When a provider or supplier of services bills the Medicare program and receives payment, but at a later date the program audits the claim and denies it, can the provider or supplier be relieved of any financial liability if it had a good faith belief that the service met all relevant coverage requirements, even when that belief is incorrect? In a recent decision, the U.S. Court of Appeals for the Sixth Circuit ruled that this relief is possible, and that administrative adjudicators must conduct an analysis under the “hold harmless” provision of the Social Security Act (the “Act”).[1]
[1] In Home Health, LLC v. Kennedy, 2026 WL 2147418 (6th Cir., July 27, 2026); also available at: https://www.opn.ca6.uscourts.gov/opinions.pdf/26a0205p-06.pdf.
On January 5, 2020, HR 7898, became law amending the Health Information Technology for Economic and Clinical Health Act (HITECH Act), 42 U.S.C. 17931, to require that “recognized cybersecurity practices” be considered by the Secretary of Health and Human Services (HHS) in determining any Health Insurance Portability and Accountability Act (HIPAA) fines, audit results or mitigation remedies. The new law provides a strong incentive to covered entities and business associates to adopt “recognized cybersecurity practices” and risk reduction frameworks when complying ...
Recent Updates
- Comment Period Closes on California OHCA’s Proposed Emergency Regulations Expanding Private Equity, Hedge Fund, and MSO Reporting in Health Care Transactions
- DOJ Revises Justice Manual on Non-Binding Guidance and Qui Tam Dismissals: Practical Considerations
- Additional SBA Crackdown on Pandemic-Era Fraud Leads to Program and Loan Suspensions, Possible FCA Enforcement
- Federal Regulatory Views on Cybersecurity and AI Amidst a Growing Threat Landscape
- Remote Monitoring Services Under the 2027 PFS Proposed Rule: Epstein Becker Green Submits Comments to CMS