Healthcare organizations are operating in an environment where compliance expectations are becoming increasingly technical, data-driven, and difficult to monitor manually. Between staffing shortages, evolving telehealth rules, payer scrutiny, and pressure to maintain productivity, many leaders are concerned about whether their documentation and billing workflows can withstand an audit. Increasingly, the risk is not tied to intentional fraud—it is tied to small operational inconsistencies repeated across hundreds or thousands of claims.
Recent activity from the U.S. Department of Health and Human Services (HHS) and its Office of Inspector General (OIG) reinforces that reality. Over the past several weeks, enforcement efforts have focused less on broad warnings and more on specific billing behaviors, documentation gaps, and utilization patterns that suggest technical noncompliance.
One of the clearest examples is a newly released OIG audit examining Medicare payments for virtual check-ins and e-visits. The audit identified approximately $2.3 million in potential improper payments, largely related to communication-based services billed too close to other evaluation and management (E/M) encounters or duplicate e-visits for the same diagnosis. In many cases, services lacked sufficient distinction from separately billable visits or failed to meet timing requirements.
Importantly, the OIG did not point only to provider error. The report also highlighted gaps in CMS system edits and insufficient provider education as contributing factors. That distinction matters because it signals that regulators are evaluating not only claims outcomes, but also the effectiveness of organizational compliance processes and internal education efforts.
At the same time, enforcement actions continue to demonstrate a coordinated and increasingly aggressive approach to healthcare fraud oversight. Recent federal cases involved false claims, kickback arrangements, controlled substance diversion, and multimillion-dollar billing schemes. The expansion of the West Coast Health Care Fraud Strike Force further illustrates the government’s continued investment in targeted, regional enforcement initiatives.
For healthcare organizations, the takeaway is practical: compliance risk increasingly lives in the details. Virtual care services, modifier usage, time-based billing, and documentation specificity all require consistent operational oversight. Regulators are also analyzing broader utilization trends, meaning unusual billing patterns may trigger scrutiny even when individual claims appear defensible on their own.
This is why proactive auditing, focused provider education, and operational reviews remain critical. Organizations that regularly evaluate documentation practices, billing logic, and workflow consistency are better positioned to identify risk areas before they become repayment demands or enforcement concerns.
At BCA, Inc., our team works with healthcare organizations to bridge the gap between regulatory expectations and day-to-day operational realities. Through targeted audits, provider education, and compliance consulting services, we help organizations identify vulnerabilities, strengthen documentation practices, and build practical strategies that support both compliance and sustainable operations.
Schedule a consultation with one of our experts.