Compliance in Healthcare
Corporate Compliance

Understanding Whistleblower Protections in Healthcare

Legal Obligations and Compliance Implications  


Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

The government’s new whistleblower complaint portal launched in April 2025 emphasizes the importance of complying with regulations related to qui tam suits, OCR investigations and protecting the rights of employees submitting a tip or complaint internally or to authorities. This article illustrates how certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation.

Introduction

Healthcare compliance professionals are often the first line of defense when systems break down. Understanding the interplay between legal protections and organizational ethics is vital—not only to ensure legal compliance, but also to foster environments where staff feel empowered and safe to report misconduct.

Whistleblowers are critical to protecting the integrity of healthcare delivery. When individuals report unsafe care, fraudulent billing, privacy violations, or ethical concerns, they help ensure accountability, uphold regulatory compliance, and safeguard patient welfare. For compliance professionals—particularly those working in environments regulated by Medicare, Medicaid, HIPAA, and federal contracts—it is essential to understand the scope and implications of whistleblower protections under current U.S. law.

This article explores the legal framework that underpins whistleblower protections, including the False Claims Act (FCA), HIPAA Privacy Rule exceptions, and National Defense Authorization Act (NDAA) provisions. It also highlights recent federal developments and compliance best practices to foster a culture of transparency and non-retaliation.

The False Claims Act and Qui Tam Provisions

For compliance departments, the implications of Qui Tam lawsuits extend far beyond financial penalties. They can lead to reputational harm, loss of patient trust, and stricter regulatory scrutiny. Therefore, proactive compliance programs must include regular audits, anonymous reporting options, and a culture that encourages early identification of potential violations.

The False Claims Act (31 U.S.C. §§ 3729–3733) is the federal government’s primary tool for combating fraud against public programs. Healthcare fraud accounts for a significant portion of FCA activity. Under its Qui Tam provision, private citizens—known as “relators”—can file lawsuits on behalf of the government when they have direct knowledge of fraudulent activities, such as billing for services not rendered or providing substandard care reimbursed by federal programs.

When the Department of Justice (DOJ) intervenes in these cases, whistleblowers may receive 15%–30% of recovered funds as a reward. In 2023 alone, the DOJ recovered over $1.8 billion from healthcare-related FCA cases, with whistleblower suits representing the vast majority of those recoveries.

Importantly, the FCA also prohibits retaliation. Section 3730(h) protects whistleblowers from termination, demotion, suspension, or harassment due to lawful acts in furtherance of a Qui Tam action or efforts to stop violations of the FCA.

HIPAA and Whistleblower Disclosures

Healthcare entities must train their workforce on the specific conditions under which PHI disclosures are permissible. Internal policies should not only comply with HIPAA but clarify what constitutes a 'good faith belief' and ensure disclosures are directed to appropriate oversight entities.

While the Health Insurance Portability and Accountability Act (HIPAA) is typically associated with patient privacy, it also contains important exceptions that protect whistleblowers. Under 45 CFR § 164.502(j), a workforce member may disclose protected health information (PHI) if:

  1. They believe in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates clinical standards; and
  2. The disclosure is made to a healthcare oversight agency, public health authority, law enforcement agency, attorney, or accreditation organization.

This clause is critical for compliance officers to understand, especially when investigating disclosures involving PHI. Any internal policy must clearly explain the scope of permissible disclosures and educate staff on when HIPAA permits these exceptions.

NDAA Protections and the Role of Contractors

The National Defense Authorization Act (NDAA) of 2013 (41 U.S.C. § 4712) expanded whistleblower protections to employees of federal contractors, grantees, and subcontractors, which includes many healthcare providers receiving federal funds. Under this statute, employees are protected from reprisal for reporting gross mismanagement, fraud, abuse of authority, or dangers to public health and safety.

Notably, these protections apply even if the employee discloses information outside of the organization, including to Congress, an Inspector General, or a federal employee responsible for contract oversight.

Compliance officers working with contractors should incorporate NDAA requirements into onboarding and ethics training materials. Additionally, contract language should affirm non-retaliation protections and clarify processes for raising concerns externally.

Recent Developments: HHS Whistleblower Portal and Enforcement

On April 14, 2025, the U.S. Department of Health and Human Services (HHS) launched a new whistleblower complaint portal specifically designed to receive reports of potential harm to children, including medically controversial treatments involving minors.

