit when the patients carry private coverage. Illinois built a close cousin in the Insurance Claims Fraud Prevention Act, 740 ILCS 92, which similarly deputizes relators against insurance kickbacks. A healthcare compliance review in either state has to test arrangements against the commercial payer statute, since the qui tam bar there watches medical device and laboratory deals closely.
Most state false claims acts mirror the federal statute closely enough that federal case law governs their interpretation, and states earned a bump in their Medicaid recovery share under 42 U.S.C. 1396h for enacting laws the OIG certifies as at least as effective as the federal one. That certification pushed roughly thirty states toward near identical text. The practical result is that a relator often files a combined federal and state complaint, and a defendant negotiating a global resolution has to satisfy several sovereigns at once. Healthcare compliance counsel treat the state share as a real number in settlement modeling, since a Medicaid heavy practice can owe more to the states collectively than to the United States.
State self-referral law adds a second divergence. California's ban at Business and Professions Code 650.01, often called PORA, prohibits referrals to entities in which the referring provider holds a financial interest, and it applies across payers rather than stopping at Medicare like Stark. The related anti-kickback provision at Business and Professions Code 650 reaches rebates and referral fees in the private market. A group practice that fits the federal in office ancillary services exception can still trip the California statute, since the two do not align exception for exception. Healthcare compliance counsel in the state read both texts side by side before approving an ownership structure.
New York took a different route. Its False Claims Act, codified at State Finance Law 187 through 194, is one of the few that reaches knowingly false tax claims, which means a healthcare defendant can face state fraud exposure that has no federal analog. New York courts read the statute in step with federal materiality doctrine, so Escobar arguments carry over, but the tax reach and the treble damages give the attorney general leverage the federal statute does not supply. Providers with New York operations fold this wider scope into their healthcare compliance risk assessment rather than treating the state act as a copy of the federal one.
Texas enforces through the Medicaid Fraud Prevention Act, Human Resources Code Chapter 36, which the attorney general uses aggressively against unlawful remuneration tied to Medicaid. The statute carries its own penalty structure and does not require the federal willfulness showing in the same terms, so a Texas matter can proceed on a state theory even where a federal criminal case would stall on intent. The state also runs its own managed care audits, which feed the fraud unit leads that mature into civil suits. A healthcare compliance team advising a Texas hospital tracks this act alongside the federal triad because the state can move first and independently.
State privacy and breach law splits from HIPAA on timing and scope. HIPAA gives covered entities up to sixty days from discovery to notify affected individuals, but several states demand faster action. Florida's Information Protection Act requires notice within thirty days, and Colorado and other states set similar short clocks that run independently of the federal deadline. State attorneys general enforce these laws on top of the Office for Civil Rights, so a single hacking incident can generate parallel obligations with different deadlines and different content requirements. A healthcare compliance officer managing a breach has to satisfy the shortest applicable clock, not the federal one, and document the reasoning for each jurisdiction touched by the data.
These state layers change the arithmetic of every matter. A single laboratory marketing arrangement might survive federal scrutiny yet expose the client under California's insurance fraud act, California's self-referral ban, a state breach law, and the federal triad all at once. Healthcare compliance counsel who map the full set of forums early avoid the trap of settling a federal case while a state relator waits in the wings. Knowing which forum a matter will land in shapes the next question, which is how an investigation actually unfolds from the first audit letter to a signed resolution.
The process start to finish: timeline, filings, evidence battlegrounds, and resolution
An enforcement matter rarely opens with a lawsuit. It usually starts with data. CMS contractors run claims through algorithms that flag outliers, and a Unified Program Integrity Contractor, the UPIC, or a Recovery Audit Contractor, the RAC, sends a records request or an overpayment demand. A commercial payer runs the same play through its special investigations unit and issues a clawback. Sometimes the first sign is a whistleblower, a former biller or a competitor, who files under seal. Whatever the source, the early document request sets the frame, and a healthcare compliance team's first job is to preserve records and read the demand for the theory hiding inside it. Reading that first letter closely often reveals whether the contractor suspects a coding pattern or a medical necessity gap the government will later call fraud.
