34 min read

> "Nobody sets out to commit healthcare fraud. They set out to solve a cash flow problem, and they

Prerequisites

  • 1
  • 4

Learning Objectives

  • Explain what a claim certifies and to whom, and why that makes coding a legal act.
  • Distinguish fraud from abuse, and explain why 'knowingly' under the False Claims Act reaches more than intentional deception.
  • Describe the False Claims Act, the Anti-Kickback Statute, and the physician self-referral law, and identify which one a given fact pattern implicates.
  • State the consequences available to the government, including exclusion, and explain why exclusion ends a career.
  • List the seven elements of an effective compliance program and say what each is for.
  • Distinguish HIPAA's privacy, security, and transactions rules and apply the minimum necessary standard.
  • Name the common coding errors, including why downcoding is not the safe choice.
  • State what to do when instructed to code something the documentation does not support.

Chapter 5: Compliance and Ethics: Fraud, Abuse, HIPAA, and Why Accuracy Is a Legal Obligation

"Nobody sets out to commit healthcare fraud. They set out to solve a cash flow problem, and they solve it eleven times, and the eleventh one is a pattern." — constructed; the shape of most enforcement actions

Overview

Chapter 4 kept saying that a code unsupported by documentation is a problem, and kept being vague about what kind. This chapter is specific.

Every claim you submit is a certification. When a claim goes to Medicare, Medicaid, TRICARE, or any other federal health program, the submitting organization is representing that the services were furnished, that they were medically necessary, and that the information on the claim is true and complete. That representation is made by the organization, and it is built by a coder and a biller.

The law that attaches to a false certification is the False Claims Act, and the thing people entering this field most need to understand about it is contained in one definition. "Knowingly" does not mean "intended to deceive." It reaches deliberate ignorance and reckless disregard of whether information is true. You do not have to decide to defraud anyone. You have to stop looking.

That is the chapter's argument, and everything else is the machinery: what separates fraud from abuse, what the three big statutes do, what the government can take, what a real compliance program contains, what HIPAA actually requires, and — the part every practitioner eventually needs — what to do when you are told to code something you cannot defend.

One clarification before starting, because it matters for how the chapter reads. This material is written from the detection and prevention side. It names schemes in order to describe how they are caught and what they cost. It does not explain how to construct documentation to support a code that was not earned, how to select a modifier to defeat an edit, or how to characterize a service to obtain coverage it does not qualify for. That line is bright and this book stays on one side of it.

In this chapter, you will learn to:

  • Explain what a claim certifies and why coding is a legal act
  • Distinguish fraud from abuse, and say why "knowingly" reaches more than deception
  • Identify which statute a fact pattern implicates
  • State what the government can take, including a career
  • List the seven elements of a compliance program and say what each is for
  • Apply HIPAA's minimum necessary standard
  • Explain why downcoding is not the safe choice
  • Say what to do when told to code something indefensible

Learning Paths

🎓 Certification — §5.2, §5.3, §5.4, §5.6, and §5.7 are all examinable. The seven compliance program elements and the fraud/abuse distinction appear on every credential.

💼 New Coder — §5.1, §5.8, and §5.9. Read §5.9 twice; you will need it sooner than you think.

💵 Biller / AR — §5.7 (you handle protected health information constantly) and §5.5 (exclusion screening is usually a billing-office function).

🏥 Practice Manager — §5.4 and §5.6 are yours. Financial relationships and compliance program design are management decisions, and both carry personal exposure.


5.1 Every claim is a certification

A claim is not a request. It is a statement of fact, made for payment, to which specific representations attach.

For Medicare, the enrollment agreement and the claim itself carry the certification. The paper CMS-1500 makes it explicit in item 31, where the provider's signature attests that the services shown were personally furnished or furnished under their direction, and that the claim complies with applicable laws. The electronic equivalents carry the same obligations. The UB-04's certification language is likewise incorporated by the provider agreement.

What is being certified, in substance:

  • The services were actually furnished
  • They were medically necessary
  • The information is true, accurate, and complete
  • The claim complies with applicable law, including the kickback and self-referral prohibitions

Read that last one again. A claim for a service that was furnished, was necessary, and was coded perfectly can still be a false claim, if the referral behind it was tainted by an unlawful financial relationship. §5.4.

The provider signs. The coder chooses the code. Those are not the same person and the law does not care.

An organization that submits a claim has certified it, and the content of that certification was assembled by whoever selected the codes. A coder who assigns a level of service the record does not support has not "made a coding error that the provider then certified." They have participated in producing a false statement — and while the individual exposure of a salaried coder is much lower than the organization's, it is not zero, and the professional exposure is substantial.

