Healthcare compliance briefing

Compliance Minute

A short, plain-English read on the regulatory developments that matter for healthcare compliance programs. Published Monday, Wednesday, and Friday, grounded in official government sources.

Wednesday, September 9, 2026

Missouri Medicaid Coverage Cutoff Deadline Removed — Act Now

A critical deadline just disappeared from Missouri's radar.

MO HealthNet removed a provider notification about the end of coverage for acupuncture, chiropractic, and physical therapy services under its Complementary Health and Alternative to Chronic Pain Management program. The coverage ends June 30, 2026 — but the deadline notification is now off their public provider page.

Why this matters: Providers who didn't see or bookmark the original notice may miss the cutoff entirely and unknowingly bill for non-covered services after June 30, 2026, triggering compliance violations and payment clawbacks. Your compliance team could face false claims exposure if billing continues post-deadline.

The practical risk: You may have in-network providers in Missouri still building these services into their workflows and staffing plans, unaware of the sunset date.

Do this today: Audit your provider network agreements and contact any Missouri-based partners offering these three services. Confirm they know coverage terminates June 30, 2026, and document that notification. Flag this date in your billing/coding systems now — don't wait until Q2 2026 scrambling to correct claims.

Wednesday, September 9, 2026

Missouri Medicaid Removes Pain Management Coverage Deadline

What happened: Missouri's Department of Health and Senior Services (DHSS) removed a critical notification about coverage ending for acupuncture, chiropractic, and physical therapy services under its Complementary Health and Alternative to Chronic Pain Management program. The deadline was July 1, 2026.

Why it matters: Removing this notification doesn't erase the July 1 deadline—it just makes it easier to miss. Providers who don't stop billing these services after June 30 will face claim denials, payment clawbacks, and potential compliance violations. Your organization needs to track this independently now that DHSS has quietly buried it.

The risk: Compliance officers at practices offering these services may assume coverage continues if they're not actively monitoring state Medicaid updates. One missed deadline could create billing and audit exposure across multiple claims.

Action today: If your organization provides acupuncture, chiropractic, or physical therapy in Missouri, flag July 1, 2026 on your compliance calendar now. Contact Missouri MO HealthNet directly to confirm the deadline and verify no other changes have been quietly removed from their website.

Tuesday, September 8, 2026

Medicare Lab Fraud Takedown: What Your Network Needs

CMS (Centers for Medicare & Medicaid Services) just revoked 157 fraudulent laboratory providers from Medicare, blocking $1.6 billion in improper payments. This isn't just a headline — it signals aggressive enforcement focused on lab billing patterns and credential verification.

For compliance officers, this means two immediate risks: labs in your network may face sudden enrollment scrutiny if they're on CMS's watchlist, and your organization could face liability if you're referring to or credentialing compromised providers without proper due diligence.

Fraudulent labs typically exploit weak referral controls, billing for unnecessary tests, or using ghost billing practices. Your organization needs to know who's actually processing your lab work and whether their Medicare enrollment is clean.

Action for today: Pull a current list of all lab providers in your network (in-house and contracted) and verify their Medicare enrollment status in real time using PECOS (Provider Enrollment, Chains, and Ownership System). Flag any recent changes or enrollment suspensions for immediate review with your compliance and contracting teams.

Sunday, September 6, 2026

Price Transparency Rules Just Got Stricter

Executive Order 14221 is tightening healthcare price transparency requirements — and it applies to nearly every provider and health plan.

Here's what's new: Hospitals must display pricing for shoppable services and publish machine-readable files of negotiated rates. Health plans need to post negotiated rates, out-of-network payments, and prescription drug prices with accessible consumer tools. The order builds on existing transparency mandates but adds teeth through enforcement and reputational risk.

The compliance implication: If your pricing information isn't readily accessible, accurate, or machine-readable, you're now a higher enforcement priority. The regulatory environment has shifted from "nice to have" transparency to "must have."

What to do today: Audit your current price transparency disclosures. Check whether your negotiated rates files are truly machine-readable (not just PDFs), your shoppable services list is complete, and your consumer tools actually work. If gaps exist, flag them to leadership now — enforcement actions are already happening across the industry.

