ABA and FWA: Compliance Best Practices

With DOJ and state Medicaid Fraud Control Unit (“MFCU”) enforcement increasing in the ABA space, proactive compliance programs are more important than ever. State Medicaid billing rules, scope-of-practice requirements, the CMS Toolkit, and recent OIG audit findings provide an important framework for identifying and monitoring compliance risk.

Documentation: The First Line of Defense

Inadequate documentation is arguably the most consistently cited deficiency across recent OIG state audits. Missing session notes, unsigned individualized treatment plans, absent supervisory co-signatures, and undocumented diagnostic support appeared in every state. The CMS Toolkit further identifies documentation red flags, including cloned notes (identical notes across individuals by the same provider or clinic), unmodified treatment plans across multiple authorization periods, and discrepancies between authorized and delivered hours.

Providers need systems in place to confirm that session notes are contemporaneous, record the exact start and end time of the session, identify the staff member and their credential, reference the specific treatment goal addressed based on the approved plan, and carry the appropriate signature required under the applicable state Medicaid rules.

Clinics need to be specifically aware of templated or cloned notes copied across clients or dates without individualization, as they are compliance red flags, and in criminal cases, can be a predicate for fraud charges.

Providers should also be alert to non-therapeutic time embedded in billed sessions. For example, time spent on naps, drop-off and pick-up, administrative tasks, or meals may not be billable under applicable payer requirements and should be evaluated against the relevant coverage and documentation rules. Some payors require that if a provider steps away from an active session, the session should be terminated and restarted upon reengagement, with the interruption documented. Generally speaking, billing for the full scheduled block regardless of what occurred during the session is arguably the most straightforward path from a documentation deficiency to a fraud allegation.

The recently published CMS Toolkit mentioned throughout this series identifies Electronic Visit Verification (EVV) as a key fraud prevention tool. While currently only required in personal care and home health service settings, CMS recommends states extend EVV requirements and integration into home-based ABA services given the high volume and decentralized nature of care at home.

Auditing and Monitoring: The Second Line of Defense

A robust audit process is central to detecting and correcting improper payments. In addition to identifying irregularities before a government auditor or qui tam relator, a policy of ongoing auditing creates a contemporaneous record of good faith compliance efforts.

The CMS Toolkit and the OIG audit findings together identify key areas for ongoing monitoring. Owners and providers should have policies and procedures in place to regularly audit and monitor OIG exclusions, session-level documentation, treatment plan integrity (to ensure plans are individualized and current), and billing patterns such as concurrent or overlapping claims.

Providers who regularly review these areas and remediate as necessary are in a categorically better position than those who discover the same issues through a government notice.

ABC: Always Be Credentialing

With high annual technician turnover rates, the risk of credentialing lapses at any given time is structurally high. Providers should maintain real-time verification of BCBA, BCaBA, and RBT credentials, as applicable, as well as any required state licensure, rather than relying on a one-time check at onboarding.

Submitting a claim under a credentialed clinician's NPI when the actual service provider was uncredentialed, or applying the wrong modifier, may create overpayment or False Claims Act exposure, particularly when the provider knowingly misrepresents who rendered the service or whether credentialing requirements were met.

Diagnostic Integrity

Fraudulent autism diagnoses are among the allegations in the Minnesota cases and highlight the importance of diagnostic integrity. Diagnostic clinicians must conduct evaluations with clinical objectivity, using standardized instruments (e.g., ADOS-2, CARS2-ST) without pressure toward any particular outcome. Critically, a provider’s compensation, performance evaluation, and advancement should in no way be tied to the number of diagnoses rendered, severity scores assigned, or hours subsequently authorized.

If the clinic ultimately refers the patient for ABA services, it should preserve the patient’s freedom of choice, disclose relevant conflicts, and avoid any inducement to remain with the clinic for treatment.

Train Staff, Create a Reporting Channel, and Protect Reporters

Behavioral technicians are not inherently billing experts, but as their time is billable, they must be trained on billing requirements and potential consequences of noncompliance. Training should cover: what constitutes a reimbursable session; how to complete a contemporaneous session note with exact times; what to do when a session is cancelled or shortened; and — critically — what to do if a supervisor instructs staff to bill regardless of whether services were delivered.

A well-trained staff member who understands both the obligation and the legal protection available to them if they report an improper billing instruction is a compliance asset. To protect that asset, providers should have a documented reporting channel (including an anonymous option), as well as a written non-retaliation policy.

A Note for Private Equity Investors

The CMS Toolkit addresses Private Equity (PE) ownership directly, and notes that PE acquisition “could result in the prioritization of profit over the quality of individual care” through lower staffing and inadequate supervision. The Toolkit calls for a clear divide between clinical and operational structures, such that “clinical directors operate independently from revenue-generation demands.”

Acquisition of an ABA provider or platform brings additional requirements and potential successor liability. Pre-closing diligence should include: a review of prior OIG audit findings, MFCU activity, and provider agreement terminations; an independent billing sample review against OIG’s documented deficiency categories; credentialing record verification for all billing staff; and OIG exclusion list checks for current and former owners. Post-acquisition, priorities should include compliant integration of billing and compliance functions, reporting any changes in ownership, control, or management within 35 days, and performing revalidation and exclusion screening on new owners.

Existing investors should evaluate whether adequate governance structures exist to identify, escalate, and address compliance concerns. Particular attention should be paid to the independence of clinical leadership, the effectiveness of compliance reporting, and the organization’s process for identifying and remediating potential issues. In the current enforcement environment, investors should understand not only where potential risks exist, but also how management responds when those risks are identified.

For Operators: Conduct an Internal Billing Audit Before a Government Audit

A privileged internal review directed by counsel can help identify irregularities before they surface in a government audit, investigation, or whistleblower complaint. When structured appropriately, the review may support good faith corrective action and provide an opportunity for voluntary self-disclosure if material overpayments are found. The focus of any internal review should follow the OIG’s documented deficiency categories: billing volume relative to peer providers; claims by staff against credentialing records; supervisory billing codes against actual supervisor time records; and overlapping or concurrent billing patterns.

Conclusion

The growth of ABA and the increased regulatory attention it has attracted present simultaneous risks and opportunities for providers and investors. Providers that treat compliance as a foundational business practice—not a defensive measure—can seize the opportunity to strengthen their compliance programs. A disciplined approach to documentation, credentialing, billing integrity, and staff accountability creates both operational efficiencies and regulatory resilience. As federal and state enforcement agencies focus on the ABA space, organizations that can demonstrate transparent operations, meaningful oversight, and a genuine culture of compliance are best situated to withstand the increased attention.

* * * *

If you have questions, please reach out to the author(s).

The Commercial Litigation Update blog is currently edited by Jennifer O'Connor and Adam Paine.

Back to Commercial Litigation Update Blog

Search This Blog

Authors

Related Services

Topics

Archives

Jump to Page

Subscribe

Sign up to receive an email notification when new Commercial Litigation Update posts are published:

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.