This is why Chapter 1 §1.6 said a coder is not responsible for the practice's revenue. The responsibility a coder does carry is that the code reflects the record and the reasoning can be reconstructed. That is not a small thing to carry. It is the whole thing.

⚖️ Compliance Check

The certification travels with the claim, not with the intention.

Three practical consequences that catch people:

A corrected claim does not erase the original. Submitting a corrected claim is the right thing to do and it does not undo the fact that the first one was submitted. What matters is whether the error was found and fixed through a functioning process, or found by someone else.

Retaining a known overpayment is itself a violation. Under the Affordable Care Act's sixty-day rule, an identified Medicare or Medicaid overpayment must be reported and returned within sixty days of identification, and a retained overpayment becomes an obligation under the False Claims Act. Chapter 31 §31.9 covers the operational side. This converts what feels like an accounting backlog into a legal exposure.

"We didn't know" has a specific legal meaning and it is usually not a defense. §5.3.

Statutes, regulations, and enforcement priorities change. Verify with your compliance officer and the primary sources; do not rely on this or any other summary.


5.2 Fraud and abuse: the difference is intent and pattern

The two words are used together so often that people treat them as one thing. They are not, and the distinction determines which authorities apply.

Fraud Abuse
Core Knowingly and willfully executing, or attempting to execute, a scheme to obtain money from a health care benefit program by false pretenses Practices inconsistent with sound fiscal, business, or medical practice that result in unnecessary cost
Requires intent? Yes No
Typical remedy Criminal prosecution, civil penalties, exclusion Repayment, education, corrective action; escalating with pattern
Example Billing for a service that was never furnished Consistently billing a higher-level visit than documentation supports, without demonstrable intent

The crucial and frequently missed point: the same conduct moves between these categories based on pattern and knowledge.

A single overcoded visit is an error. The same overcoding across 400 claims, after an internal audit identified it and nothing changed, is something else — not because anyone decided to defraud a payer, but because the knowledge element is now satisfied by the organization's own audit findings.

This is the mechanism by which ordinary practices end up in enforcement actions. Nobody wakes up and decides to commit fraud. Somebody notices a problem, does not fix it, and keeps billing.

HOW AN ERROR BECOMES SOMETHING ELSE

  ERROR                  ABUSE                    FRAUD
  ─────                  ─────                    ─────
  one claim              a pattern                a pattern + knowledge
  no knowledge           no demonstrated          + continuation
  found and fixed        intent
       │                      │                        │
       ▼                      ▼                        ▼
  correct and             repay, educate,          civil penalties,
  refund                  corrective action        criminal exposure,
                                                   exclusion

       ◄──────── the same conduct, at three stages ────────►

   WHAT MOVES IT RIGHTWARD:  volume · time · and above all,
                             EVIDENCE THAT SOMEBODY KNEW

That bottom line is the one to remember. The most dangerous document in any organization is an internal audit finding that was never acted on, because it converts every subsequent identical claim from an error into a knowing one. Chapter 37 §37.10 covers what a corrective action plan has to actually do.


5.3 The False Claims Act and the whistleblower next to you

The False Claims Act (31 U.S.C. §§ 3729–3733) is the primary civil enforcement tool in American healthcare, and it does far more work than any criminal fraud statute.

What it prohibits, in the parts that matter here: knowingly presenting, or causing to be presented, a false or fraudulent claim for payment or approval; knowingly making or using a false record or statement material to a false claim; and knowingly concealing or improperly avoiding an obligation to pay money to the government.

That third one is the overpayment provision. It is why the sixty-day rule has teeth.

"Knowingly" — the definition that changes everything

The statute defines the term at § 3729(b)(1). A person acts knowingly if they:

  1. have actual knowledge of the information;
  2. act in deliberate ignorance of its truth or falsity; or
  3. act in reckless disregard of its truth or falsity.

And it states expressly that no proof of specific intent to defraud is required.

Read the second and third prongs slowly, because they are the ones that reach ordinary organizations doing ordinary work.

Deliberate ignorance is not looking. A practice that has been told its documentation is insufficient and declines to check.

Reckless disregard is not caring enough to look properly. A coder who appends a modifier by macro without reading a note. An organization that bills a high volume of a service without ever reviewing whether the documentation supports it. A billing company that sets up an edit override and never audits its use.

None of that requires anyone to decide to cheat. That is the entire point of the definition, and it is the single most important legal fact in this chapter.

