Atlantic Health Strategies

Hidden HIPAA and OIG Risks for Group and Private Behavioral Health Practices: What Owners Miss Until the Letter Arrives

Table of Contents

Ready to See Results?

From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.

The short answer: three findings drive almost every federal enforcement action against small practices

Group and private behavioral health practices get hit by federal regulators for three things: a missing or stale HIPAA Security Risk Analysis, a failure to give patients timely access to their own records, and billing patterns that do not match the documentation. Every OCR resolution agreement and DOJ press release I read this year traces back to one of those three failures.

Owners of two-location groups in Florida, Tennessee, and New Jersey tell me the same thing after a knock on the door. They thought federal enforcement was for hospitals. It is not.

December 2024 was a busy month at the HHS Office for Civil Rights. OCR announced a $1.19 million CMP against Gulf Coast Pain Consultants, a $548,265 CMP against Children’s Hospital Colorado, and a $250,000 settlement with Inmediata Health Group in the same window. Named respondents on OCR’s 2024 and 2025 enforcement list include a family medicine office, a dental practice, a mental health center, and a pain-management group. Small entities are on the menu.

Who actually paid in 2024 and 2025

The pain-management case is the one every private practice owner should read twice. On December 3, 2024, OCR made final a $1,190,000 CMP against Gulf Coast Pain Consultants, LLC d/b/a Clearway Pain Solutions Institute, a Florida-based practice with locations in Alabama, Delaware, Maryland, New Jersey and Pennsylvania. A former contractor impermissibly accessed the ePHI of approximately 34,310 individuals on three occasions over a nearly five-month period. OCR did not confirm that a HIPAA-compliant risk analysis had been performed until September 30, 2022, and HIPAA-compliant termination procedures were not implemented until April 10, 2020. That second finding, terminated staff still holding EMR credentials, is a finding I catch on almost every mock survey we run for a group practice.

The behavioral health example is even closer to home. On July 7, 2025, OCR announced a $225,000 settlement with Deer Oaks – The Behavioral Health Solution, a psychological and psychiatric services provider serving long-term care and assisted living residents. OCR concluded Deer Oaks had failed to conduct a comprehensive and accurate risk analysis under 45 C.F.R. 164.308(a)(1)(ii)(A). The underlying ransomware attack in August 2023 affected 171,871 individuals. Two years of corrective action plan monitoring came with the check.

The Right of Access Initiative keeps producing penalties too. In November 2024, OCR imposed a $100,000 penalty against a mental health center for failing to provide timely access to patient records; it was OCR’s 51st HIPAA Right of Access enforcement action. Owners who cannot produce a records-request log within the 30-day window should assume they are the next respondent.

OCR leadership is not being subtle about where the agency is pointing. Announcing the Gulf Coast penalty, then-OCR Director Melanie Fontes Rainer said, “Current and former workforce can present threats to health care privacy and security”. Announcing the Deer Oaks settlement, OCR Director Paula M. Stannard said “identifying potential risks and vulnerabilities to ePHI is a key step in preventing or mitigating breaches of protected health information”. If the last time anyone touched your Security Risk Analysis was during EMR implementation, you are the target profile.

OIG and DOJ are watching behavioral health billing, not just hospital fraud

The OIG Work Plan should sit on every behavioral health owner’s desk. Behavioral health is squarely inside it, with active OIG projects covering Medicaid claims for Opioid Treatment Program services and Medicare Part B payments for psychotherapy services. If your group runs a telehealth-heavy PHP or IOP referral pipeline, you are inside the frame.

The DOJ numbers explain the incentive. Settlements and judgments under the False Claims Act exceeded $2.9 billion in the fiscal year ending Sept. 30, 2024, with $1.67 billion tied to the health care industry. Whistleblowers filed 979 qui tam lawsuits that year, averaging more than 18 new cases filed every week and breaking the prior record set in 2013. That volume is not tapering.

Behavioral health did not escape. Under a September 2024 settlement, Acadia Healthcare agreed to pay $16,663,918 to the United States to resolve False Claims Act liability for allegedly billing Medicare, Medicaid and TRICARE for medically unnecessary inpatient behavioral health services, plus an additional $3,186,082 to Florida, Georgia, Michigan and Nevada. Principal Deputy Assistant Attorney General Brian M. Boynton tied the case to the population directly, saying providers must satisfy medical-necessity requirements “when providing services to a vulnerable patient population, such as residents of an inpatient behavioral health facility”.

