The Compliance Crucible: Navigating Intensified Enforcement in Telehealth, AI, and Multi-State Operations
By Shannon Smith, DNP, APRN, FNP-C, PMHNP-BC, PMHNP-C · 2026-03-06
The regulatory landscape for telehealth and digital health is rapidly evolving, marked by a significant uptick in enforcement actions from federal agencies and state boards. This digest unpacks critical trends in Stark Law scrutiny, controlled substance prescribing, AI oversight, and multi-state operational complexities, offering essential insights for healthcare leaders.
The healthcare industry is experiencing a seismic shift, driven by technological innovation and the rapid expansion of virtual care models. However, this progress is met with an equally rapid maturation of the regulatory environment. Federal agencies like the DOJ, DEA, OIG, and FDA, alongside state medical and pharmacy boards, are intensifying their scrutiny, transforming what was once a nascent regulatory space into a complex compliance crucible. For telehealth founders, practice owners, and compliance officers, understanding these converging enforcement priorities is no longer optional—it's foundational to sustainable growth.
> For more on this topic, see our analysis: [The Compliance Crucible: Navigating Intensified Scrutiny in Telehealth, Medspas, and Controlled Substance Prescribing](/blog/compliance-crucible-telehealth-medspa-controlled-substances).
This editorial digest synthesizes recent intelligence, identifying critical trends that demand immediate attention. We'll explore the heightened focus on financial relationships and prescribing practices, the emerging regulatory framework for AI, and the persistent challenges of multi-state compliance, offering actionable insights to safeguard your operations.
> For more on this topic, see our analysis: [The Compliance Crucible: Navigating Intensified Scrutiny in Telehealth, Medspas, and Controlled Substance Prescribing](/blog/compliance-crucible-telehealth-medspa-controlled-substances).
Trend 1: Intensified Scrutiny on Financial Relationships and Prescribing Practices
The Department of Justice (DOJ) and the Drug Enforcement Administration (DEA) are sending an unequivocal message: the convenience of telehealth does not exempt providers or entities from long-standing federal anti-fraud statutes or controlled substance regulations. This represents a significant pivot from earlier, more permissive environments.
Stark Law and Anti-Kickback Statute in the Digital Age
The DOJ's intensified Stark Law scrutiny on telehealth physician self-referral arrangements signals a critical re-evaluation of financial models in the digital health space. Historically, Stark Law enforcement primarily targeted traditional, in-person referral networks. However, the rapid expansion of telehealth has created new avenues for financial arrangements that could inadvertently or intentionally violate the law. Any arrangement where a physician (or their immediate family member) has a financial relationship with an entity providing Designated Health Services (DHS) and refers patients to that entity must fit squarely within a Stark Law exception. This includes services like laboratory testing, imaging, physical therapy, and durable medical equipment, all increasingly integrated into telehealth and ancillary service models.
For telehealth brands, medspas offering medical services, dental practices with ancillary services, and chiropractic offices referring for imaging, this means a thorough re-evaluation of all physician compensation models, joint ventures, and referral agreements. The DOJ's stance underscores that the intent behind the referral is less important than the existence of a prohibited financial relationship and a referral for DHS. Compliance programs must be updated to specifically address the unique structures of telehealth, including remote supervision, digital prescribing, and multi-state operations. Failure to comply can result in severe penalties, including civil monetary penalties, repayment of claims, and exclusion from federal healthcare programs.
Controlled Substances: The Post-PHE Enforcement Hammer
Compounding this financial scrutiny is the DEA's aggressive enforcement against telehealth companies for controlled substance violations. The expiration of the COVID-19 Public Health Emergency (PHE) waivers on May 11, 2023, dramatically reshaped the landscape for prescribing Schedule II-V controlled medications via telehealth. The Ryan Haight Act's in-person examination mandate is back in sharp focus, with the DEA actively pursuing enforcement actions against providers and companies misusing telehealth platforms to operate 'pill mills' and facilitate illegal prescription drug diversion.
For telehealth brands and primary care practices, this necessitates a renewed emphasis on establishing legitimate practitioner-patient relationships compliant with federal and state laws. This could involve integrating in-person clinic visits into care models, partnering with local providers for initial evaluations, or carefully adhering to any future finalized DEA rules that may expand telehealth flexibilities. Mental health and pain management specialties are particularly impacted, as these medications are frequently used in their fields. The message from the DEA is unambiguous: the convenience of telehealth does not exempt providers from stringent federal regulations governing controlled substances.