Thursday, September 3, 2026

New Pricing Transparency Rules: Patient Access to Cost Data

Executive Order 14221 just raised the bar on healthcare pricing transparency. Providers and payers now have to give patients clear, accurate, and actionable pricing information—not just compliance-checkbox disclosures.

This isn't optional. Your organization needs new disclosure processes and systems to meet these requirements, or you're exposing yourself to regulatory scrutiny and reputational risk. Compliance officers should expect enforcement focus here.

The practical takeaway: You likely need to audit current pricing disclosure practices, identify gaps between what you're publishing and what "clear and actionable" actually means, and build workflows to deliver real pricing data before patients make care decisions.

Action for today: Schedule 30 minutes with your revenue cycle and patient access teams to inventory current pricing disclosure methods. Identify your biggest gaps—missing procedures, unclear cost-sharing explanations, or outdated fee schedules. You'll need a roadmap within the next 30 days.

Tuesday, September 1, 2026

Lab Billing Under Fire: $1.6B in Fraud Prevented

CMS just announced $1.6 billion in prevented fraudulent Medicare laboratory payments this week, along with 157 provider revocations. Translation: the feds are scrutinizing lab billing like never before.

Here's why this matters for your organization: If your health system owns or contracts with any lab—in-house or outsourced—you're in the enforcement crosshairs. Billing errors that might have slipped through five years ago are now triggering immediate investigation and provider termination.

The risk isn't just financial penalties. Revocation means your lab can't bill Medicare at all. Your entire revenue stream stops.

What you need to do today: Pull your lab billing audit from the last 12 months. Look specifically at test ordering patterns, modifier usage, and duplicate billing. If you spot anything questionable, flag it for your lab director and compliance team now—before CMS does. Don't wait for a survey.

This is the moment to get ahead of it.

Sunday, August 30, 2026

Lab Billing Crackdown: 157 Providers Revoked This Week

CMS just revoked 157 fraudulent Medicare laboratory providers and stopped $1.6 billion in improper payments. This isn't a slow-motion enforcement action—it's an active, aggressive sweep.

Here's what this means for you: Lab billing is a high-risk target right now. If your organization operates, contracts with, or refers to laboratory providers, you're in the enforcement spotlight. Improper lab billing—whether it's unnecessary tests, inflated coding, or credential violations—will get caught and hit hard.

The compliance implication is straightforward: weak lab provider oversight and billing controls create direct financial and reputational liability. One bad lab vendor can sink your compliance record.

Action today: Pull your lab billing data from the last 12 months and audit at least one high-volume lab vendor's credentials, billing patterns, and test justification documentation. If you don't have a lab billing audit process, build one by end of week. This is no longer optional—it's survival.

Thursday, August 27, 2026

CMS AI Strategy: Your Automation Compliance Checklist

CMS just published its AI and Machine Learning (ML) strategy for Medicare and Medicaid operations — and it's not optional reading.

The agency is embedding AI/ML across coverage decisions, coding, billing, claims processing, and provider reimbursement. That means the systems your organization relies on are changing, potentially without your knowing it. The compliance risk is real: automated decision-making can introduce bias, reduce transparency, and create audit exposure if you're not tracking what algorithms are doing or why.

For compliance officers, this means you need visibility into which automated systems your organization currently uses and which ones will be affected by CMS policy shifts. You also need to understand how your vendors are explaining their algorithms — "black box" systems are increasingly indefensible in audits.

Action item: Schedule a meeting with your IT, billing, and clinical leadership this week to inventory all AI/ML systems in your pipeline. Ask one critical question: Can you explain to a government auditor exactly how each system makes decisions? If the answer is no, that's your gap to close first.

Tuesday, August 25, 2026

Substance Use Disorder Records: Disclosure Risks Are Real

If your organization treats patients for substance use disorder (SUD), you're sitting on some of the most heavily protected patient data in healthcare. 42 CFR Part 2 creates a federal firewall around SUD treatment records — stricter than HIPAA (Health Insurance Portability and Accountability Act) — and unauthorized disclosures carry serious penalties, including criminal liability.

