Skip to main content

Healthcare compliance resource hub

Healthcare Compliance and Regulations Resources

This healthcare compliance and regulations hub helps healthcare leaders understand how privacy, security, billing, coding, program integrity, payer rules, patient financial protections and digital health requirements connect. It organizes practical education without replacing official guidance or qualified legal and compliance review.

  • Official-source links and date-stamped 2026 rule-status notes
  • Clear separation of statutes, regulations, guidance, payer policy and recommendations
  • Static directory of 83 privacy, billing, program-integrity and specialty topics
  • Educational content only—not legal advice or a compliance guarantee
Compliance control mapIllustrative
PrivacyAccess & disclosure

Policies, minimum necessary, patient rights, vendors and incidents.

Revenue cycleClaims & documentation

Coverage, coding, medical necessity, refunds and audit trails.

Program integrityMonitoring & response

Risk assessment, training, reporting, corrective action and disclosure.

Regulatory changeStatus & dates

Final, proposed, vacated, effective and compliance-date tracking.

Direct answer

What is healthcare compliance?

Healthcare compliance is the process of identifying the legal, regulatory, contractual and ethical requirements that apply to an organization, then translating them into accountable policies, training, safeguards, monitoring, reporting and corrective action. It covers far more than HIPAA and changes with provider type, payer, state, services, technology and current rule status.

A useful program connects each authority to a workflow: privacy to access and disclosure, billing to documentation and claims, and enrollment to data maintenance and revalidation. Guidance can inform design, but it is not automatically equivalent to a statute, regulation, contract or binding payer rule.

Legal and regulatory layer

Federal and state statutes, regulations, court decisions and formal rulemaking define obligations and limits. Applicability often depends on the organization, transaction, program and jurisdiction.

Program and payer layer

Medicare, Medicaid, managed-care plans, commercial payers and contracts add coverage, enrollment, documentation, claim, appeal and audit requirements.

Operational layer

Policies, system permissions, work queues, training, auditing, incident response, corrective action and evidence retention determine whether requirements work in practice.

Patient-to-payment controls

Why compliance matters across the revenue cycle

Compliance risk can begin before claim creation. Registration errors, missing authorization evidence, incomplete documentation, unsupported codes, inaccurate provider data, weak payment controls and delayed refunds can create downstream exposure. Vendor access and remote work add privacy and security risk.

Revenue-cycle stages, compliance risks and practical controls
Workflow stageTypical compliance riskControlling sourcePractical prevention
Registration and intakeWrong-patient records, incomplete consent, inaccurate demographics or insurance dataHIPAA, state law, payer requirements and practice policyIdentity checks, approved scripts, required-field validation and exception escalation
Eligibility and authorizationOutdated benefit information, missing authorization, incorrect documentation or missed deadlinesPayer manuals, contracts, CMS or Medicaid rulesSource capture, date stamps, status queues, denial reasons and qualified review
Documentation and codingUnsupported services, medical-necessity gaps, incorrect codes or modifiersOfficial code sets, coverage policy, CMS and payer guidanceProvider completion, current references, qualified coding review and audit trails
Claim submissionIncorrect provider, duplicate claim, excluded party, inaccurate certification or attachmentProgram rules, contracts, exclusions and transaction standardsEnrollment validation, edits, exclusion screening, acknowledgments and exception worklists
Payments, denials and refundsMisapplied funds, ignored denials, improper write-offs, underpayments or retained overpaymentsContracts, overpayment rules, accounting controls and payer policyReconciliation, segregation of duties, aging review, refund governance and documented escalation
Vendor and workforce accessExcess privileges, unmanaged devices, weak termination, subcontractor or BAA gapsHIPAA, security policy, contracts and state requirementsLeast privilege, MFA, managed access, audit logs, due diligence and prompt deprovisioning
Important: A clean claim is not automatically a compliant claim. Financial accuracy, medical necessity, coding support, enrollment, privacy and program-integrity requirements must all be considered.

Program framework

What are the seven elements of a healthcare compliance program?

OIG’s General Compliance Program Guidance offers a flexible, voluntary framework. The seven elements work as a cycle of leadership, practical guidance, monitoring and corrective action. Other laws, contracts or state requirements may impose more specific duties.

Standards, policies and procedures

Define expected conduct, ownership, documentation, escalation and evidence for material risk areas.

Leadership and oversight

Assign authority, independence, resources and reporting access to responsible compliance leadership.

Training and education

Use role-based, timely education tied to actual workflows, systems, mistakes and policy changes.