Medspas, dental practices, and chiropractic offices that may prescribe controlled substances for pain, anxiety, or other conditions incidental to their primary services must also be vigilant. Any controlled substance prescription, even for a short course, must be preceded by a compliant medical evaluation. Robust compliance programs, regular staff training, and clear documentation practices are essential to navigate this complex regulatory space effectively.
Trend 2: The Evolving Regulatory Landscape for AI in Healthcare
Artificial Intelligence (AI) and Machine Learning (ML) are rapidly integrating into clinical workflows, from diagnostic support to treatment planning. While promising immense benefits, the regulatory oversight for these technologies is quickly catching up, introducing new layers of complexity and risk.
FDA's Sharpening Focus on AI-Powered CDS Software
The FDA is actively refining its regulatory approach to AI- and ML-enabled Clinical Decision Support (CDS) software, particularly for tools that directly impact patient care decisions in telehealth. This evolving framework aims to balance innovation with patient safety, requiring careful evaluation of AI/ML software functionality and intended use. The key distinction often lies in whether the software provides a definitive diagnosis without substantial human clinician review or dictates a treatment protocol that could cause harm if incorrect.
For telehealth platforms, medspas using AI for skin analysis, dental practices employing AI for radiographic interpretation, and chiropractors using AI for posture analysis, this means scrutinizing any AI tools used for remote diagnosis, monitoring, or treatment planning. If an AI algorithm provides a definitive diagnosis or dictates a treatment protocol, it is more likely to be considered a regulated medical device, triggering stringent pre-market and post-market requirements. Conversely, tools that merely provide information for a clinician to consider are generally not regulated.
Navigating Liability and Practice Implications for AI
The integration of AI into CDS tools also introduces complex regulatory and liability considerations. The 'practice of medicine' implications mean that state medical boards will scrutinize how AI tools influence provider autonomy and responsibility. The liability for adverse outcomes stemming from AI recommendations ultimately rests with the supervising licensed professional. This includes understanding the data inputs, algorithmic biases, and limitations of the AI, and documenting the independent clinical review of AI-generated insights.
Across all specialties, data privacy and security are paramount. AI tools often process vast amounts of sensitive patient data, making adherence to HIPAA and state privacy laws critical. Providers must ensure that AI vendors have appropriate data security measures, Business Associate Agreements (BAAs) are in place, and that the use of AI does not inadvertently expose Protected Health Information (PHI). Failure to address these regulatory and liability concerns can lead to significant legal exposure, including malpractice claims, regulatory fines, and reputational damage.
Trend 3: The Persistent Patchwork of Multi-State Compliance
While federal agencies drive significant enforcement, state-level regulations remain a formidable challenge, particularly for businesses seeking to scale across state lines. The principle that medical licensure and the practice of medicine are regulated at the state level continues to create a complex, often contradictory, compliance environment.
Medical Practice Acts, Licensure, and Corporate Practice of Medicine
Navigating multi-state telehealth hormone optimization exemplifies the challenges concerning state-specific medical practice acts, physician licensure, and prescribing requirements. A provider must be licensed in every state where their patient is located at the time of service delivery. For hormone optimization, which often involves prescribing medications, including controlled substances like testosterone, the regulations become even more stringent. Telehealth platforms must implement robust systems to verify patient location and provider licensure, including geofencing technologies and clear patient intake protocols.
Furthermore, the Corporate Practice of Medicine (CPOM) doctrine, as highlighted by Nebraska's regulations, prohibits corporations from employing physicians or controlling medical practice in many states. This significantly impacts business structures for telehealth providers and medspas, often necessitating carefully crafted Management Services Organization (MSO) models. Under an MSO model, the professional entity (owned by licensed professionals) delivers clinical services, while the MSO provides administrative, non-clinical support. The key to compliance lies in ensuring the MSO does not exert control over clinical decision-making or physician employment.
Medspas leveraging telehealth for oversight across multiple states face complex and varied medical director requirements. Some states permit indirect supervision, while others mandate direct, on-site supervision. When telehealth is introduced for oversight, the definition of 'supervision' becomes even more nuanced. Medspas must ensure their medical director is licensed in every state where services are rendered and is actively engaged in the oversight of all delegated procedures.