This new government portal signals increased federal oversight in how healthcare institutions respond to ethical and religious concerns raised by employees and demonstrates the government’s increased commitment to ensuring that providers and institutions uphold safety, informed consent, and respect for medical ethics.

This tool may also be used to identify systemic gaps in institutional policies around consent, safety, and staff protections.

In a notable case publicized by HHS, a hospital faced sanctions for terminating a nurse who refused to participate in a pediatric procedure due to her religious beliefs. HHS concluded that the hospital violated federal conscience protections, highlighting the intersection of whistleblower law, employment rights, and provider conscience protections.

Such scenarios highlight the importance of thorough documentation and timely response by compliance departments. Independent reviews of whistleblower complaints, performed by third-party investigators or ombudspersons, can enhance transparency and fairness in case handling.

Consider a hypothetical but realistic scenario

  • A behavioral health technician reports unsafe restraint practices involving minors in a residential facility.
  • Shortly after filing the internal report, the technician is placed on administrative leave and subsequently terminated.
  • The technician files a complaint under both the FCA and state labor law.
  • The investigation reveals that internal reports were not documented properly, retaliation safeguards were not in place, and training on non-retaliation was outdated.

This case underscores the need for compliance programs to ensure proactive risk mitigation, thorough documentation, and a robust culture of safety and transparency.

The Compliance Officer’s Role: Promoting a Speak-Up Culture

Organizations should periodically evaluate the effectiveness of their whistleblower protection efforts through anonymous staff surveys, incident response audits, and tracking the outcomes of reported concerns. This proactive approach signals to staff that leadership values integrity and transparency.

Certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation. Organizations must go beyond policy documents and invest in cultural and procedural safeguards:

- Establish and communicate clear non-retaliation policies.
- Train all employees and leadership on reporting rights and retaliation indicators.
- Maintain multiple confidential channels for reporting concerns.
- Ensure prompt and fair investigation of all complaints.
- Audit for compliance with whistleblower protection policies.

Conclusion

Ultimately, the goal of any whistleblower protection program is not merely compliance, but the cultivation of an ethical culture that consistently does what is right—even when it is inconvenient or uncomfortable. This requires leadership buy-in, staff empowerment, and a long-term commitment to transparency.

Whistleblower protections are more than legal requirements—they are pillars of ethical healthcare. Laws like the FCA, HIPAA, and NDAA empower individuals to report wrongdoing without fear. Compliance professionals must champion these safeguards, not only to avoid legal liability but to protect patient welfare, support employee integrity, and sustain organizational trust.

As regulatory enforcement intensifies and new federal protections emerge, healthcare organizations must remain vigilant, proactive, and transparent. The call to protect whistleblowers is not just a mandate—it is a moral and professional imperative.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance.  Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • U.S. Department of Health and Human Services (HHS). (2025). New Whistleblower Guidance and Complaint Portal. Retrieved from https://www.hhs.gov/protect-kids
  • 31 U.S.C. §§ 3729–3733, False Claims Act (FCA).
  • 31 U.S.C. § 3730(h), Anti-Retaliation Protections under the FCA.
  • 45 CFR § 164.502(j), Whistleblower Disclosures under the HIPAA Privacy Rule.
  • National Defense Authorization Act (NDAA) of 2013, 41 U.S.C. § 4712.
  • Office for Civil Rights (OCR), HHS. (2025). Press release on hospital investigation, April 14, 2025.
  • American Institute of Healthcare Compliance (AIHC). (2025). Newsblast: New Whistleblower Complaint Portal.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

You Play a Vital Role in Protecting the Integrity of the U.S. Healthcare System

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The U.S. health care system relies heavily on third-party payers to pay the majority of medical bills on behalf of patients. Health care insurance fraud is a pressing problem, causing substantial and increasing costs in medical insurance programs. To combat fraud and abuse, all levels within a medical practice, hospital or health care organization must know how to protect the organization from engaging in abusive practices and violations of civil or criminal laws.


If you are a health care provider, remember that payers trust you to provide medically necessary, cost-effective, quality care. You exert significant influence over what services your patients get. You control the documentation describing services they receive, and your documentation serves as the basis for claims you submit. Generally, the health care system pays claims based solely on your representations in the claims documents.


