A practical walk through the law that governs a private practice — the False Claims Act, Anti-Kickback Statute, Stark, and HIPAA.
Who it's for: Physicians and owners running or building an independent practice
A practical, CME-style walk through the two bodies of law that govern a private practice: federal fraud-and-abuse compliance (the False Claims Act, Anti-Kickback Statute, Stark, billing integrity, building a compliance program, and your duties to report and self-disclose) and HIPAA (the Privacy, Security, and Breach rules, business associates, and enforcement). Educational, not legal advice.
11 lessons · $299 · lifetime access · certificate of completion
Takeaway: Compliance is existential for an independent practice — not because the rules are a trap, but because the same enforcement that's survivable for a hospital can end a small group. Four bodies watch: CMS sets the billing rules, HHS-OIG audits and can exclude you, OCR enforces HIPAA, and the DOJ prosecutes — with the False Claims Act recovering a record amount from healthcare in FY2025. But the government has also published the cure: a seven-element compliance program you build once and run. Get that right, and this becomes the thing that lets you sleep at night.
Takeaway: Here's what I want to stick. Four federal laws, and the key is how they treat intent. Stark is strict liability and civil — no intent required, so it catches the well-meaning; it runs on exceptions. The Anti-Kickback Statute is criminal but requires intent, and it has safe harbors that protect honest arrangements. The False Claims Act is the hammer — treble damages, per-claim penalties, and whistleblowers who drive most of the recoveries. And the Civil Monetary Penalties Law is the OIG's flexible civil tool, with exclusion behind it. The rungs stack, so one bad deal can trigger all four. And remember the disclaimer at the top: this is education, not legal advice — build your arrangements with your own compliance counsel, before the first referral, and you'll sleep at night.
Takeaway: Here's the heart of it. Stark is strict liability — owning the entity you refer to needs an exception that fits exactly, and good intentions are no defense. The Anti-Kickback Statute needs intent, but it's criminal, and it hands you safe harbors to build into. Under all of it run three plain questions: fair market value, commercially reasonable, and never tied to referrals. Pass those, put it in writing, keep it current — and you've built something your counsel can defend. This was education, not legal advice; the structures are yours to bring to a lawyer who can paper them right.
Takeaway: Here's the whole lesson in a breath. A clean claim is medical necessity plus documentation that proves it — and most improper payments are documentation failures, not fraud. Know the traps: upcoding, unbundling, and reflexive use of modifiers 25 and 59. Know your visitors: the RAC hunts for a cut, the MAC pays you, the UPIC investigates fraud, the OIG can exclude you, and CERT just measures. When you find an overpayment, the sixty-day clock starts — return it, because a kept overpayment becomes a False Claims Act problem. And read the OIG Work Plan, then self-audit at the top of the funnel, so that you are always the first to find your own mistakes. That is how you keep your claims clean and sleep at night.
Takeaway: A compliance program isn't a document; it's a cycle you run — assess, write, train, monitor, respond, repeat. The OIG's seven elements scale all the way down to a solo office: name an officer, write the policies, train, open a reporting line, audit a real sample, discipline evenly, and correct promptly. Screen every hire, contractor, and vendor against the LEIE — maintained by HHS-OIG — and SAM-dot-gov, at hire and every month, and keep the proof. And when your program finds something serious, remember the Self-Disclosure Protocol exists, and that coming forward, with counsel, is often the wiser path. Regulators don't expect perfection. They expect a system that catches and fixes its own mistakes. That's what you just learned to build.
Takeaway: Here's the whole of Part One, in one idea: compliance isn't really tested by whether you have problems — every practice does — it's tested by what you do the moment you find one. Build internal channels people will actually use, including an anonymous one, and protect every reporter with a non-retaliation policy you genuinely enforce. When you find something, run the workflow: investigate, document, correct. Then choose the right door — return a plain overpayment to your MAC within sixty days, take a Stark issue to the CMS SRDP, take fraud or a kickback to the OIG SDP, and call counsel before anything that smells like a False Claims Act case, because the whistleblower engine and its protections are real and powerful. And never forget the duty that isn't about money at all: in many states you are obligated to report an unsafe colleague to the board, and serious actions follow them through the NPDB. Know your state. Coming forward, the right way, with counsel, almost always beats waiting. That's how you sleep at night.
Takeaway: Here's the foundation. HIPAA is one law with three rules — Privacy decides who may use information, Security decides how to protect it, Breach Notification decides what to do when it leaks — and HITECH extended all of it to your vendors. What's protected is PHI: health information tied to a person by any of eighteen identifiers. Who's bound is you, the covered entity, and every business associate who touches your patients' data — which is why no BAA means no PHI. And the principle under all of it is minimum necessary: share the least that does the job, except when a clinician needs the most to treat. Hold that shape. Now we go deep.
Takeaway: The Privacy Rule comes down to one habit and one humility. The habit: ask, every time, is this for the patient's care or billing? If it's treatment, payment, or operations, it flows — no signature. If it's anything else, stop and get a valid authorization, and even when you may disclose, send only the minimum necessary. Honor the patient's rights on time — thirty days for access, one extension, in writing. The humility: this rule changes. The reproductive-health rule was law in 2024 and largely gone by 2025. Know the framework, then confirm the current text with your own counsel.
Takeaway: Here's the Security Rule in one breath. It protects electronic PHI through three categories of safeguards — Administrative, Physical, and Technical. Each specification is Required or Addressable, and addressable never means optional — it means implement it, substitute something equivalent, or document why not. At the center sits the security risk analysis: a Required, recurring process, and the single most-cited failure in OCR enforcement, so do it, document it, and revisit it. Layer on encryption, unique IDs, MFA, audit logs, device controls, and tested backups, and you've addressed the controls that prevent most breaches. Do this well, and you really can sleep at night — but watch the rule, because it's tightening.
Takeaway: Here's what to carry out of this lesson. Almost every piece of patient data in your practice is handled by an outside vendor, and HIPAA holds you responsible for all of it. Any vendor that creates, receives, maintains, or transmits PHI for you is a Business Associate and needs a signed BAA -- with the required terms, and with those protections flowing down to every subcontractor. Your cloud vendor counts even when the data is encrypted and never viewed. And the newest vendors -- the AI tools -- follow the same old rule: no BAA, no PHI. Build the vendor inventory, get the agreements signed, and remember this is educational, not legal advice -- your compliance counsel reviews the contracts you actually sign.
Takeaway: A breach is presumed until your documented four-factor assessment shows a low probability of compromise. If you must notify, the affected individuals get word within sixty days; five hundred or more triggers HHS and the media, and HHS posts it publicly. The four penalty tiers scale with culpability, and OCR's most-cited failures — a missing risk analysis and slow records access — are among the cheapest things to get right. None of this is fatal to a practice that prepared. Write the plan before you need it.