Table of Contents
Ready to See Results?
From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.
How often should a behavioral health organization run a compliance audit?
Most behavioral health operators should run one comprehensive compliance audit per year and layer targeted quarterly reviews on documentation, billing, supervision, and 42 CFR Part 2. That cadence is not a preference. It matches what HHS-OIG recommended when it published the General Compliance Program Guidance (GCPG) on November 6, 2023, and it matches what federal prosecutors have been looking for on chart reviews since the June 30, 2025 Takedown.
A behavioral health compliance audit is a structured review of clinical documentation, billing, policies, supervision, licensure posture, and accreditation readiness, run against the specific payer, state, and federal rules that govern each program. Most generalist healthcare compliance shops do not read SUD documentation, supervision ratios, incident reporting, or 42 CFR Part 2 the way an operator who has actually run programs does.
Atlantic Health Strategies sits in that narrow space. Our auditors have managed state licensing surveys, prepared sites for CARF and Joint Commission, corrected documentation systems after payer takebacks, and rebuilt compliance infrastructure after enforcement actions. A real audit gives leadership a clear picture of operational risk. Not a checklist. It covers documentation and medical necessity, billing integrity and modifier usage, policy alignment with current state regulations, licensure and accreditation readiness across each jurisdiction, and supervision, onboarding, and workforce practices.
Why this got very concrete on June 30, 2025
On June 30, 2025, DOJ announced its 2025 National Health Care Fraud Takedown. Prosecutors charged 324 defendants, including 96 doctors, nurse practitioners, pharmacists, and other licensed medical professionals, in 50 federal districts and 12 State Attorneys General’s Offices across the United States, for their alleged participation in various health care fraud schemes involving over $14.6 billion in intended loss. In the same coordinated action, the government seized over $245 million in cash, luxury vehicles, cryptocurrency, and other assets as part of the coordinated enforcement efforts.
Attorney General Pamela Bondi put it plainly: the schemes involved over $14.6 billion in intended loss, and HHS-OIG Acting Inspector General Juliet T. Hodgkins called the scale “unprecedented, and so is the harm we’re confronting”. CMS was in the middle of it too. CMS successfully prevented more than $4 billion from being paid, and had suspended or revoked the billing privileges of 205 providers in the months leading up to the 2025 Takedown.
Behavioral health was not a footnote. In the District of Arizona, federal prosecutors charged Farrukh Jarar Ali of ProMD Solutions in what DOJ described as an alleged $650 million scheme involving at least 41 substance abuse treatment clinics in Arizona, with AHCCCS paying approximately $564 million for these false and fraudulent claims. Ali personally received approximately $24.5 million of AHCCCS funds as a result of the scheme, and he used $2.9 million of the funds to purchase a home located on a golf estate in Dubai, United Arab Emirates. The indictment alleges something specific worth noting: Ali also created false therapy notes for treatment that was never provided, and the clinics working with Ali provided these falsified records to AHCCCS in response to audits.
That is exactly the pattern surveyors, SIU auditors, and federal prosecutors now open a chart looking for. Falsified notes. Services not rendered. Documentation that cannot survive a real review.
How the OIG raised the bar in 2023, and what changed for SUD programs in 2026
Multi-state operators, managed care contract holders, and programs approaching a survey window need a tighter cadence than annual. This is not arbitrary.
HHS-OIG released its General Compliance Program Guidance on November 6, 2023, its first comprehensive compliance program guidance in roughly 15 years. OIG’s key new recommendation in the GCPG is that the compliance committee should conduct annual risk assessments to identify and address risk areas, and quality of care considerations should be included in a compliance program to mitigate patient harm and False Claims Act liability. Jones Day’s analysis of the GCPG puts the ownership point directly: OIG also recommends adding topics, such as quality and patient safety, to compliance reviews and expressly considers the impact of ownership and payment incentives on patient care. That is the language auditors who ignore the clinical side of the chart keep missing.
For SUD programs, the cadence question got sharper in 2026. In 2024, HHS published a final rule updating 42 CFR part 2 as required by the CARES Act. The Final Rule has been effective since April 16, 2024, and compliance was required by February 16, 2026. Then the enforcement announcement landed. On February 13, 2026 HHS announced a new civil enforcement program to implement and “aggressively” enforce Part 2 requirements, and beginning February 16, 2026, the HHS Office for Civil Rights (OCR) began accepting complaints alleging violations of Part 2 and notification of breaches of SUD records. HHS now has authority to conduct compliance reviews and investigations, and impose corrective action plans, resolution agreements, and civil monetary penalties related to Part 2 noncompliance.
Operators who did not refresh consents, breach notification procedures, patient notices, and re-disclosure workflows by that date are now operating outside the rule. Financial exposure is real. The financial penalties for noncompliance also align with HIPAA, increasing from $500 for a first offense and $5,000 for subsequent offenses to the current HIPAA penalties, which in 2025, range from $141 to $2.1 million, with criminal penalties also possible. We tell SUD clients to treat the post-effective-date period as a heightened surveyor-focus window and run a targeted Part 2 review on top of the annual cycle.
Where behavioral health operators find consultants who actually specialize
Generalist healthcare compliance firms do not translate cleanly into behavioral health. The documentation rules are different. The supervision rules are different. Part 2 layered over HIPAA is different. The payer audit playbooks are different. SIU teams at behavioral health managed care plans look for patterns hospital auditors do not even think to flag.
What separates a specialized behavioral health audit partner is field experience. Operators want people who have supervised clinicians, sat through state licensing surveys in multiple jurisdictions, managed corrective action plans after CARF or Joint Commission findings, and rebuilt billing workflows after a payer SIU audit. The market is not large.
