CMS Compliance
Effectively Manage CMS Compliance to Avoid Recoupments and Other Penalties
All healthcare providers need to address CMS compliance. The Centers for Medicare and Medicaid Services (CMS) regulate numerous aspects of healthcare providers’ operations, and CMS actively enforces providers’ compliance obligations. Not only can non-compliance lead to steep financial penalties (including fines and recoupments), but it can potentially lead to loss of Medicare and Medicaid eligibility as well.
At Oberheiden P.C., we help healthcare providers throughout the United States adopt, manage, and maintain effective CMS compliance programs. We work closely with our clients to ensure that they thoroughly address all pertinent aspects of compliance, and we provide them with the custom-tailored documentation they need to manage compliance effectively. When it comes to CMS compliance, a proactive approach is key; and, if you have questions or concerns, it is important that you speak with a CMS compliance lawyer as soon as possible.
Our Experience with CMS Compliance
We have extensive experience representing healthcare providers with respect to CMS compliance. As a federal healthcare compliance and defense law firm, this is one of the core areas of our practice. We work with all types of providers nationwide, and we work alongside our clients to help them both avoid scrutiny from CMS and its fee-for-service auditors and efficiently defend against CMS audits, inspections, and investigations when necessary.
5 Core Areas of CMS Compliance for Healthcare Providers

Healthcare Team Lead
Former Federal Prosecutor
So, what is CMS compliance? Fundamentally, CMS compliance involves operating a healthcare practice or facility in accordance with the numerous laws, rules, and regulations that fall within CMS’s enforcement jurisdiction. To establish compliance—and to maintain compliance on an ongoing basis—healthcare providers must adopt custom-tailored policies and procedures, conduct appropriate training programs, and monitor and enforce compliance internally to ensure that their efforts are effective.
The Centers for Medicare and Medicaid Services enforce compliance in several areas. Here are five core areas of CMS compliance for healthcare providers in the U.S.:
1. Medicare and Medicaid Billing Compliance
The first core area of CMS compliance is Medicare and Medicaid billing compliance. All healthcare providers that bill these programs must have comprehensive policies and procedures in place to ensure that they are only billing for eligible services and items. All types of billing mistakes can be categorized as “fraud” under federal healthcare laws; and, even if a mistake is unintentional, allegations of Medicare or Medicaid billing fraud can have severe consequences—including Medicare and Medicaid exclusion in some cases.
We provide comprehensive billing compliance services that we custom-tailor to each client’s specific risks and needs. Depending on the size of your practice or business (among other factors), what it takes to manage Medicare and Medicaid billing compliance effectively can vary widely. Our lawyers can provide the documentation you need to manage compliance and help you put appropriate systems and protocols in place, and then we can assist with auditing, monitoring, and enforcing Medicare and Medicaid billing compliance on an ongoing basis.
2. HIPAA Compliance
CMS is one of several federal agencies that share responsibility for enforcing healthcare providers’ compliance with the Health Insurance Portability and Accountability Act (HIPAA). Specifically, CMS “is charged on behalf of HHS with enforcing compliance with adopted Administrative Simplification requirements.” The HIPAA Administrative Simplification requirements apply to billing, patient eligibility verifications, payments, and various other aspects of healthcare providers’ practices, and all providers must comply with the “standards and operating rules” adopted under these requirements.
To enforce HIPAA compliance, CMS conducts “proactive” audits of healthcare providers’ compliance efforts. This means that providers must not only manage HIPAA compliance effectively, but they must also be prepared to demonstrate compliance to CMS when necessary. When representing providers with respect to CMS compliance, we help our clients implement the policies, procedures, and systems required to generate documentation that demonstrates compliance as a matter of course, and we make ourselves available to communicate with CMS on behalf of our clients as necessary.
3. Emergency Preparedness (EP)
CMS also enforces healthcare providers’ obligations regarding emergency preparedness (EP). As CMS explains, “The Emergency Preparedness Requirements for Medicare and Medicaid Participating Providers and Suppliers regulation outlines four core elements which are applicable to all 17 provider types, with a degree of variation based on inpatient versus outpatient, long-term care versus non long-term care.” These four core elements are:
- Risk Assessment and Emergency Planning – Healthcare providers must adopt EP plans that address risks including (but not limited to) geographic risks, equipment and power failures, communication interruptions, cyber-attacks, and loss of facilities and supplies.
- Communication Plan – Healthcare providers must adopt communication plans that comply with all federal and state laws, and they must coordinate both internally and externally with authorities and other providers.
