Is Your Healthcare Platform Too Small to Need a Compliance Program?

No healthcare company is too small to need a compliance program. CMS and the OIG use billing data to spot patterns across organizations of every size, and a single complaint can turn a small practice into a federal case. Building a program always costs less than fixing the problem you ignored.

The number one thing we hear is "we're too small." Too small to be noticed. Too small to need a program. We don't do enough business for anyone to care.

We get why it feels true. When you are heads-down building something, the government feels far away. But CMS and the OIG do a lot of work with utilization data. They see the trends in billing and coding, and that data is how they pick who to audit and who to investigate. Size is not what gets you on the list. The numbers are.

And it only takes one person. One employee who gets upset, believes you are doing something wrong, and decides to do something about it. We have watched small practices and small businesses get pursued for $100,000 to $200,000 because someone made it a big deal. At that point, you are not too small anymore.

What does "too small to need compliance" actually cost?

It costs far more than the program would have. The moment a complaint or a billing pattern draws attention, you are no longer building a program. You are managing a problem, and the price of that is much higher.

CMS and the OIG run their audits and investigations off utilization data, which means they are watching trends, not company size. A small physician group with an unusual billing pattern is just as visible as a large one. When someone decides you are doing something wrong, the path they take is the False Claims Act, and it is a profitable one. A whistleblower receives a share of whatever the government recovers, and in fiscal year 2024 the government paid whistleblowers more than $400 million. There are entire law firms that do nothing but support these cases. That is the engine behind the numbers.

The numbers are real. In fiscal year 2024, the Department of Justice recovered more than $1.67 billion from healthcare False Claims Act cases, and whistleblowers filed 979 cases, the highest number in a single year. Settlements run from $1 million into the tens of millions. We have seen one approach a billion dollars. None of that requires you to be big. It requires you to be exposed.

Why does waiting until something happens cost more?

Because once it happens, you cannot unring the bell. Waiting means you build your program in the middle of a civil investigative demand, a prepayment review, or an OIG referral. That is the most expensive moment to start, and the work no longer prevents anything. It only cleans up.

This is the second mistake we see over and over. The thinking goes: we don't need a program until something goes wrong. By the time something goes wrong, you are dealing with audits, demands for records, and reviews that hold your payments. You are not building a compliance program at that point. You are managing compliance problems that are already piling up, and doing both at once.

We tell founders it is like building the plane and flying it at the same time. You want to build the plane, test it, then fly it. The order matters because retrofitting a program under pressure costs more in time and money than building it calmly when no one is knocking on your door.

Can you hand compliance to your billing company?

No. The government follows the money, and the money landed with you. Your billing company processes claims, but the practice or physician who received the Medicare and Medicaid payments under that NPI is the one responsible for compliance. A contract cannot move that obligation off your shoulders.

This is one of the most dangerous assumptions in healthcare. A lot of companies bill 85 to 90 percent Medicare and assume their billing company has compliance covered. When we ask what they are doing to test that, the answer is usually nothing. They have coders and billers who "know what they're doing," and no one is checking the work.

When you enrolled in Medicare and Medicaid, you made a commitment to the federal government that you would not submit anything improper, knowingly or unknowingly. Your billing company did not sign that. You did. So you have to be testing, monitoring, and watching what flows through the revenue cycle. Your indemnification clause may cover something the billing company got wrong, but you are still on the hook, because the oversight was yours to provide. When the government comes knocking, they come to your door.

That is why testing your billing and coding belongs at the top of the list. Understanding how a CPT code is built from the provider's documentation, and whether that documentation supports the payment, is the hard part. Dropping a code on a CMS 1500 is easy. Proving it was right is the work.

What goes wrong after you finally have a program?

The quiet failures happen after the program exists, because people skip the parts that feel optional. Three habits cause most of the damage: weak documentation, ignored complaints, and leaving compliance out of the room where strategy gets decided.

Documentation first. People don't write things down because they figure they will remember, or they handled it and moved on. Every compliance issue comes back around. Someone asks about it, and at some point you have to show that you fixed it. You will not remember. As we tell everyone in compliance, the day you win the lottery, you're out, and somebody has to come in behind you, understand what you did, and repeat it. That only works if it is written down.

Second, ignoring employee concerns. Investigating every matter raised, all the way to a conclusion, is one of the seven elements of a compliance program. Waving off a concern as "not a big deal" is the fastest way to create a whistleblower. The moment someone believes you are not listening, whether the issue is coding, billing, Stark, or kickbacks, they have a federal path that pays. The 979 cases filed in 2024 did not start with strangers. They started with people inside the building who felt unheard.

Third, keeping compliance out of strategy and business development. Compliance should be sitting beside you, flagging the red flags early and helping you get where you want to go in a legal, regulatory way. If your compliance person is only there to say no, you have the wrong person. The mistake is leaving them out of the conversation entirely.

What do you actually gain when you build it right?