UPIC and RAC audits often rest on extrapolation. The contractor pulls a sample of thirty or forty claims, computes an error rate, and projects it across a universe of thousands, turning a modest sample denial into a seven figure demand. Challenging the statistics is where much of the money is won or lost, because a flawed sampling methodology can void the extrapolation entirely. Medicare gives providers a five level appeal. Redetermination goes to the Medicare Administrative Contractor, reconsideration to a Qualified Independent Contractor, then a hearing before an administrative law judge at OMHA, review by the Medicare Appeals Council, and finally federal court. The OMHA backlog once ran years long, so a healthcare compliance strategy weighs whether to litigate the extrapolation or to negotiate an extended repayment. Missing an appeal deadline forfeits the right to contest the debt, and interest accrues throughout.
The qui tam track runs on its own clock. A relator files under seal under 31 U.S.C. 3730(b), and the complaint stays sealed for at least sixty days while the government investigates, though extensions routinely stretch that to years. During the seal the defendant may not even know a case exists, though a Civil Investigative Demand for documents and testimony often signals that something is moving. The government then decides whether to intervene. Intervention raises the stakes sharply, because DOJ's resources and credibility change the settlement dynamic, while a declined case can still proceed if the relator's counsel is willing to fund it. A healthcare compliance investigation that runs in parallel, quietly assessing the same claims, lets the client decide whether to fight, settle, or disclose before the seal lifts.
Telehealth billing produced a distinct enforcement wave. After the public health emergency loosened site and modality rules, DOJ and OIG pursued schemes built on telemarketed consults that generated orders for genetic tests, orthotic braces, pain creams, and cardiac monitors the patient never needed. The 2021 and 2022 national takedowns charged billions in intended loss tied to these referral mills. The pattern that draws scrutiny is a telehealth company paying per order or per consult rather than for time, which reads as a kickback. Providers that billed audio only visits during the emergency face a separate documentation problem, since the covered code set narrowed again as the waivers expired, and a claim proper in 2020 can look deficient under the rules that returned afterward. A healthcare compliance program using telehealth now separates clinician compensation from order volume and keeps documentation showing a real patient encounter behind each claim.
When an internal review finds an actual overpayment or a kickback, the client faces a disclosure decision, and the choice of channel matters. The OIG Self Disclosure Protocol handles conduct that potentially violates the Anti-Kickback Statute or otherwise involves fraud, and it offers a reduced multiplier, generally 1.5 times single damages, plus a release and usually no Corporate Integrity Agreement for cooperative disclosers. Stark only violations, meaning technical self referral problems without kickback intent, go to the CMS Self Referral Disclosure Protocol instead, which can settle for far less than full repayment. Picking the wrong forum wastes leverage. A kickback disclosed to CMS gets bounced, and a pure Stark foot fault sent to OIG invites a harsher frame. The federal overpayment rule also imposes a sixty day clock to return identified overpayments under 42 U.S.C. 1320a-7k(d), so a healthcare compliance team cannot sit on a confirmed overpayment while it debates strategy.
Exclusion screening runs underneath all of this as a continuing duty. A person or entity on the OIG List of Excluded Individuals and Entities may not be paid by any federal health program, and employing one triggers civil monetary penalties per claim. The obligation is monthly, and it covers employees, contractors, vendors, and referring physicians, checked against both the LEIE and the System for Award Management. A healthcare compliance officer who screens at hire but never again will eventually pay someone who was excluded after onboarding, and the penalties compound quickly. Delegating the check to a payroll vendor does not transfer the liability, so the program keeps its own dated screening logs.
Resolution takes a few forms. A civil False Claims Act case ends in a settlement agreement with a payment, a release, and often a Corporate Integrity Agreement that installs an independent review organization and years of reporting. An OCR breach investigation ends in a resolution agreement with a corrective action plan and a monetary settlement, or, for smaller lapses, technical assistance. A Medicare overpayment ends in repayment or a negotiated schedule. Each path leaves an obligation that outlasts the check, and the terms a healthcare compliance team negotiates at resolution, the scope of the release, the length of the integrity term, the lookback period, and the metrics the reviewer will audit, shape the client's operations for years after the file closes.
The numbers that matter: exposure, valuation, and the shape of a resolution
The check clears, but the arithmetic behind it decides how hard each side fights. In fiscal year 2023 the Department of Justice recovered more than $2.68 billion under the False Claims Act, and more than $1.8 billion of that total came from health care. That year set a record with 543 settlements and judgments. A healthcare compliance team reading those numbers should see the volume of resolved matters and the share that falls on hospitals, laboratories, physician groups, and drug manufacturers.
