If your compliance program consists of a binder on a shelf or a set of PDFs that haven’t been opened since the last Office of Inspector General (OIG) work plan update, you aren’t compliant—you are just waiting for a letter. I spent 11 years in the trenches, watching multi-site groups go from “we have a policy for that” to “we are in active litigation” because their systems couldn’t withstand the friction of a real-world inquiry.

The landscape shifted dramatically between 2024 and 2025. Enforcement agencies are no longer working in silos. They are using data fusion centers to cross-reference claims from the Centers for Medicare & Medicaid Services (CMS) against criminal databases, labor records, and tax filings in near real-time. If you aren’t stress-testing your program, you’re playing a game of catch-up you cannot win.

The 2025 Enforcement Reality: Why You’re Already Behind

The shift isn’t just about more audits; it’s about faster detection. In the past, you had the luxury of a slow audit cycle. Now, we see rapid-fire data requests. The government is deploying AI-driven detection—software that flags billing patterns that deviate even slightly from regional peer norms. It isn’t magic; it’s high-speed pattern recognition.

Agencies are now practicing cross-agency data consolidation. This means the Department of Justice (DOJ), the FBI (Federal Bureau of Investigation), and the OIG are sharing intelligence on specific billing outliers instantly. If you are seeing massive spikes in certain high-risk categories, they already know before you do.

High-Risk Focus Areas

  • Telemedicine: High-volume, low-touch encounters are the primary target.
  • Genetic Testing (GT): Often coupled with unsolicited marketing or “kickback” arrangements.
  • Durable Medical Equipment (DME): Focus on “medically unnecessary” orders for orthotics or braces.
  • Wound Care: Specifically looking at skin substitutes and complex, high-cost biologicals.

The Compliance Stress Test: Moving Beyond “Paper”

A “paper program” is a set of policies that look great in a board meeting but fall apart under scrutiny. A compliance stress test is the active, uncomfortable process of proving your systems actually function. Stop focusing on whether you *have* a policy; focus on whether the policy *works* when things go wrong.

1. Conduct Escalation Drills

Most organizations have a “who do we call” list, but nobody has ever actually walked through the first two hours of an inquiry. Run an escalation drill. Assign a point person to receive a mock subpoena or a knock at the door. Do they know how to secure the server room? Do they know which documents are privileged? Do they know who the external counsel is, and does that counsel have an active retainer?

2. The Mock Audit Healthcare Deep Dive

A mock audit healthcare event is not a “lite” version of an audit. It needs to be brutal. If your internal team performs the mock audit, you are grading your own homework—which is useless. AI-based tools that grade homeworks with AI demonstrate how automated grading can reduce manual evaluation, but a compliance audit still needs independent human review. Bring in an outside third party who has no loyalty to your billing team. Force them to pull 50 high-risk claims from the last quarter in the focus areas mentioned above. If your documentation doesn’t support the medical necessity for those 50 claims, your program has failed the test.

3. Stress-Testing Data Integrity

You likely use some form of software to catch billing errors. Is it actually catching anything, or is it just generating reports that sit in a dashboard? Take a known “problem” claim—one that you know is borderline—and run it through your detection systems. If your system flags it, great. If it doesn’t, your detection parameters are tuned too loosely.

The First 48 Hours: Your Survival Checklist

When the notification arrives, panic is your biggest enemy. If you have done the work of stress-testing, you shouldn’t be panicking. You should be executing a workflow. Keep this checklist visible in your office.

Hour Action Item Responsible Party 0-2 Establish communication channel (outside of email) Compliance Director 2-6 Secure all digital and physical records; freeze document deletion IT/Security Officer 6-12 Notify external legal counsel General Counsel/CEO 12-24 Interview billing staff involved in targeted claims Compliance Lead 24-48 Prepare “first response” summary of facts Outside Counsel/Compliance

Why “AI” Isn’t Your Compliance Savior

I hear this constantly: “We don’t need to stress-test, we have AI-driven detection in our billing platform.” AI is a tool, not a strategy. It can identify patterns, but it cannot explain intent. If your AI-driven detection flags an anomaly, you still need a human to investigate the clinical context. Over-reliance on automation often leads to “alert fatigue,” where the compliance team ignores flags because they assume the software is just being sensitive. Always cross-validate automated flags with manual chart reviews.

Building a Culture of Defensive Compliance

If your staff views compliance as the “billing police,” they will hide information from you. Stress-testing shouldn’t be a leaders-in-law.com punitive exercise; it should be framed as a way to protect the practice from external threats. Your providers need to understand that the government is looking at data, not just individual files.

Use your internal data consolidation to spot trends before the government does. If your internal reporting shows a 20% spike in DME orders, ask why. Is it a legitimate volume increase, or is there a vendor pushing unnecessary products on your staff? By identifying the trend, you can address it internally and correct it—before it shows up on an OIG report.

Actionable Steps for the Next 30 Days:

  • Identify your top three highest-revenue/highest-risk codes.
  • Perform a mock audit healthcare review on the last 30 days of claims for those codes.
  • Schedule an escalation drill with your front-desk and billing leads.
  • Review your cross-agency data integration—do your billing reports accurately reflect what you are submitting to CMS?

Stop pretending that a signed policy document is a shield. It isn’t. In 2025, compliance is about how quickly you can verify your facts and how well your team handles the pressure of an inquiry. Don’t wait for the letter to find out your system is a house of cards.

Posted by L. Derek Eldridge