When a provider or supplier of services bills the Medicare program and receives payment, but at a later date the program audits the claim and denies it, can the provider or supplier be relieved of any financial liability if it had a good faith belief that the service met all relevant coverage requirements, even when that belief is incorrect? In a recent decision, the U.S. Court of Appeals for the Sixth Circuit ruled that this relief is possible, and that administrative adjudicators must conduct an analysis under the “hold harmless” provision of the Social Security Act (the “Act”).[1]
[1] In Home Health, LLC v. Kennedy, 2026 WL 2147418 (6th Cir., July 27, 2026); also available at: https://www.opn.ca6.uscourts.gov/opinions.pdf/26a0205p-06.pdf.
On January 5, 2020, HR 7898, became law amending the Health Information Technology for Economic and Clinical Health Act (HITECH Act), 42 U.S.C. 17931, to require that “recognized cybersecurity practices” be considered by the Secretary of Health and Human Services (HHS) in determining any Health Insurance Portability and Accountability Act (HIPAA) fines, audit results or mitigation remedies. The new law provides a strong incentive to covered entities and business associates to adopt “recognized cybersecurity practices” and risk reduction frameworks when complying ...
Recent Updates
- The Largest Sunshine Act Penalty in History - Pharmaceutical Company Settles False Claims Act, Anti-Kickback Statute and Sunshine Act Allegations
- FTC Reverses Course on Health App Privacy
- The Battle Continues: No Appointments Clause Problem, BUT Eleventh Circuit Directs District Court to Consider Whether False Claims Act Qui Tam Provisions Violate Take Care, Vesting Clauses
- Bill Gates Gazes into the AI Crystal Ball: What are the Implications on the Healthcare and Life Sciences Industry
- 250+ Health Care Entities Targeted by HHS, DOJ Over Gender-Affirming Care for Minors