Effective communication

Provide accessible questions, reporting channels, non-retaliation expectations and issue routing.

Monitoring and auditing

Use risk-based reviews, data analysis, sampling and trend monitoring to test program operation.

Enforcement and discipline

Apply standards consistently and proportionately to employees, leaders, contractors and vendors.

Response and prevention

Investigate, stop harm, refund or disclose when required, correct root causes and verify sustainability.

Topic architecture

Search the healthcare compliance resource directory

All canonical topics are present in the HTML source. Filters only change visibility. Planned links should remain disabled until publication and review.

Showing 83 topicsPlanned URLs must be verified before linking.
Privacy & Security

HIPAA Compliance

Map current privacy and security controls.

HIPAAPrivacy
Privacy & Security

HIPAA Privacy Rule

Map current privacy and security controls.

Privacy RulePHI
Privacy & Security

HIPAA Security Rule

Map current privacy and security controls.

Security RuleePHI
Privacy & Security

HITECH Compliance

Map current privacy and security controls.

HITECHSecurity
Privacy & Security

42 CFR Part 2

Map current privacy and security controls.

Part 2SUD records
Billing & Coding

Modifier Compliance

Connect documentation, coding and audit controls.

ModifiersPayer policy
Billing & Coding

Payer Audit Response

Connect documentation, coding and audit controls.

Payer auditAppeals
Fraud & Abuse

False Claims Act

Identify authority, risk and response duties.

FCAClaims
Fraud & Abuse

Stark Law

Identify authority, risk and response duties.

StarkSelf-referral
CMS & Medicaid

MIPS Compliance

Verify current program, payer and audit rules.

MIPSQuality
CMS & Medicaid

RAC Audit Guide

Verify current program, payer and audit rules.

RACAudit
CMS & Medicaid

TPE Audit Guide

Verify current program, payer and audit rules.

TPEMedicare
CMS & Medicaid

ABN Compliance

Verify current program, payer and audit rules.

ABNPatient liability
Patient Financial Protection

No Surprises Act

Align patient billing and dispute safeguards.

NSABalance billing
Patient Financial Protection

Federal IDR Process

Align patient billing and dispute safeguards.

IDRDisputes
Digital Health

RPM Compliance

Track rule status and implementation duties.

RPMDevices
Specialty & Facility

DME Compliance

Map provider-specific compliance and oversight risks.

DMESupplier
Specialty & Facility

Home Health Compliance

Map provider-specific compliance and oversight risks.

Home healthDocumentation
Specialty & Facility

Hospice Compliance

Map provider-specific compliance and oversight risks.

HospiceEligibility
Specialty & Facility

Hospital Compliance

Map provider-specific compliance and oversight risks.

HospitalsCoPs
Specialty & Facility

EMTALA Compliance

Map provider-specific compliance and oversight risks.

EMTALAEmergency

Privacy and security

How does HIPAA affect revenue cycle operations?

Revenue-cycle teams routinely access protected health information during registration, eligibility, prior authorization, coding, claims, appeals, payment posting, collections, records requests and reporting. HIPAA therefore affects who can access systems, what information is used, how it is transmitted, which vendors receive it, how incidents are reported and how patients exercise access rights. Role-based access, minimum-necessary procedures and business-associate governance should be tied to actual tasks.

Privacy Rule

Define permitted uses and disclosures, minimum-necessary practices, patient rights, notices and identity verification. Sensitive records may also be subject to state law or 42 CFR Part 2.

Security Rule

Perform and maintain a risk analysis, manage access, protect devices and networks, prepare for downtime, monitor activity and document security decisions. The modernization rule remains proposed as of this page’s review date.

Breach and incident response

Staff should know how to report suspected incidents quickly. Qualified reviewers must assess facts, mitigation, risk and applicable notification duties rather than assuming every incident is or is not a reportable breach.

The 2024 Part 2 final rule has a February 16, 2026 compliance date. HHS also updated model notices in February 2026. Organizations that create or maintain Part 2 records should use current HHS materials and review whether combined HIPAA and Part 2 notices are appropriate. This topic requires specialized review because consent, redisclosure and use in proceedings can differ from ordinary HIPAA workflows.

Billing, coding and documentation

What regulations affect medical billing and coding?

Medical billing and coding operate under overlapping authorities: federal and state law, Medicare and Medicaid program rules, official code sets, coverage determinations, payer manuals, provider contracts, documentation standards and program-integrity laws. A code may be technically valid yet unsupported by the record, inconsistent with coverage, billed under the wrong provider or submitted through an ineligible arrangement. Compliance requires more than edit software.

