News & Insights

Newsletter

July 13, 2026

Health Headlines – July 13, 2026


OIG Issues Unfavorable Advisory Opinion on Paid Referral Management Software for Home Health Agencies

The Office of Inspector General (OIG) recently published an Advisory Opinion, concluding that a proposed arrangement between a home health agency (HHA) and a software vendor would constitute prohibited remuneration under the Federal Anti-Kickback Statute (AKS) if the requisite intent were present.

The Advisory Opinion requestor (Requestor) is a HHA operator that offers in-home care services to Federal health care program beneficiaries. HHAs often receive patient referrals from hospitals, and Requestor certified that hospital referrals “are often determined on a first-come, first-served basis, so the speed with which the HHA responds to a hospital’s request . . . is determinative of securing referrals.” 

Under the proposed arrangement, Requestor would pay a subscription fee to a health care software vendor (the Vendor), which provides an online referral management software (the Software) that links hospitals with HHAs during the discharge planning process. The Software provides participating hospitals with a list of all HHAs in the region, “but only those HHAs that pay to subscribe to the Software are able to receive electronic communications from the hospitals.” By paying the subscription fee, Requestor and other subscribed HHAs can receive and immediately accept referrals from hospitals through the Software. On the other hand, HHAs that do not subscribe to the Software can only accept a hospital’s referrals by contacting the appropriate person at the hospital directly by phone.

OIG concluded that this arrangement would implicate the AKS “because Requestor is paying remuneration to the Vendor in return for the Vendor, through the Software, arranging for the furnishing of home health services for which payment may be made by a Federal health care program.” This arrangement fails to satisfy multiple requirements under the AKS safe harbor for referral services, “including the requirement that referral fees be assessed uniformly against all participants[,]” because subscription fees charged to HHAs “vary based on a number of factors.” 

OIG explained that this arrangement “poses a risk of inappropriate steering and unfair competition” because “it appears that HHAs paying the Vendor’s fees would get patients because they paid for the opportunity rather than on the basis of the quality of care they offer.” OIG highlighted the risk of an “anti-competitive effect,” whereby HHAs that pay the subscription fee “would have a significant competitive advantage,” and non-paying HHAs may be “effectively eliminate[d] . . . from any chance of receiving patient referrals[.]” Furthermore, OIG believed there would be a “risk of overutilization or inappropriate utilization[,]” because HHAs that choose to pay the subscription fee “could face pressure to recoup the costs[,]” which could create an incentive to bill for services that are not medically necessary.

A copy of the Advisory Opinion is available here.

Reporter, Rebecca Hsu, Atlanta, GA, +1 404 572 3339, rhsu@kslaw.com.  

AITN

HHS Delays HIPAA Security Rule Overhaul Until 2027

HHS has delayed final action on proposed updates to the HIPAA Security Rule, with the Office of Management and Budget’s regulatory agenda now listing July 2027 as the expected publication date for a final rule. The Notice of Proposed Rulemaking (NPRM), issued by HHS’ Office for Civil Rights in January 2025, would represent the most significant overhaul of the HIPAA Security Rule in more than 10 years and is intended to strengthen protections for electronic protected health information in response to increasing cyberattacks and ransomware incidents. Proposed requirements include mandatory encryption, multifactor authentication, network segmentation, annual penetration testing, more prescriptive risk analysis requirements, and tested incident response plans. The NPRM generated nearly 5,000 public comments, with provider groups and healthcare organizations raising concerns about compliance costs, implementation timelines, and operational burden. Separately, HHS is moving forward with a final rule updating the HIPAA Privacy Rule, which is currently expected to be released in August 2026. The proposed changes are intended to improve information sharing for care coordination and case management, expand family and caregiver involvement during emergencies, and enhance patient access to health information while reducing administrative burdens on covered entities.

Editors: Chris Kenny and Ahsin Azim

Issue Editors: Christopher Jew and Marcia Foti