State-Specific Prescribing and Pharmacy Board Regulations
Beyond medical boards, state pharmacy boards are also intensifying their oversight of telehealth-originated prescriptions. Missouri's Pharmacy Board Regulations and Vermont's Pharmacy Board Regulations underscore the need for telehealth providers to ensure prescriptions meet all state requirements for a valid prescription, particularly regarding the establishment of a proper patient-practitioner relationship. This extends to compounding standards, with states like Vermont adhering to USP <795> and <797> standards, requiring any pharmacy providing compounded medications to Vermont residents to demonstrate compliance.
For telehealth brands, medspas, dental practices, and chiropractic offices serving patients in specific states, understanding these nuances is critical. For example, Missouri law outlines specific requirements for establishing a valid provider-patient relationship via telehealth, which is a prerequisite for prescribing medications. Failure to establish a valid relationship can lead to severe consequences, including disciplinary action by the respective licensing board, fines, license suspension or revocation, and potential criminal charges.
What This Means For Your Practice: Actionable Implications
The current regulatory environment demands a proactive, comprehensive, and continuously adaptive compliance strategy. Here are key takeaways for healthcare businesses:
- Re-evaluate Financial Relationships: Conduct a thorough audit of all physician compensation models, joint ventures, and referral agreements, particularly those involving Designated Health Services (DHS). Ensure every arrangement fits squarely within a Stark Law or AKS exception. This includes scrutinizing any volume-based compensation or ownership stakes that could be construed as indirect compensation.
- Strengthen Controlled Substance Protocols: With the post-PHE enforcement hammer, revisit all protocols for prescribing controlled substances via telehealth. This means ensuring robust patient identity verification, comprehensive evaluations that meet federal Ryan Haight Act and state-specific requirements, and clear documentation. Consider integrating in-person components or partnerships for initial assessments if your model relies on controlled substance prescribing.
- Vet AI Tools Rigorously: For any AI/ML-enabled CDS software, understand its intended use and regulatory classification by the FDA. Implement robust internal policies for AI usage, including staff training on its limitations and documentation of independent clinical review. Prioritize vendors with clear regulatory status and strong data security measures (HIPAA, BAAs).
- Master Multi-State Compliance: A 'one-size-fits-all' approach is a recipe for disaster. For each state of operation, meticulously research and integrate specific requirements for licensure, scope of practice, supervision, CPOM, and pharmacy regulations. This may necessitate state-specific medical directors or tailored MSO structures. Invest in dynamic compliance protocols that adapt to these variations.
- Robust Compliance Programs are Non-Negotiable: The OIG's emphasis on comprehensive compliance programs for telehealth and digital health companies underscores that these are foundational. Implement the seven elements of an effective compliance program: written policies, designated personnel, training, auditing, monitoring, enforcement, and prompt response to detected offenses. Regular internal audits and a culture of compliance are your best defense.
- Stay Abreast of Payer Policies: For commercial and self-pay models, understand that telehealth billing and coding compliance is paramount. Payer-specific policies, proper CPT/HCPCS coding, and transparent financial practices are critical. State-specific telehealth parity laws also significantly impact reimbursement, requiring continuous monitoring of legislative changes and payer updates.
Looking Ahead
The regulatory landscape will continue to evolve, driven by technological advancements and ongoing efforts to combat fraud and ensure patient safety. The current environment is not just about avoiding penalties; it's about building a resilient, ethical, and sustainable healthcare enterprise. Proactive engagement with legal counsel specializing in healthcare regulatory compliance is no longer a luxury but a strategic imperative. By embracing a culture of continuous compliance, healthcare businesses can navigate this complex terrain, mitigate risks, and ultimately thrive in the digital health era.
Further Reading
- [The Compliance Crucible: Navigating Intensified Scrutiny in Telehealth, Medspas, and Controlled Substance Prescribing](/blog/compliance-crucible-telehealth-medspa-controlled-substances)
- [Navigating the New Regulatory Frontier: DEA Crackdowns, CPOM Scrutiny, and State-Specific Telehealth Compliance](/blog/navigating-new-regulatory-frontier-dea-cpom-telehealth-compliance)
- [Navigating the Regulatory Gauntlet: CPOM, Controlled Substances, and Telehealth's Evolving Landscape](/blog/regulatory-gauntlet-cpom-controlled-substances-telehealth)
- [Telehealth Tensions: Navigating DEA Scrutiny, CPOM Landmines, and State Board Enforcement in a Post-PHE World](/blog/telehealth-tensions-dea-cpom-state-board-enforcement)