RegTech Reviews

Regulatory Requirements in Healthcare Beyond HIPAA

Healthcare organizations face a complex web of federal laws beyond HIPAA.

Staff Writer · · 11 min read
Cover illustration for “Regulatory Requirements in Healthcare Beyond HIPAA”
Industry Regulations · September 6, 2026 · 11 min read · 2,489 words

HIPAA covers exactly one thing: the privacy and security of protected health information. Everything else a healthcare organization answers for, fraud, emergency care, data blocking, workplace safety, state law, sits in a separate stack of rules that rarely gets mentioned in the same breath as HIPAA but carries just as much bite. This piece walks through that stack layer by layer: what each law actually prohibits, who shows up to enforce it, and what enforcement looks like right now.

A compliance program that only reads HIPAA is prepared for one narrow scenario and exposed everywhere else, and that's the mistake worth naming up front rather than burying in a footnote. These frameworks don't stack neatly. A single billing decision can trip the False Claims Act, the Anti-Kickback Statute, and Stark Law all at once, because they were built by different Congresses at different times to solve different problems, not to fit together like a puzzle. Anyone treating them as one big HIPAA-adjacent blob is going to get surprised by the wrong enforcement letter.

How HITECH extended HIPAA's reach and raised the stakes for violations

HITECH passed to push hospitals and clinics toward electronic health records and what regulators called "meaningful use" of health IT. That was the stated goal. What actually matters for anyone running a compliance program today is what HITECH did to enforcement, and on that front the law did two things that changed the game.

Before HITECH, HIPAA penalties were modest, and business associates, the vendors, billing companies, and IT contractors who touch patient data without being a hospital or insurer themselves, sat mostly outside direct liability. HITECH fixed both problems at once. It built a tiered civil penalty structure reaching $1.5 million per violation category per year, and it made breach notification mandatory instead of optional. Quietly patching a leak and hoping nobody noticed stopped being a strategy. If PHI got exposed, patients, HHS, and in serious cases the media, all had to be told.

The business associate piece is the one that actually reshapes daily operations, and it's the part most compliance programs still underrate. Vendors who process claims, host EHR systems, or manage medical billing are now directly liable under parts of the Security Rule and for improper PHI disclosures. A hospital's compliance exposure doesn't stop at its own walls; it extends into every contract with every company that touches patient data. Business associate agreements aren't paperwork to file away after signing. Regulators expect an organization to monitor them as a live legal control, which means third-party risk oversight isn't some adjacent nice-to-have. It's core to what HIPAA compliance requires now.

The Anti-Kickback Statute and Stark Law — two distinct laws targeting financial conflicts in referrals

Both laws exist to stop money from corrupting a doctor's judgment about where to send a patient. Past that shared purpose, they work almost nothing alike, and the single biggest mistake a compliance team can make is treating them as interchangeable. They aren't. One cares what you meant. The other doesn't care at all.

The Anti-Kickback Statute is criminal. It prohibits knowingly and willfully paying, offering, soliciting, or receiving anything of value to induce or reward referrals paid for by federal healthcare programs. Intent is the hinge: prosecutors have to show the arrangement was knowing and willful, not accidental. Land on the wrong side of it and the fallout ranges from criminal charges to civil penalties to exclusion from Medicare and Medicaid, which for most providers functions as a corporate death sentence.

The OIG carved out Safe Harbors, specific ways of structuring an arrangement that, followed exactly, put it outside AKS liability. The word "exactly" is doing real work there. Safe Harbors don't grade on a curve. Meet 90% of the requirements and legally speaking, that's the same as meeting none of them.

Stark Law, the Physician Self-Referral Law, is civil and strict liability, meaning no intent requirement at all. If a physician refers a Medicare patient for a designated health service to an entity where that physician or an immediate family member holds a financial stake, the arrangement is presumptively illegal unless it fits a specific statutory exception. The structure of the deal triggers liability regardless of what anyone meant by it. Violate it and the fallout includes significant financial and programmatic consequences under federal law.

Regulatory reforms have been introduced over time meant to simplify some of this and make room for value-based care arrangements, where providers share financial risk for outcomes. Worth flagging though: those reforms adjusted the exceptions, not the underlying statutes. Every financial relationship with a referring physician, compensation deals, ownership stakes, joint ventures, still needs review against both AKS and Stark separately. Clearing one doesn't clear the other.

