New criteria for prosecutors to use when determining whether an organization is identifying, assessing, and managing risks associated with emerging technology, specifically including AI
Advises that where relevant, prosecutors should consider technology used for conducting business and whether a risk assessment has been conducted regarding use of the technology and whether appropriate steps have been taken to mitigate its risk
Identifying and managing internal and external risks, and assessing potential impact of new technologies
Ensuring appropriate controls are in place to ensure the technology is used only for its intended purpose
Integrating management of risks into broader enterprise risk management strategies
Training employees on the use of emerging technologies
Continuous Improvement – If new technology is being used in commercial operations or the compliance program, is the organization monitoring and/or testing the technology to ensure it is functioning as intended and consistent with the Code of Conduct, and how quickly can it detect and correct decisions made by AI or other technology that are inconsistent with the organization’s values
Policies and Procedures – What efforts have been made to monitor and implement policies and procedures reflecting and dealing with changes to the legal and regulatory landscape and the use of new technologies
Data Resources and Access / Proportionate Resource Allocation
Leveraging data analytics tools to create efficiencies in compliance operations and measure compliance program effectiveness
How assets, resources and technology available to compliance/risk management compare to elsewhere in the organization
Whether there is an imbalance between technology/resources used by the organization to identify and capture market opportunities and what is used to detect and mitigate risk
Commitment to Whistleblower Protection and Anti-Retaliation
Having an anti-retaliation policy
Training employees on internal anti-retaliation policies and external anti-retaliation and whistleblower protection laws
Training employees on internal reporting systems and external whistleblower programs and regulatory regimes
Ensuring employees who report internally are not treated differently than others involved in misconduct who did not
Lessons Learned
In addition to tracking and incorporating lessons learned from the organization’s own prior issues, is the organization also looking to prior issues of other organizations operating in the same industry and/or geographical region and applying those lessons learned as part of employee training and in the compliance program
Integration in the M&A Process
DOJ consideration of whether the compliance function is integrated into the M&A process, and to what extent compliance and risk management functions play a role in designing and executing the integration plan
Revised Price Transparency Rule took effect July 1, 2024
Hospitals must conform to a standard CMS template layout with data specifications and data dictionary
Affirmation statement in the machine- readable file that the information displayed is true, accurate and complete as of the date indicated in the file
Beginning January 1, 2025, additional requirements go into effect :
Estimated allowed amount (average dollar amount the hospital has historically received from a 3rd party payer for an item or service) will be a required data element
Any modifiers(s) that may change the standard charge that corresponds to a hospital item or service, including a description of the modifier and how it changes the standard charge, must be encoded
For drugs, the drug unit and type of measurement must be included as separate data elements from the general description
GAO Report – Health Care Transparency: CMS Needs More Information on Hospital Pricing Data Completeness and Accuracy – October 2, 20243
Between 2021and 2023, CMS initiated 1,287 enforcement actions and issued over $4 million in civil monetary penalties to 14 hospitals that did not take timely corrective action
CMS does not have assurance the pricing data hospitals report are sufficiently complete and accurate
CMS has not assessed the risk to determine if additional enforcement actions are needed
GAO issues recommendation for CMS to assess whether hospital pricing data are sufficiently complete and accurate to be usable and to implement additional enforcement activities as needed
State- launched price transparency websites
Colorado recently launched price transparency website that will show all available prices at every hospital in the state and total price the hospital charges each payer
CMS Complaint Data and Enforcement Report on Health Insurance Market Reforms (August 2024)
Report found that through June 30, 2024:
CMS received 12,077 complaints of NSA violations
10,300 of the complaints were against providers/ facilities/air ambulance
1,777 of the complaints were against plans/ issuers
Complaints have resulted in $4,183,383 in monetary relief paid to consumers or providers
Complaints have resulted in $4,183,383 in monetary relief paid to consumers or providers.
Three most common complaints against providers/ facilities/air ambulance
Surprise billing for non-emergency services at an in-network facility
Surprise billing for emergency services
Good faith estimate
Three most common complaints against plans/ issuers
Non-compliance with Qualifying Payment Amount (QPA)
Late payment after Independent Dispute Resolution (IDR) determination
Non-compliance with 30-day initial payment or notice of denial of payment requirements
CMS conducted its first audit of an insurer for compliance with the NSA
Found that Aetna Health of Texas miscalculated the Qualifying Payment Amount (QPA)5 by both overestimating and underestimating the QPA for certain air ambulance services
Determined that the wrong methodology was being used to calculate the metrics
Audit also found that Aetna wasn’t sending providers disclosures required under the NSA, including the window for kicking off third-party arbitration and the insurer’s QPA for a claim
Audit was smaller in scope, looking only at Aetna?s dealings with air ambulances in one state for the first half of 2022 and finding only several errors
October 4, 2024 – Amicus brief filed in response to Texas district court decision6 that if a provider prevails in the IDR process, there is no private course of act ion to enforce the IDR award under the NSA
Amicus brief filed by American Hospital Association, American Medical Association, Federation of American Hospitals, and Texas Medical Association as part of Guardian Flight vs. Health Care Service Corp.
September 13, 2024 – Legislation introduced in the House to improve NSA enforcement.7 “No Surprises Act Enforcement Act” would:
Close enforcement gaps through increased penalties for non-compliance of statutory payment deadlines
Provide parity between penalties imposed against parties non-compliant with statutory patient protection provisions
Federal Register: Public Health Service Policies on Research Misconduct
September 12, 2024 – Office of Research Integrity released 2024 Public Health Services (PHS) Policies on Research Misconduct
First amendments since it was first codified in 2005
January 1, 2025 – Effective date
January 1, 2026 – All regulatory requirements are applicable
Provides significant modification related to research misconduct proceedings
42 CFRPart 93 addresses alleged misconduct in PHS-funded research, including NIH and CMS, and applies to all institutions that receive PHS funding for research activities
ORI will be publishing guidance to assist in preparing for Final Rule implementation
Research Misconduct
Fabrication, falsification or plagiarism in proposing, performing, or reviewing research, or in reporting research results (does not include honest error or differences in opinion)
Intentionally – To act with the aim of carrying out the act
Knowingly – To act with awareness of the act
Recklessly – To propose, perform, or review research, or report research results, with indifference to a known risk of fabrication, falsification, or plagiarism
Institutional Record
Records the institution compiled or generated during the research misconduct proceeding, except records that weren’t relied on or considered by the institution
Inquiry and Investigation Timeframes
Inquiry – Lengthened the time to complete the inquiry stage from proposed timeframe of 60 days to Final Rule’s 90 days
Investigation – Timeframe to complete an investigation extended from 120 days to 180 days
Final Rule addresses potential to extend the inquiry and investigation timeframes if an extension is needed
Appeals Process
Revised from de novo review by ALJ to ALJ review of administrative record started at the institution and supplemented by ORI
Subsequent Use Exception to 6-year Statute of Limitations
Clarifies that the exception only applies when respondent uses, republishes, or cites to the portions of the research record alleged to have been fabricated, falsified, or plagiarized
Confidentiality Obligations
Disclosure of the identity of respondents, complainants, and witnesses while conducting the research misconduct proceedings is limited, to the extent possible, to those who need to know as determined by the institution
The limitation on disclosure no longer applies once the institution makes a final determination of research misconduct findings
“The guidances were first released in 2017 and have been updated several times since, reflecting the continuous evolution of compliance requirements.”