0:00
Last year was the largest year in healthcare fraud recoveries. I think we look back next year and this year is going to be the largest. So it's just going to continue to go up and up.
0:22
You welcome to off the chart, a business medicine podcast featuring lively, informative conversations with health care experts, opinion leaders and practicing physicians about the challenges facing doctors and medical practices. My name is Austin Luttrell. I'm the associate editor of medical economics, and I'd like to thank you for joining us today. In today's episode, I sat down with Shannon Sumner, managing principal of PYA Nashville office, and the firm's Chief Compliance Officer, Shannon is a nationally recognized health care compliance expert with more than 30 years of experience helping organizations navigate fraud and abuse risk. We discussed how health care fraud enforcement has become more data driven than ever, what new initiatives from the federal government mean for individual physicians and practice leaders, and why our reactive compliance program is no longer enough for 2026 Shannon Sumner, thank you for joining us, and now let's get into the
1:11
episode. Shannon Sumner, thank you so much for joining me
1:13
today. Oh, thank you so much. I'm excited to be here
1:16
before we get started. Do you mind just sharing a bit about your background and maybe a bit about PYA as well.
1:22
Yeah, absolutely. So Shannon Sumner have been with py a for probably about a combined 16 years. And you're probably thinking, well, who is PYA? We are a national healthcare consulting and accounting firm. We're a top 100 accounting firm, probably one of the top 25 in terms of management consulting firms in the country, and I lead our regulatory compliance service line. So my background is a little bit a hodgepodge, but they all kind of connect together. Started off traditional accounting route, but then probably about 16 years of my my career has been spent with organizations of all sizes related to compliance programs, internal audit when I came back to the firm, really helped the organization and the firm start what's called our regulatory compliance service line. So we work very closely with physician practices, health systems, just a variety of different types of health care entities in assessing compliance risks. So it could be anything from what we're going to talk about today, from fraud and abuse, but you know, mergers and acquisitions helping them really think through their compliance programs and how they can be reactive and proactive related to their compliance program. So I'm excited to talk about what we're going
2:38
to talk about today. Great, just to kind of get us started off. I know physicians are reading the headlines. They're watching the news and hearing new things out of the DOJ and CMS. This administration in particular, has a lot of focus on fraud, waste and abuse. So from where you sit, how is the enforcement environment changing in 2026 and what should physicians and practice leaders be worried about now when it comes to fraud, waste and abuse?
3:03
Well, you know, in in the enforcement environment in 2026 is really more data driven and pattern focused than than ever before, investigations are increasingly triggered by analytics, so practices get flagged because their data doesn't look like their peers, and in 2026 physician practices will really face greater scrutiny, less margin for error. And therefore, if you haven't already, you really should create that compliance framework to monitor high risk areas, and thinking about some of the the top high risk areas, these are quite a few to mention, but of course, we wanted to spend some time today talking about that. So the first thing certainly billing, coding and documentation, integrity, the OIG and the DOJ continue to prioritize improper payments in high risk areas. These include many that you already know, but em level, selection and medical necessity, modifier, misuse, incident two billing split, shared visits and telehealth documentation compliance. Another risk area is as we're going to talk about quality reporting and value based payment errors so things like inaccurate or incomplete quality data, electronic health record, auto population that contradicts, you know, the clinical notes and the inability to validate reported measures and missing or late submissions. And one more to add to the list, it's been a lot of hype. Certainly related to this is Medicare Advantage and risk adjustment, huge focus by the OIG and CMS, relating to inadequate documentation, supporting HCC coding, also layering in with that marketing and incentives tied to plan enrollment or utilization risk exposure is significant. Get, and can include recoupment and risk adjustment, or RAD B audits, as they're called, also anti kickback exposure for incentive arrangements and false claims actions to layer on top of that, related to unsupport diagnoses. And in fact, the OIG just released additional compliance guidance related to Medicare Advantage plans. And one thing we can't forget about, just to throw everything else in there with it, is data privacy and security. So cyber security risks related to that certainly a compliance risk as well. We're talking about, you know, HIPAA enforcement, cyber security risks, ransomware and then third party vendor risk is really going to be hot on the horizon for 2026
5:43
so a lot of physicians are now paid through value based care arrangements. Where do you see those deals really creating risk for fraud and abuse? Are there things that organizations can build into them, kind of from the start to maybe stay out of trouble? Right?
