Compliance & HIPAA in Your Private Practice

A practical walk through the law that governs a private practice — the False Claims Act, Anti-Kickback Statute, Stark, and HIPAA.

Who it's for: Physicians and owners running or building an independent practice

A practical, CME-style walk through the two bodies of law that govern a private practice: federal fraud-and-abuse compliance (the False Claims Act, Anti-Kickback Statute, Stark, billing integrity, building a compliance program, and your duties to report and self-disclose) and HIPAA (the Privacy, Security, and Breach rules, business associates, and enforcement). Educational, not legal advice.

11 lessons · $299 · lifetime access · certificate of completion

Syllabus

  1. Lesson 1: The Compliance Landscape: Why Compliance Is Existential — and Who's Watching (23 min)

    • Explain why compliance is an existential issue for an independent practice specifically.
    • Name the four federal enforcers — DOJ, HHS-OIG, CMS, OCR — and describe how they relate.
    • Cite, roughly and with the year, what getting it wrong has cost — and name the 7 elements of a compliance program.

    Takeaway: Compliance is existential for an independent practice — not because the rules are a trap, but because the same enforcement that's survivable for a hospital can end a small group. Four bodies watch: CMS sets the billing rules, HHS-OIG audits and can exclude you, OCR enforces HIPAA, and the DOJ prosecutes — with the False Claims Act recovering a record amount from healthcare in FY2025. But the government has also published the cure: a seven-element compliance program you build once and run. Get that right, and this becomes the thing that lets you sleep at night.

  2. Lesson 2: The Big Four Fraud & Abuse Laws: False Claims Act, Anti-Kickback, Stark, and the Civil Monetary Penalties Law (23 min)

    • Name the Big Four and say what each one actually prohibits.
    • Distinguish their intent standards — strict liability vs. knowing vs. specific intent — and civil vs. criminal.
    • Recognize which laws have safe harbors or exceptions, and roughly what the penalties look like.

    Takeaway: Here's what I want to stick. Four federal laws, and the key is how they treat intent. Stark is strict liability and civil — no intent required, so it catches the well-meaning; it runs on exceptions. The Anti-Kickback Statute is criminal but requires intent, and it has safe harbors that protect honest arrangements. The False Claims Act is the hammer — treble damages, per-claim penalties, and whistleblowers who drive most of the recoveries. And the Civil Monetary Penalties Law is the OIG's flexible civil tool, with exclusion behind it. The rungs stack, so one bad deal can trigger all four. And remember the disclaimer at the top: this is education, not legal advice — build your arrangements with your own compliance counsel, before the first referral, and you'll sleep at night.

  3. Lesson 3: Stark & Anti-Kickback in Practice: ASCs, Ancillary Services, and Referrals — Structured to Survive a Look (23 min)

    • Explain the self-referral loop Stark targets, and why owning the entity you refer to needs an exception.
    • Use the two Stark exceptions that matter most to a group: group practice and in-office ancillary services.
    • Name the AKS safe harbors a surgical practice relies on — and the three tests every arrangement should pass.

    Takeaway: Here's the heart of it. Stark is strict liability — owning the entity you refer to needs an exception that fits exactly, and good intentions are no defense. The Anti-Kickback Statute needs intent, but it's criminal, and it hands you safe harbors to build into. Under all of it run three plain questions: fair market value, commercially reasonable, and never tied to referrals. Pass those, put it in writing, keep it current — and you've built something your counsel can defend. This was education, not legal advice; the structures are yours to bring to a lawyer who can paper them right.

  4. Lesson 4: Billing & Coding Compliance: Clean Claims, the 60-Day Rule, and the Audit Ecosystem (23 min)

    • Tie every clean claim back to medical necessity and the documentation that supports it.
    • Recognize the classic coding traps — upcoding, unbundling, and modifier abuse (25 and 59).
    • Name the audit contractors (RAC/MAC/UPIC/OIG/CERT) and use the 60-day rule and a self-audit to stay ahead.

    Takeaway: Here's the whole lesson in a breath. A clean claim is medical necessity plus documentation that proves it — and most improper payments are documentation failures, not fraud. Know the traps: upcoding, unbundling, and reflexive use of modifiers 25 and 59. Know your visitors: the RAC hunts for a cut, the MAC pays you, the UPIC investigates fraud, the OIG can exclude you, and CERT just measures. When you find an overpayment, the sixty-day clock starts — return it, because a kept overpayment becomes a False Claims Act problem. And read the OIG Work Plan, then self-audit at the top of the funnel, so that you are always the first to find your own mistakes. That is how you keep your claims clean and sleep at night.

  5. Lesson 5: Building a Compliance Program: Operationalizing the 7 OIG Elements — Exclusion Screening and Self-Disclosure (23 min)

    • Turn the OIG's seven elements into a concrete, scaled-down checklist for your own practice.
    • Set up exclusion screening — the LEIE and SAM.gov — at hire and monthly, and know why both lists matter.
    • Know what the OIG Self-Disclosure Protocol is, and when self-disclosing beats staying quiet.

    Takeaway: A compliance program isn't a document; it's a cycle you run — assess, write, train, monitor, respond, repeat. The OIG's seven elements scale all the way down to a solo office: name an officer, write the policies, train, open a reporting line, audit a real sample, discipline evenly, and correct promptly. Screen every hire, contractor, and vendor against the LEIE — maintained by HHS-OIG — and SAM-dot-gov, at hire and every month, and keep the proof. And when your program finds something serious, remember the Self-Disclosure Protocol exists, and that coming forward, with counsel, is often the wiser path. Regulators don't expect perfection. They expect a system that catches and fixes its own mistakes. That's what you just learned to build.

