Recent enforcement actions involving a small number of ABA providers have brought increased regulatory attention to the industry.

The most prominent example is the recent Minnesota prosecution involving allegations of billing for services that never occurred, falsified documentation, kickbacks, and concealed ownership interests. While the allegations are extreme and not representative of most ABA providers, cases like these have raised alarm among federal and state regulators.

For providers committed to compliance adherence, the more important lesson is how regulators identify, evaluate, and respond to compliance concerns. Recent audits and enforcement actions show that unresolved issues involving documentation, billing, credentialing, supervision, and governance can result in increasingly serious consequences.

Enforcement Rarely Begins with Criminal Fraud

Regulatory scrutiny does not always begin with allegations of fraud. More commonly, regulators identify issues through audits, complaints, data analytics, whistleblower reports, or routine program integrity reviews. Documentation or credentialing deficiencies, missing supervisory records, or unsupported claims may initially result in repayment demands, corrective action plans, or closer oversight rather than formal enforcement.

This distinction is important. Compliance gaps identified through audits do not automatically constitute fraud. The recent HHS-OIG audits discussed in our prior post identified recurring documentation, credentialing, treatment planning, and supervision deficiencies across multiple states. Such findings can create significant repayment exposure and regulatory risk, but they do not necessarily establish fraud. Instead, they demonstrate the compliance areas attracting the greatest attention from regulators.

How Compliance Concerns Escalate

Enforcement risk increases when organizations fail to address known concerns, lack meaningful oversight, ignore repeated warning signs, or submit claims that are not adequately supported. Regulators are increasingly focused not only on whether errors occurred, but also on how providers respond once potential issues are identified.

Providers that investigate deficiencies, implement corrective actions, strengthen controls, and monitor for ongoing compliance generally place themselves in a different position than organizations that fail to respond to identified risks. A documented good-faith compliance effort may affect how regulators evaluate an organization’s response, even when the underlying issue still requires correction, repayment, or other remedial action.

What Recent Cases Reveal About Regulatory Priorities

Although recent enforcement actions involve significantly varying fact patterns, they consistently highlight several areas of regulatory focus:

  • Documentation supporting services billed
  • Provider credentialing and qualifications
  • Required supervision of behavioral technicians
  • Medical necessity and treatment plan support
  • Ownership transparency and governance

The Minnesota enforcement actions involved allegations of billing for services that never occurred, falsified documentation, kickbacks, and concealed ownership interests.  At the state level, enforcement actions have targeted several of the concepts listed above.  While the facts differ from case to case, the common thread is that regulators continue to focus on the integrity of the underlying services and the systems used to document, supervise, and bill for those services.

Demonstrating a Culture of Compliance

Most ABA providers are focused on delivering medically necessary services and improving outcomes for individuals and families affected by autism. At the same time, providers should recognize that regulators now have a clearer understanding of the industry’s operational and compliance risks than they did even a few years ago.

For many organizations, the critical question is not whether a compliance concern will ever arise, but whether the organization can demonstrate a good-faith effort to identify, address, and prevent issues before they become larger problems. As audits, data analytics, and enforcement activity continue to expand, providers should expect increased scrutiny of their compliance infrastructure and operational controls.

The final post in this series will discuss practical compliance strategies providers can use to reduce risk, strengthen program integrity, and prepare for an increasingly complex regulatory environment.

* * * *

If you have questions, please reach out to the author(s).

The Commercial Litigation Update blog is currently edited by Jennifer O'Connor and Adam Paine.

Back to Commercial Litigation Update Blog

Search This Blog

Authors

Related Services

Topics

Archives

Jump to Page

Subscribe

Sign up to receive an email notification when new Commercial Litigation Update posts are published:

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.