5:58
I would say, you know, the biggest compliance risks and these value based arrangements, the things that we're talking about include, certainly risk adjustment, quality reporting, patient attribution and incentive payments, and it's critical for providers to avoid really vague contractual definitions. So when you're looking at those arrangements, some of those areas that can be vague, that really need to be defined, would be what counts as a covered service, a quality what counts as a quality event, or, again, an attributed patient. Really do your due diligence before entering into any new or renewing any value based care arrangement. Think it's important to understand the payment model, the incentive model, certainly quality measures. Ensure that these are defined in advance. It can't be after the fact, it has to be in advance, and that measures are objective and evidence based. Also understand your financial risk, what level of upside versus your down downside risk. Make sure that's clearly stated, and ensure you have timely access to claims and performance data that benchmarks that are used and targets they can be independently reviewed, and this is coming from someone that's been an internal audit and compliance officer. Make sure you can audit it, but ensure there are also no restrictions on patients, freedom of choice, no steering away from high risk or complex patients. And finally, ensure that any arrangement has been thoroughly vetted by legal and compliance experts, you really need to ask yourself, Could the arrangement withstand audit or regulatory
7:40
review when a practice or a physician group is negotiating a VBC arrangement or agreement. Rather, what are the top red flags that you look for from a compliance perspective, and what are some changes that can actually reduce risk there without maybe blowing up that deal? Right?
7:57
Right? Well, I think risk reducing fixes that don't, as you say, blow up the deal again, kind of clarifying those definitions. It's okay to ask questions. You're not going to blow up the deal if you ask those questions, adding in those payment guardrails. And we're all going to be talking about this forever, I think, now with AI, but requiring that data transparency, you know, really understanding, dig into the data, making sure that you could truly understand how those deals are structured, and that's okay to do that as part of the due diligence. And most deals not need don't need to be scrapped, they just need to be properly vetted again. How would I monitor a compliant execution of the agreement? Do you have people who can help you monitor the execution of that agreement? And it's really not a one and done, you need to stay on top of any arrangement, post transaction or execution. For example, you know there is a false claim to act risk if you provide knowingly and accurately data is submitted. Because if you don't have the right data, you don't have the right information, you need to know what you've got. You need to know what you're submitting. And that can be considered truly a false claim to act risk. Data errors now are treated as compliance failures and not technical mistakes. While CMS and OIG have created value based care exceptions and safe harbors, they are highly technical and easy to miss, not to scare anyone away from these arrangements, but it is critical to know what you're getting yourself into, because Stark law remains a strict liability. And in my experience from both the consultant and as an internal auditor and a compliance officer, many deals look great on paper, but they fail on execution.
9:42
So there's, there's still this, this kind of, you know, the signal about telehealth related fraud being a priority. What are some specific patterns or practices that are drawing a lot of attention regarding telehealth, and what are some steps that you know, practices that are using telehealth A lot can take to reduce that risk of being. Of you know, swept
10:00
into an investigation? Yeah, thank you for asking that question. I think many of us have also used been recipients of telehealth services in light of covid and then post covid world that we're living in right now. But what's the saying the best the best cure, is an ounce of prevention or something like that, right? But in a telehealth world, risks that need to be mitigated include controls to ensure adequate patient evaluation and medical necessity. I mean, it's this is no different than in the practice setting, but examples of concerning patterns that that they are monitoring include like a brief or a very scripted encounter, no access to medical history, Reliance solely on questionnaires. The OIG is telehealth analytics mean they're getting more and more robust, but they have flagged high volume billing for services, improbable utilization patterns and duplicate claims, incorrect coding related to place of service and time based billing. Remote prescribing is another risk. Providers must closely follow the DEA and the state rules, and then also, from a HIPAA perspective, Tallahassee risk include using platforms without the Business Associate Agreement. I mean, I mean, I can't stress that enough, you need to know who has access to your information. Do you have a business associate agreement in place in order to protect that phi? Because you talk about the different acronyms you got, you know, OIG, you've got CMS, you got DOJ, you've got OCR. So you've got to really ensure that your telehealth platforms really do comply with all of those particular elements. And then, from a HIPAA perspective, also, in addition to protecting that phi recording sessions without patient authorizations, you've got notices of privacy practices that are included as well. And because telehealth encounters, you know, they started off pretty hot and heavy and covid, I think that a lot of the risks that have come to light related to phi, but also, you know, privacy security, and then there's also those Breach Notification rules. So there's a lot of things to consider with telehealth. It's a great it's a great tool to use, but I think because there's more and more organizations that are using telehealth and for most for the for the right reasons, but unfortunately, you do have some bad actors out there that are using them for the wrong reasons. And I think that's an area that has that's going to continue to have that that particular lens and that particular focus, definitely.