You gain the freedom to run the business. With a real program, a serious issue becomes a managed matter instead of a full-scale emergency. The team handles it, mitigates it, and discloses or refunds as needed, while leadership keeps building. That is the compliance advantage.

Start with your profits. The revenue you earned lawfully is revenue you get to keep. A working program means not giving money back, not paying fines, not watching your margins take a hit. Then partnerships. Payers and hospitals want to do business with organizations that monitor their billing and operate ethically, and that can mean better rates and better contracts. Then your people, who are prouder to work somewhere with a culture of trust, which shows up in retention. And finally patient trust, which keeps you in business when patients are reading headlines about who got investigated.

The day-to-day difference is the one executives feel most. Without a program, a significant issue shuts everything down and everyone stops to deal with it. With a program, the answer is "we're going to handle it," and the executives get to focus on growth. We sat down with a client's executive recently, and the whole conversation was about strategy, because he knew the compliance side was covered. That is what lets a company scale, the ability to look ahead because someone is watching the road behind you. The OIG's 2023 General Compliance Program Guidance is built around exactly this idea, that an effective program prevents, detects, and corrects, rather than reacting after the fact.

When does this apply, and how do you start?

It applies the moment you are billing federal payers, and the start is simpler than most founders fear. You do not need perfection or a huge budget. You need a foundation, built early, and a few commitments you do not walk back.

Treat compliance as a foundation, not an afterthought. It does not have to be the very first thing, but it has to come shortly after, because the longer you wait the more it costs. Find advisors who understand both healthcare operations and compliance, because one without the other leaves a gap. Put the cost in your budget as a standing line item, set it, and don't cut it. And do not cut corners. There is an efficient way and a cost-effective way to do compliance, but there is no cheap way. Buying a set of policies and putting them on a shelf is not a program.

There is one more reason this matters for anyone building a platform. You may want to sell it someday. A clean compliance story is an asset a buyer pays for, and the gaps you left behind are the ones a diligence team will find and price against you. Protecting that investment is what a program does, financially and otherwise.

The mistakes here show up over and over, and so does the payoff when founders get it right early. For the practical build, start with the seven elements of a compliance program.

Frequently Asked Questions

Are we too small to need a compliance program? No. CMS and the OIG use utilization data to spot billing and coding patterns across companies of every size, so size does not keep you off their radar. A single complaint from one employee can turn a small practice into a federal case, and the cost of responding always exceeds the cost of a program.

Isn't our billing company handling compliance for us? Your billing company processes claims, but the practice or physician who received the federal payments under that NPI carries the compliance obligation. A contract may include indemnification, but the government follows the money to whoever was paid. You signed the enrollment commitment, so the oversight is yours.

What is the biggest billing mistake healthcare companies make? Assuming the coding is correct without ever testing it. Many companies bill mostly Medicare, lead with HIPAA when asked about risk, and never check whether their documentation supports the codes they submit. False Claims Act exposure, not privacy, is the larger financial risk for most billing-heavy organizations.

How does one upset employee become a federal case? Through the False Claims Act's whistleblower path. An employee who believes a concern was ignored can file a qui tam case and receive a share of whatever the government recovers, and law firms exist solely to support them. In 2024, whistleblowers filed 979 of these cases, a single-year record, and the government paid them more than $400 million.

What does a compliance program actually protect? It protects the profits you earned lawfully, the payer and hospital partnerships that prefer ethical operators, the trust of employees and patients, and the value of the business itself. When a serious issue surfaces, a program turns it into a managed matter instead of an emergency that stops the whole company.

When should a new healthcare company build its compliance program? Shortly after launch, not as an afterthought. Building it early is far cheaper than retrofitting one during an investigation, when you are managing problems and building the program at the same time. Budget for it as a standing line item and do not cut it.

Ross Ronan, JD, BSN, CPCO, CHC, CCEP, CMPE

Ross Ronan is the founder of Ronan Healthcare Compliance, host of “The Compliance Advantage” podcast which ranks in the top 10% globally, a seasoned board member, and a healthcare compliance strategist with nearly 30 years of industry experience. 

He has supported hundreds of healthcare industry leaders from companies like Envision Healthcare, Amulet Capital Partners, and Enhanced Healthcare Partners while engaging with entities, including McDermott Will & Schulte (MWS) and the U.S. Office of Inspector General (HHS-OIG), to promote ethical leadership and ensure operational integrity. 

Ross is a sought-after speaker at prestigious forums, like the University of Pennsylvania's law program, the Health Care Compliance Association (HCCA), the American Health Law Association (AHLA), and private equity conferences such as MWS’ HPE Miami, where he addresses the critical intersection of compliance and business strategy. 

With degrees in nursing and law and memberships in organizations like the American College of Healthcare Executives (ACHE) and the Healthcare Private Equity Roundtable, he is widely regarded by private equity partners, board members, CEOs, general counsels, and compliance officers. Ross can help operationalize compliance to eliminate ambiguity, reduce liability risks, and transform compliance into a strategic advantage. 

Next
Next

How a Compliance Program Raises Your Valuation (with Jerry Chang)