Search

2025 Healthcare Compliance Quick Reference Guide

Stay ahead with a comprehensive look at all 2025 healthcare compliance changes and prepare for a smooth rollout.

DOJ Evaluation of Corporate Compliance Programs1

New and Emerging Technology

  • New criteria for prosecutors to use when determining whether an organization is identifying, assessing, and managing risks associated with emerging technology, specifically including AI
  • Advises that where relevant, prosecutors should consider technology used for conducting business and whether a risk assessment has been conducted regarding use of the technology and whether appropriate steps have been taken to mitigate its risk
    • Identifying and managing internal and external risks, and assessing potential impact of new technologies
    • Ensuring appropriate controls are in place to ensure the technology is used only for its intended purpose
    • Integrating management of risks into broader enterprise risk management strategies
    • Training employees on the use of emerging technologies
  • Continuous Improvement – If new technology is being used in commercial operations or the compliance program, is the organization monitoring and/or testing the technology to ensure it is functioning as intended and consistent with the Code of Conduct, and how quickly can it detect and correct decisions made by AI or other technology that are inconsistent with the organization’s values
  • Policies and Procedures – What efforts have been made to monitor and implement policies and procedures reflecting and dealing with changes to the legal and regulatory landscape and the use of new technologies

Data Resources and Access / Proportionate Resource Allocation

  • Leveraging data analytics tools to create efficiencies in compliance operations and measure compliance program effectiveness
  • How assets, resources and technology available to compliance/risk management compare to elsewhere in the organization
  • Whether there is an imbalance between technology/resources used by the organization to identify and capture market opportunities and what is used to detect and mitigate risk

Commitment to Whistleblower Protection and Anti-Retaliation

  • Having an anti-retaliation policy
  • Training employees on internal anti-retaliation policies and external anti-retaliation and whistleblower protection laws
  • Training employees on internal reporting systems and external whistleblower programs and regulatory regimes
  • Ensuring employees who report internally are not treated differently than others involved in misconduct who did not

Lessons Learned

  • In addition to tracking and incorporating lessons learned from the organization’s own prior issues, is the organization also looking to prior issues of other organizations operating in the same industry and/or geographical region and applying those lessons learned as part of employee training and in the compliance program

Integration in the M&A Process

  • DOJ consideration of whether the compliance function is integrated into the M&A process, and to what extent compliance and risk management functions play a role in designing and executing the integration plan

Price Transparency Rule2

Revised Price Transparency Rule took effect July 1, 2024

  • Hospitals must conform to a standard CMS template layout with data specifications and data dictionary
  • Affirmation statement in the machine- readable file that the information displayed is true, accurate and complete as of the date indicated in the file

Beginning January 1, 2025, additional requirements go into effect :

  • Estimated allowed amount (average dollar amount the hospital has historically received from a 3rd party payer for an item or service) will be a required data element
  • Any modifiers(s) that may change the standard charge that corresponds to a hospital item or service, including a description of the modifier and how it changes the standard charge, must be encoded
  • For drugs, the drug unit and type of measurement must be included as separate data elements from the general description

GAO Report – Health Care Transparency: CMS Needs More Information on Hospital Pricing Data Completeness and Accuracy – October 2, 20243

  • Between 2021and 2023, CMS initiated 1,287 enforcement actions and issued over $4 million in civil monetary penalties to 14 hospitals that did not take timely corrective action
  • CMS does not have assurance the pricing data hospitals report are sufficiently complete and accurate
  • CMS has not assessed the risk to determine if additional enforcement actions are needed
  • GAO issues recommendation for CMS to assess whether hospital pricing data are sufficiently complete and accurate to be usable and to implement additional enforcement activities as needed

State- launched price transparency websites

  • Colorado recently launched price transparency website that will show all available prices at every hospital in the state and total price the hospital charges each payer

No Surprises Act (NSA) Update4

CMS Complaint Data and Enforcement Report on Health Insurance Market Reforms (August 2024)

  • Report found that through June 30, 2024:
    • CMS received 12,077 complaints of NSA violations
    • 10,300 of the complaints were against providers/ facilities/air ambulance
    • 1,777 of the complaints were against plans/ issuers
    • Complaints have resulted in $4,183,383 in monetary relief paid to consumers or providers
2025 Compliance Updates Article 03

Complaints have resulted in $4,183,383 in monetary relief paid to consumers or providers.

  • Three most common complaints against providers/ facilities/air ambulance
    • Surprise billing for non-emergency services at an in-network facility
    • Surprise billing for emergency services
    • Good faith estimate
  • Three most common complaints against plans/ issuers
    • Non-compliance with Qualifying Payment Amount (QPA)
    • Late payment after Independent Dispute Resolution (IDR) determination
    • Non-compliance with 30-day initial payment or notice of denial of payment requirements

CMS conducted its first audit of an insurer for compliance with the NSA

  • Found that Aetna Health of Texas miscalculated the Qualifying Payment Amount (QPA)5 by both overestimating and underestimating the QPA for certain air ambulance services
  • Determined that the wrong methodology was being used to calculate the metrics
  • Audit also found that Aetna wasn’t sending providers disclosures required under the NSA, including the window for kicking off third-party arbitration and the insurer’s QPA for a claim
  • Audit was smaller in scope, looking only at Aetna?s dealings with air ambulances in one state for the first half of 2022 and finding only several errors

October 4, 2024 – Amicus brief filed in response to Texas district court decision6 that if a provider prevails in the IDR process, there is no private course of act ion to enforce the IDR award under the NSA

  • Amicus brief filed by American Hospital Association, American Medical Association, Federation of American Hospitals, and Texas Medical Association as part of Guardian Flight vs. Health Care Service Corp.