12:36
So I know you mentioned it earlier about, you know, things being a lot more focused on on data nowadays, especially with compliance, how has that changed? The kind of cases that you're seeing, and what should organizations be doing now, particularly regarding things like documentation and coding, internal monitoring?
12:53
Yeah, absolutely. Internal auditing and monitoring one of my favorite topics. So but before the increase in analytics, claims may have been reviewed by investigators on a sample basis, so not the entire population of claims, because it was just easier to do that. They just didn't have the entire population, as we do now. And then they would extrapolate and aerate. But now the full population of claims is analyzed. Practices should be doing the same and invest in that appropriate technology to monitor your own operations. However, regardless of the method agencies are using to detect fraud, the underlying principles of good internal controls remain the same for practices. It's really that documentation integrity ensure the clinical story matches the code conduct internal monitoring and build your own dashboards to track top outlier metrics. Couple of these em distributions, modifier rates. How often are you using those high cost codes, services, procedures, supplies, denials and refunds and then conduct targeted audits. So really you think about there's so much to think about through this, but really focus on the 20% that's generating 80% of risk, and really be proactive.
14:22
You Hey there. Keith Reynolds here and welcome to the p2 management minute in just 60 seconds, we deliver proven, real world tactics you can plug into your practice today, whether that means speeding up check in, lifting staff morale or nudging patient satisfaction north. No theory, no fluff, just the kind of guidance that fits between appointments and moves the needle before lunch. But the best ideas don't all come from our newsroom. They come from you got a clever workflow. Hack an employee engagement win, or a lesson learned the hard way. I want to be true. Shoot me an email at K Reynolds at mjh life sciences.com with your topic, a quick outline or even a smartphone clip, we'll. Handle the rest and get your insights in front of your peers nationwide. Let's make every minute count together. Thanks for watching, and I'll see you in the next p2 management Minute.
15:14
A lot of our audience, they're they're independent physicians, they you know, they're in small practices, mid sized practices, if they don't have that big compliance budget, right? Could you kind of talk about, I guess, priorities and what a realistic, effective compliance program looks like in 2026 I mean, what are the must haves versus nice to haves?