Here's what makes this dangerous: staff often don't realize that SUD patient records need different handling than standard medical files. Releasing a patient's identity or treatment details without explicit written consent — even to insurance companies, law enforcement, or family members — violates federal law. We're talking potential fines and loss of federal funding.

Compliance officers need to ensure your team understands when disclosure is actually permitted (court orders require careful review; routine authorizations don't cut it).

Action: Schedule a 30-minute training session this week for anyone handling SUD patient records. Cover consent requirements, permitted disclosures, and your organization's release procedures. One preventable mistake isn't worth the fallout.

Sunday, August 23, 2026

Elder Fraud Red Flags: What You Need to Know

The DOJ Elder Justice Initiative just released updated guidance on healthcare fraud targeting elderly beneficiaries—and it's a wake-up call for all of us.

Here's the reality: elder fraud isn't just a Medicare problem. It overlaps with physical abuse, financial exploitation, neglect, and sexual abuse. Your organization likely treats seniors, and you need detection and reporting systems in place to catch suspicious patterns before they become liability issues.

For compliance officers, this means two things: (1) your team needs to know the red flags the DOJ identifies, and (2) your reporting mechanisms need to actually work when someone spots something wrong.

Action item for today: Pull your current elder abuse and fraud detection policies off the shelf. Compare them against the DOJ guidance (available in the Elder Justice Initiative materials). Identify one gap—just one—and fix it this week. Then schedule a brief training with your clinical staff on what suspicious activity actually looks like.

Don't wait for a survey finding or an investigation. Act now.

Thursday, August 20, 2026

CMS Expands ABA Oversight — Your Compliance Checklist

CMS just released a new State Toolkit for Applied Behavior Analysis (ABA) services under Medicaid and CHIP, tightening oversight of autism care for children. If your organization delivers, coordinates, or bills for ABA services, this matters immediately.

The toolkit mandates child-centered, evidence-based care standards and strengthened program integrity controls. Translation: CMS is cracking down on quality gaps and billing abuse in this space. Non-compliance could trigger audits, recoupments, and reputational damage—especially given the vulnerable population.

Non-ABA providers shouldn't tune out either. If you refer patients or work with ABA vendors, you need confidence they're meeting these new standards.

Action: Pull your ABA service agreements and documentation practices today. Map them against CMS's toolkit requirements. If gaps exist, flag them to your leadership and start remediation this week. If you don't currently provide ABA services, confirm your vendor partners are aligned with the new standards.

Tuesday, August 18, 2026

Medicare Payment Rules: What Changed in Part 424

The Issue: 42 CFR Part 424 (Conditions for Medicare Payment) governs the fundamental rules every Medicare-participating provider must follow to get paid. When this regulation updates, it directly affects billing practices, enrollment requirements, and compliance obligations across your entire organization.

Why It Matters: Your compliance program can't just focus on billing accuracy—you also need to track whether your organization still meets enrollment eligibility, documentation standards, and operational requirements to stay in the Medicare program. A lapse here isn't just a claim denial; it's a program participation risk.

What You Should Do Today: Pull up your current Part 424 compliance checklist and cross-reference it against the latest published version of the regulation. Specifically, verify that your enrollment data is current, your billing practices align with stated requirements, and your documentation processes capture what Medicare requires. If your checklist is more than a year old, rebuild it. Flag any gaps to your billing and operations teams this week.

This isn't optional—it's foundational.

Sunday, August 16, 2026

NPI Maintenance: Don't Let Provider IDs Lapse

Your National Provider Identifier (NPI) is your ticket to Medicare and most insurance claims. A lapsed, incorrect, or unused NPI creates billing rejections, payment delays, and audit red flags—fast.

Here's the compliance reality: CMS and payers actively monitor NPI validity. If your organization submits claims with inactive NPIs or fails to update provider information within required timeframes, you're looking at claim denials, overpayment recoupment notices, and potential fraud findings during audits. The administrative burden alone—tracking down lost revenue and reprocessing claims—costs real money.

The practical hit: One provider with an expired NPI can stall an entire department's revenue cycle. Multiple lapsed NPIs across your organization compound the problem exponentially.

Action for today: Pull a report of all NPIs in your billing system and cross-check them against the NPI Registry (npiregistry.cms.hhs.gov). Verify each one is active and tied to the correct provider. Flag any mismatches or inactive registrations for immediate remediation. Make this an annual audit requirement going forward.