When the federal government covers items or services rendered to Medicare and Medicaid beneficiaries, the federal fraud and abuse laws apply. Many similar state fraud and abuse laws apply to your provision of care under state-financed programs and to private-pay patients. The most important federal fraud and abuse laws that apply to healthcare are the:

  1. False Claims Act (FCA);
  2. Anti-Kickback Statute (AKS);
  3. Physician Self-Referral Law (Stark Law);
  4. United States Criminal Code
  5. Exclusion Authorities; and
  6. Civil Monetary Penalties Law (CMPL).

Implementing a successful compliance program not only assists in protecting your organization but individuals within the organization. It is crucial for providers, coders and billers to understand these laws not only because following them is the right thing to do but also because violating them could result in criminal penalties, civil fines, exclusion from the federal health care programs or loss of your medical license from your state medical board.


Government programs, such as the Centers for Medicare & Medicaid Services (CMS), find the investment in their audit and monitoring programs are effective. CMS announced in the fall of 2021 that their aggressive corrective actions led to an estimated $20.72 billion reduction of Medicare Fee-for-Service (FFS) improper payments over seven years.


When you submit a claim for services provided to a Medicare beneficiary, you are filing a bill with the federal government and certifying you earned the payment requested and complied with the billing requirements. If you knew or should have known the submitted claim was false, then the attempt to collect payment is illegal.


When an organization fails to provide training and education to deter and detect fraud and/or abuse, it is likely to be detected by an outside investigative source via action such as:

  • Focused audit by the payer due to detection of suspect billing patterns when compared to your peers;
  • Routine audits conducted by the payer, such as Medicare’s Comprehensive Error Rate Testing (CERT); and
  • Internal whistleblower or qui tam action.

Internal auditing and monitoring programs are essential to keeping medical records and billing accurate. However, a routine internal billing and documentation review could turn into a more focused internal investigation. During that investigation, is it possible that an aberrant pattern of inappropriate billing is revealed? Do you know how to proceed if this happens?


First, remember that anyone can commit health care fraud. Fraud schemes range from solo ventures to widespread activities by an institution or group. Your organization should have a designated Compliance Officer. Audit professionals should have the authority to report potential fraud and abuse situations directly to the Compliance Officer for further investigation and resolution.


Problem areas brought to the attention of the Compliance Officer should also be included in corrective action training programs to avoid the continuation of the situation. One of the most important aspects of a compliance program is training and education at all levels of the organization.


Now, let’s talk more about qui tam action. There are five potential areas in which qui tam cases arise related to Medicare or Medicaid claims and the False Claims Act (“FCA”). Qui tam claims involving Medicaid/Medicare healthcare vary, depending on the level of care needed and provided. Categories often involve allegations of total neglect or no services, worthless services, inadequate and inferior services and products, and aggressive patient treatment. Other areas of fraud involve misrepresentation of credentials, upcoding of services, unbundling of services, and misrepresentation of patient data or populations.


Words of Advice


Maintain accurate and complete medical records and documentation of the services you provide.

  • Ensure your documentation supports the claims you submit for payment. Good documentation practices help to ensure your patients get appropriate care and allow other providers to rely on your records for patients’ medical histories.

Anytime a health care business offers you something for free or below fair market value, ask yourself, “Why?”

  • Remember, when a vendor or consultant provides coding and billing advice, the provider filing the claim is responsible for the accuracy of that claim. Be suspicious when you are told that a huge enhancement of revenue will be realized if you bill like this . . .

Get expert advice from a qualified source before investing or getting into a joint venture.

  • Some physicians who invest in health care business ventures with outside parties, such as imaging centers, laboratories, equipment vendors, or physical therapy clinics, may refer more patients for the services provided by those parties than physicians who do not invest. These business relationships may improperly influence or distort physician decision-making and result in the improper steering of patients to a therapy or service where a physician has a financial interest. Arrangements could be viewed as illegal.

Avoid illegal incentives to join a hospital’s community.

  • A hospital may pay you a fair market-value salary as an employee or pay you fair market value for specific services you render to the hospital as an independent contractor. However, the hospital may not offer you money, provide you free or below-market rent for your medical office, or engage in similar activities designed to influence your referral decisions.
  • Admit your patients to the hospital best suited to care for their medical conditions or to the hospital your patients select based on their preference or insurance coverage.