15:33
Yeah, this is a great question. In fact, the OIG, they produce a publication, and they actually updated it recently, and it's called the general compliance program guidance for any of your listeners that want to go out there and read it. But it does acknowledge that one size doesn't fit all for compliance programs. So that was really good to hear that that affirmation, however, they actually do provide examples of the must haves regardless of the size, and they recognize that physician practices, smaller physician practices would fit into the smaller categories, but they do say the must haves include a designated compliance lead. It doesn't have to be at that compliance officer that you see in a lot of large organizations. It can even be part time, but it does need to be someone that is really taking the charge for developing that compliance program. We're going to talk about just a few of those things in just a second, but even part time, as long as they have access to leadership, they but the one thing they do say is they should not be whoever you select to be in that role. They should not be involved in the coding and billing portion, because it really needs to be someone that shouldn't be auditing their own work, as you will, another set of things that that's considered, you know, the must haves is written policies and procedures that actually may match the workflows. It's not just a binder or or, I would say, now, a file on your computer that just sits on a shelf. Training that is also role specific. You know, a lot of organizations have what I would consider the general compliance training, which is great, but then there all should be very specific role specific training. So your providers, your physicians, those that are involved in billing, documentation, reviews, scheduling, just to understand, particularly from a scheduling perspective, you know, protected health information. So there's a lot of different things that can be called out for training, and it's really not that challenging to develop it. In fact, the OIG and CMS has some great tools that are free. You just need to take advantage of those tools, and really utilize those tools. The OIG also mentioned a mechanism to report concerns. We see a lot of activity in both the, you know, the larger health system hospital space, but also in the physician practice space that you know from a whistleblower perspective, in many cases, it's because they just didn't feel heard. We look at a lot of the transactions that have hurt have occurred that have led to settlement agreements, and in many cases, is because people just they weren't heard. So think about, you know, do you necessarily have to buy a big subscription to a hotline system? Not necessarily, but there has to be a process in place, and a procedure and a policy in place for non retaliation. You can't retaliate against someone because they they brought some sort of concern to you as a as a health care provider. And then finally, some basic auditing and monitoring, as we talked about earlier. You know, look at the top, the top 20 that's generating the 80% don't You don't have to boil the ocean, but focus really on those high risk areas, and finally, having a good corrective action roadmap. So if you identify something you can't, you know now you're culpable. You need to make sure that you have some good controls and action plans to mitigate that risk in the future. On the nice to haves. You know, obviously, as a consultant that does this, I would love to say it's a must have, but a nice to have is a third party compliance assessment. We are actually doing this a lot more than we have before, related to some of the smaller entities. Is just, you know, things that we think are compliance might be rolled into risk. It might be rolled into quality, and you could probably be doing a lot of things that, you know, we would consider compliance, but making sure that you've got the right infrastructure for compliance assessment. So I would say a third party compliance assessment doesn't have to be done every year. I would say every, you know, three to five years when you actually have a significant change, if you're growing, if your practice is growing, if you're advancing in terms of the new services that you're providing, as we mentioned earlier, some of these contractual relationships that you're entering into, I think it's important also nice to have. You know, I would say nice to have now. I would say must have, pretty soon would be advanced analytic tools. Some. Saying that I know that for many of your viewers that may be going to conferences, really trying to take a look to see what's out there for physician practices, continuous auditing software, you know, with with that type of data analytics that's being present in the outside world, looking into your practice, you need to have some things internally looking outside. So really thinking about your your data analytics, which I said, you know, it might be nice to have now, but not for long. Plus, it's also a competitive advantage for your practice to invest in this type of infrastructure and and finally, with this particular topic, you must show consistency. It really has to be more than what they'll call a paper program. Great.
20:44
So, I mean, you kind of touched on it there. I mean, if you're a practice and you're conducting an internal audit and you find something that may be a problem, you know, an area where they're not compliant, what is that plan of action? I guess, what should they do first? And how do you decide when to self disclose versus when an internal corrective plan is enough.
21:04
And we get that ask a lot as well from our clients, but I would say the first priority is to contain the issue, pause the process, hold bills, locate documentation. I think that is going to be the first thing is, like, Kate, you got to have a plan. I know we haven't talked about this. This might be a whole nother topic for your listeners, but part of a policy and procedure in terms of, how do we respond if we have an investigation, or how do we respond if we have an internal review that we identified in error, you just need to make sure you've got some good processes in place to do it before then right when you're in like in the middle of a crisis, but first of all, pause the process, hold those bills, and very important, seek the advice of counsel, I mean, ideally, one that is well versed in these types of situations. Just like consultants, we all have our expertise. Council also has their areas of expertise. Not everyone is has their expertise in fraud, waste and abuse, anti kickback, start compliance HIPAA as well, and then possibly engage a compliance consultant under attorney client privilege, he can help do a deeper dive. There might be a repayment that's needed. There might be a corrective action plan. There should be a corrective action plan that's also implemented, and then at that time, with good counsel, you can determine whether to self disclose or whether a corrective action plan is sufficient.