Thursday, August 13, 2026

Survey Season Approaching: Know Your Deficiency Risks

CMS survey cycles are ramping up, and deficiency citations under 42 CFR Part 488 are hitting providers hard. This regulation sets the roadmap for how CMS inspectors evaluate compliance, assign citations, and escalate enforcement—including payment suspension or loss of your Medicare provider agreement.

The practical reality: a single survey finding can cascade into costly remediation plans, public reporting, and reputational damage. Your compliance program needs to be audit-ready *before* surveyors knock on the door, not after.

Here's what to do today: Pull your last three survey reports and deficiency citations. Map them against your current policies and training. If you see repeat patterns or unresolved findings, escalate immediately to leadership. Don't assume past fixes stuck—verify them. Then schedule a mock survey walk-through in your highest-risk departments within the next two weeks. The surveyors are coming. Be ready.

Tuesday, August 11, 2026

ABA Services: New Medicaid Oversight Requirements

CMS just released a state toolkit requiring strengthened program integrity protections for Applied Behavior Analysis (ABA) services under Medicaid and CHIP. This covers behavioral health treatment for children with autism—a high-utilization, high-cost service line.

Why it matters: States are implementing tighter oversight of provider qualifications, service authorization, billing practices, and fraud detection. If your organization provides or refers ABA services, you're in scope. Compliance gaps here create exposure to overpayment recoupment, audit findings, and exclusion risk.

The practical hit: You need to audit your current ABA contracting, credentialing, and billing workflows against the new toolkit standards. Non-compliance isn't optional—states are already rolling these out.

Action item: If you work with Medicaid, pull your current ABA program documentation and cross-reference it against CMS's new toolkit. Flag any gaps in prior authorization, provider qualification verification, or billing documentation for immediate remediation.

Sunday, August 9, 2026

Medicare PHP Coverage: Check Your Medical Necessity Documentation

Here's what's happening: Medicare's National Coverage Determination (NCD) 160.2 on Partial Hospitalization Programs (PHP) is your rulebook for intensive outpatient mental health and substance abuse treatment — and your biggest exposure for denials and audits if you're not documenting correctly.

Why it matters: PHP is high-touch, high-cost care. Medicare's conditions of participation aren't suggestions. If your organization bills PHP services without ironclad medical necessity documentation and proper coding, you're looking at claim denials, overpayment recoupment, and potentially OIG radar.

The practical issue: Many providers treat PHP documentation like standard outpatient visits. It's not. You need specific clinical criteria, ongoing assessment requirements, and clear justification for the intensity level billed.

Action item: Pull 5–10 recent PHP charts and audit them against NCD 160.2's coverage criteria today. Check whether your providers are documenting the clinical facts that *justify* the PHP level of care, not just treating the patient. If gaps exist, flag them now before external reviewers do.

Thursday, August 6, 2026

Elder Fraud Red Flags: What You Need to Know

The Department of Justice (DOJ) Elder Justice Initiative is signaling increased focus on healthcare fraud targeting Medicare and Medicaid beneficiaries aged 65+. This isn't just about billing errors—it includes physical abuse, financial exploitation, and neglect connected to fraudulent billing schemes.

For compliance officers, this means your organization needs to actively identify and report suspicious patterns involving elderly patients: unnecessary services, repeated emergency visits, billing for services not rendered, or coordination with bad actors in billing or care authorization. Failure to spot and report these red flags exposes your organization to False Claims Act liability, not just healthcare fraud penalties.

Here's what to do today: Pull your last 90 days of claims data and flag any high-volume providers or service patterns involving patients 65+ that seem unusual—repeat admissions, high-cost procedures without clear clinical justification, or billing anomalies. Brief your clinical and billing teams on what elder exploitation looks like in your workflows. Document it. Then decide if you need external counsel to evaluate whether disclosure to DOJ makes sense for your organization.

This is a compliance moment.