Damages drive settlement posture. The False Claims Act multiplies the government's single damages by three and adds a per-claim civil penalty that the agencies raise for inflation each year, a figure that now exceeds $27,000 per claim at the top of the range. A billing dispute worth a few hundred dollars per line becomes severe once you multiply by claim count and stack penalties on top. Single damages are the starting number, and much of the fight in a healthcare compliance matter turns on how the parties define it: the amount paid, the amount that should have been paid, or the full value of every claim a kickback touched.
Stark works on a different mechanism because it denies payment outright. A physician self-referral that violates 42 U.S.C. 1395nn renders the resulting claims non-payable, so the base exposure is everything Medicare paid for the tainted services, with civil penalties and False Claims Act liability layered above it. No intent showing reduces that base. Anti-Kickback exposure adds a criminal fine up to $100,000 per violation and up to ten years in prison, plus civil monetary penalties under 42 U.S.C. 1320a-7b(b). One arrangement can spawn parallel Stark, kickback, and False Claims Act theories, and a healthcare compliance officer treats a single suspect contract as a problem on three fronts.
Penalties compound in ways clients underestimate. Each claim form, each line item, and each certification can count as a separate violation, so a routine of daily submissions over several years turns into a claim count in the thousands before single damages enter the math. Courts have curbed the most extreme stacking on Eighth Amendment grounds, but the risk of a penalty award that dwarfs actual loss is real leverage in negotiation. The government knows it, and the defense has to answer it with a defensible claim count of its own.
HIPAA money runs on its own track. The civil penalty tiers scale with culpability, from a genuine lack of knowledge at the bottom to willful neglect left uncorrected at the top, each tier with a per-violation amount and an annual cap that the Office for Civil Rights adjusts for inflation. One unencrypted laptop can expose thousands of individuals, and OCR counts by record and by requirement violated. The breach portal tells the volume story plainly: OCR posts hundreds of breaches affecting 500 or more individuals every year, and hacking and IT incidents dominate the cause codes. A healthcare compliance program that cannot produce a current risk analysis meets that statistic without a defense.
Valuation is where seasoned counsel earns the retainer. The government opens at single damages times three, but the resolution figure reflects ability to pay, the quality of cooperation, the timing of any disclosure, and the litigation risk each side carries. A provider that self-discloses early and documents a good-faith calculation often resolves at a lower multiple than one that surfaces through a whistleblower. The relator's share, between 15 and 30 percent under the statute, tells you a qui tam plaintiff and plaintiff's counsel sit across the table with their own economic stake, and the defense has to account for that incentive when it weighs settlement against trial.
The obligation that follows the payment carries a price of its own. A Corporate Integrity Agreement can run five years, install an independent review organization, and require annual claims sampling with error-rate thresholds that trigger further review. Budget the reviewer's fees, the internal hours, and the reporting cadence, because those recurring costs frequently exceed the headline settlement over the life of the term. When counsel negotiates the lookback period, the sample size, and the definition of a reportable event, the client feels the result in every audit cycle that follows, so healthcare compliance valuation should include the integrity term, not just the check.
Telehealth enforcement added a new column to these tables. The 2020 flexibilities widened the door for remote visits, and the enforcers followed the money into audits and indictments aimed at high-volume ordering, marketing arrangements, and durable medical equipment referrals routed through telehealth platforms. A review of a telehealth book should track the ratio of orders to documented encounters, because that ratio is exactly what a data-mining contractor flags. The dollar figures in these cases climb fast once the government aggregates claims across a referral network.
Exclusion screening looks cheap until it is not. Every dollar a provider bills for an item or service furnished by an excluded person is an overpayment, and civil monetary penalties can reach into the five figures per item on top of repayment. Monthly checks against the OIG List of Excluded Individuals and Entities cost far less than one missed name across a payroll cycle. The 60-day repayment rule from 42 U.S.C. 1320a-7k(d) turns an identified overpayment into reverse False Claims Act liability if it sits, so the economics reward the provider that quantifies and returns money promptly.
Buyers should also price counsel with the numbers in front of them. When a client uses this directory to compare firms, the plan-tier ordering is disclosed on its face, so a higher placement reflects the firm's chosen plan tier rather than a concealed quality ranking. That transparency lets a healthcare compliance buyer weigh a firm's stated experience, its verification status, and its fee model against placement, instead of guessing what drove the order. Read the tier label, then read the credentials.
