Enforcement Crossroads: Navigating Telehealth Fraud Crackdowns and Evolving Compliance Mandates

2026-06-07

The second quarter of 2024 has brought a flurry of critical regulatory updates and aggressive enforcement actions shaping the healthcare landscape. From multi-billion-dollar telehealth fraud investigations to crucial HIPAA clarifications and extended DEA flexibilities, staying abreast of these changes is paramount for every practice.

The healthcare regulatory environment is in a perpetual state of flux, demanding acute vigilance from providers, operators, and investors alike. The period spanning late Q1 and early Q2 2024 has underscored this reality, presenting a landscape defined by intensified enforcement, critical regulatory adjustments, and evolving guidance. For telehealth platforms, brick-and-mortar practices expanding nationally, medspas, and specialized clinics, understanding these shifts is not merely advisable – it is essential for operational integrity and financial solvency. TrueEval is committed to dissecting these complex developments, offering clear, actionable insights to navigate the compliance challenges ahead.

> For more on this topic, see our analysis: [Regulatory Crossroads: Navigating Critical DEA and FDA Shifts in Healthcare Compliance](/blog/regulatory-crossroads-dea-fda-shifts-healthcare-compliance).

The Intensifying Enforcement Landscape: Billions in Fraud, Zero Tolerance

The Department of Justice (DOJ) and the Office of Inspector General (OIG) at the Department of Health and Human Services (HHS) continue to signal a zero-tolerance policy for healthcare fraud, particularly where it exploits emerging care delivery models. Telehealth, while a transformative force for access, has unfortunately become a significant conduit for sophisticated fraud schemes, drawing unprecedented scrutiny.

> For more on this topic, see our analysis: [Regulatory Crossroads: Navigating Critical DEA and FDA Shifts in Healthcare Compliance](/blog/regulatory-crossroads-dea-fda-shifts-healthcare-compliance).

The DOJ's Sweeping Telehealth Fraud Crackdown

May 2024 saw the DOJ announce one of its largest-ever national healthcare fraud enforcement actions. This concerted effort led to charges against over 100 individuals, including medical professionals and owners of telemedicine companies, for their alleged participation in healthcare fraud schemes totaling over $2.7 billion in false billings. The cases spanned across 32 federal districts and highlighted several recurring, troubling patterns:

  • Fraudulent Telehealth Prescriptions: A significant portion of the alleged fraud involved licensed medical professionals prescribing medically unnecessary durable medical equipment (DME), genetic tests, and controlled substances to patients they had never genuinely examined or with whom they had only brief, perfunctory virtual interactions. These interactions often lacked any legitimate clinical basis, driven instead by illicit patient recruitment and kickback schemes.
  • Durable Medical Equipment (DME) and Genetic Testing Schemes: Numerous defendants were implicated in schemes involving the submission of fraudulent claims for DME, such as braces and orthotics, and expensive genetic tests that were not medically indicated. These services were frequently marketed aggressively to beneficiaries, often through telemarketing or social media, with kickbacks paid to recruiters and prescribing providers.
  • Controlled Substances: The enforcement actions reiterated the DOJ's focus on the illicit distribution of controlled substances, where telemedicine was used to facilitate prescriptions without a legitimate doctor-patient relationship, contributing to the opioid crisis.

Implication: This crackdown is a stark reminder that the government views telehealth not as an enforcement exception, but as an area of heightened risk and priority. Providers and platforms engaged in telehealth must ensure robust clinical protocols, genuine patient-provider relationships, and rigorous anti-kickback compliance. Any arrangement where patient interactions are expedited or where remuneration is tied to the volume or value of referrals or prescriptions will be heavily scrutinized.

OCR's Continued HIPAA Enforcement: Montefiore's $4.75 Million Settlement

Beyond fraud, data security remains a paramount concern. In April 2024, the HHS Office for Civil Rights (OCR) announced a $4.75 million settlement with Montefiore Medical Center for alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) Rules. The settlement stemmed from a breach where an employee stole the protected health information (PHI) of 12,517 patients and subsequently sold it.

Key Takeaways from the Montefiore Settlement:

  • Insider Threat Mitigation: This case underscores the critical importance of protecting against insider threats. While external cyberattacks grab headlines, internal breaches, often driven by malicious intent or negligence, can be equally devastating.
  • Robust Access Controls: OCR found that Montefiore failed to implement sufficient technical and non-technical safeguards to prevent unauthorized access to PHI. This includes inadequate auditing of user activity and insufficient controls over employee access to patient records.
  • Timely Response and Breach Notification: While not the primary focus of the penalty, an effective incident response plan and timely, accurate breach notification are non-negotiable elements of HIPAA compliance.