- Policies and Procedures – Healthcare providers must adopt additional emergency preparedness policies and procedures as necessary to comply with all applicable federal and state laws.
- Training and Testing – Healthcare providers must implement training and testing procedures that comply with federal and state law, and they must update these procedures at least annually.
These are important—and complicated—aspects of CMS compliance. At Oberheiden P.C., our lawyers and consultants have the knowledge and insights required to help providers manage emergency preparedness effectively.
4. Medical Services Compliance
Along with billing, HIPAA, and emergency preparedness, healthcare providers must also address various other aspects of compliance with respect to the medical services they offer to their patients. While CMS’s Medicare Learning Network (MLN) Education Tool provides a starting point for identifying and understanding these obligations, providers must work closely with experienced compliance counsel to ensure that they are doing everything necessary to avoid CMS scrutiny.
Some examples of the types of medical services that are subject to specific CMS oversight include:
- Allergy services
- Ambulance services
- Annual wellness visits
- Echography and sonography
- Lab tests
- Home health services
- Nebulizers and drugs
- Physical therapy
- Podiatry
- Spinal orthoses
- Surgical dressings
- Urinalysis
CMS’s MLN Education Tool explains that types of providers may have compliance obligations with respect to these (and other) services, and it provides examples of issues that can lead to scrutiny of providers’ related billing practices. Ultimately, however, it is up to providers to ensure that they are fully assessing their compliance obligations and doing everything that is necessary to comply with all pertinent laws, rules, and regulations.
5. CMS Compliance for Specific Provider Types
In addition to service-specific compliance obligations, CMS enforces various provider-specific compliance obligations as well. These obligations apply to providers including (but not limited to):
- Ambulatory Surgical Centers (ASC)
- Ambulance Services
- Anesthesiologists
- Clinical Labs
- Critical Access Hospitals
- Durable Medical Equipment (DME)
- Federally Qualified Health Centers (FQHC)
- Home Health Agencies (HHA)
- Hospices
- Hospitals
- Opioid Treatment Programs
- Practice Administration
- Pharmacists
- Physicians
- Rural Health Clinics
- Skilled Nursing Facilities (SNF)
For providers that fall into one of these 16 categories, addressing all pertinent compliance obligations is extremely important. CMS expects all providers to proactively identify and address their statutory and regulatory responsibilities, and those that fail to do so can face substantial consequences in the event of a CMS audit or investigation.
FAQs: What Healthcare Providers Need to Know About CMS Compliance
What is CMS Compliance?
CMS compliance is a broad area of healthcare compliance that encompasses all matters falling within the Centers for Medicare and Medicaid Services’ enforcement jurisdiction. This includes (but is not limited to) Medicare and Medicaid billing compliance, HIPAA compliance, emergency preparedness, service-specific compliance, and various additional compliance obligations that apply to certain types of providers.
How Important is CMS Compliance for Healthcare Providers?
For healthcare providers, effectively managing CMS compliance is extremely important. Not only does CMS establish compliance obligations for healthcare providers, but it also audits and enforces healthcare providers’ compliance efforts. If a CMS audit uncovers evidence of non-compliance (or even if a provider cannot affirmatively demonstrate compliance), this can lead to recoupments, fines, loss of Medicare and Medicaid eligibility, and other penalties.
How Does CMS Monitor and Enforce Compliance?
CMS’s primary method of monitoring and enforcing compliance is through its “proactive” audit process. CMS and its fee-for-service audit contractors routinely audit healthcare providers for all aspects of compliance. While providers can appeal unfavorable audit determinations in some cases, filing a successful appeal is not always possible, and reversing an unfavorable CMS audit determination can be a cost-intensive and time-consuming process.
What Are the Penalties for CMS Non-Compliance?
The penalties for CMS non-compliance depend on the specific compliance failure involved. Generally speaking, however, CMS has the authority to impose recoupments, prepayment review, denial of pending claims, fines, and Medicare and Medicaid exclusion. When warranted, CMS can also refer providers to the DOJ or OIG for criminal prosecution.
How Can Healthcare Providers Ensure that They Are CMS-Compliant?
Healthcare providers can effectively manage CMS compliance by working with experienced legal counsel. While managing CMS compliance is not easy, it is possible—as long as providers have the insights, advice, and resources they need to satisfy their statutory and regulatory obligations.
Schedule an Appointment with a CMS Compliance Lawyer at Oberheiden P.C.
Do you need to know more about CMS compliance? If so, we invite you to get in touch. To request a complimentary initial consultation with a CMS compliance lawyer at Oberheiden P.C., call 888-680-1745 or send us a message online today.