Choosing the right lawyer for this specific matter
The doctrine you met at the start of this guide decides which lawyer you need now. A Stark problem is a strict-liability, structural problem, so it rewards a lawyer who reads the exceptions like an engineer reads a schematic and can rebuild an arrangement to fit one. An Anti-Kickback question turns on intent and the shape of a safe harbor, which calls for someone who can argue purpose and paper a deal defensively. A False Claims Act case is a litigation and multiplier problem, so it wants a trial lawyer who has argued materiality and scienter after Universal Health Services v. Escobar. Ask which of these frameworks your matter really sits in before you match a healthcare compliance lawyer to it.
Look for the parts of a resume that map to enforcement. A former Assistant United States Attorney who ran civil health care fraud cases knows how the government builds single damages from a claims universe. A lawyer who served inside OIG or CMS knows how the Self-Disclosure Protocol and the Self-Referral Disclosure Protocol read from the other side of the desk, and how a line attorney reacts to a lowball calculation. Board certification in health law, where a state offers it, signals a healthcare compliance practice rather than a general litigator taking an occasional matter. Depth in one payer program does not always transfer to another, so ask about Medicare, Medicaid, and commercial work separately.
Match the engagement to the task in front of you. Structuring a physician compensation model or a value-based arrangement is transactional work, and it belongs with counsel who lives in the Stark exceptions and the 2020 safe harbors. Defending a UPIC audit or a payer clawback is an administrative appeals problem with tight deadlines and a fixed evidentiary record. Responding to an OCR breach investigation is a privacy and security matter that leans on the risk analysis and the 60-day notification file. A healthcare compliance firm that does all of these well will still staff each one differently, so ask who actually handles your file day to day.
Press on staffing and recent work. Ask how many self-disclosures the firm filed in the last two years, and whether those went to OIG, to CMS, or to a state Medicaid program, because the calculus differs at each door. Ask who signs the correspondence and who negotiates with the government. A partner who pitches the matter and then hands it to a junior associate is a common source of client frustration, so get the working team named in the engagement letter and ask for their direct hours.
Watch for the parallel-track risk that defines these cases. A single set of facts can produce a civil False Claims Act inquiry, a criminal referral, an OCR investigation, and a licensing board complaint at once, and statements made in one forum bind the client in the others. Counsel has to sequence disclosures so an admission useful to the government in a repayment does not hand a relator a summary-judgment fact. A healthcare compliance lawyer who has only ever handled one of these tracks may not see the trap in the next one. Ask directly whether the firm coordinates the criminal and civil tracks alongside the administrative one under a single roof.
Fee structure should match the shape of the work. Transactional structuring and program builds fit flat or capped fees, while an audit appeal or a False Claims Act defense usually runs hourly, sometimes at a blended rate, and the client should ask for a staffing budget by phase. When you compare firms through this directory, the profiles carry dated, editor-reviewed verification checks that confirm a firm's bar standing and any disciplinary history as of a stated date. A healthcare compliance buyer should read the date on that check, because a verification from two years ago is not the same as one refreshed this quarter.
Use the verification the way a diligence lawyer would. The dated check tells you the directory confirmed the firm's license and reviewed its listed focus at a point in time, not that any outcome is promised. Cross-read it against the lawyer's own disclosures, the reported matters, and the OIG guidance the firm cites when it describes its healthcare compliance work. If a profile claims deep self-disclosure experience but the named team shows no enforcement background, that gap is worth a question. Verification narrows the field, and the interview closes it.
Then take the analysis back to where it began. The arrangement either fits a Stark exception or it does not, and no lawyer's confidence changes that binary. The kickback question either has a corrupt purpose behind it or a defensible one, and the documents will show which. The False Claims Act claim either alleges a lie that mattered to payment or it does not, and Escobar gives the client room to argue that point on materiality. A healthcare compliance lawyer worth hiring will tell you which of those sentences describes your matter on the first call, before the retainer, and will price the work to the framework rather than to the fear.
Sources & references
| [1] | HHS OIG, 2024. False Claims Act settlements and judgments exceed $2.68 billion in fiscal year 2023. |
| [2] | HHS Office for Civil Rights, 2024. Breach portal: cases affecting 500 or more individuals. |
| [3] | HHS OIG, 2023. General Compliance Program Guidance. |
| [4] | U.S. Congress, 2009. 31 U.S.C. 3729, False Claims Act. |
| [5] | U.S. Congress, 1989. 42 U.S.C. 1395nn, physician self-referral (Stark). |
| [6] | U.S. Congress, 1972. 42 U.S.C. 1320a-7b, Anti-Kickback Statute. |
| [7] | Supreme Court of the United States, 2016. Universal Health Services, Inc. v. United States ex rel. Escobar. |
| [8] | HHS OIG, 2021. Health Care Fraud Self-Disclosure Protocol. |
This guide is general information, not legal advice. Statutes and case law change; confirm current law with a licensed attorney in your state.