Implication: Healthcare organizations must invest in comprehensive HIPAA security measures, including strong access controls, regular audit log reviews, workforce training on PHI protection, and robust insider threat programs. The cost of non-compliance, both financial and reputational, continues to rise.

Regulatory Shifts: Adapting to Evolving Frameworks

As enforcement heats up, the regulatory landscape itself continues to evolve, necessitating constant adaptation from healthcare businesses.

DEA's Critical Extension for Telehealth Prescribing of Controlled Substances

One of the most significant and anticipated updates came from the Drug Enforcement Administration (DEA). In May 2024, the DEA issued a Second Temporary Rule for the Extension of Certain COVID-19-Related Flexibilities for Telemedicine Prescribing of Controlled Medications (89 FR 38656, May 7, 2024). This rule **extended *all* pandemic-era telehealth flexibilities for prescribing controlled substances until December 31, 2024**.

What This Means:

  • Continued Flexibility (for now): Providers can continue to prescribe Schedule II-V controlled substances via telehealth without an initial in-person medical evaluation, provided certain conditions are met (e.g., the prescription is issued pursuant to a legitimate medical purpose by a practitioner acting in the usual course of professional practice).
  • Transition Period: This extension provides a crucial, albeit temporary, reprieve, allowing patients to continue receiving care and giving providers more time to prepare for the eventual implementation of permanent rules. The DEA acknowledged the need for further public comment and evaluation before finalizing a long-term framework.
  • Uncertainty Remains: Despite the extension, the long-term future of telehealth prescribing for controlled substances remains uncertain. The DEA is still grappling with how to balance patient access, provider convenience, and public safety concerns, particularly regarding the diversion of controlled medications. The expectation is that permanent rules will likely require an in-person visit for Schedule II and III controlled substances after an initial period, or leverage a federal special registration process for telehealth practitioners.

Implication: Telehealth operators, particularly those involved in mental health, pain management, or addiction treatment, must use this extension wisely. Develop clear transition plans, explore potential partnerships for in-person evaluations, and stay acutely informed of the DEA's ongoing rulemaking process. The regulatory certainty for this crucial aspect of telehealth will likely not extend beyond year-end 2024 without a concrete permanent rule.

CMS Medicare Physician Fee Schedule (MPFS) Final Rule for CY 2024

While published in November 2023, the CMS MPFS Final Rule for Calendar Year 2024 continues to shape telehealth payment and service delivery. Key aspects for 2024 include:

  • Extension of Telehealth Services: Many of the telehealth services added to the Medicare telehealth services list on a temporary basis during the public health emergency (PHE) were extended through December 31, 2024. This provides continued payment for a broad range of virtual services.
  • Audio-Only Telehealth: Certain audio-only telehealth services continue to be paid, though the long-term future of expansive audio-only coverage remains a subject of debate.
  • Direct Supervision via Real-Time Audio/Video: CMS continued the policy allowing direct supervision to be provided virtually using real-time audio/video technology through the end of 2024. This is highly relevant for practices employing physician assistants (PAs), nurse practitioners (NPs), or other clinical staff requiring supervision.
  • Rural Health Clinics (RHCs) and Federally Qualified Health Centers (FQHCs): These entities can continue to be paid for distant site telehealth services. However, the rule maintained the 15% site-of-service differential, meaning that RHCs/FQHCs will continue to receive a reduced payment for services furnished in a facility setting compared to non-facility settings, impacting their telehealth reimbursement strategies.

Implication: While the extensions provide welcome stability, many telehealth flexibilities remain temporary. Practices should factor the potential sunsetting of these provisions into their long-term business models and be prepared for potential changes in payment parity and eligible services beyond 2024. Strategic planning around these temporary provisions is critical.

Heightened Scrutiny on the Corporate Practice of Medicine (CPOM)

While not a new regulation, the enforcement of Corporate Practice of Medicine (CPOM) doctrines has seen a noticeable uptick in select states, influenced by the proliferation of private equity investment in healthcare. States like Texas, California, New York, and Ohio maintain strict CPOM prohibitions, preventing non-physician entities from employing physicians or controlling medical decision-making. Recent actions by state medical boards and attorney generals suggest a renewed focus on ensuring genuine physician control over clinical operations.

Implication: For multi-state operators, especially medspas, management services organizations (MSOs), and telehealth companies, a meticulously structured MSO model is paramount. Ensure that physician groups maintain independent clinical judgment, that management service agreements (MSAs) are fair market value, and that no entity exerts undue influence over patient care decisions. The line between legitimate management support and unlawful control is often thin and jurisdiction-dependent.

Emerging Guidance: Navigating New Ethical and Legal Frontiers

Regulators are also issuing guidance to address new challenges, particularly at the intersection of technology, data privacy, and evolving societal values.