Materiality

Not every false statement is actionable. The falsity must be material — capable of influencing the payment decision. Courts have engaged with this at length, including on whether the government's continued payment despite knowledge of a violation bears on materiality. In practice, the requirement matters most at the margins; the mine-run coding and documentation cases are comfortably material, because a payer that knew the documentation did not support the code would not have paid.

Qui tam: the whistleblower provision

This is the part that shapes the field.

The False Claims Act permits a private person — a relator — to file suit on behalf of the government. The suit is filed under seal while the government investigates and decides whether to intervene. If the case succeeds, the relator receives a share of the recovery.

Two consequences follow, and both are worth internalizing early.

A large share of healthcare False Claims Act cases originate with insiders. Billers. Coders. Practice managers. Compliance officers. Former employees. The person best positioned to know that a practice is systematically overcoding is the person who does the coding.

Retaliation is prohibited. The statute provides a remedy for an employee discharged, demoted, suspended, threatened, or harassed because of lawful acts in furtherance of a False Claims Act action or in efforts to stop a violation.

⚖️ Compliance Check

What this means for you, personally, stated plainly.

If you are instructed to do something you believe is improper, you are not powerless and you are not without protection. §5.9 covers the sequence. But understand the structure you are inside of:

The person who reports is protected. The person who complies is not. "I was told to" has never been a defense, and the coder who quietly did what they were told is a witness at best and a defendant at worst.

And the corollary, which organizations frequently miss: the single most effective whistleblower-prevention measure is a compliance program that takes internal reports seriously. People go outside when inside does not work. Chapter 37.

This is a summary of a complex statute with real consequences. If you find yourself in this situation, consult counsel — not a textbook.


5.4 The Anti-Kickback Statute and Stark

Two statutes about money moving between people who refer to each other. They overlap, they are frequently confused, and they are different in ways that matter.

The Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b))

Criminal. It prohibits knowingly and willfully soliciting, receiving, offering, or paying any remuneration — directly or indirectly, in cash or in kind — to induce or reward referrals of items or services payable by a federal health care program.

Four features that make it broader than people expect:

"Remuneration" means anything of value. Not just cash. Free rent, subsidized staff, discounted equipment, meals, speaking fees, waived cost sharing (Chapter 2 §2.3), free supplies.

It runs in both directions. Paying and receiving are both prohibited.

Intent is required, but a "one purpose" standard has been applied — courts have held that an arrangement can violate the statute if one purpose of the remuneration is to induce referrals, even where other legitimate purposes exist.

A claim resulting from a violation is a false claim. The Affordable Care Act made this explicit, which links the criminal statute to civil False Claims Act liability.

There are statutory exceptions and regulatory safe harbors — defined arrangements that, if every element is met, are protected. Safe harbors are narrow and technical, and compliance with one is all-or-nothing.

The physician self-referral law — "Stark" (42 U.S.C. § 1395nn)

Civil, and strict liability. It prohibits a physician from making referrals for certain designated health services payable by Medicare to an entity with which the physician (or an immediate family member) has a financial relationship, unless an exception applies. It also prohibits the entity from billing for those referred services.

The critical distinction from the Anti-Kickback Statute:

Stark requires no intent. None. An arrangement that fails to satisfy an exception violates the statute regardless of why it was structured that way or whether anyone meant anything by it. This surprises people constantly, and it is why Stark compliance is a documentation and structuring discipline rather than an ethics one.

Anti-Kickback Statute Stark
Nature Criminal (and civil) Civil
Intent required Yes — knowing and willful No — strict liability
Who is covered Anyone Physicians and entities billing their referrals
What is covered Any item or service payable by a federal health care program Designated health services payable by Medicare
Protection Safe harbors — voluntary, all elements required Exceptions — mandatory compliance if the arrangement is to be lawful
Remedies Fines, imprisonment, exclusion, civil penalties, FCA liability Denial of payment, refunds, civil monetary penalties, FCA liability

⚠️ Where Claims Die

Why this appears in a coding textbook at all.

Because the claim is where it surfaces. A financial relationship is not visible on a claim form. The referral pattern is, and referral patterns are exactly what data analytics finds.

A coder or biller is unlikely to structure a physician's financial relationships. A coder or biller is extremely likely to be the first person who notices that essentially all of a practice's imaging goes to one facility, or that a new arrangement produced a step change in referral volume, or that a service line's volume does not fit its patient population.

You are not expected to render a legal opinion. You are expected to notice, and to have somewhere to say it. That is what §5.6's reporting mechanism is for.


5.5 Civil monetary penalties, exclusion, and the end of a career

The government's toolkit, roughly in ascending order of consequence.