Tuesday, August 4, 2026

Medicare Payment Eligibility: Documentation Standards Tightening

The Risk: CMS (Centers for Medicare & Medicaid Services) continues to scrutinize documentation and billing practices under 42 CFR Part 424, the foundational Medicare payment rule. Audits are flagging incomplete clinical documentation, inadequate medical necessity support, and billing misalignment with actual services rendered — triggering recoupments and compliance violations.

Why This Matters: Your organization's Medicare reimbursement hinges on meeting Part 424 requirements. Documentation deficiencies don't just cost money; they create audit trails that invite fraud investigation and can jeopardize your provider enrollment status entirely.

What to Do Today: Pull a sample of your last 20 Medicare claims and audit them against the documentation in your EHR. Specifically check that clinical notes support the billed service level and that all required elements (medical necessity, patient identification, provider credentials) are present and dated. If you find gaps, flag your billing and clinical leadership — this is fixable, but only if caught early.

Small documentation gaps compound fast.

Sunday, August 2, 2026

CMS FY 2027 Payment Changes: Review Your Models Now

CMS (Centers for Medicare & Medicaid Services) just finalized FY 2027 Medicare payment rates and policy updates, including a nationwide expansion of joint replacement care coordination programs and revised inpatient and long-term care payment formulas.

What this means for you: Your organization's reimbursement may shift—potentially significantly—depending on your service lines and care delivery model. If you participate in Medicare, these changes could affect budgets, staffing decisions, and even which services remain profitable.

The compliance angle: Payment policy changes often trigger care delivery requirement changes too. You need to understand not just the money side, but any new participation rules, documentation standards, or quality metrics embedded in these updates. Missing the operational implications can lead to inadvertent non-compliance down the line.

Your action today: Request that your finance and clinical operations teams brief you on how the FY 2027 updates impact your organization. Specifically ask: (1) Which payment models do we participate in? (2) What's changing? (3) What compliance or documentation changes do we need to implement? Don't wait for the audit cycle to discover this.

Thursday, July 30, 2026

Medicare Payment Rules Change — Review Your Billing Now

CMS just released significant Medicare physician payment reforms and updated foundational billing requirements under 42 CFR Part 424. This isn't incremental—these changes will reshape how your organization gets paid and what documentation you need to keep.

Here's what matters: Part 424 governs enrollment, billing practices, and payment eligibility for Medicare. Any updates here ripple across your entire revenue cycle. If your billing processes, provider credentials, or documentation standards don't align with the new rules, you're at risk for claim denials, overpayment recapture, or audit findings.

Compliance officers need to flag this immediately because revenue teams often lag on regulatory updates, and the payment models themselves are transforming—meaning your current workflows may already be outdated.

Action: Pull your compliance team and billing leadership together this week. Review the CMS newsroom update and Part 424 changes side-by-side. Identify which billing workflows, enrollment processes, or documentation requirements need updates before they cause payment problems.

Tuesday, July 28, 2026

HIPAA Administrative Requirements: What's Actually Required

45 CFR Part 160 — HIPAA's foundational administrative regulation — continues to be a compliance pressure point across all covered entities and business associates. The stakes are high: misalignment on privacy, security, or breach notification requirements can trigger Office for Civil Rights (OCR) investigations, penalties, and reputational damage.

Here's the practical reality: many organizations treat HIPAA compliance as a checkbox exercise, but OCR audits increasingly focus on whether your policies actually match your operations. That gap is where enforcement actions live.

Your move today: Pull your current HIPAA compliance documentation (policies, training logs, risk assessments, business associate agreements). Compare it against what 45 CFR Part 160 actually mandates — not what you think it says. If you spot gaps between policy and practice, flag them for remediation now, before an audit does it for you. This isn't glamorous work, but it's the foundation everything else rests on.

Don't wait for an OCR notice to tighten this up.

Sunday, July 26, 2026

Medicare Payment Conditions: What Your Billing Team Needs Now

CMS is signaling major shifts to Medicare reimbursement models through proposed rules this week, and 42 CFR Part 424 — the foundational regulation for Medicare payment eligibility — is the baseline you need to audit right now.

Part 424 governs everything: provider enrollment status, billing practices, and the conditions your organization must maintain to stay in the Medicare program. If your enrollment, credentialing, or billing workflows have drifted from this regulation, you're facing denied claims, overpayment recoupment demands, and potential exclusion risk.