Don’t sell free product samples.

  • Many drug/biologic companies provide free product samples to physicians. It is legal to give these samples to your patients free of charge, but it is illegal to sell the samples.
  • The federal government has prosecuted physicians for billing Medicare for free samples.
  • If you choose to accept free samples, you need reliable systems in place to safely store the samples and ensure samples remain separate from your commercial stock.

Relationships with the pharmaceutical and medical device companies

  • As a practicing physician, you may have opportunities to work as a consultant or promotional speaker for the drug or device industry. For every financial relationship offered to you, evaluate the link between the services you can provide and the compensation you will get. Test the appropriateness of any proposed relationship by asking yourself the following questions and when in doubt, get legal advice: o Does the company really need your specific expertise or input? o Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services? o Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?

o  Does the company really need your specific expertise or input?

o  Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services?

o  Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?


Educate C-Suite and Compliance Officials in Your Company


An executive, top-down approach is required for a successful compliance program. The following seven components provide a solid basis for a compliance program:


1. Conduct internal monitoring and auditing

2. Implement compliance and practice standards

3. Designate a compliance officer or contact

4. Conduct appropriate training and education

5. Respond appropriately to detected offenses and develop corrective action

6. Develop open lines of communication with employees

7. Enforce disciplinary standards through well-publicized guidelines


Establishing and following a compliance program helps health care providers avoid fraudulent activities and submit accurate claims. However, implementing mechanisms to develop a culture of compliance requires educating high-level influencers within your organization. 


Suggest C-Suite executives take online training in healthcare Corporate Compliance.

Require your Compliance Officer, Chief Executive Officer and Chief Financial Officer to become certified not only in Compliance, but in Auditing for Compliance and Conducting Internal Investigations.


Joanne Byron is the Board Chair and Chief Executive Officer of the American Institute of Healthcare Compliance (AIHC) with more than 35 years of health care coding, documentation, billing and compliance experience as a consultant, health care executive and corporate trainer. Learn more about AIHC, a 501(c)(3) non-profit training organization, today.  

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Key Revenue Cycle Trends for 2022 and Beyond

Written by: Melvin Miller, COO




Tech, investments, efficiency, patient experience, underpayment recovery, and coding automation are some of the themes that will drive the revenue cycle market momentum in 2022 and beyond. Coming at the back-end of a long period of adversity due to COVID-19 and an already challenging economic environment for hospitals and healthcare systems, we see a new wave of consolidation, invention, and innovation. In this paper, we discuss some of the trends experienced in health care.


TIGHTENING PROFIT MARGINS – A PANDEMIC RAVAGED REVENUE CYCLE TO BOTTOM OUT.


With hospitals operating on extremely tight margins, projecting cash flow and the ability to extract the maximum out of the revenue cycle is more critical than ever before. This will drive key technology and process innovation as revenue cycle leaders and managers strive to improve business outcomes.


Now, let’s look at the broad trends in each of the major revenue cycle processes.


Patient Access and Experience


Patient experience is now one of the key issues impacting the healthcare industry. There is a huge information deficit in the area of patient payments.


Patients question “How much should I pay from my pocket?” The answer has been surprisingly difficult to find. Patients must get quick and easy access to information about services performed and corresponding charges; the amount expected to be paid by their insurance company; and the out-of-pocket expenses they are expected to bear. It is important to include the aspect of the No Surprises Act, which complicates the situation for both providers and patients.


We anticipate patient access and experience to improve with new technologies that can project the costs they need to bear, improved omnichannel information availability, and improved payment plans. Patient financial services will go through a much-needed overhaul.


Prior-Authorization and Eligibility Verification


While great tech exists for information interchange, prior authorization and eligibility verification tech adoption have lagged because of a lack of standardized documentation and information exchange protocols. With clearinghouses now modernizing, there is new hope for API-driven information exchanges.