Repayment. The overpayment, returned. Often with interest. Frequently extrapolated across a universe of claims rather than limited to the ones reviewed — Chapter 37 §37.6 explains how a twenty-claim sample becomes a much larger demand.

Civil monetary penalties. The Civil Monetary Penalties Law authorizes penalties for a range of conduct including presenting claims a person knows or should know are false, and violations of the Anti-Kickback Statute. Penalties are per item or service, are adjusted for inflation, and can carry an additional assessment in lieu of damages. Look up current amounts; they change. The structural point is that per-claim penalties across a high-volume service line reach very large numbers quickly, independent of the underlying overpayment.

Corporate integrity agreement. A negotiated settlement obligation, typically running five years, under which an organization agrees to specific compliance measures: an independent review organization, mandatory training, reporting obligations, board certifications. Expensive, intrusive, and public.

Criminal prosecution. For the fraud and kickback statutes.

And exclusion.

Exclusion

The OIG may exclude — and in defined circumstances must exclude — individuals and entities from participation in all federal health care programs.

Mandatory exclusion applies to conviction of program-related crimes, patient abuse or neglect, felony health care fraud, and certain felony controlled-substance convictions. Permissive exclusion covers a longer list including misdemeanor fraud convictions, license revocation or suspension, and submission of claims for excessive charges or unnecessary services.

What exclusion means in practice is the part people underestimate.

No federal health care program may pay for any item or service furnished, ordered, or prescribed by an excluded person. The prohibition reaches beyond direct billing: it covers administrative and management services, and it reaches an excluded person employed by a provider in any capacity if the provider bills federal programs.

So exclusion does not merely end your ability to bill. It ends your employability across essentially the entire American healthcare system. A hospital that employs an excluded coder and bills Medicare is exposed for every claim the excluded person touched.

Which is why exclusion screening — checking the OIG's List of Excluded Individuals and Entities, and typically the federal exclusion system and state lists, at hire and periodically thereafter — is a routine and non-negotiable function, frequently performed by the business office.

⚖️ Compliance Check

Screen everyone, and screen regularly.

The database is free and searchable. Screening obligations extend to employees, contractors, vendors, and — in many arrangements — to the staff of entities you contract with. Many organizations screen monthly, because exclusions are added continuously and because the liability for employing an excluded person accrues from the date of exclusion, not from the date you found out.

If you are ever excluded, you cannot work around it by taking a non-billing role. The prohibition covers administrative and management services.

Screening obligations and their scope are set by federal guidance and, in many cases, by state requirements and payer contracts. Verify what applies to your organization.


5.6 The seven elements of an effective compliance program

The OIG's compliance program guidance — issued for physician practices, hospitals, third-party billing companies, and others, and consolidated in later general guidance — describes seven elements. They are examined on credential tests and they are also, genuinely, a decent design.

# Element What it is actually for
1 Written policies, procedures, and standards of conduct So the rule exists somewhere other than in someone's head
2 A designated compliance officer and compliance committee So there is a person whose job this is, with access to leadership
3 Effective training and education So the rule reaches the people who have to apply it
4 Effective lines of communication So someone can report without going through the person they are reporting about
5 Internal monitoring and auditing So problems are found while they are still errors
6 Enforcement through well-publicized disciplinary guidelines So the rule has consequences and they are applied consistently
7 Prompt response to detected offenses and corrective action So a finding leads to a change

Two observations that matter more than the list.

Element 4 is the one that actually prevents enforcement actions. The qui tam structure means insiders bring cases. Insiders bring cases when internal reporting does not work. An organization with a functioning anonymous reporting channel that visibly leads to action has removed most of the reason anyone would go outside.

Element 7 is the one organizations fail. Element 5 — auditing — is comparatively easy and produces a report. The report is then filed. And as §5.2 showed, an unactioned audit finding is worse than no audit at all, because it establishes knowledge. A compliance program that audits and does not correct has manufactured the evidence for its own prosecution.

🎓 Exam Watch

Expect at least one question on the seven elements, usually asking which of four listed items is not one of them. Distractors commonly include "obtain professional liability insurance," "conduct annual employee satisfaction surveys," or "hire an external billing company."

A second reliable question: which element addresses the requirement to respond to detected problems? Answer: element 7, prompt response and corrective action. Candidates confuse it with element 5 (monitoring and auditing) — auditing detects, corrective action responds, and they are separate elements for exactly the reason §5.6 gives.


5.7 HIPAA: privacy, security, and the transaction standards

The Health Insurance Portability and Accountability Act of 1996 is three different things a coder needs to keep separate.

The Privacy Rule

Governs the use and disclosure of protected health information (PHI) — individually identifiable health information held or transmitted by a covered entity or business associate.