Frequently asked questions
What is the practical difference between a Stark violation and an Anti-Kickback violation?
Stark is a strict-liability statute, so a self-referral that does not fit an exception creates liability regardless of intent, and the claims simply become non-payable. The Anti-Kickback Statute requires proof that one purpose of an arrangement was to induce or reward referrals, so intent and the fit of a safe harbor drive the analysis. One suspect contract can violate both, which is why the two often appear side by side in the same investigation.
Why is the False Claims Act called an enforcement multiplier?
The False Claims Act converts an underlying Stark or kickback problem into treble damages plus a per-claim civil penalty that now exceeds $27,000 per claim at the top of the range. Because each claim can count separately, a large claims universe can produce exposure far larger than the actual overpayment. The statute also lets private relators sue on the government's behalf and share in the recovery, which adds a whistleblower incentive to the mix.
What did the 2020 value-based safe harbors and exceptions change?
They created new pathways under both Stark and the Anti-Kickback Statute for arrangements built around value-based enterprises that assume defined financial risk and coordinate care. The protection scales with how much downside risk the parties take, so a full-risk arrangement gets broader relief than a care-coordination model. They do not erase the underlying rules, and documentation of the value-based purpose is what makes the protection usable.
Why does OCR keep citing risk analysis as the top HIPAA finding?
A HIPAA risk analysis has to be enterprise-wide, current, and specific to the systems that hold protected health information, and many organizations produce a one-time checklist instead. When a breach happens, OCR asks for the analysis first, and a stale or narrow one becomes evidence of willful neglect. Keeping it dated, repeated, and tied to actual remediation is the single most useful thing a security program can document.
How does the HIPAA 60-day breach notification clock work?
For a breach of unsecured protected health information, covered entities generally must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more individuals also require prompt notice to HHS and the media, while smaller breaches can be logged and reported to HHS annually. The clock runs from discovery, so delayed detection does not extend the deadline once the organization should have known.
What are the OIG seven compliance-program elements, and what changed in 2023?
The seven elements are written standards, a compliance officer and oversight, training, effective communication, monitoring and auditing, enforcement through discipline, and prompt response to detected problems. The November 2023 General Compliance Program Guidance restated these for all health care participants and folded in current expectations around risk assessment and board engagement. It is guidance rather than a mandate, but enforcers read a program against it when they judge whether a compliance effort was real.
What is the difference between a UPIC audit and a RAC audit?
Unified Program Integrity Contractors focus on suspected fraud and can request records, conduct site visits, and refer matters for payment suspension or law enforcement. Recovery Audit Contractors are paid on a contingency basis to find and recoup improper payments, and their reviews are more mechanical. Both carry appeal rights and deadlines, but a UPIC contact signals a higher-stakes integrity inquiry and usually warrants counsel early.
Should a Stark overpayment go through the OIG SDP or the CMS SRDP?
A pure Stark self-referral problem generally belongs in the CMS Self-Referral Disclosure Protocol, which is built to resolve technical Stark violations. Matters involving kickbacks or other conduct within OIG's authority go through the OIG Self-Disclosure Protocol, which can address civil monetary penalty exposure. When the facts touch both, counsel has to choose the door carefully, because the release and the settlement math differ at each one.
Why is telehealth billing drawing so much enforcement attention?
The 2020 pandemic flexibilities expanded remote billing quickly, and enforcers followed the data into high-volume ordering, marketing arrangements, and equipment referrals routed through telehealth platforms. The common red flag is a mismatch between the number of orders and the depth of documented patient encounters. Providers should audit that ratio themselves, because it is exactly what a data-mining contractor uses to build a case.
How do I verify a firm through this directory before hiring it?
Where a firm has earned verification, its dated, editor-reviewed check confirms the firm's bar standing and reviews its listed practice focus as of a specific date. Read that date first, because a verification refreshed this quarter carries more weight than one from two years ago. Treat it as diligence rather than a guarantee, and cross-read it against the lawyer's own disclosures and the enforcement background of the team named in your engagement letter.
This page lists law firms for informational purposes only and is not legal advice, a referral, or an endorsement. VerifiedLawFirms does not match, recommend, or refer clients to firms — you choose who to contact.