Top Regulatory Compliance Risks in Healthcare

A survey deficiency, a billing edit, or an employee complaint can appear manageable in isolation. The real exposure begins when those events reveal a pattern: weak controls, unexamined incentives, incomplete documentation, or leadership that treated compliance as a department rather than an operating discipline. The top regulatory compliance risks in healthcare are increasingly tied to those patterns, particularly for providers operating under reimbursement pressure, labor scarcity, and greater federal and state scrutiny.

For senior living, post-acute, home health, hospice, and skilled nursing leaders, the immediate question is not simply whether a rule has changed. It is whether the organization can demonstrate that its policies, workflows, records, and financial arrangements consistently match the rule it says it follows. That distinction will shape audit outcomes, survey results, payment integrity disputes, transaction risk, and enterprise value.

For example, in hospice, the top 5 compliance risks I routinely see are;

1) medical necessity – not meeting the likely terminal in 6 months qualification

(2) facility/hospice relationships, including the overlap or appropriateness of services – see this a lot between hospice and SNF and hospice and ALF

(3) medical director/physician relationship

(4) worthless services/not medically required services to care for the terminal condition of the patient or to provide palliation of symptoms

(5) documentation inadequate to support the care being provided or to support the service

Why Top Regulatory Compliance Risks Are Becoming More Expensive

Government enforcement has become more data-driven and less dependent on a single dramatic allegation. Claims patterns, staffing submissions, quality reporting, referral relationships, ownership data, and complaint histories can all be compared at scale. An outlier may not prove misconduct, but it can direct regulators, managed care plans, whistleblower counsel, or state agencies toward a provider that lacks a convincing explanation.

The stakes also extend beyond recoupment. A repayment demand can trigger a corporate integrity issue, lender concern, insurer notification, acquisition repricing, or reputational damage in a referral market. For an operator already confronting thin margins, the cost of remediation often exceeds the original financial exposure because remediation requires management time, outside counsel, consultant support, training, technology changes, and sustained monitoring.

This is particularly true in post-acute care, where payment rules and care delivery are deeply intertwined. Documentation supports reimbursement, but it also tells the story of medical necessity, staffing adequacy, clinical decision-making, and resident safety. When the record is inconsistent, the organization has a financial problem and a credibility problem.

A good primary list of risk areas comes from the law firm of Alston & Bird: Post-acute providers: Key risk areas and how to minimize them

1. Billing, Coding, and Medical Necessity

Billing integrity remains the most persistent risk because it touches nearly every Medicare and Medicaid provider. The familiar issues are still present: unsupported diagnoses, incorrect codes, missed claim edits, duplicate billing, inappropriate modifiers, and services that are not adequately documented. But the more consequential cases often arise from systemwide practices rather than one coding error.

In home health and hospice, eligibility and medical necessity documentation remain obvious pressure points. In skilled nursing, reimbursement classification, therapy utilization, diagnosis capture, and resident acuity documentation require ongoing scrutiny. Hospitals and physician organizations face their own coding risks, especially where inpatient status, evaluation and management services, and risk adjustment affect payment.

Leaders should resist the temptation to frame every billing issue as a revenue-cycle problem. Compliance, clinical leadership, finance, and operations need a shared view of where payment incentives may be influencing behavior. A high-performing internal audit function does more than locate errors. It tests whether the underlying workflow encourages staff to make defensible decisions under real operating conditions.

2. Referral Relationships and Financial Arrangements

The Anti-Kickback Statute, Stark Law, and related state restrictions continue to create risk wherever referrals, compensation, and ownership intersect. The danger is not limited to an obvious payment for patient volume. It can arise in medical directorships, consulting arrangements, lease terms, marketing agreements, joint ventures, management service agreements, preferred-provider relationships, and compensation plans that are poorly documented or disconnected from actual services.

Senior living and post-acute operators should pay particular attention to arrangements involving hospitals, physician groups, therapy companies, pharmacies, laboratories, and ancillary service vendors. A commercial relationship can be operationally sensible and still fail to satisfy the technical requirements that protect it. Fair market value support, written agreements, defined duties, actual performance, and periodic review matter because regulators will examine substance, not just paperwork.

Private equity-backed platforms face an additional layer of attention. Regulators and legislators are increasingly interested in whether ownership structures, management fees, and growth expectations create incentives that undermine care quality or distort clinical judgment. Investment itself is not the compliance problem. The problem is governance that makes financial engineering more visible than clinical accountability.

