A cardiologist in South Florida receives a $500 payment every time he refers a patient to a specific imaging center. A home health agency gives gift cards to hospital discharge planners who steer patients their way. A pharmaceutical company flies physicians to resort conferences in exchange for prescribing their drugs. Every one of these scenarios is a federal crime. And the question on every healthcare compliance exam — the act that prohibits the practice of kickbacks is the federal Anti-Kickback Statute (AKS), codified at 42 U.S.C. § 1320a-7b(b). If you work in healthcare, understanding this law isn't optional. It's survival.

This statute sits at the intersection of healthcare fraud enforcement and HIPAA compliance — and if your organization handles PHI, bills federal programs, or both, you need to understand how these laws overlap and reinforce each other.

What Exactly Is the Anti-Kickback Statute?

The Anti-Kickback Statute makes it a criminal offense to knowingly and willfully offer, pay, solicit, or receive anything of value to induce or reward referrals of items or services covered by federal healthcare programs. That includes Medicare, Medicaid, TRICARE, and the Veterans Health Administration.

"Anything of value" isn't limited to cash. It covers meals, travel, consulting fees, rent below fair market value, and even waived copays when done with the intent to generate referrals. The penalties are severe: criminal fines up to $100,000 per violation, up to 10 years in prison, and exclusion from all federal healthcare programs.

The Office of Inspector General (OIG) at the Department of Health and Human Services (HHS) is the primary enforcer. And they don't need to prove that a kickback was the only reason for a referral — just that it was one reason.

The One-Purpose Test That Changed Everything

In 2010, the Affordable Care Act amended the AKS to clarify that a violation occurs if "one purpose" of the payment is to induce referrals. Before that, some courts required prosecutors to show the payment was the primary purpose. That amendment closed the loophole entirely.

This means even a legitimate consulting arrangement can trigger AKS liability if part of the underlying motivation involves referrals. I've seen compliance officers lose sleep over speaker fees and advisory board payments for exactly this reason.

How the Anti-Kickback Statute Connects to HIPAA

Here's where most people get confused. HIPAA and the Anti-Kickback Statute are separate laws with separate enforcement mechanisms. But they share critical DNA — and violations of one frequently surface alongside violations of the other.

When a kickback scheme operates inside a covered entity, it almost always involves misuse of protected health information (PHI). Think about it: to steer referrals, someone needs patient data. That means accessing ePHI without a legitimate treatment, payment, or operations purpose. That's a HIPAA violation.

The HHS Office for Civil Rights (OCR) enforces HIPAA's Privacy and Security Rules. The OIG enforces the AKS. When fraud investigators pull on one thread, they often unravel both. A single whistleblower complaint can trigger parallel investigations under both statutes.

Real Enforcement: When Kickbacks and PHI Collide

In 2022, the DOJ and OIG pursued a case against a clinical laboratory network that paid physicians per-specimen fees disguised as "processing fees" to induce referrals of lab tests billed to Medicare. The investigation revealed that sales representatives accessed patient records — ePHI — to identify high-volume prescribers and target them for kickback arrangements. The company paid over $49 million to resolve False Claims Act and AKS allegations.

This pattern repeats across industries. Durable medical equipment suppliers, pharmacy compounders, home health agencies — when kickbacks drive referrals, PHI access almost always gets abused in the process.

The Act That Prohibits the Practice of Kickbacks Is Not Alone

The AKS doesn't work in isolation. It's part of a web of federal fraud and abuse laws that your compliance program must address together:

  • The Stark Law (Physician Self-Referral Law): Prohibits physicians from referring Medicare patients for certain designated health services to entities where the physician has a financial relationship. Unlike the AKS, it's a strict liability statute — no intent required.
  • The False Claims Act (FCA): Since 2010, a claim resulting from an AKS violation is automatically a false claim. This opens the door to treble damages and per-claim penalties.
  • HIPAA: The Privacy Rule restricts how PHI can be used and disclosed. The Security Rule mandates safeguards for ePHI. Any kickback scheme that involves unauthorized access to patient data creates HIPAA exposure.

Your workforce needs to understand all of these laws — not just one. That's why comprehensive HIPAA and compliance training covers fraud and abuse statutes alongside privacy and security requirements.