Covered entities: health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions.

Business associates: entities performing functions on behalf of a covered entity involving PHI — billing companies, coding contractors, clearinghouses in some roles, software vendors with access, shredding services. They are directly liable under HIPAA and must have a business associate agreement in place.

Treatment, payment, and health care operations (TPO) disclosures are generally permitted without individual authorization. Billing and coding are "payment." This is why you may access records without asking the patient's permission — and why the permission you have is bounded by what payment requires.

The minimum necessary standard. Uses and disclosures must be limited to the minimum necessary to accomplish the purpose. It does not apply to disclosures for treatment, but it very much applies to payment and operations.

For a coder or biller, minimum necessary is not abstract. It means:

  • Sending the relevant records with an appeal, not the entire chart
  • A query that quotes the pertinent note excerpt, not the whole admission
  • Access rights configured by role, so a scheduler cannot read an operative report
  • Not discussing an account where it can be overheard, including on a call from home

The Security Rule

Governs electronic PHI specifically, and requires administrative, physical, and technical safeguards: access controls, audit controls, encryption where reasonable and appropriate, workstation security, and a documented risk analysis.

The risk analysis requirement is the one most often unmet and most often cited.

The Transactions and Code Sets Rule

And this is the one that is easy to forget is HIPAA at all.

HIPAA required standardization of electronic health care transactions and the code sets used in them. It is why the 837, 835, 270/271, and 276/277 exist as national standards (Chapter 27) and why ICD-10-CM, CPT, and HCPCS are the mandated code sets. When Chapter 7 says the ICD-10-CM Official Guidelines are binding under HIPAA, this is the rule it means.

So the statute you associate with privacy notices is also the reason your entire professional vocabulary is standardized nationally.

Breach notification

The HITECH Act added breach notification requirements: notification to affected individuals, to HHS, and — above a threshold — to the media, within defined timeframes. Enforcement is by the HHS Office for Civil Rights, penalties are tiered by culpability, and resolution agreements are published.

⚠️ Where Claims Die

The mundane HIPAA failures that actually happen in business offices are not hackers.

  • Sending the whole chart with an appeal when four pages were needed. A minimum necessary violation, and it also weakens the appeal by burying the argument.
  • Faxing to a wrong number that is stored in the system from years ago.
  • Emailing PHI unencrypted because the payer's portal was down and the deadline was today.
  • Discussing an account at a front desk where the next patient in line can hear it.
  • Working from home on a shared device with records visible to a household.
  • Curiosity. Looking up a record you have no business reason to see. This is the one that most reliably ends employment, it is detected by audit log review, and it is not a gray area.

None of these require malice and all of them are reportable events.


5.8 The named errors

The categories, with the honest version of each.

Upcoding. Reporting a code that reflects a more expensive service than the documentation supports. The archetype is a level 4 or 5 office visit on documentation supporting a level 2 or 3.

Downcoding. Reporting a code that reflects a less expensive service than the documentation supports.

And here is the argument this book will keep making: downcoding is not the safe choice.

It is an inaccuracy. It understates what the provider did. It forfeits revenue the practice earned. It corrupts every downstream use of the data — quality measurement, risk adjustment (Chapter 36), and the practice's own understanding of its work. And it is not a legal defense: a false record is a false record in either direction, and a claim that misrepresents the service is a misrepresentation regardless of which way the error runs.

The reason people believe otherwise is that downcoding does not get you audited, because nobody audits for underpayment. That is a statement about detection, not about accuracy.

Unbundling. Reporting component parts of a service separately when a single comprehensive code describes it, or when edits prohibit separate reporting. Chapter 21 is entirely about the edit mechanism; Account 31-2245 in §5.8's callout below is the recurring example.

Cloning. Chapter 4 §4.6.

Billing for services not rendered. The clearest form of fraud and the least interesting, because there is no ambiguity to discuss.

Misrepresenting the provider. Billing a service furnished by one person under another's identifier. The incident-to and split/shared rules (Chapter 15 §15.11) define when a service furnished by one clinician may be reported under another's number, and the rules are specific. Outside them, it is a misrepresentation.

Misrepresenting the date, the site, or the diagnosis to obtain coverage.

And the ones without names — the errors that are simply wrong: transposed digits, wrong units, wrong laterality, a modifier applied by a macro to every claim in a batch.