The through-line in these cases is not exotic fraud. Owners see documentation that does not match the CPT code, sessions that do not meet the psychotherapy definition, and supervision that cannot be substantiated on the chart. Owners treat that as an operational problem. DOJ treats it as a legal one.

What owners actually miss until the letter arrives

Three specific gaps produce most of the exposure I see in group and private practices in Florida, Ohio, and Tennessee.

The Security Risk Analysis is missing, boilerplate, or dated. OCR Director Paula M. Stannard put it plainly in the Deer Oaks announcement: “the covered entity or business associate under investigation will often have deficient risk analysis practices”, including lacking a risk analysis entirely or failing to update it when implementing new technologies. OCR named risk analysis a top priority in October 2024, and Deer Oaks was another in a string of settlements built on that same finding.

Termination workflows are broken. When a therapist resigns on a Friday, most small practices do not deprovision EMR, email, and remote access until the following Tuesday. That gap is exactly what OCR cited in the Gulf Coast matter, where the practice did not implement compliant termination procedures until April 10, 2020, years after the underlying breach.

Owners underestimate timing. Practices sell, restructure, or take PE capital during long OCR investigation windows with no idea a matter is open. The Gulf Coast investigation ran from the 2019 breach report through the December 2024 final CMP; that is a five-year file that a buyer’s counsel would absolutely surface in diligence. Sellers who miss this hand the buyer a ticking file. Buyers who miss it inherit it.

Two more issues our reviewers catch on nearly every readiness pass: no monthly LEIE exclusion screen of clinicians and vendors, and SUD records shared under HIPAA-only consent language rather than 42 CFR Part 2-compliant consent.

One more billing-side finding is worth calling out on its own. Practices bill psychotherapy add-on codes without time documentation, or bill 90837 when the note only supports 90834. OIG has an active Work Plan project on Medicare Part B payments for psychotherapy services. If you cannot show time on the face of the note, you cannot bill the code.

How AHS handles this before the regulator does

At Atlantic Health Strategies, our team runs mock OCR and OIG readiness reviews against the same elements the regulators cite in their published resolution agreements. We start with the Security Risk Analysis, because that is where OCR starts. Our reviewers check EMR termination logs, patient-access request logs, and psychotherapy documentation against ASAM Criteria 4th Edition levels of care and CPT time thresholds. Our team screens your workforce against the LEIE and confirms your Part 2 consents actually say what Part 2 requires.

Owners in Florida and New Jersey call us for two reasons: they got a letter, or they are about to sell and their buyer’s counsel is asking questions they cannot answer. Both problems have the same root cause. Owners never built an operational backbone designed to survive a federal file review. Our team builds it, stress-tests it, and hands it back as a compliance program the owners can actually run.

If you are within twelve months of a transaction, or you have not touched your SRA in eighteen months, you are already behind. Start there.

Frequently asked questions

Does OCR actually enforce HIPAA against small group and private practices, or just large hospitals?

Small practices are directly in scope. OCR imposed a $1,190,000 civil monetary penalty on Gulf Coast Pain Consultants, a multi-state pain-management group, in December 2024, and in November 2024 imposed a $100,000 penalty on a mental health center for failing to provide timely records access, its 51st Right of Access enforcement action. Family medicine offices and dental practices are also on the enforcement list.

What is the single most common HIPAA finding against practices right now?

A missing or inadequate Security Risk Analysis. OCR Director Paula M. Stannard has publicly said the covered entity or business associate under investigation “will often have deficient risk analysis practices”, including lacking a risk analysis entirely or failing to update it when adding new technology. The Deer Oaks settlement in July 2025 is one in a continuing series of enforcement actions built on that same finding.

How exposed is a behavioral health operator to a False Claims Act case?

More exposed than most owners realize. DOJ recovered more than $2.9 billion in FCA settlements and judgments in FY 2024, with whistleblowers filing a record 979 qui tam lawsuits, averaging more than 18 new cases every week. Acadia Healthcare’s September 2024 settlement of $16,663,918 to the United States (plus $3,186,082 to Florida, Georgia, Michigan and Nevada) shows behavioral health providers are being pursued for medical-necessity, documentation, and staffing failures.

How is OIG different from OCR for a behavioral health practice?

OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules. OIG oversees federal healthcare program integrity: False Claims Act cases, the Anti-Kickback Statute, Medicaid billing accuracy, and exclusion screening. The OIG Work Plan currently lists active projects covering Medicaid claims for Opioid Treatment Program services and Medicare Part B payments for psychotherapy services. Both agencies can hit the same practice for different reasons.

Request a Free Consultation

Scroll to Top