Documentation before code selection

Authentication, date, service detail, medical necessity and required orders should be complete before coding. Templates can improve consistency, but copied or default text may create risk when it does not reflect the encounter.

Qualified coding review

Policies should define who may assign, validate or change codes; how questions return to the provider; which current resources are used; and how exceptions are documented. This page does not reproduce proprietary code descriptions.

Claim integrity and enrollment

Claims should use accurate patient, provider, location, payer, service and authorization information. Enrollment and reassignment data must be maintained because otherwise accurate services may still be billed improperly.

Overpayments and corrective action

When an error is identified, the organization should assess scope, quantify affected claims, stop the cause, determine refund or disclosure obligations, and verify that corrective action works. High-risk conclusions require qualified counsel or compliance review.

Example: A recurring modifier denial may be a simple payer edit, a documentation gap, a coding education issue, an enrollment problem or a broader pattern. Root-cause analysis should occur before changing claims at scale.

Program integrity

How do major fraud and abuse laws differ?

The False Claims Act, Anti-Kickback Statute and Stark Law are legally distinct. Their elements, intent standards, exceptions and remedies differ, and one arrangement may implicate several authorities. Only qualified counsel can reach a legal conclusion for specific facts.

False Claims Act

Focuses on knowingly presenting or causing false claims and can include reverse-false-claim issues involving improperly retained obligations. Billing accuracy, certifications, refunds and response documentation matter.

Anti-Kickback Statute

Addresses remuneration intended to induce or reward referrals or federal program business. Safe harbors are detailed and fact-specific; a business purpose alone does not resolve the analysis.

Stark Law

Applies to physician self-referrals for designated health services when a financial relationship exists, unless an exception is satisfied. It is generally structured differently from intent-based fraud analysis.

Exclusion screening

OIG maintains the List of Excluded Individuals/Entities. Organizations should define onboarding and ongoing checks, match verification, evidence retention and response to confirmed exclusions.

Beneficiary inducements

Gifts, waivers, transportation or incentives may raise issues depending on value, purpose and available exceptions. Patient-access goals should be reviewed before implementation.

Self-disclosure

OIG, CMS and state Medicaid agencies may have different disclosure pathways. Organizations should identify the issue, stop ongoing risk, preserve evidence and obtain qualified advice before choosing a pathway.

This section is educational and not legal advice. Use official agency materials and qualified counsel for arrangement, disclosure, enforcement or penalty questions.

CMS and payer programs

How should practices manage Medicare, Medicaid and payer compliance?

Medicare, Medicaid and Medicare Advantage require separate analysis. Traditional Medicare uses national and local coverage and contractor guidance; Medicaid varies by state; Medicare Advantage adds plan, network, risk-adjustment and prior-authorization requirements. Commercial contracts add obligations but do not replace federal or state rules.

Enrollment and identity

Maintain ownership, locations, licenses, reassignment, banking and contact information. Track revalidation and effective dates. A provider’s clinical qualification does not automatically establish enrollment for every payer or location.

Coverage and documentation

Use current manuals, coverage policies and payer guidance for the date of service. Archive evidence used for decisions because pages and policies may change after submission.

Audit readiness

RAC, TPE, CERT, UPIC, SMRC and payer audits have different purposes and procedures. Centralize requests, deadlines, records, communications, findings, appeals and corrective actions.

OIG issued Medicare Advantage Industry Segment-Specific Compliance Program Guidance on February 3, 2026. It is voluntary guidance designed to help organizations identify risks and structure compliance and quality activities. Organizations should use it alongside the General Compliance Program Guidance and applicable binding authorities.

Patient financial protection

How do patient billing protections affect revenue-cycle workflows?

Patient financial compliance spans estimates, notices, consent, balance billing, assistance, disputes, collections and coordination of benefits. Federal and state protections vary by coverage and service setting, so practices should confirm the applicable rule before using a standard script.

Before service

Use accurate registration, coverage checks, financial policies, good faith estimate processes when applicable and clear escalation when the expected service changes.

After adjudication

Reconcile payer responsibility, patient responsibility, contractual terms and protections before statements or collection activity begin.

Disputes and assistance

Route estimate disputes, insurance disputes, financial assistance screening, complaints and Federal IDR matters to defined owners with current instructions.

Interoperability and digital health

How should practices track final versus proposed digital-health rules?