📋 Read the Chart

text FIGURE 5.1 — "Forty-two claims, one macro" [Account 31-2245] THE DOCUMENT A commercial payer's special investigations unit findings letter, with the claim detail attached. Constructed. THE CONTEXT An eight-surgeon orthopedic group. A shoulder arthroscopy with rotator cuff repair, billed with three procedure lines. The payer reviewed 42 claims across 18 months showing the identical pattern. WHAT IT SHOWS Line 3 carries a distinct-procedural-service modifier. The operative reports document debridement of the same structures that were repaired. Under the correct coding edits, that debridement is included in the repair, and the modifier asserts a distinction the operative note does not support. The modifier was appended by a billing macro configured years earlier, not by a coder reading a note. WHAT IT DOESN'T It does not show intent, and the letter does not allege any. It does not show that the surgeons knew. It does not distinguish the claims where separate debridement genuinely occurred from the ones where it did not, because the documentation does not distinguish them either. THE DECISION Stop the macro today. Quantify the exposure across the full period, not just the sampled claims. Get counsel involved before responding. Do not amend a single operative report. THE LESSON Nobody in this practice decided to unbundle anything. A configuration did it 42 times, and the absence of intent does not make the claims correct. This is what "reckless disregard" looks like from the inside: not a decision, an unexamined default.

```text THE CLAIM AS SUBMITTED — Account 31-2245 [constructed teaching example]

LINE CODE MOD DESCRIPTION (paraphrased) CHARGE


1 29827 RT Shoulder arthroscopy, rotator cuff 4,800.00 repair 2 29826 RT Subacromial decompression with 1,200.00 partial acromioplasty (ADD-ON CODE) 3 29822 59, RT Shoulder arthroscopy, limited 900.00 debridement ◄── THE PROBLEM

THE PAYER'S FINDING [constructed] claims reviewed .................................. 42 period ........................................... 18 months average overpayment per claim .................... $612.40 demand (42 x $612.40) ............................ $25,720.80

THE PRACTICE'S OWN LATER REVIEW claims where separate debridement was, on the surgeon's recollection, genuinely performed ...... 11 of 42 claims where the OPERATIVE NOTE DOCUMENTED it .... 0 of 42 ```

That last pair of lines is the whole lesson of this chapter. Eleven of the forty-two may well have been defensible. They were not defended, because the defense is contemporaneous documentation and it cannot be built afterward. Chapter 21 §21.9 works this claim edit by edit; Chapter 37 §37.6 shows what extrapolation would have done to the number.


5.9 What to do when you are told to code something you cannot defend

This will happen. Not on your first day, probably not in your first year, and eventually.

It usually does not look like a request to commit fraud. It looks like:

  • "Dr. — always bills these as a level four. Just make it match."
  • "Put the modifier on so it goes through. We'll deal with it if they ask."
  • "Use the diagnosis that gets it covered."
  • "You're being too conservative. Everyone else codes it this way."
  • "That's how we've always done it."

Here is the sequence.

1. Make sure you are right. Genuinely. Check the guideline, the edit, the payer policy. A coder who escalates and turns out to have misread a rule has spent credibility they will need later. Chapter 3 §3.10 is where to look.

2. Assume good faith and ask a question rather than making an accusation. "Can you help me understand what's supporting the level four here? I'm reading the note and I'm only getting to a three, and I'd rather be wrong now than have this come back." That framing is not weakness. It is how you find out whether you have missed something, and it gives the other person a way to correct course without a confrontation.

3. Put it in writing. Not as a threat — as a record. An email summarizing your reading, the rule you relied on, and the question. If the answer changes your mind, you have learned something. If it does not, you have a contemporaneous record of what you said and when.

4. Code what the documentation supports. This is the part that is not negotiable. You may be overruled — someone else may change the code — but you do not enter a code you cannot defend.

5. Escalate through the compliance channel if the instruction stands. That is what element 4 is for.

6. If there is no channel, or the channel does not work, get advice from outside the organization. Your credentialing body has ethical guidance and resources. An attorney is appropriate at this point and it is not an overreaction. §5.3's protections exist; they are more useful if you have documented what happened.

📞 On the Phone

The conversation, done well, in the version that most often works.

Manager: "Dr. — bills all of these as a 99214. Can you just make them match?"

What not to say: "That would be fraud." Even when it is heading that way, this ends the conversation, makes an enemy, and — critically — makes it far less likely that anyone tells you anything next time.

What works: "I want to make sure I'm reading these right, because if I'm wrong we're leaving money on the table and I'd like to know. Here's what I'm seeing: these six all document one stable chronic problem and a refill. Under the 2021 rules that's a three on decision making, and time isn't documented. If Dr. — is doing more than the note shows, that's a documentation conversation and I'd be glad to have it — the note's underselling the work. But I can't code above what's written. Can we get fifteen minutes with them?"

