Atlantic Health Strategies

Ongoing Compliance Management for Multi-Site Behavioral Health Organizations

Table of Contents

Ready to See Results?

From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.

Answer First: What Ongoing Compliance Management Actually Requires

Multi-site behavioral health operators stay compliant when their leaders run compliance as one centralized operating system, not a stack of site-level binders. That means one policy library, one credentialing source of truth, one incident reporting workflow, and a fractional or full-time compliance officer who actually owns the risk register across every location.

The stakes are not theoretical. On January 15, 2025, the U.S. Department of Justice announced that False Claims Act settlements and judgments exceeded $2.9 billion in fiscal year 2024, with over $1.67 billion related to matters that involved the health care industry, including managed care providers, hospitals and other medical facilities, pharmacies, pharmaceutical companies, laboratories, and physicians. Whistleblowers filed 979 qui tam lawsuits, the highest number in a single year, and the government paid over $400 million to whistleblowers in relation to these FY 2024 recoveries. Behavioral health sits inside that number.

The cases my team at Atlantic Health Strategies works follow a familiar pattern. A Florida operator opens a second site in Tennessee. EMR templates drift. Supervision logs go missing at one location. Twelve months later the SIU audit lands. Operators running outpatient mental health clinics, addiction treatment programs, and integrated networks across state lines answer to state licensing boards, the HHS Office of Inspector General, the DEA, SAMHSA, and commercial payer SIUs (all of whom want different documentation). Reactive compliance loses to that environment. Every time.

The Regulatory Complexity of Multi-Site Behavioral Health Systems

Every facility sits inside its own state licensing framework, with its own supervision rules, staffing ratios, and program definitions. Then federal authority layers on top. The OIG’s General Compliance Program Guidance summarizes the primary federal fraud and abuse laws (including the Anti-Kickback Statute, Physician Self-Referral Law (the “Stark Law”), False Claims Act, Civil Monetary Penalty Authorities, Exclusion Authorities) and the HIPAA Privacy and Security Rules. Add CMS billing requirements, OSHA workplace rules, and 42 CFR Part 2 confidentiality for SUD records.

Once an operator moves from one site to four, the cracks my team finds during mock surveys are almost always the same:

  • Documentation templates that diverge by clinic director preference
  • Billing and coding protocols that vary between the Florida and Tennessee sites
  • Credentialing files missing the supervision logs the state surveyor asks for first
  • Policy versions nobody at the satellite site has actually read
  • Incident reports that never make it past the local clinical director

Operators grew compliance organically instead of designing it for multi-site governance. At AHS we replace that with one policy framework, one reporting structure, and one set of audit cadences across the network, while leaving room for state-specific variation where licensure demands it.

Fractional Compliance Leadership and the Seven Elements

For most operators with two to eight sites, a fractional Chief Compliance Officer is the right answer before a full FTE makes financial sense. The OIG anticipates this. OIG recommends that small entities lacking the financial or administrative ability to support a compliance officer on either a full-time or part-time basis consider appointing one individual as the entity’s compliance contact and have that person be responsible for ensuring all compliance activities are completed. A fractional engagement at AHS typically covers enterprise risk assessments, policy maintenance, documentation and billing audits, compliance committee reporting, exclusion screening, and ongoing staff education. Behavioral-health-specific ICPGs have not landed yet, so the GCPG is your operating rubric.

The framework AHS builds around is the OIG’s General Compliance Program Guidance, issued November 6, 2023 as the first-ever comprehensive compliance program guidance that would apply across all healthcare stakeholders, including traditional healthcare providers and facilities, as well as managed care plans, pharmaceutical manufacturers and contracted service providers. Treat it as voluntary in name and mandatory in practice. Prosecutors and surveyors use it as their rubric.

OIG sticks with the seven elements of compliance identified in the U.S. Sentencing Guidelines as the framework for its compliance program recommendations: written policies and a code of conduct, designated compliance leadership, training and education, effective lines of communication, enforcement through well-publicized disciplinary standards, auditing and monitoring, and structured response and corrective action. What changed in 2023 (and what my team operationalizes for clients) is that the new guidance also includes recommendations to conduct annual internal risk assessments, to consider quality of care as a component of the compliance program, and to emphasize the importance of a board’s and executive leadership’s oversight of compliance. For a PHP (ASAM Level 2.5, an outpatient level of care) or IOP operator, that means your utilization management documentation, your ASAM Criteria (4th Edition) level-of-care decisions, and your discharge planning are all compliance artifacts, not just clinical ones.

One piece matters specifically for behavioral health. OIG also specifically calls out the growing presence of private equity and other forms of private investment in health care and recommends that such investors scrutinize their operations and oversight to ensure compliance with fraud and abuse laws and the delivery of high-quality care for patients. If you are a PE-backed platform stitching together SUD and mental health assets across three states, the regulator is reading your cap table.

Workforce Credentialing, HIPAA Exposure, and Behavioral Health Enforcement

Workforce drift is where most multi-site programs fail their first real audit. Licensure renewals slip. Continuing education hours go untracked. Supervision logs at the Georgia site look nothing like the ones at the Arizona site. When a state surveyor asks for proof at 9:14 a.m. On a Tuesday, you have until lunch to produce it.

HIPAA and Part 2 sit next to credentialing on the risk register. The dollar exposure has teeth. On December 3, 2024, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) announced a $1.19 million civil monetary penalty against a Florida-based pain management clinic for alleged violations of the HIPAA Security Rule. According to OCR’s Notice of Proposed Determination, a former contractor impermissibly accessed the electronic protected health information (ePHI) of approximately 34,310 individuals on three occasions over a nearly five-month period. OCR Director Melanie Fontes Rainer put it plainly: “Current and former workforce can present threats to health care privacy and security”.