Safe Harbors: The Only Protection That Matters

Congress and the OIG recognized that not every financial relationship in healthcare is corrupt. The AKS includes regulatory "safe harbors" — specific arrangements that, if structured correctly, are protected from prosecution. The OIG publishes the full list of safe harbor regulations and updates them periodically.

Common safe harbors include:

  • Employment: Payments to bona fide employees are protected.
  • Personal services and management contracts: Must be written, specify services, cover at least one year, and involve fair market value compensation.
  • Space and equipment rental: Must be at fair market value with a written agreement.
  • Discounts: Properly disclosed price reductions passed along to federal programs.
  • Electronic health records: Donations of interoperable EHR technology under specific conditions.

Missing even one element of a safe harbor means you have zero protection. I've reviewed arrangements where organizations checked eight out of nine boxes and still faced OIG scrutiny. Close doesn't count.

What Happens When Your Organization Ignores This

The consequences cascade. A kickback violation triggers False Claims Act liability, which multiplies financial exposure. If PHI was accessed improperly during the scheme, OCR can pursue HIPAA penalties independently. Add state law violations — most states have their own anti-kickback statutes — and you're facing regulatory action on multiple fronts simultaneously.

Exclusion from federal healthcare programs is often the most devastating consequence. For a provider, exclusion means you cannot bill Medicare or Medicaid. For most healthcare organizations, that's a death sentence.

The OIG maintains the List of Excluded Individuals and Entities (LEIE), and every covered entity has an obligation to check it before hiring or contracting with anyone. Failure to screen against the LEIE is itself a compliance failure.

Five Steps to Protect Your Organization Right Now

Knowing that the act that prohibits the practice of kickbacks is the Anti-Kickback Statute isn't enough. You need operational safeguards.

1. Audit Every Financial Relationship

Map every arrangement where money flows between your organization and referral sources. Medical directorships, consulting agreements, lease arrangements, joint ventures — all of them. If any arrangement doesn't fit squarely within a safe harbor, restructure it or end it.

2. Train Your Entire Workforce

Physicians, executives, billing staff, sales teams, and front desk employees all need to recognize kickback red flags. Your HIPAA training program should integrate fraud and abuse education so your team understands both privacy obligations and financial compliance requirements.

3. Implement a Reporting Mechanism

Whistleblower protections under the False Claims Act incentivize employees to report violations. If your staff doesn't have a safe, anonymous way to report concerns internally, they'll report externally — directly to the OIG or through a qui tam lawsuit.

4. Screen Against the LEIE Monthly

Don't wait for annual checks. The OIG updates the exclusion list monthly. Automate this process. One excluded individual on your payroll can contaminate every claim your organization submits.

5. Document Everything

Every referral arrangement needs a written agreement. Every payment needs documentation showing fair market value. Every safe harbor analysis needs to be memorialized. When the OIG comes knocking — and eventually, for some organizations, they will — documentation is your first and strongest defense.

Quick Answer: What Act Prohibits Kickbacks in Healthcare?

The act that prohibits the practice of kickbacks is the federal Anti-Kickback Statute (AKS), found at 42 U.S.C. § 1320a-7b(b). It makes it a criminal offense to offer, pay, solicit, or receive anything of value to induce referrals for services covered by federal healthcare programs like Medicare and Medicaid. Violations carry criminal penalties of up to $100,000 per violation and 10 years imprisonment, plus exclusion from federal healthcare programs. The OIG at HHS enforces the statute, and the law intersects heavily with HIPAA when kickback schemes involve unauthorized access to PHI or ePHI.

The Bottom Line for Every Covered Entity

Healthcare fraud enforcement isn't slowing down. HHS, the OIG, and the DOJ continue to prioritize kickback schemes because they inflate costs, compromise patient care, and corrode trust in the healthcare system. If your organization touches federal dollars and handles PHI — and nearly every covered entity does both — your compliance program must address the Anti-Kickback Statute with the same rigor you apply to HIPAA privacy and security.

Don't treat these as separate silos. The organizations I've seen face the worst outcomes are the ones that built a HIPAA program in one department and a fraud compliance program in another, with no communication between them. Integrate your training. Integrate your audits. Integrate your risk assessments.

Your compliance program is only as strong as the weakest link in your workforce's understanding. Start with training that covers the full landscape — explore the HIPAA training catalog to build a foundation that keeps your organization on the right side of every federal enforcement action.