OCR Guidance on HIPAA and Reproductive Health Information

In April 2024, OCR issued critical guidance clarifying how HIPAA protects individuals' reproductive healthcare information, especially in states with abortion bans or restrictions. This guidance reinforces that:

  • HIPAA Safeguards Against Disclosure: HIPAA generally prohibits covered entities and business associates from disclosing protected health information (PHI), including reproductive health information, for the purpose of criminal, civil, or administrative investigations or proceedings against individuals for seeking, obtaining, providing, or facilitating lawful reproductive healthcare.
  • Patient Requests for Restrictions: Patients have the right to request restrictions on the disclosure of their PHI, which covered entities *must* agree to if the disclosure is for payment or healthcare operations and the patient has paid out-of-pocket in full for the service.
  • State Law Preemption: The guidance clarifies that HIPAA generally preempts state laws that are contrary to HIPAA and less protective of privacy, although exceptions exist for public health activities or law enforcement requirements that meet specific criteria.

Implication: This guidance is vital for any healthcare provider, particularly those operating across state lines, where legal interpretations of reproductive health services vary significantly. Organizations must review their privacy policies, consent forms, and data-sharing agreements to ensure alignment with this guidance, especially regarding responses to law enforcement requests. The ethical and legal obligation to protect patient privacy has gained a new dimension.

OIG's 2024 Work Plan: A Roadmap for Future Scrutiny

While released in October 2023, the OIG's 2024 Work Plan continues to serve as a critical roadmap, highlighting areas of focus for audits, evaluations, and investigations. Key areas of ongoing interest include:

  • Telehealth Services: Continued oversight of telehealth to identify fraud, waste, and abuse, particularly concerning medical necessity and proper billing.
  • Medical Necessity of Services: Scrutiny of genetic testing, durable medical equipment, and other high-cost services where medical necessity may be questionable.
  • Opioid Treatment Programs (OTPs): Ensuring compliance with regulations and appropriate care delivery.
  • Medicare Advantage (MA) Risk Adjustment: Audits to identify inflated risk scores, which can lead to overpayments to MA plans.

Implication: The OIG Work Plan provides a preview of where enforcement agencies will dedicate resources. Providers in these targeted areas should proactively review their compliance programs, billing practices, and documentation to mitigate risks. A strong internal audit function is your best defense.

What This Means For Your Practice

The current regulatory environment demands a proactive, sophisticated approach to compliance, particularly for dynamic sectors like telehealth, medspas, and multi-state clinical practices.

1. Reinforce Telehealth Compliance Frameworks: The DOJ's actions highlight that telehealth is a high-risk area. Review patient intake, consent processes, provider credentialing, and clinical protocols. Ensure legitimate patient-provider relationships are established and maintained. Scrutinize all marketing and patient recruitment practices for potential Anti-Kickback Statute (AKS) violations. 2. Audit Data Security and Privacy: The Montefiore settlement underscores the importance of HIPAA Security Rule compliance. Conduct regular risk assessments, implement robust access controls, monitor user activity, and enhance insider threat detection programs. Review privacy policies in light of the new OCR guidance on reproductive health information. 3. Prepare for Post-PHE Telehealth Realities: Leverage the DEA's extension wisely to strategize for future changes to controlled substance prescribing. For other telehealth services, understand which flexibilities are permanent and which are temporary, and build business models that can adapt to potential rollbacks in 2025 and beyond. 4. Shore Up CPOM Compliance: For practices operating with MSOs or across multiple states, ensure your corporate structure and contractual agreements rigorously comply with state-specific CPOM doctrines. Seek expert legal counsel to ensure physician independence in clinical decision-making. 5. Proactive Internal Monitoring: Utilize the OIG Work Plan as a guide. Conduct internal audits in areas identified as priorities to identify and rectify compliance gaps before external auditors or investigators do.

The regulatory landscape is not merely a set of rules; it is a dynamic ecosystem that influences every aspect of healthcare operations. TrueEval remains dedicated to providing the definitive insights necessary to navigate these complexities, ensuring your practice remains compliant, resilient, and forward-thinking.


Further Reading

  • [Regulatory Crossroads: Navigating Critical DEA and FDA Shifts in Healthcare Compliance](/blog/regulatory-crossroads-dea-fda-shifts-healthcare-compliance)
  • [Navigating the New Regulatory Gauntlet: CPOM, Telehealth Prescribing, and DOJ Scrutiny in 2024](/blog/regulatory-gauntlet-cpom-telehealth-doj-2024)
  • [Navigating the Regulatory Gauntlet: CPOM, Telehealth Prescribing, and Enforcement in 2024](/blog/regulatory-gauntlet-cpom-telehealth-prescribing-2024)
  • [Navigating the Tar Heel State: North Carolina's Evolving Healthcare Compliance Landscape for Expanding Practices](/blog/north-carolina-healthcare-compliance-roadmap-mq3sun9s)