The underlying failure at Gulf Coast reads like a mock-survey playbook. OCR launched an investigation to assess whether Gulf Coast Pain Consultants was compliant with the HIPAA Rules and determined that the first time a HIPAA-compliant risk analysis was conducted was on September 30, 2022. Gulf Coast Pain Consultants had failed to implement policies and procedures for regularly reviewing activity in information systems containing ePHI, which meant the contractor was able to access electronic health records on multiple occasions. No risk analysis. No log review. No termination procedure. Three items on any competent EOC tour checklist.

Behavioral-health-specific enforcement reinforces the point. On December 10, 2025, US Attorney David Metcalf announced that Recovery Centers of America (RCA) has agreed to pay $1,000,000 to resolve allegations that it failed to comply with provisions of the Controlled Substances Act that are designed to prevent the diversion of controlled substances for illegal uses, and an additional $1,000,000 to resolve allegations that it violated the False Claims Act. The United States’ allegations under the CSA arise from audits and investigations the Drug Enforcement Administration (DEA) conducted at RCA facilities in Pennsylvania and Maryland between 2019 and 2024. The settlement in this case provides for the whistleblower, a former Outcomes Supervisor at RCA’s corporate headquarters in King of Prussia, Pa., to receive a $230,000 share of the settlement amount. Note the coordination. The resolution was the result of coordinated efforts among the Drug Enforcement Administration (DEA), the Department of Health and Human Services Office of Inspector General, and the Office of Personnel Management Office of Inspector General. Four agencies. One SUD provider. Two states.

My team integrates licensure tracking, training completion, exclusion screening, incident reporting, and Part 2 / HIPAA documentation inside one operational backbone. Your clinical team runs the care. Your compliance program runs underneath it. When the surveyor knocks at the Georgia site, or the SIU letter lands in your Florida office, the answer should already be in the system.

What Operators Should Do This Quarter

Pick the four things that move the risk register more than anything else:

  1. Consolidate the policy library. One version, one owner, one review cadence. Kill the site-level Word docs.
  2. Run a workforce access audit against the OCR playbook. Terminated user access, log review procedures, and risk analysis dates should hold up to the same standard OCR applied to Gulf Coast. Remember, HIPAA-compliant policies and procedures for reviewing logs were not implemented until April 10, 2020, more than 9 months after OCR informed Gulf Coast Pain Consultants that it was launching an investigation. That delay is what turned a breach into a $1.19 million CMP.
  3. Rebuild your risk assessment around the 2023 GCPG. Board-level reporting, annual internal risk assessments, and quality of care metrics belong in the compliance committee packet, not a separate QI binder.
  4. Stress-test your controlled substance recordkeeping and utilization management documentation. The recoveries for FY 2024 exceeded US$2.9 billion, approximately US$1.7 billion of which involved the health care industry, and DEA and HHS-OIG are actively coordinating on SUD provider settlements.

Operators who run compliance as an operational backbone protect their license, their payer relationships, and their enterprise value. Operators who treat it as a binder get to explain themselves to a U.S. Attorney.

Frequently asked questions

What does an effective compliance program look like for a multi-site behavioral health organization?

It follows the OIG’s seven elements from the November 6, 2023 General Compliance Program Guidance: written policies and a code of conduct, designated compliance leadership, training, lines of communication, enforcement standards, auditing and monitoring, and structured response and corrective action. The 2023 update added annual internal risk assessments, board-level oversight, and quality of care as a compliance domain. For multi-site operators, that translates into one centralized policy library, one credentialing system, exclusion screening against OIG and state Medicaid lists, and a fractional or full-time compliance officer who owns risk across every location.

How large is HIPAA penalty exposure for a behavioral health provider?

OCR can impose civil monetary penalties per violation with tiered annual caps based on culpability. Recent enforcement makes the exposure concrete: on December 3, 2024, OCR imposed a $1.19 million civil monetary penalty on Gulf Coast Pain Consultants in Florida for HIPAA Security Rule failures, including failure to terminate a former contractor’s access to ePHI affecting roughly 34,310 individuals and failure to conduct a compliant risk analysis until September 30, 2022. For multi-site operators, the practical takeaway is that termination workflows, log review procedures, and a current risk analysis are the three artifacts a surveyor will ask for first.

Do I need a full-time compliance officer, or can a fractional model work?

For most operators with two to eight sites, a fractional CCO is the right entry point. The OIG’s General Compliance Program Guidance explicitly recommends that small entities lacking the resources to support a full-time or part-time compliance officer designate one individual as the entity’s compliance contact who is responsible for ensuring all compliance activities are completed. As enterprise complexity and payer footprint grow, that role moves from fractional to full-time, and eventually to a compliance department reporting to the CEO with direct access to the board.

Why is DEA enforcement suddenly relevant to behavioral health operators?

Because federal agencies are coordinating on SUD provider settlements in ways they were not five years ago. The December 10, 2025 Recovery Centers of America resolution was announced by the U.S. Attorney for the Eastern District of Pennsylvania and reflected coordinated work with the DEA, HHS-OIG, and the OPM Office of Inspector General, resolving both Controlled Substances Act and False Claims Act allegations across facilities in Pennsylvania and Maryland. If you operate residential detoxification (ASAM Level 3.7 under the 4th Edition) or any level dispensing controlled substances, your DEA recordkeeping is now sitting inside the same enforcement ecosystem as your Medicaid billing.

Request a Free Consultation

Scroll to Top