22:29
As you look at trends in telehealth, value based care, new digital tools. I know, you know, we talked about AI briefly, where do you expect the next wave of enforcement to land? You know, like, what should physicians be looking at now and doing now to stay ahead of those kind of evolving risks?
22:47
Well, we've talked about it, but artificial intelligence, I mean, AI enabled documentation and coding tools, these will come under heavy scrutiny if you are already utilizing such tools, I would say, create what we're seeing. And this is something that can be done regardless of the size of the organization, but have some type of AI Governance Committee. It could be three people, but to inventory and really evaluate the risk. There are many tools that are available out there to assess risk, and my recommendation would be to conduct, conduct an internal risk assessment of the impact AI has on if you're using it for clinical decision making, what impact the use of AI has on patient protecting patient privacy, what it does related to security and billing risk areas, you know, A big area right now that we're saying, again, regardless of the the type of organization, but third party risk, you know, who, who are you working with? Are you doing the due diligence on those providers or those, those third parties that are helping you in a variety of different areas within your practice, what access of information that they have and they because they can also be a big risk, those contracts that I mentioned related to business associate agreements, review those, are they protecting your information? Are they securing have they had a certain level of security assessment for their particular work that they do in supporting you and your practice?
24:16
CMS, they had a press conference at the White House with the vice president the health secretary and the CMS administrator, and they announced the new crush initiative. Is there anything regarding that their in their new announcement on the war on health care fraud, I believe they called it the physicians need to know about.
24:35
I mean, you know, the times have changed where the emphasis was on the the big the big entities, the big health care systems, the the, you know, insurance providers, ma plans. But now individuals, and if any of your listeners have can go out there and just kind of Google or use AI to do it related to the health care from fraud in the practice setting, they're going. Going after individual providers. They're going after individual individual physicians. What I would share is that the the topic of healthcare fraud enforcement is not going away. Last year was probably the largest year in terms of healthcare fraud recoveries of over $6 billion These are easy targets, again, with the use of the data analytic tools. In fact, think it was last, last year, CMS actually, literally had what's called a chili cook off contest. They actually called it that, and it was to solicit vendors that can help them create and enhance data analytic tools. What are the frauds that they should be looking for? There's just going to be more and more emphasis on targeting, identifying fraud and abuse. And as I mentioned earlier, there's there's just the perception that you could have an error, but the government has now provided notice that you have to have a really strong compliance program in place to identify, to mitigate, protect those federal health care funding dollars, and so I don't think that's going to go any go away, and last week's conference about that is a clear it's a clear indication that they're just going to continue to really focus on this. And again, like last year was the largest year in healthcare fraud recoveries, I think we look back next year, and this year is going to be the largest. So it's just going to continue to go up and up.
26:38
Great. Is there anything that you think we might have missed, or anything else you'd like to share.
26:44
You know, I am on my soapbox here, but I think the best compliance programs are really operational partners, and practices really should move from reactive compliance to proactive compliance. As I mentioned, the OIG has made it clear that the absence of an effective compliance program is an aggravating factor in enforcement actions, even for small practices. So prevention really is the best medicine.
27:10
Shannon Sumner, thank you again for joining me. Thank you enjoyed it.
27:22
You again, that was Shannon Sumner, managing principal of PYs Nashville office and the firm's Chief Compliance Officer on behalf of the whole medical economics and physicians practice teams. I'd like to thank you for listening to the show and ask that you please subscribe so you don't miss the next episode. As always, be sure to check back on Monday and Thursday mornings for the latest conversations with experts, sharing strategies, stories and solutions for your practice. You can find us by searching off the chart, wherever you get your podcasts, and if you'd like the best stories that medical economics and physics practice published delivered straight to your email six days of the week, subscribe to our newsletters at medical economics.com and physicianspractice.com off the chart a business and medicine pod. Executive produced by Chris mazzolini and Keith Reynolds and produced by Austin Latrell. Medical economics and physicians practice are both members of the mjh Life Sciences family. Thank you. You. You.
We recommend upgrading to the latest Chrome, Firefox, Safari, or Edge.
Please check your internet connection and refresh the page. You might also try disabling any ad blockers.
You can visit our support center if you're having problems.