This monthly update highlights key regulatory developments, enforcement trends, and
compliance issues affecting health care providers across the continuum – from solo practices to hospitals and large physician groups. Each section includes practical action items to help you assess risk and prepare for upcoming obligations.
Regulatory Developments
Iowa HF 2635 Brings Significant Changes to Prior Authorization Requirements
Effective July 1, 2026, Iowa House File 2635 implements several reforms affecting health carriers, utilization review organizations, and healthcare providers. Among the most significant changes, health insurers are prohibited from requiring prior authorization for medically recommended cancer screenings and emergency medical services. These reforms are intended to reduce administrative barriers to timely care and improve patient access to preventive and emergency services.
HF 2635 also establishes new standards governing the use of artificial intelligence (AI) in utilization review. While health carriers may use AI-assisted tools during the prior authorization process, AI may not serve as the sole basis for denying, delaying, or downgrading a request involving medical necessity. Human clinical judgment must remain part of any adverse determination.
As implementation approaches, providers should review their prior authorization processes and monitor communications from commercial payers regarding revised authorization requirements and implementation procedures.
Action Items
- Continue documenting medical necessity, even when prior authorization is no longer required.
- Educate clinical, scheduling, and revenue cycle staff regarding services that no longer require prior authorization under Iowa law.
- Monitor communications from commercial payers regarding updated prior authorization policies and implementation guidance.
- Update internal policies and patient communication materials, as appropriate.
Contracting Focus
OIG Requests Public Input on Anti-Kickback Safe Harbor Regulations
On June 22, 2026, the Office of Inspector General (OIG) issued a Request for Information seeking public input on whether modifications to the Federal Anti-Kickback Statute safe harbor regulations or beneficiary inducement exceptions are warranted, particularly in connection with remuneration provided to individuals participating in clinical trials.
Although the request focuses on clinical trial participation, it reflects the OIG’s continued evaluation of whether existing fraud and abuse regulations appropriately accommodate evolving healthcare delivery models. Organizations entering into physician arrangements, vendor relationships, care coordination initiatives, or patient engagement programs should continue to ensure those arrangements are carefully structured to comply with applicable fraud and abuse laws.
Organizations with an interest in these issues – including health systems, academic medical centers, clinical trial sponsors, and industry stakeholders may wish to consider submitting comments to the OIG during the public comment period. Participation in the rulemaking process provides an opportunity to help shape future regulatory guidance and safe harbor protections.
Action Items
- Review physician compensation and referral arrangements for continued compliance.
- Evaluate vendor and care coordination agreements for Anti-Kickback Statute implications.
- Consider whether your organization or industry association should submit comments to the OIG.
- Consult legal counsel before implementing new financial incentive or patient engagement programs.
Compliance Focus
National Health Care Fraud Takedown Highlights Continued Enforcement Priorities
On June 23, 2026, the U.S. Department of Justice and the U.S. Department of Health and Human Services announced the results of the 2026 National Health Care Fraud Takedown, charging 455 defendants in connection with more than $6.5 billion in alleged fraudulent schemes. The cases involved allegations of false claims, medically unnecessary services, kickbacks, telemedicine fraud, laboratory testing, durable medical equipment, wound care products, community mental health services, and other fraudulent billing practices.
While most providers maintain robust compliance programs, the enforcement action serves as a reminder that federal agencies continue to rely heavily on data analytics, coordinated investigations, and interagency cooperation to identify potential fraud. Organizations should continue emphasizing accurate documentation, medical necessity, billing integrity, and effective compliance oversight.
Action Items
- Review internal auditing and monitoring activities.
- Reinforce documentation and medical necessity requirements with providers and staff.
- Encourage workforce reporting through established compliance reporting mechanisms.
Litigation and Risk Management Trends
Enforcement Continues to Emphasize Documentation and Oversight
Recent federal enforcement actions continue to demonstrate that inadequate documentation, insufficient oversight, and weak internal controls frequently serve as the foundation for False Claims Act investigations and other enforcement actions. Even where allegations involve intentional misconduct, regulators routinely examine the effectiveness of an organization’s compliance program, auditing practices, and leadership oversight.
Healthcare organizations should periodically assess whether existing compliance programs are effectively identifying and addressing operational risks before they become enforcement issues.
Action Items
- Conduct periodic compliance risk assessments.
- Review documentation standards in high-risk service lines.
- Evaluate internal reporting and corrective action processes.
- Assess whether compliance committee reporting adequately addresses emerging risks.
FAQ of the Month
We Received a Commercial Payer Audit or Request for Records. What Should We Do?
Do not assume an audit or records request is routine or that every requested record should simply be produced without review. Commercial payer audits can result in claim denials, recoupment demands, extrapolated overpayment findings, or allegations that documentation does not support the services billed.
Organizations should promptly identify the scope of the request, preserve all responsive records, verify applicable response deadlines, and carefully review the medical record for completeness before submission. It is also important to understand the payer’s contractual audit rights, applicable provider manual provisions, and available appeal rights before responding.
A thoughtful, coordinated response can often improve the outcome of an audit and better position the organization should an appeal become necessary.
Upcoming Deadlines & Reminders
- Iowa HF 2635 Effective Date: July 1, 2026.
- HIPAA Claims Attachment Standards – Compliance Deadline: May 26, 2028.
- Section 504 Accessibility Compliance Deadlines: Covered entities with 15 or moreemployees must comply with applicable web and mobile accessibility requirements by May 11, 2027. Covered entities with fewer than 15 employees have until May 10, 2028 to comply.
- Monthly OIG Exclusion Screening: Continue monthly screening of employees, contractors, and vendors against the OIG List of Excluded Individuals and Entities (LEIE).
- Medicare Revalidation: Monitor CMS notices and applicable enrollment revalidation deadlines.
Disclaimer
The information provided in this publication is for general informational purposes only and does not constitute legal advice. No attorney-client relationship is created by this publication. Because the application of these legal developments depends on the specific facts and circumstances of each situation, organizations should consult legal counsel regarding questions or implementation decisions.
For questions about these developments or assistance with healthcare regulatory, compliance, contracting, or reimbursement matters, please contact Paul A. Drey or Emily E. Reiners of the Brick Gentry P.C. Healthcare & Regulatory Team.