The practical hit: A single billing error tied to Part 424 non-compliance can trigger audits across your entire patient population. Your compliance program's credibility hinges on getting this right.

Action today: Pull your last three Medicare enrollment verification letters and have your billing director walk you through the specific conditions listed. Identify any gaps between what's required and what you're actually doing. Don't wait for the new rules — fix the foundation first.

Thursday, July 23, 2026

Medicare Payment Reforms: What Your Organization Needs to Know

CMS (Centers for Medicare & Medicaid Services) is proposing significant Medicare reforms that will reshape how physicians get paid and how healthcare organizations structure themselves around accountable care models. The shift toward value-based payment is accelerating, and these aren't minor tweaks—they affect enrollment requirements, billing practices, and payment eligibility across the board.

For compliance officers, this means your organization's current payment methodologies and participation agreements may need updating. You'll need to understand which proposed rules apply to your entity type and when implementation occurs.

Here's what matters: These changes directly impact your Medicare enrollment status, billing compliance, and potential penalties for non-compliance. Missing the comment period or failing to prepare internally could mean scrambling later.

Action item for today: Pull up CMS-2452-P specifically and identify which proposed indirect hold harmless thresholds affect your organization. Flag this for your CFO and legal team by end of week. You don't need to comment yet, but you need to understand the exposure.

Tuesday, July 21, 2026

Executive Order 14219: Your Fraud Prevention Playbook Just Changed

Executive Order (EO) 14219 — Eliminating Waste and Saving Taxpayer Dollars — signals that the federal government is turning up the heat on program integrity across healthcare. This isn't theoretical; it means new compliance requirements, tighter auditing standards, and enhanced fraud prevention expectations are coming your way.

For you as a compliance officer, this translates into two immediate concerns: (1) your current fraud detection and prevention protocols may not meet the new baseline standards being developed, and (2) reporting obligations and documentation requirements will likely expand.

The risk isn't penalties tomorrow — it's being unprepared when CMS and OIG clarify what "program integrity" means under this EO. Organizations that wait for final rulemaking to act will scramble.

Action today: Schedule a 30-minute meeting with your CFO and internal audit team to review your current fraud prevention program against the Office of Inspector General (OIG) Compliance Program Guidance. Identify three gaps you can close now before formal guidance drops.

Sunday, July 19, 2026

NPI Compliance: Don't Overlook This Medicare Requirement

Your National Provider Identifier (NPI) — that 10-digit number every provider needs — isn't just a filing requirement. It's the backbone of all HIPAA-covered transactions, from claims to eligibility checks to referrals. If your NPI data is inaccurate, outdated, or not properly maintained in CMS systems, you're creating downstream problems: claim denials, payment delays, and audit exposure.

Here's the real risk: Many organizations treat NPI assignment as a one-time event. It's not. Under 45 CFR Part 162, you're required to maintain accurate NPI information throughout your relationship with Medicare, Medicaid, and private payers. Changes in practice location, ownership, facility type, or taxonomy codes all trigger update obligations — and non-compliance can jeopardize your provider agreement.

For compliance officers, this means your organization's NPI records are a blind spot worth fixing today. Audit your NPI data in CMS PECOS (Provider Enrollment, Chain, and Ownership System) right now. Verify that what's registered matches your current operations. If discrepancies exist, file corrections immediately — don't wait for an audit notice to surface them.

Thursday, July 16, 2026

HIPAA Breaches Are Rising — Your Controls Need Audit

Healthcare data breaches hit record levels last year, and regulators are scrutinizing how organizations detect, respond to, and report them. HIPAA (Health Insurance Portability and Accountability Act) violations carry fines up to $1.5 million per violation category annually — and that's before state attorneys general pile on.

For compliance officers, this means your security posture and breach response protocols are under the microscope. If HHS (U.S. Department of Health and Human Services) initiates an audit, weak encryption, delayed breach discovery, or botched notifications will be flagged immediately.

Here's what matters: You need documented, tested procedures for identifying unauthorized access to protected health information (PHI), notifying affected individuals within 60 days, and reporting breaches to HHS. Vague or missing controls invite enforcement.