Technology rules often have separate publication, effective and compliance dates. Identify the agency, rule number, affected entity, final or proposed status, dependencies, testing needs and action date before treating a requirement as operational.

Prior authorization and APIs

CMS-0057-F includes operational requirements beginning in 2026 and API requirements primarily beginning in 2027. Decision-timeframe, denial-reason and metrics provisions should not be confused with API build deadlines.

Claims attachments

The 2026 final rule adopts national standards for electronic claims attachments and electronic signatures. Covered entities have a future compliance date, so inventories, vendor roadmaps, testing and trading-partner planning should begin before the deadline.

AI and automation

Use-case approval should address data access, human review, validation, bias, documentation, monitoring, incident handling and vendor terms. AI output should not replace required clinical, coding or legal judgment.

Last reviewed July 28, 2026

2026 healthcare regulatory watchlist

These cards summarize official-source status as of the review date. Recheck every item before publication or operational use.

Final; compliance active

42 CFR Part 2 Final Rule

Agency
HHS, SAMHSA and OCR
Published
February 8, 2024
Compliance
February 16, 2026
Provider action
Review consent, notices, breach, redisclosure, vendor and record workflows for Part 2 data.
Read the HHS Part 2 fact sheet
Final; phased dates

CMS Interoperability and Prior Authorization — CMS-0057-F

Agency
CMS
Operational
Generally January 1, 2026
APIs
Generally January 1, 2027
Provider action
Track payer denial reasons, decision timeframes, metrics, portal changes and API readiness.
Review CMS-0057-F
Final; implementation period

Electronic Claims Attachments and Signatures

Agency
CMS / HHS
Effective
May 26, 2026
Compliance
May 26, 2028
Provider action
Inventory attachment workflows, signatures, vendors, trading partners, data formats and testing dependencies.
Read the CMS announcement
Final; phased applicability

Federal IDR Operations Final Rule

Agency
HHS, Labor, Treasury and OPM
Released
May 28, 2026
Status
Final with several provisions tied to effective dates or future operational guidance
Provider action
Update open-negotiation, eligibility, batching, fee, evidence and registry procedures as provisions are operationalized.
Read the final-rule fact sheet
Proposed, not final

HIPAA Security Rule Modernization

Agency
HHS Office for Civil Rights
Proposed
December 27, 2024
Status
HHS regulatory page still identifies an NPRM as of this review
Provider action
Do not present proposed requirements as binding; compare current safeguards with the proposal and monitor for a final rule.
Check HHS regulatory initiatives
Updated guidance

OIG Medicare Advantage Compliance Guidance

Agency
HHS-OIG
Issued
February 3, 2026
Status
Voluntary industry segment-specific guidance
Provider action
Assess relevant MA risks, oversight, data, payment and quality processes alongside binding program rules.
Review the Medicare Advantage ICPG
State update

New York OMIG Compliance Program Review Module

Agency
New York OMIG
Updated
July 6, 2026
Status
Updated module for submissions from July 6, 2026 forward
Provider action
Use the current module only when OMIG instructs the provider to submit it; maintain supporting evidence throughout the review period.
Read the OMIG update
Ongoing state alerts

Florida Medicaid Provider Alerts

Agency
Florida AHCA
Updated
Continuously
Status
Provider-type and program-specific notices
Provider action
Subscribe, assign ownership and route alerts to enrollment, billing, clinical, technology and compliance teams as applicable.
Review Florida Medicaid alerts

State-specific operations

How are New York and Florida requirements addressed?

New York

New York Medicaid providers should use OMIG’s compliance library, current review module, certification information, work plan and self-disclosure materials. OMIG states that certain providers are subject to mandatory compliance program requirements under Social Services Law § 363-d and 18 NYCRR Part 521. The 2026 work plan describes 12-month compliance review periods for reviews initiated after July 1, 2025.

Open the OMIG Compliance Library

Florida

Florida Medicaid operations should use AHCA’s current provider handbooks, fee schedules, health care alerts, enrollment materials and program-integrity resources. Requirements can differ by provider type and managed-care arrangement. A generic Florida summary should not replace the controlling handbook, alert or contract for the date of service.

Open Florida Medicaid Health Care Alerts

State privacy, licensure, professional scope, call recording, record retention, telehealth and patient-finance questions should receive state-specific review. Do not apply one state’s rule nationwide.

Self-assessment

Healthcare compliance and audit-readiness checklist

This checklist is a planning aid, not legal advice or certification. Mark an item only when ownership, source, process and evidence are clear.