AHS serves community agencies, SUD programs, residential providers, and outpatient clinics, including PHP (ASAM Level 2.5, an outpatient level of care), IOP, and outpatient services across states like Florida, Arizona, Texas, Utah, and Tennessee. We do not work in California or New York, and we do not provide ABA or autism services. Our scope is behavioral health and SUD operations.
A good partner identifies gaps and then helps operators actually close them: policy updates, workflow redesign, staff training, supervision structures, and corrective action plans that match real capacity.
One note on AI-driven audit tools. Our team has tested several. Our auditors still catch documentation patterns the AI misses, and we have seen AI tools hallucinate findings and skip obvious errors. We use technology where it accelerates the work, but a person reads the charts.
How AHS schedules and runs a behavioral health compliance audit
The process is straightforward and designed to limit disruption to clinical and billing teams:
- Initial conversation. A short discussion about size, programs, payers, licensure status, accreditation cycle, and current concerns. This calibrates scope.
- Scope and workplan. Our team outlines the service lines, locations, policies, documentation samples, and billing data we will review. Predictable and bounded.
- Document collection and review. Our auditors review charts, policies, billing data, supervision records, and required elements tied to state, payer, and accreditor expectations.
- Operational interviews. We meet with clinical leadership, billing, quality, and administrative staff to surface workflow gaps that do not show up on paper.
- Findings and recommendations. A clear written report explaining what is compliant, what needs correction, and how to fix it on a realistic timeline.
- Ongoing support. Many clients move to a quarterly or semi-annual review cycle so audit work becomes part of the operational rhythm, not a reaction to a payer letter.
OIG has also raised the bar on what internal audits should assess. The GCPG addresses developments and emerging issues in the healthcare industry, including a recommendation to incorporate quality and patient safety oversight into compliance programs; new entrants in the healthcare industry; financial incentives and ownership; and financial arrangements tracking. That is a bar most generalist auditors do not clear. Our chart reviewers include clinicians who read medical necessity, not just billing coders who check boxes.
The federal enforcement environment for behavioral health is the most aggressive it has been in a decade. The 2025 action resulted in criminal charges against 324 defendants, with intended losses exceeding $14.6 billion, making it the largest health care fraud Takedown in U.S. Department of Justice history and doubling the previous record of $6 billion. Put those trends together with OCR’s active enforcement of the updated Part 2 rule, OIG’s 2023 GCPG raising the bar on quality and risk-assessment expectations, and CARF’s continued focus on outcome data, and any behavioral health operator waiting for a trigger event to audit is now working against the grain of every regulator in the system. Scheduled audits are the cheapest insurance policy available.
Frequently asked questions
How often should a behavioral health organization run a compliance audit?
Most operators should run one comprehensive audit annually and add quarterly or semi-annual targeted reviews on documentation, billing, supervision, and 42 CFR Part 2. Multi-state operators and programs under managed care contracts often need tighter cycles. The HHS-OIG General Compliance Program Guidance, released November 6, 2023, reinforces internal monitoring and auditing as one of the seven elements of an effective compliance program and recommends that the compliance committee conduct annual risk assessments to identify and address risk areas.
What does a behavioral health compliance audit actually cover?
Documentation and medical necessity (assessments, treatment plans, progress notes, discharge), billing and coding integrity, policy alignment with current state and payer rules, licensure and accreditation readiness (CARF or Joint Commission), supervision and workforce practices, and 42 CFR Part 2 controls for SUD programs. OIG’s 2023 GCPG also recommends incorporating quality and patient safety oversight into compliance programs, since excessive or medically unnecessary services can trigger False Claims Act liability.
What changed with 42 CFR Part 2 in 2026?
The SAMHSA and OCR final rule modifying 42 CFR Part 2 has been effective since April 16, 2024, with a compliance deadline of February 16, 2026. HHS announced a civil enforcement program on February 13, 2026, and OCR began accepting complaints and breach notifications on February 16, 2026. Key changes include a single patient consent for treatment, payment, and healthcare operations, alignment of breach notification and penalties with HIPAA, and OCR authority to investigate violations, impose corrective action plans, and levy civil monetary penalties. Penalties now align with HIPAA’s 2025 tier of $141 to $2.1 million per violation.
Why did federal enforcement escalate so sharply in 2025 for behavioral health operators?
DOJ’s 2025 National Health Care Fraud Takedown charged 324 defendants across 50 federal districts in connection with over $14.6 billion in alleged fraud, making it the largest such action in DOJ history and doubling the previous $6 billion record. Behavioral health was a central focus: in Arizona, federal prosecutors charged Farrukh Jarar Ali of ProMD Solutions in an alleged $650 million scheme involving at least 41 substance abuse treatment clinics, with AHCCCS paying approximately $564 million on those claims. CMS also prevented more than $4 billion in improper payments and suspended or revoked billing privileges for 205 providers in the months leading up to the Takedown.
References
- DOJ Office of Public Affairs, National Health Care Fraud Takedown Results in 324 Defendants Charged (June 30, 2025)
- HHS-OIG, 2025 National Health Care Fraud Takedown
- U.S. Attorney’s Office, District of Arizona, Charges 7 Defendants as Part of National Health Care Fraud Takedown
- HHS-OIG, General Compliance Program Guidance (November 6, 2023)
- HHS, Understanding Confidentiality of Substance Use Disorder (SUD) Patient Records or “Part 2”
- HHS, Fact Sheet: 42 CFR Part 2 Final Rule
- HIPAA Journal, February 16, 2026 Compliance Deadline for Part 2 Final Rule
- Quarles, 42 CFR Part 2 Compliance Deadline and HHS Enforcement
- Jones Day, HHS-OIG Issues New General Compliance Program Guidance
- Sidley, HHS-OIG Releases General Compliance Program Guidance for Healthcare Industry