September 13, 2024 – Legislation introduced in the House to improve NSA enforcement.7 “No Surprises Act Enforcement Act” would:

  • Close enforcement gaps through increased penalties for non-compliance of statutory payment deadlines
  • Provide parity between penalties imposed against parties non-compliant with statutory patient protection provisions
  • Increase transparency in reporting requirements

Research Misconduct Final Rule8

Federal Register: Public Health Service Policies on Research Misconduct

  • September 12, 2024 – Office of Research Integrity released 2024 Public Health Services (PHS) Policies on Research Misconduct
    • First amendments since it was first codified in 2005
  • January 1, 2025 – Effective date
  • January 1, 2026 – All regulatory requirements are applicable
  • Provides significant modification related to research misconduct proceedings
  • 42 CFRPart 93 addresses alleged misconduct in PHS-funded research, including NIH and CMS, and applies to all institutions that receive PHS funding for research activities
  • ORI will be publishing guidance to assist in preparing for Final Rule implementation

Research Misconduct

  • Fabrication, falsification or plagiarism in proposing, performing, or reviewing research, or in reporting research results (does not include honest error or differences in opinion)
    • Intentionally – To act with the aim of carrying out the act
    • Knowingly – To act with awareness of the act
    • Recklessly – To propose, perform, or review research, or report research results, with indifference to a known risk of fabrication, falsification, or plagiarism

Institutional Record

  • Records the institution compiled or generated during the research misconduct proceeding, except records that weren’t relied on or considered by the institution

Inquiry and Investigation Timeframes

  • Inquiry – Lengthened the time to complete the inquiry stage from proposed timeframe of 60 days to Final Rule’s 90 days
  • Investigation – Timeframe to complete an investigation extended from 120 days to 180 days
  • Final Rule addresses potential to extend the inquiry and investigation timeframes if an extension is needed

Appeals Process

  • Revised from de novo review by ALJ to ALJ review of administrative record started at the institution and supplemented by ORI

Subsequent Use Exception to 6-year Statute of Limitations

  • Clarifies that the exception only applies when respondent uses, republishes, or cites to the portions of the research record alleged to have been fabricated, falsified, or plagiarized

Confidentiality Obligations

  • Disclosure of the identity of respondents, complainants, and witnesses while conducting the research misconduct proceedings is limited, to the extent possible, to those who need to know as determined by the institution
  • The limitation on disclosure no longer applies once the institution makes a final determination of research misconduct findings

“The guidances were first released in 2017 and have been updated several times since, reflecting the continuous evolution of compliance requirements.”

Lynne Rinehimer, Esq., Senior Solutions Consultant, symplr

Grants Management9

October. 3, 2024 – New Strategic Plan from OIG: “Safeguarding the Integrity of HHS Grants and Contracts”

  • OIG has identified several risks related to how HHS grants and contracts are administered
  • OIG’s identifies three strategic goals
    • Goal 1 – Strengthen compliance with requirements throughout the grants and contracts life cycle
      • Ensure awarding agencies and awardees are complying with requirements for grants and contracts
      • Improving grant monitoring of subrecipient activities and reporting through enhanced oversight
    • Goal 2 – Promote award practices that achieve program outcomes
      • Support quality, safety, and equity in HHS programs
      • Prevent, detect, and correct performance issues
    • Goal 3 – Enhance public trust in HHS awards by mitigating fraud, waste, abuse, and mismanagement
      • Ensure accountability through program oversight, enforcement actions, and remedies
      • Protect HHS awards through training and outreach

HIPAA Privacy Rule to Support Reproductive Health Care Privacy10

HHS Privacy Rule to Support Reproductive Health Care Privacy

  • Compliance date – December 23, 2024 (except for Notice of Privacy Practices requirements)
  • Prohibits the use or disclosure of PHI by a covered entity, or their business associate, to:
    • Conduct a criminal, civil or administrative investigation into any person seeking, obtaining, providing or facilitating reproductive health care (RHI)
    • Impose criminal, civil or administrative liability on any person seeking, obtaining, providing or facilitating RHC
    • Identify any person for the purpose of conducting such investigation or imposing such liability
  • Prohibition applies when the covered entity or business associate reasonably determines that one or more of the following conditions exists:
    • The RHC is lawful in the state in which it is being provided under the circumstances it is being provided
    • The RHC is protected, required, or authorized by Federal law, including the Constitution, regardless of the state in which it is provided
    • The lawful presumption applies
  • New requirements related to attestations, disclosure to law enforcement, and Notice of Privacy Practices

Cybersecurity

  • Proposed HIPAA Security Rule Modifications
    • DHHS has filed proposed modifications to the Security Rule with the Office of Information and Regulatory Affairs
    • Focus is on strengthening the cybersecurity of electronic PHI
    • It is anticipated that HHS will release the Notice of Proposed Rulemaking before the end of the year, with a 60-day period for public feedback
2025 Compliance Updates Article 02

There has been a 264% increase in large ransomware breaches since 2018.

  • September/October 2024 – OCR marked the 4th-7th civil monetary penalty ransomware enforcement actions, and 1st enforcement action in OCR’s Risk Analysis Initiative
    • 264% increase in large ransomware breaches since 2018
  • OIG – Video on website “Strengthening Cybersecurity in Health Care”11
    • OIG has formed a multidisciplinary Cybersecurity Team

Download and print out this quick reference guide.

Whats New in Healthcare Compliance for 2025 Quick Reference Cover

Resources