  6. Lesson 6: Reporting & Self-Disclosure: Internal Channels and the Duty to Report: What You Must Do When You Find Inappropriate Billing, a Bad Referral, or an Impaired Colleague (24 min)

    • Run an internal report end to end — the hotline and anonymous channels, non-retaliation, investigation, and correction.
    • Pick the right government path: the 60-day overpayment return, the OIG SDP, or the CMS SRDP.
    • Understand the False Claims Act whistleblower process — and the separate, often mandatory, duty to report a colleague.

    Takeaway: Here's the whole of Part One, in one idea: compliance isn't really tested by whether you have problems — every practice does — it's tested by what you do the moment you find one. Build internal channels people will actually use, including an anonymous one, and protect every reporter with a non-retaliation policy you genuinely enforce. When you find something, run the workflow: investigate, document, correct. Then choose the right door — return a plain overpayment to your MAC within sixty days, take a Stark issue to the CMS SRDP, take fraud or a kickback to the OIG SDP, and call counsel before anything that smells like a False Claims Act case, because the whistleblower engine and its protections are real and powerful. And never forget the duty that isn't about money at all: in many states you are obligated to report an unsafe colleague to the board, and serious actions follow them through the NPDB. Know your state. Coming forward, the right way, with counsel, almost always beats waiting. That's how you sleep at night.

  7. Lesson 7: HIPAA Foundations: The Rules, the PHI, and Who Is Bound (23 min)

    • Name the three HIPAA rules — Privacy, Security, Breach Notification — and what HITECH added.
    • Define protected health information and list the 18 identifiers that make data PHI.
    • Tell a Covered Entity from a Business Associate, and apply the minimum-necessary principle.

    Takeaway: Here's the foundation. HIPAA is one law with three rules — Privacy decides who may use information, Security decides how to protect it, Breach Notification decides what to do when it leaks — and HITECH extended all of it to your vendors. What's protected is PHI: health information tied to a person by any of eighteen identifiers. Who's bound is you, the covered entity, and every business associate who touches your patients' data — which is why no BAA means no PHI. And the principle under all of it is minimum necessary: share the least that does the job, except when a clinician needs the most to treat. Hold that shape. Now we go deep.

  8. Lesson 8: The HIPAA Privacy Rule: TPO, Patient Rights, the Notice, and When You Need a Signed Authorization (23 min)

    • Explain what flows freely under Treatment, Payment, and Operations — and what doesn't.
    • Name the patient's core rights and the right-of-access deadline you must meet.
    • Tell when a signed authorization is required, and apply minimum-necessary at the front desk.

    Takeaway: The Privacy Rule comes down to one habit and one humility. The habit: ask, every time, is this for the patient's care or billing? If it's treatment, payment, or operations, it flows — no signature. If it's anything else, stop and get a valid authorization, and even when you may disclose, send only the minimum necessary. Honor the patient's rights on time — thirty days for access, one extension, in writing. The humility: this rule changes. The reproductive-health rule was law in 2024 and largely gone by 2025. Know the framework, then confirm the current text with your own counsel.

  9. Lesson 9: The HIPAA Security Rule: Protecting Electronic PHI — Safeguards, the Risk Analysis, and Practical Controls (23 min)

    • Name the three categories of Security Rule safeguards — Administrative, Physical, and Technical.
    • Explain the Required vs Addressable distinction — and why 'addressable' never means 'optional.'
    • Describe the security risk analysis and the core technical controls every practice should have.

    Takeaway: Here's the Security Rule in one breath. It protects electronic PHI through three categories of safeguards — Administrative, Physical, and Technical. Each specification is Required or Addressable, and addressable never means optional — it means implement it, substitute something equivalent, or document why not. At the center sits the security risk analysis: a Required, recurring process, and the single most-cited failure in OCR enforcement, so do it, document it, and revisit it. Layer on encryption, unique IDs, MFA, audit logs, device controls, and tested backups, and you've addressed the controls that prevent most breaches. Do this well, and you really can sleep at night — but watch the rule, because it's tightening.

  10. Lesson 10: Business Associates & Vendors: BAAs, the Subcontractor Chain, Cloud & EHR Vendors, and AI Tools (23 min)

    • Decide when a vendor is a Business Associate -- and when it isn't.
    • Name the required terms a HIPAA-compliant BAA must contain, and why flow-down matters.
    • Apply the 'no BAA, no PHI' rule to cloud, EHR, billing -- and especially to AI tools and chatbots.

    Takeaway: Here's what to carry out of this lesson. Almost every piece of patient data in your practice is handled by an outside vendor, and HIPAA holds you responsible for all of it. Any vendor that creates, receives, maintains, or transmits PHI for you is a Business Associate and needs a signed BAA -- with the required terms, and with those protections flowing down to every subcontractor. Your cloud vendor counts even when the data is encrypted and never viewed. And the newest vendors -- the AI tools -- follow the same old rule: no BAA, no PHI. Build the vendor inventory, get the agreements signed, and remember this is educational, not legal advice -- your compliance counsel reviews the contracts you actually sign.

  11. Lesson 11: Breaches, Enforcement & Penalties: What Happens When Something Goes Wrong — and How to Be Ready (23 min)

    • Define a HIPAA breach and run the four-factor risk assessment that decides whether you must notify.
    • State the notification duties and deadlines — individuals, HHS, and media — and the 500-patient threshold.
    • Name the four civil-penalty tiers and sketch an incident-response plan you can actually use.

    Takeaway: A breach is presumed until your documented four-factor assessment shows a low probability of compromise. If you must notify, the affected individuals get word within sixty days; five hundred or more triggers HHS and the media, and HHS posts it publicly. The four penalty tiers scale with culpability, and OCR's most-cited failures — a missing risk analysis and slow records access — are among the cheapest things to get right. None of this is fatal to a practice that prepared. Write the plan before you need it.

Related guides