Four things are happening in that answer: it offers the possibility that you are wrong, it states the rule specifically, it reframes the problem as documentation rather than accusation, and it proposes a next step. It also, quietly and unmistakably, says no.

And if the answer is "just do it anyway": "I'm not able to do that. I'll code what's documented, and I'll put my reasoning in an email so there's a record of where we landed. If you want a second opinion I'd genuinely welcome one — compliance or an external auditor."


5.10 The coder's professional ethics

Beyond the law, there is a professional standard, and both major credentialing organizations publish one.

The recurring commitments, across both:

  • Code accurately, honestly, and completely, based only on documentation
  • Refuse to participate in or conceal unethical coding or billing practices
  • Advance coding knowledge through continuing education
  • Protect confidentiality
  • Report suspected violations through appropriate channels
  • Do not misrepresent credentials or qualifications
  • Do not accept anything of value that could compromise judgment

Violating them can cost your credential, which — as §5.5 explained about exclusion, and as Chapter 39 will explain about credentials — is a substantial share of your employability.

But the reason to hold them is not the credential.

The reason is that this profession runs on a claim that nobody can verify in the moment. A coder who says a note supports a level four is making an assertion that, in practice, will almost never be checked. The whole system — the payer's adjudication, the provider's certification, the patient's statement, the government's payment — proceeds on the assumption that the person who read the note told the truth about what it said.

That is a great deal of trust placed in a job that does not pay especially well and that most people outside it have never heard of. Holding it is the work.


🗂️ The Encounter

🗂️ The Encounter

What this chapter contributes: the compliance reading of the same note.

Chapter 4 read Figure 4.2 as a coder. Read it now as an auditor, and then as a prosecutor, because those are different readings and the difference is instructive.

The claim as submitted: 99214 with modifier 25, 20610-RT, J1030, 36415.

The auditor's reading. Does the record support each line?

Line Supported? On what
20610-RT Yes Site, laterality, approach, technique, absence of guidance, all documented
J1030 Yes Agent and dose (40 mg) both documented
36415 Yes Explicitly documented as performed in office
99214 with modifier 25 Yes — and this is the one worth examining Three chronic conditions individually assessed, prescription drug management, two tests ordered with reasons, all independent of the knee

Now the counterfactual, which is the point of putting this in Chapter 5.

Suppose the note had said only this:

text ASSESSMENT AND PLAN 1. Diabetes, hypertension, hyperlipidemia - stable, continue current medications. 2. Right knee pain. Injection performed today - see procedure note.

Everything clinical is the same. The visit happened, the conditions were addressed, the medications were continued. And the claim would be indefensible, because modifier 25 asserts a significant, separately identifiable evaluation and management service, and this version documents an acknowledgment rather than an evaluation.

What the theory would look like. Not "someone lied" — that is rarely how these cases are constructed. It would look like this:

  1. Modifier 25 was applied to the E/M line.
  2. The modifier asserts a separately identifiable service.
  3. The documentation does not support it.
  4. The pattern is consistent across N claims over M months.
  5. Nobody read a note before appending the modifier — it was applied by rule.
  6. Therefore: reckless disregard, satisfying "knowingly," without anyone having formed an intent to defraud.

Step 5 is where Account 31-2245 and this hypothetical converge, and it is why §5.8's shoulder claim is in this chapter. The mechanism of most coding enforcement is not a decision. It is an unexamined default operating at volume.

What this settles. That Account 10-4471's claim is defensible on its documentation — and that its defensibility rests entirely on four sentences a physician chose to write, none of which were required by any template.

What it does not settle. Whether the payer will agree. It will not, on the first pass. And the distance between "defensible" and "paid" is Part VI.

Open questions: Q5 and Q6 remain open. A new one is now visible and is deferred by name: whether modifier 25 was correctly applied — Q1 — which Chapter 14 will raise properly and Chapters 21 and 30 will resolve.


Conclusion

Every claim is a certification, and "knowingly" reaches deliberate ignorance and reckless disregard.

What was decided in this chapter. What a claim certifies, including compliance with the kickback and self-referral laws. That fraud requires intent and abuse does not, and that the same conduct moves between them on volume, time, and evidence that somebody knew — which makes an unactioned audit finding the most dangerous document in an organization. The False Claims Act, its definition of "knowingly," materiality, and the qui tam structure that means insiders bring the cases and are protected when they do. The Anti-Kickback Statute and Stark, and the crucial difference that one requires intent and the other is strict liability. What the government can take, ending with exclusion — which ends employability rather than merely billing. The seven compliance program elements, with the observation that element 4 prevents cases and element 7 is the one organizations fail. HIPAA's three faces, including the transactions rule that made your entire vocabulary a national standard. The named errors, and the argument that downcoding is not the safe choice. A six-step sequence for the day you are told to code something you cannot defend. And a professional standard that exists because nobody checks the coder in the moment.