The False Claims Act — the federal government's primary tool for recovering healthcare fraud losses

The False Claims Act makes it illegal to submit a false or fraudulent claim to a federal payer, and it's the mechanism that turns a billing error or a fraud scheme into federal-level financial liability. As of 2024, civil penalties run from $13,946 to $27,894 per violation, adjusted annually for inflation. That range applies per claim, not per scheme; a billing pattern touching a few thousand claims scales the total liability accordingly. Criminal exposure sits on top of that: fines up to $500,000 per violation and up to five years in prison per violation.

DOJ announced FCA settlements and judgments exceeded $6.8 billion in fiscal year 2025, the highest annual total in the statute's history, and over $5.7 billion of that tied specifically to healthcare matters. Whistleblowers filed 1,297 qui tam lawsuits that year, also a record.

That pattern is the real story here, more than any single dollar figure. Qui tam suits, filed by private individuals on the government's behalf, are now the dominant way fraud gets flagged in the first place. Employees, former employees, even competitors, are functioning as an informal enforcement arm, and they get a cut of whatever the government recovers. Give someone a financial stake in reporting what they see, and a lot of them will.

Medicare Advantage risk-score manipulation has become its own enforcement category, and the recent settlements make the shape of it obvious. One provider paid $98 million in December 2024 for submitting invalid diagnosis codes to inflate patient risk scores. A separate company paid $62 million in March 2025 over spinal condition billing under Medicare Advantage. And in one coordinated action, DOJ's National Health Care Fraud Takedown brought criminal charges against 324 defendants tied to schemes allegedly worth more than $14.6 billion.

Here's the part that should worry a compliance officer more than any headline fraud case: the common trigger categories are upcoding, billing for services that weren't rendered or weren't documented properly, and claims lacking medical necessity. Those are documentation failures as much as fraud schemes. Nobody has to intend fraud for FCA liability to attach. A sloppy coding process is sufficient on its own.

EMTALA's non-negotiable obligations when a patient arrives at the emergency department

EMTALA exists because of one specific, ugly practice: hospitals turning away uninsured patients in medical emergencies, a practice regulators at the time called patient dumping. Congress passed the law in 1986 to shut that down, and it applies to every Medicare-participating hospital with an emergency department, full stop, regardless of whether the patient can pay a dime.

Three duties sit at the center of it. First, a medical screening exam for anyone who shows up, to determine if an emergency medical condition actually exists. Second, stabilization: if a condition is found, the hospital has to treat it until it's resolved or stable, insurance status be damned. Third, appropriate transfer, following EMTALA's specific procedural rules, if the hospital genuinely can't provide the needed care. That third duty runs both directions: a hospital with the specialized capability to treat a transferred patient is obligated to accept it, not just permitted to.

As of August 2024, penalties run $133,420 per violation for hospitals with 100 or more beds, and $66,712 per violation for smaller ones. CMS holds the nuclear option, termination from Medicare, while HHS OIG separately wields civil monetary penalty authority.

Between 2004 and 2018, HHS OIG investigated more than 7,000 EMTALA complaints and upheld 3,567 of them, settling an average of 21 violations a year through civil penalties. That's not a rare, dramatic failure pattern. That's a steady, ongoing rate of enforcement, the kind that indicates EMTALA problems happen constantly in ordinary hospital operations. Triage protocols, transfer agreements, on-call specialist coverage: all of it carries EMTALA weight, and none of it should be left entirely to clinical staff to manage without administrative oversight.

Information blocking rules under the 21st Century Cures Act — now actively enforced

The 21st Century Cures Act, passed in 2016, prohibits practices that interfere with accessing, exchanging, or using electronic health information. It exists because health systems, EHR vendors, and information networks were restricting data flow, sometimes for legitimate security reasons, often for competitive or financial ones, and patients and rival providers were the ones stuck without records.

Enforcement rolled out in stages, and the timeline actually matters for figuring out who's exposed to what, right now, rather than who might be exposed someday. Health IT developers and information exchanges faced enforcement first, with substantial civil monetary penalties applying once their compliance phase took effect. Penalties for healthcare providers took effect in a subsequent phase, with disincentives for Medicare-participating hospitals and clinicians phasing in shortly after. Medicare Shared Savings Program disincentives followed in a subsequent phase. Then, HHS put out a joint OIG and ASTP alert signaling active enforcement intent. That alert marks the shift from future risk to present enforcement.

