Buttaci Leardi & Werner LLC | Contents of this website may contain attorney advertising | Results may vary depending on your particular facts and legal circumstances | Recognition Methodology

Protect Yourself Against Payer Audit Liability: Begin with a Compliance Program

Authors: John Leardi; Vincent Buttaci; Paul Werner

Ghost-billing. Billing for “unnecessary” items/services. Double-billing. Misuse of provider numbers. Billing for non-covered services. Billing for unbundled services. Failing to properly use coding modifiers. Cluster-billing. Up-coding the level of service provided. Documentation that does not support billing. These are the top ten issues that can cause a payer refund demand.

Whether you run a small practice or manage a large healthcare organization, it is your responsibility to ensure that you are compliant with all regulatory standards, because the individual and corporate consequences of being audited for failure to comply can include steep monetary fines, reputational damage, or even the loss of the organization’s license.

Staying ahead of an audit is a process that requires advance planning, ongoing training, spot checks on coding and billing, and a full understanding of the laws that impact your organization. The success of the process is strengthened when the organization has a true culture of compliance, with repeated messaging that the responsibility for compliance is everyone’s, from leaders to all staff.

1. What is driving the increase in payer audits of healthcare organizations?

We are all aware of changes in the delivery of healthcare. Insurance covers less and less; benefits have become more complex. There is more regulation (e.g., Stark, AKS), recovery audit contractors (RACs), and increased patient financial responsibility. Some would also point to the “dark side” of healthcare reform. The result of all of these factors is an increased utilization of post and pre-payment audits, generally defined as an investigation by a health benefit plan, carrier, or agent regarding whether a claim was properly previously paid.

At their core, payer audits are based on money.

Statistics from government agencies show the exorbitant cost of fraud and abuse, which directly supports the increased frequency of payer audits. With this information as a backdrop, healthcare organizations must pay attention to compliance.

The old days of investigating fraud and abuse with a random audit are gone. Today’s audits are focused on “program integrity,” the use of technology, data aggregation, and statistical outliers to identify improper payments, regardless of whether fraud or abuse enters the equations. There is nothing random about audits any longer.

2. Who is selected for a payer audit, and how are audits conducted? What might elevate your risk of being audited?

Audits are typically triggered by certain “red flags” such as provider profiling, complaints from disgruntled patients or former employees, aggressive advertising, submitting claims for care of family members and/or employees, or suspicious billing practices.

A Special Investigations Unit (SIU) Agent will commonly use these tools when conducting an audit.

  • A request for production of records;
  • Submission of questionnaires/surveys to patients;
  • Conducting interviews with patients;
  • Conducting interviews of current and former employees;
  • Telephone conferences and/or meetings with the provider; and
  • In rare circumstances, sending an agent into a practice undercover.

Your risk for non-compliance is exponential if you do not have a Compliance Program with clear and concise manuals articulating policies and procedures for claim preparation, corroborating documentation, internal quality assurance reviews, education for every team member on management’s expectations of staff roles and responsibilities, and an outline describing what the individual and corporate consequences could be for failing to meet those standards. Your healthcare organization needs to have, and support, a culture of compliance.

3. Which strategies support a healthcare organization’s culture of compliance?

The culture of compliance rests on more than a single manual or a plan; it must be strategically grounded by a comprehensive Compliance Program that is structured to fit the needs of your practice. Leadership can use the Compliance Program not only to streamline operations and adhere to laws and regulations, but also to foster a culture of accountability throughout the practice. By improving the knowledge of the staff of the organization, you reduce the risk of penalties, fines, and potential loss of licenses. Compliance Programs cannot be one-size-fits-all. An experienced and knowledgeable healthcare attorney familiar with carrier reimbursement, regulatory and licensing requirements, and fraud and abuse issues will develop a plan that is specifically tailored to meet the needs of your practice.

4. What should an effective Compliance Program include?

An effective Compliance Program must start with the federal and state laws and regulations that apply to your healthcare organization, as well as any industry-specific guidelines. The execution of the Program is multi-faceted, including plans, policies and procedures; training, testing and refinements as needed. We recommend beginning with a Baseline Compliance Audit.

5. What is a baseline compliance audit?

A baseline compliance audit is your starting point in evaluating your healthcare organization’s compliance status. It should be a fully objective review, not done by a clinician or by an internal staff member.

Rather, this baseline compliance audit is most effective when completed by a knowledgeable healthcare attorney. It is a review of your practice’s formational documents, employment contracts, consulting agreements, space and equipment leases, third-party billing contracts, and all other contracts.

In addition, we recommend engaging a certified professional coder to perform an audit of your practice’s claims submissions and documentation to identify problematic areas that must be addressed/improved to comply with the plan.

6. What happens after the baseline compliance audit?

The analysis of the baseline compliance audit will provide important alignments or adjustments with current laws and regulations, information for the Compliance Program at large, and individual policies, trainings, and procedures.

At a minimum, a Compliance Program should cover:

  • Billing and coding standards
  • Data privacy regulations (e.g., HIPAA)
  • Employee training and education on compliance
  • Risk management policies
  • Clear reporting procedures for potential violations

Take note: it is the leadership’s obligation to be vigilant and continually monitor practice compliance. This ongoing attention must become a routine business operation, to more quickly and easily identify compliance issues before they escalate into a larger problem that might result in liability. That compliance will depend upon periodic internal audits and regular training of billing staff.

While it is critical to appreciate which laws and regulations are applicable, it’s just as important that the facilitation of the Compliance Program be in plain language rather than legalese. By developing a format and tone that is easy to follow and understand, via manuals and training sessions, your staff will be better equipped to follow the procedures and policies. This is where the Compliance Manual comes into play.

7. What is the purpose of a compliance manual?

A compliance manual is one of the most powerful risk management tools your healthcare organization can use. It serves as a detailed guide to all the laws, regulations, and internal policies that your organization must adhere to. An effective compliance manual should clearly indicate a dedicated compliance officer to oversee staff training and to be available for questions.

The goals of the manual are to:

  • Develop effective internal procedures to ensure compliance with all applicable laws, regulations, and rules;
  • Improve patient record documentation to properly reflect the care needed/given;
  • Improve the knowledge-level of all of the practice’s employees;
  • Reduce the amount and frequency of claim denials;
  • Streamline practice operations by fostering improved communication;
  • Reduce the practice’s exposure to fines, penalties, and overpayment demands; and
  • Avoid personal liability for non-compliance.  

8. How can a healthcare organization stay ahead of “new” compliance issues?

Prevention is always better than cure, and therefore we recommend:

  • An ongoing education program. Continual training will ensure that your staff is always up to date on the latest regulations.
  • Refreshers on the need and procedures for ongoing communication, so that potential issues are identified and addressed before they become serious problems.
  • Periodic internal audits to assess the impact of pending or new regulations or laws.

Regular staff training sessions on regulations and internal procedures plus internal audits will help to keep your healthcare organization on track. By fostering a culture of accountability, you minimize the chances of overlooking compliance risks that could result in penalties or audit findings.

Conclusion

The potential for an audit must be a daily consideration within your healthcare organization. Building a comprehensive Compliance Program, educating your staff, and conducting periodic internal audits are essential steps in keeping your practice in compliance. Please reach out to our team of healthcare attorneys to discuss your organization’s need for a Compliance Program.

Tagged with: , ,

  • Posted on: Jan 31 2025