What remains open. Everything technical. You now know what is at stake and not one code.

The bridge to Chapter 6. Five chapters of context, and the reader has not yet held the tools. The next chapter is the toolkit: three code books and what each is for, how to set one up so it works under time pressure, what an encoder does and does not decide, the practice management system and the electronic health record, the clearinghouse and the scrubber, and the free authoritative sources you will use for the rest of your career. Then, in Chapter 7, the first code.


Key Terms

Fraud — knowingly and willfully executing, or attempting to execute, a scheme to obtain money from a health care benefit program by false pretenses. Requires intent. (Ch.5)

Abuse — practices inconsistent with sound fiscal, business, or medical practice that result in unnecessary cost. Does not require intent. (Ch.5)

False Claims Act — 31 U.S.C. §§ 3729–3733; the primary civil enforcement statute, prohibiting knowingly presenting false claims, using false records material to them, and improperly avoiding an obligation to repay. (Ch.5)

Knowingly (FCA) — actual knowledge, deliberate ignorance, or reckless disregard of truth or falsity. No specific intent to defraud is required. (Ch.5)

Qui tam — the False Claims Act provision permitting a private relator to sue on the government's behalf and share in the recovery, with anti-retaliation protection. (Ch.5)

Anti-Kickback Statute — 42 U.S.C. § 1320a-7b(b); criminal prohibition on knowingly and willfully soliciting, receiving, offering, or paying remuneration to induce or reward federal health care program referrals. (Ch.5)

Safe harbor — a defined arrangement that, if every element is satisfied, is protected from Anti-Kickback Statute liability. All-or-nothing. (Ch.5)

Stark Law (physician self-referral law) — 42 U.S.C. § 1395nn; civil, strict liability prohibition on physician referrals for designated health services to entities with which they have a financial relationship, absent an exception. (Ch.5)

Civil Monetary Penalties Law — authority for per-item penalties and assessments for defined conduct including presenting claims a person knows or should know are false. (Ch.5)

Exclusion — OIG action barring an individual or entity from participation in all federal health care programs; reaches items or services furnished, ordered, or prescribed by the excluded person and extends to employment in any capacity by a billing provider. (Ch.5)

Corporate integrity agreement — a negotiated settlement obligation imposing specific compliance measures, typically for five years. (Ch.5)

HIPAA — the Health Insurance Portability and Accountability Act of 1996; source of the Privacy Rule, the Security Rule, and the Transactions and Code Sets Rule that mandates ICD-10-CM, CPT, and HCPCS. (Ch.5)

Protected health information (PHI) — individually identifiable health information held or transmitted by a covered entity or business associate. (Ch.5)

Covered entity — a health plan, health care clearinghouse, or provider transmitting health information electronically in covered transactions. (Ch.5)

Business associate — an entity performing functions involving PHI on behalf of a covered entity; directly liable under HIPAA and requiring a business associate agreement. (Ch.5)

Minimum necessary — the standard requiring uses and disclosures to be limited to what is needed for the purpose. Applies to payment and operations; not to treatment. (Ch.5)

Compliance program — the seven-element structure described in OIG guidance: policies, a compliance officer, training, communication lines, monitoring and auditing, enforcement, and prompt corrective action. (Ch.5)

Upcoding — reporting a code reflecting a more expensive service than the documentation supports. (Ch.5)

Downcoding — reporting a code reflecting a less expensive service than the documentation supports. An inaccuracy, not a safe harbor, and not a defense. (Ch.5)

Unbundling — reporting component parts separately when a comprehensive code describes the service or when edits prohibit separate reporting. (Ch.5)


Spaced Review

  1. State the three prongs of "knowingly" under the False Claims Act, and give a coding example of the third that involves no intent to deceive.

  2. (Chapter 4) A practice's internal audit finds that 30% of its level 4 visits are unsupported. The practice files the report and changes nothing. Explain, using §5.2, what that report did to the practice's legal position on every subsequent claim.

  3. Distinguish the Anti-Kickback Statute from Stark on four dimensions. Which one can be violated by an arrangement nobody intended anything improper by?

  4. Name the seven compliance program elements. Which one most reduces the likelihood of a qui tam action, and why?

  5. (Chapter 2) A practice routinely waives copays for patients it considers financially strained, with no written policy and no individual determination. Name the two statutes potentially implicated and the compliant alternative.