Autonomous Coding


Automation tech is seeing increasing adoption, and there is a general perception that coding, billing, and accounts receivable problems will be solved through automation. Artificial Intelligence, Machine Learning, and Robotic Process Automation technologies provide great promise to lower labor costs. Medical coding is becoming data-driven and autonomous with improved standardization through ICD-11 and a better combination of virtual scribing, Universal Medical Language Systems (UMLS), OCR, and natural language processing (NLP). While these are still early days, coding tech is yet to prove effective in finding discharges not fully coded (DNFC) and arresting revenue leakage.


A/R, Denial Management, and Appeals Filing

Accounts Receivable (A/R) status has moved from calls to portals. We see increasing relevance for chatbots using conversational artificial intelligence (AI) in A/R and denial management filing. Data structures can now power customized appeals filing as well.

Focus on the Front-End

Most revenue cycle leaders agree that they need to solve revenue cycle issues in the front-end rather than elongate the cycle and wait to address them in the back end. They recognize that they need to link prior authorization, revenue integrity, clinical documentation improvement, and denial management to accelerate their revenue cycle. The ability to quickly identify denial issues, determine root causes, and develop solutions to reduce these denials through an iterative model that focuses on denial prevention is considered the key to addressing revenue cycle issues.

Underpayment and Analytics

The Hospital revenue cycle is fraught with underpayment issues. Contract analysis and underpayment identification can help arrest underpayments. As the shift to more branded, national healthcare practices happens, performance analytics becomes a critical business function. Practice-specific analytics using standard measures and Key Performance Indicators or KPIs will enable accurate views of performance and drive corrective action.

Unprecedented Financial Activity – Private Equity (PE), IPOs, Mega-mergers, and More

“It’s like Woodstock,” as some revenue cycle dealmakers are saying. The role of private equity in healthcare, in general, and the revenue cycle business, in particular, has increased to an unprecedented level.

  • Entry of the big boys. The big boys, i.e., the large PE firms have made strategic investments in revenue cycle assets.
  • Technology-led investments. Some of the themes that PE firms are investing in include focused revenue cycle service providers and niche technology companies such as autonomous coding, patient experience, prior authorization, and large-scale offshore providers.
  • Investments in revenue cycle aggregators. It seems like if a company’s resume says revenue cycle, it is likely to attract many valuations. Further, larger companies choose to hit the primary market through an initial public offering. We are seeing increasing consolidation of revenue cycle service providers as well.
  • Provider side consolidation. There is an increasing amount of investment in consolidation on the provider side. The push to provide a branded healthcare experience through nationwide chains is driving investments in areas such as urgent care, behavioral/mental health, wellness-focused treatments, home healthcare franchises, etc.

In 2022, we anticipate the continuance of these trends and mega-mergers will be more of a norm than an aberration.

Telehealth Adoption

Spurred on by the pandemic, telehealth adoption is increasing. Not only does this mean a lower cost of care, but it also requires the adoption of new processes for patient monitoring and managing the revenue cycle.

Remote Working

The COVID-19 necessitated revenue cycle team members to adopt work-from-home models. It also required operations managers to be flexible and adopt technologies to monitor revenue cycle performance. We anticipate that hospitals and healthcare systems will look at remote working as the new normal and encourage a significant percentage of their workforce to work remotely.

Labor Shortage and Outsourcing

There is an acute shortage of qualified revenue cycle staff. Many community hospitals are concerned about the community’s response to outsourcing and offshoring strategies they adopt. At this time of rising hospital expenses and reducing revenues due to declining reimbursements, outsourcing, offshoring, and automation can help them contain costs and sustain profitability. If using a U.S. based company that offshores the majority of their work, have you checked with legal counsel regarding how this type of business associate can be held accountable under U.S. laws (such as HIPAA, False Claims Act, etc.)

Conclusion

There has never been a better time to be in healthcare – and these are the most challenging times as well. Both in terms of economic activity and innovation, 2022 is likely to set a scorching pace. Whether you are a healthcare system, revenue cycle services provider, or technology solutions provider, this year will force you to think innovatively, build new delivery frameworks, and create the revenue cycle of the future.

Additional Resources:

_________________________________________________________

Melvin Miller is an experienced Chief Operating Officer with a demonstrated history of working in the healthcare industry for over 15 years, Satish, a.k.a. Melvin, has experience in team building, business development, Healthcare Information Technology (HIT), revenue cycle process training, US. Health Insurance Portability and Accountability Act (HIPAA), and Healthcare Management.
Read More