Service pathways

How Zenith Assistance can support revenue-cycle operations

Zenith Assistance’s current website lists medical billing, coding, hospital and office RCM, credentialing and CAQH revalidation, prior authorization, patient registration, practice management and virtual-assistant support. It lists a St. Petersburg, Florida address. This page does not present Zenith as a law firm or guarantee compliance.

Practice management

Review front-office, payer, claim and reporting workflows as a connected operating system.

Explore practice management

Free RCM audit

Use the official audit page to discuss revenue-cycle workflows. Do not submit protected health information through general web fields.

Book a Free RCM Audit
Verification note for the publisher: Before adding ISO certification, HIPAA compliance, performance, provider-count, software-count or case-study claims to this page, confirm the current certificate or internal evidence and approved wording.

Privacy-conscious next step

Request a revenue-cycle workflow review

A Free RCM Audit can help identify workflow questions involving registration, eligibility, authorization, documentation, claim edits, denials, A/R and reporting. It is not legal advice, a compliance certification or a guarantee of reimbursement. Use only general business information in the initial request—never include patient names, dates of birth, medical record numbers, claim numbers or clinical details.

Rank Math-ready visible FAQs

Frequently asked healthcare compliance questions

Requirements vary by provider type, payer, state, service and current rule status. Use these concise answers as orientation, then check the controlling authority and obtain qualified review for high-risk decisions.

Healthcare compliance translates applicable laws, rules, contracts and standards into policies, training, controls, monitoring and corrective action. Duties vary by provider, payer, state, data and current rule status.

Billing and coding may involve HIPAA, Medicare, Medicaid, coverage policies, documentation rules, official code sets, payer contracts, overpayment duties and fraud-and-abuse laws. Current official sources control.

OIG commonly describes written standards, leadership, training, communication, monitoring and auditing, consistent enforcement, and prompt response with corrective action. Guidance is generally voluntary unless another authority makes a control binding.

HIPAA affects registration, authorizations, coding, claims, payment posting, collections, records, vendors and remote access because those workflows may use protected health information.

Common risks include unsupported services, incomplete documentation, incorrect coding, excluded or unenrolled providers, improper patient billing, untimely refunds, excessive access and weak audit trails.

A statute comes from a legislature; a regulation from authorized rulemaking; guidance explains an agency approach; payer policy governs coverage or administration. Their legal force and appeal routes differ.

Centralize the request, identify authority and scope, preserve deadlines, assemble complete records, control communications, track submissions and plan corrective action. Do not alter records.

Use continuous, risk-based monitoring plus formal reviews after major rule, payer, service, ownership, technology or staffing changes. The right cadence depends on size, complexity and governing requirements.

Applicable Medicare or Medicaid overpayments generally must be reported and returned by the later of 60 days after identification or the corresponding cost-report due date. Qualified review is essential.

Review policies, qualifications, access controls, BAAs, exclusion screening, audit trails, incident response, subcontractors, reporting, data return and exit support. Verify marketing claims against evidence and contracts.

Zenith Assistance’s current website states that its medical billing, RCM and related services support providers across all 50 U.S. states. Confirm service scope and local requirements during consultation.

Use official state sources: OMIG and other controlling agencies for New York; AHCA, Florida Medicaid handbooks, fee schedules and alerts for Florida.

Sources and editorial transparency

Primary sources and review standards

Trace material claims to current official sources. Record publication, effective and compliance dates, status, scope and last verification. Document corrections when later authority changes an earlier summary.

Written by: Zenith Assistance

Compliance reviewed by: Syed Zohaib - CEO

Coding reviewed by: Syed Zohaib - CEO

RCM reviewed by: Syed Zohaib - CEO

Last official-source review: July 28, 2026

Editorial standards: Use the site’s editorial and corrections process for updates.

Legal disclaimer: This content is educational and not legal advice. It does not create an attorney-client relationship, certify compliance or replace current official rules, payer policies, contracts or qualified professional review.

Final action

Build clearer controls around your revenue cycle

Use this resource hub to organize healthcare compliance and regulations by authority, workflow, risk, status and accountable owner. When operational billing or RCM support is needed, discuss the practice’s workflows with Zenith Assistance without sending PHI through general website fields.

+1 (463) 293-1289connect@zenithassistance.com3110 1st Avenue North Suite 2M #1171, St. Petersburg, FL 33713
100% HIPAA-COMPLIANT RETROSPECTIVE CLAIMS REVIEW
— VERIFY YOUR TRUE NET COLLECTION RATE —

Book A Free RCM Audit Now!