3. Quality Reporting, Staffing, and Survey Readiness

Quality is no longer a separate reputational category. It is increasingly a regulatory, reimbursement, and enforcement issue. Providers that submit inaccurate quality data, fail to meet reporting requirements, or cannot substantiate public metrics can face payment consequences and heightened scrutiny. A gap between reported performance and the resident or patient experience is especially dangerous.

Skilled nursing providers know that staffing data, payroll-based journal submissions, survey findings, and quality measures now travel together in the public and regulatory conversation. A facility may technically complete its submissions yet remain exposed if its staffing plan does not align with the acuity of the population it serves. The same principle applies in home health, hospice, and assisted living: paper compliance cannot compensate for a care model that routinely outruns available staff.

Assisted living operators must also avoid importing a Medicare-centric compliance mindset into a state-regulated environment. State licensing rules, medication management standards, resident assessment requirements, memory care obligations, incident reporting, and disclosure rules may be the dominant risks. Multi-state operators need centralized oversight, but they cannot assume that one corporate policy satisfies materially different state requirements.

4. Privacy, Cybersecurity, and the Expanding Vendor Problem

Healthcare data remains a high-value target, and a cyber incident can quickly become a compliance event. HIPAA exposure is only one part of the equation. Organizations also face contractual obligations, state privacy and breach-notification requirements, operational disruption, and potential liability when a vendor mishandles protected information.

The vendor issue is where many providers remain underprepared. Billing companies, cloud platforms, electronic health record consultants, remote monitoring firms, staffing agencies, pharmacies, and marketing vendors may all touch sensitive data or critical systems. A signed business associate agreement is necessary in many situations, but it does not prove that access is limited, systems are monitored, backups are usable, or breach response roles are understood.

Boards should ask a practical question: if the primary systems went down tomorrow, who has authority to make clinical, financial, legal, and communications decisions in the first four hours? If that question produces a vague answer, the organization has a material governance gap.

5. Workforce Practices, Whistleblowers, and Retaliation Claims

Labor shortages have forced many organizations to rely on agency staff, overtime, contractors, and rapid hiring. Those choices may be necessary, but they create compliance exposure when credentialing, supervision, wage practices, training, and reporting expectations weaken under pressure.

Whistleblower risk deserves special attention. Employees often see documentation shortcuts, staffing gaps, billing concerns, infection-control failures, and resident-care problems before executives do. A culture that discourages reporting does not eliminate allegations. It redirects them to regulators, plaintiff attorneys, social media, or competitors.

The most effective compliance programs make it safe to raise concerns and difficult to ignore them. That requires more than a hotline. It requires prompt investigation, consistent discipline, feedback to the reporter where appropriate, and a clear prohibition on retaliation. Leaders should review whether reported concerns are concentrated in a facility, department, supervisor group, or service line. Patterns in complaints can be as revealing as patterns in claims data.

Building a Compliance Program That Holds Up Under Scrutiny

A policy binder will not protect an organization whose daily practices contradict it. The better approach is to identify the few risks that could create the greatest financial, clinical, or reputational damage and then test them in the field. Are staff following the policy? Does the record support the service? Are managers escalating concerns? Can the organization show what it did after discovering a problem?

This work should be prioritized, not indiscriminate. A regional assisted living operator may need to focus first on state survey readiness, medication management, staffing practices, and resident agreements. A Medicare-heavy post-acute platform may need deeper review of documentation, coding, quality reporting, referral arrangements, and payment integrity. The right risk assessment depends on the business model, payer mix, geography, ownership structure, and recent enforcement history.

The organizations best positioned for the next cycle of oversight will not be those that predict every rule change. They will be the ones that can explain their decisions, prove their controls, and correct failures before an outside party makes those failures the story. Check out my recent post regarding what a post-acute care compliance checklist involves here: Post Acute Care Compliance Checklist for 2026 – Reg’s Blog

Leave a Reply

Your email address will not be published. Required fields are marked *

Picture of Reg

Reg

Healthcare executive, consultant, and author covering post-acute care, senior living, and the economics behind both - for 30+ years.

Join Our Mailing List

No noise - just what changed in healthcare policy and economics, and why it matters to your operation.