Action today: Schedule a working session with your IT and privacy teams to audit your current breach detection capabilities. Identify gaps in logging, access monitoring, or notification workflows — then prioritize fixes. Don't wait for regulators to find the problems first.

Tuesday, July 14, 2026

Medicare Payment Rule Changes: Your Billing Ops Need Updates

CMS just announced proposed changes to Medicare payment models for outpatient services—ambulatory surgical centers and hospitals are in scope. This isn't just theoretical: payment methodology shifts require real operational changes to your billing workflows, coding practices, and revenue cycle processes.

If your organization bills Medicare for outpatient services, you'll need to understand exactly how reimbursement calculations change under the new model. Miss the details, and you risk billing errors, denials, and compliance exposure down the road.

Here's the thing: the full proposed rule is still being finalized, but the comment period is coming. Don't wait until it's final to start preparing.

Action for today: Pull your revenue cycle and billing leadership into a brief sync. Ask them to flag which current billing processes would be affected by payment methodology changes. Start a basic tracker now so you're ready to implement quickly once the final rule drops—and you'll have documentation showing good-faith preparation if regulators ever ask.

Sunday, July 12, 2026

CMS Survey Procedures: What Inspectors Actually Look For

If your organization participates in Medicare or Medicaid, you need to understand how CMS actually enforces compliance. 42 CFR Part 488 establishes the survey, certification, and enforcement procedures that govern how regulatory inspections happen, deficiencies get cited, and penalties get imposed.

Here's the practical reality: CMS surveyors use this framework to assess whether you meet federal Conditions of Participation (CoPs). If they find gaps, the citations they issue trace directly back to Part 488's deficiency categories. The severity level they assign determines whether you get a corrective action plan, payment sanctions, or termination.

The compliance risk is straightforward — most organizations respond to deficiencies reactively rather than proactively understanding what inspectors are trained to look for. You're essentially playing defense without knowing the playbook.

Action item: Pull your most recent CMS survey report (or request one if you haven't been surveyed recently) and map cited deficiencies directly to Part 488's enforcement categories. This tells you exactly what CMS cares about in your space—and what to audit before they do.

Thursday, July 9, 2026

Watch the 2027 OPPS Payment Rule — It's Coming

CMS just released a proposed rule (CMS-1850-P) that will reshape how Medicare reimburses outpatient hospital and ambulatory surgical center (ASC) services starting in 2027. The stated goals are solid—better quality, lower drug costs, reduced patient out-of-pocket expenses—but the devil is always in the details.

For your organization: payment methodologies and quality reporting requirements will change, which means your current billing workflows, modifier usage, and performance metrics may need adjustment. This affects nearly every hospital and ASC in the country.

Here's the practical reality: compliance teams that wait until 2027 to understand these changes will scramble. Teams that start now can influence internal conversations, test workflows early, and avoid surprises at implementation.

Action for today: Assign someone to download the proposed rule from CMS Newsroom and schedule a 30-minute team sync to identify which of your service lines will be most affected. Flag it internally now, and you'll have breathing room to adapt.

Tuesday, July 7, 2026

NPI Maintenance: Don't Let Provider IDs Lapse

Your providers' National Provider Identifiers (NPIs) are foundational — without them, claims don't process, directories go stale, and you're exposed to billing compliance violations.

Here's what's happening: NPIs require periodic renewal and must stay current across all systems. We're seeing providers overlook renewal deadlines, which cascades into claim rejections, billing disputes, and audit findings. One lapsed NPI can trigger downstream problems: denied claims, invalid billing records, and even questions about whether you knew who was actually treating patients.

The compliance risk is real. A single provider with an inactive NPI doesn't just mean one claim gets denied — it creates a paper trail suggesting your enrollment and credentialing controls weren't monitoring active status.

Your action today: Pull your current NPI roster and cross-check renewal dates against the National Provider Enumeration (NPE) database. Flag any renewals due in the next 90 days. Have your credentialing team own the renewal calendar — don't let this slip between billing and compliance. A 15-minute audit saves a compliance headache.

Want the Compliance Minute in your inbox, plus the full regulatory intelligence platform?

Request a Demo

Informational only, not legal advice. Government source content is in the public domain.