Providers and health IT companies face different consequences under the same rule, worth keeping straight. Providers see reduced Medicare reimbursements and exclusion from shared savings programs, rather than the flat civil monetary penalty that applies to developers. Health IT developers and exchanges face that civil monetary penalty and additional regulatory consequences, a significant operational threat.

Several regulatory exceptions exist, covering privacy, security, preventing harm, and infeasibility, among others, but they're narrow and require documentation to invoke. Nobody gets to claim one after the fact and call it a day. Common risk scenarios include denying a patient's records request because the requested format is inconvenient, restricting a competing provider's access to shared data, or signing an EHR contract with terms that quietly limit data portability. That last one means legal review of EHR and health information exchange contracts belongs in compliance now, not sitting off in IT procurement where nobody's checking for it.

42 CFR Part 2 and the separate privacy regime for substance use disorder records

42 CFR Part 2 governs records from federally assisted substance use disorder treatment programs, and it's stricter than HIPAA in one specific, deliberate way. Under HIPAA, providers can share records for routine treatment, payment, and operations purposes without patient consent in a lot of circumstances. Part 2 doesn't allow that same latitude for SUD records. Consent requirements apply even where HIPAA would let information move freely, which is exactly the point: Congress wanted SUD records harder to move, not easier.

The rule applies to any program that holds itself out as providing, and does provide, alcohol or drug abuse diagnosis, treatment, or referral, as long as it receives federal assistance in some form. Regulatory updates over recent years brought Part 2 closer to HIPAA in some procedural respects while keeping its heightened core protections intact, so compliance teams need to track both what aligned and what didn't. Some provisions moved toward HIPAA's standard; others remained distinct.

The operational headache shows up in integrated care. As primary care, behavioral health, and SUD treatment increasingly get delivered under one roof or one record system, sorting which records fall under Part 2's stricter rules and which fall under HIPAA alone gets genuinely complicated. Organizations running integrated care models need a distinct policy framework for Part 2, one substantial enough to stand on its own rather than trailing behind the HIPAA manual as an afterthought.

OSHA obligations inside healthcare settings — the compliance layer that protects the workforce

OSHA's healthcare rules deal with hazards that look nothing like a typical office or factory floor: bloodborne pathogens, workplace violence, hazardous drug exposure, airborne infectious disease. The Bloodborne Pathogens Standard requires exposure control plans, engineering controls, staff training, and follow-up after any exposure incident.

Workplace violence deserves particular attention, and not as a footnote. Emergency departments and behavioral health units face well-documented elevated risks of violence against workers, and where no specific OSHA standard covers it, the agency's general duty clause fills the gap. Hazardous drug standards cover safe handling for chemotherapy agents and similar medications, and respiratory protection protocols govern exposure to airborne infectious disease, the kind of risk that drew significant public attention a few years back and has since faded from most people's daily concern.

What makes OSHA compliance tricky in healthcare is where the rules actually live. They're embedded in clinical protocols, staff training calendars, incident reporting systems, and facilities management, scattered across departments that don't always talk to the formal compliance office. That's exactly why OSHA exposure slips outside a compliance program's radar even when everyone individually assumes someone else owns it. Citations and penalties are public record too, so the exposure isn't only financial; a facility with a string of violations carries a reputational cost as well. Compliance leaders need clear ownership assigned, trained clinical and facilities staff, and safety incident data actually feeding into the broader compliance monitoring system rather than sitting in its own silo, ignored until an inspector shows up.

State-level requirements that exceed federal floors — the layer that differs by jurisdiction

Federal healthcare law sets a floor, not a ceiling, and states routinely build higher. The same organization can be fully compliant with every federal rule covered above and still be out of compliance in a specific state, because that state decided the federal baseline wasn't protective enough. That's not a loophole. That's the design.

Privacy is the clearest example. Several states have passed health data privacy laws reaching further than HIPAA, covering consumer health data held by companies that aren't HIPAA covered entities at all: wellness apps, employer wellness programs, fitness trackers quietly collecting health metrics all day. HIPAA was never built to reach those companies, so states stepped in where the federal framework simply stops.

Breach notification follows the same pattern. Most states run their own notification laws, each with its own timeline, its own required content, its own threshold for what counts as a reportable breach. A national health system operating across a dozen states is managing a dozen overlapping breach notification obligations, each with a slightly different clock running, none of them synced to the others. That's the rules working exactly as designed, layered and uneven on purpose, because Congress left states room to go further and states took it and kept going.

More in Industry Regulations